In Zabbix version 6.0.0 – 7.0.0alpha1 a critical vulnerability CVE-2024-22120 was detected. This vulnerability allows command execution and SQL injection via “clientip.” To address this issue, users should upgrade Zabbix to version 7.0.0 beta1. For more information, visit https://avd.aquasec.com/nvd/2024/cve-2024-22120/.
Read more MonitoringIn Mattermost versions from 9.5.x before 9.5.3, from 9.7.x before 9.7.1 and from 8.1.x before 8.1.12 a medium severity vulnerability CVE-2024-34029 was detected. The /api/v4/groups//channels//link endpoint has a permission issue. Users can see members of an AD/LDAP group linked to a team by adding the group to a channel, even if they shouldn’t have access. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-34029.
Read more CommunicationIn GitLab CE/EE versions before 16.10.6, version 16.11 before 16.11.3, and 17.0 before 17.0.1 a medium severity vulnerability CVE-2023-6502 was detected. It is possible for a malicious user to cause a denial of service using a crafted wiki page. For more details, visit https://avd.aquasec.com/nvd/2023/cve-2023-6502.
Read more Developer ToolsIn GitLab CE/EE versions from 13.11 before 16.10.6, from 16.11 before 16.11.3, from 17.0 before 17.0.1, a medium severity vulnerability CVE-2023-7045 was detected. An attacker could exploit this vulnerability to steal security tokens through the Kubernetes Agent Server (KAS). For more details, visit https://avd.aquasec.com/nvd/2023/cve-2023-7045/.
Read more Developer ToolsIn Ghost versions before 5.82.0 a high severity vulnerability CVE-2024-34448 was detected. This issue lets attackers add harmful data during a member CSV export. Unauthenticated users can input dangerous code into registration fields. Users should update to the latest version to fix this problem. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-34448.
Read more CMSIn the Keycloak OpenID Connect component in the “checkLoginIframe” a high severity vulnerability CVE-2024-1249 was detected. The vulnerability allows unvalidated cross-origin messages. Attackers can coordinate and send millions of requests in seconds using simple code. It significantly impacts the application’s availability without proper origin validation for incoming messages. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-1249/.
Read more SecurityIn Dolibarr versions before 19.0.2 a low severity vulnerability CVE-2024-34051 was detected. This flaw allows attackers to execute harmful scripts through the “facid” parameter on the payment card page. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-34051/.
Read more ERPIn Dolibarr version 9.0.1 a critical severity vulnerability CVE-2024-5315 was detected. This issue in ERP-CRM could let attackers access database information through a vulnerable parameter. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-5315/.
Read more ERPIn Moodle versions from 4.0 through 4.3.3, from 4.2 through 4.2.6, and from 4.1 through 4.1.9 a medium severity vulnerability CVE-2024-34008 was detected. Admin actions for managing analytics models lacked the token needed to prevent CSRF risks. CSRF involves unauthorized requests made on behalf of a user without their consent. There is no proper solution yet. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-34008.
Read more Educational