From 093f1f6382333a5669328e22d1e6973e287e477f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 17 Jul 2024 18:32:23 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-78hx-gp6g-7mj6.json | 16 ++-- .../GHSA-2rhx-qhxp-5jpw.json | 6 +- .../GHSA-j8cm-g7r6-hfpq.json | 73 +++++++++++++++++++ .../GHSA-xmxg-28xr-rp8x.json | 2 +- .../GHSA-45q4-h8rr-hgx2.json | 6 +- .../GHSA-4gxj-5mmr-7pxq.json | 6 +- .../GHSA-gpgj-xrgw-8mx2.json | 6 +- .../GHSA-jf28-v5f6-cvpr.json | 6 +- .../GHSA-7w3v-fgq3-jwhp.json | 11 ++- .../GHSA-ch3r-hjxg-j657.json | 11 ++- .../GHSA-mh75-cw6c-vrcq.json | 9 ++- .../GHSA-rvq4-9f28-mrwc.json | 11 ++- .../GHSA-xr65-8g34-2hcm.json | 11 ++- .../GHSA-28jg-69qr-j99g.json | 38 ++++++++++ .../GHSA-2whg-fx75-q3fr.json | 42 +++++++++++ .../GHSA-4rcj-fmjg-q9fv.json | 38 ++++++++++ .../GHSA-5697-p67m-73p6.json | 38 ++++++++++ .../GHSA-57c8-7jwm-wc5w.json | 38 ++++++++++ .../GHSA-67ww-939x-f5pp.json | 38 ++++++++++ .../GHSA-748p-59x5-mx7f.json | 54 ++++++++++++++ .../GHSA-7r42-ppxw-235f.json | 38 ++++++++++ .../GHSA-82vj-crx8-gvp9.json | 38 ++++++++++ .../GHSA-9h6c-2f95-gmf7.json | 38 ++++++++++ .../GHSA-c6hx-833p-hm7m.json | 38 ++++++++++ .../GHSA-cv3h-4jh6-rh6p.json | 38 ++++++++++ .../GHSA-hcf8-5j78-887v.json | 6 +- .../GHSA-mgj5-j889-643m.json | 38 ++++++++++ .../GHSA-mq58-p8pv-xx7f.json | 35 +++++++++ .../GHSA-p6xf-x5px-f2vq.json | 38 ++++++++++ .../GHSA-pfpx-3hgc-pc2g.json | 42 +++++++++++ .../GHSA-xfp3-mm6f-4fw4.json | 35 +++++++++ 31 files changed, 812 insertions(+), 32 deletions(-) create mode 100644 advisories/github-reviewed/2024/07/GHSA-j8cm-g7r6-hfpq/GHSA-j8cm-g7r6-hfpq.json create mode 100644 advisories/unreviewed/2024/07/GHSA-28jg-69qr-j99g/GHSA-28jg-69qr-j99g.json create mode 100644 advisories/unreviewed/2024/07/GHSA-2whg-fx75-q3fr/GHSA-2whg-fx75-q3fr.json create mode 100644 advisories/unreviewed/2024/07/GHSA-4rcj-fmjg-q9fv/GHSA-4rcj-fmjg-q9fv.json create mode 100644 advisories/unreviewed/2024/07/GHSA-5697-p67m-73p6/GHSA-5697-p67m-73p6.json create mode 100644 advisories/unreviewed/2024/07/GHSA-57c8-7jwm-wc5w/GHSA-57c8-7jwm-wc5w.json create mode 100644 advisories/unreviewed/2024/07/GHSA-67ww-939x-f5pp/GHSA-67ww-939x-f5pp.json create mode 100644 advisories/unreviewed/2024/07/GHSA-748p-59x5-mx7f/GHSA-748p-59x5-mx7f.json create mode 100644 advisories/unreviewed/2024/07/GHSA-7r42-ppxw-235f/GHSA-7r42-ppxw-235f.json create mode 100644 advisories/unreviewed/2024/07/GHSA-82vj-crx8-gvp9/GHSA-82vj-crx8-gvp9.json create mode 100644 advisories/unreviewed/2024/07/GHSA-9h6c-2f95-gmf7/GHSA-9h6c-2f95-gmf7.json create mode 100644 advisories/unreviewed/2024/07/GHSA-c6hx-833p-hm7m/GHSA-c6hx-833p-hm7m.json create mode 100644 advisories/unreviewed/2024/07/GHSA-cv3h-4jh6-rh6p/GHSA-cv3h-4jh6-rh6p.json create mode 100644 advisories/unreviewed/2024/07/GHSA-mgj5-j889-643m/GHSA-mgj5-j889-643m.json create mode 100644 advisories/unreviewed/2024/07/GHSA-mq58-p8pv-xx7f/GHSA-mq58-p8pv-xx7f.json create mode 100644 advisories/unreviewed/2024/07/GHSA-p6xf-x5px-f2vq/GHSA-p6xf-x5px-f2vq.json create mode 100644 advisories/unreviewed/2024/07/GHSA-pfpx-3hgc-pc2g/GHSA-pfpx-3hgc-pc2g.json create mode 100644 advisories/unreviewed/2024/07/GHSA-xfp3-mm6f-4fw4/GHSA-xfp3-mm6f-4fw4.json diff --git a/advisories/github-reviewed/2024/03/GHSA-78hx-gp6g-7mj6/GHSA-78hx-gp6g-7mj6.json b/advisories/github-reviewed/2024/03/GHSA-78hx-gp6g-7mj6/GHSA-78hx-gp6g-7mj6.json index 1127a62c995..456d6762df3 100644 --- a/advisories/github-reviewed/2024/03/GHSA-78hx-gp6g-7mj6/GHSA-78hx-gp6g-7mj6.json +++ b/advisories/github-reviewed/2024/03/GHSA-78hx-gp6g-7mj6/GHSA-78hx-gp6g-7mj6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-78hx-gp6g-7mj6", - "modified": "2024-07-17T00:32:52Z", + "modified": "2024-07-17T18:31:00Z", "published": "2024-03-20T18:10:36Z", "aliases": [ "CVE-2024-1394" @@ -136,7 +136,7 @@ }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:2767" + "url": "https://access.redhat.com/errata/RHSA-2024:1462" }, { "type": "WEB", @@ -170,6 +170,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:4581" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4591" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-1394" @@ -198,10 +202,6 @@ "type": "WEB", "url": "https://vuln.go.dev/ID/GO-2024-2660.json" }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:1462" - }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:1468" @@ -277,6 +277,10 @@ { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:2730" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:2767" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/05/GHSA-2rhx-qhxp-5jpw/GHSA-2rhx-qhxp-5jpw.json b/advisories/github-reviewed/2024/05/GHSA-2rhx-qhxp-5jpw/GHSA-2rhx-qhxp-5jpw.json index 82a814d22f1..93cc7ed0227 100644 --- a/advisories/github-reviewed/2024/05/GHSA-2rhx-qhxp-5jpw/GHSA-2rhx-qhxp-5jpw.json +++ b/advisories/github-reviewed/2024/05/GHSA-2rhx-qhxp-5jpw/GHSA-2rhx-qhxp-5jpw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2rhx-qhxp-5jpw", - "modified": "2024-05-20T15:30:03Z", + "modified": "2024-07-17T18:31:00Z", "published": "2024-05-17T15:31:10Z", "aliases": [ "CVE-2024-5042" @@ -71,6 +71,10 @@ "type": "WEB", "url": "https://github.com/submariner-io/submariner-operator/commit/b27a04c4270e53cbff6ff8ac6245db10c204bcab" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4591" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-5042" diff --git a/advisories/github-reviewed/2024/07/GHSA-j8cm-g7r6-hfpq/GHSA-j8cm-g7r6-hfpq.json b/advisories/github-reviewed/2024/07/GHSA-j8cm-g7r6-hfpq/GHSA-j8cm-g7r6-hfpq.json new file mode 100644 index 00000000000..092570bb3d6 --- /dev/null +++ b/advisories/github-reviewed/2024/07/GHSA-j8cm-g7r6-hfpq/GHSA-j8cm-g7r6-hfpq.json @@ -0,0 +1,73 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8cm-g7r6-hfpq", + "modified": "2024-07-17T18:30:55Z", + "published": "2024-07-17T18:30:55Z", + "aliases": [ + "CVE-2024-40640" + ], + "summary": "vodozemac's usage of non-constant time base64 decoder could lead to leakage of secret key material", + "details": "Versions before 0.7.0 of vodozemac use a non-constant time base64 implementation for importing key material for Megolm group sessions and `PkDecryption` Ed25519 secret keys. This flaw might allow an attacker to infer some information about the secret key material through a side-channel attack.\n\n### Impact\n\nThe use of a non-constant time base64 implementation might allow an attacker to observe timing variations in the encoding and decoding operations of the secret key material. This could potentially provide insights into the underlying secret key material.\n\nThe impact of this vulnerability is considered low because exploiting the attacker is required to have access to high precision timing measurements, as well as repeated access to the base64 encoding or decoding processes. Additionally, the estimated leakage amount is bounded and low according to the referenced paper.\n\n### Patches\n\nThe patch is in commit 734b6c6948d4b2bdee3dd8b4efa591d93a61d272.\n\n### Workarounds\nNone.\n\n### References\nA detailed description of the precise attack can be found at https://arxiv.org/abs/2108.04600. We kindly thank Soatok for pointing out this research to us.\n\n### For more information\nIf you have any questions or comments about this advisory please email us at [security at matrix.org](mailto:security@matrix.org).\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "crates.io", + "name": "vodozemac" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.7.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/matrix-org/vodozemac/security/advisories/GHSA-j8cm-g7r6-hfpq" + }, + { + "type": "WEB", + "url": "https://github.com/matrix-org/vodozemac/commit/734b6c6948d4b2bdee3dd8b4efa591d93a61d272" + }, + { + "type": "WEB", + "url": "https://github.com/matrix-org/vodozemac/commit/77765dace11266ef9523301624a01265c6e0f790" + }, + { + "type": "WEB", + "url": "https://arxiv.org/abs/2108.04600" + }, + { + "type": "PACKAGE", + "url": "https://github.com/matrix-org/vodozemac" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-208" + ], + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2024-07-17T18:30:55Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-xmxg-28xr-rp8x/GHSA-xmxg-28xr-rp8x.json b/advisories/unreviewed/2022/05/GHSA-xmxg-28xr-rp8x/GHSA-xmxg-28xr-rp8x.json index 7b845679c18..4be4aa6e05e 100644 --- a/advisories/unreviewed/2022/05/GHSA-xmxg-28xr-rp8x/GHSA-xmxg-28xr-rp8x.json +++ b/advisories/unreviewed/2022/05/GHSA-xmxg-28xr-rp8x/GHSA-xmxg-28xr-rp8x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xmxg-28xr-rp8x", - "modified": "2022-05-14T03:05:20Z", + "modified": "2024-07-17T18:30:59Z", "published": "2022-05-14T03:05:20Z", "aliases": [ "CVE-2017-16531" diff --git a/advisories/unreviewed/2024/05/GHSA-45q4-h8rr-hgx2/GHSA-45q4-h8rr-hgx2.json b/advisories/unreviewed/2024/05/GHSA-45q4-h8rr-hgx2/GHSA-45q4-h8rr-hgx2.json index b049f391aea..25e78dc9c41 100644 --- a/advisories/unreviewed/2024/05/GHSA-45q4-h8rr-hgx2/GHSA-45q4-h8rr-hgx2.json +++ b/advisories/unreviewed/2024/05/GHSA-45q4-h8rr-hgx2/GHSA-45q4-h8rr-hgx2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-45q4-h8rr-hgx2", - "modified": "2024-07-03T18:43:03Z", + "modified": "2024-07-17T18:31:00Z", "published": "2024-05-21T21:30:27Z", "aliases": [ "CVE-2024-35060" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35060" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-45q4-h8rr-hgx2" + }, { "type": "WEB", "url": "https://www.linkedin.com/pulse/remote-code-execution-via-man-in-the-middle-more-ujkze" diff --git a/advisories/unreviewed/2024/05/GHSA-4gxj-5mmr-7pxq/GHSA-4gxj-5mmr-7pxq.json b/advisories/unreviewed/2024/05/GHSA-4gxj-5mmr-7pxq/GHSA-4gxj-5mmr-7pxq.json index 304eda89fa2..28e06050aca 100644 --- a/advisories/unreviewed/2024/05/GHSA-4gxj-5mmr-7pxq/GHSA-4gxj-5mmr-7pxq.json +++ b/advisories/unreviewed/2024/05/GHSA-4gxj-5mmr-7pxq/GHSA-4gxj-5mmr-7pxq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4gxj-5mmr-7pxq", - "modified": "2024-07-03T18:43:00Z", + "modified": "2024-07-17T18:31:00Z", "published": "2024-05-21T18:31:24Z", "aliases": [ "CVE-2024-35058" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35058" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-4gxj-5mmr-7pxq" + }, { "type": "WEB", "url": "https://www.linkedin.com/pulse/remote-code-execution-via-man-in-the-middle-more-ujkze" diff --git a/advisories/unreviewed/2024/05/GHSA-gpgj-xrgw-8mx2/GHSA-gpgj-xrgw-8mx2.json b/advisories/unreviewed/2024/05/GHSA-gpgj-xrgw-8mx2/GHSA-gpgj-xrgw-8mx2.json index 2e04fbc6ec3..aebc17b7d20 100644 --- a/advisories/unreviewed/2024/05/GHSA-gpgj-xrgw-8mx2/GHSA-gpgj-xrgw-8mx2.json +++ b/advisories/unreviewed/2024/05/GHSA-gpgj-xrgw-8mx2/GHSA-gpgj-xrgw-8mx2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gpgj-xrgw-8mx2", - "modified": "2024-05-21T18:31:24Z", + "modified": "2024-07-17T18:30:59Z", "published": "2024-05-21T18:31:24Z", "aliases": [ "CVE-2024-35056" @@ -18,6 +18,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35056" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-gpgj-xrgw-8mx2" + }, { "type": "WEB", "url": "https://www.linkedin.com/pulse/remote-code-execution-via-man-in-the-middle-more-ujkze" diff --git a/advisories/unreviewed/2024/05/GHSA-jf28-v5f6-cvpr/GHSA-jf28-v5f6-cvpr.json b/advisories/unreviewed/2024/05/GHSA-jf28-v5f6-cvpr/GHSA-jf28-v5f6-cvpr.json index 470dc03d9cc..cd92bc7177c 100644 --- a/advisories/unreviewed/2024/05/GHSA-jf28-v5f6-cvpr/GHSA-jf28-v5f6-cvpr.json +++ b/advisories/unreviewed/2024/05/GHSA-jf28-v5f6-cvpr/GHSA-jf28-v5f6-cvpr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jf28-v5f6-cvpr", - "modified": "2024-07-03T18:42:59Z", + "modified": "2024-07-17T18:30:59Z", "published": "2024-05-21T18:31:24Z", "aliases": [ "CVE-2024-35057" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35057" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-jf28-v5f6-cvpr" + }, { "type": "WEB", "url": "https://www.linkedin.com/pulse/remote-code-execution-via-man-in-the-middle-more-ujkze" diff --git a/advisories/unreviewed/2024/06/GHSA-7w3v-fgq3-jwhp/GHSA-7w3v-fgq3-jwhp.json b/advisories/unreviewed/2024/06/GHSA-7w3v-fgq3-jwhp/GHSA-7w3v-fgq3-jwhp.json index 451b5ad6014..abd5cade35c 100644 --- a/advisories/unreviewed/2024/06/GHSA-7w3v-fgq3-jwhp/GHSA-7w3v-fgq3-jwhp.json +++ b/advisories/unreviewed/2024/06/GHSA-7w3v-fgq3-jwhp/GHSA-7w3v-fgq3-jwhp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7w3v-fgq3-jwhp", - "modified": "2024-06-12T12:30:40Z", + "modified": "2024-07-17T18:31:00Z", "published": "2024-06-08T15:31:18Z", "aliases": [ "CVE-2024-36968" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix div-by-zero in l2cap_le_flowctl_init()\n\nl2cap_le_flowctl_init() can cause both div-by-zero and an integer\noverflow since hdev->le_mtu may not fall in the valid range.\n\nMove MTU from hci_dev to hci_conn to validate MTU and stop the connection\nprocess earlier if MTU is invalid.\nAlso, add a missing validation in read_buffer_size() and make it return\nan error value if the validation fails.\nNow hci_conn_add() returns ERR_PTR() as it can fail due to the both a\nkzalloc failure and invalid MTU value.\n\ndivide error: 0000 [#1] PREEMPT SMP KASAN NOPTI\nCPU: 0 PID: 67 Comm: kworker/u5:0 Tainted: G W 6.9.0-rc5+ #20\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\nWorkqueue: hci0 hci_rx_work\nRIP: 0010:l2cap_le_flowctl_init+0x19e/0x3f0 net/bluetooth/l2cap_core.c:547\nCode: e8 17 17 0c 00 66 41 89 9f 84 00 00 00 bf 01 00 00 00 41 b8 02 00 00 00 4c\n89 fe 4c 89 e2 89 d9 e8 27 17 0c 00 44 89 f0 31 d2 <66> f7 f3 89 c3 ff c3 4d 8d\nb7 88 00 00 00 4c 89 f0 48 c1 e8 03 42\nRSP: 0018:ffff88810bc0f858 EFLAGS: 00010246\nRAX: 00000000000002a0 RBX: 0000000000000000 RCX: dffffc0000000000\nRDX: 0000000000000000 RSI: ffff88810bc0f7c0 RDI: ffffc90002dcb66f\nRBP: ffff88810bc0f880 R08: aa69db2dda70ff01 R09: 0000ffaaaaaaaaaa\nR10: 0084000000ffaaaa R11: 0000000000000000 R12: ffff88810d65a084\nR13: dffffc0000000000 R14: 00000000000002a0 R15: ffff88810d65a000\nFS: 0000000000000000(0000) GS:ffff88811ac00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000020000100 CR3: 0000000103268003 CR4: 0000000000770ef0\nPKRU: 55555554\nCall Trace:\n \n l2cap_le_connect_req net/bluetooth/l2cap_core.c:4902 [inline]\n l2cap_le_sig_cmd net/bluetooth/l2cap_core.c:5420 [inline]\n l2cap_le_sig_channel net/bluetooth/l2cap_core.c:5486 [inline]\n l2cap_recv_frame+0xe59d/0x11710 net/bluetooth/l2cap_core.c:6809\n l2cap_recv_acldata+0x544/0x10a0 net/bluetooth/l2cap_core.c:7506\n hci_acldata_packet net/bluetooth/hci_core.c:3939 [inline]\n hci_rx_work+0x5e5/0xb20 net/bluetooth/hci_core.c:4176\n process_one_work kernel/workqueue.c:3254 [inline]\n process_scheduled_works+0x90f/0x1530 kernel/workqueue.c:3335\n worker_thread+0x926/0xe70 kernel/workqueue.c:3416\n kthread+0x2e3/0x380 kernel/kthread.c:388\n ret_from_fork+0x5c/0x90 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n \nModules linked in:\n---[ end trace 0000000000000000 ]---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-08T13:15:58Z" diff --git a/advisories/unreviewed/2024/06/GHSA-ch3r-hjxg-j657/GHSA-ch3r-hjxg-j657.json b/advisories/unreviewed/2024/06/GHSA-ch3r-hjxg-j657/GHSA-ch3r-hjxg-j657.json index 17224f6d55b..a44b2fabf24 100644 --- a/advisories/unreviewed/2024/06/GHSA-ch3r-hjxg-j657/GHSA-ch3r-hjxg-j657.json +++ b/advisories/unreviewed/2024/06/GHSA-ch3r-hjxg-j657/GHSA-ch3r-hjxg-j657.