In Sonatype Nexus Repository versions from 3.0 to 3.68.0 a high severity vulnerability CVE-2024-4956 was detected. This flaw allows attackers to manipulate file paths, accessing files outside the restricted directory. The issue is fixed in version 3.68.1. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-4956/.
Read more Developer ToolsIn OpenStack Platform a medium severity vulnerability CVE-2024-4840 was detected. This flaw could expose sensitive information by storing plaintext passwords in log files. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-4840/.
Read more Cloud ComputingIn MongoDB Server versions 5.0.x up to 5.0.16 and 6.0.x up to 6.0.5 a medium severity vulnerability CVE-2024-3374 was detected. This vulnerability lets unauthorized users crash the server by creating a large BSON object during diagnostic metrics generation. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-3374.
Read more DatabaseIn Mattermost versions from 9.5.0 through 9.5.3, 9.7.0, 9.7.1 and from 8.1.0 through 8.1.12 a medium severity vulnerability CVE-2024-34029 was detected. This flaw lets unauthorized users see AD/LDAP group members linked to a team by adding the group to a channel. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-34029/.
Read more CommunicationIn Mattermost versions from 9.5.0 through 9.5.3, 9.6.0, 9.6.1, 9.7.0, 9.7.1 and from 8.1.0 through 8.1.12 a medium severity vulnerability CVE-2024-29215 was detected. It lets users run slash commands in channels they aren’t members of by linking a playbook run to the channel. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-29215/.
Read more CommunicationIn GitLab versions from 13.2.4 to 17.0 a medium severity vulnerability CVE-2024-1947 was detected. This vulnerability allows attackers to create a DoS attack. There is no solution to this yet. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-1947/.
Read more Developer ToolsIn GitLab versions 13.2.4 to 17.0 a medium severity vulnerability CVE-2024-5258 was detected. This vulnerability allows attackers to bypass authorization. There is no solution to this yet. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-5258/.
Read more Developer ToolsIn all GitLab CE/EE versions starting from 11.11 prior to 16.10.6, from 16.11 prior to 16.11.3, and from 17.0 prior to 17.0.1a medium severity vulnerability CVE-2024-5318 was detected. This vulnerability allows a guest user to access dependency lists of private projects through job artifacts. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-5318.
Read more Developer ToolsIn Keycloak a high severity vulnerability CVE-2024-1132 was detected. URLs included in a redirect are not properly validated. Attackers can create malicious requests to bypass validation and access other URLs and sensitive information. It affects clients using a wildcard in the Valid Redirect URIs field and needs user interaction. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-1132/.
Read more Security