diff --git a/advisories/unreviewed/2024/06/GHSA-2rp5-xcq9-p4w3/GHSA-2rp5-xcq9-p4w3.json b/advisories/unreviewed/2024/06/GHSA-2rp5-xcq9-p4w3/GHSA-2rp5-xcq9-p4w3.json new file mode 100644 index 00000000000..23cf5f0d33d --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-2rp5-xcq9-p4w3/GHSA-2rp5-xcq9-p4w3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rp5-xcq9-p4w3", + "modified": "2024-06-30T18:30:38Z", + "published": "2024-06-30T18:30:38Z", + "aliases": [ + "CVE-2023-50953" + ], + "details": "IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system. IBM X-Force ID: 275775.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50953" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/275775" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7159057" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-30T18:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-3434-hc3m-8mmm/GHSA-3434-hc3m-8mmm.json b/advisories/unreviewed/2024/06/GHSA-3434-hc3m-8mmm/GHSA-3434-hc3m-8mmm.json new file mode 100644 index 00000000000..4d76e8fcf9a --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-3434-hc3m-8mmm/GHSA-3434-hc3m-8mmm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3434-hc3m-8mmm", + "modified": "2024-06-30T18:30:37Z", + "published": "2024-06-30T18:30:37Z", + "aliases": [ + "CVE-2024-5062" + ], + "details": "A reflected Cross-Site Scripting (XSS) vulnerability was identified in zenml-io/zenml version 0.57.1. The vulnerability exists due to improper neutralization of input during web page generation, specifically within the survey redirect parameter. This flaw allows an attacker to redirect users to a specified URL after completing a survey, without proper validation of the 'redirect' parameter. Consequently, an attacker can execute arbitrary JavaScript code in the context of the user's browser session. This vulnerability could be exploited to steal cookies, potentially leading to account takeover.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5062" + }, + { + "type": "WEB", + "url": "https://github.com/zenml-io/zenml/commit/21edd863c0ba53c1110b6f018a07c2d6853cf6d4" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/ceddd3c1-a9da-4d6c-85c4-41d4d1e1102f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-30T16:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-5ww6-xvhm-x8q3/GHSA-5ww6-xvhm-x8q3.json b/advisories/unreviewed/2024/06/GHSA-5ww6-xvhm-x8q3/GHSA-5ww6-xvhm-x8q3.json new file mode 100644 index 00000000000..e39313be81a --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-5ww6-xvhm-x8q3/GHSA-5ww6-xvhm-x8q3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5ww6-xvhm-x8q3", + "modified": "2024-06-30T18:30:38Z", + "published": "2024-06-30T18:30:38Z", + "aliases": [ + "CVE-2023-50952" + ], + "details": "IBM InfoSphere Information Server 11.7 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 275774.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50952" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/275774" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7158437" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-30T18:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-5xr3-jfwm-2p2g/GHSA-5xr3-jfwm-2p2g.json b/advisories/unreviewed/2024/06/GHSA-5xr3-jfwm-2p2g/GHSA-5xr3-jfwm-2p2g.json new file mode 100644 index 00000000000..ce7ba99901d --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-5xr3-jfwm-2p2g/GHSA-5xr3-jfwm-2p2g.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xr3-jfwm-2p2g", + "modified": "2024-06-30T18:30:37Z", + "published": "2024-06-30T18:30:37Z", + "aliases": [ + "CVE-2024-28795" + ], + "details": "IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 286832.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28795" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/286832" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7158408" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-30T16:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-cq47-mvqf-ggfh/GHSA-cq47-mvqf-ggfh.json b/advisories/unreviewed/2024/06/GHSA-cq47-mvqf-ggfh/GHSA-cq47-mvqf-ggfh.json new file mode 100644 index 00000000000..2864cc5b0f4 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-cq47-mvqf-ggfh/GHSA-cq47-mvqf-ggfh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cq47-mvqf-ggfh", + "modified": "2024-06-30T18:30:38Z", + "published": "2024-06-30T18:30:38Z", + "aliases": [ + "CVE-2024-31898" + ], + "details": "IBM InfoSphere Information Server 11.7 could allow an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references. IBM X-Force ID: 288182.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31898" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/288182" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7158425" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-30T18:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-crv7-mhxq-6c8r/GHSA-crv7-mhxq-6c8r.json b/advisories/unreviewed/2024/06/GHSA-crv7-mhxq-6c8r/GHSA-crv7-mhxq-6c8r.json new file mode 100644 index 00000000000..a60b990eb23 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-crv7-mhxq-6c8r/GHSA-crv7-mhxq-6c8r.