CVE-2024-1220
published 2024-03-06CVE-2024-1220: A stack-based buffer overflow in the built-in web server in Moxa NPort W2150A/W2250A Series firmware version 2.3 and prior allows a remote attacker to exploit…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.66%
47.3th percentile
A stack-based buffer overflow in the built-in web server in Moxa NPort W2150A/W2250A Series firmware version 2.3 and prior allows a remote attacker to exploit the vulnerability by sending crafted payload to the web service. Successful exploitation of the vulnerability could result in denial of service.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| aimeos | ai-admin-graphql | >= 2022.04.1 < 2022.10.10 | 2022.10.10 |
| aimeos | ai-admin-graphql | >= 2023.04.1 < 2023.10.6 | 2023.10.6 |
| aimeos | ai-admin-graphql | >= 2024.04.1 < 2024.04.6 | 2024.04.6 |
| aimeos | ai-admin-graphql | >= 2024.04.1 < 2024.04.2 | 2024.04.2 |
| gitlab | gitlab | — | — |
| gitlab | gitlab_ce | — | — |
| kimai | kimai | >= 0 < 2.13.0 | 2.13.0 |
| lunary | lunary | >= 0 < 1.4.9 | 1.4.9 |
| lunary | lunary | >= 0 < 1.4.10 | 1.4.10 |
| moxa | nport_w2150a-t_firmware | <= 2.3 | — |
| moxa | nport_w2150a_firmware | <= 2.3 | — |
| moxa | nport_w2150a_w2250a_series | 1.0 – 2.3 | — |
| moxa | nport_w2250a-t_firmware | <= 2.3 | — |
| moxa | nport_w2250a_firmware | <= 2.3 | — |
| msrc | microsoft_edge_for_android | — | — |
| msrc | microsoft_outlook_for_android | — | — |
| zenml | zenml | >= 0 < 0.56.2 | 0.56.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
vendor_msrc5.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Withdrawn Advisory: Lunary information disclosure vulnerability
ghsa·2024-09-13
CVE-2024-6867 [MEDIUM] CWE-1220 Withdrawn Advisory: Lunary information disclosure vulnerability
Withdrawn Advisory: Lunary information disclosure vulnerability
## Withdrawn Advisory
This advisory has been withdrawn because the [lunary npm package](https://www.npmjs.com/package/lunary) is connected to https://github.com/lunary-ai/lunary-js, not the https://github.com/lunary-ai/lunary repo that is discussed in this advisory.
**The underlying vulnerability report is still valid**, but it doesn't affect a product in a [GitHub Advisory Database supported ecosystem](https://docs.github.com/en/code-security/security-advisories/working-with-global-security-advisories-from-the-github-advisory-database/about-the-github-advisory-database#github-reviewed-advisories).
This link is maintained to preserve external references.
## Original Description
An information disclosure vulnerability exist
GHSA
aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
ghsa·2024-07-02
CVE-2024-39323 [HIGH] CWE-1220 aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6 fix this issue.
GHSA
aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services
ghsa·2024-07-02
CVE-2024-39324 [LOW] CWE-1220 aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services
aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end. Versions 2022.10.10, 2023.10.6, and 2024.4.2 contain a patch for the issue.
GHSA
lunary-ai/lunary Access Control Vulnerability in Prompt Variation Management
ghsa·2024-06-10
CVE-2024-5389 [MEDIUM] CWE-1220 lunary-ai/lunary Access Control Vulnerability in Prompt Variation Management
lunary-ai/lunary Access Control Vulnerability in Prompt Variation Management
Withdrawn: This advisory was incorrectly linked the the npm package `lunary`. The advisory is valid, but not for that package.
In lunary-ai/lunary version 1.2.13, an insufficient granularity of access control vulnerability allows users to create, update, get, and delete prompt variations for datasets not owned by their organization. This issue arises due to the application not properly validating the ownership of dataset prompts and their variations against the organization or project of the requesting user. As a result, unauthorized modifications to dataset prompts can occur, leading to altered or removed dataset prompts without proper authorization. This vulnerability impacts the integrity and consistency of d
GHSA
Improper authorization in zenml
ghsa·2024-06-06
CVE-2024-2035 [MEDIUM] CWE-1220 Improper authorization in zenml
Improper authorization in zenml
An improper authorization vulnerability exists in the zenml-io/zenml repository, specifically within the API PUT /api/v1/users/id endpoint. This vulnerability allows any authenticated user to modify the information of other users, including changing the `active` status of user accounts to false, effectively deactivating them. This issue affects version 0.55.3 and was fixed in version 0.56.2. The impact of this vulnerability is significant as it allows for the deactivation of admin accounts, potentially disrupting the functionality and security of the application.
GHSA
Kimai API returns timesheet entries a user should not be authorized to view
ghsa·2024-03-29
CVE-2024-29200 [MEDIUM] CWE-1220 Kimai API returns timesheet entries a user should not be authorized to view
Kimai API returns timesheet entries a user should not be authorized to view
### Summary
The permission `view_other_timesheet` performs differently for the Kimai UI and the API, thus returning unexpected data through the API.
### Details
When setting the `view_other_timesheet` permission to true, on the frontend, users can only see timesheet entries for teams they are a part of. When requesting all timesheets from the API, however, all timesheet entries are returned, regardless of whether the user shares team permissions or not.
Example:
There are projects P1 and P2, Teams T1 and T2, users U1 and U2 and Timesheet entries E1 and E2. U1 is team leader of team T1 and has access to P1. U2 is in Team T2 and has access to both P1 and P2. U2 creates E1 for P1 and E2 for P2.
