Category Archives: Advisories

USN-7031-2: Puma vulnerability

Read Time:20 Second

USN-7031-1 fixed CVE-2024-45614 in Puma for Ubuntu 24.04 LTS.
This update fixes the CVE for Ubuntu 22.04 LTS and Ubuntu 20.04 LTS.

Original advisory details:

It was discovered that Puma incorrectly handled parsing certain headers.
A remote attacker could possibly use this issue to overwrite header values
set by intermediate proxies by providing duplicate headers containing
underscore characters.

Read More

USN-7030-1: py7zr vulnerability

Read Time:13 Second

It was discovered that py7zr was vulnerable to path traversal attacks.
If a user or automated system were tricked into extracting a specially
crafted 7z archive, an attacker could possibly use this issue to write
arbitrary files outside the target directory on the host.

Read More

CyberDanube Security Research 20240919-0 | Multiple Vulnerabilities in Netman204

Read Time:15 Second

Posted by Thomas Weber via Fulldisclosure on Sep 23

CyberDanube Security Research 20240919-0
——————————————————————————-
title| Multiple Vulnerabilities
product| Netman 204
vulnerable version| 4.05
fixed version| –
CVE number| CVE-2024-8877, CVE-2024-8878
impact| High
homepage| https://www.riello-ups.com/
found| 2024-05-17
by| D….

Read More

Submit Exploit CVE-2024-42831

Read Time:21 Second

Posted by arfaoui haythem on Sep 23

# Exploit Title: Reflected XSS in Elaine’s Realtime CRM Automation v6.18.17
# Date: 09/2024
# Exploit Author: Haythem Arfaoui (CBTW Team)
# Vendor Homepage: https://www.elaine.io/
# Software Link:
https://www.elaine.io/en/products/elaine-marketing-automation/
# Version: 6.18.17 and below
# Tested on: Windows, Linux
# CVE : CVE-2024-42831

# Description
A reflected cross-site scripting (XSS) vulnerability in Elaine’s Realtime
CRM…

Read More

USN-7021-2: Linux kernel vulnerabilities

Read Time:22 Second

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
– GPU drivers;
– BTRFS file system;
– F2FS file system;
– GFS2 file system;
– BPF subsystem;
– Netfilter;
– RxRPC session sockets;
– Integrity Measurement Architecture(IMA) framework;
(CVE-2024-27012, CVE-2024-39496, CVE-2024-26677, CVE-2024-42228,
CVE-2024-38570, CVE-2024-39494, CVE-2024-42160, CVE-2024-41009)

Read More