diff --git a/advisories/unreviewed/2024/10/GHSA-cm5g-3pgc-8rg4/GHSA-cm5g-3pgc-8rg4.json b/advisories/github-reviewed/2024/10/GHSA-cm5g-3pgc-8rg4/GHSA-cm5g-3pgc-8rg4.json similarity index 68% rename from advisories/unreviewed/2024/10/GHSA-cm5g-3pgc-8rg4/GHSA-cm5g-3pgc-8rg4.json rename to advisories/github-reviewed/2024/10/GHSA-cm5g-3pgc-8rg4/GHSA-cm5g-3pgc-8rg4.json index 0e1315d3c8f..dc76f536e22 100644 --- a/advisories/unreviewed/2024/10/GHSA-cm5g-3pgc-8rg4/GHSA-cm5g-3pgc-8rg4.json +++ b/advisories/github-reviewed/2024/10/GHSA-cm5g-3pgc-8rg4/GHSA-cm5g-3pgc-8rg4.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-cm5g-3pgc-8rg4", - "modified": "2024-11-07T00:30:36Z", + "modified": "2024-11-25T21:31:20Z", "published": "2024-10-29T18:30:37Z", "aliases": [ "CVE-2024-10491" ], + "summary": "Express ressource injection", "details": "A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in the Link header when unsanitized data is used.\n\nThe issue arises from improper sanitization in `Link` header values, which can allow a combination of characters like `,`, `;`, and `<>` to preload malicious resources.\n\nThis vulnerability is especially relevant for dynamic parameters.", "severity": [ { @@ -14,7 +15,25 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "npm", + "name": "express" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "3.21.4" + } + ] + } + ] + } ], "references": [ { @@ -31,8 +50,8 @@ "CWE-74" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-11-25T21:31:20Z", "nvd_published_at": "2024-10-29T17:15:03Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-ww86-3cc2-9g27/GHSA-ww86-3cc2-9g27.json b/advisories/unreviewed/2023/07/GHSA-ww86-3cc2-9g27/GHSA-ww86-3cc2-9g27.json index 5c1f96df475..83be5e07ebe 100644 --- a/advisories/unreviewed/2023/07/GHSA-ww86-3cc2-9g27/GHSA-ww86-3cc2-9g27.json +++ b/advisories/unreviewed/2023/07/GHSA-ww86-3cc2-9g27/GHSA-ww86-3cc2-9g27.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-8m6h-q36w-xvg7/GHSA-8m6h-q36w-xvg7.json b/advisories/unreviewed/2024/02/GHSA-8m6h-q36w-xvg7/GHSA-8m6h-q36w-xvg7.json index 7900f8f4802..6ad5040e8b1 100644 --- a/advisories/unreviewed/2024/02/GHSA-8m6h-q36w-xvg7/GHSA-8m6h-q36w-xvg7.json +++ b/advisories/unreviewed/2024/02/GHSA-8m6h-q36w-xvg7/GHSA-8m6h-q36w-xvg7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8m6h-q36w-xvg7", - "modified": "2024-02-15T09:30:35Z", + "modified": "2024-11-25T21:30:48Z", "published": "2024-02-15T09:30:35Z", "aliases": [ "CVE-2024-0353" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0353" }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/179495/ESET-NOD32-Antivirus-17.2.7.0-Unquoted-Service-Path.html" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/182464/ESET-NOD32-Antivirus-18.0.12.0-Unquoted-Service-Path.html" + }, { "type": "WEB", "url": "https://support.eset.com/en/ca8612-eset-customer-advisory-link-following-local-privilege-escalation-vulnerability-in-eset-products-for-windows-fixed" diff --git a/advisories/unreviewed/2024/02/GHSA-xx6x-c9h6-h6fv/GHSA-xx6x-c9h6-h6fv.json b/advisories/unreviewed/2024/02/GHSA-xx6x-c9h6-h6fv/GHSA-xx6x-c9h6-h6fv.json index 65727e6c5cf..4f62f465a47 100644 --- a/advisories/unreviewed/2024/02/GHSA-xx6x-c9h6-h6fv/GHSA-xx6x-c9h6-h6fv.json +++ b/advisories/unreviewed/2024/02/GHSA-xx6x-c9h6-h6fv/GHSA-xx6x-c9h6-h6fv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xx6x-c9h6-h6fv", - "modified": "2024-02-26T18:30:31Z", + "modified": "2024-11-25T21:30:48Z", "published": "2024-02-26T18:30:31Z", "aliases": [ "CVE-2024-26465" ], "details": "A DOM based cross-site scripting (XSS) vulnerability in the component /beep/Beep.Instrument.js of stewdio beep.js before commit ef22ad7 allows attackers to execute arbitrary Javascript via sending a crafted URL.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-26T16:27:59Z" diff --git a/advisories/unreviewed/2024/03/GHSA-3r58-xjch-5xjp/GHSA-3r58-xjch-5xjp.json b/advisories/unreviewed/2024/03/GHSA-3r58-xjch-5xjp/GHSA-3r58-xjch-5xjp.json index fe8ef3581a8..c7a7e49cb9d 100644 --- a/advisories/unreviewed/2024/03/GHSA-3r58-xjch-5xjp/GHSA-3r58-xjch-5xjp.json +++ b/advisories/unreviewed/2024/03/GHSA-3r58-xjch-5xjp/GHSA-3r58-xjch-5xjp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3r58-xjch-5xjp", - "modified": "2024-03-18T06:30:51Z", + "modified": "2024-11-25T21:30:48Z", "published": "2024-03-18T06:30:51Z", "aliases": [ "CVE-2021-47157" ], "details": "The Kossy module before 0.60 for Perl allows JSON hijacking because of X-Requested-With mishandling.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-346" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-18T05:15:06Z" diff --git a/advisories/unreviewed/2024/04/GHSA-fc5p-cp62-fgpc/GHSA-fc5p-cp62-fgpc.json b/advisories/unreviewed/2024/04/GHSA-fc5p-cp62-fgpc/GHSA-fc5p-cp62-fgpc.json index b2b3c7aa51f..cacb3bddd06 100644 --- a/advisories/unreviewed/2024/04/GHSA-fc5p-cp62-fgpc/GHSA-fc5p-cp62-fgpc.json +++ b/advisories/unreviewed/2024/04/GHSA-fc5p-cp62-fgpc/GHSA-fc5p-cp62-fgpc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fc5p-cp62-fgpc", - "modified": "2024-04-26T03:30:29Z", + "modified": "2024-11-25T21:30:48Z", "published": "2024-04-26T03:30:29Z", "aliases": [ "CVE-2024-33667" ], "details": "An issue was discovered in Zammad before 6.3.0. An authenticated agent could perform a remote Denial of Service attack by calling an endpoint that accepts a generic method name, which was not properly sanitized against an allowlist.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-26T01:15:46Z" diff --git a/advisories/unreviewed/2024/04/GHSA-p5g2-89mm-prg6/GHSA-p5g2-89mm-prg6.json b/advisories/unreviewed/2024/04/GHSA-p5g2-89mm-prg6/GHSA-p5g2-89mm-prg6.json index 966378b04cb..bf8d88b8337 100644 --- a/advisories/unreviewed/2024/04/GHSA-p5g2-89mm-prg6/GHSA-p5g2-89mm-prg6.json +++ b/advisories/unreviewed/2024/04/GHSA-p5g2-89mm-prg6/GHSA-p5g2-89mm-prg6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p5g2-89mm-prg6", - "modified": "2024-04-11T03:35:00Z", + "modified": "2024-11-25T21:30:48Z", "published": "2024-04-11T03:35:00Z", "aliases": [ "CVE-2024-26019" ], "details": "Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in submit processing. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing to the website using the product.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-11T03:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-wq89-j555-p43g/GHSA-wq89-j555-p43g.json b/advisories/unreviewed/2024/04/GHSA-wq89-j555-p43g/GHSA-wq89-j555-p43g.json index f45533720cd..1a138b351e3 100644 --- a/advisories/unreviewed/2024/04/GHSA-wq89-j555-p43g/GHSA-wq89-j555-p43g.json +++ b/advisories/unreviewed/2024/04/GHSA-wq89-j555-p43g/GHSA-wq89-j555-p43g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wq89-j555-p43g", - "modified": "2024-04-15T06:30:34Z", + "modified": "2024-11-25T21:30:48Z", "published": "2024-04-15T06:30:34Z", "aliases": [ "CVE-2024-1712" ], "details": "The Carousel Slider WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-15T05:15:14Z" diff --git a/advisories/unreviewed/2024/05/GHSA-m29j-f39x-2r24/GHSA-m29j-f39x-2r24.json b/advisories/unreviewed/2024/05/GHSA-m29j-f39x-2r24/GHSA-m29j-f39x-2r24.json index 1fb770296cd..95366cd6267 100644 --- a/advisories/unreviewed/2024/05/GHSA-m29j-f39x-2r24/GHSA-m29j-f39x-2r24.json +++ b/advisories/unreviewed/2024/05/GHSA-m29j-f39x-2r24/GHSA-m29j-f39x-2r24.