In Django CMS versions before 4.0 a medium severity vulnerability CVE-2024-11406 was detected. This vulnerability allows Stored Cross-Site Scripting (XSS) through improper neutralization of input in Django CMS Attributes Fields. To address this issue, update to Django CMS version 4.0 or later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-11406.
Read more Application DevelopmentIn Authentik versions prior to 2024.8.5 a medium severity vulnerability CVE-2024-52287 was detected. This vulnerability allows attackers to obtain OAuth tokens with unauthorized scopes using client_credentials or device_code grants. These tokens could be used to perform malicious actions in trusted systems. To fix this issue, users need to update to versions 2024.8.5 or 2024.10.3. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-52287.
Read more SecurityIn Dolibarr versions prior to 15.0.0 a medium severity vulnerability CVE-2021-3991 was found. This vulnerability lets attackers view sensitive reception details by accessing specific URLs without proper permissions. To fix this issue, users are advised to upgrade to version 15.0.0 or above. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2021-3991.
Read more ERPIn Harbor versions from and including 2.x up to and including 2.4.2, from and including 2.5 up to and including 2.5.1, from and including 2.0.0 before 2.4.3, and from and including 2.5.0 before 2.5.2 a medium severity vulnerability CVE-2022-31667 was found. This vulnerability lets attackers revoke robot account permissions in projects they can’t access by sending a crafted request. To fix this issue, users are advised to upgrade to versions 2.5.2 and later. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2022-31667.
Read more Developer ToolsIn Gogs versions 0.12.7 and prior a critical severity vulnerability CVE-2022-1884 was found. This vulnerability allows attackers to execute arbitrary commands on the server by uploading a malicious config file. It affects all Windows installations with repository uploads enabled, risking unauthorized access and system compromise. To fix this issue, users are advised to upgrade to version 0.12.8 or the latest 0.13.0+dev. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2022-1884.
Read more Developer ToolsIn Harbor versions before 2.5.2 a high severity vulnerability CVE-2022-31669 was detected. This vulnerability allows attackers to modify tag immutability policies in other projects by sending requests with an ID that belongs to a project the currently authenticated user doesn’t have access to. To fix this issue, users must upgrade to Harbor version 2.5.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2022-31669.
Read more Developer ToolsIn Harbor versions prior to 2.7.0 a high severity vulnerability CVE-2022-31668 was detected. This vulnerability allows attackers to modify P2P preheat policies in projects they don’t have permission to access. To fix this issue, users should upgrade Harbor to version 2.7.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2022-31668.
Read more Developer ToolsIn Apache Airflow versions prior to 2.10.3 a medium severity vulnerability CVE-2024-50378 was detected. This vulnerability allows authenticated users with audit log access to view sensitive variable values, potentially leading to unauthorized access. To fix this problem, users should upgrade to version 2.10.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-50378.
In Moodle versions starting from 0 before 4.1.0, from 4.1.0 before 4.1.14, from 4.2.0 before 4.2.11, from 4.3.0 before 4.3.8, and from 4.4.0 before 4.4.4 a medium severity vulnerability CVE-2024-48901 was detected. This vulnerability allows attackers to access and view the schedule of a report in Moodle without having the necessary permissions to edit it. To fix this issue, users should upgrade Moodle to versions 4.5.0-rc2 or higher. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-48901.
Read more Educational