Weekly digest
Week 6, 2024 (5–11 Feb)
21 new CVEs this week, in line with the recent average. Severity skewed high: 6 critical and 8 high, 67% of the total. 3 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. clearml was the most-affected vendor with 3.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 12 that matter most of the 21 published.
CVE-2024-21762Critical· 9.8CISA KEV0dayPoCA out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7…
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7…
CVE-2024-24590High· 8.8PoCAllegro AI ClearML vulnerable to deserialization of untrusted data
Allegro AI ClearML vulnerable to deserialization of untrusted data
CVE-2024-21490High· 7.5PoCThis affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0
This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. Wit…
CVE-2024-25675Critical· 9.8An issue was discovered in MISP before 2.4.184
An issue was discovered in MISP before 2.4.184. A client does not need to use POST to start an export generation process. This is related to app/Controller/JobsController.php and app/View/Events/export.ctp.
CVE-2024-25674Critical· 9.8An issue was discovered in MISP before 2.4.184
An issue was discovered in MISP before 2.4.184. Organisation logo upload is insecure because of a lack of checks for the file extension and MIME type.
CVE-2024-24811Critical· 9.8SQLAlchemyDA unauthenticated arbitrary SQL query execution
SQLAlchemyDA unauthenticated arbitrary SQL query execution
CVE-2024-24563Critical· 9.8Vyper negative array index bounds checks
Vyper negative array index bounds checks
CVE-2024-24825Critical· 9.1DIRAC's TokenManager does not check permissions on cached tokens
DIRAC's TokenManager does not check permissions on cached tokens
CVE-2024-24591High· 8.8Allegro AI ClearML path traversal vulnerability
Allegro AI ClearML path traversal vulnerability
CVE-2024-1314High· 8.6Kinto Attachment's attachments can be replaced on read-only records
Kinto Attachment's attachments can be replaced on read-only records
CVE-2023-32192High· 8.3Rancher API Server Cross-site Scripting Vulnerability
Rancher API Server Cross-site Scripting Vulnerability
CVE-2024-24680High· 7.5An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2
An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with very long strings.
Most-affected vendors
By CVEs published in the period.