Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Andrei Agape

Researcher fromTelia
#16906of 53,632
15.9Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2024-5014
6.1
2024-06-27
Vmware · Vmware Cloud Director · CVE-2024-22272
Name of the Vulnerable Software and Affected Versions: VMware Cloud Director (affected versions not specified) Description: The issue is related to improper privilege management, which can lead to a Denial of Service for active sessions within an organization's scope. An authenticated tenant administrator may accidentally disable their organization. The vulnerability can be exploited remotely, potentially causing a disruption in service. Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2024-21082
9.8
2024-02-09
Misp · Misp · CVE-2024-25674
**Name of the Vulnerable Software and Affected Versions** MISP versions prior to 2.4.184 **Description** An issue was discovered in the organisation logo upload feature due to a lack of checks for the file extension and MIME type, making it insecure. **Recommendations** For versions prior to 2.4.184, update to version 2.4.184 or later to resolve the issue. As a temporary workaround, consider restricting the organisation logo upload feature until a patch is available.