CVE-2024-8640 : GITLAB ENTERPRISE EDITION UP TO 17.1.6/17.2.4/17.3.1 CUBE SERVER COMMAND INJECTION

Description

An issue has been discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. Due to incomplete input filtering, it was possible to inject commands into a connected Cube server.

References

https://gitlab.com/gitlab-org/gitlab/-/issues/486213

https://hackerone.com/reports/2687770

For More Information

CVERecord

Common Vulnerabilityies and Exposures

Contact us to get started

CVE-2024-57903 : LINUX KERNEL UP TO 5.15.175/6.1.123/6.6.69/6.12.8 IN_ATOMIC STACK-BASED OVERFLOW

CVE-2024-57903 : LINUX KERNEL UP TO 5.15.175/6.1.123/6.6.69/6.12.8 IN_ATOMIC STACK-BASED OVERFLOW

Description In the Linux kernel, the following vulnerability has been resolved: net: restrict SO_REUSEPORT to inet sockets After blamed commit,

CVE-2024-12867 : ARCTIC SECURITY ARCTIC HUB UP TO 5.5.1872 CONFIGURATION SERVER-SIDE REQUEST FORGERY

CVE-2024-12867 : ARCTIC SECURITY ARCTIC HUB UP TO 5.5.1872 CONFIGURATION SERVER-SIDE REQUEST FORGERY

Description Server-Side Request Forgery in URL Mapper in Arctic Security’s Arctic Hub versions 3.0.1764-5.6.1877 allows an unauthenticated remote attacker to

CVE-2024-12840 : RED HAT SATELLITE HTTP PROXY SERVER-SIDE REQUEST FORGERY

CVE-2024-12840 : RED HAT SATELLITE HTTP PROXY SERVER-SIDE REQUEST FORGERY

Description A server-side request forgery exists in Satellite. When a PUT HTTP request is made to /http_proxies/test_connection, when supplied with