Weekly digest
Week 46, 2024 (11–17 Nov)
A busier-than-usual week with 17 new CVEs (recent average about 14). Of those, 2 high. One arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. calibreweb was the most-affected vendor with 3.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 12 that matter most of the 17 published.
CVE-2024-49039High· 8.8CISA KEV0dayPoCWindows Task Scheduler Elevation of Privilege Vulnerability
Windows Task Scheduler Elevation of Privilege Vulnerability
CVE-2024-45784High· 7.5Apache Airflow: Sensitive configuration values are not masked in the logs by default
Apache Airflow: Sensitive configuration values are not masked in the logs by default
CVE-2023-34049Medium· 6.7Salt preflight script could be attacker controlled
Salt preflight script could be attacker controlled
CVE-2024-49393Medium· 6.5In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message con…
In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message con…
CVE-2021-3988Medium· 6.1Cross-site Scripting (XSS) - DOM in janeczku/calibre-web
Cross-site Scripting (XSS) - DOM in janeczku/calibre-web
CVE-2023-6110Medium· 5.5OpenStack improperly deletes access rules
OpenStack improperly deletes access rules
CVE-2021-3987Medium· 5.4Improper Access Control in janeczku/calibre-web
Improper Access Control in janeczku/calibre-web
CVE-2024-4311Medium· 5.4Missing ratelimit on passwrod resets in zenml
Missing ratelimit on passwrod resets in zenml
CVE-2024-11079Medium· 5.5A flaw was found in Ansible-Core
A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote da…
RUSTSEC-2024-0401Medium· 5.3Denial of service because of stack overflow with malicious decompression input
Denial of service because of stack overflow with malicious decompression input
CVE-2024-49395Medium· 5.3In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.
In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.
CVE-2024-49394Medium· 5.3In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original sender.
In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original sender.
Most-affected vendors
By CVEs published in the period.