In Apache Airflow versions 2.10.0 a low severity vulnerability CVE-2024-45498 was detected. This vulnerability allows attackers to create a fake login page and deceive users into authenticating with attacker-controlled credentials due to the absence of a unique token in the authentication POST request. To fix this problem, users should upgrade to version 2.10.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-45498.
Read more Data AnalyticsIn Apache Airflow versions before 2.10.1 a high severity vulnerability CVE-2024-45034 was detected. This vulnerability allows DAG authors to add local settings to the DAG folder, which can be executed by the scheduler, bypassing its intended restrictions. To fix this problem, users should upgrade to version 2.10.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-45034.
Read more Data AnalyticsIn Apache HTTP Server versions 2.4.0 through 2.4.59 a critical severity vulnerability CVE-2024-38474 was detected. This vulnerability allows attackers to execute scripts in restricted directories or expose sensitive scripts meant for CGI execution only due to an unsafe substitution encoding issue. To fix this problem, users should upgrade Apache HTTP Server to version 2.4.60. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-38474.
Read more Application DevelopmentIn Apache HTTP Server versions 2.4.59 and earlier a critical severity vulnerability CVE-2024-38476 was detected. This vulnerability allows malicious response headers in backend applications to cause information disclosure, SSRF, or local script execution. To fix this problem, users should upgrade Apache HTTP Server to version 2.4.60. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-38476.
Read more Application DevelopmentIn WP Discourse in all versions up to, and including 2.5.1 a medium severity vulnerability CVE-2024-35168 was detected. This vulnerability allows authenticated users with Subscriber-level access or higher to perform unauthorized actions due to a missing capability check. To fix this problem, users should upgrade WP Discourse to version 2.5.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-35168.
Read more CommunicationIn Keycloak all versions a low severity vulnerability CVE-2024-5203 was detected. This vulnerability allows attackers to craft a fake login page and trick users into authenticating with an attacker-controlled account due to a missing unique token in the authentication POST request. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-5203.
Read more SecurityIn Keycloak in OAuth 2.0 Pushed Authorization Requests (PAR) a high severity vulnerability CVE-2024-4540 was detected. Client-provided parameters in plain text were found in the KC_RESTART cookie, potentially leading to an information disclosure vulnerability. There’s no fix available for this issue at the moment. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-4540.
Read more SecurityIn HAProxy versions before 2.9.10 and before 3.0.4 a high severity vulnerability CVE-2024-45506 was detected. This vulnerability allows a remote attacker to trigger a denial of service (DoS). To address this issue, users are advised to upgrade to version 2.9.20 or version 3.0.4 immediately. For more details, visit the official advisory at the https://nvd.nist.gov/vuln/detail/CVE-2024-45506.
Read more Application DevelopmentIn SuiteCRM versions 7.14.4 and 8.6.1 a high severity vulnerability CVE-2024-45392 was detected. This vulnerability allows attackers to delete records via the API due to insufficient access control checks. To fix this issue users must upgrade to versions 7.14.5 and 8.6.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-45392.
Read more CRM