From 018e4b1c76ea54badd48790627eebc97f59fce97 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 23 Jul 2024 03:32:02 +0000 Subject: [PATCH] Publish Advisories GHSA-25p8-9wv3-j93j GHSA-5mqx-rpxv-mvxj GHSA-hp5j-w8wg-jp3r GHSA-j7pf-cvcp-vq8q GHSA-mrv6-53xm-wqhf GHSA-p7hh-r4jx-72fm GHSA-qfc3-gmpf-rm94 GHSA-w52f-78r3-v89r --- .../GHSA-25p8-9wv3-j93j.json | 6 +- .../GHSA-5mqx-rpxv-mvxj.json | 38 ++++++++++++ .../GHSA-hp5j-w8wg-jp3r.json | 10 ++- .../GHSA-j7pf-cvcp-vq8q.json | 6 +- .../GHSA-mrv6-53xm-wqhf.json | 50 +++++++++++++++ .../GHSA-p7hh-r4jx-72fm.json | 6 +- .../GHSA-qfc3-gmpf-rm94.json | 62 +++++++++++++++++++ .../GHSA-w52f-78r3-v89r.json | 38 ++++++++++++ 8 files changed, 212 insertions(+), 4 deletions(-) create mode 100644 advisories/unreviewed/2024/07/GHSA-5mqx-rpxv-mvxj/GHSA-5mqx-rpxv-mvxj.json create mode 100644 advisories/unreviewed/2024/07/GHSA-mrv6-53xm-wqhf/GHSA-mrv6-53xm-wqhf.json create mode 100644 advisories/unreviewed/2024/07/GHSA-qfc3-gmpf-rm94/GHSA-qfc3-gmpf-rm94.json create mode 100644 advisories/unreviewed/2024/07/GHSA-w52f-78r3-v89r/GHSA-w52f-78r3-v89r.json diff --git a/advisories/unreviewed/2024/07/GHSA-25p8-9wv3-j93j/GHSA-25p8-9wv3-j93j.json b/advisories/unreviewed/2024/07/GHSA-25p8-9wv3-j93j/GHSA-25p8-9wv3-j93j.json index 001c824081e..e3a527c1c3d 100644 --- a/advisories/unreviewed/2024/07/GHSA-25p8-9wv3-j93j/GHSA-25p8-9wv3-j93j.json +++ b/advisories/unreviewed/2024/07/GHSA-25p8-9wv3-j93j/GHSA-25p8-9wv3-j93j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-25p8-9wv3-j93j", - "modified": "2024-07-22T21:30:40Z", + "modified": "2024-07-23T03:30:33Z", "published": "2024-07-22T21:30:40Z", "aliases": [ "CVE-2024-6913" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://cyberdanube.com/en/en-multiple-vulnerabilities-in-perten-processplus" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jul/13" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-5mqx-rpxv-mvxj/GHSA-5mqx-rpxv-mvxj.json b/advisories/unreviewed/2024/07/GHSA-5mqx-rpxv-mvxj/GHSA-5mqx-rpxv-mvxj.json new file mode 100644 index 00000000000..5132b17191e --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-5mqx-rpxv-mvxj/GHSA-5mqx-rpxv-mvxj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mqx-rpxv-mvxj", + "modified": "2024-07-23T03:30:33Z", + "published": "2024-07-23T03:30:33Z", + "aliases": [ + "CVE-2024-6717" + ], + "details": "HashiCorp Nomad and Nomad Enterprise 1.6.12 up to 1.7.9, and 1.8.1 archive unpacking during migration is vulnerable to path escaping of the allocation directory. This vulnerability, CVE-2024-6717, is fixed in Nomad 1.6.13, 1.7.10, and 1.8.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6717" + }, + { + "type": "WEB", + "url": "https://discuss.hashicorp.com/t/hcsec-2024-15-nomad-vulnerable-to-allocation-directory-path-escape-through-archive-unpacking/68781" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-610" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-23T01:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-hp5j-w8wg-jp3r/GHSA-hp5j-w8wg-jp3r.json b/advisories/unreviewed/2024/07/GHSA-hp5j-w8wg-jp3r/GHSA-hp5j-w8wg-jp3r.json index 55fb3e63735..d7c048a0a59 100644 --- a/advisories/unreviewed/2024/07/GHSA-hp5j-w8wg-jp3r/GHSA-hp5j-w8wg-jp3r.json +++ b/advisories/unreviewed/2024/07/GHSA-hp5j-w8wg-jp3r/GHSA-hp5j-w8wg-jp3r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hp5j-w8wg-jp3r", - "modified": "2024-07-04T09:32:49Z", + "modified": "2024-07-23T03:30:33Z", "published": "2024-07-04T09:32:49Z", "aliases": [ "CVE-2024-3904" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3904" }, + { + "type": "WEB", + "url": "https://jvn.jp/vu/JVNVU91215350/index.html" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-191-02" + }, { "type": "WEB", "url": "https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2024-003_en.pdf" diff --git a/advisories/unreviewed/2024/07/GHSA-j7pf-cvcp-vq8q/GHSA-j7pf-cvcp-vq8q.json b/advisories/unreviewed/2024/07/GHSA-j7pf-cvcp-vq8q/GHSA-j7pf-cvcp-vq8q.json index c9d7d8ff5a3..d69c3efd7fc 100644 --- a/advisories/unreviewed/2024/07/GHSA-j7pf-cvcp-vq8q/GHSA-j7pf-cvcp-vq8q.json +++ b/advisories/unreviewed/2024/07/GHSA-j7pf-cvcp-vq8q/GHSA-j7pf-cvcp-vq8q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j7pf-cvcp-vq8q", - "modified": "2024-07-22T21:30:41Z", + "modified": "2024-07-23T03:30:33Z", "published": "2024-07-22T21:30:40Z", "aliases": [ "CVE-2024-6912" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://cyberdanube.com/en/en-multiple-vulnerabilities-in-perten-processplus" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jul/13" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-mrv6-53xm-wqhf/GHSA-mrv6-53xm-wqhf.json b/advisories/unreviewed/2024/07/GHSA-mrv6-53xm-wqhf/GHSA-mrv6-53xm-wqhf.json new file mode 100644 index 00000000000..1021184d9fb --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-mrv6-53xm-wqhf/GHSA-mrv6-53xm-wqhf.