From 088445fcb024c7bbab4ad335589e5d6429830b68 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 10 Oct 2024 21:32:03 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-8vhq-qq4p-grq3.json | 86 +++++++++++-------- .../GHSA-mjm5-8p7x-r4cv.json | 1 + .../GHSA-8f29-jv59-33jp.json | 1 + .../GHSA-hcw4-x562-rv3j.json | 1 + .../GHSA-wh73-785p-7wcf.json | 11 ++- .../GHSA-j6qj-c649-wpqq.json | 11 ++- .../GHSA-2j74-3g9x-9cw4.json | 6 +- .../GHSA-2x2h-53cj-6jjx.json | 38 ++++++++ .../GHSA-3h6c-6qpq-hv5j.json | 38 ++++++++ .../GHSA-69rg-jv6m-76wg.json | 9 +- .../GHSA-72w8-q27v-r283.json | 38 ++++++++ .../GHSA-88gj-pxgp-vc28.json | 38 ++++++++ .../GHSA-9xfp-2644-5v32.json | 38 ++++++++ .../GHSA-cc5q-6gfg-rw5g.json | 38 ++++++++ .../GHSA-cfr2-7pw9-8g22.json | 58 +++++++++++++ .../GHSA-fcww-rh3v-86v8.json | 58 +++++++++++++ .../GHSA-fmmq-pcrc-2hcv.json | 38 ++++++++ .../GHSA-gf5h-4pjr-gwj4.json | 38 ++++++++ .../GHSA-gv8m-hc54-33cp.json | 38 ++++++++ .../GHSA-hmr6-x7h8-r5mp.json | 6 +- .../GHSA-j457-97cq-4x7p.json | 54 ++++++++++++ .../GHSA-jw4c-324x-xpc8.json | 58 +++++++++++++ .../GHSA-m39v-rgw3-qmpc.json | 54 ++++++++++++ .../GHSA-mfh4-qvwj-c4ff.json | 38 ++++++++ .../GHSA-pf8h-79jj-r6cc.json | 38 ++++++++ .../GHSA-phj7-phjc-r9wg.json | 38 ++++++++ .../GHSA-q6g9-h87p-p9fw.json | 38 ++++++++ .../GHSA-qfh6-hjfc-cx2m.json | 58 +++++++++++++ .../GHSA-qx68-647q-334v.json | 58 +++++++++++++ .../GHSA-rr8j-7w34-xp5j.json | 38 ++++++++ .../GHSA-rx73-mj92-mhc9.json | 38 ++++++++ .../GHSA-v8c3-f895-g4r9.json | 38 ++++++++ .../GHSA-vqqv-5pgx-px9w.json | 54 ++++++++++++ .../GHSA-x5wp-rg6r-3pmj.json | 38 ++++++++ 34 files changed, 1183 insertions(+), 47 deletions(-) create mode 100644 advisories/unreviewed/2024/10/GHSA-2x2h-53cj-6jjx/GHSA-2x2h-53cj-6jjx.json create mode 100644 advisories/unreviewed/2024/10/GHSA-3h6c-6qpq-hv5j/GHSA-3h6c-6qpq-hv5j.json create mode 100644 advisories/unreviewed/2024/10/GHSA-72w8-q27v-r283/GHSA-72w8-q27v-r283.json create mode 100644 advisories/unreviewed/2024/10/GHSA-88gj-pxgp-vc28/GHSA-88gj-pxgp-vc28.json create mode 100644 advisories/unreviewed/2024/10/GHSA-9xfp-2644-5v32/GHSA-9xfp-2644-5v32.json create mode 100644 advisories/unreviewed/2024/10/GHSA-cc5q-6gfg-rw5g/GHSA-cc5q-6gfg-rw5g.json create mode 100644 advisories/unreviewed/2024/10/GHSA-cfr2-7pw9-8g22/GHSA-cfr2-7pw9-8g22.json create mode 100644 advisories/unreviewed/2024/10/GHSA-fcww-rh3v-86v8/GHSA-fcww-rh3v-86v8.json create mode 100644 advisories/unreviewed/2024/10/GHSA-fmmq-pcrc-2hcv/GHSA-fmmq-pcrc-2hcv.json create mode 100644 advisories/unreviewed/2024/10/GHSA-gf5h-4pjr-gwj4/GHSA-gf5h-4pjr-gwj4.json create mode 100644 advisories/unreviewed/2024/10/GHSA-gv8m-hc54-33cp/GHSA-gv8m-hc54-33cp.json create mode 100644 advisories/unreviewed/2024/10/GHSA-j457-97cq-4x7p/GHSA-j457-97cq-4x7p.json create mode 100644 advisories/unreviewed/2024/10/GHSA-jw4c-324x-xpc8/GHSA-jw4c-324x-xpc8.json create mode 100644 advisories/unreviewed/2024/10/GHSA-m39v-rgw3-qmpc/GHSA-m39v-rgw3-qmpc.json create mode 100644 advisories/unreviewed/2024/10/GHSA-mfh4-qvwj-c4ff/GHSA-mfh4-qvwj-c4ff.json create mode 100644 advisories/unreviewed/2024/10/GHSA-pf8h-79jj-r6cc/GHSA-pf8h-79jj-r6cc.json create mode 100644 advisories/unreviewed/2024/10/GHSA-phj7-phjc-r9wg/GHSA-phj7-phjc-r9wg.json create mode 100644 advisories/unreviewed/2024/10/GHSA-q6g9-h87p-p9fw/GHSA-q6g9-h87p-p9fw.json create mode 100644 advisories/unreviewed/2024/10/GHSA-qfh6-hjfc-cx2m/GHSA-qfh6-hjfc-cx2m.json create mode 100644 advisories/unreviewed/2024/10/GHSA-qx68-647q-334v/GHSA-qx68-647q-334v.json create mode 100644 advisories/unreviewed/2024/10/GHSA-rr8j-7w34-xp5j/GHSA-rr8j-7w34-xp5j.json create mode 100644 advisories/unreviewed/2024/10/GHSA-rx73-mj92-mhc9/GHSA-rx73-mj92-mhc9.json create mode 100644 advisories/unreviewed/2024/10/GHSA-v8c3-f895-g4r9/GHSA-v8c3-f895-g4r9.json create mode 100644 advisories/unreviewed/2024/10/GHSA-vqqv-5pgx-px9w/GHSA-vqqv-5pgx-px9w.json create mode 100644 advisories/unreviewed/2024/10/GHSA-x5wp-rg6r-3pmj/GHSA-x5wp-rg6r-3pmj.json diff --git a/advisories/github-reviewed/2022/05/GHSA-8vhq-qq4p-grq3/GHSA-8vhq-qq4p-grq3.json b/advisories/github-reviewed/2022/05/GHSA-8vhq-qq4p-grq3/GHSA-8vhq-qq4p-grq3.json index c5c2659f0ba..0f18bfd366c 100644 --- a/advisories/github-reviewed/2022/05/GHSA-8vhq-qq4p-grq3/GHSA-8vhq-qq4p-grq3.json +++ b/advisories/github-reviewed/2022/05/GHSA-8vhq-qq4p-grq3/GHSA-8vhq-qq4p-grq3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8vhq-qq4p-grq3", - "modified": "2022-07-01T21:47:32Z", + "modified": "2024-10-10T21:30:40Z", "published": "2022-05-13T01:11:53Z", "aliases": [ "CVE-2017-1000487" @@ -46,39 +46,7 @@ }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2018:1322" - }, - { - "type": "PACKAGE", - "url": "https://github.com/codehaus-plexus/plexus-utils" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe@%3Ccommits.druid.apache.org%3E" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/r2e94f72f53df432302d359fd66cfa9e9efb8d42633d54579a4377e62@%3Cdev.avro.apache.org%3E" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/r9584c4304c888f651d214341a939bd264ed30c9e3d0d30fe85097ecf@%3Ccommits.pulsar.apache.org%3E" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26@%3Ccommits.pulsar.apache.org%3E" - }, - { - "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2018/01/msg00010.html" - }, - { - "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2018/01/msg00011.html" - }, - { - "type": "WEB", - "url": "https://snyk.io/vuln/SNYK-JAVA-ORGCODEHAUSPLEXUS-31522" + "url": "https://www.debian.org/security/2018/dsa-4149" }, { "type": "WEB", @@ -86,7 +54,55 @@ }, { "type": "WEB", - "url": "https://www.debian.org/security/2018/dsa-4149" + "url": "https://snyk.io/vuln/SNYK-JAVA-ORGCODEHAUSPLEXUS-31522" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2018/01/msg00011.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2018/01/msg00010.html" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26@%3Ccommits.pulsar.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r9584c4304c888f651d214341a939bd264ed30c9e3d0d30fe85097ecf@%3Ccommits.pulsar.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r9584c4304c888f651d214341a939bd264ed30c9e3d0d30fe85097ecf%40%3Ccommits.pulsar.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r2e94f72f53df432302d359fd66cfa9e9efb8d42633d54579a4377e62@%3Cdev.avro.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r2e94f72f53df432302d359fd66cfa9e9efb8d42633d54579a4377e62%40%3Cdev.avro.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe@%3Ccommits.druid.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3E" + }, + { + "type": "PACKAGE", + "url": "https://github.com/codehaus-plexus/plexus-utils" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2018:1322" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/11/GHSA-mjm5-8p7x-r4cv/GHSA-mjm5-8p7x-r4cv.json b/advisories/unreviewed/2023/11/GHSA-mjm5-8p7x-r4cv/GHSA-mjm5-8p7x-r4cv.json index af918dcc56b..7be49511453 100644 --- a/advisories/unreviewed/2023/11/GHSA-mjm5-8p7x-r4cv/GHSA-mjm5-8p7x-r4cv.json +++ b/advisories/unreviewed/2023/11/GHSA-mjm5-8p7x-r4cv/GHSA-mjm5-8p7x-r4cv.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-611", "CWE-732" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/03/GHSA-8f29-jv59-33jp/GHSA-8f29-jv59-33jp.json b/advisories/unreviewed/2024/03/GHSA-8f29-jv59-33jp/GHSA-8f29-jv59-33jp.json index 03c23e15570..a151d240099 100644 --- a/advisories/unreviewed/2024/03/GHSA-8f29-jv59-33jp/GHSA-8f29-jv59-33jp.json +++ b/advisories/unreviewed/2024/03/GHSA-8f29-jv59-33jp/GHSA-8f29-jv59-33jp.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1285", "CWE-755" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/03/GHSA-hcw4-x562-rv3j/GHSA-hcw4-x562-rv3j.json b/advisories/unreviewed/2024/03/GHSA-hcw4-x562-rv3j/GHSA-hcw4-x562-rv3j.json index bf385a87739..899ab31f062 100644 --- a/advisories/unreviewed/2024/03/GHSA-hcw4-x562-rv3j/GHSA-hcw4-x562-rv3j.json +++ b/advisories/unreviewed/2024/03/GHSA-hcw4-x562-rv3j/GHSA-hcw4-x562-rv3j.