Weekly digest
Week 50, 2024 (9–15 Dec)
18 new CVEs this week, in line with the recent average. Of those, 4 critical and 4 high. 5 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. apache-superset was the most-affected vendor with 4.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 12 that matter most of the 18 published.
CVE-2024-55956Critical· 9.8CISA KEVPoCIn Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Aut…
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Aut…
CVE-2024-55587High· 8.8PoCpython-libarchive directory traversal
python-libarchive directory traversal
CVE-2024-53866Critical· 9.8The package manager pnpm prior to version 9.15.0 seems to mishandle overrides and global cache: Overrides from one workspace leak into npm metadata saved in global cache; npm metadata from global cache affects other workspaces; and insta…
The package manager pnpm prior to version 9.15.0 seems to mishandle overrides and global cache: Overrides from one workspace leak into npm metadata saved in global cache; npm metadata from global cache affects other workspaces; and insta…
CVE-2024-53947Critical· 9.8Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions
Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions
CVE-2024-55550Low· 2.7CISA KEVPoCMitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization
Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to…
CVE-2024-40583Critical· 9.1Pentaminds CuroVMS v2.0.1 was discovered to contain exposed credentials.
Pentaminds CuroVMS v2.0.1 was discovered to contain exposed credentials.
CVE-2024-52059High· 7.8Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Heap-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in RTI Connext Professional (Security Plugins) allows Overflow Variables and Tags
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Heap-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in RTI Connext Professional (Security Plugins) allows Overflow Variables and Tags. This issu…
CVE-2024-12397High· 7.4A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests
A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoo…
CVE-2024-40582High· 7.5Pentaminds CuroVMS v2.0.1 was discovered to contain exposed sensitive information.
Pentaminds CuroVMS v2.0.1 was discovered to contain exposed sensitive information.
CVE-2024-55890MediumPoCD-Tale allows Remote Code Execution through the Custom Filter Input
D-Tale allows Remote Code Execution through the Custom Filter Input
CVE-2024-55633Medium· 6.5Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access
Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access
CVE-2024-53949Medium· 6.5Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled
Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled
Most-affected vendors
By CVEs published in the period.