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ch3r-hjxg-j657", - "modified": "2024-06-08T15:31:18Z", + "modified": "2024-07-17T18:31:00Z", "published": "2024-06-08T15:31:18Z", "aliases": [ "CVE-2024-36969" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix division by zero in setup_dsc_config\n\nWhen slice_height is 0, the division by slice_height in the calculation\nof the number of slices will cause a division by zero driver crash. This\nleaves the kernel in a state that requires a reboot. This patch adds a\ncheck to avoid the division by zero.\n\nThe stack trace below is for the 6.8.4 Kernel. I reproduced the issue on\na Z16 Gen 2 Lenovo Thinkpad with a Apple Studio Display monitor\nconnected via Thunderbolt. The amdgpu driver crashed with this exception\nwhen I rebooted the system with the monitor connected.\n\nkernel: ? die (arch/x86/kernel/dumpstack.c:421 arch/x86/kernel/dumpstack.c:434 arch/x86/kernel/dumpstack.c:447)\nkernel: ? do_trap (arch/x86/kernel/traps.c:113 arch/x86/kernel/traps.c:154)\nkernel: ? setup_dsc_config (drivers/gpu/drm/amd/amdgpu/../display/dc/dsc/dc_dsc.c:1053) amdgpu\nkernel: ? do_error_trap (./arch/x86/include/asm/traps.h:58 arch/x86/kernel/traps.c:175)\nkernel: ? setup_dsc_config (drivers/gpu/drm/amd/amdgpu/../display/dc/dsc/dc_dsc.c:1053) amdgpu\nkernel: ? exc_divide_error (arch/x86/kernel/traps.c:194 (discriminator 2))\nkernel: ? setup_dsc_config (drivers/gpu/drm/amd/amdgpu/../display/dc/dsc/dc_dsc.c:1053) amdgpu\nkernel: ? asm_exc_divide_error (./arch/x86/include/asm/idtentry.h:548)\nkernel: ? setup_dsc_config (drivers/gpu/drm/amd/amdgpu/../display/dc/dsc/dc_dsc.c:1053) amdgpu\nkernel: dc_dsc_compute_config (drivers/gpu/drm/amd/amdgpu/../display/dc/dsc/dc_dsc.c:1109) amdgpu\n\nAfter applying this patch, the driver no longer crashes when the monitor\nis connected and the system is rebooted. I believe this is the same\nissue reported for 3113.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-369" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-08T13:15:58Z" diff --git a/advisories/unreviewed/2024/06/GHSA-mh75-cw6c-vrcq/GHSA-mh75-cw6c-vrcq.json b/advisories/unreviewed/2024/06/GHSA-mh75-cw6c-vrcq/GHSA-mh75-cw6c-vrcq.json index b59507ac762..32d583162da 100644 --- a/advisories/unreviewed/2024/06/GHSA-mh75-cw6c-vrcq/GHSA-mh75-cw6c-vrcq.json +++ b/advisories/unreviewed/2024/06/GHSA-mh75-cw6c-vrcq/GHSA-mh75-cw6c-vrcq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mh75-cw6c-vrcq", - "modified": "2024-06-08T15:31:18Z", + "modified": "2024-07-17T18:31:00Z", "published": "2024-06-08T15:31:18Z", "aliases": [ "CVE-2024-36965" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nremoteproc: mediatek: Make sure IPI buffer fits in L2TCM\n\nThe IPI buffer location is read from the firmware that we load to the\nSystem Companion Processor, and it's not granted that both the SRAM\n(L2TCM) size that is defined in the devicetree node is large enough\nfor that, and while this is especially true for multi-core SCP, it's\nstill useful to check on single-core variants as well.\n\nFailing to perform this check may make this driver perform R/W\noperations out of the L2TCM boundary, resulting (at best) in a\nkernel panic.\n\nTo fix that, check that the IPI buffer fits, otherwise return a\nfailure and refuse to boot the relevant SCP core (or the SCP at\nall, if this is single core).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-08T13:15:57Z" diff --git a/advisories/unreviewed/2024/06/GHSA-rvq4-9f28-mrwc/GHSA-rvq4-9f28-mrwc.json b/advisories/unreviewed/2024/06/GHSA-rvq4-9f28-mrwc/GHSA-rvq4-9f28-mrwc.json index 7dc427a558e..2a74c7264c4 100644 --- a/advisories/unreviewed/2024/06/GHSA-rvq4-9f28-mrwc/GHSA-rvq4-9f28-mrwc.json +++ b/advisories/unreviewed/2024/06/GHSA-rvq4-9f28-mrwc/GHSA-rvq4-9f28-mrwc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rvq4-9f28-mrwc", - "modified": "2024-06-08T15:31:18Z", + "modified": "2024-07-17T18:31:00Z", "published": "2024-06-08T15:31:18Z", "aliases": [ "CVE-2024-36967" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKEYS: trusted: Fix memory leak in tpm2_key_encode()\n\n'scratch' is never freed. Fix this by calling kfree() in the success, and\nin the error case.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-08T13:15:58Z" diff --git a/advisories/unreviewed/2024/06/GHSA-xr65-8g34-2hcm/GHSA-xr65-8g34-2hcm.json b/advisories/unreviewed/2024/06/GHSA-xr65-8g34-2hcm/GHSA-xr65-8g34-2hcm.json index 9abcba1977f..667fb560b7f 100644 --- a/advisories/unreviewed/2024/06/GHSA-xr65-8g34-2hcm/GHSA-xr65-8g34-2hcm.json +++ b/advisories/unreviewed/2024/06/GHSA-xr65-8g34-2hcm/GHSA-xr65-8g34-2hcm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xr65-8g34-2hcm", - "modified": "2024-06-07T06:30:29Z", + "modified": "2024-07-17T18:31:00Z", "published": "2024-06-07T06:30:29Z", "aliases": [ "CVE-2024-36082" ], "details": "SQL injection vulnerability in Music Store - WordPress eCommerce versions prior to 1.1.14 allows a remote authenticated attacker with an administrative privilege to execute arbitrary SQL commands. Information stored in the database may be obtained or altered by the attacker.