From 002804aa0357c3400cad741d914f3609114ec197 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 13 Sep 2024 21:32:48 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-mqq7-v29v-25f6.json | 4 +- .../GHSA-5px3-vmv6-3cq9.json | 2 +- .../GHSA-35p2-9fg3-f2p2.json | 2 +- .../GHSA-7x98-4rw8-872g.json | 2 +- .../GHSA-h3j8-wx8r-29j6.json | 2 +- .../GHSA-h9px-j846-3j9p.json | 2 +- .../GHSA-h6m5-xj4q-9xw4.json | 2 +- .../GHSA-j66v-q82h-4f8h.json | 2 +- .../GHSA-g458-xvmc-qg2r.json | 2 +- .../GHSA-5vpg-rf76-m7c5.json | 1 + .../GHSA-hqhw-r7ww-86xw.json | 1 + .../GHSA-gfgx-4754-9hhp.json | 11 ++-- .../GHSA-hx83-hmj3-pffc.json | 9 ++- .../GHSA-364p-86w3-x6rv.json | 9 ++- .../GHSA-8423-fqh5-4pfr.json | 6 +- .../GHSA-j2ww-8383-6mw8.json | 2 +- .../GHSA-mvj8-h6fp-pcrp.json | 9 ++- .../GHSA-q7v4-578f-ph8j.json | 2 +- .../GHSA-24xq-67qf-j3xr.json | 1 + .../GHSA-2mjg-798r-mxwh.json | 3 +- .../GHSA-3q68-hm47-94vg.json | 3 +- .../GHSA-3x4g-4374-v83h.json | 35 +++++++++++ .../GHSA-48wc-9j2c-rwp5.json | 3 +- .../GHSA-6qq3-v7mp-wx7q.json | 35 +++++++++++ .../GHSA-974p-hhmc-6h46.json | 11 ++-- .../GHSA-9g66-w5hj-vhx4.json | 35 +++++++++++ .../GHSA-cc7f-7qrj-r4v2.json | 6 +- .../GHSA-cf2w-h975-2fpg.json | 3 +- .../GHSA-cx6w-h9jj-x2vr.json | 3 +- .../GHSA-h827-7423-x2vc.json | 11 ++-- .../GHSA-jhgj-6hmm-vm6v.json | 11 ++-- .../GHSA-jm4p-4c99-gp7x.json | 11 ++-- .../GHSA-mcxm-8hr3-frmx.json | 1 + .../GHSA-p47w-6xhw-hhxj.json | 35 +++++++++++ .../GHSA-p7wm-h6q7-mx95.json | 2 +- .../GHSA-pq2c-46q4-qwg3.json | 11 ++-- .../GHSA-q74x-f8wx-jrgv.json | 35 +++++++++++ .../GHSA-qf89-78m6-x24m.json | 62 +++++++++++++++++++ .../GHSA-r89w-9fr4-c7c9.json | 11 ++-- .../GHSA-rvhr-9pp2-823m.json | 4 +- .../GHSA-v3gc-cff3-2vg3.json | 39 ++++++++++++ .../GHSA-vfwm-h968-g65h.json | 11 ++-- .../GHSA-vp6m-7x2g-h3wf.json | 11 ++-- .../GHSA-x6p2-rpj7-w423.json | 62 +++++++++++++++++++ .../GHSA-xr4c-mmrv-3h6c.json | 35 +++++++++++ 45 files changed, 495 insertions(+), 65 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-3x4g-4374-v83h/GHSA-3x4g-4374-v83h.json create mode 100644 advisories/unreviewed/2024/09/GHSA-6qq3-v7mp-wx7q/GHSA-6qq3-v7mp-wx7q.json create mode 100644 advisories/unreviewed/2024/09/GHSA-9g66-w5hj-vhx4/GHSA-9g66-w5hj-vhx4.json create mode 100644 advisories/unreviewed/2024/09/GHSA-p47w-6xhw-hhxj/GHSA-p47w-6xhw-hhxj.json create mode 100644 advisories/unreviewed/2024/09/GHSA-q74x-f8wx-jrgv/GHSA-q74x-f8wx-jrgv.json create mode 100644 advisories/unreviewed/2024/09/GHSA-qf89-78m6-x24m/GHSA-qf89-78m6-x24m.json create mode 100644 advisories/unreviewed/2024/09/GHSA-v3gc-cff3-2vg3/GHSA-v3gc-cff3-2vg3.json create mode 100644 advisories/unreviewed/2024/09/GHSA-x6p2-rpj7-w423/GHSA-x6p2-rpj7-w423.json create mode 100644 advisories/unreviewed/2024/09/GHSA-xr4c-mmrv-3h6c/GHSA-xr4c-mmrv-3h6c.json diff --git a/advisories/unreviewed/2023/01/GHSA-mqq7-v29v-25f6/GHSA-mqq7-v29v-25f6.json b/advisories/unreviewed/2023/01/GHSA-mqq7-v29v-25f6/GHSA-mqq7-v29v-25f6.json index 99f839e671a..2831d8afca4 100644 --- a/advisories/unreviewed/2023/01/GHSA-mqq7-v29v-25f6/GHSA-mqq7-v29v-25f6.json +++ b/advisories/unreviewed/2023/01/GHSA-mqq7-v29v-25f6/GHSA-mqq7-v29v-25f6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mqq7-v29v-25f6", - "modified": "2023-01-25T21:30:18Z", + "modified": "2024-09-13T21:31:18Z", "published": "2023-01-18T18:30:16Z", "aliases": [ "CVE-2022-47966" @@ -68,7 +68,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-5px3-vmv6-3cq9/GHSA-5px3-vmv6-3cq9.json b/advisories/unreviewed/2023/04/GHSA-5px3-vmv6-3cq9/GHSA-5px3-vmv6-3cq9.json index 36c090edf4a..4f01a0aed5c 100644 --- a/advisories/unreviewed/2023/04/GHSA-5px3-vmv6-3cq9/GHSA-5px3-vmv6-3cq9.json +++ b/advisories/unreviewed/2023/04/GHSA-5px3-vmv6-3cq9/GHSA-5px3-vmv6-3cq9.