From 04a16aff2ddc0a9ef9c29dd7a69522694e7b693b Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sun, 30 Jun 2024 18:32:19 +0000 Subject: [PATCH] Publish Advisories GHSA-2rp5-xcq9-p4w3 GHSA-3434-hc3m-8mmm GHSA-5ww6-xvhm-x8q3 GHSA-5xr3-jfwm-2p2g GHSA-cq47-mvqf-ggfh GHSA-crv7-mhxq-6c8r GHSA-p9r6-pcrg-rp27 GHSA-rfrp-hqmx-gff6 GHSA-v34f-8v6r-qr8h GHSA-v84w-2v56-wm6q GHSA-x7f5-fmr9-q92p --- .../GHSA-2rp5-xcq9-p4w3.json | 42 +++++++++++++++++++ .../GHSA-3434-hc3m-8mmm.json | 42 +++++++++++++++++++ .../GHSA-5ww6-xvhm-x8q3.json | 42 +++++++++++++++++++ .../GHSA-5xr3-jfwm-2p2g.json | 42 +++++++++++++++++++ .../GHSA-cq47-mvqf-ggfh.json | 42 +++++++++++++++++++ .../GHSA-crv7-mhxq-6c8r.json | 42 +++++++++++++++++++ .../GHSA-p9r6-pcrg-rp27.json | 42 +++++++++++++++++++ .../GHSA-rfrp-hqmx-gff6.json | 42 +++++++++++++++++++ .../GHSA-v34f-8v6r-qr8h.json | 42 +++++++++++++++++++ .../GHSA-v84w-2v56-wm6q.json | 42 +++++++++++++++++++ .../GHSA-x7f5-fmr9-q92p.json | 42 +++++++++++++++++++ 11 files changed, 462 insertions(+) create mode 100644 advisories/unreviewed/2024/06/GHSA-2rp5-xcq9-p4w3/GHSA-2rp5-xcq9-p4w3.json create mode 100644 advisories/unreviewed/2024/06/GHSA-3434-hc3m-8mmm/GHSA-3434-hc3m-8mmm.json create mode 100644 advisories/unreviewed/2024/06/GHSA-5ww6-xvhm-x8q3/GHSA-5ww6-xvhm-x8q3.json create mode 100644 advisories/unreviewed/2024/06/GHSA-5xr3-jfwm-2p2g/GHSA-5xr3-jfwm-2p2g.json create mode 100644 advisories/unreviewed/2024/06/GHSA-cq47-mvqf-ggfh/GHSA-cq47-mvqf-ggfh.json create mode 100644 advisories/unreviewed/2024/06/GHSA-crv7-mhxq-6c8r/GHSA-crv7-mhxq-6c8r.json create mode 100644 advisories/unreviewed/2024/06/GHSA-p9r6-pcrg-rp27/GHSA-p9r6-pcrg-rp27.json create mode 100644 advisories/unreviewed/2024/06/GHSA-rfrp-hqmx-gff6/GHSA-rfrp-hqmx-gff6.json create mode 100644 advisories/unreviewed/2024/06/GHSA-v34f-8v6r-qr8h/GHSA-v34f-8v6r-qr8h.json create mode 100644 advisories/unreviewed/2024/06/GHSA-v84w-2v56-wm6q/GHSA-v84w-2v56-wm6q.json create mode 100644 advisories/unreviewed/2024/06/GHSA-x7f5-fmr9-q92p/GHSA-x7f5-fmr9-q92p.json diff --git a/advisories/unreviewed/2024/06/GHSA-2rp5-xcq9-p4w3/GHSA-2rp5-xcq9-p4w3.json b/advisories/unreviewed/2024/06/GHSA-2rp5-xcq9-p4w3/GHSA-2rp5-xcq9-p4w3.json new file mode 100644 index 00000000000..23cf5f0d33d --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-2rp5-xcq9-p4w3/GHSA-2rp5-xcq9-p4w3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rp5-xcq9-p4w3", + "modified": "2024-06-30T18:30:38Z", + "published": "2024-06-30T18:30:38Z", + "aliases": [ + "CVE-2023-50953" + ], + "details": "IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system. IBM X-Force ID: 275775.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50953" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/275775" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7159057" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-30T18:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-3434-hc3m-8mmm/GHSA-3434-hc3m-8mmm.json b/advisories/unreviewed/2024/06/GHSA-3434-hc3m-8mmm/GHSA-3434-hc3m-8mmm.json new file mode 100644 index 00000000000..4d76e8fcf9a --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-3434-hc3m-8mmm/GHSA-3434-hc3m-8mmm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3434-hc3m-8mmm", + "modified": "2024-06-30T18:30:37Z", + "published": "2024-06-30T18:30:37Z", + "aliases": [ + "CVE-2024-5062" + ], + "details": "A reflected Cross-Site Scripting (XSS) vulnerability was identified in zenml-io/zenml version 0.57.1. The vulnerability exists due to improper neutralization of input during web page generation, specifically within the survey redirect parameter. This flaw allows an attacker to redirect users to a specified URL after completing a survey, without proper validation of the 'redirect' parameter. Consequently, an attacker can execute arbitrary JavaScript code in the context of the user's browser session. This vulnerability could be exploited to steal cookies, potentially leading to account takeover.