In GitLab versions from 15.8 through 16.11.6, from 17.0 through 17.0.4 and from 17.1 through 17.1.2 a high severity vulnerability CVE-2024-6385 was detected. This vulnerability allows attackers to trigger a pipeline as another user under certain circumstances. To fix this problem, users should upgrade GitLab to one of the following versions 16.11.6, 17.0.4, or 17.1.2. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-6385.
Read more Developer ToolsIn Bootstrap versions from 4.0.0 upĀ to 4.6.2 a medium severity vulnerability CVE-2024-6531 was detected. This vulnerability can expose users to Cross-Site Scripting (XSS) attacks. The issue is present in the carousel component, where the data-slide and data-slide-to attributes can be exploited through the href attribute of an tag due to inadequate sanitization. The vulnerability allows attackers to run arbitrary JavaScript in the victim’s browser. To address this issue, users should upgrade to versions 5.0.0-beta1 or higher. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-6531.
In the OpenSearch Dashboards Reporting plugin a medium severity vulnerability CVE-2024-39900 was detected. A ‘Report Owner’ can export and share reports from OpenSearch Dashboards, potentially accessing private tenant resources like notebooks. The system didn’t verify if the user was the resource author, leading to possible unauthorized data exposure. This issue is fixed in OpenSearch version 2.14. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39900.
Read more Data AnalyticsIn Airbyte versions till 0.62.2 a high severity vulnerability CVE-2024-38363 was detected. This vulnerability allows attackers to execute arbitrary code on the server as the web server user. To address this issue, users must update to version 0.62.2. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-38363/.
Read more Data AnalyticsIn Django versions before 4.2.14 and 5.0.7 a low severity vulnerability CVE-2024-39614 was detected. This vulnerability allows attackers to cause denial of service by using specific characters in long strings. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39614/.
Read more Application DevelopmentIn Django versions before 4.2.14 and 5.0.7 a low severity vulnerability CVE-2024-39330 was detected. This vulnerability allows attackers to traverse the directory via certain inputs. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39330/.
Read more Application DevelopmentIn Next.js versions prior to 13.5 a high severity vulnerability CVE-2024-39693 was detected. This vulnerability could crash servers, impacting their availability. To address this issue users should upgrade to versions 13.5 and later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39693.
Read more Application DevelopmentIn Joomla versions 3.0.0-3.10.15-elts, 4.0.0-4.4.5, 5.0.0-5.1.1 a low severity vulnerability CVE-2024-26279 was detected. This vulnerability allows attackers to access sensitive data via cross-scripting. There is no fix to this yet. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-26279/.
Read more CMSIn Joomla versions from 3.7.0 through 3.10.15, from 4.0.0 through 4.4.5, and from 5.0.0 through 5.1.1 a medium severity vulnerability CVE-2024-26278 was detected. This vulnerability allows attackers to inject malicious scripts into web pages viewed by other users, potentially leading to unauthorized actions or data theft. To fix this problem, users should upgrade Joomla to one of the following versions 3.10.16, 4.4.6, or 5.1.2. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-26278.