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1285", "CWE-755" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/06/GHSA-wh73-785p-7wcf/GHSA-wh73-785p-7wcf.json b/advisories/unreviewed/2024/06/GHSA-wh73-785p-7wcf/GHSA-wh73-785p-7wcf.json index 113d15bfa5a..21b97d9a10e 100644 --- a/advisories/unreviewed/2024/06/GHSA-wh73-785p-7wcf/GHSA-wh73-785p-7wcf.json +++ b/advisories/unreviewed/2024/06/GHSA-wh73-785p-7wcf/GHSA-wh73-785p-7wcf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wh73-785p-7wcf", - "modified": "2024-06-07T00:30:36Z", + "modified": "2024-10-10T21:30:42Z", "published": "2024-06-07T00:30:36Z", "aliases": [ "CVE-2023-49441" ], "details": "dnsmasq 2.9 is vulnerable to Integer Overflow via forward_query.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-06T22:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-j6qj-c649-wpqq/GHSA-j6qj-c649-wpqq.json b/advisories/unreviewed/2024/08/GHSA-j6qj-c649-wpqq/GHSA-j6qj-c649-wpqq.json index bbbdd02cf7e..749a0aa766f 100644 --- a/advisories/unreviewed/2024/08/GHSA-j6qj-c649-wpqq/GHSA-j6qj-c649-wpqq.json +++ b/advisories/unreviewed/2024/08/GHSA-j6qj-c649-wpqq/GHSA-j6qj-c649-wpqq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j6qj-c649-wpqq", - "modified": "2024-08-19T21:35:10Z", + "modified": "2024-10-10T21:30:42Z", "published": "2024-08-19T21:35:10Z", "aliases": [ "CVE-2024-42812" ], "details": "In D-Link DIR-860L v2.03, there is a buffer overflow vulnerability due to the lack of length verification for the SID field in gena.cgi. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-19T20:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-2j74-3g9x-9cw4/GHSA-2j74-3g9x-9cw4.json b/advisories/unreviewed/2024/10/GHSA-2j74-3g9x-9cw4/GHSA-2j74-3g9x-9cw4.json index 351affc301b..c452abd6b28 100644 --- a/advisories/unreviewed/2024/10/GHSA-2j74-3g9x-9cw4/GHSA-2j74-3g9x-9cw4.json +++ b/advisories/unreviewed/2024/10/GHSA-2j74-3g9x-9cw4/GHSA-2j74-3g9x-9cw4.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2j74-3g9x-9cw4", - "modified": "2024-10-04T12:31:01Z", + "modified": "2024-10-10T21:30:42Z", "published": "2024-10-04T12:31:01Z", "aliases": [ "CVE-2024-47651" ], "details": "This vulnerability exists in Shilpi Client Dashboard due to improper handling of multiple parameters in the API endpoint. An authenticated remote attacker could exploit this vulnerability by including multiple “userid” parameters in the API request body leading to unauthorized access of sensitive information belonging to other users.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/10/GHSA-2x2h-53cj-6jjx/GHSA-2x2h-53cj-6jjx.json b/advisories/unreviewed/2024/10/GHSA-2x2h-53cj-6jjx/GHSA-2x2h-53cj-6jjx.json new file mode 100644 index 00000000000..e4e708cc85c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2x2h-53cj-6jjx/GHSA-2x2h-53cj-6jjx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2x2h-53cj-6jjx", + "modified": "2024-10-10T21:30:41Z", + "published": "2024-10-10T21:30:41Z", + "aliases": [ + "CVE-2023-24463" + ], + "details": "Improper input validation in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24463" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00851.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3h6c-6qpq-hv5j/GHSA-3h6c-6qpq-hv5j.json b/advisories/unreviewed/2024/10/GHSA-3h6c-6qpq-hv5j/GHSA-3h6c-6qpq-hv5j.json new file mode 100644 index 00000000000..072ae58ac6e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3h6c-6qpq-hv5j/GHSA-3h6c-6qpq-hv5j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3h6c-6qpq-hv5j", + "modified": "2024-10-10T21:30:42Z", + "published": "2024-10-10T21:30:42Z", + "aliases": [ + "CVE-2023-27303" + ], + "details": "Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27303" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00851.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-69rg-jv6m-76wg/GHSA-69rg-jv6m-76wg.json b/advisories/unreviewed/2024/10/GHSA-69rg-jv6m-76wg/GHSA-69rg-jv6m-76wg.json index 9c790552ac5..5d685d7e9a8 100644 --- a/advisories/unreviewed/2024/10/GHSA-69rg-jv6m-76wg/GHSA-69rg-jv6m-76wg.json +++ b/advisories/unreviewed/2024/10/GHSA-69rg-jv6m-76wg/GHSA-69rg-jv6m-76wg.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-69rg-jv6m-76wg", - "modified": "2024-10-04T21:31:30Z", + "modified": "2024-10-10T21:30:42Z", "published": "2024-10-04T21:31:30Z", "aliases": [ "CVE-2024-9054" ], "details": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Microchip TimeProvider 4100 (Configuration modules) allows Command Injection.