Weekly digest
Week 40, 2024 (30 Sep – 6 Oct)
A quiet week: only 5 new CVEs against a recent average of about 15. Of those, 1 high. No new KEV entries.
New this week, ranked by depth score
The 5 that matter most of the 5 published.
CVE-2024-47534High· 7.5Incorrect delegation lookups can make go-tuf download the wrong artifact
Incorrect delegation lookups can make go-tuf download the wrong artifact
CVE-2024-9355Medium· 6.5A vulnerability was found in Golang FIPS OpenSSL
A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false posi…
CVE-2024-9440Medium· 5.4Slim Select 2.0 versions through 2.9.0 are affected by a potential cross-site scripting vulnerability
Slim Select 2.0 versions through 2.9.0 are affected by a potential cross-site scripting vulnerability. In select.ts:createOption(), the text variable from the user-provided Options object is assigned to an innerHTML without sanitation. S…
CVE-2024-9341Medium· 5.4A flaw was found in Go
A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic …
CVE-2024-47211Medium· 5.3OpenStack Ironic fails to verify checksums of supplied image_source URLs
OpenStack Ironic fails to verify checksums of supplied image_source URLs
Most-affected vendors
By CVEs published in the period.