Weekly digest
Week 16, 2024 (15–21 Apr)
31 new CVEs this week, in line with the recent average. Severity skewed high: 1 critical and 16 high, 55% of the total. 3 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. mlflow was the most-affected vendor with 5.
New this week, ranked by depth score
The 12 that matter most of the 31 published.
CVE-2024-1561High· 7.5PoCgradio vulnerable to Path Traversal
gradio vulnerable to Path Traversal
CVE-2024-1483High· 7.5PoCmlflow Path Traversal vulnerability
mlflow Path Traversal vulnerability
CVE-2024-28056Critical· 9.8Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects
Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authentication component is removed from an Amplify project, a Condition property is removed but "…
CVE-2024-26822High· 8.7In the Linux kernel, the following vulnerability has been resolved: smb: client: set correct id, uid and cruid for multiuser automounts When uid, gid and cruid are not specified, we need to dynamically set them into the filesystem cont…
In the Linux kernel, the following vulnerability has been resolved: smb: client: set correct id, uid and cruid for multiuser automounts When uid, gid and cruid are not specified, we need to dynamically set them into the filesystem cont…
CVE-2024-1183Medium· 6.5PoCgradio Server-Side Request Forgery vulnerability
gradio Server-Side Request Forgery vulnerability
CVE-2024-1135High· 8.2Request smuggling leading to endpoint restriction bypass in Gunicorn
Request smuggling leading to endpoint restriction bypass in Gunicorn
CVE-2024-1132High· 8.1A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect
A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information withi…
CVE-2024-1560High· 8.1mlflow vulnerable to Path Traversal
mlflow vulnerable to Path Traversal
CVE-2024-26823High· 7.8In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Restore quirk probing for ACPI-based systems While refactoring the way the ITSs are probed, the handling of quirks applicable to ACPI-based platfor…
In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Restore quirk probing for ACPI-based systems While refactoring the way the ITSs are probed, the handling of quirks applicable to ACPI-based platfor…
CVE-2024-4340High· 7.5sqlparse parsing heavily nested list leads to Denial of Service
sqlparse parsing heavily nested list leads to Denial of Service
CVE-2024-31580High· 7.5PyTorch heap buffer overflow vulnerability
PyTorch heap buffer overflow vulnerability
CVE-2024-1249High· 7.4A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages
A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly i…
Most-affected vendors
By CVEs published in the period.