What you need to know today.
Ansible AWX and Eclipse GlassFish face information disclosure risks, while Firefox 153 patches numerous vulnerabilities.

A cross-organization information disclosure vulnerability in Ansible AWX allows unauthorized users to access sensitive stdout data. Specifically, the EventConsumer component fails to properly authorize requests for inventory, project, and system job events, enabling attackers to potentially exfiltrate data across different organizations within the AWX instance. This flaw could lead to the exposure of critical system configurations or sensitive operational details. Users are advised to update to a patched version of Ansible AWX as soon as possible to mitigate this risk.
Eclipse GlassFish versions 5.1.0 through 6.2.5 are affected by a relative path traversal vulnerability. The issue stems from a failure to properly filter request paths that begin with './', allowing unauthenticated remote attackers to access arbitrary files on the server. This could lead to unauthorized information disclosure or potentially further system compromise depending on the accessed files. Administrators should upgrade to a fixed version of GlassFish or apply relevant security patches to address this vulnerability.
Mozilla has released Firefox 153, addressing a significant number of vulnerabilities, including memory safety bugs and various component-specific flaws. Among the issues fixed are mitigation bypasses in the DOM and Networking components, privilege escalations in DOM: Content Processes and Data Loss Prevention, sandbox escapes in DOM: Networking and Disability Access APIs, and information disclosures in Graphics: WebGPU and Privacy. Additionally, spoofing issues in the Address Bar and Firefox for Android, clickjacking in Firefox for Android, and denial-of-service in Graphics: WebGPU were resolved. These updates are crucial for maintaining the security and integrity of user data and system access.