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m29j-f39x-2r24", - "modified": "2024-05-14T18:30:46Z", + "modified": "2024-11-25T21:30:48Z", "published": "2024-05-14T18:30:46Z", "aliases": [ "CVE-2024-32606" ], "details": "HDF5 Library through 1.14.3 may attempt to dereference uninitialized values in h5tools_str_sprint in tools/lib/h5tools_str.c (called from h5tools_dump_simple_data in tools/lib/h5tools_dump.c).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-908" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:36:45Z" diff --git a/advisories/unreviewed/2024/06/GHSA-4xhv-qc2f-6267/GHSA-4xhv-qc2f-6267.json b/advisories/unreviewed/2024/06/GHSA-4xhv-qc2f-6267/GHSA-4xhv-qc2f-6267.json index fa0b5ff2b48..1a18d62c200 100644 --- a/advisories/unreviewed/2024/06/GHSA-4xhv-qc2f-6267/GHSA-4xhv-qc2f-6267.json +++ b/advisories/unreviewed/2024/06/GHSA-4xhv-qc2f-6267/GHSA-4xhv-qc2f-6267.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4xhv-qc2f-6267", - "modified": "2024-06-29T21:30:47Z", + "modified": "2024-11-25T21:30:48Z", "published": "2024-06-29T21:30:47Z", "aliases": [ "CVE-2024-39846" ], "details": "NewPass before 1.2.0 stores passwords (rather than password hashes) directly, which makes it easier to obtain unauthorized access to sensitive information. NOTE: in each case, data at rest is encrypted, but is decrypted within process memory during use.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-312" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-29T21:15:09Z" diff --git a/advisories/unreviewed/2024/07/GHSA-28xh-chph-8x29/GHSA-28xh-chph-8x29.json b/advisories/unreviewed/2024/07/GHSA-28xh-chph-8x29/GHSA-28xh-chph-8x29.json index fd6b258b621..ae209a81293 100644 --- a/advisories/unreviewed/2024/07/GHSA-28xh-chph-8x29/GHSA-28xh-chph-8x29.json +++ b/advisories/unreviewed/2024/07/GHSA-28xh-chph-8x29/GHSA-28xh-chph-8x29.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-28xh-chph-8x29", - "modified": "2024-07-10T09:30:41Z", + "modified": "2024-11-25T21:30:48Z", "published": "2024-07-10T09:30:41Z", "aliases": [ "CVE-2024-39490" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: sr: fix missing sk_buff release in seg6_input_core\n\nThe seg6_input() function is responsible for adding the SRH into a\npacket, delegating the operation to the seg6_input_core(). This function\nuses the skb_cow_head() to ensure that there is sufficient headroom in\nthe sk_buff for accommodating the link-layer header.\nIn the event that the skb_cow_header() function fails, the\nseg6_input_core() catches the error but it does not release the sk_buff,\nwhich will result in a memory leak.\n\nThis issue was introduced in commit af3b5158b89d (\"ipv6: sr: fix BUG due\nto headroom too small after SRH push\") and persists even after commit\n7a3f5b0de364 (\"netfilter: add netfilter hooks to SRv6 data plane\"),\nwhere the entire seg6_input() code was refactored to deal with netfilter\nhooks.\n\nThe proposed patch addresses the identified memory leak by requiring the\nseg6_input_core() function to release the sk_buff in the event that\nskb_cow_head() fails.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-10T08:15:11Z" diff --git a/advisories/unreviewed/2024/09/GHSA-354q-9jjr-5vm7/GHSA-354q-9jjr-5vm7.json b/advisories/unreviewed/2024/09/GHSA-354q-9jjr-5vm7/GHSA-354q-9jjr-5vm7.json index 9807700914c..769ca062927 100644 --- a/advisories/unreviewed/2024/09/GHSA-354q-9jjr-5vm7/GHSA-354q-9jjr-5vm7.json +++ b/advisories/unreviewed/2024/09/GHSA-354q-9jjr-5vm7/GHSA-354q-9jjr-5vm7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-354q-9jjr-5vm7", - "modified": "2024-09-30T21:02:13Z", + "modified": "2024-11-25T21:30:48Z", "published": "2024-09-30T21:02:13Z", "aliases": [ "CVE-2024-28811" ], "details": "An issue was discovered in Infinera hiT 7300 5.60.50. A web application allows a remote privileged attacker to execute applications contained in a specific OS directory via HTTP invocations.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-30T19:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-cwq5-xwx7-85wm/GHSA-cwq5-xwx7-85wm.json b/advisories/unreviewed/2024/09/GHSA-cwq5-xwx7-85wm/GHSA-cwq5-xwx7-85wm.json index 035d703b51b..90625b35b86 100644 --- a/advisories/unreviewed/2024/09/GHSA-cwq5-xwx7-85wm/GHSA-cwq5-xwx7-85wm.json +++ b/advisories/unreviewed/2024/09/GHSA-cwq5-xwx7-85wm/GHSA-cwq5-xwx7-85wm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cwq5-xwx7-85wm", - "modified": "2024-09-10T12:30:35Z", + "modified": "2024-11-25T21:30:48Z", "published": "2024-09-06T06:31:41Z", "aliases": [ "CVE-2024-45751" ], "details": "tgt (aka Linux target framework) before 1.0.93 attempts to achieve entropy by calling rand without srand. The PRNG seed is always 1, and thus the sequence of challenges is always identical.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,13 +32,17 @@ { "type": "WEB", "url": "https://www.openwall.com/lists/oss-security/2024/09/07/2" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/09/07/2" } ], "database_specific": { "cwe_ids": [ - + "CWE-338" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-06T05:15:13Z" diff --git a/advisories/unreviewed/2024/10/GHSA-33v4-22cq-m9g2/GHSA-33v4-22cq-m9g2.json b/advisories/unreviewed/2024/10/GHSA-33v4-22cq-m9g2/GHSA-33v4-22cq-m9g2.json index 5e7e9dd6792..c82c35fea94 100644 --- a/advisories/unreviewed/2024/10/GHSA-33v4-22cq-m9g2/GHSA-33v4-22cq-m9g2.json +++ b/advisories/unreviewed/2024/10/GHSA-33v4-22cq-m9g2/GHSA-33v4-22cq-m9g2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-33v4-22cq-m9g2", - "modified": "2024-10-26T12:30:43Z", + "modified": "2024-11-25T21:30:48Z", "published": "2024-10-26T12:30:43Z", "aliases": [ "CVE-2024-9772" diff --git a/advisories/unreviewed/2024/10/GHSA-w6g8-4xp6-6cr3/GHSA-w6g8-4xp6-6cr3.json b/advisories/unreviewed/2024/10/GHSA-w6g8-4xp6-6cr3/GHSA-w6g8-4xp6-6cr3.json index 7e461f52aea..17848395e2b 100644 --- a/advisories/unreviewed/2024/10/GHSA-w6g8-4xp6-6cr3/GHSA-w6g8-4xp6-6cr3.json +++ b/advisories/unreviewed/2024/10/GHSA-w6g8-4xp6-6cr3/GHSA-w6g8-4xp6-6cr3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w6g8-4xp6-6cr3", - "modified": "2024-10-12T06:31:30Z", + "modified": "2024-11-25T21:30:48Z", "published": "2024-10-12T06:31:30Z", "aliases": [ "CVE-2024-9776" diff --git a/advisories/unreviewed/2024/11/GHSA-2c4h-jg67-pgcw/GHSA-2c4h-jg67-pgcw.json b/advisories/unreviewed/2024/11/GHSA-2c4h-jg67-pgcw/GHSA-2c4h-jg67-pgcw.json index 4e7ea11553e..9e57dad030f 100644 --- a/advisories/unreviewed/2024/11/GHSA-2c4h-jg67-pgcw/GHSA-2c4h-jg67-pgcw.json +++ b/advisories/unreviewed/2024/11/GHSA-2c4h-jg67-pgcw/GHSA-2c4h-jg67-pgcw.