Overview : |
SuiteCRM 7.10.x versions prior to 7.10.21 and 7.11.x versions prior to 7.11.9 allow SQL Injection. |
Affected Product(s) : |
|
Vulnerability Details : |
||||
Solution : Upgrade to SuiteCRM patched version |
Kubernetes WAF Ingress Controller for your Cloud Container and Microservices security . OWASP Top 10 Security for your k8 Docker deployments and API from Bots and Attacks
Overview : |
SuiteCRM 7.10.x versions prior to 7.10.21 and 7.11.x versions prior to 7.11.9 allow SQL Injection. |
Affected Product(s) : |
|
Vulnerability Details : |
||||
Solution : Upgrade to SuiteCRM patched version |
Description zot is a production-ready vendor-neutral OCI image registry. The group data stored for users in the boltdb database (meta.db) is an append-list so group revocations/removals are ignored in the API. SetUserGroups is alled on login, but instead of replacing the group memberships, they are appended. This may be due to some conflict with the […]
Description Server-Side Request Forgery in URL Mapper in Arctic Security’s Arctic Hub versions 3.0.1764-5.6.1877 allows an unauthenticated remote attacker to exfiltrate and modify configurations and data. References https://www.arcticsecurity.com/security/vulnerability-note-2024-12-20 For More Information CVERecord
Description A server-side request forgery exists in Satellite. When a PUT HTTP request is made to /http_proxies/test_connection, when supplied with the http_proxies variable set to localhost, the attacker can fetch the localhost banner. References https://access.redhat.com/security/cve/CVE-2024-12840 https://bugzilla.redhat.com/show_bug.cgi?id=2333494 For More Information CVERecord