Skip to content

Source profile

watchtowr.com

watchtowr.com

Evidence-bounded context

A field appears only when the current profile revision carries supporting evidence. Missing context stays visibly unknown.

Source classes
Not yet evidenced
Ownership
Not yet evidenced
Funding ties
Not yet evidenced
Declared affiliations
Not yet evidenced
Geographic base
Not yet evidenced
Methodology
Not yet evidenced

Current clusters

build3 publishers

Default NetScaler Gateway configurations meet the conditions for both exploited pre-auth RCE bugs

Citrix confirmed attackers are exploiting two CVSS 9.5 pre-auth RCE flaws in NetScaler ADC and Gateway, one of them present in default configurations. Self-managed appliances need the fixed build, installed after evidence is saved, since an upgrade can erase signs of intrusion.

Perspective Coverage

3 publishers
Builder
Builder 20%
Operator
Operator 68%
Investor
Investor 12%

Reality

Evidence70
Adoption
Insufficient
Hype gap+5
Incentives35
Confidence72
build3 publishers

A file.path parameter in GitLab's commit API reads server files before authentication

The fix ships in 19.3.2, 19.2.6 and 19.1.8, and scanning for the flaw started the day after disclosure. Whether you can tell if a read succeeded on your instance depends on whether your proxy logs request bodies.

Perspective Coverage

3 publishers
Builder
Builder 22%
Operator
Operator 73%
Investor
Investor 5%

Reality

Evidence80
Adoption
Insufficient
Hype gap+15
Incentives45
Confidence74