2024年10月26日星期六

GitLab 多個漏洞

發佈日期: 2024年10月25日

風險: 中度風險

類型: 伺服器 - 其他伺服器

於 GitLab 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況及跨網站指令碼。


影響

  • 阻斷服務
  • 跨網站指令碼

受影響之系統或技術

  • GitLab Community Edition (CE) 17.3.6, 17.4.3 及 17.5.1 以前的版本
  • GitLab Enterprise Edition (EE) 17.3.6, 17.4.3 及 17.5.1 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

GitLab Multiple Vulnerabilities

Release Date: 25 Oct 2024

RISK: Medium Risk

TYPE: Servers - Other Servers

Multiple vulnerabilities were identified in GitLab. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition and cross-site scripting on the targeted system.


Impact

  • Denial of Service
  • Cross-Site Scripting

System / Technologies affected

  • GitLab Community Edition (CE) versions prior to 17.3.6, 17.4.3 and 17.5.1
  • GitLab Enterprise Edition (EE) versions prior to 17.3.6, 17.4.3 and 17.5.1

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Microsoft Edge 多個漏洞

發佈日期: 2024年10月25日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Microsoft Edge 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發繞過保安限制、阻斷服務狀況及遠端執行任意程式碼。


影響

  • 阻斷服務
  • 遠端執行程式碼
  • 繞過保安限制

受影響之系統或技術

  • Microsoft Edge (Stable) 130.0.2849.56 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 Microsoft Edge (Stable) 130.0.2849.56 或之後的版本

漏洞識別碼


資料來源


相關連結

Microsoft Edge Multiple Vulnerabilities

Release Date: 25 Oct 2024

RISK: Medium Risk

TYPE: Clients - Browsers

Multiple vulnerabilities were identified in Microsoft Edge. A remote attacker could exploit some of these vulnerabilities to trigger security restriction bypass, denial of service condition and remote code execution on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution
  • Security Restriction Bypass

System / Technologies affected

  • Microsoft Edge (Stable) version prior to 130.0.2849.56

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to Microsoft Edge (Stable) version 130.0.2849.56 or later

Vulnerability Identifier


Source


Related Link

2024年10月24日星期四

Fortinet FortiManager遠端執行程式碼漏洞

發佈日期: 2024年10月24日

風險: 極高度風險

類型: 操作系統 - Network

於 Fortinet FortiManager發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發遠端執行任意程式碼。

 

注意:

已偵測到 CVE-2024-47575 正被廣泛利用,FortiManager的fgfmd服務中缺少關鍵功能驗證的漏洞可能允許未經身份驗證的遠端攻擊者透過特製請求執行任意程式碼或命令。

 


影響

  • 遠端執行程式碼

受影響之系統或技術

  • FortiManager 7.6 的 7.6.0 版本
  • FortiManager 7.4 的 7.4.0 至 7.4.4 版本
  • FortiManager 7.2 的 7.2.0 至 7.2.7 版本
  • FortiManager 7.0 的 7.0.0 至 7.0.12 版本
  • FortiManager 6.4 的 6.4.0 至 6.4.14 版本
  • FortiManager 6.2 的 6.2.0 至 6.2.12 版本
  • FortiManager Cloud 7.4 的 7.4.1 至 7.4.4 版本
  • FortiManager Cloud 7.2 的 7.2.1 至 7.2.7 版本
  • FortiManager Cloud 7.0 的 7.0.1 至 7.0.12 版本
  • FortiManager Cloud 6.4 的 所有版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Fortinet FortiManager Remote Code Execution Vulnerability

Release Date: 24 Oct 2024

RISK: Extremely High Risk

TYPE: Operating Systems - Networks OS

A vulnerability was identified in Fortinet FortiManager. A remote attacker could exploit this vulnerability to trigger remote code execution on the targeted system.

 

Note:

Exploit in the wild has been detected for CVE-2024-47575, a missing authentication for critical function vulnerability in FortiManager fgfmd daemon may allow a remote unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.


