Rewterz
Amazon Confirms Breach of Employee Data Following Vendor Intrusion
November 12, 2024
Rewterz
RustyStealer and New Ymir Ransomware Collaborate in Cyberattacks – Active IOCs
November 12, 2024

Multiple Apache Products Vulnerabilities

Severity

High

Analysis Summary

CVE-2024-50378 CVSS:4.9

Apache Airflow could allow a remote authenticated attacker to obtain sensitive information, caused by secrets not masked in UI when sensitive variables are set via Airflow cli. By sending a specially crafted request, an attacker could exploit this vulnerability to obtain sensitive information in audit logs, and use this information to launch further attacks against the affected system.

CVE-2024-51504 CVSS:9.1

Apache ZooKeeper could allow a remote attacker to bypass security restrictions, caused by a flaw when using IPAuthenticationProvider. By spoofing client's IP address in request headers, an attacker could exploit this vulnerability to bypass authentication.

Impact

  • Information Disclosure
  • Security Bypass

Indicators of Compromise

CVE

  • CVE-2024-50378
  • CVE-2024-51504

Affected Vendors

Apache

Affected Products

  • Apache ZooKeeper - 3.9.0
  • Apache ZooKeeper - 3.9.2
  • Apache Software Foundation Apache ZooKeeper - 3.9.0
  • Apache Airflow - 2.10.2

Remediation

Upgrade to the latest version of Apache Products, available from the Apache Website.

CVE-2024-50378

CVE-2024-51504