CVE-2024-22229
published 2024-01-24CVE-2024-22229: Dell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed by an authenticated attacker. An attacker could exploit this…
PriorityP423medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
0.30%
22.0th percentile
Dell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed by an authenticated attacker. An attacker could exploit this vulnerability to forge log entries, create false alarms, and inject malicious content into logs that compromise logs integrity. A malicious attacker could also prevent the product from logging information while malicious actions are performed or implicate an arbitrary user for malicious activities.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dell | unity | < 5.3.0.0.5.120 | 5.3.0.0.5.120 |
| dell | unity_operating_environment | — | — |
| dell | unity_xt_operating_environment | — | — |
| dell | unityvsa_operating_environment | — | — |
| flarum | core | >= 0 < 1.8.5 | 1.8.5 |
| flarum | framework | >= 0 < 1.8.5 | 1.8.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-63fr-hqmm-7x7r: Dell Unity, versions prior to 5
ghsa_unreviewed·2024-01-24
CVE-2024-22229 [LOW] CWE-116 GHSA-63fr-hqmm-7x7r: Dell Unity, versions prior to 5
Dell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed by an authenticated attacker. An attacker could exploit this vulnerability to forge log entries, create false alarms, and inject malicious content into logs that compromise logs integrity. A malicious attacker could also prevent the product from logging information while malicious actions are performed or implicate an arbitrary user for malicious activities.
GHSA
Flarum's logout Route allows open redirects
ghsa·2024-01-05
CVE-2024-21641 [MEDIUM] CWE-601 Flarum's logout Route allows open redirects
Flarum's logout Route allows open redirects
### Impact
The Flarum `/logout` route includes a redirect parameter that allows any third party to redirect users from a (trusted) domain of the Flarum installation to redirect to any link. Sample: `example.com/logout?return=https://google.com`. For logged-in users, the logout must be confirmed. Guests are immediately redirected. This could be used by spammers to redirect to a web address using a trusted domain of a running Flarum installation.
Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526
### Patches
The vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possibl
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-01-24
Published