In OneDev versions prior to 11.0.9 a high severity vulnerability CVE-2024-45309 was detected. This vulnerability allows attackers to read arbitrary files accessible by the OneDev server process, even without authentication. To fix this issue, users must upgrade to version 11.0.9. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-45309.
Read more Developer ToolsIn OpenShift GraphQL introspection feature a medium severity vulnerability CVE-2024-50312 was detected. This vulnerability lets unauthorized users access introspection, exposing all available queries and mutations, which increases attack risk. To temporarily fix this, disable GraphQL introspection in OpenShift Console settings; this may limit some development tools. For more information, visit https://avd.aquasec.com/nvd/2024/cve-2024-50312.
Read more Developer ToolsIn GitLab versions from 11.2 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1 a medium severity vulnerability CVE-2024-6826 was detected. Attackers can exploit this vulnerability by importing a malicious XML file, potentially causing a denial of service (DoS). To fix this issue, users are advised to upgrade to versions 17.3.6 or above, 17.4.3 or above, 17.5.1 or above. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-6826.
Read more Developer ToolsIn GitLab CE/EE all versions from 11.2 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1 a high severity vulnerability CVE-2024-6826 was detected. This vulnerability allows attackers to cause a denial of service (DoS) by importing a maliciously crafted XML manifest file into GitLab, potentially leading to service disruption. To fix this issue, users should update GitLab to versions 17.5.1, 17.4.3, and 17.3.6. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-6826.
Read more Developer ToolsIn GitLab CE/EE versions from 15.10 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1 a high severity vulnerability CVE-2024-8312 was detected. This vulnerability allows attackers to inject HTML into the Global Search field on a diff view, leading to cross-site scripting (XSS) attacks. To fix this issue, users should update GitLab to versions 17.5.1, 17.4.3, and 17.3.6. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-8312.
Read more Developer ToolsIn OpenShift version 4 a medium severity vulnerability CVE-2024-50311 was detected. This vulnerability allows attackers to exploit the GraphQL batching functionality. The flaw arises when multiple queries can be sent within a single request, enabling an attacker to submit a request containing thousands of aliases in one query. This issue causes excessive resource consumption, leading to application unavailability for legitimate users. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-50311.
Read more Developer ToolsIn Rancher versions >= 2.6.0, < 2.6.14, >= 2.7.0, < 2.7.10, >= 2.8.0, < 2.8.2 a high severity vulnerability CVE-2023-32194 was detected. This vulnerability allows users with a create or * global role for “namespaces” to access, create, update, or delete core namespaces, potentially compromising project security. To fix this problem, users should upgrade to the versions 2.6.14, 2.7.10, 2.8.2 or higher. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2023-32194.
Read more Developer ToolsIn Rancher version < 0.0.0-20240207153957-4fd7d821d952 a high severity vulnerability CVE-2023-32192 was detected. This vulnerability allows attackers to exploit unauthenticated cross-site scripting (XSS) in the public API, enabling them to execute arbitrary JavaScript code in a victim’s browser. To fix this problem, users should upgrade to the version 0.0.0-20240207153957-4fd7d821d952. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2023-32192.
Read more Developer ToolsIn Rancher versions 2.7.0 and prior, 2.8.0 and prior a medium severity vulnerability CVE-2024-21218 was detected. This vulnerability allows RKE1 clusters to repeatedly reconcile when secret encryption is enabled, exposing Kube API secret values in plaintext on the AppliedSpec. Cluster owners, members, and project members can access this data through the apiserver. To fix this issue, users are advised to upgrade to versions 2.7.14 and 2.8.5. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-22032.
Read more Developer Tools