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-363w-4gjr-hxxf/GHSA-363w-4gjr-hxxf.json b/advisories/unreviewed/2024/11/GHSA-363w-4gjr-hxxf/GHSA-363w-4gjr-hxxf.json index 93c7a99d89c..0f2acda0533 100644 --- a/advisories/unreviewed/2024/11/GHSA-363w-4gjr-hxxf/GHSA-363w-4gjr-hxxf.json +++ b/advisories/unreviewed/2024/11/GHSA-363w-4gjr-hxxf/GHSA-363w-4gjr-hxxf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-363w-4gjr-hxxf", - "modified": "2024-11-19T18:31:07Z", + "modified": "2024-11-25T21:30:49Z", "published": "2024-11-19T18:31:07Z", "aliases": [ "CVE-2024-53070" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: dwc3: fix fault at system suspend if device was already runtime suspended\n\nIf the device was already runtime suspended then during system suspend\nwe cannot access the device registers else it will crash.\n\nAlso we cannot access any registers after dwc3_core_exit() on some\nplatforms so move the dwc3_enable_susphy() call to the top.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T18:15:26Z" diff --git a/advisories/unreviewed/2024/11/GHSA-37xg-wj5r-mvrr/GHSA-37xg-wj5r-mvrr.json b/advisories/unreviewed/2024/11/GHSA-37xg-wj5r-mvrr/GHSA-37xg-wj5r-mvrr.json index ec3eca29ddf..3a5263664f6 100644 --- a/advisories/unreviewed/2024/11/GHSA-37xg-wj5r-mvrr/GHSA-37xg-wj5r-mvrr.json +++ b/advisories/unreviewed/2024/11/GHSA-37xg-wj5r-mvrr/GHSA-37xg-wj5r-mvrr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-37xg-wj5r-mvrr", - "modified": "2024-11-15T18:30:51Z", + "modified": "2024-11-25T21:30:48Z", "published": "2024-11-15T18:30:51Z", "aliases": [ "CVE-2024-46462" ], "details": "By default, dedicated folders of ZEDMAIL for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ZEDMAIL has to be modified to prevent this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T18:15:28Z" diff --git a/advisories/unreviewed/2024/11/GHSA-3h3v-7x89-cc9g/GHSA-3h3v-7x89-cc9g.json b/advisories/unreviewed/2024/11/GHSA-3h3v-7x89-cc9g/GHSA-3h3v-7x89-cc9g.json index 752d43ac5d3..76808fa1f09 100644 --- a/advisories/unreviewed/2024/11/GHSA-3h3v-7x89-cc9g/GHSA-3h3v-7x89-cc9g.json +++ b/advisories/unreviewed/2024/11/GHSA-3h3v-7x89-cc9g/GHSA-3h3v-7x89-cc9g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3h3v-7x89-cc9g", - "modified": "2024-11-14T00:31:11Z", + "modified": "2024-11-25T21:30:48Z", "published": "2024-11-14T00:31:11Z", "aliases": [ "CVE-2024-40405" ], "details": "Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker via a crafted request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-13T23:15:03Z" diff --git a/advisories/unreviewed/2024/11/GHSA-3pc7-c3mc-73r6/GHSA-3pc7-c3mc-73r6.json b/advisories/unreviewed/2024/11/GHSA-3pc7-c3mc-73r6/GHSA-3pc7-c3mc-73r6.json index f58dd0d37dc..89bc31059bd 100644 --- a/advisories/unreviewed/2024/11/GHSA-3pc7-c3mc-73r6/GHSA-3pc7-c3mc-73r6.json +++ b/advisories/unreviewed/2024/11/GHSA-3pc7-c3mc-73r6/GHSA-3pc7-c3mc-73r6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3pc7-c3mc-73r6", - "modified": "2024-11-15T18:30:52Z", + "modified": "2024-11-25T21:30:48Z", "published": "2024-11-15T18:30:52Z", "aliases": [ "CVE-2024-46465" ], "details": "By default, dedicated folders of CRYHOD for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of CRYHOD has to be modified to prevent this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T18:15:28Z" diff --git a/advisories/unreviewed/2024/11/GHSA-3wxw-9pjm-38cr/GHSA-3wxw-9pjm-38cr.json b/advisories/unreviewed/2024/11/GHSA-3wxw-9pjm-38cr/GHSA-3wxw-9pjm-38cr.json new file mode 100644 index 00000000000..b3155babc19 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3wxw-9pjm-38cr/GHSA-3wxw-9pjm-38cr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wxw-9pjm-38cr", + "modified": "2024-11-25T21:30:50Z", + "published": "2024-11-25T21:30:50Z", + "aliases": [ + "CVE-2024-53599" + ], + "details": "A cross-site scripting (XSS) vulnerability in the /scroll.php endpoint of LafeLabs Chaos v0.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53599" + }, + { + "type": "WEB", + "url": "https://github.com/NoPurposeInLife/vulnerability_research/tree/main/CVE-2024-53599" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T19:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-47m4-p2m7-6fv5/GHSA-47m4-p2m7-6fv5.json b/advisories/unreviewed/2024/11/GHSA-47m4-p2m7-6fv5/GHSA-47m4-p2m7-6fv5.json index f22fefdd906..f70f6627efd 100644 --- a/advisories/unreviewed/2024/11/GHSA-47m4-p2m7-6fv5/GHSA-47m4-p2m7-6fv5.json +++ b/advisories/unreviewed/2024/11/GHSA-47m4-p2m7-6fv5/GHSA-47m4-p2m7-6fv5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-47m4-p2m7-6fv5", - "modified": "2024-11-22T21:32:15Z", + "modified": "2024-11-25T21:30:49Z", "published": "2024-11-22T21:32:15Z", "aliases": [ "CVE-2024-51073" ], "details": "An issue in Instrument Cluster KIA Seltos Software v1.0, Hardware v1.0 allows attackers to disrupt communications between the Instrument cluster and CAN bus.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-22T16:15:33Z" diff --git a/advisories/unreviewed/2024/11/GHSA-4c64-c9rj-qw7x/GHSA-4c64-c9rj-qw7x.json b/advisories/unreviewed/2024/11/GHSA-4c64-c9rj-qw7x/GHSA-4c64-c9rj-qw7x.json new file mode 100644 index 00000000000..d39b25622a4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4c64-c9rj-qw7x/GHSA-4c64-c9rj-qw7x.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4c64-c9rj-qw7x", + "modified": "2024-11-25T21:30:50Z", + "published": "2024-11-25T21:30:50Z", + "aliases": [ + "CVE-2024-53556" + ], + "details": "An Open Redirect vulnerability in Taiga v6.8.1 allows attackers to redirect users to arbitrary websites via appending a crafted link to /login?next= in the login page URL.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53556" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1CIr8oHSF4JaqOn51wIhyZyvsCtlX0Q_e/view?usp=drive_link" + }, + { + "type": "WEB", + "url": "https://gist.githubusercontent.com/Tommywarren/b42479a048aa8ef11a63a76d14403443/raw/e24c1003accf8daf2e840b7c67d2f0ab30bdd3e6/CVE-2024-53556" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T21:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4crp-rgr3-rv8m/GHSA-4crp-rgr3-rv8m.json b/advisories/unreviewed/2024/11/GHSA-4crp-rgr3-rv8m/GHSA-4crp-rgr3-rv8m.json index e90e50a874e..40501c17547 100644 --- a/advisories/unreviewed/2024/11/GHSA-4crp-rgr3-rv8m/GHSA-4crp-rgr3-rv8m.json +++ b/advisories/unreviewed/2024/11/GHSA-4crp-rgr3-rv8m/GHSA-4crp-rgr3-rv8m.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-4f73-836m-4mcr/GHSA-4f73-836m-4mcr.json b/advisories/unreviewed/2024/11/GHSA-4f73-836m-4mcr/GHSA-4f73-836m-4mcr.json index 6f4fb9f5c4c..9fd4cb2f4de 100644 --- a/advisories/unreviewed/2024/11/GHSA-4f73-836m-4mcr/GHSA-4f73-836m-4mcr.json +++ b/advisories/unreviewed/2024/11/GHSA-4f73-836m-4mcr/GHSA-4f73-836m-4mcr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4f73-836m-4mcr", - "modified": "2024-11-19T18:31:07Z", + "modified": "2024-11-25T21:30:49Z", "published": "2024-11-19T18:31:07Z", "aliases": [ "CVE-2024-53073" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Never decrement pending_async_copies on error\n\nThe error flow in nfsd4_copy() calls cleanup_async_copy(), which\nalready decrements nn->pending_async_copies.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T18:15:26Z" diff --git a/advisories/unreviewed/2024/11/GHSA-4hxp-5wxw-83f8/GHSA-4hxp-5wxw-83f8.json b/advisories/unreviewed/2024/11/GHSA-4hxp-5wxw-83f8/GHSA-4hxp-5wxw-83f8.json index 1dc2e2debbb..06bbacaaab0 100644 --- a/advisories/unreviewed/2024/11/GHSA-4hxp-5wxw-83f8/GHSA-4hxp-5wxw-83f8.json +++ b/advisories/unreviewed/2024/11/GHSA-4hxp-5wxw-83f8/GHSA-4hxp-5wxw-83f8.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-56wh-6gx4-4442/GHSA-56wh-6gx4-4442.json b/advisories/unreviewed/2024/11/GHSA-56wh-6gx4-4442/GHSA-56wh-6gx4-4442.json index a2973e81c54..82c4ee58026 100644 --- a/advisories/unreviewed/2024/11/GHSA-56wh-6gx4-4442/GHSA-56wh-6gx4-4442.json +++ b/advisories/unreviewed/2024/11/GHSA-56wh-6gx4-4442/GHSA-56wh-6gx4-4442.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-56wh-6gx4-4442", - "modified": "2024-11-19T18:31:07Z", + "modified": "2024-11-25T21:30:48Z", "published": "2024-11-19T18:31:07Z", "aliases": [ "CVE-2024-53065" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/slab: fix warning caused by duplicate kmem_cache creation in kmem_buckets_create\n\nCommit b035f5a6d852 (\"mm: slab: reduce the kmalloc() minimum alignment\nif DMA bouncing possible\") reduced ARCH_KMALLOC_MINALIGN to 8 on arm64.\nHowever, with KASAN_HW_TAGS enabled, arch_slab_minalign() becomes 16.\nThis causes kmalloc_caches[*][8] to be aliased to kmalloc_caches[*][16],\nresulting in kmem_buckets_create() attempting to create a kmem_cache for\nsize 16 twice. This duplication triggers warnings on boot:\n\n[ 2.325108] ------------[ cut here ]------------\n[ 2.325135] kmem_cache of name 'memdup_user-16' already exists\n[ 2.325783] WARNING: CPU: 0 PID: 1 at mm/slab_common.c:107 __kmem_cache_create_args+0xb8/0x3b0\n[ 2.327957] Modules linked in:\n[ 2.328550] CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.12.0-rc5mm-unstable-arm64+ #12\n[ 2.328683] Hardware name: QEMU QEMU Virtual Machine, BIOS 2024.02-2 03/11/2024\n[ 2.328790] pstate: 61000009 (nZCv daif -PAN -UAO -TCO +DIT -SSBS BTYPE=--)\n[ 2.328911] pc : __kmem_cache_create_args+0xb8/0x3b0\n[ 2.328930] lr : __kmem_cache_create_args+0xb8/0x3b0\n[ 2.328942] sp : ffff800083d6fc50\n[ 2.328961] x29: ffff800083d6fc50 x28: f2ff0000c1674410 x27: ffff8000820b0598\n[ 2.329061] x26: 000000007fffffff x25: 0000000000000010 x24: 0000000000002000\n[ 2.329101] x23: ffff800083d6fce8 x22: ffff8000832222e8 x21: ffff800083222388\n[ 2.329118] x20: f2ff0000c1674410 x19: f5ff0000c16364c0 x18: ffff800083d80030\n[ 2.329135] x17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000000\n[ 2.329152] x14: 0000000000000000 x13: 0a73747369786520 x12: 79646165726c6120\n[ 2.329169] x11: 656820747563205b x10: 2d2d2d2d2d2d2d2d x9 : 0000000000000000\n[ 2.329194] x8 : 0000000000000000 x7 : 0000000000000000 x6 : 0000000000000000\n[ 2.329210] x5 : 0000000000000000 x4 : 0000000000000000 x3 : 0000000000000000\n[ 2.329226] x2 : 0000000000000000 x1 : 0000000000000000 x0 : 0000000000000000\n[ 2.329291] Call trace:\n[ 2.329407] __kmem_cache_create_args+0xb8/0x3b0\n[ 2.329499] kmem_buckets_create+0xfc/0x320\n[ 2.329526] init_user_buckets+0x34/0x78\n[ 2.329540] do_one_initcall+0x64/0x3c8\n[ 2.329550] kernel_init_freeable+0x26c/0x578\n[ 2.329562] kernel_init+0x3c/0x258\n[ 2.329574] ret_from_fork+0x10/0x20\n[ 2.329698] ---[ end trace 0000000000000000 ]---\n\n[ 2.403704] ------------[ cut here ]------------\n[ 2.404716] kmem_cache of name 'msg_msg-16' already exists\n[ 2.404801] WARNING: CPU: 2 PID: 1 at mm/slab_common.c:107 __kmem_cache_create_args+0xb8/0x3b0\n[ 2.404842] Modules linked in:\n[ 2.404971] CPU: 2 UID: 0 PID: 1 Comm: swapper/0 Tainted: G W 6.12.0-rc5mm-unstable-arm64+ #12\n[ 2.405026] Tainted: [W]=WARN\n[ 2.405043] Hardware name: QEMU QEMU Virtual Machine, BIOS 2024.02-2 03/11/2024\n[ 2.405057] pstate: 60400009 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ 2.405079] pc : __kmem_cache_create_args+0xb8/0x3b0\n[ 2.405100] lr : __kmem_cache_create_args+0xb8/0x3b0\n[ 2.405111] sp : ffff800083d6fc50\n[ 2.405115] x29: ffff800083d6fc50 x28: fbff0000c1674410 x27: ffff8000820b0598\n[ 2.405135] x26: 000000000000ffd0 x25: 0000000000000010 x24: 0000000000006000\n[ 2.405153] x23: ffff800083d6fce8 x22: ffff8000832222e8 x21: ffff800083222388\n[ 2.405169] x20: fbff0000c1674410 x19: fdff0000c163d6c0 x18: ffff800083d80030\n[ 2.405185] x17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000000\n[ 2.405201] x14: 0000000000000000 x13: 0a73747369786520 x12: 79646165726c6120\n[ 2.405217] x11: 656820747563205b x10: 2d2d2d2d2d2d2d2d x9 : 0000000000000000\n[ 2.405233] x8 : 0000000000000000 x7 : 0000000000000000 x6 : 0000000000000000\n[ 2.405248] x5 : 0000000000000000 x4 : 0000000000000000 x3 : 0000000000000000\n[ 2.405271] x2 : 0000000000000000 x1 : 0000000000000000 x0 : 0000000000000000\n[ 2.405287] Call trace:\n[ 2\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T18:15:26Z" diff --git a/advisories/unreviewed/2024/11/GHSA-5phw-w7h3-vg96/GHSA-5phw-w7h3-vg96.json b/advisories/unreviewed/2024/11/GHSA-5phw-w7h3-vg96/GHSA-5phw-w7h3-vg96.json index c5cf96dc445..085aa485a75 100644 --- a/advisories/unreviewed/2024/11/GHSA-5phw-w7h3-vg96/GHSA-5phw-w7h3-vg96.json +++ b/advisories/unreviewed/2024/11/GHSA-5phw-w7h3-vg96/GHSA-5phw-w7h3-vg96.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5phw-w7h3-vg96", - "modified": "2024-11-14T00:31:11Z", + "modified": "2024-11-25T21:30:48Z", "published": "2024-11-14T00:31:11Z", "aliases": [ "CVE-2024-40407" ], "details": "A full path disclosure in Cybele Software Thinfinity Workspace before v7.0.2.113 allows attackers to obtain the root path of the application via unspecified vectors.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-13T23:15:03Z" diff --git a/advisories/unreviewed/2024/11/GHSA-6hr3-3gcm-jjw8/GHSA-6hr3-3gcm-jjw8.json b/advisories/unreviewed/2024/11/GHSA-6hr3-3gcm-jjw8/GHSA-6hr3-3gcm-jjw8.json index 59381545b0c..4100b46e6bb 100644 --- a/advisories/unreviewed/2024/11/GHSA-6hr3-3gcm-jjw8/GHSA-6hr3-3gcm-jjw8.json +++ b/advisories/unreviewed/2024/11/GHSA-6hr3-3gcm-jjw8/GHSA-6hr3-3gcm-jjw8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6hr3-3gcm-jjw8", - "modified": "2024-11-25T18:33:26Z", + "modified": "2024-11-25T21:30:50Z", "published": "2024-11-25T18:33:26Z", "aliases": [ "CVE-2024-45756" ], "details": "An issue was discovered in Centreon centreon-open-tickets 24.10.x before 24.10.0, 24.04.x before 24.04.2, 23.10.x before 23.10.1, 23.04.x before 23.04.3, and 22.10.x before 22.10.2. SQL injection can occur in the form to create a ticket. Exploitation is only accessible to authenticated users with high-privileged access.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-25T18:15:12Z" diff --git a/advisories/unreviewed/2024/11/GHSA-77g8-jx2r-h4w8/GHSA-77g8-jx2r-h4w8.json b/advisories/unreviewed/2024/11/GHSA-77g8-jx2r-h4w8/GHSA-77g8-jx2r-h4w8.json index 23b0cae24b5..9d6e9e9e864 100644 --- a/advisories/unreviewed/2024/11/GHSA-77g8-jx2r-h4w8/GHSA-77g8-jx2r-h4w8.json +++ b/advisories/unreviewed/2024/11/GHSA-77g8-jx2r-h4w8/GHSA-77g8-jx2r-h4w8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-77g8-jx2r-h4w8", - "modified": "2024-11-15T18:30:51Z", + "modified": "2024-11-25T21:30:48Z", "published": "2024-11-15T18:30:51Z", "aliases": [ "CVE-2024-46463" ], "details": "By default, dedicated folders of ORIZON for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ORIZON has to be modified to prevent this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T18:15:28Z" diff --git a/advisories/unreviewed/2024/11/GHSA-77gw-48rv-vrfg/GHSA-77gw-48rv-vrfg.json b/advisories/unreviewed/2024/11/GHSA-77gw-48rv-vrfg/GHSA-77gw-48rv-vrfg.json index f9f1d19a9ff..f308c92ba11 100644 --- a/advisories/unreviewed/2024/11/GHSA-77gw-48rv-vrfg/GHSA-77gw-48rv-vrfg.json +++ b/advisories/unreviewed/2024/11/GHSA-77gw-48rv-vrfg/GHSA-77gw-48rv-vrfg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-77gw-48rv-vrfg", - "modified": "2024-11-14T00:31:11Z", + "modified": "2024-11-25T21:30:48Z", "published": "2024-11-14T00:31:11Z", "aliases": [ "CVE-2024-40404" ], "details": "Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endpoint where Web Sockets connections are established.