Publish Advisories

GHSA-2254-9c75-9fpv
GHSA-78jh-rw4h-46r3
GHSA-7xww-xh6h-rqhj
GHSA-94q6-333x-cv3g
GHSA-9qf5-3c29-69qj
GHSA-c8pj-3w86-3gqp
GHSA-q3rr-xqpw-vv2x
GHSA-v58q-q96x-jmrj
GHSA-v8rx-gg8c-mc3c
GHSA-3m9j-v59x-pvvm
GHSA-6cx5-pwpx-7g84
GHSA-9p5w-7f45-v3jm
GHSA-fhx3-jwgv-mpc2
GHSA-gmc7-25r9-p22h
GHSA-hwvw-gh23-qpvq
GHSA-vhhq-fxg5-hvp8
GHSA-w7r3-xv3m-6g2f
GHSA-wq73-4j39-6948
This commit is contained in:
advisory-database[bot]
2024-04-02 15:31:57 +00:00
parent 86e66678f8
commit 08fb05fd2a
18 changed files with 349 additions and 11 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2254-9c75-9fpv",
"modified": "2023-05-24T21:30:18Z",
"modified": "2024-04-02T15:30:36Z",
"published": "2023-05-15T15:30:23Z",
"aliases": [
"CVE-2023-32787"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-400"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-05-15T15:15:12Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-78jh-rw4h-46r3",
"modified": "2024-02-20T18:30:34Z",
"modified": "2024-04-02T15:30:36Z",
"published": "2024-02-20T18:30:34Z",
"aliases": [
"CVE-2024-23310"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23310"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OIRLGNQM33KAWVWP5RPMAPHWNP3IY5YW"
},
{
"type": "WEB",
"url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1923"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7xww-xh6h-rqhj",
"modified": "2024-02-20T18:30:34Z",
"modified": "2024-04-02T15:30:36Z",
"published": "2024-02-20T18:30:34Z",
"aliases": [
"CVE-2024-21795"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21795"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OIRLGNQM33KAWVWP5RPMAPHWNP3IY5YW"
},
{
"type": "WEB",
"url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1920"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-94q6-333x-cv3g",
"modified": "2024-02-20T18:30:34Z",
"modified": "2024-04-02T15:30:36Z",
"published": "2024-02-20T18:30:34Z",
"aliases": [
"CVE-2024-23305"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23305"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OIRLGNQM33KAWVWP5RPMAPHWNP3IY5YW"
},
{
"type": "WEB",
"url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1918"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9qf5-3c29-69qj",
"modified": "2024-02-20T18:30:34Z",
"modified": "2024-04-02T15:30:36Z",
"published": "2024-02-20T18:30:34Z",
"aliases": [
"CVE-2024-22097"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22097"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OIRLGNQM33KAWVWP5RPMAPHWNP3IY5YW"
},
{
"type": "WEB",
"url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1917"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c8pj-3w86-3gqp",
"modified": "2024-02-20T18:30:34Z",
"modified": "2024-04-02T15:30:36Z",
"published": "2024-02-20T18:30:34Z",
"aliases": [
"CVE-2024-23606"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23606"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OIRLGNQM33KAWVWP5RPMAPHWNP3IY5YW"
},
{
"type": "WEB",
"url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1925"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q3rr-xqpw-vv2x",
"modified": "2024-02-20T18:30:34Z",
"modified": "2024-04-02T15:30:36Z",
"published": "2024-02-20T18:30:34Z",
"aliases": [
"CVE-2024-23313"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23313"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OIRLGNQM33KAWVWP5RPMAPHWNP3IY5YW"
},
{
"type": "WEB",
"url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1922"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v58q-q96x-jmrj",
"modified": "2024-02-20T18:30:34Z",
"modified": "2024-04-02T15:30:36Z",
"published": "2024-02-20T18:30:34Z",
"aliases": [
"CVE-2024-21812"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21812"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OIRLGNQM33KAWVWP5RPMAPHWNP3IY5YW"
},
{
"type": "WEB",
"url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1921"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v8rx-gg8c-mc3c",
"modified": "2024-02-20T18:30:34Z",
"modified": "2024-04-02T15:30:36Z",
"published": "2024-02-20T18:30:34Z",
"aliases": [
"CVE-2024-23809"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23809"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OIRLGNQM33KAWVWP5RPMAPHWNP3IY5YW"
},
{
"type": "WEB",
"url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1919"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3m9j-v59x-pvvm",
"modified": "2024-04-02T15:30:37Z",
"published": "2024-04-02T15:30:37Z",
"aliases": [
"CVE-2024-29514"
],
"details": "File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29514"
},
{
