Skip to main content

Threats Tagged 'cve-2024-7923'

View all threats tagged with 'cve-2024-7923'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2024-7923

Threats Tagged 'cve-2024-7923'

Click on any threat for detailed analysis and mitigation recommendations

Red Hat OpenShift Dev Spaces provides a cloud developer workspace server and a browser-based IDE built for teams and organizations. Dev Spaces runs in OpenShift and is well-suited for container-based development. The 3.25 release is based on Eclipse Che 7.111 and uses the DevWorkspace engine to provide support for workspaces based on devfile v2.1 and v2.2. Users still using the v1 standard should migrate as soon as possible. https://devfile.io/docs/2.2.0/migrating-to-devfile-v2 Dev Spaces supports OpenShift EUS releases v4.16 and higher. Users are expected to update to supported OpenShift releases in order to continue to get Dev Spaces updates. https://access.redhat.com/support/policy/updates/openshift#crw

Join the discussion

Red Hat Developer Hub (RHDH) is Red Hat's enterprise-grade, self-managed, customizable developer portal based on Backstage.io. RHDH is supported on OpenShift and other major Kubernetes clusters (AKS, EKS, GKE). The core features of RHDH include a single pane of glass, a centralized software catalog, self-service via golden path templates, and Tech Docs. RHDH is extensible by plugins.

Join the discussion

Red Hat Satellite 6.13.7.2 includes security updates addressing authentication bypass vulnerabilities in Foreman and pulpcore components. These vulnerabilities could allow unauthorized access if exploited. Users are advised to upgrade to the updated packages to remediate these issues. The update is rated as important by Red Hat Product Security.

Join the discussion

Red Hat Satellite 6.14.4.2 addresses important security vulnerabilities involving authentication bypass issues in Foreman and Pulpcore components. These vulnerabilities could allow unauthorized access if exploited. Users are advised to upgrade to the updated packages to remediate these issues. The update is rated as important by Red Hat Product Security. No CVSS score is provided, but the impact is significant due to authentication bypass risks.

Join the discussion

Red Hat Satellite 6.15.3.1 addresses important security vulnerabilities including authentication bypass issues in Foreman and pulpcore components. These vulnerabilities could allow unauthorized access if exploited. Users are advised to upgrade to the updated packages to remediate these issues. The update is rated as important by Red Hat Product Security. Detailed upgrade instructions are available in the official Red Hat Satellite documentation.

Join the discussion
0

An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the puppet-pulpcore configuration. This issue arises from Apache's mod_proxy not properly unsetting headers because of restrictions on underscores in HTTP headers, allowing authentication through a malformed header. This flaw impacts all active Satellite deployments (6.13, 6.14 and 6.15) which are using Pulpcore version 3.0+ and could potentially enable unauthorized users to gain administrative access.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Tag: cve-2024-7923
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses