In Joomla versions 3.4.6-3.10.16-elts, 4.0.0-4.4.6, and 5.0.0-5.1.2 a low severity vulnerability CVE-2024-27184 was detected. If a URL isn’t carefully checked, it might not be clear whether a link is leading someone to a safe, internal page or an external, potentially risky site. To fix this problem, users should upgrade to version 3.10.17-elts, 4.4.7, or 5.1.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-27184.
Read more CMSIn CKAN versions 2.7.0 and before 2.10.5 a high severity vulnerability CVE-2024-41675 was detected. This vulnerability allows attackers to inject malicious scripts into the data displayed on a webpage, leading to potential theft of user data, session hijacking, or redirection to harmful sites. To fix this issue, users must update CKAN to versions 2.10.5 or 2.11.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-41675.
Read more Data AnalyticsIn Authentik versions >= 2024.6.0-rc1, < 2024.6.4 < 2024.4.4 a high severity vulnerability CVE-2024-42490 was detected. The vulnerability allows attackers to potentially access sensitive information, like certificates and private keys, by exploiting endpoints without proper authentication or authorization checks. To fix this issue, users should update Authentik to versions 2024.6.4 or 2024.4.4. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-42490.
Read more SecurityIn GitLab versions before 17.1.6, 17.2.4, and 17.3.1 a medium severity vulnerability CVE-2024-8041 was detected. A DoS vulnerability can disrupt the service by importing a malicious repository through the GitHub importer. To fix this problem, users should upgrade to version 17.1.6, 17.2.4, 17.3.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-8041.
Read more Developer ToolsIn GitLab versions from 17.0 to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior to 17.3.1 a medium severity vulnerability CVE-2024-7110 was detected. This vulnerability allows attackers to execute arbitrary commands in a victim’s pipeline through prompt injection. To fix this problem, users should upgrade GitLab to versions 17.1.6, 17.2.4, or 17.3.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-7110.
Read more Developer ToolsIn NPM Matrix messaging protocol Client-Server SDK for JavaScript a medium severity vulnerability CVE-2024-42369 was detected. A malicious homeserver can create a cyclic room structure, causing infinite recursion in getRoomUpgradeHistory and affecting ‘leaveRoomChain()’. Fixed in version 34.3.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-42369.
Read more Developer ToolsIn Joomla versions 3.0.0-3.10.16-elts, 4.0.0-4.4.6, 5.0.0-5.1.2 a critical severity vulnerability CVE-2024-27185 was detected. The pagination class incorporates arbitrary parameters into links, potentially enabling cache poisoning attacks. To fix this problem, users should upgrade to version 3.10.17-elts, 4.4.7, or 5.1.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-27185.
Read more CMSIn Apache Airflow versions before 2.10.0 a medium severity vulnerability CVE-2024-41937 was detected. This vulnerability allows attackers to potentially run harmful scripts on a user’s browser when they click on a provider link in Apache Airflow, potentially leading to data theft. To fix this problem, users should upgrade Apache Airflow to version 2.10.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-41937.
Read more Data AnalyticsIn Flask-cors versions 4.0.1 a high severity vulnerability CVE-2024-6221 was detected. This vulnerability allows attackers to access private network resources without permission, potentially leading to data theft or unauthorized access to sensitive information. To fix this problem, users should upgrade Flask-cors to version 4.0.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-6221.
Read more Application Development