In OpenShift version 4 a medium severity vulnerability CVE-2024-50311 was detected. This vulnerability allows attackers to exploit the GraphQL batching functionality. The flaw arises when multiple queries can be sent within a single request, enabling an attacker to submit a request containing thousands of aliases in one query. This issue causes excessive resource consumption, leading to application unavailability for legitimate users. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-50311.
Read more Developer ToolsIn Nginx UI versions 2.0.0-beta.35 and earlier a high severity vulnerability CVE-2024-49366 was detected. This vulnerability allows attackers to exploit unverified JSON input to write arbitrary files to the server, potentially resulting in a loss of permissions. To fix this issue, users must upgrade to version 2.0.0-beta.26. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-49366.
Read more Application DevelopmentIn Liferay Portal versions 7.3.2 through 7.4.3.107 and Liferay DXP versions from 2023.Q4.0 through 2023.Q4.2 and 2023.Q3.1 through 2023.Q3.5 a high severity vulnerability CVE-2024-26272 was detected. This vulnerability allows attackers to take control of the system, change passwords, shut it down, and run harmful commands remotely. To fix this issue, users should upgrade the Liferay Portal to version 7.4.3.108, Liferay DXP to versions 2024.Q1.1, 2023.Q4.3, 2023.Q3.6, 7.3 Update 36. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-26272.
Read more CMSIn Rancher version < 0.0.0-20240207153957-4fd7d821d952 a high severity vulnerability CVE-2023-32192 was detected. This vulnerability allows attackers to exploit unauthenticated cross-site scripting (XSS) in the public API, enabling them to execute arbitrary JavaScript code in a victim’s browser. To fix this problem, users should upgrade to the version 0.0.0-20240207153957-4fd7d821d952. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2023-32192.
Read more Developer ToolsIn MongoDB Server versions 6.0 (prior to 6.0.17), 7.0 (prior to 7.0.13), and 7.3 (prior to 7.3.4) a medium severity vulnerability CVE-2024-8305 was detected. This vulnerability allows attackers to trigger crashes in secondary nodes by incorrectly enforcing index constraints. In extreme cases, multiple secondaries may crash, potentially leaving no primaries available. To address this issue, update to the latest fixed versions: 6.0.17, 7.0.13, or 7.3.4. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-8305.
Read more DatabaseIn VMware HCX (Hybrid Cloud Extension) versions 4.8.0 – 4.8.2 and 4.9.0 – 4.9.1 a high severity vulnerability CVE-2024-38814 was detected. This vulnerability allows authenticated attackers with non-administrator privileges to execute specially crafted SQL queries, potentially leading to unauthorized remote code execution on the HCX Manager. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-38814.
Read more Cloud ComputingIn NGINX versions prior to 2.0.0-beta.36 a high severity vulnerability CVE-2024-49368 was found. This vulnerability in Nginx UI allows attackers to run harmful commands by sending unverified input, leading to serious security risks. To fix this issue, users are advised to upgrade to version 2.0.0-beta.36. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-49368.
Read more Application DevelopmentIn Rancher versions >= 2.6.0, < 2.6.14, >= 2.7.0, < 2.7.10, >= 2.8.0, < 2.8.2 a high severity vulnerability CVE-2023-32194 was detected. This vulnerability allows users with a create or * global role for “namespaces” to access, create, update, or delete core namespaces, potentially compromising project security. To fix this problem, users should upgrade to the versions 2.6.14, 2.7.10, 2.8.2 or higher. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2023-32194.
Read more Developer ToolsIn Rancher versions >= 2.6.0, < 2.6.14, >= 2.7.0, < 2.7.10, >= 2.8.0, < 2.8.2 a high severity vulnerability CVE-2023-22649 was detected. This vulnerability may expose sensitive data in Rancher’s audit logs if audit logging is enabled and the audit level is set to 1 or above. To fix this problem, users should upgrade to the latest version 2.6.14, 2.7.10 and 2.8.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2023-22649.
Read more Data Analytics