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-35p2-9fg3-f2p2/GHSA-35p2-9fg3-f2p2.json b/advisories/unreviewed/2023/07/GHSA-35p2-9fg3-f2p2/GHSA-35p2-9fg3-f2p2.json index 919e256aa7f..1b48b7411e5 100644 --- a/advisories/unreviewed/2023/07/GHSA-35p2-9fg3-f2p2/GHSA-35p2-9fg3-f2p2.json +++ b/advisories/unreviewed/2023/07/GHSA-35p2-9fg3-f2p2/GHSA-35p2-9fg3-f2p2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-35p2-9fg3-f2p2", - "modified": "2024-02-11T06:30:25Z", + "modified": "2024-09-13T21:31:19Z", "published": "2023-07-24T18:30:44Z", "aliases": [ "CVE-2023-3750" diff --git a/advisories/unreviewed/2023/07/GHSA-7x98-4rw8-872g/GHSA-7x98-4rw8-872g.json b/advisories/unreviewed/2023/07/GHSA-7x98-4rw8-872g/GHSA-7x98-4rw8-872g.json index 27392eef60d..dab4d92364e 100644 --- a/advisories/unreviewed/2023/07/GHSA-7x98-4rw8-872g/GHSA-7x98-4rw8-872g.json +++ b/advisories/unreviewed/2023/07/GHSA-7x98-4rw8-872g/GHSA-7x98-4rw8-872g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7x98-4rw8-872g", - "modified": "2024-01-30T18:30:18Z", + "modified": "2024-09-13T21:31:19Z", "published": "2023-07-25T18:30:32Z", "aliases": [ "CVE-2023-3772" diff --git a/advisories/unreviewed/2023/07/GHSA-h3j8-wx8r-29j6/GHSA-h3j8-wx8r-29j6.json b/advisories/unreviewed/2023/07/GHSA-h3j8-wx8r-29j6/GHSA-h3j8-wx8r-29j6.json index 74460d305fa..8bce952ccfa 100644 --- a/advisories/unreviewed/2023/07/GHSA-h3j8-wx8r-29j6/GHSA-h3j8-wx8r-29j6.json +++ b/advisories/unreviewed/2023/07/GHSA-h3j8-wx8r-29j6/GHSA-h3j8-wx8r-29j6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h3j8-wx8r-29j6", - "modified": "2023-11-21T18:30:25Z", + "modified": "2024-09-13T21:31:19Z", "published": "2023-07-31T18:30:22Z", "aliases": [ "CVE-2023-4004" diff --git a/advisories/unreviewed/2023/07/GHSA-h9px-j846-3j9p/GHSA-h9px-j846-3j9p.json b/advisories/unreviewed/2023/07/GHSA-h9px-j846-3j9p/GHSA-h9px-j846-3j9p.json index 55368cf0ecf..78fca3d5a90 100644 --- a/advisories/unreviewed/2023/07/GHSA-h9px-j846-3j9p/GHSA-h9px-j846-3j9p.json +++ b/advisories/unreviewed/2023/07/GHSA-h9px-j846-3j9p/GHSA-h9px-j846-3j9p.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-h6m5-xj4q-9xw4/GHSA-h6m5-xj4q-9xw4.json b/advisories/unreviewed/2023/09/GHSA-h6m5-xj4q-9xw4/GHSA-h6m5-xj4q-9xw4.json index 2a267d859d7..f5870fae332 100644 --- a/advisories/unreviewed/2023/09/GHSA-h6m5-xj4q-9xw4/GHSA-h6m5-xj4q-9xw4.json +++ b/advisories/unreviewed/2023/09/GHSA-h6m5-xj4q-9xw4/GHSA-h6m5-xj4q-9xw4.json @@ -48,7 +48,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-j66v-q82h-4f8h/GHSA-j66v-q82h-4f8h.json b/advisories/unreviewed/2023/09/GHSA-j66v-q82h-4f8h/GHSA-j66v-q82h-4f8h.json index df10c723344..77662fafd4c 100644 --- a/advisories/unreviewed/2023/09/GHSA-j66v-q82h-4f8h/GHSA-j66v-q82h-4f8h.json +++ b/advisories/unreviewed/2023/09/GHSA-j66v-q82h-4f8h/GHSA-j66v-q82h-4f8h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j66v-q82h-4f8h", - "modified": "2024-02-27T21:31:25Z", + "modified": "2024-09-13T21:31:20Z", "published": "2023-09-25T21:30:26Z", "aliases": [ "CVE-2023-42753" diff --git a/advisories/unreviewed/2023/10/GHSA-g458-xvmc-qg2r/GHSA-g458-xvmc-qg2r.json b/advisories/unreviewed/2023/10/GHSA-g458-xvmc-qg2r/GHSA-g458-xvmc-qg2r.json index 11293eae163..153b8d7ae2c 100644 --- a/advisories/unreviewed/2023/10/GHSA-g458-xvmc-qg2r/GHSA-g458-xvmc-qg2r.json +++ b/advisories/unreviewed/2023/10/GHSA-g458-xvmc-qg2r/GHSA-g458-xvmc-qg2r.json @@ -44,7 +44,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-5vpg-rf76-m7c5/GHSA-5vpg-rf76-m7c5.json b/advisories/unreviewed/2023/12/GHSA-5vpg-rf76-m7c5/GHSA-5vpg-rf76-m7c5.json index 6098ff0766a..0d4681291cc 100644 --- a/advisories/unreviewed/2023/12/GHSA-5vpg-rf76-m7c5/GHSA-5vpg-rf76-m7c5.json +++ b/advisories/unreviewed/2023/12/GHSA-5vpg-rf76-m7c5/GHSA-5vpg-rf76-m7c5.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/12/GHSA-hqhw-r7ww-86xw/GHSA-hqhw-r7ww-86xw.json b/advisories/unreviewed/2023/12/GHSA-hqhw-r7ww-86xw/GHSA-hqhw-r7ww-86xw.json index 64ad2ad0f96..a5803cb9f96 100644 --- a/advisories/unreviewed/2023/12/GHSA-hqhw-r7ww-86xw/GHSA-hqhw-r7ww-86xw.json +++ b/advisories/unreviewed/2023/12/GHSA-hqhw-r7ww-86xw/GHSA-hqhw-r7ww-86xw.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/06/GHSA-gfgx-4754-9hhp/GHSA-gfgx-4754-9hhp.json b/advisories/unreviewed/2024/06/GHSA-gfgx-4754-9hhp/GHSA-gfgx-4754-9hhp.json index c120fcb2096..18c5e7de37d 100644 --- a/advisories/unreviewed/2024/06/GHSA-gfgx-4754-9hhp/GHSA-gfgx-4754-9hhp.json +++ b/advisories/unreviewed/2024/06/GHSA-gfgx-4754-9hhp/GHSA-gfgx-4754-9hhp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gfgx-4754-9hhp", - "modified": "2024-06-11T15:31:14Z", + "modified": "2024-09-13T21:31:20Z", "published": "2024-06-11T15:31:14Z", "aliases": [ "CVE-2024-5695" ], "details": "If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been triggered, and in rarer situations, memory corruption could have occurred. This vulnerability affects Firefox < 127.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-11T13:15:51Z" diff --git a/advisories/unreviewed/2024/06/GHSA-hx83-hmj3-pffc/GHSA-hx83-hmj3-pffc.json b/advisories/unreviewed/2024/06/GHSA-hx83-hmj3-pffc/GHSA-hx83-hmj3-pffc.json index d5c2bdb799b..1841b9c99dc 100644 --- a/advisories/unreviewed/2024/06/GHSA-hx83-hmj3-pffc/GHSA-hx83-hmj3-pffc.json +++ b/advisories/unreviewed/2024/06/GHSA-hx83-hmj3-pffc/GHSA-hx83-hmj3-pffc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hx83-hmj3-pffc", - "modified": "2024-06-11T15:31:13Z", + "modified": "2024-09-13T21:31:20Z", "published": "2024-06-11T15:31:13Z", "aliases": [ "CVE-2024-5689" ], "details": "In addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay the 'My Shots' button that appeared, and direct the user to a replica Firefox Screenshots page that could be used for phishing. This vulnerability affects Firefox < 127.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-11T13:15:50Z" diff --git a/advisories/unreviewed/2024/08/GHSA-364p-86w3-x6rv/GHSA-364p-86w3-x6rv.json b/advisories/unreviewed/2024/08/GHSA-364p-86w3-x6rv/GHSA-364p-86w3-x6rv.json index 65c29eee3d7..1fb66181477 100644 --- a/advisories/unreviewed/2024/08/GHSA-364p-86w3-x6rv/GHSA-364p-86w3-x6rv.json +++ b/advisories/unreviewed/2024/08/GHSA-364p-86w3-x6rv/GHSA-364p-86w3-x6rv.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-364p-86w3-x6rv", - "modified": "2024-08-29T12:31:05Z", + "modified": "2024-09-13T21:31:21Z", "published": "2024-08-29T12:31:05Z", "aliases": [ "CVE-2024-5622" ], "details": "An untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROL <= R 4.2.-07P3 and <= R 4.4-00P3 may allow an authenticated local attacker to execute arbitrary code with elevated privileges.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" @@ -28,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-250" + "CWE-250", + "CWE-426" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-8423-fqh5-4pfr/GHSA-8423-fqh5-4pfr.json b/advisories/unreviewed/2024/08/GHSA-8423-fqh5-4pfr/GHSA-8423-fqh5-4pfr.json index 38f97e76156..9b618e05021 100644 --- a/advisories/unreviewed/2024/08/GHSA-8423-fqh5-4pfr/GHSA-8423-fqh5-4pfr.json +++ b/advisories/unreviewed/2024/08/GHSA-8423-fqh5-4pfr/GHSA-8423-fqh5-4pfr.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8423-fqh5-4pfr", - "modified": "2024-08-29T12:31:05Z", + "modified": "2024-09-13T21:31:21Z", "published": "2024-08-29T12:31:05Z", "aliases": [ "CVE-2024-5624" ], "details": "Reflected Cross-Site Scripting (XSS) in Shift Logbook application of B&R APROL <= R 4.4-00P3 may allow a network-based attacker to execute arbitrary JavaScript code in the context of the user's browser session", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/08/GHSA-j2ww-8383-6mw8/GHSA-j2ww-8383-6mw8.json b/advisories/unreviewed/2024/08/GHSA-j2ww-8383-6mw8/GHSA-j2ww-8383-6mw8.json index 915f63e8447..2a5e7d59995 100644 --- a/advisories/unreviewed/2024/08/GHSA-j2ww-8383-6mw8/GHSA-j2ww-8383-6mw8.json +++ b/advisories/unreviewed/2024/08/GHSA-j2ww-8383-6mw8/GHSA-j2ww-8383-6mw8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j2ww-8383-6mw8", - "modified": "2024-08-31T09:30:44Z", + "modified": "2024-09-13T21:31:21Z", "published": "2024-08-31T09:30:44Z", "aliases": [ "CVE-2024-8276" diff --git a/advisories/unreviewed/2024/08/GHSA-mvj8-h6fp-pcrp/GHSA-mvj8-h6fp-pcrp.json b/advisories/unreviewed/2024/08/GHSA-mvj8-h6fp-pcrp/GHSA-mvj8-h6fp-pcrp.json index f88cb5d929b..35eb1cfafba 100644 --- a/advisories/unreviewed/2024/08/GHSA-mvj8-h6fp-pcrp/GHSA-mvj8-h6fp-pcrp.json +++ b/advisories/unreviewed/2024/08/GHSA-mvj8-h6fp-pcrp/GHSA-mvj8-h6fp-pcrp.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mvj8-h6fp-pcrp", - "modified": "2024-08-29T12:31:05Z", + "modified": "2024-09-13T21:31:21Z", "published": "2024-08-29T12:31:05Z", "aliases": [ "CVE-2024-5623" ], "details": "An untrusted search path vulnerability in B&R APROL <= R 4.4-00P3 may be used by an authenticated local attacker to get other users to execute arbitrary code under their privileges.