Impact

  • Remote Code Execution

System / Technologies affected

  • FortiManager 7.6 version 7.6.0
  • FortiManager 7.4 versions 7.4.0 through 7.4.4
  • FortiManager 7.2 versions 7.2.0 through 7.2.7
  • FortiManager 7.0 versions 7.0.0 through 7.0.12
  • FortiManager 6.4 versions 6.4.0 through 6.4.14
  • FortiManager 6.2 versions 6.2.0 through 6.2.12
  • FortiManager Cloud 7.4 versions 7.4.1 through 7.4.4
  • FortiManager Cloud 7.2 versions 7.2.1 through 7.2.7
  • FortiManager Cloud 7.0 versions 7.0.1 through 7.0.12
  • FortiManager Cloud 6.4 all versions

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2024年10月23日星期三

Google Chrome 多個漏洞

發佈日期: 2024年10月23日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發繞過保安限制、阻斷服務狀況及遠端執行任意程式碼。


影響

  • 阻斷服務
  • 遠端執行程式碼
  • 繞過保安限制

受影響之系統或技術

  • Google Chrome 130.0.6723.69 (Linux) 之前的版本
  • Google Chrome 130.0.6723.69/.70 (Mac) 之前的版本
  • Google Chrome 130.0.6723.69/.70 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 升級 130.0.6723.69 (Linux) 或之後的版本
  • 升級 130.0.6723.69/.70 (Mac) 或之後的版本
  • 升級 130.0.6723.69/.70 (Windows) 或之後的版本

漏洞識別碼


資料來源


相關連結

Google Chrome Multiple Vulnerabilities

Release Date: 23 Oct 2024

RISK: Medium Risk

TYPE: Clients - Browsers

Multiple vulnerabilities were identified in Google Chrome. A remote attacker could exploit some of these vulnerabilities to trigger security restriction bypass, denial of service condition and remote code execution on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution
  • Security Restriction Bypass

System / Technologies affected

  • Google Chrome prior to 130.0.6723.69 (Linux)
  • Google Chrome prior to 130.0.6723.69/.70 (Mac)
  • Google Chrome prior to 130.0.6723.69/.70 (Windows)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 130.0.6723.69 (Linux) or later
  • Update to version 130.0.6723.69/.70 (Mac) or later
  • Update to version 130.0.6723.69/.70 (Windows) or later

Vulnerability Identifier


Source


Related Link

2024年10月22日星期二

NetApp 產品多個漏洞

發佈日期: 2024年10月21日

風險: 中度風險

類型: 伺服器 - 其他伺服器

於 NetApp 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、洩露敏感資料及資料篡改。


影響

  • 阻斷服務
  • 篡改
  • 資料洩露

受影響之系統或技術

  • E-Series SANtricity OS Controller Software 11.x
  • ONTAP tools for VMware vSphere 9
  • AFF Baseboard Management Controller (BMC) - A1K/A70/A90
  • FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400
  • FAS/AFF Baseboard Management Controller (BMC) - A800/C800
  • FAS/AFF Baseboard Management Controller (BMC) - A900/9500
  • FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750
  • FAS/AFF Baseboard Management Controller (BMC) - FAS2820

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝供應商提供的修補程式:

 


漏洞識別碼


資料來源


相關連結

NetApp Products Multiple Vulnerabilities

Release Date: 21 Oct 2024

RISK: Medium Risk

TYPE: Servers - Other Servers

Multiple vulnerabilities were identified in NetApp Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, sensitive information disclosure and data manipulation on the targeted system.


Impact

  • Denial of Service
  • Data Manipulation
  • Information Disclosure

System / Technologies affected

  • E-Series SANtricity OS Controller Software 11.x
  • ONTAP tools for VMware vSphere 9
  • AFF Baseboard Management Controller (BMC) - A1K/A70/A90
  • FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400
  • FAS/AFF Baseboard Management Controller (BMC) - A800/C800
  • FAS/AFF Baseboard Management Controller (BMC) - A900/9500
  • FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750
  • FAS/AFF Baseboard Management Controller (BMC) - FAS2820

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 


Vulnerability Identifier


Source


Related Link

Synology 產品多個漏洞

發佈日期: 2024年10月21日

風險: 中度風險

類型: 伺服器 - 其他伺服器


於 Synology 產品發現多個漏洞,遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼、繞過保安限制和阻斷服務狀況。

 

影響

  • 遠端執行程式碼
  • 阻斷服務
  • 繞過保安限制

受影響之系統或技術

  • BeeStation OS 1.1-65373 之前的版本
  • Synology Camera BC500 韌體 1.1.3-0442 之前的版本
  • Synology Camera CC400W  韌體 1.1.3-0442 之前的版本
  • Synology Camera TC500 韌體 1.1.3-0442 之前的版本
 

