In Zulip versions 8.0 to 8.3 a high severity vulnerability CVE-2024-36612 was detected. This vulnerability allows attackers to exploit a memory leak in the handling of popovers. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-36612.
Read more CommunicationIn Zabbix versions 6.0.0 up to 6.0.31, 6.4.0 up to 6.4.16 and 7.0.0 to 7.0.1 a critical severity vulnerability CVE-2024-42327 was detected. This vulnerability allows attackers with API access, even with non-admin accounts, to exploit an SQL injection in the `CUser` class via the `addRelatedObjects` function. To address this issue, users should upgrade Zabbix to versions 6.0.32rc1, 6.4.17rc1 or 7.0.2rc1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-42327.
Read more MonitoringIn Zabbix versions 6.0.0 to 6.0.34, 6.4.0 to 6.4.19, and 7.0.0 to 7.0.4 a low severity vulnerability CVE-2024-42332 was detected. This vulnerability lets attackers send an SNMP (Simple Network Management Protocol) trap with extra data, showing fake information in the Zabbix UI. The attack works if SNMP authentication is off or if the attacker knows the community/authentication details. An SNMP item must also be set as text on the target host. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-42332.
Read more MonitoringIn Zowe API Mediation Layer versions 1.0.0 to 1.28.8 and 2.0.0 to 2.18.0 a medium severity vulnerability CVE-2024-9798 was detected. This vulnerability allows attackers to access a public health endpoint, revealing a list of all services, which is potentially valuable information for attackers. To fix this isse, users must upgrade to Zowe versions 2.18.0 or higher. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-9798.
Read more Developer ToolsIn OpenShift versions prior to 1.29.11, starting from 1.30.0 up to 1.30.8, starting from 1.31.0 up to 1.31.3 a high severity vulnerability CVE-2024-8676 was detected. This vulnerability allows attackers with access to the kubelet or CRI-O socket to exploit pod restoration and bypass mount access validations. To fix this issues, users must upgrade to to versions 1.29.11, 1.30.8, 1.31.3 or above. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-8676.
Read more Developer ToolsIn OpenShift versions 4.12 to 4.17 a medium severity vulnerability CVE-2024-9676 was found in Podman, Buildah, and CRI-O. This flaw can lead to a denial of service (OOM kill) when using a malicious image with an auto-assigned user namespace. The vulnerability occurs because the containers/storage library doesn’t properly handle symlink files, allowing access to files on the host. To address this issue, users should upgrade to version 4.9.5-150400.4.35.1 or higher. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-9676.
In Traefik versions prior to 2.11.14, prior to 3.0.0 and prior to 3.2.1 a medium severity vulnerability CVE-2024-52003 was detected. This vulnerability allows attackers to provide the X-Forwarded-Prefix header from an untrusted source, leading to potential issues. To address this issue, users must upgrade to Traefik version 2.11.14 or 3.2.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-52003.
Read more SecurityIn PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, and 8.3.* before 8.3.14 a critical severity vulnerability CVE-2024-8932 was detected. This vulnerability allows attackers to cause an integer overflow through uncontrolled long string inputs to the ldap_escape() function on 32-bit systems, leading to an out-of-bounds write. To address this issue, users must upgrade to PHP versions 8.1.31, 8.2.26 or 8.3.14. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-8932.
Read more Web DevelopmentIn PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, and 8.3.* before 8.3.14 a medium severity vulnerability CVE-2024-8929 was detected. This vulnerability allows attackers to exploit a malicious MySQL server to force the PHP client to reveal sensitive data from its memory, including information from other users. To address this issue, users must upgrade to PHP versions 8.1.31 or later, 8.2.26, or 8.3.14. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-8929.
Read more Web Development