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-13T23:15:03Z" diff --git a/advisories/unreviewed/2024/11/GHSA-7hwj-x2vh-jqv9/GHSA-7hwj-x2vh-jqv9.json b/advisories/unreviewed/2024/11/GHSA-7hwj-x2vh-jqv9/GHSA-7hwj-x2vh-jqv9.json index d9c1f8472a7..49f97f33b0a 100644 --- a/advisories/unreviewed/2024/11/GHSA-7hwj-x2vh-jqv9/GHSA-7hwj-x2vh-jqv9.json +++ b/advisories/unreviewed/2024/11/GHSA-7hwj-x2vh-jqv9/GHSA-7hwj-x2vh-jqv9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7hwj-x2vh-jqv9", - "modified": "2024-11-19T18:31:07Z", + "modified": "2024-11-25T21:30:49Z", "published": "2024-11-19T18:31:07Z", "aliases": [ "CVE-2024-53063" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: dvbdev: prevent the risk of out of memory access\n\nThe dvbdev contains a static variable used to store dvb minors.\n\nThe behavior of it depends if CONFIG_DVB_DYNAMIC_MINORS is set\nor not. When not set, dvb_register_device() won't check for\nboundaries, as it will rely that a previous call to\ndvb_register_adapter() would already be enforcing it.\n\nOn a similar way, dvb_device_open() uses the assumption\nthat the register functions already did the needed checks.\n\nThis can be fragile if some device ends using different\ncalls. This also generate warnings on static check analysers\nlike Coverity.\n\nSo, add explicit guards to prevent potential risk of OOM issues.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-755" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T18:15:26Z" diff --git a/advisories/unreviewed/2024/11/GHSA-7wh4-8q83-x7vq/GHSA-7wh4-8q83-x7vq.json b/advisories/unreviewed/2024/11/GHSA-7wh4-8q83-x7vq/GHSA-7wh4-8q83-x7vq.json new file mode 100644 index 00000000000..c2bc3085926 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7wh4-8q83-x7vq/GHSA-7wh4-8q83-x7vq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wh4-8q83-x7vq", + "modified": "2024-11-25T21:30:50Z", + "published": "2024-11-25T21:30:50Z", + "aliases": [ + "CVE-2024-51723" + ], + "details": "A Stored Cross-Site Scripting (XSS) vulnerability in the Management Console of BlackBerry AtHoc version 7.15 could allow an attacker to potentially execute actions in the context of the victim's session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51723" + }, + { + "type": "WEB", + "url": "https://support.blackberry.com/pkb/s/article/140250" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T19:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-87vp-wcxm-f9g2/GHSA-87vp-wcxm-f9g2.json b/advisories/unreviewed/2024/11/GHSA-87vp-wcxm-f9g2/GHSA-87vp-wcxm-f9g2.json index 72033213f9d..f6fbbd69f55 100644 --- a/advisories/unreviewed/2024/11/GHSA-87vp-wcxm-f9g2/GHSA-87vp-wcxm-f9g2.json +++ b/advisories/unreviewed/2024/11/GHSA-87vp-wcxm-f9g2/GHSA-87vp-wcxm-f9g2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-87vp-wcxm-f9g2", - "modified": "2024-11-19T18:31:07Z", + "modified": "2024-11-25T21:30:48Z", "published": "2024-11-19T18:31:06Z", "aliases": [ "CVE-2024-53064" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nidpf: fix idpf_vc_core_init error path\n\nIn an event where the platform running the device control plane\nis rebooted, reset is detected on the driver. It releases\nall the resources and waits for the reset to complete. Once the\nreset is done, it tries to build the resources back. At this\ntime if the device control plane is not yet started, then\nthe driver timeouts on the virtchnl message and retries to\nestablish the mailbox again.\n\nIn the retry flow, mailbox is deinitialized but the mailbox\nworkqueue is still alive and polling for the mailbox message.\nThis results in accessing the released control queue leading to\nnull-ptr-deref. Fix it by unrolling the work queue cancellation\nand mailbox deinitialization in the reverse order which they got\ninitialized.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T18:15:26Z" diff --git a/advisories/unreviewed/2024/11/GHSA-8m8g-4g6j-89fc/GHSA-8m8g-4g6j-89fc.json b/advisories/unreviewed/2024/11/GHSA-8m8g-4g6j-89fc/GHSA-8m8g-4g6j-89fc.json index 97410425d35..6e3f7ee5e21 100644 --- a/advisories/unreviewed/2024/11/GHSA-8m8g-4g6j-89fc/GHSA-8m8g-4g6j-89fc.json +++ b/advisories/unreviewed/2024/11/GHSA-8m8g-4g6j-89fc/GHSA-8m8g-4g6j-89fc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8m8g-4g6j-89fc", - "modified": "2024-11-14T00:31:11Z", + "modified": "2024-11-25T21:30:48Z", "published": "2024-11-14T00:31:11Z", "aliases": [ "CVE-2024-40410" ], "details": "Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain a hardcoded cryptographic key used for encryption.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-13T23:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-8vqq-vp59-hxpx/GHSA-8vqq-vp59-hxpx.json b/advisories/unreviewed/2024/11/GHSA-8vqq-vp59-hxpx/GHSA-8vqq-vp59-hxpx.json index e29a4188f2c..9e9ed46ef8a 100644 --- a/advisories/unreviewed/2024/11/GHSA-8vqq-vp59-hxpx/GHSA-8vqq-vp59-hxpx.json +++ b/advisories/unreviewed/2024/11/GHSA-8vqq-vp59-hxpx/GHSA-8vqq-vp59-hxpx.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-c26p-5f2j-p2gv/GHSA-c26p-5f2j-p2gv.json b/advisories/unreviewed/2024/11/GHSA-c26p-5f2j-p2gv/GHSA-c26p-5f2j-p2gv.json index 54bc346c81b..52fc34ec5bb 100644 --- a/advisories/unreviewed/2024/11/GHSA-c26p-5f2j-p2gv/GHSA-c26p-5f2j-p2gv.json +++ b/advisories/unreviewed/2024/11/GHSA-c26p-5f2j-p2gv/GHSA-c26p-5f2j-p2gv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c26p-5f2j-p2gv", - "modified": "2024-11-14T00:31:11Z", + "modified": "2024-11-25T21:30:48Z", "published": "2024-11-14T00:31:11Z", "aliases": [ "CVE-2024-50956" ], "details": "A buffer overflow in the RecvSocketData function of Inovance HCPLC_AM401-CPU1608TPTN 21.38.0.0, HCPLC_AM402-CPU1608TPTN 41.38.0.0, and HCPLC_AM403-CPU1608TN 81.38.0.0 allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted Modbus message.