In Rancher versions >= 2.6.0, < 2.6.14, >= 2.7.0, < 2.7.10, >= 2.8.0, < 2.8.2 a high severity vulnerability CVE-2023-32194 was detected. This vulnerability allows users with a create or * global role for “namespaces” to access, create, update, or delete core namespaces, potentially compromising project security. To fix this problem, users should upgrade to the versions 2.6.14, 2.7.10, 2.8.2 or higher. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2023-32194.
Read more Developer ToolsIn Rancher versions >= 2.6.0, < 2.6.14, >= 2.7.0, < 2.7.10, >= 2.8.0, < 2.8.2 a high severity vulnerability CVE-2023-22649 was detected. This vulnerability may expose sensitive data in Rancher’s audit logs if audit logging is enabled and the audit level is set to 1 or above. To fix this problem, users should upgrade to the latest version 2.6.14, 2.7.10 and 2.8.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2023-22649.
Read more Data AnalyticsIn WordPress versions before 6.0.2 a medium severity vulnerability CVE-2024-4973 was detected. This vulnerability allows attackers to insert malicious code into posts or pages, which runs when someone views them, potentially compromising the site’s security. To fix this issue, users should upgrade WordPress to version 6.0.2. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-4973.
Read more CMSIn WordPress versions up to and including 2.0.6 a high severity vulnerability CVE-2024-4443 was detected. This vulnerability allows attackers to create malicious files on the site, potentially giving them control over the website. To fix this issue, users should upgrade WordPress to version 6.0.2. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-4443.
Read more CMSIn WordPress versions 1.8.0 and prior a high severity vulnerability CVE-2024-47304 was found. SQL Injection allows attackers to access sensitive data without authorization, posing a serious risk to confidentiality. Although the potential for data alteration or service disruption is low, the exposure of information could still compromise the security of the system. To fix this issue, users are advised to upgrade to version 1.8.1 or higher. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-47304.
Read more CMSIn Python versions prior to 0.22.4 a medium severity vulnerability CVE-2024-9979 was found. This vulnerability can cause crashes or data errors by accessing freed memory incorrectly. To fix this issue, users are advised to upgrade to version 0.22.4 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-9979.
Read more Application DevelopmentIn Grafana version 11.0.0 and prior a critical severity vulnerability CVE-2024-9264 was detected. The SQL Expressions feature in Grafana allows poorly sanitized duckdb queries with user input, leading to command injection and local file inclusion. Users with VIEWER or higher permissions can exploit this if the duckdb binary is in Grafana’s $PATH. To fix this issue, users need to update to versions 11.0.5, 11.1.6, 11.2.1, 11.0.6, 11.1.7, or 11.2.2. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-9264.
In Rancher versions 2.7.0 and prior, 2.8.0 and prior a medium severity vulnerability CVE-2024-21218 was detected. This vulnerability allows RKE1 clusters to repeatedly reconcile when secret encryption is enabled, exposing Kube API secret values in plaintext on the AppliedSpec. Cluster owners, members, and project members can access this data through the apiserver. To fix this issue, users are advised to upgrade to versions 2.7.14 and 2.8.5. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-22032.
Read more Developer ToolsIn Rancher versions >=2.7.0, < 2.7.14, >=2.8.0, <2.8.5 a high severity vulnerability CVE-2023-22650 was detected. This vulnerability allows deleted, disabled, or revoked users from an authentication provider to retain access in Rancher, leaving their tokens still usable. To fix this problem, users should upgrade to the latest version 2.7.14 and 2.8.5. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2023-22650.
Read more Data Analytics