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" @@ -28,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-250" + "CWE-250", + "CWE-426" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-q7v4-578f-ph8j/GHSA-q7v4-578f-ph8j.json b/advisories/unreviewed/2024/08/GHSA-q7v4-578f-ph8j/GHSA-q7v4-578f-ph8j.json index b28cbaf01aa..072aedff77d 100644 --- a/advisories/unreviewed/2024/08/GHSA-q7v4-578f-ph8j/GHSA-q7v4-578f-ph8j.json +++ b/advisories/unreviewed/2024/08/GHSA-q7v4-578f-ph8j/GHSA-q7v4-578f-ph8j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q7v4-578f-ph8j", - "modified": "2024-08-28T12:30:33Z", + "modified": "2024-09-13T21:31:21Z", "published": "2024-08-28T12:30:33Z", "aliases": [ "CVE-2024-7447" diff --git a/advisories/unreviewed/2024/09/GHSA-24xq-67qf-j3xr/GHSA-24xq-67qf-j3xr.json b/advisories/unreviewed/2024/09/GHSA-24xq-67qf-j3xr/GHSA-24xq-67qf-j3xr.json index c6384ee890c..280804206b9 100644 --- a/advisories/unreviewed/2024/09/GHSA-24xq-67qf-j3xr/GHSA-24xq-67qf-j3xr.json +++ b/advisories/unreviewed/2024/09/GHSA-24xq-67qf-j3xr/GHSA-24xq-67qf-j3xr.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-770", "CWE-789" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/09/GHSA-2mjg-798r-mxwh/GHSA-2mjg-798r-mxwh.json b/advisories/unreviewed/2024/09/GHSA-2mjg-798r-mxwh/GHSA-2mjg-798r-mxwh.json index 9e649870653..8161b007dd8 100644 --- a/advisories/unreviewed/2024/09/GHSA-2mjg-798r-mxwh/GHSA-2mjg-798r-mxwh.json +++ b/advisories/unreviewed/2024/09/GHSA-2mjg-798r-mxwh/GHSA-2mjg-798r-mxwh.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-457" + "CWE-457", + "CWE-908" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-3q68-hm47-94vg/GHSA-3q68-hm47-94vg.json b/advisories/unreviewed/2024/09/GHSA-3q68-hm47-94vg/GHSA-3q68-hm47-94vg.json index 6d140d8d36f..244cb9ca70b 100644 --- a/advisories/unreviewed/2024/09/GHSA-3q68-hm47-94vg/GHSA-3q68-hm47-94vg.json +++ b/advisories/unreviewed/2024/09/GHSA-3q68-hm47-94vg/GHSA-3q68-hm47-94vg.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-457" + "CWE-457", + "CWE-908" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-3x4g-4374-v83h/GHSA-3x4g-4374-v83h.json b/advisories/unreviewed/2024/09/GHSA-3x4g-4374-v83h/GHSA-3x4g-4374-v83h.json new file mode 100644 index 00000000000..0154d9d07b5 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3x4g-4374-v83h/GHSA-3x4g-4374-v83h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3x4g-4374-v83h", + "modified": "2024-09-13T21:31:22Z", + "published": "2024-09-13T21:31:22Z", + "aliases": [ + "CVE-2024-44096" + ], + "details": "there is a possible arbitrary read due to an insecure default value. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44096" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-09-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-48wc-9j2c-rwp5/GHSA-48wc-9j2c-rwp5.json b/advisories/unreviewed/2024/09/GHSA-48wc-9j2c-rwp5/GHSA-48wc-9j2c-rwp5.json index 733722c1036..d4ecec4320f 100644 --- a/advisories/unreviewed/2024/09/GHSA-48wc-9j2c-rwp5/GHSA-48wc-9j2c-rwp5.json +++ b/advisories/unreviewed/2024/09/GHSA-48wc-9j2c-rwp5/GHSA-48wc-9j2c-rwp5.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-259" + "CWE-259", + "CWE-798" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-6qq3-v7mp-wx7q/GHSA-6qq3-v7mp-wx7q.json b/advisories/unreviewed/2024/09/GHSA-6qq3-v7mp-wx7q/GHSA-6qq3-v7mp-wx7q.json new file mode 100644 index 00000000000..fc2a7d16e4f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6qq3-v7mp-wx7q/GHSA-6qq3-v7mp-wx7q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6qq3-v7mp-wx7q", + "modified": "2024-09-13T21:31:22Z", + "published": "2024-09-13T21:31:22Z", + "aliases": [ + "CVE-2024-44095" + ], + "details": "In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible corrupt memory due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44095" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-09-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-974p-hhmc-6h46/GHSA-974p-hhmc-6h46.json b/advisories/unreviewed/2024/09/GHSA-974p-hhmc-6h46/GHSA-974p-hhmc-6h46.json index 57fd4ea76c3..f0d579bcaef 100644 --- a/advisories/unreviewed/2024/09/GHSA-974p-hhmc-6h46/GHSA-974p-hhmc-6h46.json +++ b/advisories/unreviewed/2024/09/GHSA-974p-hhmc-6h46/GHSA-974p-hhmc-6h46.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-974p-hhmc-6h46", - "modified": "2024-09-13T18:31:48Z", + "modified": "2024-09-13T21:31:22Z", "published": "2024-09-13T18:31:48Z", "aliases": [ "CVE-2024-39924" ], "details": "An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified in the authentication and authorization process of the endpoint responsible for altering the metadata of an emergency access. It permits an attacker with granted emergency access to escalate their privileges by changing the access level and modifying the wait time. Consequently, the attacker can gain full control over the vault (when only intended to have read access) while bypassing the necessary wait period.