A vulnerability was found in Survey Solutions 21.09.1 (Survey Software). It has been rated as problematic. Affected by this issue is an unknown code of the file /metrics of the component Headquarters Application Endpoint. Applying the patch 99e7e8345cb98f2eda08e37976e3d3aeb49971c9 is able to eliminate this problem. The bugfix is ready for download at github.com.
Survey Solutions 21.09.1 Headquarters Application Endpoint /metrics information disclosure
- Virtual Patching
- October 5, 2021
- 10:05 am
CVE-2024-6121 : NI SYSTEMLINK SERVER/FLEXLOGGER REDIS VULNERABLE THIRD-PARTY COMPONENT
Description An out-of-date version of Redis shipped with NI SystemLink Server is susceptible to multiple vulnerabilities, including CVE-2022-24834. This affects
CVE-2024-40634 : ARGOPROJ ARGO-CD UP TO 2.9.19/2.10.14/2.11.5 /API/WEBHOOK RESOURCE CONSUMPTION
Description Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. This report details a security vulnerability in Argo
CVE-2024-39685 : FISHAUDIO BERT-VITS2 UP TO 2.3 RESAMPLE DATA_DIR OS COMMAND INJECTION
Description Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is used directly in