← Back to feed
Vulnerabilities & PatchesEmerging1 sourceFeb 9, 2022 · 18:29via API Security News

Issue 171: DPD parcel tracking flaw, Apache Pulsar and Casdoor vulnerabilities, trends in API industry

Brief

This week, we have news of multiple API flaws and vulnerabilities: the parcel tracking portal at DPD that may have exposed customer data; an API vulnerability in the Apache Pulsar that allowed access data in different tenants; and an SQL injection vulnerability in Casdoor API. On the more positive side, we take a look at the emerging trends in the API industry.

Vulnerability: DPD parcel tracking flaw may have exposed customer data

The big news this week was the disclosure of a vulnerability in the parcel tracking portal of DPG Group , which may have exposed customer data.

The vulnerability was discovered by Pen Test Partners in September 2021, and they co-operated with DPD Group to assess and triage the vulnerability. DPD Group resolved the vulnerability in October 2021 and had requested that the details only be published in the new year to have time to conduct a full review.

Read more on API Security News