{"id":47249,"date":"2026-04-15T12:45:22","date_gmt":"2026-04-15T12:45:22","guid":{"rendered":"http:\/\/localhost\/?p=47249"},"modified":"2026-04-15T12:45:22","modified_gmt":"2026-04-15T12:45:22","slug":"kiuwan-sast-2824120-improper-enforcement","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=47249","title":{"rendered":"\ud83d\udcc4 Kiuwan SAST 2.8.2412.0 Improper Enforcement_PACKETSTORM:218979"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-04-15T16:58:09&#8243;,&#8221;description&#8221;:&#8221;It was found out that a user is still able to login at the Kiuwan WebUI via SSO, even if the Kiuwan mapped account has been disabled in the user settings by an admin. This issue has been addressed in version 2.8.2509.4&#8230;&#8221;,&#8221;published&#8221;:&#8221;2026-04-15T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2026-04-15T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 Kiuwan SAST 2.8.2412.0 Improper Enforcement&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:218979&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2026-24069&#8243;],&#8221;sourceData&#8221;:&#8221;SEC Consult Vulnerability Lab Security Advisory \\u003c 20260414-0 \\u003e\\n    =======================================================================\\n                  title: Improper Enforcement of Locked Accounts in WebUI (SSO)\\n    \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 product: Kiuwan SAST on-premise (KOP) \\u0026 cloud\/SaaS\\n    \u00a0vulnerable version: \\u003c2.8.2509.4\\n    \u00a0 \u00a0 \u00a0 fixed version: 2.8.2509.4\\n    \u00a0 \u00a0 \u00a0 \u00a0 \u00a0CVE number: CVE-2026-24069\\n    \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0impact: medium\\n               homepage:https:\/\/www.kiuwan.com\/\\n    \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 found: 2025-03-31\\n                     by: Bernhard Gr\u00fcndling (Office Vienna)\\n                         Fabian W\u00fcrfl (Office Vienna)\\n                         Johannes Greil (Office Vienna)\\n                         SEC Consult Vulnerability Lab\\n    \\n                         An integrated part of SEC Consult, an Atos business\\n                         Europe | Asia\\n    \\n                         https:\/\/www.sec-consult.com\\n    \\n    =======================================================================\\n    \\n    Vendor description:\\n    &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-\\n    \\&#8221;Thorough code inspection is essential for designing secure software products.\\n    While your development team may not have time to comb through every line of code,\\n    Kiuwan does. For 20 years, it has been the choice of developers to scan code\\n    automatically and remediate defects according to security standards like OWASP,\\n    CWE, SANS, and CERT.\\n    \\n    Static application security testing (SAST) scans for security flaws in the source\\n    code without running the program. It is a white-box testing method that is the\\n    counterpart to dynamic application software testing (DAST), which tests web applications\\n    for run-time vulnerabilities. [&#8230;]\\&#8221;\\n    \\n    Source:https:\/\/www.kiuwan.com\/code-security-sast\/\\n    \\n    \\n    Business recommendation:\\n    &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;\\n    The vendor provides a patch which should be installed immediately.\\n    \\n    SEC Consult highly recommends to perform a thorough security review of the product\\n    conducted by security professionals to identify and resolve potential further\\n    security issues.\\n    \\n    \\n    Vulnerability overview\/description:\\n    &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;\\n    1) Improper Enforcement of Locked Accounts in WebUI (SSO) (CVE-2026-24069)\\n    Kiuwan offers the possibility to enable single sign-on (SSO) for authentication,\\n    e.g. through Microsoft ADFS or Azure to authenticate against an active directory.\\n    It needs to map the AD user accounts with locally configured accounts for\\n    authorization purposes, e.g. to configure the roles and access to applications.\\n    SSO users have the local logon disabled and there is no password set, authentication\\n    only works via SSO then.\\n    \\n    It was found out that the user is still able to login at the Kiuwan WebUI via SSO,\\n    even if the Kiuwan mapped account has been disabled in the user settings by an admin.\\n    The login does not work in the scanner agent (KLA &#8211; Kiuwan Local Analyzer) though.\\n    There the authorization check seems to be verifying the validity of the account first\\n    and throws the error message \\&#8221;Failed to authenticate using Single sign-on\\&#8221;.