Weekly digest
Week 1, 2025 (30 Dec – 5 Jan)
A quiet week: only 3 new CVEs against a recent average of about 17. Of those, 1 high. No new KEV entries.
New this week, ranked by depth score
The 3 that matter most of the 3 published.
CVE-2024-45497High· 7.6A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the build pod
A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the build pod. This file contains sensitive credenti…
CVE-2024-8447Medium· 5.9A security issue was discovered in the LRA Coordinator component of Narayana
A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution time of approximately 2 seconds occurs. If Join is called with the same LRA ID within that timeframe, the applicatio…
CVE-2024-52294Medium· 4.3khoj has an IDOR in subscription management allows unauthorized subscription modifications
khoj has an IDOR in subscription management allows unauthorized subscription modifications
Most-affected vendors
By CVEs published in the period.