CVE-2024-24824

Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, arbitrary classes can be loaded and instantiated using a HTTP PUT request to the / ...

Continue Reading
Rancher permissions on ‘namespaces’ in any API group grants ‘edit’ permissions on namespaces in ‘core’

Impact A vulnerability has been identified when granting a create or * global role for a resource type of "namespaces"; no matter the API group, the subject will receive * permission ...

Continue Reading
Rancher permissions on ‘namespaces’ in any API group grants ‘edit’ permissions on namespaces in ‘core’

Impact A vulnerability has been identified when granting a create or * global role for a resource type of "namespaces"; no matter the API group, the subject will receive * permission ...

Continue Reading
Rancher ‘Audit Log’ leaks sensitive information

Impact A vulnerability has been identified which may lead to sensitive data being leaked into Rancher's audit logs. Rancher Audit Logging is an opt-in feature, only deployments that have it enabl ...

Continue Reading
Rancher ‘Audit Log’ leaks sensitive information

Impact A vulnerability has been identified which may lead to sensitive data being leaked into Rancher's audit logs. Rancher Audit Logging is an opt-in feature, only deployments that have it enabl ...

Continue Reading
Norman API Cross-site Scripting Vulnerability

Impact A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in Norman's public API endpoint can be exploited. This can lead to an attacker exploiting the vulner ...

Continue Reading
Norman API Cross-site Scripting Vulnerability

Impact A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in Norman's public API endpoint can be exploited. This can lead to an attacker exploiting the vulner ...

Continue Reading
Rancher API Server Cross-site Scripting Vulnerability

Impact A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in the API Server's public API endpoint can be exploited. This can lead to an attacker exploiting th ...

Continue Reading

Back to Main

Subscribe for the latest news: