Proactive Insights and Support For Open-Source Applications
  • Applications
  • Platform
  • Support
  • Resources
    • 2025 OSS Research
    • FAQ
    • Newsflash
    • OSSpedia
    • How-to Guides
    • Case Studies
    • Articles
  • Company
    • About Us
    • The OSS in Hossted
  • Contact
Book a demo
Book a demo
  • Applications
  • Platform
  • Support
  • Resources
    • 2025 OSS Research
    • FAQ
    • Newsflash
    • OSSpedia
    • How-to Guides
    • Case Studies
    • Articles
  • Company
    • About Us
    • The OSS in Hossted
  • Contact
  • Home
  • Knowledge Base
  • Newsflash

Our news and updates

All OSSpediaArticlesHow ToNewsflashCase Studies
Don't Miss out!
Join our newsletter for exclusive updates on open source innovations.

    Choose category
    • Communication
      • Communication
    • Communication and Collaboration
      • Communication
    • Specialized Software
      • Educational
      • Graphic Design
    • Business and Enterprise Solutions
      • Customer Service
      • Productivity
      • Supply Chain Management (SCM)
      • CRM
      • E-commerce
      • CMS
      • Marketing Automation
      • ERP
    • Project and Agile Management
      • Project Management
      • IT Business Management
    • Infrastructure and Network
      • CMS
      • Networking
      • Storage
      • Security
    • DevOps
      • DevOps
      • Mobile App Development
      • Backup and Recovery
      • Data Analytics
      • Web Development
      • Developer Stacks
      • Cloud Computing
      • Monitoring
      • Application Development
      • Developer Tools
    • Data Management and Analytics
      • Communication
      • Application Development
      • Analytics
      • Machine Learning
      • Database
      • Data Analytics
    25 Jul 2024 Business and Enterprise Solutions
    Dolibarr: Remote Code Execution Vulnerability

    In Dolibarr ERP CRM versions before 19.0.2-php8.2 a high severity vulnerability CVE-2024-40137 was detected. A vulnerability in the Computed field parameter of the Users Module Setup in Dolibarr ERP CRM allows remote code execution. This issue is fixed in versions 19.0.2-php8.2 and later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-40137.

    Read more
    ERP
    25 Jul 2024 Specialized Software
    Moodle: XSS Vulnerability Allows Malicious Script Injection and User Data Manipulation

    In Virtual Programming Lab for Moodle versions up to v4.2.3 a medium severity vulnerability CVE-2024-34312 was detected. This issue allows attackers to inject malicious scripts into web pages viewed by users, potentially leading to unauthorized access or manipulation of user data. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-34312.

    Read more
    Educational
    25 Jul 2024 DevOps
    Python: Remote Code Execution Vulnerability in pypa/setuptools Package Index Module

    In Setuptools is a widely-used Python library for packaging, distributing, and installing Python projects a high severity vulnerability CVE-2024-6345 was detected. A vulnerability in the `package_index` module of pypa/setuptools (up to version 69.1.1) allows remote code execution through its download functions, which are susceptible to code injection with user-controlled inputs like package URLs. To address this issue users should upgrade to version 70.0. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-6345.

    Read more
    Application Development
    24 Jul 2024 Data Management and Analytics
    MongoDB: String Handling Flaw in MongoDB Rust Driver

    In MongoDB Rust Driver 2.0 versions prior to 2.8.2 a medium severity vulnerability CVE-2024-6382 was detected. Incorrect handling of some string inputs in the MongoDB Rust driver can create unintended server commands, leading to unexpected behavior or data modification. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-6382.

    Read more
    Database
    24 Jul 2024 Data Management and Analytics
    PostgreSQL: REFRESH MATERIALIZED VIEW CONCURRENTLY Vulnerability

    In PostgreSQL in REFRESH MATERIALIZED VIEW CONCURRENTLY command versions before 16.2, 15.6, 14.11, 13.14, and 12.18 a high severity vulnerability CVE-2024-0985 was detected. This command should safely refresh views, but due to a flaw, the view creator can trick a superuser or someone with higher privileges into running harmful functions. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-0985.

    Read more
    Database
    24 Jul 2024 Data Management and Analytics
    MySQL: High-Privileged Attackers Can Crash MySQL Server

    In MySQL Server versions 8.0.37 and prior, and 8.4.0 and prior a medium severity vulnerability CVE-2024-20996 was detected. A high-privileged attacker with network access can exploit this vulnerability to compromise MySQL Server, causing it to hang or crash repeatedly. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-20996.

    Read more
    Database
    24 Jul 2024 DevOps
    Spring Cloud: DOS Vulnerability in Spring Cloud Function Web Module

    In the Spring Cloud Function framework versions 4.1.x prior to 4.1.2 and 4.0.x prior to 4.0.8 a high severity vulnerability CVE-2024-22271 was detected. The application is vulnerable to a DOS attack if it tries to use non-existing functions while using the Spring Cloud Function Web module. To address this issue users should upgrade to 4.0.8 or 4.1.2. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-22271.

    Read more
    Application Development
    24 Jul 2024 Data Management and Analytics
    MySQL Server: Critical Update Required to Prevent DoS Attacks

    In MySQL Server versions prior to 8.0.37 and prior to 8.4.0 a medium severity vulnerability CVE-2024-21179 was detected. This vulnerability allows attackers with network access to cause a hang or crash, leading to a denial of service (DoS). To fix this problem, users should upgrade MySQL Server to versions 8.0.37 and 8.4.0. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-21179.

    Read more
    Database
    24 Jul 2024 DevOps
    OpenStack: Upgrade to Prevent File Access Exploit in Cinder, Glance, and Nova

    In OpenStack components Cinder through version 24.0.0, Glance before version 28.0.2, and Nova before version 29.0.3 a medium severity vulnerability CVE-2024-32498 was detected. This vulnerability allows attackers to read important files on your system using a specially made file. To fix this problem, users should upgrade the OpenStack Cinder component to version 24.0.1 or later, the OpenStack Glance component to version 28.0.2 or later and the OpenStack Nova component to version 29.0.3 or later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-32498.

    Read more
    Cloud Computing
    Proactive Insights and Support For Open-Source Applications
    Contact us: Whatsapp
    Company
    • About Hossted
    • Data Processing Addendum
    Solutions
    • Applications
    • Support Plans
    • About Solution
    Resources
    • FAQ
    • Knowledge Base

    © HOSSTED 2026 All rights reserved

    • Privacy Policy
    • Terms and Conditions
    • Cookies Policy
    Cookie Settings

    We use cookies to measure marketing efforts and improve our services. Please review the cookie settings and confirm your choice.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}