CVE-2024-52336 : RED HAT FAST DATAPATH FOR RHEL/ENTERPRISE LINUX D-BUS INSTANCE_CREATE CROSS SITE SCRIPTING

Description

A script injection vulnerability was identified in the Tuned package. The `instance_create()` D-Bus function can be called by locally logged-in users without authentication. This flaw allows a local non-privileged user to execute a D-Bus call with `script_pre` or `script_post` options that permit arbitrary scripts with their absolute paths to be passed. These user or attacker-controlled executable scripts or programs could then be executed by Tuned with root privileges that could allow attackers to local privilege escalation.

References

https://access.redhat.com/errata/RHSA-2024:10384

https://access.redhat.com/security/cve/CVE-2024-52336

https://bugzilla.redhat.com/show_bug.cgi?id=2324540

For More Information

CVERecord

Common Vulnerabilityies and Exposures

Contact us to get started

CVE-2024-8114 : GITLAB COMMUNITY EDITION/ENTERPRISE EDITION UP TO 17.4.4/17.5.2/17.6.0 PERSONAL ACCESS TOKEN AUTHORIZATION

CVE-2024-8114 : GITLAB COMMUNITY EDITION/ENTERPRISE EDITION UP TO 17.4.4/17.5.2/17.6.0 PERSONAL ACCESS TOKEN AUTHORIZATION

Description An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and

CVE-2024-49052 : MICROSOFT AZURE FUNCTIONS POLICYWATCH MISSING AUTHENTICATION

CVE-2024-49052 : MICROSOFT AZURE FUNCTIONS POLICYWATCH MISSING AUTHENTICATION

Description Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network.

CVE-2024-49035 : MICROSOFT PARTNER CENTER PARTNER.MICROSOFT.COM PRIVILEGES MANAGEMENT

CVE-2024-49035 : MICROSOFT PARTNER CENTER PARTNER.MICROSOFT.COM PRIVILEGES MANAGEMENT

Description An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network. References