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Amber" @@ -32,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-72w8-q27v-r283/GHSA-72w8-q27v-r283.json b/advisories/unreviewed/2024/10/GHSA-72w8-q27v-r283/GHSA-72w8-q27v-r283.json new file mode 100644 index 00000000000..1306b8952d0 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-72w8-q27v-r283/GHSA-72w8-q27v-r283.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-72w8-q27v-r283", + "modified": "2024-10-10T21:30:41Z", + "published": "2024-10-10T21:30:41Z", + "aliases": [ + "CVE-2023-22848" + ], + "details": "Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22848" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00851.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-88gj-pxgp-vc28/GHSA-88gj-pxgp-vc28.json b/advisories/unreviewed/2024/10/GHSA-88gj-pxgp-vc28/GHSA-88gj-pxgp-vc28.json new file mode 100644 index 00000000000..56763a6cbcf --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-88gj-pxgp-vc28/GHSA-88gj-pxgp-vc28.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88gj-pxgp-vc28", + "modified": "2024-10-10T21:30:42Z", + "published": "2024-10-10T21:30:42Z", + "aliases": [ + "CVE-2023-27301" + ], + "details": "Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27301" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00851.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9xfp-2644-5v32/GHSA-9xfp-2644-5v32.json b/advisories/unreviewed/2024/10/GHSA-9xfp-2644-5v32/GHSA-9xfp-2644-5v32.json new file mode 100644 index 00000000000..90e7b5235e3 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9xfp-2644-5v32/GHSA-9xfp-2644-5v32.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xfp-2644-5v32", + "modified": "2024-10-10T21:30:41Z", + "published": "2024-10-10T21:30:41Z", + "aliases": [ + "CVE-2023-24589" + ], + "details": "Improper buffer restrictions in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24589" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00851.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-cc5q-6gfg-rw5g/GHSA-cc5q-6gfg-rw5g.json b/advisories/unreviewed/2024/10/GHSA-cc5q-6gfg-rw5g/GHSA-cc5q-6gfg-rw5g.json new file mode 100644 index 00000000000..42ffd7a7a6c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-cc5q-6gfg-rw5g/GHSA-cc5q-6gfg-rw5g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cc5q-6gfg-rw5g", + "modified": "2024-10-10T21:30:41Z", + "published": "2024-10-10T21:30:41Z", + "aliases": [ + "CVE-2023-25777" + ], + "details": "Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25777" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00851.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-cfr2-7pw9-8g22/GHSA-cfr2-7pw9-8g22.json b/advisories/unreviewed/2024/10/GHSA-cfr2-7pw9-8g22/GHSA-cfr2-7pw9-8g22.json new file mode 100644 index 00000000000..2c668efbfe8 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-cfr2-7pw9-8g22/GHSA-cfr2-7pw9-8g22.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfr2-7pw9-8g22", + "modified": "2024-10-10T21:30:43Z", + "published": "2024-10-10T21:30:43Z", + "aliases": [ + "CVE-2024-9811" + ], + "details": "A vulnerability classified as critical has been found in code-projects Restaurant Reservation System 1.0. This affects an unknown part of the file filter3.php. The manipulation of the argument company leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9811" + }, + { + "type": "WEB", + "url": "https://github.com/ppp-src/a/issues/24" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.279963" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.279963" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.418728" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-10T21:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-fcww-rh3v-86v8/GHSA-fcww-rh3v-86v8.json b/advisories/unreviewed/2024/10/GHSA-fcww-rh3v-86v8/GHSA-fcww-rh3v-86v8.json new file mode 100644 index 00000000000..335b05339f3 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-fcww-rh3v-86v8/GHSA-fcww-rh3v-86v8.