In Nextcloud Server versions 27.1.9 and earlier a low severity vulnerability CVE-2024-37887 was detected. This vulnerability allows attackers to read private shared calendar events’ recurrence exceptions. To address this issue, it is recommended to upgrade to Nextcloud Server version 27.1.10, 28.0.6, or 29.0.1, and Nextcloud Enterprise Server to version 27.1.10, 28.0.6, or 29.0.1. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-37887.
Read more StorageIn Nextcloud Server versions prior to 26.0.12, 27.1.7 and 28.0.3 a medium severity vulnerability CVE-2024-37884 was detected. This vulnerability allows malicious users to delete old versions of files they only have read permissions for. To address this issue, it is recommended to upgrade Nextcloud Server to version 26.0.12, 27.1.7, or 28.0.3, and Nextcloud Enterprise Server to the same versions. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-37884.
Read more StorageIn Nextcloud Server versions prior to 26.0.12, 27.1.7 and 28.0.3 a medium severity vulnerability CVE-2024-37315 was detected. This vulnerability allows attackers with read-only access to restore older versions of a document if the files_versions app is enabled. To address this issue, it is recommended to upgrade to Nextcloud Server version to 26.0.12, 27.1.7 or 28.0.3 and the Nextcloud Enterprise Server versions to 23.0.12.16, 24.0.12.12, 25.0.13.6, 26.0.12, 27.1.7 or 28.0.3 For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-37315.
Read more StorageIn OpenShift a medium severity vulnerability CVE-2024-43168 related to a heap-buffer-overflow was detected in Unbound’s `cfg_mark_ports` function. This issue is found within `config_file.c`. The vulnerability can lead to memory corruption. Attackers with local access can exploit this issue by providing specially crafted input. This can potentially cause the application to crash or allow arbitrary code execution, leading to a denial of service or unauthorized actions on the system. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-43168.
Read more Developer ToolsIn Jenkins 2.470 and earlier, LTS 2.452.3 and earlier a medium severity vulnerability CVE-2024-43045 was detected. The application skips a permission check on an HTTP endpoint, letting attackers with Overall/Read access view other users’ “My Views.” In Jenkins 2.471, LTS 2.452.4, and LTS 2.462.1, access to a user’s “My Views” is restricted to the owning user and administrators. To address this issue, users should upgrade to versions 2.471-r0 or higher. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-43045.
Read more Developer ToolsIn Django versions 5.0 before 5.0.8 and 4.2 before 4.2.15 a high severity vulnerability CVE-2024-41991 was detected. This vulnerability allows attackers to overload the system with a large amount of text, causing it to slow down or stop working. To fix this problem, users should upgrade Django to versions 4.2.15, 5.0.8 or higher. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-41991.
Read more Application DevelopmentIn Jenkins versions 2.470 and earlier, LTS 2.452.3 and earlier a high severity vulnerability CVE-2024-43044 was detected. This vulnerability allows attackers to access and read any files on the main Jenkins server, potentially exposing sensitive information. To fix this problem, users should upgrade Jenkins to versions 2.471, LTS 2.452.4. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-43044.
Read more Developer ToolsIn Django versions 5.0 before 5.0.8 and 4.2 before 4.2.15 a high severity vulnerability CVE-2024-41990 was detected. This vulnerability allows attackers to crash the system or make it unresponsive by sending enormous amounts of data with certain patterns. To fix this problem, users should upgrade Django to versions 5.0.8 and 4.2.15. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-41990.
Read more Application DevelopmentIn Django versions 5.0 before 5.0.8 and 4.2 before 4.2.15 a high severity vulnerability CVE-2024-41989 was detected. This vulnerability allows attackers to slow down or crash the system by sending a special number that uses a lot of memory. To fix this problem, users should upgrade Django to versions 5.0.8 and 4.2.15. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-41989.
Read more Application Development