Database/Control plane, storage & DevOps
Prometheus / Thanos (golang-jwt): Unclear ParseWithClaims error behavior
CVSS 3.1CVE-2024-51744Control plane, storage & DevOpscurated
Impact
Unclear ParseWithClaims error behavior -> callers may accept an expired-and-invalid token
Who can reach it
Network (remote)
What to do
Control-plane: dependency bump and rebuild of Go control-plane services
References
Related entries
- GitLab: a developer removed from a project can still push commits via merge request collaboration settingsCVE-2025-14562 · GitLab CE/EE (merge request collaboration authorization)Low
- Inspektor Gadget: malformed ELF crashes or exhausts memory in the privileged eBPF tracerCVE-2026-44778 · Inspektor Gadget uprobetracer USDT note parser (pkg/uprobetracer/usdt.go)Low
- Jenkins: project naming strategy config lets Overall/Manage holders instantiate admin-only typesCVE-2026-70430 · Jenkins core (project naming strategy configuration)Low
- Sunbird Power IQ 9.2.0 API: Error-based SQL injection through an outdated API endpoint with missing input validationCVE-2025-55703 · Sunbird Power IQ 9.2.0 APILow
- Trivy: Terraform filesystem functions read paths above the scan root during misconfig scansCVE-2026-104994 · Trivy (Terraform misconfiguration scanner, filesystem functions)Low
- Lenovo ThinkSystem SR670 V2 (shipped in Manufacturing Mode): SR670 V2 servers built between roughly June 2021 and JulyCVE-2024-23591 · Lenovo ThinkSystem SR670 V2 (shipped in Manufacturing Mode)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.