CVE-2024-21481
Lun, 05/08/2024 – 15:15
CVE-2024-21481
CVE-2024-21481
Lun, 05/08/2024 – 15:15
CVE-2024-21481
CVE-2024-21479
Lun, 05/08/2024 – 15:15
CVE-2024-21479
CVE-2024-21467
Lun, 05/08/2024 – 15:15
CVE-2024-21467
CVE-2024-36448
Lun, 05/08/2024 – 10:15
CVE-2024-36448
This issue affects Apache IoTDB Workbench: from 0.13.0.
As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.
NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2024-40096
Lun, 05/08/2024 – 10:15
CVE-2024-40096
CVE-2024-4607
Lun, 05/08/2024 – 12:15
CVE-2024-4607
CVE-2024-2937
Lun, 05/08/2024 – 12:15
CVE-2024-2937
CVE-2024-6472
Lun, 05/08/2024 – 13:15
CVE-2024-6472
Signed macros are scripts that have been digitally signed by the
developer using a cryptographic signature. When a document with a signed
macro is opened a warning is displayed by LibreOffice before the macro
is executed.
Previously if verification failed the user could fail to understand the failure and choose to enable the macros anyway.
This issue affects LibreOffice: from 24.2 before 24.2.5.
CVE-2024-42447
Lun, 05/08/2024 – 08:15
CVE-2024-42447
This issue affects Apache Airflow Providers FAB: 1.2.1 (when used with Apache Airflow 2.9.3) and FAB 1.2.0 for all Airflow versions. The FAB provider prevented the user from logging out.
* FAB provider 1.2.1 only affected Airflow 2.9.3 (earlier and later versions of Airflow are not affected)
* FAB provider 1.2.0 affected all versions of Airflow.
Users who run Apache Airflow 2.9.3 are recommended to upgrade to Apache Airflow Providers FAB version 1.2.2 which fixes the issue.
Users who run Any Apache Airflow version and have FAB provider 1.2.0 are recommended to upgrade to Apache Airflow Providers FAB version 1.2.2 which fixes the issue.
Also upgrading Apache Airflow to latest version available is recommended.
Note: Early version of Airflow reference container images of Airflow 2.9.3 and constraint files contained FAB provider 1.2.1 version, but this is fixed in updated versions of the images.
Users are advised to pull the latest Airflow images or reinstall FAB provider according to the current constraints.
CVE-2024-38856
Lun, 05/08/2024 – 09:15
CVE-2024-38856
This issue affects Apache OFBiz: through 18.12.14.
Users are recommended to upgrade to version 18.12.15, which fixes the issue.
Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check user's permissions because they rely on the configuration of their endpoints).