In GitLab CE/EE versions from 17.3 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2 a medium severity vulnerability CVE-2024-8179 was detected. This vulnerability allows attackers to perform cross-site scripting (XSS) attacks if Content Security Policy (CSP) is not enabled. To address this issue, users should upgrade GitLab CE/EE to versions 17.4.6, 17.5.4, or 17.6.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-8179.
Read more Developer ToolsIn iTop versions before 2.7.11, from including 3.0.0-alpha and before 3.1.2, and from including 3.2.0-alpha1 and before 3.2.0 a high severity vulnerability CVE-2024-54139 was detected. This vulnerability allows attackers to perform cross-site scripting, which can lead to cross-site request forgery via the `_table_id` parameter. To address this issue, users should upgrade iTop to versions 2.7.11, 3.1.2, or 3.2.0. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-54139.
Read more IT Business ManagementIn GitLab CE/EE versions from 15.0 and before 17.4.6, from including 17.5 and before 17.5.4, and from including 17.6 and before 17.6.2 a medium severity vulnerability CVE-2024-8650 was detected. This vulnerability allows non-member users to view unresolved threads marked as internal notes in public projects’ merge requests. To address this issue, update GitLab CE/EE to versions 17.4.6, 17.5.4, or 17.6.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-8650.
Read more Developer ToolsIn GitLab CE/EE versions from 16.9 and before 17.4.6, from including 17.5 and before 17.5.4, and from including 17.6 and before 17.6.2 a medium severity vulnerability CVE-2024-8116 was detected. This vulnerability allows an unauthorized user, under specific conditions, to retrieve branch names by using a specific GraphQL query. To address this issue, update GitLab CE/EE to versions 17.4.6, 17.5.4, or 17.6.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-8116.
Read more Developer ToolsIn GitLab EE versions starting from 14.3 before 17.4.6, from 17.5 before 17.5.4, from 17.6 before 17.6.2 a low severity vulnerability CVE-2024-10043 was detected. This vulnerability allows attackers to access confidential incident titles through the Wiki History Diff feature, potentially exposing sensitive information. To address this issue, users should upgrade GitLab EE to versions 17.4.6, 17.5.4, or 17.6.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-10043.
Read more Developer ToolsIn GitLab CE/EE versions from 11.8 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2 a medium severity vulnerability CVE-2024-9387 was detected. This vulnerability allows attackers to perform an open redirect via a specific releases API endpoint. To address this issue, users should upgrade GitLab CE/EE to versions 17.4.6, 17.5.4, or 17.6.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-9387.
Read more Developer ToolsIn Opt-In Downloads plugin for WordPress versions up to 4.07 a high severity vulnerability CVE-2024-10590 was detected. This vulnerability allows authenticated users with Subscriber-level access or higher to upload arbitrary files, potentially leading to remote code execution (RCE) on NGINX servers. To address this issue, users must upgrade to a version later than 4.07. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-10590.
Read more CMSIn Cognito Forms plugin for WordPress versions up to 2.0.6 a medium severity vulnerability CVE-2024-10182 was detected. This vulnerability allows authenticated users with Contributor-level access or higher to inject arbitrary web scripts into pages, which execute whenever a user accesses an affected page. To address this issue, users must upgrade to a version later than 2.0.6. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-10182.
Read more CMSIn HQ Rental Software plugin for WordPress versions up to 1.5.29 a high severity vulnerability CVE-2024-11689 was detected. This vulnerability allows unauthenticated attackers to update arbitrary options, potentially leading to privilege escalation, by tricking a site administrator into performing an action such as clicking on a link. To address this issue, users must upgrade to a version later than 1.5.29. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-11689.
Read more CMS