In Ghost versions from the beginning up to 1.4.0 a high severity vulnerability CVE-2024-34559 was detected. To protect sensitive information, it’s essential to adjust log settings properly before releasing a product. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-34559/.
Read more CMSIn GitLab versions before 16.10.6, 16.11.3, and 17.0.1 a high severity vulnerability CVE-2024-4835 was detected. Attackers can create a harmful webpage and steal sensitive user data. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-4835/.
Read more Developer ToolsIn WordPress a high severity vulnerability CVE-2024-31210 was detected. Administrative users in WordPress may unintentionally upload harmful files when adding new plugins, potentially leading to unauthorized execution of code. However, this mainly affects high-level administrators and multi-site setups, with lower-level users and sites with specific security configurations being unaffected. This vulnerability is resolved in WordPress version 6.4.3 and backported to versions 6.3.3, 6.2.4, 6.1.5, 6.0.7, 5.9.9, 5.8.9, 5.7.11, 5.6.13, 5.5.14, 5.4.15, 5.3.17, 5.2.20, 5.1.18, 5.0.21, 4.9.25, 2.8.24, 4.7.28, 4.6.28, 4.5.31, 4.4.32, 4.3.33, 4.2.37, and 4.1.40. For more information, visit https://avd.aquasec.com/nvd/2024/cve-2024-31210/.
Read more CMSIn Airflow versions 2.7.0 through 2.8.4 a medium severity vulnerability CVE-2024-31869 was detected. A security flaw exposes sensitive provider configurations to authenticated users via the ‘configuration’ UI page when certain settings are configured, affecting mainly the Celery provider. Consider upgrading to Airflow version 2.9 or adjusting your expose_config setting to False as a temporary solution. For more information, visit https://avd.aquasec.com/nvd/2024/cve-2024-31869/.
Read more Data AnalyticsIn Node.js versions up to 21.7.2 a command inject vulnerability CVE-2024-3566 was detected. It lets a hacker run commands on Windows apps that indirectly depend on the CreateProcess function when the specific conditions are satisfied. There’s no fix available for this issue at the moment. For more information, visit https://avd.aquasec.com/nvd/2024/cve-2024-3566/.
Read more Application DevelopmentIn WordPress versions from 6.4.0 to 6.4.2 a medium severity vulnerability CVE-2024-31211 was detected. The product deserializes untrusted data without sufficient verification, compromising data integrity and exposing it to manipulation. Attackers can exploit “gadget chains” during deserialization to execute unauthorized actions, posing serious security risks. This issue is resolved in WordPress version 6.4.2. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-31211/.
Read more CMSIn Vault and Vault Enterprise versions from 1.14.0 up to 1.15.6 and 1.14.10 a medium severity vulnerability CVE-2024-2660 was detected. The TLS certificate authentication method failed to verify Online Certificate Status Protocol (OCSP) responses from multiple sources, potentially allowing unauthorized access. This issue is resolved in Vault version 1.16.0 and Vault Enterprise versions 1.16.1, 1.15.7, and 1.14.11. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-2660/.
Read more SecurityIn Spring Framework versions 5.3.0, 5.3.33, 6.0.0, 6.0.18, 6.1.0, and 6.1.5 a high-severity vulnerability CVE-2024-22262 was detected. This vulnerability could allow a remote attacker to conduct phishing attacks due to an open redirect vulnerability in UriComponentsBuilder. An attacker could exploit this vulnerability using a specially crafted URL to redirect a victim to arbitrary websites. Upgrading to version 5.3.34, 6.0.19, or 6.1.6 fixes this vulnerability. For more information, visit https://avd.aquasec.com/nvd/2024/cve-2024-22262/.
Read more Application DevelopmentIn pgAdmin versions before 8.4 a critical severity vulnerability CVE-2024-2044 was detected. Unauthenticated attackers can execute code by loading and deserializing remote pickle objects on Windows servers, while authenticated attackers on POSIX/Linux servers can upload and deserialize pickle objects to gain code execution. The issue is fixed in versions 8.4 or higher. For more information, visit https://avd.aquasec.com/nvd/2024/cve-2024-2044/.
Read more Database