diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index ba7314a9e226..f5af9b864a2a 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -1,110 +1,110 @@ ]> &vuln-2025; &vuln-2024; &vuln-2023; &vuln-2022; &vuln-2021; &vuln-2020; &vuln-2019; &vuln-2018; &vuln-2017; &vuln-2016; &vuln-2015; &vuln-2014; &vuln-2013; &vuln-2012; &vuln-2011; &vuln-2010; &vuln-2009; &vuln-2008; &vuln-2007; &vuln-2006; &vuln-2005; &vuln-2004; &vuln-2003; diff --git a/security/vuxml/vuln/2025.xml b/security/vuxml/vuln/2025.xml index 5588926228b8..f4e44f9d9f30 100644 --- a/security/vuxml/vuln/2025.xml +++ b/security/vuxml/vuln/2025.xml @@ -1,34 +1,116 @@ + + redis,valkey -- Denial-of-service valnerability due to malformed ACL selectors + + + redis + 7.0.07.4.2 + + + redis72 + 7.2.7 + + + valkey + 8.0.2 + + + + +

Redis core team reports:

+
+

+ An authenticated with sufficient privileges may create a + malformed ACL selector which, when accessed, triggers a + server panic and subsequent denial of service.The problem + exists in Redis 7.0.0 or newer. +

+
+ +
+ + CVE-2024-51741 + https://github.com/redis/redis/security/advisories/GHSA-prpq-rh5h-46g9 + + + 2025-01-06 + 2025-01-10 + +
+ + + redis,valkey -- Remote code execution valnerability + + + redis + 7.4.2 + + + redis72 + 7.2.7 + + + redis62 + 6.2.17 + + + valkey + 8.0.2 + + + + +

Redis core team reports:

+
+

+ An authenticated user may use a specially crafted Lua + script to manipulate the garbage collector and potentially + lead to remote code execution. The problem exists in all + versions of Redis with Lua scripting. +

+
+ +
+ + CVE-2024-46981 + https://github.com/redis/redis/security/advisories/GHSA-39h2-x6c4-6w4c + + + 2025-01-06 + 2025-01-10 + +
+ Gitlab -- Vulnerabilities gitlab-ce gitlab-ee 17.7.017.7.1 17.6.017.6.3 11.0.017.5.5

Gitlab reports:

Possible access token exposure in GitLab logs

Cyclic reference of epics leads resource exhaustion

Unauthorized user can manipulate status of issues in public projects

Instance SAML does not respect external_provider configuration

CVE-2025-0194 CVE-2024-6324 CVE-2024-12431 CVE-2024-13041 https://about.gitlab.com/releases/2025/01/08/patch-release-gitlab-17-7-1-released/ 2025-01-08 2025-01-08