A vulnerability, which was classified as critical, was found in Wazuh up to 4.7.1. This affects an unknown part of the file /var/ossec/active-response/bin. The manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2023-50260. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Wazuh up to 4.7.1 and classified as very critical. This issue affects some unknown processing of the component wazuh-analysisd. The manipulation leads to heap-based buffer overflow.
The identification of this vulnerability is CVE-2024-32038. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in argoproj argo-cd. Affected by this issue is the function ignoreDifferences. The manipulation leads to resource consumption.
This vulnerability is handled as CVE-2024-32476. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in argo-cd and classified as problematic. This issue affects some unknown processing of the component Redis Server. The manipulation leads to risky cryptographic algorithm.
The identification of this vulnerability is CVE-2024-31989. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.