Author: Angelo Barbosa

CVE-2024-29887 | Serverpod up to 1.2.5 serverpod_client certificate validation (GHSA-h6x7-r5rg-x5fw)

A vulnerability, which was classified as problematic, has been found in Serverpod up to 1.2.5. Affected by this issue is some unknown functionality of the component serverpod_client. The manipulation leads to improper certificate validation. This vulnerability is handled as CVE-2024-29887. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-29891 | Zitadel up to 2.48.2 Avatar Image unrestricted upload

A vulnerability classified as critical was found in Zitadel up to 2.48.2. Affected by this vulnerability is an unknown functionality of the component Avatar Image Handler. The manipulation leads to unrestricted upload. This vulnerability is known as CVE-2024-29891. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-28860 | Cilium up to 1.13.14/1.14.8/1.15.2 ESP Sequence Number inadequate encryption (GHSA-pwqm-x5x6-5586)

A vulnerability classified as problematic has been found in Cilium up to 1.13.14/1.14.8/1.15.2. Affected is an unknown function of the component ESP Sequence Number Handler. The manipulation leads to inadequate encryption strength. This vulnerability is traded as CVE-2024-28860. The attack can only be done within the local network. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-28247 | pi-hole up to 5.17.3 information disclosure

A vulnerability was found in pi-hole up to 5.17.3. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to information disclosure. The identification of this vulnerability is CVE-2024-28247. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-28233 | JupyterHub up to 4.0.x cross site scripting

A vulnerability was found in JupyterHub up to 4.0.x. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting. This vulnerability was named CVE-2024-28233. The attack can be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More