In Ansible version 2 a medium severity vulnerability CVE-2024-10033 was detected. This vulnerability allows attackers to inject malicious scripts, redirect users, or steal sessions and data by exploiting the “?next=” parameter in a URL. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-10033.
Read more IT Business ManagementIn Foreman versions 6.13, 6.14 and 6.15 a critical severity vulnerability CVE-2024-7012 was detected. This vulnerability allows unauthorized users to gain admin access due to improper header handling by Apache’s mod_proxy. To fix this problem, users should upgrade to versions 6.13.7.2, 6.14.4.2, or 6.15.3.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-7012.
Read more IT Business ManagementIn Foreman versions before 3.11.1 a medium severity vulnerability CVE-2024-7700 was detected. This vulnerability allows attackers to exploit user actions to execute malicious code. To fix this issue, users should upgrade Foreman to version 3.11.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-7700.
Read more IT Business ManagementIn OpenProject versions before 14.3.0 a medium severity vulnerability CVE-2024-41801 was detected. This vulnerability allows attackers to redirect users with a fake HOST header, affecting default installations. Upgrade to version 14.3.0 to fix this by rejecting invalid hostnames. If upgrading isn’t possible, use mod_security for Apache, adjust Host and X-Forwarded-Host headers manually, or apply a patch for older versions. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-41801.
Read more Project ManagementIn OpenProject versions prior to 14.3.0 a medium severity vulnerability CVE-2024-41801 was detected. This vulnerability allows attackers to redirect users to fake sites to steal their credentials. To fix this problem, users should upgrade OpenProject to version 14.3.0. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-41801.
Read more Project ManagementIn OpenProject a high severity vulnerability CVE-2024-35224 was detected. A project admin could exploit a bug in the Cost Report feature to insert harmful code. Updating to version 13.4.2, 14.0.2, or 14.1.0 resolves this vulnerability. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-35224/.
Read more Project ManagementIn Kanboard version 1.2.36 a high severity vulnerability CVE-2024-36399 was detected. This vulnerability allows attackers to take over any other project. To address this issue, users need to update to version 1.2.37. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-36399/.
Read more Project ManagementIn Kimai all versions before 2.13.0 a medium severity vulnerability CVE-2024-29200 was detected. Setting the “view_other_timesheet” permission to true allows users to see only their team’s timesheet entries in the Kimai UI, but when using the API, it returns all timesheet entries, regardless of team memberships. This vulnerability is resolved in version 2.13.0. For more information, visit https://avd.aquasec.com/nvd/2024/cve-2024-29200/.
Read more Project ManagementIn iTop a high severity vulnerability CVE-2023-47622 was detected. Refreshing dashlets could allow attackers to inject harmful code into the webpage if the system doesn’t properly clean up user-entered data. The issue is resolved in versions 3.0.4 and 3.1.1. For more information, visit https://avd.aquasec.com/nvd/2023/cve-2023-47622/.
Read more IT Business Management