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-13T22:15:15Z" diff --git a/advisories/unreviewed/2024/11/GHSA-c95v-4jjw-2rfc/GHSA-c95v-4jjw-2rfc.json b/advisories/unreviewed/2024/11/GHSA-c95v-4jjw-2rfc/GHSA-c95v-4jjw-2rfc.json index 43d753a83aa..c3f2d94e47d 100644 --- a/advisories/unreviewed/2024/11/GHSA-c95v-4jjw-2rfc/GHSA-c95v-4jjw-2rfc.json +++ b/advisories/unreviewed/2024/11/GHSA-c95v-4jjw-2rfc/GHSA-c95v-4jjw-2rfc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c95v-4jjw-2rfc", - "modified": "2024-11-19T18:31:07Z", + "modified": "2024-11-25T21:30:49Z", "published": "2024-11-19T18:31:07Z", "aliases": [ "CVE-2024-53077" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nrpcrdma: Always release the rpcrdma_device's xa_array\n\nDai pointed out that the xa_init_flags() in rpcrdma_add_one() needs\nto have a matching xa_destroy() in rpcrdma_remove_one() to release\nunderlying memory that the xarray might have accrued during\noperation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T18:15:27Z" diff --git a/advisories/unreviewed/2024/11/GHSA-cgh6-mrm3-hqpj/GHSA-cgh6-mrm3-hqpj.json b/advisories/unreviewed/2024/11/GHSA-cgh6-mrm3-hqpj/GHSA-cgh6-mrm3-hqpj.json index bbd30082b23..c6c90f76bc7 100644 --- a/advisories/unreviewed/2024/11/GHSA-cgh6-mrm3-hqpj/GHSA-cgh6-mrm3-hqpj.json +++ b/advisories/unreviewed/2024/11/GHSA-cgh6-mrm3-hqpj/GHSA-cgh6-mrm3-hqpj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cgh6-mrm3-hqpj", - "modified": "2024-11-19T18:31:07Z", + "modified": "2024-11-25T21:30:49Z", "published": "2024-11-19T18:31:07Z", "aliases": [ "CVE-2024-53072" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86/amd/pmc: Detect when STB is not available\n\nLoading the amd_pmc module as:\n\n amd_pmc enable_stb=1\n\n...can result in the following messages in the kernel ring buffer:\n\n amd_pmc AMDI0009:00: SMU cmd failed. err: 0xff\n ioremap on RAM at 0x0000000000000000 - 0x0000000000ffffff\n WARNING: CPU: 10 PID: 2151 at arch/x86/mm/ioremap.c:217 __ioremap_caller+0x2cd/0x340\n\nFurther debugging reveals that this occurs when the requests for\nS2D_PHYS_ADDR_LOW and S2D_PHYS_ADDR_HIGH return a value of 0,\nindicating that the STB is inaccessible. To prevent the ioremap\nwarning and provide clarity to the user, handle the invalid address\nand display an error message.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T18:15:26Z" diff --git a/advisories/unreviewed/2024/11/GHSA-cm82-pv3f-7x6g/GHSA-cm82-pv3f-7x6g.json b/advisories/unreviewed/2024/11/GHSA-cm82-pv3f-7x6g/GHSA-cm82-pv3f-7x6g.json index 273d096484f..a346fee13f5 100644 --- a/advisories/unreviewed/2024/11/GHSA-cm82-pv3f-7x6g/GHSA-cm82-pv3f-7x6g.json +++ b/advisories/unreviewed/2024/11/GHSA-cm82-pv3f-7x6g/GHSA-cm82-pv3f-7x6g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cm82-pv3f-7x6g", - "modified": "2024-11-14T00:31:11Z", + "modified": "2024-11-25T21:30:48Z", "published": "2024-11-14T00:31:11Z", "aliases": [ "CVE-2024-51027" ], "details": "Ruijie NBR800G gateway NBR_RGOS_11.1(6)B4P9 is vulnerable to command execution in /itbox_pi/networksafe.php via the province parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-13T22:15:15Z" diff --git a/advisories/unreviewed/2024/11/GHSA-fc6c-wh46-2q9r/GHSA-fc6c-wh46-2q9r.json b/advisories/unreviewed/2024/11/GHSA-fc6c-wh46-2q9r/GHSA-fc6c-wh46-2q9r.json index 6db62b1ba60..2b769329fb3 100644 --- a/advisories/unreviewed/2024/11/GHSA-fc6c-wh46-2q9r/GHSA-fc6c-wh46-2q9r.json +++ b/advisories/unreviewed/2024/11/GHSA-fc6c-wh46-2q9r/GHSA-fc6c-wh46-2q9r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fc6c-wh46-2q9r", - "modified": "2024-11-19T18:31:07Z", + "modified": "2024-11-25T21:30:48Z", "published": "2024-11-19T18:31:07Z", "aliases": [ "CVE-2024-53066" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfs: Fix KMSAN warning in decode_getfattr_attrs()\n\nFix the following KMSAN warning:\n\nCPU: 1 UID: 0 PID: 7651 Comm: cp Tainted: G B\nTainted: [B]=BAD_PAGE\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009)\n=====================================================\n=====================================================\nBUG: KMSAN: uninit-value in decode_getfattr_attrs+0x2d6d/0x2f90\n decode_getfattr_attrs+0x2d6d/0x2f90\n decode_getfattr_generic+0x806/0xb00\n nfs4_xdr_dec_getattr+0x1de/0x240\n rpcauth_unwrap_resp_decode+0xab/0x100\n rpcauth_unwrap_resp+0x95/0xc0\n call_decode+0x4ff/0xb50\n __rpc_execute+0x57b/0x19d0\n rpc_execute+0x368/0x5e0\n rpc_run_task+0xcfe/0xee0\n nfs4_proc_getattr+0x5b5/0x990\n __nfs_revalidate_inode+0x477/0xd00\n nfs_access_get_cached+0x1021/0x1cc0\n nfs_do_access+0x9f/0xae0\n nfs_permission+0x1e4/0x8c0\n inode_permission+0x356/0x6c0\n link_path_walk+0x958/0x1330\n path_lookupat+0xce/0x6b0\n filename_lookup+0x23e/0x770\n vfs_statx+0xe7/0x970\n vfs_fstatat+0x1f2/0x2c0\n __se_sys_newfstatat+0x67/0x880\n __x64_sys_newfstatat+0xbd/0x120\n x64_sys_call+0x1826/0x3cf0\n do_syscall_64+0xd0/0x1b0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nThe KMSAN warning is triggered in decode_getfattr_attrs(), when calling\ndecode_attr_mdsthreshold(). It appears that fattr->mdsthreshold is not\ninitialized.\n\nFix the issue by initializing fattr->mdsthreshold to NULL in\nnfs_fattr_init().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-908" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T18:15:26Z" diff --git a/advisories/unreviewed/2024/11/GHSA-fg3p-cr7g-8j6c/GHSA-fg3p-cr7g-8j6c.json b/advisories/unreviewed/2024/11/GHSA-fg3p-cr7g-8j6c/GHSA-fg3p-cr7g-8j6c.json index e9f3c727b46..d7d1691d965 100644 --- a/advisories/unreviewed/2024/11/GHSA-fg3p-cr7g-8j6c/GHSA-fg3p-cr7g-8j6c.json +++ b/advisories/unreviewed/2024/11/GHSA-fg3p-cr7g-8j6c/GHSA-fg3p-cr7g-8j6c.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-fgg8-x8gw-hg74/GHSA-fgg8-x8gw-hg74.json b/advisories/unreviewed/2024/11/GHSA-fgg8-x8gw-hg74/GHSA-fgg8-x8gw-hg74.json index 42643fc27a1..ae5feca7085 100644 --- a/advisories/unreviewed/2024/11/GHSA-fgg8-x8gw-hg74/GHSA-fgg8-x8gw-hg74.json +++ b/advisories/unreviewed/2024/11/GHSA-fgg8-x8gw-hg74/GHSA-fgg8-x8gw-hg74.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-fx6h-9x6m-54jv/GHSA-fx6h-9x6m-54jv.json b/advisories/unreviewed/2024/11/GHSA-fx6h-9x6m-54jv/GHSA-fx6h-9x6m-54jv.json index 7eff8acb8cd..69bf3e5bdd5 100644 --- a/advisories/unreviewed/2024/11/GHSA-fx6h-9x6m-54jv/GHSA-fx6h-9x6m-54jv.json +++ b/advisories/unreviewed/2024/11/GHSA-fx6h-9x6m-54jv/GHSA-fx6h-9x6m-54jv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fx6h-9x6m-54jv", - "modified": "2024-11-14T00:31:11Z", + "modified": "2024-11-25T21:30:48Z", "published": "2024-11-14T00:31:11Z", "aliases": [ "CVE-2024-40408" ], "details": "Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerability allows attackers to create arbitrary user profiles with elevated privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-13T23:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-g337-g667-mjvw/GHSA-g337-g667-mjvw.json b/advisories/unreviewed/2024/11/GHSA-g337-g667-mjvw/GHSA-g337-g667-mjvw.json index 0472288cfbe..142c4d8afb5 100644 --- a/advisories/unreviewed/2024/11/GHSA-g337-g667-mjvw/GHSA-g337-g667-mjvw.json +++ b/advisories/unreviewed/2024/11/GHSA-g337-g667-mjvw/GHSA-g337-g667-mjvw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g337-g667-mjvw", - "modified": "2024-11-06T18:31:10Z", + "modified": "2024-11-25T21:30:48Z", "published": "2024-11-06T09:31:21Z", "aliases": [ "CVE-2024-9681" @@ -32,11 +32,15 @@ { "type": "WEB", "url": "https://curl.se/docs/CVE-2024-9681.json" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/11/06/2" } ], "database_specific": { "cwe_ids": [ - + "CWE-697" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-g6m8-94m7-hxgm/GHSA-g6m8-94m7-hxgm.json b/advisories/unreviewed/2024/11/GHSA-g6m8-94m7-hxgm/GHSA-g6m8-94m7-hxgm.json index d00ec90dabb..53cf96e93c7 100644 --- a/advisories/unreviewed/2024/11/GHSA-g6m8-94m7-hxgm/GHSA-g6m8-94m7-hxgm.json +++ b/advisories/unreviewed/2024/11/GHSA-g6m8-94m7-hxgm/GHSA-g6m8-94m7-hxgm.