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crv7-mhxq-6c8r", + "modified": "2024-06-30T18:30:37Z", + "published": "2024-06-30T18:30:37Z", + "aliases": [ + "CVE-2023-35022" + ], + "details": "IBM InfoSphere Information Server 11.7 could allow a local user to update projects that they do not have the authorization to access. IBM X-Force ID: 258254.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35022" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/258254" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7158447" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-30T16:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-p9r6-pcrg-rp27/GHSA-p9r6-pcrg-rp27.json b/advisories/unreviewed/2024/06/GHSA-p9r6-pcrg-rp27/GHSA-p9r6-pcrg-rp27.json new file mode 100644 index 00000000000..6d8e8275d42 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-p9r6-pcrg-rp27/GHSA-p9r6-pcrg-rp27.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9r6-pcrg-rp27", + "modified": "2024-06-30T18:30:38Z", + "published": "2024-06-30T18:30:38Z", + "aliases": [ + "CVE-2024-35119" + ], + "details": "IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system. IBM X-Force ID: 290342.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35119" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/290342" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7159052" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-30T17:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-rfrp-hqmx-gff6/GHSA-rfrp-hqmx-gff6.json b/advisories/unreviewed/2024/06/GHSA-rfrp-hqmx-gff6/GHSA-rfrp-hqmx-gff6.json new file mode 100644 index 00000000000..e9caa777890 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-rfrp-hqmx-gff6/GHSA-rfrp-hqmx-gff6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfrp-hqmx-gff6", + "modified": "2024-06-30T18:30:38Z", + "published": "2024-06-30T18:30:37Z", + "aliases": [ + "CVE-2024-31902" + ], + "details": "IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 289234.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31902" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/289234" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7159066" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-30T17:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-v34f-8v6r-qr8h/GHSA-v34f-8v6r-qr8h.json b/advisories/unreviewed/2024/06/GHSA-v34f-8v6r-qr8h/GHSA-v34f-8v6r-qr8h.json new file mode 100644 index 00000000000..a7a94b258e3 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-v34f-8v6r-qr8h/GHSA-v34f-8v6r-qr8h.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v34f-8v6r-qr8h", + "modified": "2024-06-30T18:30:37Z", + "published": "2024-06-30T18:30:37Z", + "aliases": [ + "CVE-2023-50954" + ], + "details": "IBM InfoSphere Information Server 11.7 returns sensitive information in URL information that could be used in further attacks against the system. IBM X-Force ID: 275776.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50954" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/275776" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7158597" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-598" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-30T17:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-v84w-2v56-wm6q/GHSA-v84w-2v56-wm6q.json b/advisories/unreviewed/2024/06/GHSA-v84w-2v56-wm6q/GHSA-v84w-2v56-wm6q.json new file mode 100644 index 00000000000..32b95fa3b89 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-v84w-2v56-wm6q/GHSA-v84w-2v56-wm6q.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v84w-2v56-wm6q", + "modified": "2024-06-30T18:30:37Z", + "published": "2024-06-30T18:30:37Z", + "aliases": [ + "CVE-2024-28798" + ], + "details": "IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 287172.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28798" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/287172" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7158439" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-30T17:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-x7f5-fmr9-q92p/GHSA-x7f5-fmr9-q92p.json b/advisories/unreviewed/2024/06/GHSA-x7f5-fmr9-q92p/GHSA-x7f5-fmr9-q92p.json new file mode 100644 index 00000000000..40188b2a4ee --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-x7f5-fmr9-q92p/GHSA-x7f5-fmr9-q92p.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7f5-fmr9-q92p", + "modified": "2024-06-30T18:30:38Z", + "published": "2024-06-30T18:30:38Z", + "aliases": [ + "CVE-2024-28797" + ], + "details": "IBM InfoSphere Information Server 11.7 is vulnerable stored to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 287136.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28797" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/287136" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7158431" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-30T18:15:03Z" + } +} \ No newline at end of file