In the UI, U1 with `
GHSA
GHSA-h7pr-3fcx-999q: A stack-based buffer overflow in the built-in web server in Moxa NPort W2150A/W2250A Series firmware version 2
ghsa_unreviewed·2024-03-06
CVE-2024-1220 [HIGH] CWE-121 GHSA-h7pr-3fcx-999q: A stack-based buffer overflow in the built-in web server in Moxa NPort W2150A/W2250A Series firmware version 2
A stack-based buffer overflow in the built-in web server in Moxa NPort W2150A/W2250A Series firmware version 2.3 and prior allows a remote attacker to exploit the vulnerability by sending crafted payload to the web service. Successful exploitation of the vulnerability could result in denial of service.
GitLab
CVE-2024-12619: An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1, allowing in
vendor_gitlab·2025-03-28·CVSS 5.2
CVE-2024-12619 [MEDIUM] CWE-1220 CVE-2024-12619: An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1, allowing in
CVE-2024-12619: An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1, allowing internal users to gain unauthorized access to internal projects.
Red Hat
microcode_ctl: Insufficient granularity of access control in UEFI firmware
vendor_redhat·2025-02-12·CVSS 6.8
CVE-2024-39279 [MEDIUM] CWE-1220 microcode_ctl: Insufficient granularity of access control in UEFI firmware
microcode_ctl: Insufficient granularity of access control in UEFI firmware
Insufficient granularity of access control in UEFI firmware in some Intel(R) processors may allow a authenticated user to potentially enable denial of service via local access.
Package: microcode_ctl (Red Hat Enterprise Linux 10) - Not affected
Package: microcode_ctl (Red Hat Enterprise Linux 7) - Out of support scope
GitLab
CVE-2024-11931: An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.6.4, from 17.7 prior to 17.7.3, and from 17.8 prior
vendor_gitlab·2025-01-24·CVSS 6.4
CVE-2024-11931 [MEDIUM] CWE-1220 CVE-2024-11931: An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.6.4, from 17.7 prior to 17.7.3, and from 17.8 prior
CVE-2024-11931: An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.6.4, from 17.7 prior to 17.7.3, and from 17.8 prior to 17.8.1. Under certain conditions, it may have been possible for users with developer role to exfiltrate protected CI variables via CI lint.
Microsoft
Outlook for Android Elevation of Privilege Vulnerability
vendor_msrc·2024-10-08·CVSS 5.7
CVE-2024-43604 [MEDIUM] CWE-1220 Outlook for Android Elevation of Privilege Vulnerability
Outlook for Android Elevation of Privilege Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
This vulnerability requires that a user with an affected version of Outlook open a malicious meeting or appointment invite from the attacker.
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to have access to the location where the target file will be run. They would then need to plant a specific file that would be used as part of the exploitation.
FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability?
An attacker who successfully exploited this
Red Hat
php: cgi.force_redirect configuration is bypassable due to the environment variable collision
vendor_redhat·2024-10-07·CVSS 7.5
CVE-2024-8927 [HIGH] CWE-1220 php: cgi.force_redirect configuration is bypassable due to the environment variable collision
php: cgi.force_redirect configuration is bypassable due to the environment variable collision
In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being run by the HTTP server. However, in certain scenarios, the content of this variable can be controlled by the request submitter via HTTP headers, which can lead to cgi.force_redirect option not being correctly applied. In certain configurations this may lead to arbitrary file inclusion in PHP.
A flaw was found in PHP. The configuration directive `cgi.force_redirect` prevents anyone from calling PHP directly with a URL such as http://host.example/cgi-bin/php/secretdir/script.php. However, in certain uncommon configurations, an attacker may
Red Hat
jenkins: Item creation restriction bypass vulnerability
vendor_redhat·2024-10-02·CVSS 4.3
CVE-2024-47804 [MEDIUM] CWE-1220 jenkins: Item creation restriction bypass vulnerability
jenkins: Item creation restriction bypass vulnerability
If an attempt is made to create an item of a type prohibited by `ACL#hasCreatePermission2` or `TopLevelItemDescriptor#isApplicableIn(ItemGroup)` through the Jenkins CLI or the REST API and either of these checks fail, Jenkins 2.478 and earlier, LTS 2.462.2 and earlier creates the item in memory, only deleting it from disk, allowing attackers with Item/Configure permission to save the item to persist it, effectively bypassing the item creation restriction.
A flaw was found in Jenkins. When attempting to create an item prohibited by `ACL#hasCreatePermission2` or `TopLevelItemDescriptor#isApplicableIn(ItemGroup)` through the Jenkins CLI or the REST API, if either of these checks fail, Jenkins creates the item in memory and only deletes
Microsoft
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
vendor_msrc·2024-03-12·CVSS 3.9
CVE-2024-26246 [LOW] CWE-1220 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An attacker who successfully exploited this could bypass the Edge AutoFill Protection feature
FAQ: According to the CVSS metric, the attack vector is physical (AV:P), user interaction is required (UI:R), and privileges required is high (PR:H). What does that mean for this vulnerability?
An authorized attacker with physical access to a victim's unsecured Android phone must use the autofill feature on Edge Android to access victim's saved credentials.
FAQ:
Microsoft Edge Channel
Microsoft Edge Version
Date Released
Based on Chromium Version
Stable
122.0.2365.92
3/14/2024
122.0.6261.128/.129
Extended Stable
122.0.236
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://www.moxa.com/en/support/product-support/security-advisory/mpsa-238975-nport-w2150a-w2250a-series-web-server-stack-based-buffer-overflow-vulnerabilityhttps://www.moxa.com/en/support/product-support/security-advisory/mpsa-238975-nport-w2150a-w2250a-series-web-server-stack-based-buffer-overflow-vulnerability
2024-03-06
Published