"type": "WEB",
"url": "https://github.com/zzq66/cve6"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-02T13:15:51Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6cx5-pwpx-7g84",
"modified": "2024-04-02T15:30:37Z",
"published": "2024-04-02T15:30:37Z",
"aliases": [
"CVE-2024-30946"
],
"details": "DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/co_do.php.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30946"
},
{
"type": "WEB",
"url": "https://github.com/testgo1safe/cms/blob/main/1.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-02T13:15:51Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9p5w-7f45-v3jm",
"modified": "2024-04-02T15:30:37Z",
"published": "2024-04-02T15:30:37Z",
"aliases": [
"CVE-2024-2389"
],
"details": "In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified.  An unauthenticated user can gain entry to the system via the Flowmon management interface, allowing for the execution of arbitrary system commands.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2389"
},
{
"type": "WEB",
"url": "https://support.kemptechnologies.com/hc/en-us/articles/24878235038733-CVE-2024-2389-Flowmon-critical-security-vulnerability"
},
{
"type": "WEB",
"url": "https://www.flowmon.com"
}
],
"database_specific": {
"cwe_ids": [
"CWE-78"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-02T13:15:51Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fhx3-jwgv-mpc2",
"modified": "2024-04-02T15:30:37Z",
"published": "2024-04-02T15:30:37Z",
"aliases": [
"CVE-2024-30621"
],
"details": "Tenda AX1803 v1.0.0.1 contains a stack overflow via the serverName parameter in the function fromAdvSetMacMtuWan.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30621"
},
{
"type": "WEB",
"url": "https://github.com/re1wn/IoT_vuln/blob/main/Tenda_AX1803_v1.0.0.1_contains_a_stack_overflow_via_the_serverName_parameter_in_the_function_fromAdvSetMacMtuWan.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-02T14:15:08Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gmc7-25r9-p22h",
"modified": "2024-04-02T15:30:37Z",
"published": "2024-04-02T15:30:37Z",
"aliases": [
"CVE-2024-30620"
],
"details": "Tenda AX1803 v1.0.0.1 contains a stack overflow via the serviceName parameter in the function fromAdvSetMacMtuWan.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30620"
},
{
"type": "WEB",
"url": "https://github.com/re1wn/IoT_vuln/blob/main/Tenda_AX1803_v1.0.0.1_contains_a_stack_overflow_via_the_serviceName_parameter_in_the_function_fromAdvSetMacMtuWan.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-02T14:15:08Z"
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hwvw-gh23-qpvq",
"modified": "2024-04-02T15:30:37Z",
"published": "2024-04-02T15:30:37Z",
"aliases": [
"CVE-2024-22780"
],
"details": "Cross Site Scripting vulnerability in CA17 TeamsACS v.1.0.1 allows a remote attacker to execute arbitrary code via a crafted script to the errmsg parameter.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22780"
},
{
"type": "WEB",
"url": "https://fuo.fi/CVE-2024-22780"
},
{
"type": "WEB",
"url": "https://github.com/CA17/TeamsACS"
},
{
"type": "WEB",
"url": "http://ca17.com"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-02T15:15:52Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vhhq-fxg5-hvp8",
"modified": "2024-04-02T00:30:47Z",
"modified": "2024-04-02T15:30:36Z",
"published": "2024-04-02T00:30:46Z",
"aliases": [
"CVE-2024-3164"
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w7r3-xv3m-6g2f",
"modified": "2024-04-02T15:30:37Z",
"published": "2024-04-02T15:30:37Z",
"aliases": [
"CVE-2023-50313"
],
"details": "IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for outbound TLS connections caused by a failure to honor user configuration. IBM X-Force ID: 274812.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50313"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/274812"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7145620"
}
],
"database_specific": {
"cwe_ids": [
"CWE-327"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-02T13:15:51Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wq73-4j39-6948",
"modified": "2024-04-02T15:30:37Z",
"published": "2024-04-02T15:30:37Z",
"aliases": [
"CVE-2024-30965"
],
"details": "DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/member_scores.php.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30965"
},
{
"type": "WEB",
"url": "https://github.com/Fishkey1/cms/commit/e9d294951ab2dd85709f1d12ad4747f25d326b1b"
},
{
"type": "WEB",
"url": "https://github.com/Fishkey1/cms/tree/main"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-02T14:15:08Z"
}
}