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fcww-rh3v-86v8", + "modified": "2024-10-10T21:30:43Z", + "published": "2024-10-10T21:30:43Z", + "aliases": [ + "CVE-2024-9810" + ], + "details": "A vulnerability was found in SourceCodester Record Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file sort2_user.php. The manipulation of the argument qualification leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9810" + }, + { + "type": "WEB", + "url": "https://github.com/GangZhou1/VUL/blob/main/Record-Management-System-1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.279962" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.279962" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.420806" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-10T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-fmmq-pcrc-2hcv/GHSA-fmmq-pcrc-2hcv.json b/advisories/unreviewed/2024/10/GHSA-fmmq-pcrc-2hcv/GHSA-fmmq-pcrc-2hcv.json new file mode 100644 index 00000000000..f58153cc341 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-fmmq-pcrc-2hcv/GHSA-fmmq-pcrc-2hcv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmmq-pcrc-2hcv", + "modified": "2024-10-10T21:30:42Z", + "published": "2024-10-10T21:30:41Z", + "aliases": [ + "CVE-2023-27300" + ], + "details": "Improper buffer restrictions in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27300" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00851.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-gf5h-4pjr-gwj4/GHSA-gf5h-4pjr-gwj4.json b/advisories/unreviewed/2024/10/GHSA-gf5h-4pjr-gwj4/GHSA-gf5h-4pjr-gwj4.json new file mode 100644 index 00000000000..03cefd23ff5 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-gf5h-4pjr-gwj4/GHSA-gf5h-4pjr-gwj4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gf5h-4pjr-gwj4", + "modified": "2024-10-10T21:30:41Z", + "published": "2024-10-10T21:30:41Z", + "aliases": [ + "CVE-2023-26585" + ], + "details": "Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26585" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00851.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-gv8m-hc54-33cp/GHSA-gv8m-hc54-33cp.json b/advisories/unreviewed/2024/10/GHSA-gv8m-hc54-33cp/GHSA-gv8m-hc54-33cp.json new file mode 100644 index 00000000000..d01f991000b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-gv8m-hc54-33cp/GHSA-gv8m-hc54-33cp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gv8m-hc54-33cp", + "modified": "2024-10-10T21:30:42Z", + "published": "2024-10-10T21:30:42Z", + "aliases": [ + "CVE-2023-27308" + ], + "details": "Improper buffer restrictions in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27308" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00851.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-hmr6-x7h8-r5mp/GHSA-hmr6-x7h8-r5mp.json b/advisories/unreviewed/2024/10/GHSA-hmr6-x7h8-r5mp/GHSA-hmr6-x7h8-r5mp.json index e8e0c313f16..a7967cc2a33 100644 --- a/advisories/unreviewed/2024/10/GHSA-hmr6-x7h8-r5mp/GHSA-hmr6-x7h8-r5mp.json +++ b/advisories/unreviewed/2024/10/GHSA-hmr6-x7h8-r5mp/GHSA-hmr6-x7h8-r5mp.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hmr6-x7h8-r5mp", - "modified": "2024-10-04T21:31:30Z", + "modified": "2024-10-10T21:30:42Z", "published": "2024-10-04T21:31:30Z", "aliases": [ "CVE-2024-7801" ], "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip TimeProvider 4100 (Data plot modules) allows SQL Injection.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:C/RE:M/U:Amber" diff --git a/advisories/unreviewed/2024/10/GHSA-j457-97cq-4x7p/GHSA-j457-97cq-4x7p.json b/advisories/unreviewed/2024/10/GHSA-j457-97cq-4x7p/GHSA-j457-97cq-4x7p.json new file mode 100644 index 00000000000..c9321c8dee2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-j457-97cq-4x7p/GHSA-j457-97cq-4x7p.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j457-97cq-4x7p", + "modified": "2024-10-10T21:30:43Z", + "published": "2024-10-10T21:30:43Z", + "aliases": [ + "CVE-2024-9807" + ], + "details": "A vulnerability was found in Craig Rodway Classroombookings 2.8.7 and classified as problematic. This issue affects some unknown processing of the file /sessions of the component Session Page. The manipulation of the argument Name leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 2.8.8 is able to address this issue. It is recommended to upgrade the affected component. The project maintainer was contacted early about the disclosure. He responded very quickly, friendly, and professional.