Proactive Insights and Support For Open-Source Applications
  • Applications
  • Platform
  • Support
  • Resources
    • 2025 OSS Research
    • FAQ
    • Newsflash
    • OSSpedia
    • How-to Guides
    • Case Studies
    • Articles
  • Company
    • About Us
    • The OSS in Hossted
  • Contact
Book a demo
Book a demo
  • Applications
  • Platform
  • Support
  • Resources
    • 2025 OSS Research
    • FAQ
    • Newsflash
    • OSSpedia
    • How-to Guides
    • Case Studies
    • Articles
  • Company
    • About Us
    • The OSS in Hossted
  • Contact
  • Home
  • Knowledge Base
  • Newsflash

Our news and updates

All OSSpediaArticlesHow ToNewsflashCase Studies
Don't Miss out!
Join our newsletter for exclusive updates on open source innovations.

    Choose category
    • Communication
      • Communication
    • Communication and Collaboration
      • Utility
      • Communication and Collaboration
      • Communication
    • Specialized Software
      • Educational
      • Graphic Design
    • Business and Enterprise Solutions
      • Customer Service
      • Productivity
      • Supply Chain Management (SCM)
      • CRM
      • E-commerce
      • CMS
      • Marketing Automation
      • ERP
    • Project and Agile Management
      • Project Management
      • IT Business Management
    • Infrastructure and Network
      • CMS
      • Networking
      • Storage
      • Security
    • DevOps
      • DevOps
      • Mobile App Development
      • Backup and Recovery
      • Data Analytics
      • Web Development
      • Developer Stacks
      • Cloud Computing
      • Monitoring
      • Application Development
      • Developer Tools
    • Data Management and Analytics
      • Communication
      • Application Development
      • Analytics
      • Machine Learning
      • Database
      • Data Analytics
    10 Oct 2024 DevOps
    GitLab: Deploy Keys Push to Archived Repository Vulnerability

    In GitLab versions starting from 8.16 up to 17.2.8, versions 17.3 prior to 17.3.5, and versions 17.4 prior to 17.4.2 a medium severity vulnerability related to deploy keys CVE-2024-9623 was detected. This vulnerability allows attackers to push code to an archived repository, potentially leading to unauthorized changes or data breaches. To fix this issue, users should upgrade GitLab to versions 17.2.9, 17.3.5, or 17.4.2. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-9623.

    Read more
    Developer Tools
    9 Oct 2024 Data Management and Analytics
    Redis: Denial of Service Vulnerability via Malformed ACL Selector

    In Redis versions prior to 7.2.6 and 7.4.1 a medium severity vulnerability CVE-2024-31227 was detected. An authenticated user with sufficient privileges can create a malformed ACL selector in Redis, triggering a server panic and causing a denial of service. To fix this problem, users should upgrade to versions 7.2.6 and 7.4.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-31227.

    Read more
    Database
    9 Oct 2024 Data Management and Analytics
    Redis: Denial of Service Vulnerability via Long String Match Patterns

    In Redis versions prior to 6.2.16, 7.2.6 and 7.4.1 a medium severity vulnerability CVE-2024-31228 was detected. Authenticated users can trigger a denial-of-service in Redis by using specially crafted long string match patterns on certain commands, leading to stack overflow and a process crash. To fix this problem, users should upgrade to versions 6.2.16, 7.2.6 and 7.4.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-31228.

    Read more
    Database
    9 Oct 2024 Communication and Collaboration
    Rocket.Chat: Insufficient E2EE Password Entropy Vulnerability

    In Rocket.Chat versions prior to 4.5.1 a medium severity vulnerability CVE-2024-42027 was detected. Rocket.Chat Mobile’s E2EE password has insufficient entropy, allowing attackers to crack it with enough time and resources. To fix this problem, users should upgrade Rocket.Chat to version 4.5.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-42027.

    Read more
    Communication
    9 Oct 2024 DevOps
    Portainer: Improper Encryption Algorithm in AesEncrypt Leading to Vulnerabilities

    In Portainer versions prior to 2.20.2 a critical severity vulnerability CVE-2024-33662 was detected. Portainer uses an improper encryption algorithm in the AesEncrypt function, which could allow attackers to exploit vulnerabilities. To fix this problem, users should upgrade to version 2.20.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-33662.

    Read more
    Developer Tools
    9 Oct 2024 Data Management and Analytics
    Redis: Critical Vulnerability Allows Remote Code Execution via Lua Script

    In Redis versions prior to 6.2.16, 7.2.6 and 7.4.1 a high severity vulnerability CVE-2024-31449 was detected. An authenticated user can exploit a vulnerability in Redis by using a crafted Lua script, potentially leading to remote code execution. Users are advised to upgrade to the latest version to mitigate this risk. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-31449.

    Read more
    Database
    8 Oct 2024 Communication and Collaboration
    Discourse: JavaScript Execution Vulnerability in Disabled CSP Environments

    In Discourse versions before 2.9.0 a medium severity vulnerability CVE-2024-47772 was detected. This vulnerability allows attackers to run harmful JavaScript code in users’ browsers by sending a specially crafted chat message on Discourse sites with disabled security settings (CSP). To fix this issue, users should upgrade Discourse to version 2.9.0. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-47772.

    Read more
    Communication
    8 Oct 2024 Communication and Collaboration
    Discourse: Exposure of Hidden Tags Vulnerability

    In Discourse stable versions up to and including 3.3.1, beta versions up to and including 3.4.0.beta1, and tests-passed versions up to and including 3.4.0.beta1 a medium severity vulnerability CVE-2024-45297 was detected. This vulnerability allows attackers to view topics with a hidden tag in Discourse if they know the label or name of that tag, potentially exposing sensitive information. To fix this issue, users should upgrade Discourse to stable versions 3.3.2, beta versions 3.4.0.beta2, and tests-passed versions 3.4.0.beta2 and higher. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-45297.

    Read more
    Communication
    8 Oct 2024 Communication and Collaboration
    Discourse: Email Address Bypass Vulnerability

    In Discourse stable versions up to and including 3.3.1, beta versions up to and including 3.4.0.beta1, and tests-passed versions up to and including 3.4.0.beta1 a medium severity vulnerability CVE-2024-45051 was detected. This vulnerability allows attackers to use a maliciously crafted email address to bypass domain-based restrictions, potentially granting them unauthorized access to private sites, categories, and groups within Discourse. To fix this issue, users should upgrade Discourse to stable versions 3.3.2 and higher, beta versions 3.4.0.beta2 and higher, and tests-passed versions 3.4.0.beta2 and higher. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-45051.

    Read more
    Communication
    Proactive Insights and Support For Open-Source Applications
    Contact us: Whatsapp
    Company
    • About Hossted
    • Data Processing Addendum
    Solutions
    • Applications
    • Support Plans
    • About Solution
    Resources
    • FAQ
    • Knowledge Base

    © HOSSTED 2026 All rights reserved

    • Privacy Policy
    • Terms and Conditions
    • Cookies Policy
    Cookie Settings

    We use cookies to measure marketing efforts and improve our services. Please review the cookie settings and confirm your choice.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}