Weekly digest
Week 17, 2024 (22–28 Apr)
23 new CVEs this week, in line with the recent average. Of those, 2 critical and 8 high. 2 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. rancher was the most-affected vendor with 3.
New this week, ranked by depth score
The 12 that matter most of the 23 published.
CVE-2024-33668Critical· 9.1PoCAn issue was discovered in Zammad before 6.3.0
An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker could try to brute force them to upload malicious content to article drafts they have no …
CVE-2020-8559Medium· 6.8PoCPrivilege Escalation in Kubernetes
Privilege Escalation in Kubernetes
CVE-2024-32880Critical· 9.1pyLoad allows upload to arbitrary folder lead to RCE
pyLoad allows upload to arbitrary folder lead to RCE
CVE-2021-31999High· 8.8Rancher Privilege escalation vulnerability via malicious "Connection" header
Rancher Privilege escalation vulnerability via malicious "Connection" header
CVE-2021-25318High· 8.8Rancher does not properly specify ApiGroup when creating Kubernetes RBAC resources
Rancher does not properly specify ApiGroup when creating Kubernetes RBAC resources
CVE-2024-22373High· 8.1An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23
An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to a heap buffer overflow. An attacker can provide…
CVE-2021-36775High· 8.0Rancher's Failure to delete orphaned role bindings does not revoke project level access from group based authentication
Rancher's Failure to delete orphaned role bindings does not revoke project level access from group based authentication
CVE-2024-1139High· 7.7A credentials leak vulnerability was found in the cluster monitoring operator in OCP
A credentials leak vulnerability was found in the cluster monitoring operator in OCP. This issue may allow a remote attacker who has basic login credentials to check the pod manifest to discover a repository pull secret.
CVE-2024-28717High· 7.8OpenStack Storlets arbitrary code execution vulnerability
OpenStack Storlets arbitrary code execution vulnerability
CVE-2024-33663High· 7.4python-jose algorithm confusion with OpenSSH ECDSA keys
python-jose algorithm confusion with OpenSSH ECDSA keys
CVE-2024-3154High· 7.2A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation
A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.
CVE-2024-32868Medium· 6.5ZITADEL provides users the possibility to use Time-based One-Time-Password (TOTP) and One-Time-Password (OTP) through SMS and Email
ZITADEL provides users the possibility to use Time-based One-Time-Password (TOTP) and One-Time-Password (OTP) through SMS and Email. While ZITADEL already gives administrators the option to define a `Lockout Policy` with a maximum amount…
Most-affected vendors
By CVEs published in the period.