In the RediSearch module that provides querying, secondary indexing, and full-text search for Redis versions 2.6.24, 2.8.21, 2.10.10 a high severity vulnerability CVE-2024-51737 was detected. This vulnerability allows attackers to trigger a buffer overflow by using specially crafted arguments in the FT.SEARCH or FT.AGGREGATE commands, potentially leading to remote code execution. To fix this issue, users should upgrade the RediSearch module for Redis to versions 2.6.24, 2.8.21, and 2.10.10. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-51737.
In Django versions 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18 a medium severity vulnerability CVE-2024-56374 was detected. This vulnerability could cause a denial-of-service (DoS) attack due to insufficient limits on strings during IPv6 validation, affecting clean_ipv6_address, is_valid_ipv6_address and django.forms.GenericIPAddressField. To address this issue, users should upgrade Django to versions 5.1.5, 5.0.11 or 4.2.18. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-56374.
Read more Application DevelopmentIn Keycloak version 21.0.2 a medium severity vulnerability CVE-2024-11734 was detected. This vulnerability allows attackers to disrupt the Keycloak service by modifying security headers, causing requests to fail and the service to become unavailable. To fix this issue, users should upgrade Keycloak to version 26.0.8. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-11734.
In Invoice Ninja versions 5.8.56 through 5.11.23 a high severity vulnerability CVE-2025-0474 was detected. This vulnerability allows attackers to perform authenticated Server-Side Request Forgery (SSRF), enabling arbitrary file read and network resource requests as the application user. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-0474.
Read more SecurityIn Keycloak versions prior to 26.0.8 a medium severity vulnerability CVE-2024-11736 was detected. This vulnerability allows admin users to access sensitive server environment variables and system properties through URLs. By using placeholders like ${env.VARNAME} or ${PROPNAME}, the server replaces them with actual values during URL processing. To address this issue, users should upgrade Keycloak to version 26.0.8 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-11736.
Read more SecurityIn MonicaHQ version 4.1.2 a medium severity vulnerability CVE-2024-54999 was detected. This vulnerability allows attackers to exploit a Client-Side Injection via the `last_name` parameter in the General Information module. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-54999.
Read more CRMIn MonicaHQ version 4.1.1 a medium severity vulnerability CVE-2024-54997 was detected. This vulnerability allows attackers to exploit an authenticated Client-Side Injection via the `entry` text field at `/journal/entries/ID/edit`. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-54997.
Read more CRMIn GitLab CE/EE versions starting from 17.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3 and starting from 17.7 prior to 17.7.1 a medium severity vulnerability CVE-2025-0194 was detected. This vulnerability allows attackers to access tokens that may have been logged when API requests were made in a specific manner. To address this issue, users should upgrade GitLab CE/EE to versions 17.5.5, 17.6.3, or 17.7.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-0194.
Read more Developer ToolsIn GitLab CE/EE versions starting from 16.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1 a medium severity vulnerability CVE-2024-13041 was detected. This vulnerability allows attackers to bypass user access restrictions, potentially giving unauthorized users access to internal projects or groups in GitLab. To fix this issue, users should upgrade GitLab CE/EE to versions 17.5.5, 17.6.3, 17.7.1. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-13041.
Read more Developer Tools