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼

  • 暫無 CVE 可提供

資料來源


相關連結

Synology Products Multiple Vulnerabilities

Release Date: 21 Oct 2024

RISK: Medium Risk

TYPE: Servers - Other Servers

Multiple vulnerabilities were identified in Synology products. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution, security restriction bypass and denial of service condition on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service
  • Security Restriction Bypass

System / Technologies affected

  • BeeStation OS versions below 1.1-65373
  • Synology Camera BC500 Firmware versions below 1.1.3-0442
  • Synology Camera CC400W Firmware versions below 1.1.3-0442
  • Synology Camera TC500 Firmware versions below 1.1.3-0442

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier

  • No CVE information is available

Source


Related Link

2024年10月18日星期五

Microsoft Edge 多個漏洞

發佈日期: 2024年10月18日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Microsoft Edge 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發彷冒、繞過保安限制、阻斷服務狀況及遠端執行任意程式碼。


影響

  • 阻斷服務
  • 仿冒
  • 遠端執行程式碼
  • 繞過保安限制

受影響之系統或技術

  • Microsoft Edge (Stable) 130.0.2849.46 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 Microsoft Edge (Stable) 130.0.2849.46 或之後的版本

漏洞識別碼


資料來源


相關連結

Microsoft Edge Multiple Vulnerabilities

Release Date: 18 Oct 2024

RISK: Medium Risk

TYPE: Clients - Browsers

Multiple vulnerabilities were identified in Microsoft Edge. A remote attacker could exploit some of these vulnerabilities to trigger spoofing, security restriction bypass, denial of service condition and remote code execution on the targeted system.


Impact

  • Denial of Service
  • Spoofing
  • Remote Code Execution
  • Security Restriction Bypass

System / Technologies affected

  • Microsoft Edge (Stable) version prior to 130.0.2849.46

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to Microsoft Edge (Stable) version 130.0.2849.46 or later

Vulnerability Identifier


Source


Related Link

2024年10月17日星期四

F5 產品多個漏洞

發佈日期: 2024年10月17日

風險: 高度風險

類型: 操作系統 - Network

於 F5 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升及跨網站指令碼。
 

注意:

受影響之系統或技術暫無可修補 CVE-2019-10768, CVE-2019-14863, CVE-2022-25869, CVE-2023-26116, CVE-2023-26117 和 CVE-2023-26118 的修補程式。因此,風險等級由中度風險升為高度風險。

 


影響

  • 阻斷服務
  • 權限提升
  • 跨網站指令碼

受影響之系統或技術

BIG-IP (all modules)

  • 15.1.0 - 15.1.10
  • 16.1.0 - 16.1.5
  • 17.1.0 - 17.1.1

 

BIG-IQ Centralized Management

  • 8.2.0

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

 

臨時處理方法:

對於 CVE-2019-10768、CVE-2019-14863、CVE-2022-25869、CVE-2023-26116、CVE-2023-26117 和 CVE-2023-26118,從以下臨時處理方法以減少攻擊:

 

  1. 移除對不完全信任用戶的訪問權限

漏洞識別碼


資料來源


相關連結

F5 Products Multiple Vulnerabilities

Release Date: 17 Oct 2024

RISK: High Risk

TYPE: Operating Systems - Networks OS

Multiple vulnerabilities were identified in F5 Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege and cross-site scripting on the targeted system.

 

Note:

No patch is currently available for CVE-2019-10768, CVE-2019-14863, CVE-2022-25869, CVE-2023-26116, CVE-2023-26117 and CVE-2023-26118 of the affected products. Hence, the risk level is rated from Medium Risk to High Risk.