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9807" + }, + { + "type": "WEB", + "url": "https://github.com/JunMing27/CVE/blob/main/CVE%20-%20classroombookings%20Cross%20Site%20Scripting%20(XSS)%20at%20create%20and%20edit%20session%20page%20via%20Administrator%20Dashboard.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.279959" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.279959" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.419262" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-10T19:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jw4c-324x-xpc8/GHSA-jw4c-324x-xpc8.json b/advisories/unreviewed/2024/10/GHSA-jw4c-324x-xpc8/GHSA-jw4c-324x-xpc8.json new file mode 100644 index 00000000000..98c629076e0 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jw4c-324x-xpc8/GHSA-jw4c-324x-xpc8.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jw4c-324x-xpc8", + "modified": "2024-10-10T21:30:43Z", + "published": "2024-10-10T21:30:43Z", + "aliases": [ + "CVE-2024-9808" + ], + "details": "A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/?page=products/view_product. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9808" + }, + { + "type": "WEB", + "url": "https://github.com/r1ckyL/cve/blob/main/sql.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.279960" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.279960" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.420744" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-10T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m39v-rgw3-qmpc/GHSA-m39v-rgw3-qmpc.json b/advisories/unreviewed/2024/10/GHSA-m39v-rgw3-qmpc/GHSA-m39v-rgw3-qmpc.json new file mode 100644 index 00000000000..fad8e8508f9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m39v-rgw3-qmpc/GHSA-m39v-rgw3-qmpc.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m39v-rgw3-qmpc", + "modified": "2024-10-10T21:30:43Z", + "published": "2024-10-10T21:30:43Z", + "aliases": [ + "CVE-2024-9806" + ], + "details": "A vulnerability has been found in Craig Rodway Classroombookings up to 2.8.6 and classified as problematic. This vulnerability affects unknown code of the file /rooms/fields of the component Room Page. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.8.7 is able to address this issue. It is recommended to upgrade the affected component. The project maintainer was contacted early about the disclosure. He responded very quickly, friendly, and professional.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9806" + }, + { + "type": "WEB", + "url": "https://github.com/JunMing27/CVE/blob/main/CVE%20-%20classroombookings%20Cross%20Site%20Scripting%20(XSS)%20at%20custom%20field.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.279958" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.279958" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.418715" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-10T19:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mfh4-qvwj-c4ff/GHSA-mfh4-qvwj-c4ff.json b/advisories/unreviewed/2024/10/GHSA-mfh4-qvwj-c4ff/GHSA-mfh4-qvwj-c4ff.json new file mode 100644 index 00000000000..989de8eec15 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mfh4-qvwj-c4ff/GHSA-mfh4-qvwj-c4ff.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mfh4-qvwj-c4ff", + "modified": "2024-10-10T21:30:41Z", + "published": "2024-10-10T21:30:41Z", + "aliases": [ + "CVE-2023-25769" + ], + "details": "Uncontrolled resource consumption in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25769" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00851.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-pf8h-79jj-r6cc/GHSA-pf8h-79jj-r6cc.json b/advisories/unreviewed/2024/10/GHSA-pf8h-79jj-r6cc/GHSA-pf8h-79jj-r6cc.json new file mode 100644 index 00000000000..f436efdfb7f --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-pf8h-79jj-r6cc/GHSA-pf8h-79jj-r6cc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf8h-79jj-r6cc", + "modified": "2024-10-10T21:30:41Z", + "published": "2024-10-10T21:30:41Z", + "aliases": [ + "CVE-2023-22390" + ], + "details": "Improper buffer restrictions in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22390" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00851.