+ Errors on AI features
https://jira-service-management.status.atlassian.com/incidents/k657vnzycmwj
https://confluence.status.atlassian.com/incidents/8jwgf1g1wc4x
+ netrc and redirect credential leak
https://curl.se/docs/CVE-2024-11053.html
CVE-2024-11053
+ RHSA-2024:10957 Important: Updated 8.0 container image is now available in the Red Hat Ecosystem Catalog.
https://access.redhat.com/errata/RHSA-2024:10957
CVE-2024-48916
+ RHSA-2024:10953 Important: python36:3.6 security update
https://access.redhat.com/errata/RHSA-2024:10953
CVE-2024-53899
+ RHSA-2024:10952 Moderate: php:7.4 security update
https://access.redhat.com/errata/RHSA-2024:10952
CVE-2023-0567
CVE-2023-0568
CVE-2023-3247
CVE-2023-3823
CVE-2023-3824
CVE-2024-2756
CVE-2024-3096
CVE-2024-5458
CVE-2024-8925
CVE-2024-8927
CVE-2024-9026
+ RHSA-2024:10951 Moderate: php:8.2 security update
https://access.redhat.com/errata/RHSA-2024:10951
CVE-2024-2756
CVE-2024-3096
CVE-2024-5458
CVE-2024-8925
CVE-2024-8927
CVE-2024-9026
+ RHSA-2024:10943 Moderate: kernel security update
https://access.redhat.com/errata/RHSA-2024:10943
CVE-2024-46695
CVE-2024-49949
CVE-2024-50082
CVE-2024-50099
CVE-2024-50110
CVE-2024-50142
CVE-2024-50192
CVE-2024-50256
CVE-2024-50264
+ RHSA-2024:10926 Moderate: java-1.8.0-ibm security update
https://access.redhat.com/errata/RHSA-2024:10926
CVE-2024-21208
CVE-2024-21210
CVE-2024-21217
CVE-2024-21235
+ RHSA-2024:10957 Important: Updated 8.0 container image is now available in the Red Hat Ecosystem Catalog.
https://access.redhat.com/errata/RHSA-2024:10957
CVE-2024-48916
+ RHSA-2024:10956 Important: Red Hat Ceph Storage 8.0 security update
https://access.redhat.com/errata/RHSA-2024:10956
CVE-2024-48916
+ RHSA-2024:10950 Moderate: php:8.1 security update
https://access.redhat.com/errata/RHSA-2024:10950
CVE-2024-2756
CVE-2024-3096
CVE-2024-5458
CVE-2024-8925
CVE-2024-8927
CVE-2024-9026
+ RHSA-2024:10949 Moderate: php:8.2 security update
https://access.redhat.com/errata/RHSA-2024:10949
CVE-2024-2756
CVE-2024-3096
CVE-2024-5458
CVE-2024-8925
CVE-2024-8927
CVE-2024-9026
+ RHSA-2024:10939 Moderate: kernel security update
https://access.redhat.com/errata/RHSA-2024:10939
CVE-2024-26615
CVE-2024-43854
CVE-2024-44994
CVE-2024-45018
CVE-2024-46695
CVE-2024-49949
CVE-2024-50251
+ About the security content of Safari 18.2
https://support.apple.com/en-us/121846
+ About the security content of iOS 18.2 and iPadOS 18.2
https://support.apple.com/en-us/121837
+ About the security content of iPadOS 17.7.3
https://support.apple.com/en-us/121838
+ About the security content of macOS Sequoia 15.2
https://support.apple.com/en-us/121839
+ About the security content of macOS Sonoma 14.7.2
https://support.apple.com/en-us/121840
+ About the security content of macOS Ventura 13.7.2
https://support.apple.com/en-us/121842
+ About the security content of watchOS 11.2
https://support.apple.com/en-us/121843
+ About the security content of tvOS 18.2
https://support.apple.com/en-us/121844
+ About the security content of visionOS 2.2
https://support.apple.com/en-us/121845
+ Mozilla Firefox 133.0.3 released
https://www.mozilla.org/en-US/firefox/133.0.3/releasenotes/
+ Mozilla Foundation Security Advisory 2024-69 Security Vulnerabilities fixed in Thunderbird 128.5.2
https://www.mozilla.org/en-US/security/advisories/mfsa2024-69/
CVE-2024-50336
+ Mozilla Thunderbird 128.5.2 released
https://www.thunderbird.net/en-US/thunderbird/128.5.2esr/releasenotes/
+ ProFTPD 1.3.8c released
http://www.proftpd.org/docs/RELEASE_NOTES-1.3.8c
+ Tcl/Tk 8.6.16 released
https://wiki.tcl-lang.org/page/Changes+in+Tcl%2FTk+8.6
+ VU#164934 PDQ Deploy allows reuse of deleted credentials that can compromise a device and facilitate lateral movement
https://www.kb.cert.org/vuls/id/164934
+ Strutsの脆弱性(Critical: CVE-2024-53677)
https://security.sios.jp/vulnerability/struts-vulnerability-20241211/
CVE-2024-53677
ニュース&リポート
ECサイトが非保持のカード情報狙う 「侵害期間」の長期化で被害拡大
脆弱性を突きスクリプトを改ざんする手口が相次ぐ
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020800017/120401180/?ST=nxt_thmit_security
JVNVU#99283811 Intel NUCソフトウェア・スタジオサービスソフトウェアにおける複数の脆弱性
https://jvn.jp/vu/JVNVU99283811/index.html
JVNVU#91750786 Siemens製品に対するアップデート(2024年12月)
https://jvn.jp/vu/JVNVU91750786/index.html
JVNVU#90082354 MOBATIME製Network Master Clock - DTS 4801における認証情報を初期設定のまま使用する脆弱性
https://jvn.jp/vu/JVNVU90082354/index.html
JVNVU#95245080 複数のSchneider Electric製品における複数の脆弱性
https://jvn.jp/vu/JVNVU95245080/index.html
JVNVU#99631820 National Instruments製LabVIEWにおける境界外読み取りの脆弱性
https://jvn.jp/vu/JVNVU99631820/index.html
JVNVU#98560128 Horner Automation製Cscapeにおける境界外読み取りの脆弱性
https://jvn.jp/vu/JVNVU98560128/index.html
JVNVU#91729891 Rockwell Automation製Arenaにおける複数の脆弱性
https://jvn.jp/vu/JVNVU91729891/index.html