In Graphite a critical severity vulnerability CVE-2023-34308 was detected. It enables remote code execution when users engage with harmful files or web pages. The software lacks proper checks on files like projects and source code, causing buffer overflow. For additional details, visit https://avd.aquasec.com/nvd/2023/cve-2023-34308.
Read more Data AnalyticsIn OpenShift a critical security vulnerability CVE-2024-5037 was detected. This vulnerability allows attackers to use a forged token to bypass the authentication. There is no fix available for this. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-5037/.
Read more Developer ToolsIn Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 a critical security vulnerability CVE-2024-36241 was detected. This vulnerability allows attackers to view arbitrary post contents via a slash command. The system must have safe areas with trust boundaries to address this issue. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-36241.
Read more CommunicationIn Mattermost versions from 9.5.0 through 9.5.3, 9.6.0, 9.6.1 and from 8.1.0 through 8.1.12 a medium severity vulnerability CVE-2024-34152 was detected. It allows a guest to view the details of a public playbook by making a specific server request. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-34152/.
Read more CommunicationIn Moodle versions from 4.3 to 4.3.3 a medium severity vulnerability CVE-2024-34009 was detected. ReCAPTCHA on the login page can be bypassed due to insufficient validation checks, although this issue does not affect other pages. To fix this issue, users should upgrade Moodle to versions 4.3.4 or later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-34009/.
Read more EducationalIn Nginx versions from 1.25.0 to before 1.26.1 a medium severity vulnerability CVE-2024-35200 was detected. This issue affects NGINX Plus and NGINX OSS when using the HTTP/3 module. Attackers can cause a denial-of-service (DoS) by stopping NGINX worker processes. Only the data plane is affected, not the control plane. Affected organizations should fix this problem immediately to reduce the risk. For additional details, visit https://avd.aquasec.com/nvd/2024/cve-2024-35200.
Read more Application DevelopmentIn Apache Airflow version 2.9.0 a critical security vulnerability CVE-2024-32077 was detected. This vulnerability allows attackers to inject data into the task instance logs. To address this issue, users are advised to upgrade to version 2.9.1. For more information, visit https://avd.aquasec.com/nvd/2024/cve-2024-32077/.
In Fluent Bit versions 2.0.7 to 3.0.3 a critical security vulnerability CVE-2024-4323 was detected. This vulnerability allows attackers to parse trace requests and may result in remote code execution. There is no actual solution for this vulnerability. For more information, visit https://avd.aquasec.com/nvd/2024/cve-2024-4323/.
In Ghost versions from the beginning up to 1.4.0 a high severity vulnerability CVE-2024-34559 was detected. To protect sensitive information, it’s essential to adjust log settings properly before releasing a product. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-34559/.
Read more CMS