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-07T04:15:30Z" diff --git a/advisories/unreviewed/2024/07/GHSA-28jg-69qr-j99g/GHSA-28jg-69qr-j99g.json b/advisories/unreviewed/2024/07/GHSA-28jg-69qr-j99g/GHSA-28jg-69qr-j99g.json new file mode 100644 index 00000000000..0d8a48967e6 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-28jg-69qr-j99g/GHSA-28jg-69qr-j99g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28jg-69qr-j99g", + "modified": "2024-07-17T18:31:00Z", + "published": "2024-07-17T18:31:00Z", + "aliases": [ + "CVE-2024-20395" + ], + "details": "A vulnerability in the media retrieval functionality of Cisco Webex App could allow an unauthenticated, adjacent attacker to gain access to sensitive session information.\n\n This vulnerability is due to insecure transmission of requests to backend services when the app accesses embedded media, such as images. An attacker could exploit this vulnerability by sending a message with embedded media that is stored on a messaging server to a targeted user. If the attacker can observe transmitted traffic in a privileged network position, a successful exploit could allow the attacker to capture session token information from insecurely transmitted requests and possibly reuse the captured session information to take further actions as the targeted user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20395" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-app-ZjNm8X8j" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-523" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-2whg-fx75-q3fr/GHSA-2whg-fx75-q3fr.json b/advisories/unreviewed/2024/07/GHSA-2whg-fx75-q3fr/GHSA-2whg-fx75-q3fr.json new file mode 100644 index 00000000000..83b23568cdc --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-2whg-fx75-q3fr/GHSA-2whg-fx75-q3fr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2whg-fx75-q3fr", + "modified": "2024-07-17T18:31:01Z", + "published": "2024-07-17T18:31:01Z", + "aliases": [ + "CVE-2023-42010" + ], + "details": "IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 could disclose sensitive information in the HTTP response using man in the middle techniques. IBM X-Force ID: 265507.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42010" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/265507" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7160433" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T18:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-4rcj-fmjg-q9fv/GHSA-4rcj-fmjg-q9fv.json b/advisories/unreviewed/2024/07/GHSA-4rcj-fmjg-q9fv/GHSA-4rcj-fmjg-q9fv.json new file mode 100644 index 00000000000..52d02c52a2f --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-4rcj-fmjg-q9fv/GHSA-4rcj-fmjg-q9fv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rcj-fmjg-q9fv", + "modified": "2024-07-17T18:31:00Z", + "published": "2024-07-17T18:31:00Z", + "aliases": [ + "CVE-2024-20401" + ], + "details": "A vulnerability in the content scanning and message filtering features of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to overwrite arbitrary files on the underlying operating system.\n\n This vulnerability is due to improper handling of email attachments when file analysis and content filters are enabled. An attacker could exploit this vulnerability by sending an email that contains a crafted attachment through an affected device. A successful exploit could allow the attacker to replace any file on the underlying file system. The attacker could then perform any of the following actions: add users with root privileges, modify the device configuration, execute arbitrary code, or cause a permanent denial of service (DoS) condition on the affected device.\n\n Note: Manual intervention is required to recover from the DoS condition. Customers are advised to contact the Cisco Technical Assistance Center (TAC) to help recover a device in this condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20401" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-afw-bGG2UsjH" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-36" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-5697-p67m-73p6/GHSA-5697-p67m-73p6.json b/advisories/unreviewed/2024/07/GHSA-5697-p67m-73p6/GHSA-5697-p67m-73p6.json new file mode 100644 index 00000000000..6f2607db361 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-5697-p67m-73p6/GHSA-5697-p67m-73p6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5697-p67m-73p6", + "modified": "2024-07-17T18:31:00Z", + "published": "2024-07-17T18:31:00Z", + "aliases": [ + "CVE-2024-20419" + ], + "details": "A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including administrative users.\n\n This vulnerability is due to improper implementation of the password-change process. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow an attacker to access the web UI or API with the privileges of the compromised user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20419" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cssm-auth-sLw3uhUy" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-620" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-57c8-7jwm-wc5w/GHSA-57c8-7jwm-wc5w.json b/advisories/unreviewed/2024/07/GHSA-57c8-7jwm-wc5w/GHSA-57c8-7jwm-wc5w.json new file mode 100644 index 00000000000..b5f689ea2fc --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-57c8-7jwm-wc5w/GHSA-57c8-7jwm-wc5w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57c8-7jwm-wc5w", + "modified": "2024-07-17T18:31:00Z", + "published": "2024-07-17T18:31:00Z", + "aliases": [ + "CVE-2023-4976" + ], + "details": "A flaw exists in Purity//FB whereby a local account is permitted to authenticate to the management interface using an unintended method that allows an attacker to gain privileged access to the array.