In Rancher versions 2.7.0 to 2.7.14, 2.8.0 to 2.8.7, and 2.9.0 to 2.9.1 a high severity vulnerability CVE-2024-22030 was detected. This vulnerability allows attackers to exploit a man-in-the-middle attack by controlling an expired domain or performing DNS spoofing/hijacking against the Rancher URL. To fix this issue, users must upgrade to versions 2.7.15, 2.8.8, or 2.9.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-22030.
Read more Developer ToolsIn Rancher versions 2.7.0 to 2.7.13 and 2.8.0 to 2.8.4 a high severity vulnerability CVE-2023-32196 was detected. This vulnerability allows attackers to escalate privileges due to improper enforcement of privilege escalation checks for RoleTemplate objects when external=true. To fix this issue, users must upgrade to versions 2.7.14 or 2.8.5. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2023-32196.
Read more Developer ToolsIn GitLab EE versions 12.5 prior to 17.2.9, 17.3 prior to 17.3.5, and 17.4 prior to 17.4.2 a critical severity vulnerability CVE-2024-9164 was detected. This vulnerability allows attackers to run pipelines on arbitrary branches. To fix this issue, users must upgrade to versions 17.2.9, 17.3.5, or 17.4.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-9164.
Read more Developer ToolsIn GitLab CE/EE versions 11.6 prior to 17.2.9, 17.3 prior to 17.3.5, and 17.4 prior to 17.4.2 a high severity vulnerability CVE-2024-8970 was detected. This vulnerability allows attackers to trigger a pipeline as another user under certain circumstances. To fix this issue, users must upgrade to versions 17.2.9, 17.3.5, or 17.4.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-8970.
Read more Developer ToolsIn GitLab CE/EE versions 11.4 prior to 17.2.9, 17.3 prior to 17.3.5, and 17.4 prior to 17.4.2 a medium severity vulnerability CVE-2024-5005 was detected. This vulnerability allows guest users to disclose project templates using the API. To fix this issue, users must upgrade to versions 17.2.9, 17.3.5, or 17.4.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-5005.
Read more Developer ToolsIn GitLab versions starting from 15.10 before 17.2.9, from 17.3 before 17.3.5, and from 17.4 before 17.4.2 a high severity vulnerability CVE-2024-8977 was detected. This vulnerability could allow attackers to exploit the Product Analytics Dashboard, leading to Server-Side Request Forgery attacks. To fix this issue, upgrading to GitLab version 17.2.9, 17.3.5, or 17.4.2 is recommended. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-8977.
Read more Developer ToolsIn GitLab versions starting from 16.6 before 17.2.9, from 17.3 before 17.3.5, and from 17.4 before 17.4.2 a low severity vulnerability CVE-2024-9596 was discovered. This vulnerability allows an unauthenticated attacker to determine the GitLab version number of a GitLab instance. To mitigate this issue, upgrading to GitLab version 17.2.9, 17.3.5, or 17.4.2 is recommended. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-9596.
Read more Developer ToolsIn GitLab CE/EE versions 8.16 to 17.2.8, 17.3.0 to 17.3.4, and 17.4.0 to 17.4.1 a medium severity vulnerability CVE-2024-9623 was detected. This vulnerability allows attackers to use deploy keys to push to an archived repository. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-9623.
Read more Developer ToolsIn SonarQube versions before 9.9.5 LTA and 10.x before 10.5 a high severity vulnerability CVE-2024-47910 was detected. A SonarQube user with Administrator privileges can modify a GitHub integration configuration to exfiltrate a pre-signed JWT, posing a security risk. To fix this problem, users should upgrade to version 9.9.5 LTA or later and 10.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-47910.
Read more Developer Tools