A vulnerability classified as critical has been found in Bitdefender Box 1.3.11.490. This affects an unknown part of the file /check_image_and_trigger_recovery API of the component API Endpoint. The manipulation leads to command injection. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is uniquely identified as CVE-2024-13871. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Bitdefender Box up to 1.3.52.928. This issue affects some unknown processing. The manipulation leads to security version number mutable to older versions. This vulnerability only affects products that are no longer supported by the maintainer.
The identification of this vulnerability is CVE-2024-13870. It is possible to launch the attack on the local host. There is no exploit available.
A vulnerability, which was classified as critical, has been found in run-llama llama_index up to 0.2.x. This issue affects the function run_sql_query of the component database_agent. The manipulation leads to sql injection.
The identification of this vulnerability is CVE-2024-12909. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in run-llama llama_index up to 0.5.0. Affected is the function default_jsonalyzer of the component JSONalyzeQueryEngine. The manipulation leads to creation of temporary file in directory with insecure permissions.
This vulnerability is traded as CVE-2024-12911. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.