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-g8g4-68c7-93h5/GHSA-g8g4-68c7-93h5.json b/advisories/unreviewed/2024/11/GHSA-g8g4-68c7-93h5/GHSA-g8g4-68c7-93h5.json index 3d44254558a..5fe7501837a 100644 --- a/advisories/unreviewed/2024/11/GHSA-g8g4-68c7-93h5/GHSA-g8g4-68c7-93h5.json +++ b/advisories/unreviewed/2024/11/GHSA-g8g4-68c7-93h5/GHSA-g8g4-68c7-93h5.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-g8rg-m62r-h7gq/GHSA-g8rg-m62r-h7gq.json b/advisories/unreviewed/2024/11/GHSA-g8rg-m62r-h7gq/GHSA-g8rg-m62r-h7gq.json index e8617c27213..1a6e172f921 100644 --- a/advisories/unreviewed/2024/11/GHSA-g8rg-m62r-h7gq/GHSA-g8rg-m62r-h7gq.json +++ b/advisories/unreviewed/2024/11/GHSA-g8rg-m62r-h7gq/GHSA-g8rg-m62r-h7gq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g8rg-m62r-h7gq", - "modified": "2024-11-15T18:30:52Z", + "modified": "2024-11-25T21:30:48Z", "published": "2024-11-15T18:30:52Z", "aliases": [ "CVE-2024-46467" ], "details": "By default, dedicated folders of ZONEPOINT for Windows up to 2024.1 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ZONEPOINT has to be modified to prevent this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T18:15:28Z" diff --git a/advisories/unreviewed/2024/11/GHSA-g9jc-92w4-hqr8/GHSA-g9jc-92w4-hqr8.json b/advisories/unreviewed/2024/11/GHSA-g9jc-92w4-hqr8/GHSA-g9jc-92w4-hqr8.json index df7d7b6f4c0..6602bb08885 100644 --- a/advisories/unreviewed/2024/11/GHSA-g9jc-92w4-hqr8/GHSA-g9jc-92w4-hqr8.json +++ b/advisories/unreviewed/2024/11/GHSA-g9jc-92w4-hqr8/GHSA-g9jc-92w4-hqr8.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-ghf3-4f69-3865/GHSA-ghf3-4f69-3865.json b/advisories/unreviewed/2024/11/GHSA-ghf3-4f69-3865/GHSA-ghf3-4f69-3865.json new file mode 100644 index 00000000000..eec87a2b3aa --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-ghf3-4f69-3865/GHSA-ghf3-4f69-3865.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghf3-4f69-3865", + "modified": "2024-11-25T21:30:50Z", + "published": "2024-11-25T21:30:50Z", + "aliases": [ + "CVE-2024-50671" + ], + "details": "Incorrect access control in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows attackers with Authenticated User roles to obtain email addresses via the \"Get users\" feature. The vulnerability occurs due to a flaw in permission verification logic, where the wildcard character in permitted URLs grants unintended access to endpoints restricted to users with Super Admin roles. This makes it possible for attackers to disclose the email addresses of all users.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50671" + }, + { + "type": "WEB", + "url": "https://github.com/adaptlearning/adapt_authoring" + }, + { + "type": "WEB", + "url": "https://github.com/dos-m0nk3y/CVE/tree/main/CVE-2024-50671" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T21:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gw66-x3q6-f7fv/GHSA-gw66-x3q6-f7fv.json b/advisories/unreviewed/2024/11/GHSA-gw66-x3q6-f7fv/GHSA-gw66-x3q6-f7fv.json index e61dbe99099..a9604eac09a 100644 --- a/advisories/unreviewed/2024/11/GHSA-gw66-x3q6-f7fv/GHSA-gw66-x3q6-f7fv.json +++ b/advisories/unreviewed/2024/11/GHSA-gw66-x3q6-f7fv/GHSA-gw66-x3q6-f7fv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gw66-x3q6-f7fv", - "modified": "2024-11-25T18:33:26Z", + "modified": "2024-11-25T21:30:50Z", "published": "2024-11-25T18:33:26Z", "aliases": [ "CVE-2023-26280" diff --git a/advisories/unreviewed/2024/11/GHSA-jcmq-qjhc-h546/GHSA-jcmq-qjhc-h546.json b/advisories/unreviewed/2024/11/GHSA-jcmq-qjhc-h546/GHSA-jcmq-qjhc-h546.json index 867048e0d86..1c2f94a3e27 100644 --- a/advisories/unreviewed/2024/11/GHSA-jcmq-qjhc-h546/GHSA-jcmq-qjhc-h546.json +++ b/advisories/unreviewed/2024/11/GHSA-jcmq-qjhc-h546/GHSA-jcmq-qjhc-h546.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jcmq-qjhc-h546", - "modified": "2024-11-15T18:30:51Z", + "modified": "2024-11-25T21:30:48Z", "published": "2024-11-15T18:30:51Z", "aliases": [ "CVE-2024-46466" ], "details": "By default, dedicated folders of ZONECENTRAL for Windows up to 2024.3 or up to Q.2021.2 (ANSSI qualification submission) can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ZONECENTRAL has to be modified to prevent this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T18:15:28Z" diff --git a/advisories/unreviewed/2024/11/GHSA-m49c-4fx3-rqr9/GHSA-m49c-4fx3-rqr9.json b/advisories/unreviewed/2024/11/GHSA-m49c-4fx3-rqr9/GHSA-m49c-4fx3-rqr9.json index dd43579005a..7b9425af9ef 100644 --- a/advisories/unreviewed/2024/11/GHSA-m49c-4fx3-rqr9/GHSA-m49c-4fx3-rqr9.json +++ b/advisories/unreviewed/2024/11/GHSA-m49c-4fx3-rqr9/GHSA-m49c-4fx3-rqr9.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-mh8w-gxgh-8grm/GHSA-mh8w-gxgh-8grm.json b/advisories/unreviewed/2024/11/GHSA-mh8w-gxgh-8grm/GHSA-mh8w-gxgh-8grm.json index cd758a0a6ef..472dcdb073f 100644 --- a/advisories/unreviewed/2024/11/GHSA-mh8w-gxgh-8grm/GHSA-mh8w-gxgh-8grm.json +++ b/advisories/unreviewed/2024/11/GHSA-mh8w-gxgh-8grm/GHSA-mh8w-gxgh-8grm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mh8w-gxgh-8grm", - "modified": "2024-11-19T18:31:07Z", + "modified": "2024-11-25T21:30:49Z", "published": "2024-11-19T18:31:07Z", "aliases": [ "CVE-2024-53067" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: core: Start the RTC update work later\n\nThe RTC update work involves runtime resuming the UFS controller. Hence,\nonly start the RTC update work after runtime power management in the UFS\ndriver has been fully initialized. This patch fixes the following kernel\ncrash:\n\nInternal error: Oops: 0000000096000006 [#1] PREEMPT SMP\nWorkqueue: events ufshcd_rtc_work\nCall trace:\n _raw_spin_lock_irqsave+0x34/0x8c (P)\n pm_runtime_get_if_active+0x24/0x9c (L)\n pm_runtime_get_if_active+0x24/0x9c\n ufshcd_rtc_work+0x138/0x1b4\n process_one_work+0x148/0x288\n worker_thread+0x2cc/0x3d4\n kthread+0x110/0x114\n ret_from_fork+0x10/0x20", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T18:15:26Z" diff --git a/advisories/unreviewed/2024/11/GHSA-mm73-f56r-p9c7/GHSA-mm73-f56r-p9c7.json b/advisories/unreviewed/2024/11/GHSA-mm73-f56r-p9c7/GHSA-mm73-f56r-p9c7.json index 0dba0f4c15e..efe44d1d620 100644 --- a/advisories/unreviewed/2024/11/GHSA-mm73-f56r-p9c7/GHSA-mm73-f56r-p9c7.json +++ b/advisories/unreviewed/2024/11/GHSA-mm73-f56r-p9c7/GHSA-mm73-f56r-p9c7.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-p5g4-jr8m-xjw5/GHSA-p5g4-jr8m-xjw5.json b/advisories/unreviewed/2024/11/GHSA-p5g4-jr8m-xjw5/GHSA-p5g4-jr8m-xjw5.json index e7da29bd38b..cca366ea3c6 100644 --- a/advisories/unreviewed/2024/11/GHSA-p5g4-jr8m-xjw5/GHSA-p5g4-jr8m-xjw5.json +++ b/advisories/unreviewed/2024/11/GHSA-p5g4-jr8m-xjw5/GHSA-p5g4-jr8m-xjw5.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-p7jq-9jcx-rwrh/GHSA-p7jq-9jcx-rwrh.json b/advisories/unreviewed/2024/11/GHSA-p7jq-9jcx-rwrh/GHSA-p7jq-9jcx-rwrh.json index c2b536ed9ff..1b9917ffbc4 100644 --- a/advisories/unreviewed/2024/11/GHSA-p7jq-9jcx-rwrh/GHSA-p7jq-9jcx-rwrh.json +++ b/advisories/unreviewed/2024/11/GHSA-p7jq-9jcx-rwrh/GHSA-p7jq-9jcx-rwrh.