3.1

CVSS3.1

CVE-2024-45099 - IBM Security ReaQta cross-site scripting

IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

📅 Published: Nov. 14, 2024, 12:02 p.m. 🔄 Last Modified: Nov. 16, 2024, 12:11 a.m.

7.4

CVSS3.1

CVE-2022-31668 - User permission validation failure and disclosure of P2P preheat execution logs

Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p preheat policy with an id that belongs to a project that the currently authenticated user doesn't have access to, the attacker could modify p2p preheat policies configured in other…

📅 Published: Nov. 14, 2024, 11:56 a.m. 🔄 Last Modified: Nov. 19, 2024, 3:25 p.m.

6.4

CVSS3.1

CVE-2022-31667 - Harbor fails to validate the user permissions when updating a robot account

Harbor fails to validate the user permissions when updating a robot account that belongs to a project that the authenticated user doesn’t have access to.  By sending a request that attempts to update a robot account, and specifying a robot account id and robot account name that belongs to a differ…

📅 Published: Nov. 14, 2024, 11:50 a.m. 🔄 Last Modified: Nov. 19, 2024, 3:25 p.m.

5.6

CVSS3.1

CVE-2024-45670 - IBM Security SOAR weak password recovery mechanism

IBM Security SOAR 51.0.1.0 and earlier contains a mechanism for users to recover or change their passwords without knowing the original password, but the user account must be compromised prior to the weak recovery mechanism.

📅 Published: Nov. 14, 2024, 11:50 a.m. 🔄 Last Modified: Nov. 16, 2024, 12:24 a.m.

6.4

CVSS3.1

CVE-2022-31669 - Harbor fails to validate the user permissions when updating tag immutability policies

Harbor fails to validate the user permissions when updating tag immutability policies.  By sending a request to update a tag immutability policy with an id that belongs to a project that the currently authenticated user doesn’t have access to, the attacker could modify tag immutability policies co…

📅 Published: Nov. 14, 2024, 11:48 a.m. 🔄 Last Modified: Nov. 19, 2024, 3:20 p.m.

7.7

CVSS3.1

CVE-2022-31670 - Harbor fails to validate the user permissions when updating tag retention policies

Harbor fails to validate the user permissions when updating tag retention policies.  By sending a request to update a tag retention policy with an id that belongs to a project that the currently authenticated user doesn’t have access to, the attacker could modify tag retention policies configured …

📅 Published: Nov. 14, 2024, 11:45 a.m. 🔄 Last Modified: Nov. 19, 2024, 3:20 p.m.

7.4

CVSS3.1

CVE-2022-31671 - Harbor fails to validate the user permissions when reading and updating job execution logs through …

Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs. By sending a request that attempts to read/update P2P preheat execution logs and specifying different job IDs, malicious authenticated users could read all the job logs sto…

📅 Published: Nov. 14, 2024, 11:42 a.m. 🔄 Last Modified: Nov. 19, 2024, 3:40 p.m.

7.7

CVSS3.1

CVE-2022-31666 - Harbor fails to validate user permissions while Viewing, updating and deleting Webhook policies

Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of other users.  The attacker could modify Webhook policies configured in other projects.

📅 Published: Nov. 14, 2024, 11:32 a.m. 🔄 Last Modified: July 12, 2025, 10:44 p.m.

5.4

CVSS3.1

CVE-2024-8180 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. Improper output encoding could lead to XSS if CSP is not enabled.

📅 Published: Nov. 14, 2024, 11:02 a.m. 🔄 Last Modified: Dec. 13, 2024, 1:26 a.m.

8.5

CVSS3.1

CVE-2024-9693 - Incorrect Authorization in GitLab

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.0 prior to 17.3.7, starting from 17.4 prior to 17.4.4, and starting from 17.5 prior to 17.5.2, which could have allowed unauthorized access to the Kubernetes agent in a cluster under specific configurations.

📅 Published: Nov. 14, 2024, 11:02 a.m. 🔄 Last Modified: Nov. 26, 2024, 1:57 a.m.
Total resulsts: 349182
Page 7879 of 34,919
« previous page » next page
Filters