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T18:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-9g66-w5hj-vhx4/GHSA-9g66-w5hj-vhx4.json b/advisories/unreviewed/2024/09/GHSA-9g66-w5hj-vhx4/GHSA-9g66-w5hj-vhx4.json new file mode 100644 index 00000000000..335f63fe7d7 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-9g66-w5hj-vhx4/GHSA-9g66-w5hj-vhx4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9g66-w5hj-vhx4", + "modified": "2024-09-13T21:31:22Z", + "published": "2024-09-13T21:31:22Z", + "aliases": [ + "CVE-2024-44092" + ], + "details": "In TBD of TBD, there is a possible LCS signing enforcement missing due to test/debugging code left in a production build. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44092" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-09-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-cc7f-7qrj-r4v2/GHSA-cc7f-7qrj-r4v2.json b/advisories/unreviewed/2024/09/GHSA-cc7f-7qrj-r4v2/GHSA-cc7f-7qrj-r4v2.json index 88baf4312c7..f768c073ba9 100644 --- a/advisories/unreviewed/2024/09/GHSA-cc7f-7qrj-r4v2/GHSA-cc7f-7qrj-r4v2.json +++ b/advisories/unreviewed/2024/09/GHSA-cc7f-7qrj-r4v2/GHSA-cc7f-7qrj-r4v2.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cc7f-7qrj-r4v2", - "modified": "2024-09-06T15:32:58Z", + "modified": "2024-09-13T21:31:21Z", "published": "2024-09-06T15:32:58Z", "aliases": [ "CVE-2024-1744" ], "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ariva Computer Accord ORS allows Retrieve Embedded Sensitive Data.This issue affects Accord ORS: before 7.3.2.1.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-cf2w-h975-2fpg/GHSA-cf2w-h975-2fpg.json b/advisories/unreviewed/2024/09/GHSA-cf2w-h975-2fpg/GHSA-cf2w-h975-2fpg.json index cb7a2a62e72..c56d2a8e445 100644 --- a/advisories/unreviewed/2024/09/GHSA-cf2w-h975-2fpg/GHSA-cf2w-h975-2fpg.json +++ b/advisories/unreviewed/2024/09/GHSA-cf2w-h975-2fpg/GHSA-cf2w-h975-2fpg.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-457" + "CWE-457", + "CWE-908" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-cx6w-h9jj-x2vr/GHSA-cx6w-h9jj-x2vr.json b/advisories/unreviewed/2024/09/GHSA-cx6w-h9jj-x2vr/GHSA-cx6w-h9jj-x2vr.json index 21a440e2b6b..d4ba2e5e31c 100644 --- a/advisories/unreviewed/2024/09/GHSA-cx6w-h9jj-x2vr/GHSA-cx6w-h9jj-x2vr.json +++ b/advisories/unreviewed/2024/09/GHSA-cx6w-h9jj-x2vr/GHSA-cx6w-h9jj-x2vr.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-311" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-h827-7423-x2vc/GHSA-h827-7423-x2vc.json b/advisories/unreviewed/2024/09/GHSA-h827-7423-x2vc/GHSA-h827-7423-x2vc.json index 9911623d99e..5f262800cbf 100644 --- a/advisories/unreviewed/2024/09/GHSA-h827-7423-x2vc/GHSA-h827-7423-x2vc.json +++ b/advisories/unreviewed/2024/09/GHSA-h827-7423-x2vc/GHSA-h827-7423-x2vc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h827-7423-x2vc", - "modified": "2024-09-05T00:31:23Z", + "modified": "2024-09-13T21:31:21Z", "published": "2024-09-05T00:31:23Z", "aliases": [ "CVE-2024-45429" ], "details": "Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5 and earlier. If an attacker with the 'capability' setting privilege which is set in the product settings stores an arbitrary script in the field label, the script may be executed on the web browser of the logged-in user with the same privilege as the attacker's.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-04T23:15:12Z" diff --git a/advisories/unreviewed/2024/09/GHSA-jhgj-6hmm-vm6v/GHSA-jhgj-6hmm-vm6v.json b/advisories/unreviewed/2024/09/GHSA-jhgj-6hmm-vm6v/GHSA-jhgj-6hmm-vm6v.json index 3dde404e251..c16bb7a4cc6 100644 --- a/advisories/unreviewed/2024/09/GHSA-jhgj-6hmm-vm6v/GHSA-jhgj-6hmm-vm6v.json +++ b/advisories/unreviewed/2024/09/GHSA-jhgj-6hmm-vm6v/GHSA-jhgj-6hmm-vm6v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jhgj-6hmm-vm6v", - "modified": "2024-09-13T18:31:47Z", + "modified": "2024-09-13T21:31:22Z", "published": "2024-09-13T18:31:47Z", "aliases": [ "CVE-2024-44685" ], "details": "Titan SFTP and Titan MFT Server 2.0.25.2426 and earlier have a vulnerability a vulnerability where sensitive information, including passwords, is exposed in clear text within the JSON response when configuring SMTP settings via the Web UI.