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-pfcx-5c23-m8c6/GHSA-pfcx-5c23-m8c6.json b/advisories/unreviewed/2024/11/GHSA-pfcx-5c23-m8c6/GHSA-pfcx-5c23-m8c6.json index 7d88cca4dfc..28b062d8d21 100644 --- a/advisories/unreviewed/2024/11/GHSA-pfcx-5c23-m8c6/GHSA-pfcx-5c23-m8c6.json +++ b/advisories/unreviewed/2024/11/GHSA-pfcx-5c23-m8c6/GHSA-pfcx-5c23-m8c6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pfcx-5c23-m8c6", - "modified": "2024-11-22T21:32:15Z", + "modified": "2024-11-25T21:30:49Z", "published": "2024-11-22T21:32:15Z", "aliases": [ "CVE-2024-51074" ], "details": "Incorrect access control in Instrument Cluster KIA Seltos Software v1.0, Hardware v1.0 allows attackers to arbitrarily change odometer readings in the vehicle.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-22T16:15:33Z" diff --git a/advisories/unreviewed/2024/11/GHSA-qvxf-rx86-53ww/GHSA-qvxf-rx86-53ww.json b/advisories/unreviewed/2024/11/GHSA-qvxf-rx86-53ww/GHSA-qvxf-rx86-53ww.json index a8fd36a5b24..b43bd42a0f5 100644 --- a/advisories/unreviewed/2024/11/GHSA-qvxf-rx86-53ww/GHSA-qvxf-rx86-53ww.json +++ b/advisories/unreviewed/2024/11/GHSA-qvxf-rx86-53ww/GHSA-qvxf-rx86-53ww.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-r57p-9vwh-hqg7/GHSA-r57p-9vwh-hqg7.json b/advisories/unreviewed/2024/11/GHSA-r57p-9vwh-hqg7/GHSA-r57p-9vwh-hqg7.json index 5e2408fcae0..14c1d8078e2 100644 --- a/advisories/unreviewed/2024/11/GHSA-r57p-9vwh-hqg7/GHSA-r57p-9vwh-hqg7.json +++ b/advisories/unreviewed/2024/11/GHSA-r57p-9vwh-hqg7/GHSA-r57p-9vwh-hqg7.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-r5h8-fch6-xr5v/GHSA-r5h8-fch6-xr5v.json b/advisories/unreviewed/2024/11/GHSA-r5h8-fch6-xr5v/GHSA-r5h8-fch6-xr5v.json index 4206a755f2f..849cd8aae4e 100644 --- a/advisories/unreviewed/2024/11/GHSA-r5h8-fch6-xr5v/GHSA-r5h8-fch6-xr5v.json +++ b/advisories/unreviewed/2024/11/GHSA-r5h8-fch6-xr5v/GHSA-r5h8-fch6-xr5v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r5h8-fch6-xr5v", - "modified": "2024-11-25T06:34:58Z", + "modified": "2024-11-25T21:30:50Z", "published": "2024-11-25T06:34:58Z", "aliases": [ "CVE-2024-10709" ], "details": "The YaDisk Files WordPress plugin through 1.2.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-25T06:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-r9v3-wmhr-p388/GHSA-r9v3-wmhr-p388.json b/advisories/unreviewed/2024/11/GHSA-r9v3-wmhr-p388/GHSA-r9v3-wmhr-p388.json index a4957778f40..6141d4d6091 100644 --- a/advisories/unreviewed/2024/11/GHSA-r9v3-wmhr-p388/GHSA-r9v3-wmhr-p388.json +++ b/advisories/unreviewed/2024/11/GHSA-r9v3-wmhr-p388/GHSA-r9v3-wmhr-p388.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-rcr8-p88j-65jw/GHSA-rcr8-p88j-65jw.json b/advisories/unreviewed/2024/11/GHSA-rcr8-p88j-65jw/GHSA-rcr8-p88j-65jw.json index 80666bc7385..5fb7f2e06dc 100644 --- a/advisories/unreviewed/2024/11/GHSA-rcr8-p88j-65jw/GHSA-rcr8-p88j-65jw.json +++ b/advisories/unreviewed/2024/11/GHSA-rcr8-p88j-65jw/GHSA-rcr8-p88j-65jw.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-rw9x-j3p5-vvx2/GHSA-rw9x-j3p5-vvx2.json b/advisories/unreviewed/2024/11/GHSA-rw9x-j3p5-vvx2/GHSA-rw9x-j3p5-vvx2.json index 93ef281928b..73e64163b3d 100644 --- a/advisories/unreviewed/2024/11/GHSA-rw9x-j3p5-vvx2/GHSA-rw9x-j3p5-vvx2.json +++ b/advisories/unreviewed/2024/11/GHSA-rw9x-j3p5-vvx2/GHSA-rw9x-j3p5-vvx2.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-v3vm-xgxp-h9fp/GHSA-v3vm-xgxp-h9fp.json b/advisories/unreviewed/2024/11/GHSA-v3vm-xgxp-h9fp/GHSA-v3vm-xgxp-h9fp.json index 66d37d4714e..e6ba8d5eebf 100644 --- a/advisories/unreviewed/2024/11/GHSA-v3vm-xgxp-h9fp/GHSA-v3vm-xgxp-h9fp.json +++ b/advisories/unreviewed/2024/11/GHSA-v3vm-xgxp-h9fp/GHSA-v3vm-xgxp-h9fp.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-vg3v-8w3m-rfrq/GHSA-vg3v-8w3m-rfrq.json b/advisories/unreviewed/2024/11/GHSA-vg3v-8w3m-rfrq/GHSA-vg3v-8w3m-rfrq.json index 731d65be56b..957c35cb5e2 100644 --- a/advisories/unreviewed/2024/11/GHSA-vg3v-8w3m-rfrq/GHSA-vg3v-8w3m-rfrq.json +++ b/advisories/unreviewed/2024/11/GHSA-vg3v-8w3m-rfrq/GHSA-vg3v-8w3m-rfrq.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-vh5p-6rcm-5x83/GHSA-vh5p-6rcm-5x83.json b/advisories/unreviewed/2024/11/GHSA-vh5p-6rcm-5x83/GHSA-vh5p-6rcm-5x83.json new file mode 100644 index 00000000000..93a66e71317 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vh5p-6rcm-5x83/GHSA-vh5p-6rcm-5x83.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vh5p-6rcm-5x83", + "modified": "2024-11-25T21:30:50Z", + "published": "2024-11-25T21:30:50Z", + "aliases": [ + "CVE-2024-50672" + ], + "details": "A NoSQL injection vulnerability in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows unauthenticated attackers to reset user and administrator account passwords via the \"Reset password\" feature. The vulnerability occurs due to insufficient validation of user input, which is used as a query in Mongoose's find() function. This makes it possible for attackers to perform a full takeover of the administrator account. Attackers can then use the newly gained administrative privileges to upload a custom plugin to perform remote code execution (RCE) on the server hosting the web application.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50672" + }, + { + "type": "WEB", + "url": "https://github.com/adaptlearning/adapt_authoring" + }, + { + "type": "WEB", + "url": "https://github.com/dos-m0nk3y/CVE/tree/main/CVE-2024-50672" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T21:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vv6x-mmfx-2x2g/GHSA-vv6x-mmfx-2x2g.json b/advisories/unreviewed/2024/11/GHSA-vv6x-mmfx-2x2g/GHSA-vv6x-mmfx-2x2g.json index 4155a152502..bad04aaf640 100644 --- a/advisories/unreviewed/2024/11/GHSA-vv6x-mmfx-2x2g/GHSA-vv6x-mmfx-2x2g.json +++ b/advisories/unreviewed/2024/11/GHSA-vv6x-mmfx-2x2g/GHSA-vv6x-mmfx-2x2g.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-whgj-xqgq-mp34/GHSA-whgj-xqgq-mp34.json b/advisories/unreviewed/2024/11/GHSA-whgj-xqgq-mp34/GHSA-whgj-xqgq-mp34.json index b2e4420f4fe..ea1dacc5ed6 100644 --- a/advisories/unreviewed/2024/11/GHSA-whgj-xqgq-mp34/GHSA-whgj-xqgq-mp34.json +++ b/advisories/unreviewed/2024/11/GHSA-whgj-xqgq-mp34/GHSA-whgj-xqgq-mp34.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-wr4j-4rh5-7rvv/GHSA-wr4j-4rh5-7rvv.json b/advisories/unreviewed/2024/11/GHSA-wr4j-4rh5-7rvv/GHSA-wr4j-4rh5-7rvv.json index 27fcdd993cd..f70a15e1c8b 100644 --- a/advisories/unreviewed/2024/11/GHSA-wr4j-4rh5-7rvv/GHSA-wr4j-4rh5-7rvv.json +++ b/advisories/unreviewed/2024/11/GHSA-wr4j-4rh5-7rvv/GHSA-wr4j-4rh5-7rvv.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-xrh5-v6q2-cjwm/GHSA-xrh5-v6q2-cjwm.json b/advisories/unreviewed/2024/11/GHSA-xrh5-v6q2-cjwm/GHSA-xrh5-v6q2-cjwm.json index 211ed7fda98..b3d1c16bbdc 100644 --- a/advisories/unreviewed/2024/11/GHSA-xrh5-v6q2-cjwm/GHSA-xrh5-v6q2-cjwm.json +++ b/advisories/unreviewed/2024/11/GHSA-xrh5-v6q2-cjwm/GHSA-xrh5-v6q2-cjwm.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false,