In Discourse versions priorto 3.2.3 and 3.3.0.beta3 a medium severity vulnerability CVE-2024-37165 was detected. A flaw in the Onebox feature can allow harmful code to run if the data is not cleaned correctly. This issue only affects Discourse instances that have turned off the default Content Security Policy. This vulnerability is fixed in 3.2.3 and 3.3.0.beta3. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-37299.
Read more CommunicationIn Discourse versions prior to 3.2.5 and 3.3.0.beta5 a medium severity vulnerability CVE-2024-37299 was detected. Creating requests with very long tag group names can make a Discourse instance less available. This issue is resolved in versions 3.2.5 and 3.3.0.beta5. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-37299.
Read more CommunicationIn Discourse versions prior to 3.2.5 and 3.3.0.beta5 a medium severity vulnerability CVE-2024-39320 was detected. This vulnerability allows attackers to inject iframes from any domain, bypassing the intended restrictions enforced by the allowed_iframes setting. This vulnerability is fixed in 3.2.5 and 3.3.0.beta5. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39320.
Read more CommunicationIn all WooCommerce versions up to, and including 3.5.1 a medium severity vulnerability CVE-2024-6458 was detected. Attackers with basic access can change post titles without permission. This can also lead to harmful scripts being saved, which can affect admins who view these posts. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-6458.
Read more E-commerceIn Magento versions before 20.10.1 a medium severity vulnerability CVE-2024-41676 was detected. This vulnerability allows attackers to view sensitive files in GitLab. To fix this problem, users should upgrade Magento to version 20.10.1 or higher. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-41676.
Read more E-commerceIn CPython a medium severity CVE-2024-3219 was detected. The socket module provides a fallback for socket.socketpair() on Windows using AF_INET/AF_INET6, but this method is insecure against local attacks. Linux, macOS, and CPython versions before 3.5 are not affected. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-3219.
Read more Application DevelopmentIn GitLab CE/EE all versions from 16.6 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 a high severity vulnerability CVE-2024-7047 was detected. A cross-site scripting (XSS) vulnerability allows an attacker to run arbitrary scripts as the logged-in user, potentially leading to unauthorized actions and access to sensitive information. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-7047.
Read more Developer ToolsIn Magento versions prior to 20.10.1 a medium severity vulnerability CVE-2024-41676 was detected. There is a security issue where admins can accidentally add harmful code in these settings: design/header/welcome, design/header/logo_src, design/header/logo_src_small, and design/header/logo_alt. These settings allow text or image URLs but may unintentionally include dangerous code. This issue is fixed in version 20.10.1 and later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-41676.
Read more E-commerceIn Python versions prior to 3.12.6-r0 a low severity vulnerability CVE-2024-4032 was detected. The ipaddress module is incorrectly labeling some IP addresses as “global” or “private.” This causes errors in the is_private and is_global properties. To fix this problem, users should upgrade to versions 3.12.4 and 3.13.0a6. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-4032.