\\n    \\n    \\n    Proof of concept:\\n    &#8212;&#8212;&#8212;&#8212;&#8212;&#8211;\\n    1) Improper Enforcement of Locked Accounts in WebUI (SSO) (CVE-2026-24069)\\n    No specific PoC is necessary. An SSO login is possible even after disabling\\n    the Kiuwan mapped user account in the Kiuwan user admin settings.\\n    Steps to reproduce:\\n    a) Disable user in Kiuwan user settings\\n    b) Authenticate via SSO, e.g. through Microsoft ADFS\\n    c) Login is possible in the Kiuwan WebUI\\n    \\n    \\n    Vulnerable \/ tested versions:\\n    &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;\\n    The following version has been tested which was the latest version available\\n    at the time of the test:\\n    * 2.8.2412.0\\n    \\n    \\n    Vendor contact timeline:\\n    &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;\\n    2025-04-02: Contacting vendor through official Kiuwan ticket system\\n                (https:\/\/kiuwan.zendesk.com)\\n                Kiuwan support responds that they will take a look into\\n                our submission. Support sends us a few details regarding\\n                SSO authentication.\\n    2025-04-03: Informing the vendor that we know how SSO auth in Kiuwan\\n                works and our vulnerability exploits the improper enforcement\\n                of locked accounts.\\n    2025-04-15: Vendor informs us that the issue has been escalated to R\\u0026D.\\n    2025-07-29: Vendor has resolved the issue in the latest Kiuwan Cloud release.\\n    2025-07-29: Asking the vendor regarding the fix for Kiuwan On-Premise.\\n                Vendor responds that it is currently being tested for KOP and\\n                they will inform us.\\n    2025-11-03: Asking for a status update as we were not informed yet.\\n    2025-11-10: Support team responds that KOP release is expected within the\\n                next couple of weeks.\\n    2025-11-24: Issue has been resolved in the latest KOP release.\\n    2025-11-28: Informing vendor that we cannot upgrade\/verify the KOP release yet,\\n                scheduled for 2026.\\n    2026-04-14: Public release of advisory.\\n    \\n    \\n    Solution:\\n    &#8212;&#8212;&#8212;\\n    The security issue has been fixed by the vendor on 29th July 2025 for the\\n    Kiuwan Cloud solution.\\n    \\n    The vendor provides a patch for the Kiuwan On-Premises version 2.8.2509.4\\n    which can be downloaded from the vendor&#8217;s installation page:\\n    https:\/\/support.kiuwan.com\/hc\/en-us\/articles\/36356787260433-Kiuwan-On-Premises-Distributed-Installation-Guide\\n    \\n    \\n    Workaround:\\n    &#8212;&#8212;&#8212;&#8211;\\n    None\\n    \\n    \\n    Advisory URL:\\n    &#8212;&#8212;&#8212;&#8212;-\\n    https:\/\/sec-consult.com\/vulnerability-lab\/\\n    \\n    \\n    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\\n    \\n    SEC Consult Vulnerability Lab\\n    An integrated part of SEC Consult, an Atos business\\n    Europe | Asia\\n    \\n    About SEC Consult Vulnerability Lab\\n    The SEC Consult Vulnerability Lab is an integrated part of SEC Consult, an\\n    Atos business. It ensures the continued knowledge gain of SEC Consult in the\\n    field of network and application security to stay ahead of the attacker. The\\n    SEC Consult Vulnerability Lab supports high-quality penetration testing and\\n    the evaluation of new offensive and defensive technologies for our customers.\\n    Hence our customers obtain the most current information about vulnerabilities\\n    and valid recommendation about the risk profile of new technologies.\\n    \\n    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\\n    Interested to work with the experts of SEC Consult?\\n    Send us your applicationhttps:\/\/sec-consult.com\/career\/\\n    \\n    Interested in improving your cyber security with the experts of SEC Consult?\\n    Contact our local officeshttps:\/\/sec-consult.com\/contact\/\\n    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\\n    \\n    Mail: security-research at sec-consult dot com\\n    Web:https:\/\/www.sec-consult.com\\n    Blog:https:\/\/blog.sec-consult.com\\n    X:https:\/\/x.com\/sec_consult\\n    \\n    EOF Bernhard Gr\u00fcndling, Johannes Greil, Fabian W\u00fcrfl \/ @2026&#8243;,&#8221;sourceHref&#8221;:&#8221;https:\/\/packetstorm.news\/download\/218979&#8243;,&#8221;cvss&#8221;:{&#8220;score&#8221;:5.4,&#8221;severity&#8221;:&#8221;MEDIUM&#8221;,&#8221;vector&#8221;:&#8221;CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:N&#8221;,&#8221;version&#8221;:&#8221;3.1&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/packetstorm.news\/files\/id\/218979\/&#8221;,&#8221;category_name&#8221;:&#8221;Exploit&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-04-15T16:58:09&#8243;,&#8221;description&#8221;:&#8221;It