In Apache NiFi versions 1.10.0 through 1.27.0 and 2.0.0-M1 through 2.0.0-M3 a medium severity vulnerability CVE-2024-45477 was detected. This allows attackers to inject and execute arbitrary JavaScript code within the session context of an authenticated user authorized to configure a Parameter Context. To fix this issue, users must upgrade to Apache NiFi version 1.28.0 or 2.0.0-M4. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-45477.
Read more Data AnalyticsIn Grafana version 10.4.0 a low severity vulnerability CVE-2024-10452 was detected. This vulnerability allows organization admins to delete pending invites created in an organization they are not part of. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-10452.
Read more Data AnalyticsIn MongoDB Server versions 6.0 (prior to 6.0.17), 7.0 (prior to 7.0.13), and 7.3 (prior to 7.3.4) a medium severity vulnerability CVE-2024-8305 was detected. This vulnerability allows attackers to trigger crashes in secondary nodes by incorrectly enforcing index constraints. In extreme cases, multiple secondaries may crash, potentially leaving no primaries available. To address this issue, update to the latest fixed versions: 6.0.17, 7.0.13, or 7.3.4. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-8305.
Read more DatabaseIn Grafana version 11.0.0 and prior a critical severity vulnerability CVE-2024-9264 was detected. The SQL Expressions feature in Grafana allows poorly sanitized duckdb queries with user input, leading to command injection and local file inclusion. Users with VIEWER or higher permissions can exploit this if the duckdb binary is in Grafana’s $PATH. To fix this issue, users need to update to versions 11.0.5, 11.1.6, 11.2.1, 11.0.6, 11.1.7, or 11.2.2. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-9264.
In MariaDB version 11.1 a medium severity vulnerability CVE-2024-27766 was detected. This vulnerability allows remote attackers to execute arbitrary code through the lib_mysqludf_sys.so function. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-27766.
In MariaDB versions 10.5 a medium severity vulnerability CVE-2023-39593 was detected. This vulnerability allows authenticated attackers to execute arbitrary commands with elevated privileges. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39593.
Read more DatabaseIn MySQL versions 8.0.39 and prior, 8.4.2 and prior, and 9.0.1 and prior a medium severity vulnerability CVE-2024-21218 was detected. This vulnerability allows attackers with high privileges and network access to cause a MySQL server crash, resulting in a denial of service (DoS). Currently, there’s no patch version for this vulnerability. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-21218.
Read more DatabaseIn MySQL versions 8.0.39 and prior, 8.4.2 and prior, and 9.0.1 and prior a medium severity vulnerability CVE-2024-21239 was detected. This vulnerability allows attackers to crash the MySQL server or make it unresponsive, disrupting access to data and services. To fix this issue, users should upgrade MySQL to versions 8.0.40, 8.4.3, or 9.0.2. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-21239.
Read more DatabaseIn MySQL versions prior to 8.0.39, prior to 8.4.2, and prior to 9.0.1 a medium severity vulnerability CVE-2024-21238 was detected. This vulnerability allows attackers to cause the MySQL server to freeze or crash, preventing users from accessing their data and services. To fix this issue, users should upgrade MySQL to versions 8.0.40, 8.4.3, or 9.0.2. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-21238.
Read more Database