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4976" + }, + { + "type": "WEB", + "url": "https://purestorage.com/security" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T16:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-67ww-939x-f5pp/GHSA-67ww-939x-f5pp.json b/advisories/unreviewed/2024/07/GHSA-67ww-939x-f5pp/GHSA-67ww-939x-f5pp.json new file mode 100644 index 00000000000..2ca77ba1631 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-67ww-939x-f5pp/GHSA-67ww-939x-f5pp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67ww-939x-f5pp", + "modified": "2024-07-17T18:31:00Z", + "published": "2024-07-17T18:31:00Z", + "aliases": [ + "CVE-2024-20396" + ], + "details": "A vulnerability in the protocol handlers of Cisco Webex App could allow an unauthenticated, remote attacker to gain access to sensitive information.\n\n This vulnerability exists because the affected application does not safely handle file protocol handlers. An attacker could exploit this vulnerability by persuading a user to follow a link that is designed to cause the application to send requests. If the attacker can observe transmitted traffic in a privileged network position, a successful exploit could allow the attacker to capture sensitive information, including credential information, from the requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20396" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-app-ZjNm8X8j" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-748p-59x5-mx7f/GHSA-748p-59x5-mx7f.json b/advisories/unreviewed/2024/07/GHSA-748p-59x5-mx7f/GHSA-748p-59x5-mx7f.json new file mode 100644 index 00000000000..36a6e4e1fcd --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-748p-59x5-mx7f/GHSA-748p-59x5-mx7f.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-748p-59x5-mx7f", + "modified": "2024-07-17T18:31:00Z", + "published": "2024-07-17T18:31:00Z", + "aliases": [ + "CVE-2024-6830" + ], + "details": "A vulnerability, which was classified as critical, was found in SourceCodester Simple Inventory Management System 1.0. Affected is an unknown function of the file action.php of the component Order Handler. The manipulation of the argument order_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-271812.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6830" + }, + { + "type": "WEB", + "url": "https://github.com/Xu-Mingming/cve/blob/main/sql1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.271812" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.271812" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.375233" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-7r42-ppxw-235f/GHSA-7r42-ppxw-235f.json b/advisories/unreviewed/2024/07/GHSA-7r42-ppxw-235f/GHSA-7r42-ppxw-235f.json new file mode 100644 index 00000000000..cce5e4030e5 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-7r42-ppxw-235f/GHSA-7r42-ppxw-235f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7r42-ppxw-235f", + "modified": "2024-07-17T18:31:00Z", + "published": "2024-07-17T18:31:00Z", + "aliases": [ + "CVE-2024-20416" + ], + "details": "A vulnerability in the upload module of Cisco RV340 and RV345 Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device.\n\n This vulnerability is due to insufficient boundary checks when processing specific HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system of the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20416" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv34x-rce-7pqFU2e" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-130" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-82vj-crx8-gvp9/GHSA-82vj-crx8-gvp9.json b/advisories/unreviewed/2024/07/GHSA-82vj-crx8-gvp9/GHSA-82vj-crx8-gvp9.json new file mode 100644 index 00000000000..3a9af49c9e0 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-82vj-crx8-gvp9/GHSA-82vj-crx8-gvp9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82vj-crx8-gvp9", + "modified": "2024-07-17T18:31:00Z", + "published": "2024-07-17T18:31:00Z", + "aliases": [ + "CVE-2024-20323" + ], + "details": "A vulnerability in Cisco Intelligent Node (iNode) Software could allow an unauthenticated, remote attacker to hijack the TLS connection between Cisco iNode Manager and associated intelligent nodes and send arbitrary traffic to an affected device.\n\n This vulnerability is due to the presence of hard-coded cryptographic material. An attacker in a man-in-the-middle position between Cisco iNode Manager and associated deployed nodes could exploit this vulnerability by using the static cryptographic key to generate a trusted certificate and impersonate an affected device. A successful exploit could allow the attacker to read data that is meant for a legitimate device, modify the startup configuration of an associated node, and, consequently, cause a denial of service (DoS) condition for downstream devices that are connected to the affected node.