May brought a fresh batch of security headaches. This month, we’re focusing on critical vulnerabilities in widely used software like Apache, Gitlab, and Github. These flaws could allow attackers to steal data, hijack systems, or wreak havoc in your network. Let’s break down the top 5 CVEs you need to address right away to stay secure.
CVE-2024-27348 is a critical vulnerability in Apache HugeGraph-Server that allows remote code execution (RCE). This means an attacker could potentially take control of your system if it’s running a vulnerable version of the software.
Here’s a breakdown of the CVE:
The vulnerability exists because the software doesn’t properly sanitize user input, which allows attackers to inject Groovy code. Groovy is a programming language that can be used to execute commands on the system.
Mitigation:
The recommended mitigation for this vulnerability is to upgrade to Apache HugeGraph-Server version 1.3.0 or later. This version fixes the vulnerability by properly sanitizing user input.
Here are some additional things to keep in mind:
CVE-2024-24919 is a high-severity information disclosure vulnerability that affects Check Point Security Gateway devices. It was identified in May 2024 and has been exploited in the wild since at least April 2024. Here’s a breakdown of the vulnerability:
The good news is that Check Point has released a security fix to address this vulnerability. Here’s what you should do:
For more information on the vulnerability, you can refer to the following resources:
Check Point’s security advisory: https://support.checkpoint.com/results/sk/sk182336
GitLab addressed a critical security vulnerability – CVE-2024-4835 through patch releases for GitLab Community Edition (CE) and Enterprise Edition (EE). This vulnerability was a cross-site scripting (XSS) flaw, which could have allowed attackers to inject malicious code into GitLab web pages.
Here’s a breakdown of the vulnerability:
Resolution:
GitLab released patches to address this vulnerability in May 2024. These patches are available for the following versions:
Recommendation:
It’s crucial to update your GitLab installation to the latest patched version (mentioned above) as soon as possible to mitigate this critical vulnerability and protect your data.
CVE-2024-27130 is a critical vulnerability that affects QNAP’s Network Attached Storage (NAS) devices running the QTS operating system. This vulnerability allows for Remote Code Execution (RCE), which means an attacker could potentially take complete control of your NAS device if it’s exploited.
Here’s a breakdown of the issue:
Here’s what makes this vulnerability critical:
What to Do:
Fortunately, QNAP released a security patch (QTS 5.1.7.2770 version 20240520) in May 2024 to address this vulnerability. It’s crucial to update your QNAP NAS device to the latest version as soon as possible.
Here are some additional resources:
CVE-2024-4985 refers to a critical vulnerability discovered in May 2024 that affects GitHub Enterprise Server (GHES). This vulnerability allowed attackers to bypass authentication altogether, potentially gaining unauthorized access to sensitive code repositories and private information.
Here’s a breakdown of the issue:
It’s important to note that this vulnerability only affected GHES instances configured with:
Thankfully, GitHub addressed this issue swiftly by releasing patches for various GHES versions.
Recommendation:
If you are using an affected version of GHES (prior to 3.13.0), update your server to the patched versions: 3.9.15, 3.10.12, 3.11.10, or 3.12.4. This will mitigate the risk of attackers exploiting this vulnerability.
For further information, you can refer to the official GitHub security advisory: https://github.com/advisories/GHSA-5pw9-f9r4-mv2r
That’s it for our top CVEs of May! By patching these vulnerabilities promptly, you can significantly reduce your attack surface and keep those pesky hackers at bay. Remember, staying informed and applying security updates is an ongoing process. Stay tuned for more in-depth analysis and the latest security threats in the coming months! For real-time updates, follow Strobes on social media!
Strobes Vulnerability Intel portal is created to provide a comprehensive archive of the latest vulnerabilities, exploits, and CVEs targeting a given platform or application – Learn more
The post Top 5 CVEs and Vulnerabilities of May 2024 appeared first on Strobes Security.
*** This is a Security Bloggers Network syndicated blog from Strobes Security authored by Shubham Jha. Read the original post at: https://strobes.co/blog/top-5-cves-and-vulnerabilities-of-may-2024/