 


Impact

  • Denial of Service
  • Elevation of Privilege
  • Cross-Site Scripting

System / Technologies affected

BIG-IP (all modules)

  • 15.1.0 - 15.1.10
  • 16.1.0 - 16.1.5
  • 17.1.0 - 17.1.1

 

BIG-IQ Centralized Management

  • 8.2.0

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

 

Workaround:

 

For CVE-2019-10768, CVE-2019-14863, CVE-2022-25869, CVE-2023-26116, CVE-2023-26117 and CVE-2023-26118,  reduce the vulnerability of attacks by following workaround:

  1. Remove access for users who are not completely trusted

Vulnerability Identifier


Source


Related Link

IBM WebSphere 產品多個漏洞

發佈日期: 2024年10月17日

風險: 中度風險

類型: 伺服器 - 互聯網應用伺服器

於 IBM WebSphere 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況。


影響

  • 阻斷服務

受影響之系統或技術

  • IBM WebSphere Application Server 版本 8.5
  • IBM WebSphere Application Server Liberty 20.0.0.12 - 24.0.0.10

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

IBM WebSphere Products Multiple Vulnerabilities

Release Date: 17 Oct 2024

RISK: Medium Risk

TYPE: Servers - Internet App Servers

Multiple vulnerabilities were identified in IBM WebSphere Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition on the targeted system.


Impact

  • Denial of Service

System / Technologies affected

  • IBM WebSphere Application Server 8.5
  • IBM WebSphere Application Server Liberty 20.0.0.12 - 24.0.0.10

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Kubernetes Multiple Vulnerabilities

Release Date: 17 Oct 2024

RISK: Medium Risk

TYPE: Operating Systems - Application Platforms

Multiple vulnerabilities were identified in Kubernetes. A remote attacker could exploit some of these vulnerabilities to trigger security restriction bypass and elevation of privilege on the targeted system.


Impact

  • Security Restriction Bypass
  • Elevation of Privilege

System / Technologies affected

  • Kubernetes Image Builder version v0.1.37 or earlier

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to Kubernetes Image Builder v0.1.38 or later

Vulnerability Identifier


Source


Related Link

Kubernetes 多個漏洞

發佈日期: 2024年10月17日

風險: 中度風險

類型: 操作系統 - 應用程式平台

於 Kubernetes 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發繞過保安限制及權限提升。


影響

  • 繞過保安限制
  • 權限提升

受影響之系統或技術

  • Kubernetes Image Builder v0.1.37 或之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 升級 Kubernetes Image Builder v0.1.38 或之後的版本

漏洞識別碼


資料來源


相關連結

2024年10月16日星期三

甲骨文產品多個漏洞

發佈日期: 2024年10月16日

風險: 中度風險

類型: 伺服器 - 數據庫伺服器

於甲骨文產品發現多個漏洞,遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升、阻斷服務狀況、遠端執行程式碼、敏感資料洩露、篡改及繞過保安限制。

 


影響

  • 阻斷服務
  • 遠端執行程式碼
  • 繞過保安限制
  • 資料洩露
  • 權限提升
  • 篡改

受影響之系統或技術

  • Oracle MySQL
  • Java SE
  • Oracle Database Server
  • WebLogic Server
  • VirtualBox

 

 

有關其他 甲骨文 產品,請參閱以下連結:

https://www.oracle.com/security-alerts/cpuoct2024.html


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

 

甲骨文 Critical Patch Update Advisory


漏洞識別碼


資料來源


相關連結

https://www.oracle.com/security-alerts/cpuoct2024.html

    Oracle Products Multiple Vulnerabilities

    Release Date: 16 Oct 2024

    RISK: Medium Risk

    TYPE: Servers - Database Servers

    Multiple vulnerabilities were identified in Oracle Products, a remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, denial of service condition, remote code execution, sensitive information disclosure, data manipulation and security restriction bypass on the targeted system.

     


    Impact

    • Denial of Service
    • Remote Code Execution
    • Security Restriction Bypass
    • Information Disclosure
    • Elevation of Privilege
    • Data Manipulation

    System / Technologies affected

    • Oracle MySQL
    • Java SE
    • Oracle Database Server
    • WebLogic Server
    • VirtualBox

     

     

    For other Oracle products, please refer to the link below:

    https://www.oracle.com/security-alerts/cpuoct2024.html


    Solutions

    Before installation of the software, please visit the vendor web-site for more details.

     

    Apply fixes issued by the vendor:

     

    Oracle Critical Patch Update Advisory


    Vulnerability Identifier


    Source


    Related Link

    https://www.oracle.com/security-alerts/cpuoct2024.html

      Apache Tomcat 多個漏洞

      Apache Tomcat 多個漏洞 發佈日期: 2026年08月05日 風險: 中度風險 類型: 伺服器 - 網站伺服器 於 Apache T...