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20323" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-inode-static-key-VUVCeynn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-321" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-9h6c-2f95-gmf7/GHSA-9h6c-2f95-gmf7.json b/advisories/unreviewed/2024/07/GHSA-9h6c-2f95-gmf7/GHSA-9h6c-2f95-gmf7.json new file mode 100644 index 00000000000..e04257a83f5 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-9h6c-2f95-gmf7/GHSA-9h6c-2f95-gmf7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9h6c-2f95-gmf7", + "modified": "2024-07-17T18:31:01Z", + "published": "2024-07-17T18:31:01Z", + "aliases": [ + "CVE-2024-20429" + ], + "details": "A vulnerability in the web-based management interface of Cisco AsyncOS for Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary system commands on an affected device.\n\n This vulnerability is due to insufficient input validation in certain portions of the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges. To successfully exploit this vulnerability, an attacker would need at least valid Operator credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20429" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-priv-esc-ssti-xNO2EOGZ" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-c6hx-833p-hm7m/GHSA-c6hx-833p-hm7m.json b/advisories/unreviewed/2024/07/GHSA-c6hx-833p-hm7m/GHSA-c6hx-833p-hm7m.json new file mode 100644 index 00000000000..72f6cb6b99b --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-c6hx-833p-hm7m/GHSA-c6hx-833p-hm7m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6hx-833p-hm7m", + "modified": "2024-07-17T18:31:01Z", + "published": "2024-07-17T18:31:01Z", + "aliases": [ + "CVE-2024-38870" + ], + "details": "Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP and OpManager Enterprise Edition versions before 128104, from 128151 before 128238, from 128247 before 128250 are vulnerable to Stored XSS vulnerability in reports module.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38870" + }, + { + "type": "WEB", + "url": "https://www.manageengine.com/network-monitoring/security-updates/cve-2024-38870.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-cv3h-4jh6-rh6p/GHSA-cv3h-4jh6-rh6p.json b/advisories/unreviewed/2024/07/GHSA-cv3h-4jh6-rh6p/GHSA-cv3h-4jh6-rh6p.json new file mode 100644 index 00000000000..fe1c1896fec --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-cv3h-4jh6-rh6p/GHSA-cv3h-4jh6-rh6p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cv3h-4jh6-rh6p", + "modified": "2024-07-17T18:31:00Z", + "published": "2024-07-17T18:31:00Z", + "aliases": [ + "CVE-2024-20400" + ], + "details": "A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote attacker to redirect a user to a malicious web page.\n\n This vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by intercepting and modifying an HTTP request from a user. A successful exploit could allow the attacker to redirect the user to a malicious web page.\n\n Note: Cisco Expressway Series refers to Cisco Expressway Control (Expressway-C) devices and Cisco Expressway Edge (Expressway-E) devices.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20400" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-redirect-KJsFuXgj" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-hcf8-5j78-887v/GHSA-hcf8-5j78-887v.json b/advisories/unreviewed/2024/07/GHSA-hcf8-5j78-887v/GHSA-hcf8-5j78-887v.json index c29b2ab427f..c7449fa6f2d 100644 --- a/advisories/unreviewed/2024/07/GHSA-hcf8-5j78-887v/GHSA-hcf8-5j78-887v.json +++ b/advisories/unreviewed/2024/07/GHSA-hcf8-5j78-887v/GHSA-hcf8-5j78-887v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hcf8-5j78-887v", - "modified": "2024-07-17T15:30:52Z", + "modified": "2024-07-17T18:31:00Z", "published": "2024-07-17T15:30:52Z", "aliases": [ "CVE-2024-29120" @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/y3oqz7l8vd7jxxx3z2khgl625nvfr60j" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/17/4" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-mgj5-j889-643m/GHSA-mgj5-j889-643m.json b/advisories/unreviewed/2024/07/GHSA-mgj5-j889-643m/GHSA-mgj5-j889-643m.json new file mode 100644 index 00000000000..449f61deb72 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-mgj5-j889-643m/GHSA-mgj5-j889-643m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgj5-j889-643m", + "modified": "2024-07-17T18:31:00Z", + "published": "2024-07-17T18:31:00Z", + "aliases": [ + "CVE-2024-20296" + ], + "details": "A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to upload arbitrary files to an affected device. To exploit this vulnerability, an attacker would need at least valid Policy Admin credentials on the affected device.