Portrait of Md. Tareq Ahamed Jony Active
Knight Squad Academy Team

Md. Tareq Ahamed Jony

Tareq is a founding member of the Knight Squad community and is part of Knight Squad Academy as an Offensive Security Researcher. He takes classes and contributes to certification design and assessment development, with a focus on web application security, practical testing, and responsible vulnerability research. He has responsibly reported vulnerabilities to organizations and projects including Meta (Facebook), Yahoo, Mozilla, Nextcloud, and Apache Airflow, and his research work includes 3+ published CVEs. He holds recognized certifications including eJPT, CRTA, CAPen, and C-APIPen, and supports hands-on learning by creating CTF challenges for KnightCTF and BDSec CTF.

Credentials
  • eJPT
  • CRTA
  • CAPen
  • C-APIPen
  • CPSA
12 CVE disclosures
1 Published article

Security Research & Publications

Vulnerability disclosures

Public records with concise research context.

CVSS score 4.3 Medium
Published

We failed to apply CVE-2023-40611 in 2.7.1 and this vulnerability was marked as fixed then.  Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc.  Users should upgrade to version 2.7.3 or later which has removed the vulnerability.

View advisory
CVSS score 6.1 Medium
Published

Notes is a note-taking app for Nextcloud, an open-source cloud platform. Starting in version 4.4.0 and prior to version 4.8.0, when creating a note file with HTML, the content is rendered in the preview instead of the file being offered to download. Nextcloud Notes app version 4.8.0 contains a patch for the issue. No known workarounds are available.

View advisory