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T16:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-jm4p-4c99-gp7x/GHSA-jm4p-4c99-gp7x.json b/advisories/unreviewed/2024/09/GHSA-jm4p-4c99-gp7x/GHSA-jm4p-4c99-gp7x.json index fdd0a44a91a..2bdbbda25b8 100644 --- a/advisories/unreviewed/2024/09/GHSA-jm4p-4c99-gp7x/GHSA-jm4p-4c99-gp7x.json +++ b/advisories/unreviewed/2024/09/GHSA-jm4p-4c99-gp7x/GHSA-jm4p-4c99-gp7x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jm4p-4c99-gp7x", - "modified": "2024-09-13T18:31:47Z", + "modified": "2024-09-13T21:31:22Z", "published": "2024-09-13T18:31:47Z", "aliases": [ "CVE-2024-44798" ], "details": "phpgurukul Bus Pass Management System 1.0 is vulnerable to Cross-site scripting (XSS) in /admin/pass-bwdates-reports-details.php via fromdate and todate parameters.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T16:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-mcxm-8hr3-frmx/GHSA-mcxm-8hr3-frmx.json b/advisories/unreviewed/2024/09/GHSA-mcxm-8hr3-frmx/GHSA-mcxm-8hr3-frmx.json index 15da548c13e..e5dd2c60775 100644 --- a/advisories/unreviewed/2024/09/GHSA-mcxm-8hr3-frmx/GHSA-mcxm-8hr3-frmx.json +++ b/advisories/unreviewed/2024/09/GHSA-mcxm-8hr3-frmx/GHSA-mcxm-8hr3-frmx.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-798", "CWE-912" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/09/GHSA-p47w-6xhw-hhxj/GHSA-p47w-6xhw-hhxj.json b/advisories/unreviewed/2024/09/GHSA-p47w-6xhw-hhxj/GHSA-p47w-6xhw-hhxj.json new file mode 100644 index 00000000000..062220d8289 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-p47w-6xhw-hhxj/GHSA-p47w-6xhw-hhxj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p47w-6xhw-hhxj", + "modified": "2024-09-13T21:31:22Z", + "published": "2024-09-13T21:31:22Z", + "aliases": [ + "CVE-2024-44094" + ], + "details": "In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44094" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-09-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-p7wm-h6q7-mx95/GHSA-p7wm-h6q7-mx95.json b/advisories/unreviewed/2024/09/GHSA-p7wm-h6q7-mx95/GHSA-p7wm-h6q7-mx95.json index 52a381efe1e..83ef5ceab5b 100644 --- a/advisories/unreviewed/2024/09/GHSA-p7wm-h6q7-mx95/GHSA-p7wm-h6q7-mx95.json +++ b/advisories/unreviewed/2024/09/GHSA-p7wm-h6q7-mx95/GHSA-p7wm-h6q7-mx95.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-pq2c-46q4-qwg3/GHSA-pq2c-46q4-qwg3.json b/advisories/unreviewed/2024/09/GHSA-pq2c-46q4-qwg3/GHSA-pq2c-46q4-qwg3.json index 89a593ab95c..2be2e0d8f71 100644 --- a/advisories/unreviewed/2024/09/GHSA-pq2c-46q4-qwg3/GHSA-pq2c-46q4-qwg3.json +++ b/advisories/unreviewed/2024/09/GHSA-pq2c-46q4-qwg3/GHSA-pq2c-46q4-qwg3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pq2c-46q4-qwg3", - "modified": "2024-09-04T03:30:44Z", + "modified": "2024-09-13T21:31:21Z", "published": "2024-09-04T03:30:44Z", "aliases": [ "CVE-2024-41716" ], "details": "Cleartext storage of sensitive information vulnerability exists in WindLDR and WindO/I-NV4. If this vulnerability is exploited, an attacker who obtained the product's project file may obtain user credentials of the PLC or Operator Interfaces. As a result, an attacker may be able to manipulate and/or suspend the PLC and Operator Interfaces by accessing or hijacking them.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-312" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-04T01:15:11Z" diff --git a/advisories/unreviewed/2024/09/GHSA-q74x-f8wx-jrgv/GHSA-q74x-f8wx-jrgv.json b/advisories/unreviewed/2024/09/GHSA-q74x-f8wx-jrgv/GHSA-q74x-f8wx-jrgv.json new file mode 100644 index 00000000000..88d66a54012 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-q74x-f8wx-jrgv/GHSA-q74x-f8wx-jrgv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q74x-f8wx-jrgv", + "modified": "2024-09-13T21:31:22Z", + "published": "2024-09-13T21:31:22Z", + "aliases": [ + "CVE-2024-44093" + ], + "details": "In ppmp_unprotect_buf of drm/code/drm_fw.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44093" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-09-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-qf89-78m6-x24m/GHSA-qf89-78m6-x24m.json b/advisories/unreviewed/2024/09/GHSA-qf89-78m6-x24m/GHSA-qf89-78m6-x24m.json new file mode 100644 index 00000000000..69a200be01d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-qf89-78m6-x24m/GHSA-qf89-78m6-x24m.