8.3
CVE-2024-45041 - External Secrets Operator vulnerable to privilege escalation
External Secrets Operator is a Kubernetes operator that integrates external secret management systems. The external-secrets has a deployment called default-external-secrets-cert-controller, which is bound with a same-name ClusterRole. This ClusterRole has "get/list" verbs of secrets resources. It aβ¦
4.8
CVE-2024-8373 - AngularJS improper sanitization in '<source>' element
Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects all versβ¦
4.8
CVE-2024-8372 - AngularJS improper sanitization in 'srcset' attribute
Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects AngularJS versions 1.3.0-rc.4 and β¦
9.7
CVE-2024-40643 - Joplin has a parsing error leading to Cross-site Scripting (XSS)
Joplin is a free, open source note taking and to-do application. Joplin fails to take into account that "<" followed by a non letter character will not be considered html. As such it is possible to do an XSS by putting an "illegal" tag within a tag.
0.0
CVE-2024-45804 -
This CVE is a duplicate of another CVE.
7.1
CVE-2024-7015 - Improper Authentication in Profelis Informatics and Consulting's PassBOX
Missing Authentication for Critical Function vulnerability in Profelis Informatics and Consulting PassBox allows Authentication Abuse.This issue affects PassBox: before v1.2.
4.8
CVE-2024-7318 - Keycloak-core: one time passcode (otp) is valid longer than expiration timeseverity
A vulnerability was found in Keycloak. Expired OTP codes are still usable when using FreeOTP when the OTP token period is set to 30 seconds (default). Instead of expiring and deemed unusable around 30 seconds in, the tokens are valid for an additional 30 seconds totaling 1 minute. A one time passcβ¦
6.1
CVE-2024-7260 - Keycloak-core: open redirect on account page
An open redirect vulnerability was found in Keycloak. A specially crafted URL can be constructed where the referrer and referrer_uri parameters are made to trick a user to visit a malicious webpage. A trusted URL can trick users and automation into believing that the URL is safe, when, in fact, it β¦
7.1
CVE-2024-7341 - Wildfly-elytron: org.keycloak/keycloak-services: session fixation in elytron saml adapters
A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, even when the turnOffChangeSessionIdOnLogin option is configured. This flaw allows an attacker who hijacks the current session before authenticationβ¦
6.3
CVE-2024-6572 - Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and fβ¦
Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem' in Checkmk before Checkmk 2.3.0p15, 2.2.0p33, 2.1.0p48 and 2.0.0 (EOL) allows man-in-the-middle attackers to intercept traffic