In Ansible versions up to 4.50.3 a medium severity vulnerability CVE-2025-53862 was detected. This vulnerability allows attackers to access three API endpoints that return verbose responses, potentially exposing sensitive information. To fix this issue, users should upgrade Ansible to version 4.52.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-53862.
Read more IT Business ManagementIn Ansible version 2.x a low severity vulnerability CVE‑2025‑53861 was detected. This vulnerability allows attackers to intercept session data or hijack user sessions by exploiting insecure cookies transmitted over unencrypted connections. To fix this issue, users should upgrade Ansible to version 4.52.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-53861.
Read more IT Business ManagementIn Apache HTTP Server versions up to 2.4.63 a medium severity vulnerability CVE-2025-49812 was detected. This vulnerability allows attackers to hijack active HTTP sessions by exploiting a misconfigured TLS upgrade path, potentially gaining unauthorized access to user data or actions. To fix this issue, users should upgrade Apache HTTP Server to version 2.4.64. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-49812.
Read more Application DevelopmentIn Flask version 3.1.0 a medium severity vulnerability CVE-2025-47278 was detected. This vulnerability allows attackers to potentially take advantage of old session keys still being used, which weakens protection for user sessions in some setups. To fix this issue, users should upgrade Flask to version 3.1.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-47278.
Read more Application DevelopmentIn GitLab EE versions from 13.3 up to 17.11.6, 18.0.4, and 18.1.2 a medium severity vulnerability CVE-2025-3396 was detected. This vulnerability allows attakers to bypass group-level forking restrictions by manipulating API requests. To fix this issue, users should upgrade GitLab EE to versions 17.11.6, 18.0.4, or 18.1.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3396.
Read more Developer ToolsIn GitLab EE versions from 18.0 up to 18.0.4 and 18.1.2 a low severity vulnerability CVE-2025-6168 was detected. This vulnerability allows attackers to bypass group-level user invitation restrictions by sending specially crafted API requests. To fix this issue, users should upgrade GitLab EE to versions 18.0.4 or 18.1.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-6168.
Read more Developer ToolsIn GitLab CE/EE versions from 17.11 up to 17.11.6, 18.0.4, and 18.1.2 a high severity vulnerability CVE-2025-6948 was detected. This vulnerability allows attackers to perform actions on behalf of other users by injecting malicious content. To fix this issue, users should upgrade GitLab to versions 17.11.6, 18.0.4, or 18.1.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-6948.
Read more Developer ToolsIn GitLab EE versions from 18.0 up to 18.0.4 and 18.1.2 a medium severity vulnerability CVE-2025-4972 was detected. This vulnerability allows attackers with invitation privileges to bypass group-level user invitation restrictions by manipulating the group invitation functionality. To fix this issue, users should upgrade GitLab EE to versions 18.0.4 or 18.1.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-4972.
Read more Developer ToolsIn MongoDB Server versions prior to 8.0.10 a medium severity vulnerability CVE-2025-6712 was detected. This vulnerability allows attackers to cause the MongoDB server to crash by triggering excessive memory usage. To fix this issue users should upgrade MongoDB to version 8.0.10. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-6712.
Read more Database