In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, and 8.3.* before 8.3.14 a critical severity vulnerability CVE-2024-8932 was detected. This vulnerability allows attackers to cause an integer overflow through uncontrolled long string inputs to the ldap_escape() function on 32-bit systems, leading to an out-of-bounds write. To address this issue, users must upgrade to PHP versions 8.1.31, 8.2.26 or 8.3.14. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-8932.
Read more Web DevelopmentIn PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, and 8.3.* before 8.3.14 a medium severity vulnerability CVE-2024-8929 was detected. This vulnerability allows attackers to exploit a malicious MySQL server to force the PHP client to reveal sensitive data from its memory, including information from other users. To address this issue, users must upgrade to PHP versions 8.1.31 or later, 8.2.26, or 8.3.14. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-8929.
Read more Web DevelopmentIn HAProxy versions 2.2.9-2 and 2.6.12-1 a medium severity vulnerability CVE-2024-53008 was detected. This vulnerability allows attackers to bypass ACL (Access Control List) restrictions, potentially accessing sensitive information. To address this issue, users must upgrade to 2.9.12-1 version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-53008.
Read more Application DevelopmentIn Keycloak versions up to 26.0.2 a medium severity vulnerability CVE-2024-10451 was detected. This vulnerability allows attackers to capture sensitive runtime values, such as passwords, which may be embedded in bytecode during the build process. To address this issue, users must upgrade to Keycloak versions 26.0.6 or 26.0.9. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-10451.
Read more SecurityIn Keycloak versions prior to 24.0.9, prior to 26.0.6 and 25.0.0 and prior a medium severity vulnerability CVE-2024-9666 was detected. This vulnerability allows attackers to exploit improper handling of proxy headers, leading to costly DNS resolution operations and potential denial of service (DoS). To address this issue, users must upgrade to Keycloak versions 26.0.6 or 24.0.9. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-9666.
Read more SecurityIn Keycloak versions up to 26.0.6 a low severity vulnerability CVE-2024-10492 was detected. This vulnerability allows attackers with high privileges to confirm the existence of sensitive Vault files by creating resources like an LDAP provider configuration and a Vault read file. To address this issue users must upgrade to Keycloak versions 26.0.6 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-10492.
Read more SecurityIn GitLab CE/EE versions from 8.12 before 17.4.5, 17.5 before 17.5.3 and 17.6 before 17.6.1 a high severity vulnerability CVE-2024-8114 was detected. This vulnerability allows an attacker with access to a victim’s Personal Access Token (PAT) to escalate privileges. To address this issue, users must upgrade to GitLab CE/EE versions 17.4.5, 17.5.3, or 17.6.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-8114.
Read more Developer ToolsIn GitLab CE/EE versions starting from 15.6 prior to 17.4.5, starting from 17.5 prior to 17.5.3, and starting from 17.6 prior to 17.6.1 a medium severity vulnerability CVE-2024-8177 was detected. This vulnerability allows attackers to cause a Denial of Service by integrating a malicious Harbor registry. To address this issue, users must upgrade to GitLab CE/EE versions 17.4.5, 17.5.3, or 17.6.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-8177.
Read more Developer ToolsIn Keycloak versions up to 26.0.6 a high severity vulnerability CVE-2024-10270 was detected. This vulnerability allows attackers to trigger a denial of service (DoS) by exhausting system resources due to Regex complexity if untrusted data is passed to the SearchQueryUtils method. To address this issue, users must upgrade to Keycloak versions 26.0.6 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-10270.
Read more Security