Proactive Insights and Support For Open-Source Applications
  • Applications
  • Platform
  • Support
  • Resources
    • 2025 OSS Research
    • FAQ
    • Newsflash
    • OSSpedia
    • How-to Guides
    • Case Studies
    • Articles
  • Company
    • About Us
    • The OSS in Hossted
  • Contact
Book a demo
Book a demo
  • Applications
  • Platform
  • Support
  • Resources
    • 2025 OSS Research
    • FAQ
    • Newsflash
    • OSSpedia
    • How-to Guides
    • Case Studies
    • Articles
  • Company
    • About Us
    • The OSS in Hossted
  • Contact
  • Home
  • Knowledge Base
  • Newsflash

Our news and updates

All OSSpediaArticlesHow ToNewsflashCase Studies
Don't Miss out!
Join our newsletter for exclusive updates on open source innovations.

    Choose category
    • Communication
      • Communication
    • Communication and Collaboration
      • Utility
      • Communication and Collaboration
      • Communication
    • Specialized Software
      • Educational
      • Graphic Design
    • Business and Enterprise Solutions
      • Customer Service
      • Productivity
      • Supply Chain Management (SCM)
      • CRM
      • E-commerce
      • CMS
      • Marketing Automation
      • ERP
    • Project and Agile Management
      • Project Management
      • IT Business Management
    • Infrastructure and Network
      • CMS
      • Networking
      • Storage
      • Security
    • DevOps
      • DevOps
      • Mobile App Development
      • Backup and Recovery
      • Data Analytics
      • Web Development
      • Developer Stacks
      • Cloud Computing
      • Monitoring
      • Application Development
      • Developer Tools
    • Data Management and Analytics
      • Communication
      • Application Development
      • Analytics
      • Machine Learning
      • Database
      • Data Analytics
    15 Nov 2024 DevOps
    GitLab: Domain Name Collision Risk

    In GitLab CE/EE versions starting from 16.3 before 17.3.7, from 17.4 before 17.4.4, and from 17.5 before 17.5.2 a low severity vulnerability CVE-2024-9633 was detected. This vulnerability allows attackers to create a group with a name matching an existing unique Pages domain, potentially leading to domain confusion attacks. Currently, there is no fixed version available for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-9633.

    Read more
    Developer Tools
    15 Nov 2024 DevOps
    GitLab: JavaScript Injection Risk in Analytics Dashboards

    In GitLab CE/EE versions starting from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2 a medium severity vulnerability CVE-2024-8648 was detected. This vulnerability allows attackers to inject malicious JavaScript code in Analytics Dashboards through a specially crafted URL. To fix this issue, users should upgrade GitLab CE/EE to versions 17.5.2, 17.4.4, and 17.3.7. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-8648.

    Read more
    Developer Tools
    15 Nov 2024 DevOps
    GitLab: Device OAuth Flow API Access Vulnerability

    In GitLab CE/EE versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4, and starting from 17.5 prior to 17.5.2 a medium severity vulnerability CVE-2024-7404 was detected. This vulnerability allows attackers to gain full API access as the victim via the Device OAuth flow. To fix this issue, users should upgrade GitLab CE/EE to versions 17.5.2, 17.4.4, and 17.3.7. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-7404.

    Read more
    Developer Tools
    15 Nov 2024 Data Management and Analytics
    Grafana: Medium Severity Vulnerability in Cloud Migration Assistant

    In Grafana OSS and Grafana Enterprise version 11.2.0 a medium severity vulnerability CVE-2024-9476 was detected. This vulnerability allows users to access other organization’s resources via the Cloud Migration Assistant. It affects instances using the Organizations feature for resource isolation. To address this issue, users are advised to upgrade to versions 11.2.3+security-01 or 11.3.0+security-01. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-9476.

    Read more
    Data Analytics
    15 Nov 2024 DevOps
    Harbor: Unauthorized Access to Job Execution Logs

    In Harbor versions 1.0.0 and above, 1.10.12 and prior, 2.0.0 and above, 2.4.2 and prior, 2.5.0 and above, 2.5.1 and prior a high severity vulnerability CVE-2022-31671 was detected. This vulnerability allows malicious authenticated users to access or modify job execution logs in Harbor by sending requests with different job IDs, exposing all logs stored in the Harbor database due to improper permission validation. To fix this issue, users need to update Harbor to version 2.5.2 or above. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2022-31671.

    Read more
    Developer Tools
    14 Nov 2024 Project and Agile Management
    Ansible: Risk of Code Execution Due to Unsafe Content Protection

    In Ansible versions 2, including Ansible-Core a medium severity vulnerability CVE-2024-11079 was found. This issue allows attackers to bypass protections and execute unsafe content using the hostvars object. If playbooks improperly handle remote data or module outputs, it could lead to arbitrary code execution. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-11079.

    Read more
    IT Business Management
    14 Nov 2024 Project and Agile Management
    iTop: Cross-Site Request Forgery Vulnerability

    In iTop versions before 3.2.0 a high severity Cross-Site Request Forgery (CSRF) vulnerability CVE-2024-52002 was detected. This vulnerability allows attackers to exploit certain URL endpoints to carry out unauthorized actions. To address this issue, users are advised to upgrade to version 3.2.0. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-52002.

    Read more
    IT Business Management
    14 Nov 2024 Project and Agile Management
    iTop: Unauthorized Service Access Issue

    In iTop versions before 3.2.0 a medium severity vulnerability CVE-2024-52001 was detected. It allows portal users to access restricted service information. This issue has been addressed in version 3.2.0, and all users are advised to upgrade. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-52001.

    Read more
    IT Business Management
    14 Nov 2024 Project and Agile Management
    iTop: Reflected XSS Security Issue in Versions Before 3.2.0

    In iTop versions before 3.2.0 a high severity vulnerability CVE-2024-52000 was detected. It allows attackers to run malicious JavaScript by modifying request payloads. This issue is fixed in version 3.2.0 through improved error message handling. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-52000.

    Read more
    IT Business Management
    Proactive Insights and Support For Open-Source Applications
    Contact us: Whatsapp
    Company
    • About Hossted
    • Data Processing Addendum
    Solutions
    • Applications
    • Support Plans
    • About Solution
    Resources
    • FAQ
    • Knowledge Base

    © HOSSTED 2026 All rights reserved

    • Privacy Policy
    • Terms and Conditions
    • Cookies Policy
    Cookie Settings

    We use cookies to measure marketing efforts and improve our services. Please review the cookie settings and confirm your choice.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}