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qf89-78m6-x24m", + "modified": "2024-09-13T21:31:22Z", + "published": "2024-09-13T21:31:22Z", + "aliases": [ + "CVE-2024-8783" + ], + "details": "A vulnerability classified as problematic has been found in OpenTibiaBR MyAAC up to 0.8.16. Affected is an unknown function of the file system/pages/forum/new_post.php of the component Post Reply Handler. The manipulation of the argument post_topic leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The patch is identified as bf6ae3df0d32fa22552bb44ca4f8489a6e78cc1c. It is recommended to apply a patch to fix this issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8783" + }, + { + "type": "WEB", + "url": "https://github.com/opentibiabr/myaac/issues/121" + }, + { + "type": "WEB", + "url": "https://github.com/opentibiabr/myaac/pull/122" + }, + { + "type": "WEB", + "url": "https://github.com/opentibiabr/myaac/pull/122/commits/bf6ae3df0d32fa22552bb44ca4f8489a6e78cc1c" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.277434" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.277434" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.406368" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-r89w-9fr4-c7c9/GHSA-r89w-9fr4-c7c9.json b/advisories/unreviewed/2024/09/GHSA-r89w-9fr4-c7c9/GHSA-r89w-9fr4-c7c9.json index 9ac96bbfad3..75c38723a28 100644 --- a/advisories/unreviewed/2024/09/GHSA-r89w-9fr4-c7c9/GHSA-r89w-9fr4-c7c9.json +++ b/advisories/unreviewed/2024/09/GHSA-r89w-9fr4-c7c9/GHSA-r89w-9fr4-c7c9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r89w-9fr4-c7c9", - "modified": "2024-09-13T18:31:48Z", + "modified": "2024-09-13T21:31:22Z", "published": "2024-09-13T18:31:48Z", "aliases": [ "CVE-2024-39925" ], "details": "An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. It lacks an offboarding process for members who leave an organization. As a result, the shared organization key is not rotated when a member departs. Consequently, the departing member, whose access should be revoked, retains a copy of the organization key. Additionally, the application fails to adequately protect some encrypted data stored on the server. Consequently, an authenticated user could gain unauthorized access to encrypted data of any organization, even if the user is not a member of the targeted organization. However, the user would need to know the corresponding organizationId. Hence, if a user (whose access to an organization has been revoked) already possesses the organization key, that user could use the key to decrypt the leaked data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T18:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-rvhr-9pp2-823m/GHSA-rvhr-9pp2-823m.json b/advisories/unreviewed/2024/09/GHSA-rvhr-9pp2-823m/GHSA-rvhr-9pp2-823m.json index 59f94e46dba..b7fdc4375a9 100644 --- a/advisories/unreviewed/2024/09/GHSA-rvhr-9pp2-823m/GHSA-rvhr-9pp2-823m.json +++ b/advisories/unreviewed/2024/09/GHSA-rvhr-9pp2-823m/GHSA-rvhr-9pp2-823m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rvhr-9pp2-823m", - "modified": "2024-09-12T00:31:22Z", + "modified": "2024-09-13T21:31:22Z", "published": "2024-09-12T00:31:22Z", "aliases": [ "CVE-2024-7889" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-664" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-v3gc-cff3-2vg3/GHSA-v3gc-cff3-2vg3.json b/advisories/unreviewed/2024/09/GHSA-v3gc-cff3-2vg3/GHSA-v3gc-cff3-2vg3.json new file mode 100644 index 00000000000..1a3686911bd --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-v3gc-cff3-2vg3/GHSA-v3gc-cff3-2vg3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3gc-cff3-2vg3", + "modified": "2024-09-13T21:31:22Z", + "published": "2024-09-13T21:31:22Z", + "aliases": [ + "CVE-2024-44430" + ], + "details": "SQL Injection vulnerability in Best Free Law Office Management Software-v1.0 allows an attacker to execute arbitrary code and obtain sensitive information via a crafted payload to the kortex_lite/control/register_case.php interface", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44430" + }, + { + "type": "WEB", + "url": "https://blog.csdn.net/samwbs/article/details/140954482" + }, + { + "type": "WEB", + "url": "https://github.com/samwbs/kortexcve/blob/main/xss_register_case/XSS_register_case.