In Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.0, 9.8.x <= 9.8.2 a medium severity vulnerability CVE-2024-43780 was detected. This vulnerability allows a guest user with read access to upload files to a channel. To fix this issue, users must upgrade Mattermost to versions 9.5.8, 9.10.1, 9.9.2, 9.8.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-43780/.
Read more CommunicationIn Mattermost versions ≤ 1.0.0 a medium severity vulnerability CVE-2024-43105 was detected. This vulnerability allows a user to consume excessive resources by running the /export command multiple times at once. To fix this issue, users must upgrade Mattermost to version 1.0.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-43105.
In OpenSearch versions 2.16.0, 1.3.19 and earlier a medium severity vulnerability CVE-2024-43794 was detected. The Dashboards Security Plugin adds a user interface for managing security features. Improper validation of the nextUrl parameter may cause an external redirect during login if certain parameters are manipulated. To fix this problem, users should upgrade to version 1.3.19 or 2.16.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-43794.
Read more Data AnalyticsIn OpenShift versions from 2.6.7 through 2.8.13 a high severity vulnerability CVE-2024-6508 was detected. A flaw in the OpenShift Console’s OAuth2 protocol can allow Cross-Site Request Forgery (CSRF) attacks due to improper use of the state parameter, enabling unauthorized access to accounts. The attack requires initiation from within the local network and no exploit is available. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-6508.
Read more Developer ToolsIn the CPython “zipfile” module versions from 3.0 through 3.13.0 a high severity vulnerability CVE-2024-8088 was detected. The “zipfile.ZipFile” class is not affected. However, using “zipfile.Path” methods like “namelist()” or “iterdir()” on a malicious zip file can cause an infinite loop, but only in programs that handle user-controlled zip archives. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-8088.
Read more Application DevelopmentIn GitLab versions starting from 12.5 before 17.1.6, versions starting from 17.2 before 17.2.4, and versions starting from 17.3 before 17.3.1 a medium severity vulnerability CVE-2024-3127 was detected. Under certain conditions, unauthorized users might be able to bypass IP restrictions for groups via GraphQL and perform some group-level actions. To fix this problem, users should upgrade to version 17.1.6, 17.2.4, 17.3.1, or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-3127.
Read more Developer ToolsIn Spring Boot versions 2.7.0 to 2.7.21, 3.0.0 to 3.0.16, 3.1.0 to 3.1.12, 3.2.0 to 3.2.8, and 3.3.0 to 3.3.2 a medium severity vulnerability CVE-2024-38807 was detected. This vulnerability allows for signature forgery, where content that appears to have been signed by one signer has actually been signed by another. To fix this issue, users must upgrade Spring Boot to 2.7.22, 3.0.17, 3.1.13, 3.2.9, or 3.3.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-38807.
Read more Application DevelopmentIn Mattermost Plugin Channel Export versions before 1.0.0 a medium severity vulnerability CVE-2024-43105 was detected. This vulnerability allows attackers to overload the system by running the export command multiple times, which can slow down or crash the server. To fix this problem, users should upgrade Mattermost Plugin Channel Export to version 1.0.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-43105.
Read more CommunicationIn GitLab versions from 8.2 prior to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior to 17.3.1 a medium severity vulnerability CVE-2024-6502 was detected. This vulnerability allows attackers to create a branch with the same name as a deleted tag. To fix this problem, users should upgrade GitLab to versions 17.1.6, 17.2.4, or 17.3.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-6502.
Read more Developer Tools