diff --git a/advisories/unreviewed/2024/12/GHSA-5vhp-6mvg-gg49/GHSA-5vhp-6mvg-gg49.json b/advisories/unreviewed/2024/12/GHSA-5vhp-6mvg-gg49/GHSA-5vhp-6mvg-gg49.json new file mode 100644 index 00000000000..3357cd5b60a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5vhp-6mvg-gg49/GHSA-5vhp-6mvg-gg49.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vhp-6mvg-gg49", + "modified": "2024-12-03T12:31:11Z", + "published": "2024-12-03T12:31:11Z", + "aliases": [ + "CVE-2024-12062" + ], + "details": "The Charity Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.3.2 via the 'nacharity_elementor_template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private or draft posts created by Elementor that they should not have access to.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12062" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/charity-addon-for-elementor/trunk/elementor/lib/lib.php#L12" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7ac68314-c704-4273-addc-4bc623659769?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T10:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7g2h-2mgx-vhpc/GHSA-7g2h-2mgx-vhpc.json b/advisories/unreviewed/2024/12/GHSA-7g2h-2mgx-vhpc/GHSA-7g2h-2mgx-vhpc.json new file mode 100644 index 00000000000..68bad99af6e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7g2h-2mgx-vhpc/GHSA-7g2h-2mgx-vhpc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7g2h-2mgx-vhpc", + "modified": "2024-12-03T12:31:11Z", + "published": "2024-12-03T12:31:11Z", + "aliases": [ + "CVE-2024-47476" + ], + "details": "Dell NetWorker Management Console, version(s) 19.11, contain(s) an Improper Verification of Cryptographic Signature vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47476" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000255884/dsa-2024-477-security-update-for-dell-networker-runtime-environment-nre-multiple-component-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-347" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T10:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8r8p-6qcr-pv6h/GHSA-8r8p-6qcr-pv6h.json b/advisories/unreviewed/2024/12/GHSA-8r8p-6qcr-pv6h/GHSA-8r8p-6qcr-pv6h.json new file mode 100644 index 00000000000..b4d45c791e8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8r8p-6qcr-pv6h/GHSA-8r8p-6qcr-pv6h.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8r8p-6qcr-pv6h", + "modified": "2024-12-03T12:31:11Z", + "published": "2024-12-03T12:31:11Z", + "aliases": [ + "CVE-2024-11782" + ], + "details": "The WP Mailster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mst_subscribe' shortcode in all versions up to, and including, 1.8.17.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11782" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-mailster/tags/1.8.17.0/mailster/subscr/SubscriberPlugin.php#L216" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3198497/wp-mailster/trunk/mailster/subscr/SubscriberPlugin.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/909beed4-06a9-4ec4-bf00-4072a38af82b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T10:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9f3p-pw3r-85xg/GHSA-9f3p-pw3r-85xg.json b/advisories/unreviewed/2024/12/GHSA-9f3p-pw3r-85xg/GHSA-9f3p-pw3r-85xg.json new file mode 100644 index 00000000000..768806b8342 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9f3p-pw3r-85xg/GHSA-9f3p-pw3r-85xg.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9f3p-pw3r-85xg", + "modified": "2024-12-03T12:31:11Z", + "published": "2024-12-03T12:31:11Z", + "aliases": [ + "CVE-2024-11326" + ], + "details": "The Campaign Monitor Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.5.7. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11326" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/campaign-monitor-wp/trunk/includes/eoi-subscribers.php#L353" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3198560/campaign-monitor-wp/trunk/includes/eoi-subscribers.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/95ebb2ad-91a8-4a0d-ba91-f417943545b4?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T11:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mfm5-wjjm-f6hj/GHSA-mfm5-wjjm-f6hj.json b/advisories/unreviewed/2024/12/GHSA-mfm5-wjjm-f6hj/GHSA-mfm5-wjjm-f6hj.json new file mode 100644 index 00000000000..c30e18efc5f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mfm5-wjjm-f6hj/GHSA-mfm5-wjjm-f6hj.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mfm5-wjjm-f6hj", + "modified": "2024-12-03T12:31:10Z", + "published": "2024-12-03T12:31:10Z", + "aliases": [ + "CVE-2024-11325" + ], + "details": "The AWeber Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.5.7. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11325" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/aweber-wp/trunk/includes/eoi-subscribers.php#L353" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3198559/aweber-wp/trunk/includes/eoi-subscribers.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/21c09207-38a1-47ae-ae1e-52f8eea4785d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T10:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rcq8-9q3j-98mw/GHSA-rcq8-9q3j-98mw.json b/advisories/unreviewed/2024/12/GHSA-rcq8-9q3j-98mw/GHSA-rcq8-9q3j-98mw.json new file mode 100644 index 00000000000..cc8a6c636d6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rcq8-9q3j-98mw/GHSA-rcq8-9q3j-98mw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rcq8-9q3j-98mw", + "modified": "2024-12-03T12:31:11Z", + "published": "2024-12-03T12:31:11Z", + "aliases": [ + "CVE-2024-45106" + ], + "details": "Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate the S3 secrets of any other user. This is only possible if:\n * ozone.s3g.secret.http.enabled is set to true. The default value of this configuration is false.\n * The user configured in ozone.s3g.kerberos.principal is also configured in ozone.s3.administrators or ozone.administrators.\n\n\nUsers are recommended to upgrade to Apache Ozone version 1.4.1 which disables the affected endpoint.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45106" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/rylnxwttp004kvotpk9j158vb238pfkm" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/12/02/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T10:15:05Z" + } +} \ No newline at end of file