In Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 a medium severity vulnerability CVE-2024-41144 was detected. The application doesn’t validate synced posts correctly when shared channels are enabled, letting a malicious user create, update, or delete posts in any channel. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-41144.
Read more CommunicationIn Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, and 9.8.x <= 9.8.1 a medium severity vulnerability CVE-2024-41162 was detected. This product doesn’t prevent remote modification of local channels when shared channels are enabled, allowing a malicious user to make any local channel read-only. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-41162.
Read more CommunicationIn Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, and 9.8.x <= 9.8.1 a high severity vulnerability CVE-2024-39274 was detected. This vulnerability allows remote attackers to add users to arbitrary teams and channels. To fix this problem, users should upgrade Mattermost to versions 9.9.1, 9.5.7, 9.7.6, and 9.8.2 and later. For more details, https://avd.aquasec.com/nvd/2024/cve-2024-39274.
Read more CommunicationIn Elasticsearch versions 7.0.0 to 7.17.18 and 8.0.0 to 8.12.0 a medium severity vulnerability CVE-2024-23444 was detected. This vulnerability allows attackers to potentially access the unprotected private key stored on the computer, posing a security risk. To fix this problem, users should upgrade Elasticsearch to versions 7.17.19 and 8.13.0. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-23444.
In Joomla versions 4.0.0 to 4.4.5 and 5.0.0 to 5.1.1 a medium severity vulnerability CVE-2024-21730 was detected. This vulnerability allows attackers to inject malicious scripts that would be executed in the user’s browser, posing a security risk. To fix this problem, users should upgrade Joomla to versions 4.4.6 and 5.1.2. For more details, https://avd.aquasec.com/nvd/2024/cve-2024-21730.
Read more CMSIn Joomla versions 3.0.0 to 3.10.15, 4.0.0 to 4.4.5, and 5.0.0 to 5.1.1 a medium severity vulnerability CVE-2024-21731 was detected. This vulnerability allows attackers to embed harmful scripts that can run within a user’s web browser, posing significant security risks. To fix this problem, users should upgrade Joomla to versions 3.10.16, 4.4.6, and 5.1.2. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-21731.
In MySQL version 8.4.0 and prior a medium severity vulnerability CVE-2024-21170 was detected. This vulnerability allows attackers to gain unauthorized access to and modify data in MySQL Connectors, potentially causing disruptions and partial service outages. To fix this problem, users should upgrade MySQL to version 8.4.1 and later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-21170.
In MySQL versions 8.0.37 and earlier, 8.4.0 and earlier a medium severity vulnerability CVE-2024-21177 was detected. This vulnerability allows attackers to repeatedly crash MySQL Server, resulting in a total service outage. To fix this problem, users should upgrade MySQL to versions 8.0.38 and later, 8.4.1 and later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-21177.
Read more DatabaseIn Kibana versions before 8.11.2 a medium severity vulnerability CVE-2024-37281 was detected. This vulnerability allows attackers to crash a Kibana instance by sending too many harmful requests. To fix this problem, users should upgrade Kibana to version 8.11.2 or higher. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-37281.
Read more Data Analytics