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-phj7-phjc-r9wg/GHSA-phj7-phjc-r9wg.json b/advisories/unreviewed/2024/10/GHSA-phj7-phjc-r9wg/GHSA-phj7-phjc-r9wg.json new file mode 100644 index 00000000000..7db9bb8e9e1 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-phj7-phjc-r9wg/GHSA-phj7-phjc-r9wg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phj7-phjc-r9wg", + "modified": "2024-10-10T21:30:43Z", + "published": "2024-10-10T21:30:42Z", + "aliases": [ + "CVE-2024-47648" + ], + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in EventPrime Events EventPrime.This issue affects EventPrime: from n/a through 4.0.4.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47648" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/eventprime-event-calendar-management/wordpress-eventprime-plugin-4-0-4-5-open-redirection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-10T19:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-q6g9-h87p-p9fw/GHSA-q6g9-h87p-p9fw.json b/advisories/unreviewed/2024/10/GHSA-q6g9-h87p-p9fw/GHSA-q6g9-h87p-p9fw.json new file mode 100644 index 00000000000..44935539b4d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-q6g9-h87p-p9fw/GHSA-q6g9-h87p-p9fw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6g9-h87p-p9fw", + "modified": "2024-10-10T21:30:42Z", + "published": "2024-10-10T21:30:41Z", + "aliases": [ + "CVE-2023-26596" + ], + "details": "Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26596" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00851.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qfh6-hjfc-cx2m/GHSA-qfh6-hjfc-cx2m.json b/advisories/unreviewed/2024/10/GHSA-qfh6-hjfc-cx2m/GHSA-qfh6-hjfc-cx2m.json new file mode 100644 index 00000000000..bf696ebc241 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qfh6-hjfc-cx2m/GHSA-qfh6-hjfc-cx2m.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfh6-hjfc-cx2m", + "modified": "2024-10-10T21:30:43Z", + "published": "2024-10-10T21:30:43Z", + "aliases": [ + "CVE-2024-9812" + ], + "details": "A vulnerability classified as critical was found in code-projects Crud Operation System 1.0. This vulnerability affects unknown code of the file delete.php. The manipulation of the argument sid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9812" + }, + { + "type": "WEB", + "url": "https://github.com/ppp-src/a/issues/25" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.279964" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.279964" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.418729" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-10T21:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qx68-647q-334v/GHSA-qx68-647q-334v.json b/advisories/unreviewed/2024/10/GHSA-qx68-647q-334v/GHSA-qx68-647q-334v.json new file mode 100644 index 00000000000..12d6cf1135d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qx68-647q-334v/GHSA-qx68-647q-334v.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qx68-647q-334v", + "modified": "2024-10-10T21:30:43Z", + "published": "2024-10-10T21:30:43Z", + "aliases": [ + "CVE-2024-9809" + ], + "details": "A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as critical. Affected by this vulnerability is the function delete_product of the file /classes/Master.php?f=delete_product. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9809" + }, + { + "type": "WEB", + "url": "https://github.com/wuyanzu-lab/cve/blob/main/sql.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.279961" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.279961" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.420745" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-10T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-rr8j-7w34-xp5j/GHSA-rr8j-7w34-xp5j.json b/advisories/unreviewed/2024/10/GHSA-rr8j-7w34-xp5j/GHSA-rr8j-7w34-xp5j.json new file mode 100644 index 00000000000..1fec6331c94 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rr8j-7w34-xp5j/GHSA-rr8j-7w34-xp5j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rr8j-7w34-xp5j", + "modified": "2024-10-10T21:30:43Z", + "published": "2024-10-10T21:30:43Z", + "aliases": [ + "CVE-2024-9180" + ], + "details": "A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their privileges to Vault’s root policy. Fixed in Vault Community Edition 1.18.0 and Vault Enterprise 1.18.0, 1.17.7, 1.16.11, and 1.15.16.