USN-7099-1: OpenJDK 21 vulnerabilities

Read Time:33 Second

Andy Boothe discovered that the Networking component of OpenJDK 21 did not
properly handle access under certain circumstances. An unauthenticated
attacker could possibly use this issue to cause a denial of service.
(CVE-2024-21208)

It was discovered that the Hotspot component of OpenJDK 21 did not properly
handle vectorization under certain circumstances. An unauthenticated
attacker could possibly use this issue to access unauthorized resources
and expose sensitive information. (CVE-2024-21210, CVE-2024-21235)

It was discovered that the Serialization component of OpenJDK 21 did not
properly handle deserialization under certain circumstances. An
unauthenticated attacker could possibly use this issue to cause a denial
of service. (CVE-2024-21217)

Read More

lemonldap-ng-2.20.1-1.el9

Read Time:25 Second

FEDORA-EPEL-2024-18565c82f2

Packages in this update:

lemonldap-ng-2.20.1-1.el9

Update description:

Update to lemonldap-ng 2.20.1:

[Security] Adaptative Authentication Rules triggered by “Refresh my rights”
[Security] XSS in upgradeSession / forceUpgrade pages
downloadSamlMetadata missing from packages in 2.20.0
CDA request for id is not valid
“This application is not known” when trying to access a federation application with empty RelayState
SAML regression in 2.20.0
Internal error when captcha rule isn’t validated

Read More

lemonldap-ng-2.20.1-1.el8

Read Time:25 Second

FEDORA-EPEL-2024-c35d90e5f2

Packages in this update:

lemonldap-ng-2.20.1-1.el8

Update description:

Update to lemonldap-ng 2.20.1:

[Security] Adaptative Authentication Rules triggered by “Refresh my rights”
[Security] XSS in upgradeSession / forceUpgrade pages
downloadSamlMetadata missing from packages in 2.20.0
CDA request for id is not valid
“This application is not known” when trying to access a federation application with empty RelayState
SAML regression in 2.20.0
Internal error when captcha rule isn’t validated

Read More

lemonldap-ng-2.20.1-1.fc41

Read Time:24 Second

FEDORA-2024-7bc1df53fc

Packages in this update:

lemonldap-ng-2.20.1-1.fc41

Update description:

Update to lemonldap-ng 2.20.1:

[Security] Adaptative Authentication Rules triggered by “Refresh my rights”
[Security] XSS in upgradeSession / forceUpgrade pages
downloadSamlMetadata missing from packages in 2.20.0
CDA request for id is not valid
“This application is not known” when trying to access a federation application with empty RelayState
SAML regression in 2.20.0
Internal error when captcha rule isn’t validated

Read More

lemonldap-ng-2.20.1-1.fc39

Read Time:24 Second

FEDORA-2024-d0a6c4ac13

Packages in this update:

lemonldap-ng-2.20.1-1.fc39

Update description:

Update to lemonldap-ng 2.20.1:

[Security] Adaptative Authentication Rules triggered by “Refresh my rights”
[Security] XSS in upgradeSession / forceUpgrade pages
downloadSamlMetadata missing from packages in 2.20.0
CDA request for id is not valid
“This application is not known” when trying to access a federation application with empty RelayState
SAML regression in 2.20.0
Internal error when captcha rule isn’t validated

Read More

lemonldap-ng-2.20.1-1.fc40

Read Time:24 Second

FEDORA-2024-e457192aa2

Packages in this update:

lemonldap-ng-2.20.1-1.fc40

Update description:

Update to lemonldap-ng 2.20.1:

[Security] Adaptative Authentication Rules triggered by “Refresh my rights”
[Security] XSS in upgradeSession / forceUpgrade pages
downloadSamlMetadata missing from packages in 2.20.0
CDA request for id is not valid
“This application is not known” when trying to access a federation application with empty RelayState
SAML regression in 2.20.0
Internal error when captcha rule isn’t validated

Read More

SEC Consult SA-20241107-0 :: Multiple Vulnerabilities in HASOMED Elefant and Elefant Software Updater

Read Time:19 Second

Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Nov 09

SEC Consult Vulnerability Lab Security Advisory < 20241107-0 >
=======================================================================
title: Multiple Vulnerabilities
product: HASOMED Elefant and Elefant Software Updater
vulnerable version: <24.04.00, Elefant Software Updater <1.4.2.1811
fixed version: 24.04.00, Elefant Software Updater 1.4.2.1811
CVE number: CVE-2024-50588,…

Read More