was found out that a user is still able to login at the Kiuwan WebUI via SSO, even if the Kiuwan mapped account has&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[6,8,82,12,21,13,53,7,11,5],"class_list":["post-47249","post","type-post","status-publish","format-standard","hentry","category-category_exploit","tag-cve","tag-cvss","tag-cvss-54","tag-exploit","tag-medium","tag-news","tag-packetstorm","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>\ud83d\udcc4 Kiuwan SAST 2.8.2412.0 Improper Enforcement_PACKETSTORM:218979 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=47249\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\ud83d\udcc4 Kiuwan SAST 2.8.2412.0 Improper Enforcement_PACKETSTORM:218979 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2026-04-15T16:58:09&#8243;,&#8221;description&#8221;:&#8221;It was found out that a user is still able to login at the Kiuwan WebUI via SSO, even if the Kiuwan mapped account has...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=47249\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2026-04-15T12:45:22+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=47249#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=47249\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"\ud83d\udcc4 Kiuwan SAST 2.8.2412.0 Improper Enforcement_PACKETSTORM:218979\",\"datePublished\":\"2026-04-15T12:45:22+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=47249\"},\"wordCount\":1177,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"CVSS-5.4\",\"exploit\",\"MEDIUM\",\"news\",\"packetstorm\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_exploit\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=47249#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=47249\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=47249\",\"name\":\"\ud83d\udcc4 Kiuwan SAST 2.8.2412.0 Improper Enforcement_PACKETSTORM:218979 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2026-04-15T12:45:22+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=47249#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=47249\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=47249#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\ud83d\udcc4 Kiuwan SAST 2.8.2412.0 Improper Enforcement_PACKETSTORM:218979\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\ud83d\udcc4 Kiuwan SAST 2.8.2412.0 Improper Enforcement_PACKETSTORM:218979 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=47249","og_locale":"en_US","og_type":"article","og_title":"\ud83d\udcc4 Kiuwan SAST 2.8.2412.0 Improper Enforcement_PACKETSTORM:218979 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2026-04-15T16:58:09&#8243;,&#8221;description&#8221;:&#8221;It was found out that a user is still able to login at the Kiuwan WebUI via SSO, even if the Kiuwan mapped account has...","og_url":"https:\/\/zero.redgem.net\/?p=47249","og_site_name":"zero redgem","article_published_time":"2026-04-15T12:45:22+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=47249#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=47249"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"\ud83d\udcc4 Kiuwan SAST 2.8.2412.0 Improper Enforcement_PACKETSTORM:218979","datePublished":"2026-04-15T12:45:22+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=47249"},"wordCount":1177,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","CVSS-5.4","exploit","MEDIUM","news","packetstorm","Security","tapic","Vulnerability"],"articleSection":["category_exploit"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=47249#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=47249","url":"https:\/\/zero.redgem.net\/?p=47249","name":"\ud83d\udcc4 Kiuwan SAST 2.8.2412.0 Improper Enforcement_PACKETSTORM:218979 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2026-04-15T12:45:22+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=47249#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=47249"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=47249#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"\ud83d\udcc4 Kiuwan SAST 2.8.2412.0 Improper Enforcement_PACKETSTORM:218979"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/47249","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=47249"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/47249\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=47249"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=47249"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=47249"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}