In Harbor versions before 2.5.2 a high severity vulnerability CVE-2022-31669 was detected. This vulnerability allows attackers to modify tag immutability policies in other projects by sending requests with an ID that belongs to a project the currently authenticated user doesn’t have access to. To fix this issue, users must upgrade to Harbor version 2.5.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2022-31669.
Read more Developer ToolsIn Harbor versions prior to 2.7.0 a high severity vulnerability CVE-2022-31668 was detected. This vulnerability allows attackers to modify P2P preheat policies in projects they don’t have permission to access. To fix this issue, users should upgrade Harbor to version 2.7.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2022-31668.
Read more Developer ToolsIn Harbor versions prior to 2.5.2 a high severity vulnerability CVE-2022-31670 was detected. This vulnerability allows an attacker to modify tag retention policies in projects they don’t have access to by sending a request with a policy ID from another project, due to Harbor’s failure to validate user permissions. To fix this issue, users need to update to version 2.5.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2022-31670.
Read more Developer ToolsIn GitLab CE/EE versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4, and starting from 17.5 prior to 17.5.2 a medium severity vulnerability CVE-2024-7404 was detected. This vulnerability allows attackers to gain full API access as the victim via the Device OAuth flow. To fix this issue, users should upgrade GitLab CE/EE to versions 17.5.2, 17.4.4, and 17.3.7. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-7404.
Read more Developer ToolsIn Harbor versions 1.0.0 and above, 1.10.12 and prior, 2.0.0 and above, 2.4.2 and prior, 2.5.0 and above, 2.5.1 and prior a high severity vulnerability CVE-2022-31671 was detected. This vulnerability allows malicious authenticated users to access or modify job execution logs in Harbor by sending requests with different job IDs, exposing all logs stored in the Harbor database due to improper permission validation. To fix this issue, users need to update Harbor to version 2.5.2 or above. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2022-31671.
Read more Developer ToolsIn GitLab CE/EE versions starting from 16.3 before 17.3.7, from 17.4 before 17.4.4, and from 17.5 before 17.5.2 a low severity vulnerability CVE-2024-9633 was detected. This vulnerability allows attackers to create a group with a name matching an existing unique Pages domain, potentially leading to domain confusion attacks. Currently, there is no fixed version available for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-9633.
Read more Developer ToolsIn GitLab CE/EE versions starting from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2 a medium severity vulnerability CVE-2024-8648 was detected. This vulnerability allows attackers to inject malicious JavaScript code in Analytics Dashboards through a specially crafted URL. To fix this issue, users should upgrade GitLab CE/EE to versions 17.5.2, 17.4.4, and 17.3.7. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-8648.
Read more Developer ToolsIn Mattermost versions 9.10.x ≤ 9.10.2, 9.11.x ≤ 9.11.1, and 9.5.x ≤ 9.5.9 a medium severity vulnerability CVE-2024-46872 was found. This vulnerability lets attackers bypass security by manipulating user inputs, leading to CSRF attacks in Playbooks. To fix this issue, users are advised to upgrade to version 8.0.0 or above, specifically the version released after 2024-09-26. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-46872.
Read more Developer ToolsIn Sonatype Nexus Repository versions 3.0.0 through 3.72.0 a medium severity vulnerability CVE-2024-5764 was detected. This vulnerability allows attackers to exploit hard-coded encryption passphrases in the repository’s configuration database, compromising the security of stored secrets like SMTP, HTTP proxy credentials, and user tokens. Currently, there is no patch version for this vurnerability. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-5764.
Read more Developer Tools