In NGINX versions prior to 2.0.0-beta.36 a medium severity vulnerability CVE-2024-49367 was found. This vulnerability in Nginx UI allows attackers to control the log path and, with directory traversal, access sensitive files on the server, posing a serious security risk. To address this issue, upgrade to version 2.0.0-beta.36. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-49367.
Read more Application DevelopmentIn Liferay Portal versions 7.3.2 to 7.4.3.111 and Liferay DXP versions 2023.Q4.0 to 2023.Q4.5, 2023.Q3.1 to 2023.Q3.8, 7.4 GA to update 92, and 7.3 GA to update 36 a critical vulnerability CVE-2024-38002 was detected. This vulnerability allows attackers to modify workflow definitions and execute arbitrary code (RCE) by exploiting missing permission checks in the workflow component via the headless API. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-38002.
Read more CMSIn OpenShift version 4 a medium severity vulnerability CVE-2024-50311 was detected. This vulnerability allows attackers to exploit the GraphQL batching functionality. The flaw arises when multiple queries can be sent within a single request, enabling an attacker to submit a request containing thousands of aliases in one query. This issue causes excessive resource consumption, leading to application unavailability for legitimate users. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-50311.
Read more Developer ToolsIn Nginx UI versions 2.0.0-beta.35 and earlier a high severity vulnerability CVE-2024-49366 was detected. This vulnerability allows attackers to exploit unverified JSON input to write arbitrary files to the server, potentially resulting in a loss of permissions. To fix this issue, users must upgrade to version 2.0.0-beta.26. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-49366.
Read more Application DevelopmentIn Liferay Portal versions 7.3.2 through 7.4.3.107 and Liferay DXP versions from 2023.Q4.0 through 2023.Q4.2 and 2023.Q3.1 through 2023.Q3.5 a high severity vulnerability CVE-2024-26272 was detected. This vulnerability allows attackers to take control of the system, change passwords, shut it down, and run harmful commands remotely. To fix this issue, users should upgrade the Liferay Portal to version 7.4.3.108, Liferay DXP to versions 2024.Q1.1, 2023.Q4.3, 2023.Q3.6, 7.3 Update 36. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-26272.
Read more CMSIn Rancher versions >= 2.6.0, < 2.6.14, >= 2.7.0, < 2.7.10, >= 2.8.0, < 2.8.2 a high severity vulnerability CVE-2023-32194 was detected. This vulnerability allows users with a create or * global role for “namespaces” to access, create, update, or delete core namespaces, potentially compromising project security. To fix this problem, users should upgrade to the versions 2.6.14, 2.7.10, 2.8.2 or higher. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2023-32194.
Read more Developer ToolsIn Rancher version < 0.0.0-20240207153957-4fd7d821d952 a high severity vulnerability CVE-2023-32192 was detected. This vulnerability allows attackers to exploit unauthenticated cross-site scripting (XSS) in the public API, enabling them to execute arbitrary JavaScript code in a victim’s browser. To fix this problem, users should upgrade to the version 0.0.0-20240207153957-4fd7d821d952. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2023-32192.
Read more Developer ToolsIn MongoDB Server versions 6.0 (prior to 6.0.17), 7.0 (prior to 7.0.13), and 7.3 (prior to 7.3.4) a medium severity vulnerability CVE-2024-8305 was detected. This vulnerability allows attackers to trigger crashes in secondary nodes by incorrectly enforcing index constraints. In extreme cases, multiple secondaries may crash, potentially leaving no primaries available. To address this issue, update to the latest fixed versions: 6.0.17, 7.0.13, or 7.3.4. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-8305.
Read more DatabaseIn VMware HCX (Hybrid Cloud Extension) versions 4.8.0 – 4.8.2 and 4.9.0 – 4.9.1 a high severity vulnerability CVE-2024-38814 was detected. This vulnerability allows authenticated attackers with non-administrator privileges to execute specially crafted SQL queries, potentially leading to unauthorized remote code execution on the HCX Manager. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-38814.
Read more Cloud Computing