Author: Angelo Barbosa

CVE-2024-28860 | Cilium up to 1.13.14/1.14.8/1.15.2 ESP Sequence Number inadequate encryption (GHSA-pwqm-x5x6-5586)

A vulnerability classified as problematic has been found in Cilium up to 1.13.14/1.14.8/1.15.2. Affected is an unknown function of the component ESP Sequence Number Handler. The manipulation leads to inadequate encryption strength. This vulnerability is traded as CVE-2024-28860. The attack can only be done within the local network. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-28247 | pi-hole up to 5.17.3 information disclosure

A vulnerability was found in pi-hole up to 5.17.3. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to information disclosure. The identification of this vulnerability is CVE-2024-28247. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-28233 | JupyterHub up to 4.0.x cross site scripting

A vulnerability was found in JupyterHub up to 4.0.x. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting. This vulnerability was named CVE-2024-28233. The attack can be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-3024 | appneta tcpreplay up to 4.4.4 get.c get_layer4_v6 heap-based overflow

A vulnerability was found in appneta tcpreplay up to 4.4.4. It has been classified as problematic. This affects the function get_layer4_v6 of the file /tcpreplay/src/common/get.c. The manipulation leads to heap-based buffer overflow. This vulnerability is uniquely identified as CVE-2024-3024. Attacking locally is a requirement. Furthermore, there is an exploit available. The vendor was contacted early about this disclosure but did not respond in any...

Read More

CVE-2024-28085 | util-linux wall term-utils/wall.c injection

A vulnerability was found in util-linux and classified as problematic. Affected by this issue is some unknown functionality of the file term-utils/wall.c of the component wall. The manipulation leads to injection. This vulnerability is handled as CVE-2024-28085. Local access is required to approach this attack. Furthermore, there is an exploit...

Read More