In Argo CD a medium severity vulnerability CVE-2024-37152 was detected. This vulnerability allows unauthorized access to sensitive settings via the /api/v1/settings endpoint without authentication. All sensitive settings are hidden except passwordPattern. The vulnerability is fixed in versions 2.11.3, 2.10.12, and 2.9.17. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-37152.
Read more Developer ToolsIn Argo CD a medium severity vulnerability CVE-2024-36106 was detected. This vulnerability allows authenticated users to enumerate cluster names via error messages. It’s also possible to enumerate the names of projects with project-scoped clusters if you know the clusters names. This vulnerability is fixed in versions 2.11.3, 2.10.12, and 2.9.17. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-36106.
Read more Developer ToolsIn OpenShift a critical security vulnerability CVE-2024-5037 was detected. This vulnerability allows attackers to use a forged token to bypass the authentication. There is no fix available for this. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-5037/.
Read more Developer ToolsIn GitLab versions before 16.10.6, 16.11.3, and 17.0.1 a high severity vulnerability CVE-2024-4835 was detected. Attackers can create a harmful webpage and steal sensitive user data. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-4835/.
Read more Developer ToolsIn Openshift a medium severity vulnerability CVE-2024-0406 was detected. An issue has been identified where certain files, when unpacked from a tar file, could potentially grant unauthorized access or modify files with the user’s permission, so be cautious when extracting files from unknown sources. For more information, visit https://avd.aquasec.com/nvd/2024/cve-2024-0406/.
Read more Developer ToolsIn Kubernetes all versions before 1.20.5 and version 1.20.2-1 a low severity vulnerability CVE-2024-3177 was detected. When using Kubernetes, there is a security issue where users might bypass restrictions and access unauthorized secrets if containers, including init and ephemeral types, use the ‘envFrom’ field, despite policies meant to prevent this. For more information, visit https://avd.aquasec.com/nvd/2024/cve-2024-3177/.
Read more Developer ToolsIn Jenkins versions 2.441 and earlier a critical severity vulnerability CVE-2024-23897 was detected. Due to this bug, in LTS versions 2.426.2 and earlier, attackers gain access to any file on the Jenkins controller system by using a feature that interprets file paths preceded by the “@” character without requiring authentication. For more information, visit https://avd.aquasec.com/nvd/2024/cve-2024-23897/.
Read more Developer ToolsIn GitLab CE/EE versions 16.7.7 prior to 16.8.6, 16.9 prior to 16.9.4 and 16.10 prior to 16.10.2 a medium severity vulnerability CVE-2023-6489 was detected. Due to a bug in GitLab’s chat integration feature lets attackers overload the system, causing slowdowns and service interruptions. For more information, visit https://avd.aquasec.com/nvd/2023/cve-2023-6489/.
Read more Developer ToolsIn GitLab CE/EE all versions starting from 16.9 before 16.9.4, and from 16.10 before 16.10.2 a high severity vulnerability CVE-2024-3092 was detected. This issue allows attackers to do things on someone else’s behalf by injecting a harmful code. For more information, visit https://avd.aquasec.com/nvd/2024/cve-2024-3092/.
Read more Developer Tools