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9180" + }, + { + "type": "WEB", + "url": "https://discuss.hashicorp.com/t/hcsec-2024-21-vault-operators-in-root-namespace-may-elevate-their-privileges/70565" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-10T21:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-rx73-mj92-mhc9/GHSA-rx73-mj92-mhc9.json b/advisories/unreviewed/2024/10/GHSA-rx73-mj92-mhc9/GHSA-rx73-mj92-mhc9.json new file mode 100644 index 00000000000..cedd49d4704 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rx73-mj92-mhc9/GHSA-rx73-mj92-mhc9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rx73-mj92-mhc9", + "modified": "2024-10-10T21:30:41Z", + "published": "2024-10-10T21:30:41Z", + "aliases": [ + "CVE-2023-24481" + ], + "details": "Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24481" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00851.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-v8c3-f895-g4r9/GHSA-v8c3-f895-g4r9.json b/advisories/unreviewed/2024/10/GHSA-v8c3-f895-g4r9/GHSA-v8c3-f895-g4r9.json new file mode 100644 index 00000000000..43b18edb972 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-v8c3-f895-g4r9/GHSA-v8c3-f895-g4r9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8c3-f895-g4r9", + "modified": "2024-10-10T21:30:42Z", + "published": "2024-10-10T21:30:42Z", + "aliases": [ + "CVE-2023-27307" + ], + "details": "Improper buffer restrictions in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27307" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00851.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-vqqv-5pgx-px9w/GHSA-vqqv-5pgx-px9w.json b/advisories/unreviewed/2024/10/GHSA-vqqv-5pgx-px9w/GHSA-vqqv-5pgx-px9w.json new file mode 100644 index 00000000000..d3868ec824a --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-vqqv-5pgx-px9w/GHSA-vqqv-5pgx-px9w.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vqqv-5pgx-px9w", + "modified": "2024-10-10T21:30:43Z", + "published": "2024-10-10T21:30:43Z", + "aliases": [ + "CVE-2024-9813" + ], + "details": "A vulnerability, which was classified as critical, has been found in Codezips Pharmacy Management System 1.0. This issue affects some unknown processing of the file product/register.php. The manipulation of the argument category leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9813" + }, + { + "type": "WEB", + "url": "https://github.com/ppp-src/CVE/issues/10" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.279965" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.279965" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.418904" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-10T21:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-x5wp-rg6r-3pmj/GHSA-x5wp-rg6r-3pmj.json b/advisories/unreviewed/2024/10/GHSA-x5wp-rg6r-3pmj/GHSA-x5wp-rg6r-3pmj.json new file mode 100644 index 00000000000..519d268048e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-x5wp-rg6r-3pmj/GHSA-x5wp-rg6r-3pmj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x5wp-rg6r-3pmj", + "modified": "2024-10-10T21:30:43Z", + "published": "2024-10-10T21:30:42Z", + "aliases": [ + "CVE-2024-47354" + ], + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in smp7, wp.Insider Simple Membership After Login Redirection.This issue affects Simple Membership After Login Redirection: from n/a through 1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47354" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/simple-membership-after-login-redirection/wordpress-simple-membership-after-login-redirection-plugin-1-6-open-redirection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-10T19:15:16Z" + } +} \ No newline at end of file