Publish Advisories

GHSA-294x-pcj2-wqf8
GHSA-68wq-r58h-5q45
GHSA-cgvx-9447-vcch
GHSA-cm55-w5wp-4fgq
GHSA-ff7q-6vwh-v9m4
GHSA-hrvr-7x5w-xpmq
GHSA-vfjj-rqvw-qh77
GHSA-xpvm-9wx5-vjpw
This commit is contained in:
advisory-database[bot]
2024-06-28 00:34:36 +00:00
parent 3cb4293047
commit 0775c453fc
8 changed files with 269 additions and 3 deletions
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-294x-pcj2-wqf8",
"modified": "2024-06-28T00:33:31Z",
"published": "2024-06-28T00:33:31Z",
"aliases": [
"CVE-2024-36059"
],
"details": "Directory Traversal vulnerability in Kalkitech ASE ASE61850 IEDSmart upto and including version 2.3.5 allows attackers to read/write arbitrary files via the IEC61850 File Transfer protocol.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36059"
},
{
"type": "WEB",
"url": "https://kalkitech.com/wp-content/uploads/2024/05/CYB_60704_Advisory_v1.0.pdf"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-27T22:15:10Z"
}
}
@@ -0,0 +1,47 @@
{
"schema_version": "1.4.0",
"id": "GHSA-68wq-r58h-5q45",
"modified": "2024-06-28T00:33:31Z",
"published": "2024-06-28T00:33:31Z",
"aliases": [
"CVE-2024-4395"
],
"details": "The XPC service within the audit functionality of Jamf Compliance Editor before version 1.3.1 on macOS can lead to local privilege escalation.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4395"
},
{
"type": "WEB",
"url": "https://github.com/Jamf-Concepts/jamf-compliance-editor/raw/v1.3.1/Jamf%20Compliance%20Editor%20-%20User%20Guide.pdf"
},
{
"type": "WEB",
"url": "https://github.com/Jamf-Concepts/jamf-compliance-editor/releases/download/v1.3.1/JamfComplianceEditor.v1.3.1.pkg"
},
{
"type": "WEB",
"url": "https://khronokernel.com/macos/2024/05/01/CVE-2024-4395.html"
},
{
"type": "WEB",
"url": "https://trusted.jamf.com/docs/establishing-compliance-baselines#support"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-27T22:15:10Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cgvx-9447-vcch",
"modified": "2024-06-28T00:33:31Z",
"published": "2024-06-28T00:33:31Z",
"aliases": [
"CVE-2024-39705"
],
"details": "NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39705"
},
{
"type": "WEB",
"url": "https://github.com/nltk/nltk/issues/2522"
},
{
"type": "WEB",
"url": "https://github.com/nltk/nltk/issues/3266"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-27T22:15:10Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cm55-w5wp-4fgq",
"modified": "2024-06-28T00:33:31Z",
"published": "2024-06-28T00:33:31Z",
"aliases": [
"CVE-2024-6071"
],
"details": "PTC Creo Elements/Direct License Server exposes a web interface which can be used by unauthenticated remote attackers to execute arbitrary OS commands on the server.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6071"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-177-02"
},
{
"type": "WEB",
"url": "https://www.ptc.com/en/support/article/CS417607"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-27T23:15:50Z"
}
}
@@ -0,0 +1,47 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ff7q-6vwh-v9m4",
"modified": "2024-06-28T00:33:31Z",
"published": "2024-06-28T00:33:31Z",
"aliases": [
"CVE-2023-52892"
],
"details": "In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields in TLS certificates are incorrectly allowed to have a special meaning in regular expressions (such as a + wildcard), leading to name confusion in X.509 certificate host verification.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52892"
},
{
"type": "WEB",
"url": "https://github.com/phpseclib/phpseclib/issues/1943"
},
{
"type": "WEB",
"url": "https://github.com/phpseclib/phpseclib/commit/6cd6e8ceab9f2b55c8cd81d2192bf98cbeaf4627"
},
{
"type": "WEB",
"url": "https://github.com/phpseclib/phpseclib/releases/tag/3.0.33"
},
{
"type": "WEB",
"url": "https://github.com/x509-name-testing/name_testing_artifacts"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-27T22:15:10Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hrvr-7x5w-xpmq",
"modified": "2024-06-27T21:32:09Z",
"modified": "2024-06-28T00:33:31Z",
"published": "2024-06-27T21:32:09Z",
"aliases": [
"CVE-2024-5642"
@@ -22,9 +22,17 @@
"type": "WEB",
"url": "https://github.com/python/cpython/pull/23014"
},
{
"type": "WEB",
"url": "https://github.com/python/cpython/commit/39258d3595300bc7b952854c915f63ae2d4b9c3e"
},
{
"type": "WEB",
"url": "https://jbp.io/2024/06/27/cve-2024-5535-openssl-memory-safety.html"
},
{
"type": "WEB",
"url": "https://mail.python.org/archives/list/security-announce@python.org/thread/PLP2JI3PJY33YG6P5BZYSSNU66HASXBQ"
}
],
"database_specific": {
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vfjj-rqvw-qh77",
"modified": "2024-06-28T00:33:31Z",
"published": "2024-06-28T00:33:31Z",
"aliases": [
"CVE-2016-20022"
],
"details": "In the Linux kernel before 4.8, usb_parse_endpoint in drivers/usb/core/config.c does not validate the wMaxPacketSize field of an endpoint descriptor. NOTE: This vulnerability only affects products that are no longer supported by the supplier.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2016-20022"
},
{
"type": "WEB",
"url": "https://github.com/torvalds/linux/commit/aed9d65ac3278d4febd8665bd7db59ef53e825fe"
},
{
"type": "WEB",
"url": "https://lore.kernel.org/lkml/1486322541-8206-8-git-send-email-w%401wt.eu"
},
{
"type": "WEB",
"url": "https://www.spinics.net/lists/linux-usb/msg144177.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-27T23:15:50Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xpvm-9wx5-vjpw",
"modified": "2024-06-07T03:31:04Z",
"modified": "2024-06-28T00:33:30Z",
"published": "2024-06-07T03:31:04Z",
"aliases": [
"CVE-2022-4968"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4968"
},
{
"type": "WEB",
"url": "https://github.com/canonical/netplan/commit/4c39b75b5c6ae7d976bda6da68da60d9a7f085ee"
},
{
"type": "WEB",
"url": "https://bugs.launchpad.net/netplan/+bug/1987842"
@@ -36,7 +40,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-200"
"CWE-200",
"CWE-497"
],
"severity": "MODERATE",
"github_reviewed": false,