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5062" + }, + { + "type": "WEB", + "url": "https://github.com/zenml-io/zenml/commit/21edd863c0ba53c1110b6f018a07c2d6853cf6d4" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/ceddd3c1-a9da-4d6c-85c4-41d4d1e1102f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-30T16:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-5ww6-xvhm-x8q3/GHSA-5ww6-xvhm-x8q3.json b/advisories/unreviewed/2024/06/GHSA-5ww6-xvhm-x8q3/GHSA-5ww6-xvhm-x8q3.json new file mode 100644 index 00000000000..e39313be81a --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-5ww6-xvhm-x8q3/GHSA-5ww6-xvhm-x8q3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5ww6-xvhm-x8q3", + "modified": "2024-06-30T18:30:38Z", + "published": "2024-06-30T18:30:38Z", + "aliases": [ + "CVE-2023-50952" + ], + "details": "IBM InfoSphere Information Server 11.7 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 275774.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50952" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/275774" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7158437" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-30T18:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-5xr3-jfwm-2p2g/GHSA-5xr3-jfwm-2p2g.json b/advisories/unreviewed/2024/06/GHSA-5xr3-jfwm-2p2g/GHSA-5xr3-jfwm-2p2g.json new file mode 100644 index 00000000000..ce7ba99901d --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-5xr3-jfwm-2p2g/GHSA-5xr3-jfwm-2p2g.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xr3-jfwm-2p2g", + "modified": "2024-06-30T18:30:37Z", + "published": "2024-06-30T18:30:37Z", + "aliases": [ + "CVE-2024-28795" + ], + "details": "IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 286832.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28795" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/286832" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7158408" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-30T16:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-cq47-mvqf-ggfh/GHSA-cq47-mvqf-ggfh.json b/advisories/unreviewed/2024/06/GHSA-cq47-mvqf-ggfh/GHSA-cq47-mvqf-ggfh.json new file mode 100644 index 00000000000..2864cc5b0f4 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-cq47-mvqf-ggfh/GHSA-cq47-mvqf-ggfh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cq47-mvqf-ggfh", + "modified": "2024-06-30T18:30:38Z", + "published": "2024-06-30T18:30:38Z", + "aliases": [ + "CVE-2024-31898" + ], + "details": "IBM InfoSphere Information Server 11.7 could allow an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references. IBM X-Force ID: 288182.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31898" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/288182" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7158425" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-30T18:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-crv7-mhxq-6c8r/GHSA-crv7-mhxq-6c8r.json b/advisories/unreviewed/2024/06/GHSA-crv7-mhxq-6c8r/GHSA-crv7-mhxq-6c8r.json new file mode 100644 index 00000000000..a60b990eb23 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-crv7-mhxq-6c8r/GHSA-crv7-mhxq-6c8r.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crv7-mhxq-6c8r", + "modified": "2024-06-30T18:30:37Z", + "published": "2024-06-30T18:30:37Z", + "aliases": [ + "CVE-2023-35022" + ], + "details": "IBM InfoSphere Information Server 11.7 could allow a local user to update projects that they do not have the authorization to access. IBM X-Force ID: 258254.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35022" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/258254" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7158447" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-30T16:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-p9r6-pcrg-rp27/GHSA-p9r6-pcrg-rp27.json b/advisories/unreviewed/2024/06/GHSA-p9r6-pcrg-rp27/GHSA-p9r6-pcrg-rp27.json new file mode 100644 index 00000000000..6d8e8275d42 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-p9r6-pcrg-rp27/GHSA-p9r6-pcrg-rp27.