10
CVE-2024-29202 - JumpServer vulnerable to Jinja2 template injection in Ansible leads to RCE in Celery
JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can exploit a Jinja2 template injection vulnerability in JumpServer's Ansible to execute arbitrary code within the Celery container. Since the Celery container runs with root privileges and hβ¦
10
CVE-2024-29201 - JumpServer's insecure Ansible playbook validation leads to RCE in Celery
JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can bypass the input validation mechanism in JumpServer's Ansible to execute arbitrary code within the Celery container. Since the Celery container runs with root privileges and has database β¦
4.6
CVE-2024-29020 - JumpServer allows nn authorized attacker to get sensitive information in playbook files when playboβ¦
JumpServer is an open source bastion host and an operation and maintenance security audit system. An authorized attacker can obtain sensitive information contained within playbook files if they manage to learn the playbook_id of another user. This breach of confidentiality can lead to information dβ¦
4.6
CVE-2024-29024 - JumpServer Direct Object Reference (IDOR) Vulnerability in File Manager Bulk Transfer Functionality
JumpServer is an open source bastion host and an operation and maintenance security audit system. An authenticated user can exploit the Insecure Direct Object Reference (IDOR) vulnerability in the file manager's bulk transfer by manipulating job IDs to upload malicious files, potentially compromisβ¦
8.4
CVE-2024-23537 - Apache Fineract: Under certain circumstances, this vulnerability allowed users, without specific peβ¦
Improper Privilege Management vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.9.0, which fixes the issue.
9.9
CVE-2024-23538 - Apache Fineract: Under certain system configurations, the sqlSearch parameter was vulnerable to SQLβ¦
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.8.5 or 1.9.0, which fix the issue.
8.3
CVE-2024-23539 - Apache Fineract: Under certain system configurations, the sqlSearch parameter for specific endpointβ¦
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.8.5 or 1.9.0, which fix the issue.
3.5
CVE-2024-3081 - EasyCorp EasyAdmin Autocomplete autocomplete.js cross site scripting
A vulnerability was found in EasyCorp EasyAdmin up to 4.8.9. It has been declared as problematic. Affected by this vulnerability is the function Autocomplete of the file assets/js/autocomplete.js of the component Autocomplete. The manipulation of the argument item leads to cross site scripting. Theβ¦
5.9
CVE-2024-28867 - Swift Prometheus un-sanitized metric name or labels can be used to take over exported metrics
Swift Prometheus is a Swift client for the Prometheus monitoring system, supporting counters, gauges and histograms. In code which applies _un-sanitized string values into metric names or labels_, an attacker could make use of this and send a `?lang` query parameter containing newlines, `}` or simβ¦
6.5
CVE-2024-30508 - WordPress WP Hotel Booking plugin <= 2.0.9.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in ThimPress WP Hotel Booking.This issue affects WP Hotel Booking: from n/a through 2.0.9.2.