A vulnerability, which was classified as problematic, has been found in actionpack Gem up to 5.2.4.5/5.2.5/6.0.3.6/6.1.3.1 on Ruby (Ruby Gem). Affected by this issue is the function authenticate_or_request_with_http_token/authenticate_with_http_token
of the component Action Controller. Upgrading to version 5.2.4.6, 5.2.6, 6.0.3.7 or 6.1.3.2 eliminates this vulnerability.
actionpack Gem up to 5.2.4.5/5.2.5/6.0.3.6/6.1.3.1 on Ruby Action Controller resource consumption
- Virtual Patching
- June 12, 2021
- 3:56 am
CVE-2024-31869 : APACHE AIRFLOW UP TO 2.8.4 CONFIGURATION UI PAGE INFORMATION DISCLOSURE
Description Airflow versions 2.7.0 through 2.8.4 have a vulnerability that allows an authenticated user to see sensitive provider configuration via
CVE-2024-24856 : LINUX KERNEL UP TO 6.8 ACPI_ALLOCATE_ZEROED NULL POINTER DEREFERENCE
Description The memory allocation function ACPI_ALLOCATE_ZEROED does not guarantee a successful allocation, but the subsequent code directly dereferences the pointer
CVE-2024-2912 : BENTOML FRAMEWORK UP TO 1.2.4 POST REQUEST INSECURE DEFAULT INITIALIZATION OF RESOURCE
Description An insecure deserialization vulnerability exists in the BentoML framework, allowing remote code execution (RCE) by sending a specially crafted