CVE-2024-12093

CVSS v3 Score
6.8
Medium

Vulnerability Description

An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation allows modified SAML response to bypass 2FA requirement under specialized conditions.

CVSS:6.5(Medium)

prepareUnique index may cause secondaries to crash due to incorrect enforcement of index constraints on secondaries, where in extreme cases may cause multiple secondaries crashing leading to no primar...

CVSS:7.4(High)

In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter

CVSS:7.5(High)

NLnet Labs Routinator prior to 0.10.0 produces invalid RTR payload if an RPKI CA uses too large values in the max-length parameter in a ROA. This will lead to RTR clients such as routers to reject the...

CVSS:7.5(High)

An Improper Validation of Consistency within Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker...

CVSS:5.7(Medium)

A denial of service vulnerability was found in the 389-ds-base LDAP server. This issue may allow an authenticated user to cause a server denial of service while attempting to log in with a user with a...

CVSS:8.0(High)

A command injection vulnerability exists in local RACADM. A malicious authenticated user could gain control of the underlying operating system.