\n\n This vulnerability is due to improper validation of files that are uploaded to the web-based management interface. An attacker could exploit this vulnerability by uploading arbitrary files to an affected device. A successful exploit could allow the attacker to store malicious files on the system, execute arbitrary commands on the operating system, and elevate privileges to root.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20296" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-file-upload-krW2TxA9" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-mq58-p8pv-xx7f/GHSA-mq58-p8pv-xx7f.json b/advisories/unreviewed/2024/07/GHSA-mq58-p8pv-xx7f/GHSA-mq58-p8pv-xx7f.json new file mode 100644 index 00000000000..f6b1c50a43f --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-mq58-p8pv-xx7f/GHSA-mq58-p8pv-xx7f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq58-p8pv-xx7f", + "modified": "2024-07-17T18:31:01Z", + "published": "2024-07-17T18:31:01Z", + "aliases": [ + "CVE-2024-38447" + ], + "details": "NATO NCI ANET 3.4.1 allows Insecure Direct Object Reference via a modified ID field in a request for a private draft report (that belongs to an arbitrary user).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38447" + }, + { + "type": "WEB", + "url": "https://www.linkedin.com/pulse/idors-ncia-anet-v341-visionspace-technologies-hepxe" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T18:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-p6xf-x5px-f2vq/GHSA-p6xf-x5px-f2vq.json b/advisories/unreviewed/2024/07/GHSA-p6xf-x5px-f2vq/GHSA-p6xf-x5px-f2vq.json new file mode 100644 index 00000000000..f03fc62d630 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-p6xf-x5px-f2vq/GHSA-p6xf-x5px-f2vq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6xf-x5px-f2vq", + "modified": "2024-07-17T18:31:01Z", + "published": "2024-07-17T18:31:01Z", + "aliases": [ + "CVE-2024-20435" + ], + "details": "A vulnerability in the CLI of Cisco AsyncOS for Secure Web Appliance could allow an authenticated, local attacker to execute arbitrary commands and elevate privileges to root.\n\n This vulnerability is due to insufficient validation of user-supplied input for the CLI. An attacker could exploit this vulnerability by authenticating to the system and executing a crafted command on the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system and elevate privileges to root. To successfully exploit this vulnerability, an attacker would need at least guest credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20435" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-swa-priv-esc-7uHpZsCC" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-250" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-pfpx-3hgc-pc2g/GHSA-pfpx-3hgc-pc2g.json b/advisories/unreviewed/2024/07/GHSA-pfpx-3hgc-pc2g/GHSA-pfpx-3hgc-pc2g.json new file mode 100644 index 00000000000..35691c2bebe --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-pfpx-3hgc-pc2g/GHSA-pfpx-3hgc-pc2g.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfpx-3hgc-pc2g", + "modified": "2024-07-17T18:31:01Z", + "published": "2024-07-17T18:31:01Z", + "aliases": [ + "CVE-2024-40639" + ], + "details": "Gotenberg provides a developer-friendly API to interact with powerful tools like Chromium and LibreOffice for converting numerous document formats (HTML, Markdown, Word, Excel, etc.) into PDF files, and more! Prior to version 8.1.0, the default value for the flag `--chromium-deny-list` allowed to display some internal files from the Gotenberg container. Version 8.1.0 provides a new default value fixing the issue. Prior to version 8.1.0, Gotenberg uses the standard `regexp` Go library, which does not support negative lookahead. Therefore, the new default value for the `--chromium-deny-list` is not applicable. However, one could find an alternative using either or both `--chromium-deny-list` and `--chromium-allow-list` flags. Users are advised to upgrade. There are no known workarounds for this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/gotenberg/gotenberg/security/advisories/GHSA-rh2x-ccvw-q7r3" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40639" + }, + { + "type": "WEB", + "url": "https://github.com/gotenberg/gotenberg/commit/ad152e62e5124b673099a9103eb6e7f933771794" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-xfp3-mm6f-4fw4/GHSA-xfp3-mm6f-4fw4.json b/advisories/unreviewed/2024/07/GHSA-xfp3-mm6f-4fw4/GHSA-xfp3-mm6f-4fw4.json new file mode 100644 index 00000000000..eab0cb14ef9 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-xfp3-mm6f-4fw4/GHSA-xfp3-mm6f-4fw4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xfp3-mm6f-4fw4", + "modified": "2024-07-17T18:31:01Z", + "published": "2024-07-17T18:31:01Z", + "aliases": [ + "CVE-2024-38446" + ], + "details": "NATO NCI ANET 3.4.1 mishandles report ownership. A user can create a report and, despite the restrictions imposed by the UI, change the author of that report to an arbitrary user (without their consent or knowledge) via a modified UUID in a POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38446" + }, + { + "type": "WEB", + "url": "https://www.linkedin.com/pulse/idors-ncia-anet-v341-visionspace-technologies-hepxe" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T17:15:15Z" + } +} \ No newline at end of file