In Magento (Adobe Commerce) versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier a low severity vulnerability CVE-2024-45134 was detected. This vulnerability allows an admin attacker to bypass security features, potentially exposing sensitive information and aiding further attacks. To fix this problem, users should upgrade to version 2.4.7-p3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-45134.
Read more E-commerceIn Magento (Adobe Commerce) versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, and 2.4.4-p10 a high severity vulnerability CVE-2024-45132 was detected. This vulnerability allows attackers to gain unauthorized access to higher privileges, potentially compromising sensitive information. To fix this issue, users should upgrade Adobe Commerce to versions 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, and 2.4.4-p11. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-45132.
Read more E-commerceIn GitLab CE/EE versions 11.4 prior to 17.2.9, 17.3 prior to 17.3.5, and 17.4 prior to 17.4.2 a medium severity vulnerability CVE-2024-5005 was detected. This vulnerability allows guest users to disclose project templates using the API. To fix this issue, users must upgrade to versions 17.2.9, 17.3.5, or 17.4.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-5005.
Read more Developer ToolsIn Magento (Adobe Commerce) versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier a medium severity vulnerability CVE-2024-45149 was detected. This vulnerability allows low-privileged attackers to bypass security features, potentially compromising confidentiality. Exploitation does not require user interaction. Currently, there is no fix version for this issue.For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-45149.
Read more E-commerceIn Magento (Adobe Commerce) versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier a medium severity vulnerability CVE-2024-45148 was detected. This vulnerability allows attackers to bypass security features and gain unauthorized access without proper credentials. Exploitation of this issue does not require user interaction. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-45148.
Read more E-commerceIn GitLab EE versions 12.5 prior to 17.2.9, 17.3 prior to 17.3.5, and 17.4 prior to 17.4.2 a critical severity vulnerability CVE-2024-9164 was detected. This vulnerability allows attackers to run pipelines on arbitrary branches. To fix this issue, users must upgrade to versions 17.2.9, 17.3.5, or 17.4.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-9164.
Read more Developer ToolsIn GitLab CE/EE versions 11.6 prior to 17.2.9, 17.3 prior to 17.3.5, and 17.4 prior to 17.4.2 a high severity vulnerability CVE-2024-8970 was detected. This vulnerability allows attackers to trigger a pipeline as another user under certain circumstances. To fix this issue, users must upgrade to versions 17.2.9, 17.3.5, or 17.4.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-8970.
Read more Developer ToolsIn GitLab versions starting from 15.10 before 17.2.9, from 17.3 before 17.3.5, and from 17.4 before 17.4.2 a high severity vulnerability CVE-2024-8977 was detected. This vulnerability could allow attackers to exploit the Product Analytics Dashboard, leading to Server-Side Request Forgery attacks. To fix this issue, upgrading to GitLab version 17.2.9, 17.3.5, or 17.4.2 is recommended. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-8977.
Read more Developer ToolsIn GitLab versions starting from 16.6 before 17.2.9, from 17.3 before 17.3.5, and from 17.4 before 17.4.2 a low severity vulnerability CVE-2024-9596 was discovered. This vulnerability allows an unauthenticated attacker to determine the GitLab version number of a GitLab instance. To mitigate this issue, upgrading to GitLab version 17.2.9, 17.3.5, or 17.4.2 is recommended. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-9596.
Read more Developer Tools