Articles
Newsflash
2 Jul 2025 Project and Agile Management
Ansible: Remote Command Execution in AAP EDA through Git URL Injection

In Ansible Automation Platform’s EDA component, all versions before 1.1.10 a high severity vulnerability CVE-2025-49520 was detected. This vulnerability allows attackers to execute arbitrary system commands on the EDA worker by injecting malicious arguments into the git ls-remote command, potentially leading to sensitive data exposure, such as Kubernetes or OpenShift service account tokens, and full cluster compromise. To fix this issue, users should upgrade Ansible Automation Platform’s EDA component to version 1.1.11. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-49520.

Read more
IT Business Management
2 Jul 2025 DevOps
aaPanel: Critical Command Injection

In AAPanel version 7.0.7 a critical severity vulnerability CVE-2024-42922 was detected. This vulnerability allows attackers to perform OS command injection, potentially leading to full system compromise. To address this issue users must upgrade to a patched version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-42922.

Read more
Application Development
2 Jul 2025 DevOps
Sentry: OAuth Persistence Vulnerability

In Sentry versions prior to 25.5.0 a high severity vulnerability CVE-2025-53099 was detected. This vulnerability allows attackers with a malicious OAuth application to exploit a race condition and improper authorization code handling during the OAuth exchange process, enabling them to maintain persistent access to a user’s account even after the application is de-authorized. To address this issue users must upgrade to version 25.5.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-53099.

Read more
Monitoring
2 Jul 2025 Infrastructure and Network
Apache Guacamole: High Severity SSH Session Exploit

In Apache Guacamole versions 1.5.5 and earlier a high severity vulnerability CVE-2024-35164 was detected. This vulnerability allows a malicious user with access to a text-based connection (such as SSH) to exploit improperly validated console codes, potentially leading to arbitrary code execution with the privileges of the running guacd process. To fix this issue, users should upgrade to version 1.6.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-35164.

Read more
Networking
2 Jul 2025 Data Management and Analytics
Apache Cassandra: Improper Authorization

In Apache Cassandra versions 4.0.0 through 4.0.15, 4.1.0 through 4.1.7, and 5.0.0 through 5.0.2
a high severity vulnerability CVE-2025-24860 was detected. This vulnerability allows users to access unauthorized datacenters or IP/CIDR groups and modify their own permissions via DCL statements. To fix this issue, users should upgrade to versions 4.0.16, 4.1.8, or 5.0.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-24860.

Read more
Database
1 Jul 2025 DevOps
Sentry: Unauthorized Issue Access Vulnerability

In Sentry versions 25.1.0 through 25.5.1 a medium severity vulnerability CVE-2025-53073 was detected. This vulnerability allows authenticated attackers to perform unauthorized actions, such as adding comments, on a project’s issue endpoint without being a member of the project’s team. Currently there is no fix for this vulnerability. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-53073.

Read more
Monitoring
Case Studies