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mrv6-53xm-wqhf", + "modified": "2024-07-23T03:30:33Z", + "published": "2024-07-23T03:30:33Z", + "aliases": [ + "CVE-2024-6885" + ], + "details": "The MaxiBlocks: 2200+ Patterns, 190 Pages, 14.2K Icons & 100 Styles plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maxi_remove_custom_image_size and maxi_add_custom_image_size functions in all versions up to, and including, 1.9.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6885" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/maxi-blocks/tags/1.9.2/core/class-maxi-image-crop.php#L100" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/maxi-blocks/tags/1.9.2/core/class-maxi-image-crop.php#L42" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/maxi-blocks/tags/1.9.2/plugin.php#L221" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/249b08c5-7429-4690-9f08-fc3f049aa62c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-23T02:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-p7hh-r4jx-72fm/GHSA-p7hh-r4jx-72fm.json b/advisories/unreviewed/2024/07/GHSA-p7hh-r4jx-72fm/GHSA-p7hh-r4jx-72fm.json index f215a9eab64..ef3b2d94287 100644 --- a/advisories/unreviewed/2024/07/GHSA-p7hh-r4jx-72fm/GHSA-p7hh-r4jx-72fm.json +++ b/advisories/unreviewed/2024/07/GHSA-p7hh-r4jx-72fm/GHSA-p7hh-r4jx-72fm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p7hh-r4jx-72fm", - "modified": "2024-07-22T21:30:40Z", + "modified": "2024-07-23T03:30:33Z", "published": "2024-07-22T21:30:40Z", "aliases": [ "CVE-2024-6911" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://cyberdanube.com/en/en-multiple-vulnerabilities-in-perten-processplus" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jul/13" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-qfc3-gmpf-rm94/GHSA-qfc3-gmpf-rm94.json b/advisories/unreviewed/2024/07/GHSA-qfc3-gmpf-rm94/GHSA-qfc3-gmpf-rm94.json new file mode 100644 index 00000000000..4debc0238a1 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-qfc3-gmpf-rm94/GHSA-qfc3-gmpf-rm94.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfc3-gmpf-rm94", + "modified": "2024-07-23T03:30:33Z", + "published": "2024-07-23T03:30:33Z", + "aliases": [ + "CVE-2024-6828" + ], + "details": "The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization and capability checks on the Redux_Color_Scheme_Import function in versions 4.4.12 to 4.4.17. This makes it possible for unauthenticated attackers to upload JSON files, which can be used to conduct stored cross-site scripting attacks and, in some rare cases, when the wp_filesystem fails to initialize - to Remote Code Execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6828" + }, + { + "type": "WEB", + "url": "https://core.trac.wordpress.org/browser/tags/6.5.4/src/wp-includes/class-wp-theme-json.php#L1690" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/redux-framework/tags/4.4.17/redux-core/inc/classes/class-redux-filesystem.php#L614" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/redux-framework/tags/4.4.17/redux-core/inc/classes/class-redux-helpers.php#L938" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/redux-framework/tags/4.4.17/redux-core/inc/extensions/color_scheme/color_scheme/class-redux-color-scheme-import.php#L75" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/redux-framework/tags/4.4.17/redux-core/inc/fields/typography/redux-typography.js#L646" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/redux-framework/trunk/redux-core/inc/classes/class-redux-filesystem.php#L166" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/18a37063-31aa-4b1f-b1a5-1ea921a20686?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-23T02:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-w52f-78r3-v89r/GHSA-w52f-78r3-v89r.json b/advisories/unreviewed/2024/07/GHSA-w52f-78r3-v89r/GHSA-w52f-78r3-v89r.json new file mode 100644 index 00000000000..a69d0a7ee2d --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-w52f-78r3-v89r/GHSA-w52f-78r3-v89r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w52f-78r3-v89r", + "modified": "2024-07-23T03:30:33Z", + "published": "2024-07-23T03:30:33Z", + "aliases": [ + "CVE-2024-1575" + ], + "details": "The improper privilege management vulnerability in the Zyxel WBE660S firmware version 6.70(ACGG.3) and earlier versions could allow an authenticated user to escalate privileges and download the configuration files on a vulnerable device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1575" + }, + { + "type": "WEB", + "url": "https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-improper-privilege-management-vulnerability-in-aps-07-23-2024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-23T02:15:02Z" + } +} \ No newline at end of file