

Multiple GitLab Community and Enterprise Edition Vulnerabilities
June 27, 2024
Remcos RAT – Active IOCs
June 27, 2024
Multiple GitLab Community and Enterprise Edition Vulnerabilities
June 27, 2024
Remcos RAT – Active IOCs
June 27, 2024Severity
Medium
Analysis Summary
CVE-2024-27140 CVSS:5.4
Apache Archiva is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
CVE-2024-25142 CVSS:6.2
Apache Airflow could allow a local attacker to obtain sensitive information, caused by not return Cache-Control header for dynamic content. An attacker could exploit this vulnerability to obtain sensitive information from browser cache, and use this information to launch further attacks against the affected system.
Impact
- Information Disclosure
- Cross-Site Scripting
Indicators of Compromise
CVE
- CVE-2024-27140
- CVE-2024-25142
Affected Vendors
Affected Products
- Apache Archiva 2.2.10
- Apache Airflow 2.9.1
Remediation
Upgrade to the latest version of Apache Airflow, available from the Apache Website.