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T20:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vfwm-h968-g65h/GHSA-vfwm-h968-g65h.json b/advisories/unreviewed/2024/09/GHSA-vfwm-h968-g65h/GHSA-vfwm-h968-g65h.json index 35044b5fc1b..03ac2b86be9 100644 --- a/advisories/unreviewed/2024/09/GHSA-vfwm-h968-g65h/GHSA-vfwm-h968-g65h.json +++ b/advisories/unreviewed/2024/09/GHSA-vfwm-h968-g65h/GHSA-vfwm-h968-g65h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vfwm-h968-g65h", - "modified": "2024-09-13T18:31:48Z", + "modified": "2024-09-13T21:31:22Z", "published": "2024-09-13T18:31:48Z", "aliases": [ "CVE-2024-39926" ], "details": "An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A stored cross-site scripting (XSS) or, due to the default CSP, HTML injection vulnerability has been discovered in the admin dashboard. This potentially allows an authenticated attacker to inject malicious code into the dashboard, which is then executed or rendered in the context of an administrator's browser when viewing the injected content. However, it is important to note that the default Content Security Policy (CSP) of the application blocks most exploitation paths, significantly mitigating the potential impact.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T18:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-vp6m-7x2g-h3wf/GHSA-vp6m-7x2g-h3wf.json b/advisories/unreviewed/2024/09/GHSA-vp6m-7x2g-h3wf/GHSA-vp6m-7x2g-h3wf.json index fefca255e4e..ceb1451d47d 100644 --- a/advisories/unreviewed/2024/09/GHSA-vp6m-7x2g-h3wf/GHSA-vp6m-7x2g-h3wf.json +++ b/advisories/unreviewed/2024/09/GHSA-vp6m-7x2g-h3wf/GHSA-vp6m-7x2g-h3wf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vp6m-7x2g-h3wf", - "modified": "2024-09-03T21:31:12Z", + "modified": "2024-09-13T21:31:21Z", "published": "2024-09-03T21:31:12Z", "aliases": [ "CVE-2024-45180" ], "details": "SquaredUp DS for SCOM 6.2.1.11104 allows XSS.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-03T20:15:08Z" diff --git a/advisories/unreviewed/2024/09/GHSA-x6p2-rpj7-w423/GHSA-x6p2-rpj7-w423.json b/advisories/unreviewed/2024/09/GHSA-x6p2-rpj7-w423/GHSA-x6p2-rpj7-w423.json new file mode 100644 index 00000000000..4cf977ba082 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-x6p2-rpj7-w423/GHSA-x6p2-rpj7-w423.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6p2-rpj7-w423", + "modified": "2024-09-13T21:31:22Z", + "published": "2024-09-13T21:31:22Z", + "aliases": [ + "CVE-2024-8784" + ], + "details": "A vulnerability classified as critical was found in QDocs Smart School Management System 7.0.0. Affected by this vulnerability is an unknown functionality of the file /user/chat/mynewuser of the component Chat. The manipulation of the argument users[] with the input 1'+AND+(SELECT+3220+FROM+(SELECT(SLEEP(5)))ZNun)+AND+'WwBM'%3d'WwBM as part of POST Request Parameter leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.0.1 is able to address this issue. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8784" + }, + { + "type": "WEB", + "url": "https://codecanyon.net/item/smart-school-school-management-system/19426018" + }, + { + "type": "WEB", + "url": "https://github.com/bytium/vulnerability-research/blob/main/Advisory%20for%20Time-Based%20Blind%20SQL%20Injection%20in%20QDocs%20Smart%20School.md" + }, + { + "type": "WEB", + "url": "https://smart-school.in/article/version-7-0-1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.277435" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.277435" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.407385" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xr4c-mmrv-3h6c/GHSA-xr4c-mmrv-3h6c.json b/advisories/unreviewed/2024/09/GHSA-xr4c-mmrv-3h6c/GHSA-xr4c-mmrv-3h6c.json new file mode 100644 index 00000000000..cdbe01fdcda --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xr4c-mmrv-3h6c/GHSA-xr4c-mmrv-3h6c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xr4c-mmrv-3h6c", + "modified": "2024-09-13T21:31:22Z", + "published": "2024-09-13T21:31:22Z", + "aliases": [ + "CVE-2024-29779" + ], + "details": "there is a possible escalation of privilege due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29779" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-09-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T21:15:10Z" + } +} \ No newline at end of file