In Sonatype Nexus Repository 2.x versions up to and including 2.15.2 a high severity vulnerability CVE-2025-9868 was detected. This vulnerability in the Remote Browser Plugin allows unauthenticated remote attackers to exfiltrate proxy repository credentials via crafted HTTP requests. To address this issue, users should upgrade to Nexus Repository 3.x. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-9868.
Read more Developer ToolsIn SonarQube versions prior to 25.6, 2025.3 Commercial, and 2025.1.3 LTA a medium severity vulnerability CVE-2025-62292 was detected. Authenticated low-privileged users can query the /api/v2/users-management/users endpoint and access user fields intended for administrators only, including the email addresses of other accounts. To address this issue, users should upgrade SonarQube to versions 25.6, 2025.3 Commercial, 2025.1.3 LTA or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-62292.
Read more Developer ToolsIn GitLab EE versions 18.3 to 18.3.4 and 18.4 to 18.4.2 a high severity vulnerability CVE-2025-11340 was detected. This vulnerability allows authenticated users with read-only API tokens to perform unauthorized write operations on vulnerability records by exploiting incorrectly scoped GraphQL mutations. To address this issue, users should upgrade GitLab to versions 18.4.2 or 18.3.4. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-11340.
Read more Developer ToolsIn GitLab CE/EE versions 5.2 prior to 18.2.8, 18.3 prior to 18.3.4 and 18.4 prior to 18.4.2 a medium severity vulnerability CVE-2025-2934 was detected. This vulnerability allows authenticated attackers to create a denial of service condition by configuring malicious webhook endpoints that send crafted HTTP responses. To address this issue, users should upgrade GitLab to versions 18.4.2, 18.3.4 or 18.2.8. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-2934.
Read more Developer ToolsIn Rancher Manager versions 2.9.0 through 2.9.11, 2.10.0 through 2.10.9, 2.11.0 through 2.11.5, and 2.12.0 through 2.12.1 a high severity vulnerability CVE-2024-58260 was detected. A missing server-side validation on the .username field allows users with update permissions on other User resources to cause denial of access for targeted accounts, potentially impacting system availability and user access. To address this issue, users should upgrade Rancher Manager to versions 2.9.12, 2.10.10, 2.11.6, 2.12.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-58260.
Read more Developer ToolsIn Rancher Manager versions 2.9.0 through 2.9.11, 2.10.0 through 2.10.9, 2.11.0 through 2.11.5, and 2.12.0 through 2.12.1 a medium severity vulnerability CVE-2025-54468 was detected. The /meta/proxy endpoint may send Impersonate-Extra-* headers to external entities, such as amazonaws.com. These headers can contain identifiable or sensitive information, including email addresses. To address this issue, users should upgrade Rancher Manager to versions 2.9.12, 2.10.10, 2.11.6, 2.12.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-54468.
Read more Developer ToolsIn Rancher Manager versions 2.9.0 through 2.9.11, 2.10.0 through 2.10.9, 2.11.0 through 2.11.5, and 2.12.0 through 2.12.1 a high severity vulnerability CVE-2024-58267 was detected. The SAML authentication mechanism used by the Rancher CLI tool is vulnerable to phishing attacks. The custom authentication protocol for SAML-based providers can be exploited to steal Rancher authentication tokens, allowing attackers to potentially gain unauthorized access. To address this issue, users should upgrade Rancher Manager to versions 2.9.12, 2.10.10, 2.11.6, 2.12.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-58267.
Read more Developer ToolsIn Argo CD versions 2.9.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.6, and 3.0.17 a high severity vulnerability CVE-2025-59538 was detected. This vulnerability allows unauthenticated attackers to cause a denial-of-service (DoS) by sending a malformed Azure DevOps git.push webhook to the /api/webhook endpoint when webhook.azuredevops.username and webhook.azuredevops.password are not set, causing the server process to crash due to an index-out-of-range panic on an empty JSON array. To address this issue, users should upgrade Argo CD to versions 2.14.20, 3.2.0-rc2, 3.1.8 or 3.0.19. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-59538.
Read more Developer ToolsIn Argo CD versions 1.2.0 through 1.8.7, 2.0.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.7 and 3.0.18 a high severity vulnerability CVE-2025-59537 was detected. This vulnerability allows unauthenticated attackers to cause a denial-of-service (DoS) condition by sending a malformed Gogs webhook payload to the `/api/webhook` endpoint when `webhook.gogs.secret` is not set, causing the Argo CD server process to crash if the `commits[].repo` field in the JSON payload is missing or null. To address this issue, users should upgrade Argo CD to versions 2.14.20, 3.2.0-rc2, 3.1.8 or 3.0.19. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-59537.
Read more Developer Tools