In Airflow versions 2.4.0 and before 2.9.3 a low severity vulnerability CVE-2024-39877 was detected. This vulnerability allows attackers to execute arbitrary code in the scheduler context. To address this issue, users must upgrade to the version 2.9.3. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39877.
Read more Data AnalyticsIn Fastapi OPA a medium severity vulnerability CVE-2024-40627 was detected. The OpaMiddleware lets all HTTP OPTIONS requests through without checking authentication, which can reveal entity existence to attackers. To address this issue users should upgrade to version 2.0.1. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-40627.
Read more Application DevelopmentIn Apache Airflow version before 2.9.3 a medium severity vulnerability CVE-2024-39863 was detected. This vulnerability allows an authenticated attacker to inject a malicious link when installing a provider. To fix this problem, users should upgrade Apache Airflow to version 2.9.3. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39863.
Read more Data AnalyticsIn Gitlab versions 17.0 to 17.1.2 a low severity vulnerability CVE-2024-5470 was detected. This vulnerability allows attackers to create project-level deploy tokens as guest users. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-5470/.
Read more Developer ToolsIn GitLab CE/EE versions 17.0 to 17.0.3 and 17.1 to 17.1.1 a medium severity vulnerability CVE-2024-5257 was detected. A developer with the admin_compliance_framework role could change the URL for a group namespace. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-5257.
In GitLab CE/EE, all versions starting from 16.5 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 a low severity vulnerability CVE-2024-2880 was detected. This vulnerability allows a user with admin_group_member custom role permission to ban group members. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-2880/.
In OpenSSH’s server (sshd) a high severity vulnerability CVE-2024-6387 was detected. There is a timing problem that can cause sshd to handle some signals unsafely. An unauthenticated, remote attacker could exploit this by failing to log in within a certain time frame. To address this issue, users should upgrade OpenSSH’s to version 9.8p1. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-6387.
Read more Developer StacksIn Superset version 4.0.1 a medium severity vulnerability CVE-2024-39887 was detected. This vulnerability allows attackers to bypass Apache Superset’s SQL authorization. To address this issue, users must update version 4.0.2. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39887/.
Read more Data AnalyticsIn NetworkManager for Red Hat OpenShift Container Platform 4 a low severity vulnerability CVE-2024-6501 was detected. If a system has DEBUG logs on and an interface called eth1 with LLDP enabled, a hacker could send a bad LLDP packet, causing NetworkManager to crash and resulting in a denial of service. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-6501/.
Read more Developer Tools