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9r6-pcrg-rp27", + "modified": "2024-06-30T18:30:38Z", + "published": "2024-06-30T18:30:38Z", + "aliases": [ + "CVE-2024-35119" + ], + "details": "IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system. IBM X-Force ID: 290342.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35119" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/290342" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7159052" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-30T17:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-rfrp-hqmx-gff6/GHSA-rfrp-hqmx-gff6.json b/advisories/unreviewed/2024/06/GHSA-rfrp-hqmx-gff6/GHSA-rfrp-hqmx-gff6.json new file mode 100644 index 00000000000..e9caa777890 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-rfrp-hqmx-gff6/GHSA-rfrp-hqmx-gff6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfrp-hqmx-gff6", + "modified": "2024-06-30T18:30:38Z", + "published": "2024-06-30T18:30:37Z", + "aliases": [ + "CVE-2024-31902" + ], + "details": "IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 289234.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31902" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/289234" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7159066" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-30T17:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-v34f-8v6r-qr8h/GHSA-v34f-8v6r-qr8h.json b/advisories/unreviewed/2024/06/GHSA-v34f-8v6r-qr8h/GHSA-v34f-8v6r-qr8h.json new file mode 100644 index 00000000000..a7a94b258e3 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-v34f-8v6r-qr8h/GHSA-v34f-8v6r-qr8h.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v34f-8v6r-qr8h", + "modified": "2024-06-30T18:30:37Z", + "published": "2024-06-30T18:30:37Z", + "aliases": [ + "CVE-2023-50954" + ], + "details": "IBM InfoSphere Information Server 11.7 returns sensitive information in URL information that could be used in further attacks against the system. IBM X-Force ID: 275776.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50954" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/275776" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7158597" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-598" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-30T17:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-v84w-2v56-wm6q/GHSA-v84w-2v56-wm6q.json b/advisories/unreviewed/2024/06/GHSA-v84w-2v56-wm6q/GHSA-v84w-2v56-wm6q.json new file mode 100644 index 00000000000..32b95fa3b89 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-v84w-2v56-wm6q/GHSA-v84w-2v56-wm6q.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v84w-2v56-wm6q", + "modified": "2024-06-30T18:30:37Z", + "published": "2024-06-30T18:30:37Z", + "aliases": [ + "CVE-2024-28798" + ], + "details": "IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 287172.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28798" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/287172" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7158439" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-30T17:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-x7f5-fmr9-q92p/GHSA-x7f5-fmr9-q92p.json b/advisories/unreviewed/2024/06/GHSA-x7f5-fmr9-q92p/GHSA-x7f5-fmr9-q92p.json new file mode 100644 index 00000000000..40188b2a4ee --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-x7f5-fmr9-q92p/GHSA-x7f5-fmr9-q92p.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7f5-fmr9-q92p", + "modified": "2024-06-30T18:30:38Z", + "published": "2024-06-30T18:30:38Z", + "aliases": [ + "CVE-2024-28797" + ], + "details": "IBM InfoSphere Information Server 11.7 is vulnerable stored to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 287136.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28797" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/287136" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7158431" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-30T18:15:03Z" + } +} \ No newline at end of file