In GitLab CE/EE all versions starting from 16.1 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1 a low severity vulnerability CVE-2024-4011 was detected. This vulnerability allows non-project member to promote key results to objectives. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-4011.
Read more Developer ToolsIn GitLab CE/EE all versions starting from 1.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1 multiple Denial of Service (DoS) vulnerabilities CVE-2024-4557 of medium severity were detected. They allow an attacker to cause resource exhaustion via banzai pipeline. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-4557.
Read more Developer ToolsIn GitLab versions 16.11 to 17.1.1 a high severity vulnerability CVE-2024-6323 was detected. This vulnerability allows attackers to leak the content of a private repository in a public project. There is no fix to this yet. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-6323/.
Read more Developer ToolsIn GitLab CE/EE versions from 15.8 onwards a critical security vulnerability CVE-2024-5655 was detected. Attackers can trigger a pipeline as another user under certain circumstances. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-5655.
Read more Developer ToolsIn GitLab CE/EE, all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, a medium severity vulnerability CVE-2024-5430 was detected. This issue allows a project maintainer to delete the merge request approval policy via GraphQL. There is no fix for this yet. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-5430.
Read more Developer ToolsIn OpenShift Container Platform 3.11, which uses CRI-O to manage containers, a high severity vulnerability CVE-2024-5154 was detected. Attackers can gain access to sensitive information which should not be accessible from the container. This could include configuration files, security keys, and other confidential data. To fix this problem, users should upgrade OpenShift Container Platform to version 4.15.17. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-5154.
Read more Developer ToolsIn Harbor versions 2.8.x before 2.8.4, 2.9.x before 2.9.2, and 2.10.x before 2.10.0, a medium severity vulnerability CVE-2024-22244 was detected. This vulnerability allows attackers to redirect users to malicious websites. To fix this problem, users should upgrade Harbor to versions 2.8.5, 2.9.3, or 2.10.1. For more details, visit Aqua Security’s advisory.
Read more Developer ToolsIn SonarQube versions before 10.4 and 9.9.4 LTA (Long-Term Support) a medium severity vulnerability CVE-2024-38460 was detected. This vulnerability allows attackers to exploit encrypted values exposed in plaintext within URL parameters found in logs such as SonarQube Access Logs and Proxy Logs. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-38460.
Read more Developer ToolsIn GitLab CE/EE all versions prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2 a medium severity vulnerability CVE-2024-1736 was detected. The vulnerability in GitLab’s CI/CD (Continuous Integration/Continuous Delivery) pipeline editor can potentially lead to denial of service attacks via specially crafted configuration files. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-1736.
Read more Developer Tools