In GitLab EE versions starting from 17.3 before 17.3.7, starting from 17.4 before 17.4.4 and starting from 17.5 before 17.5.2 a medium severity vulnerability CVE-2024-10240 was detected. This vulnerability allows unauthenticated users to access details about merge requests (MR) in a private project under specific conditions. To fix this issue, users are advised to upgrade GitLab EE to versions 17.6.1, 17.5.3, or 17.4.5. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-10240.
Read more Developer ToolsIn GitLab CE/EE versions 16.11 prior to 17.4.5, 17.5 prior to 17.5.3, 17.6 prior to 17.6.1 a medium severity vulnerability CVE-2024-11668 was detected. This vulnerability allows attackers to bypass authentication and access sensitive data through long-lasting connections. To fix this issue, users should upgrade GitLab CE/EE to versions 17.4.5, 17.5.3 or 17.6.1. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-11668.
Read more Developer ToolsIn GitLab CE/EE versions 16.9.8 prior to 17.4.5, 17.5 prior to 17.5.3, 17.6 prior to 17.6.1 a medium severity vulnerability CVE-2024-11669 was detected. This vulnerability allows attackers to access sensitive data without proper authorization by exploiting certain security weaknesses in GitLab’s API. To fix this issue, users should upgrade GitLab CE/EE to versions 17.4.5, 17.5.3, or 17.6.1. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-11669.
Read more Developer ToolsIn GitLab CE/EE versions 13.2.4 prior to 17.4.5, 17.5 prior to 17.5.3, 17.6 prior to 17.6.1 a medium severity vulnerability CVE-2024-11828 was detected. This vulnerability allows attackers to create a denial of service (DoS) condition by sending crafted API calls. To fix this issue, users should upgrade GitLab CE/EE to versions 17.4.5, 17.5.3 or 17.6.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-11828.
Read more Developer ToolsIn GitLab CE/EE versions prior to 12.6, prior to 17.4.5, 17.5 prior to 17.5.3, and 17.6 prior to 17.6.1 a medium severity vulnerability CVE-2024-8237 was detected. This vulnerability allows attackers to crash the system using a fake cargo.toml file. To fix this issue, users are advised to upgrade GitLab CE/EE to versions 17.6.1, 17.5.3, or 17.4.5. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-8237.
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, and 8.3.* before 8.3.14 a medium severity vulnerability CVE-2024-11234 was detected. This vulnerability allows attackers to perform HTTP request smuggling due to improper sanitization of the URI when using streams with a proxy and the “request_fulluri” option. This could allow attackers to send arbitrary requests from the server, potentially accessing restricted resources. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-11234.
Read more Web DevelopmentIn PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, and 8.3.* before 8.3.14 a medium severity vulnerability CVE-2024-11233 was detected. This vulnerability allows attackers to exploit an error in the convert.quoted-printable-decode filter, leading to a buffer overread by one byte. In certain cases, this can cause crashes or disclose content from other memory areas. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-11233.
Read more Web DevelopmentIn Sentry version 24.11.0 a medium severity vulnerability CVE-2024-53253 was detected. A specific error message could expose a plaintext Client ID and Client Secret in the HTTP response. This issue affects self-hosted users with custom integrations. To address this issue, upgrade to the latest version or downgrade to 24.10.0. For Sentry SaaS users, no action is needed as the issue was resolved. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-53253.
Read more MonitoringIn OpenShift version 4 a medium severity vulnerability CVE-2024-6538 was detected. A Server Side Request Forgery (SSRF) attack can occur if an attacker provides a URL for the server to query. This allows the attacker to perform arbitrary HTTP requests, potentially disclosing information or impacting other services within the cluster. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-6538.
Read more Developer Tools