In Gitlab versions 17.0 to 17.1.2 a low severity vulnerability CVE-2024-5470 was detected. This vulnerability allows attackers to create project-level deploy tokens as guest users. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-5470/.
Read more Developer ToolsIn GitLab CE/EE versions 17.0 to 17.0.3 and 17.1 to 17.1.1 a medium severity vulnerability CVE-2024-5257 was detected. A developer with the admin_compliance_framework role could change the URL for a group namespace. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-5257.
In GitLab CE/EE, all versions starting from 16.5 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 a low severity vulnerability CVE-2024-2880 was detected. This vulnerability allows a user with admin_group_member custom role permission to ban group members. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-2880/.
In NetworkManager for Red Hat OpenShift Container Platform 4 a low severity vulnerability CVE-2024-6501 was detected. If a system has DEBUG logs on and an interface called eth1 with LLDP enabled, a hacker could send a bad LLDP packet, causing NetworkManager to crash and resulting in a denial of service. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-6501/.
Read more Developer ToolsIn Gitlab versions from 11.8 to 17.1.2 a low severity vulnerability CVE-2024-6595 was detected. This vulnerability allows attackers to upload an NPM package. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-6595/.
Read more Developer ToolsIn OpenSSH’s server (sshd) versions 4.13, 4.14, 4.15, and 4.16 a high severity vulnerability CVE-2024-6409 was detected. If a remote attacker doesn’t authenticate within a specific time frame, sshd’s signal handler can be triggered asynchronously. This handler calls non-async-signal-safe functions like syslog(), potentially allowing a successful attacker to execute remote code on the sshd server with unprivileged user privileges. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-6409.
In GitLab versions from 15.8 through 16.11.6, from 17.0 through 17.0.4 and from 17.1 through 17.1.2 a high severity vulnerability CVE-2024-6385 was detected. This vulnerability allows attackers to trigger a pipeline as another user under certain circumstances. To fix this problem, users should upgrade GitLab to one of the following versions 16.11.6, 17.0.4, or 17.1.2. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-6385.
Read more Developer ToolsIn GitLab versions from 16.3 through 16.11.5, from 17.0 through 17.0.3, and from 17.1 through 17.1.1 a medium severity vulnerability CVE-2024-2177 was detected. This vulnerability allows attackers to trick the login system by using a specially designed message. To fix this problem, users should upgrade GitLab to one of the following versions: 16.11.5, 17.0.3, or 17.1.1. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-2177.
Read more Developer ToolsIn Gogs version 0.13.0 a high severity vulnerability CVE-2024-39933 was detected. This vulnerability allows attackers to access the code in a new release. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39933/.
Read more Developer Tools