mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-294x-pcj2-wqf8 GHSA-68wq-r58h-5q45 GHSA-cgvx-9447-vcch GHSA-cm55-w5wp-4fgq GHSA-ff7q-6vwh-v9m4 GHSA-hrvr-7x5w-xpmq GHSA-vfjj-rqvw-qh77 GHSA-xpvm-9wx5-vjpw
This commit is contained in:
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-294x-pcj2-wqf8",
|
||||
"modified": "2024-06-28T00:33:31Z",
|
||||
"published": "2024-06-28T00:33:31Z",
|
||||
"aliases": [
|
||||
"CVE-2024-36059"
|
||||
],
|
||||
"details": "Directory Traversal vulnerability in Kalkitech ASE ASE61850 IEDSmart upto and including version 2.3.5 allows attackers to read/write arbitrary files via the IEC61850 File Transfer protocol.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36059"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://kalkitech.com/wp-content/uploads/2024/05/CYB_60704_Advisory_v1.0.pdf"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-27T22:15:10Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,47 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-68wq-r58h-5q45",
|
||||
"modified": "2024-06-28T00:33:31Z",
|
||||
"published": "2024-06-28T00:33:31Z",
|
||||
"aliases": [
|
||||
"CVE-2024-4395"
|
||||
],
|
||||
"details": "The XPC service within the audit functionality of Jamf Compliance Editor before version 1.3.1 on macOS can lead to local privilege escalation.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4395"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/Jamf-Concepts/jamf-compliance-editor/raw/v1.3.1/Jamf%20Compliance%20Editor%20-%20User%20Guide.pdf"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/Jamf-Concepts/jamf-compliance-editor/releases/download/v1.3.1/JamfComplianceEditor.v1.3.1.pkg"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://khronokernel.com/macos/2024/05/01/CVE-2024-4395.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://trusted.jamf.com/docs/establishing-compliance-baselines#support"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-27T22:15:10Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-cgvx-9447-vcch",
|
||||
"modified": "2024-06-28T00:33:31Z",
|
||||
"published": "2024-06-28T00:33:31Z",
|
||||
"aliases": [
|
||||
"CVE-2024-39705"
|
||||
],
|
||||
"details": "NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39705"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/nltk/nltk/issues/2522"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/nltk/nltk/issues/3266"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-27T22:15:10Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,42 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-cm55-w5wp-4fgq",
|
||||
"modified": "2024-06-28T00:33:31Z",
|
||||
"published": "2024-06-28T00:33:31Z",
|
||||
"aliases": [
|
||||
"CVE-2024-6071"
|
||||
],
|
||||
"details": "PTC Creo Elements/Direct License Server exposes a web interface which can be used by unauthenticated remote attackers to execute arbitrary OS commands on the server.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6071"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-177-02"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.ptc.com/en/support/article/CS417607"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-862"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-27T23:15:50Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,47 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-ff7q-6vwh-v9m4",
|
||||
"modified": "2024-06-28T00:33:31Z",
|
||||
"published": "2024-06-28T00:33:31Z",
|
||||
"aliases": [
|
||||
"CVE-2023-52892"
|
||||
],
|
||||
"details": "In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields in TLS certificates are incorrectly allowed to have a special meaning in regular expressions (such as a + wildcard), leading to name confusion in X.509 certificate host verification.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52892"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/phpseclib/phpseclib/issues/1943"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/phpseclib/phpseclib/commit/6cd6e8ceab9f2b55c8cd81d2192bf98cbeaf4627"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/phpseclib/phpseclib/releases/tag/3.0.33"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/x509-name-testing/name_testing_artifacts"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-27T22:15:10Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-hrvr-7x5w-xpmq",
|
||||
"modified": "2024-06-27T21:32:09Z",
|
||||
"modified": "2024-06-28T00:33:31Z",
|
||||
"published": "2024-06-27T21:32:09Z",
|
||||
"aliases": [
|
||||
"CVE-2024-5642"
|
||||
@@ -22,9 +22,17 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/python/cpython/pull/23014"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/python/cpython/commit/39258d3595300bc7b952854c915f63ae2d4b9c3e"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://jbp.io/2024/06/27/cve-2024-5535-openssl-memory-safety.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://mail.python.org/archives/list/security-announce@python.org/thread/PLP2JI3PJY33YG6P5BZYSSNU66HASXBQ"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -0,0 +1,43 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-vfjj-rqvw-qh77",
|
||||
"modified": "2024-06-28T00:33:31Z",
|
||||
"published": "2024-06-28T00:33:31Z",
|
||||
"aliases": [
|
||||
"CVE-2016-20022"
|
||||
],
|
||||
"details": "In the Linux kernel before 4.8, usb_parse_endpoint in drivers/usb/core/config.c does not validate the wMaxPacketSize field of an endpoint descriptor. NOTE: This vulnerability only affects products that are no longer supported by the supplier.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2016-20022"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/torvalds/linux/commit/aed9d65ac3278d4febd8665bd7db59ef53e825fe"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lore.kernel.org/lkml/1486322541-8206-8-git-send-email-w%401wt.eu"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.spinics.net/lists/linux-usb/msg144177.html"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-27T23:15:50Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-xpvm-9wx5-vjpw",
|
||||
"modified": "2024-06-07T03:31:04Z",
|
||||
"modified": "2024-06-28T00:33:30Z",
|
||||
"published": "2024-06-07T03:31:04Z",
|
||||
"aliases": [
|
||||
"CVE-2022-4968"
|
||||
@@ -21,6 +21,10 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4968"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/canonical/netplan/commit/4c39b75b5c6ae7d976bda6da68da60d9a7f085ee"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://bugs.launchpad.net/netplan/+bug/1987842"
|
||||
@@ -36,7 +40,8 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-200"
|
||||
"CWE-200",
|
||||
"CWE-497"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
|
||||
Reference in New Issue
Block a user