CVE-2024-7798
Jue, 15/08/2024 – 00:15
CVE-2024-7798
CVE-2024-7798
Jue, 15/08/2024 – 00:15
CVE-2024-7798
CVE-2024-7800
Jue, 15/08/2024 – 00:15
CVE-2024-7800
CVE-2024-7799
Jue, 15/08/2024 – 00:15
CVE-2024-7799
CVE-2024-7808
Jue, 15/08/2024 – 01:15
CVE-2024-7808
CVE-2024-7797
Jue, 15/08/2024 – 00:15
CVE-2024-7797
*** Pendiente de traducción *** In HashiCorp Nomad and Nomad Enterprise from 0.6.1 up to 1.16.13, 1.7.10, and 1.8.2, the archive unpacking process is vulnerable to writes outside the allocation directory during migration of allocation directories when multiple archive headers target the same file. This vulnerability, CVE-2024-7625, is fixed in Nomad 1.6.14, 1.7.11, and 1.8.3. Access or compromise of the Nomad client agent at the source allocation first is a prerequisite for leveraging this vulnerability.
*** Pendiente de traducción *** CVE-2024-7507 IMPACT
A denial-of-service vulnerability exists in the affected products. This vulnerability occurs when a malformed PCCC message is received, causing a fault in the controller.
*** Pendiente de traducción *** CVE-2024-6078 IMPACT
An improper authentication vulnerability exists in the affected product, which could allow a malicious user to generate cookies for any user ID without the use of a username or password. If exploited, a malicious user could take over the account of a legitimate user. The malicious user would be able to view and modify data stored in the cloud.
CVE-2024-42360
Mié, 14/08/2024 – 20:15
CVE-2024-42360
*** Pendiente de traducción *** CVE-2024-40620 IMPACT
A vulnerability exists in the affected product due to lack of encryption of sensitive information. The vulnerability results in data being sent between the Console and the Dashboard without encryption, which can be seen in the logs of proxy servers, potentially impacting the data's confidentiality.