Weekly digest
Week 38, 2024 (16–22 Sep)
A heavy week: 25 new CVEs, well above the recent average of about 14. Severity skewed high: 3 critical and 10 high, 52% of the total. 2 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. linux was the most-affected vendor with 3.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 12 that matter most of the 25 published.
CVE-2024-8698High· 7.7PoCA flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class
A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly determines whether a SAML signature is for the full document or only for specific assertions based on the position o…
CVE-2024-45496Critical· 9.9A flaw was found in OpenShift
A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges in the OpenShift Container Platform's build process. During the build initialization step, the git-clone container is run with a privileged securit…
CVE-2024-7387Critical· 9.1A flaw was found in openshift/builder
A flaw was found in openshift/builder. This vulnerability allows command injection via path traversal, where a malicious user can execute arbitrary commands on the OpenShift node running the builder container. When using the “Docker” str…
CVE-2024-44004Critical· 9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows SQL Injection. This issue affects WPCargo Track & Trace: before 8.0.4.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows SQL Injection. This issue affects WPCargo Track & Trace: before 8.0.4.
CVE-2024-35515High· 8.8sqlitedict insecure deserialization vulnerability
sqlitedict insecure deserialization vulnerability
CVE-2024-45858High· 8.8Guardrails has an arbitrary code execution vulnerability
Guardrails has an arbitrary code execution vulnerability
CVE-2024-8883Medium· 6.1PoCA misconfiguration flaw was found in Keycloak
A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as author…
CVE-2024-46786High· 7.8In the Linux kernel, the following vulnerability has been resolved: fscache: delete fscache_cookie_lru_timer when fscache exits to avoid UAF The fscache_cookie_lru_timer is initialized when the fscache module is inserted, but is not de…
In the Linux kernel, the following vulnerability has been resolved: fscache: delete fscache_cookie_lru_timer when fscache exits to avoid UAF The fscache_cookie_lru_timer is initialized when the fscache module is inserted, but is not de…
CVE-2024-46754High· 7.8⚖ disputedIn the Linux kernel, the following vulnerability has been resolved: bpf: Remove tst_run from lwt_seg6local_prog_ops. The syzbot reported that the lwt_seg6 related BPF ops can be invoked via bpf_test_run() without without entering input…
In the Linux kernel, the following vulnerability has been resolved: bpf: Remove tst_run from lwt_seg6local_prog_ops. The syzbot reported that the lwt_seg6 related BPF ops can be invoked via bpf_test_run() without without entering input…
CVE-2024-46741High· 7.8⚖ disputedIn the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Fix double free of 'buf' in error path smatch warning: drivers/misc/fastrpc.c:1926 fastrpc_req_mmap() error: double free of 'buf' In fastrpc_req_mmap()…
In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Fix double free of 'buf' in error path smatch warning: drivers/misc/fastrpc.c:1926 fastrpc_req_mmap() error: double free of 'buf' In fastrpc_req_mmap()…
CVE-2024-45601High· 7.5Mesop has a local file Inclusion via static file serving functionality
Mesop has a local file Inclusion via static file serving functionality
CVE-2024-8768High· 7.5vLLM denial of service vulnerability
vLLM denial of service vulnerability
Most-affected vendors
By CVEs published in the period.