diff --git a/advisories/unreviewed/2024/06/GHSA-269c-4g57-c9vg/GHSA-269c-4g57-c9vg.json b/advisories/unreviewed/2024/06/GHSA-269c-4g57-c9vg/GHSA-269c-4g57-c9vg.json new file mode 100644 index 00000000000..40334249547 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-269c-4g57-c9vg/GHSA-269c-4g57-c9vg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-269c-4g57-c9vg", + "modified": "2024-06-27T00:31:04Z", + "published": "2024-06-27T00:31:04Z", + "aliases": [ + "CVE-2024-1816" + ], + "details": "An issue was discovered in GitLab CE/EE affecting all versions starting from 12.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows for an attacker to cause a denial of service using a crafted OpenAPI file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1816" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2370737" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/442852" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-27T00:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-3492-v7j6-2xgv/GHSA-3492-v7j6-2xgv.json b/advisories/unreviewed/2024/06/GHSA-3492-v7j6-2xgv/GHSA-3492-v7j6-2xgv.json new file mode 100644 index 00000000000..b4b178d9a45 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-3492-v7j6-2xgv/GHSA-3492-v7j6-2xgv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3492-v7j6-2xgv", + "modified": "2024-06-27T00:31:04Z", + "published": "2024-06-27T00:31:04Z", + "aliases": [ + "CVE-2024-4011" + ], + "details": "An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows non-project member to promote key results to objectives.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4011" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2456186" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/457235" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-27T00:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-38f2-vcgr-hqxh/GHSA-38f2-vcgr-hqxh.json b/advisories/unreviewed/2024/06/GHSA-38f2-vcgr-hqxh/GHSA-38f2-vcgr-hqxh.json new file mode 100644 index 00000000000..6ce581b568a --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-38f2-vcgr-hqxh/GHSA-38f2-vcgr-hqxh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38f2-vcgr-hqxh", + "modified": "2024-06-27T00:31:04Z", + "published": "2024-06-27T00:31:04Z", + "aliases": [ + "CVE-2024-4557" + ], + "details": "Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1 which allowed an attacker to cause resource exhaustion via banzai pipeline.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4557" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2485172" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/460517" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-27T00:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-3x45-j72c-xqpj/GHSA-3x45-j72c-xqpj.json b/advisories/unreviewed/2024/06/GHSA-3x45-j72c-xqpj/GHSA-3x45-j72c-xqpj.json new file mode 100644 index 00000000000..d2ed9a0ce50 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-3x45-j72c-xqpj/GHSA-3x45-j72c-xqpj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3x45-j72c-xqpj", + "modified": "2024-06-27T00:31:04Z", + "published": "2024-06-27T00:31:04Z", + "aliases": [ + "CVE-2024-28982" + ], + "details": "Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User Console against XML External Entity Reference.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28982" + }, + { + "type": "WEB", + "url": "https://support.pentaho.com/hc/en-us/articles/27569195609869--Resolved-Hitachi-Vantara-Pentaho-Business-Analytics-Server-Improper-Restriction-of-XML-External-Entity-Reference-versions-before-10-1-0-0-and-9-3-0-7-including-8-3-x-Impacted-CVE-2024-28982" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-776" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T23:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-73p8-f56m-692w/GHSA-73p8-f56m-692w.json b/advisories/unreviewed/2024/06/GHSA-73p8-f56m-692w/GHSA-73p8-f56m-692w.json new file mode 100644 index 00000000000..a26e2e8576d --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-73p8-f56m-692w/GHSA-73p8-f56m-692w.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73p8-f56m-692w", + "modified": "2024-06-27T00:31:04Z", + "published": "2024-06-27T00:31:04Z", + "aliases": [ + "CVE-2024-3115" + ], + "details": "An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to access issues and epics without having an SSO session using Duo Chat.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3115" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2417868" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/452548" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-27T00:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-76xj-g72f-jr82/GHSA-76xj-g72f-jr82.json b/advisories/unreviewed/2024/06/GHSA-76xj-g72f-jr82/GHSA-76xj-g72f-jr82.json new file mode 100644 index 00000000000..867fc7623db --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-76xj-g72f-jr82/GHSA-76xj-g72f-jr82.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76xj-g72f-jr82", + "modified": "2024-06-27T00:31:04Z", + "published": "2024-06-27T00:31:04Z", + "aliases": [ + "CVE-2024-37248" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Anima allows Stored XSS.This issue affects Anima: from n/a through 1.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37248" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/anima/wordpress-anima-theme-1-4-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T22:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-7ghr-75pj-w6vc/GHSA-7ghr-75pj-w6vc.json b/advisories/unreviewed/2024/06/GHSA-7ghr-75pj-w6vc/GHSA-7ghr-75pj-w6vc.json new file mode 100644 index 00000000000..ef2b84890c5 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-7ghr-75pj-w6vc/GHSA-7ghr-75pj-w6vc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7ghr-75pj-w6vc", + "modified": "2024-06-27T00:31:04Z", + "published": "2024-06-27T00:31:04Z", + "aliases": [ + "CVE-2024-4901" + ], + "details": "An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, where a stored XSS vulnerability could be imported from a project with malicious commit notes.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4901" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2500163" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/461773" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-27T00:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-86gc-q5qm-hm5q/GHSA-86gc-q5qm-hm5q.json b/advisories/unreviewed/2024/06/GHSA-86gc-q5qm-hm5q/GHSA-86gc-q5qm-hm5q.json new file mode 100644 index 00000000000..45b668ab750 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-86gc-q5qm-hm5q/GHSA-86gc-q5qm-hm5q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86gc-q5qm-hm5q", + "modified": "2024-06-27T00:31:04Z", + "published": "2024-06-27T00:31:04Z", + "aliases": [ + "CVE-2024-28983" + ], + "details": "Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malicious URL to inject content into the Analyzer plugin interface.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28983" + }, + { + "type": "WEB", + "url": "https://support.pentaho.com/hc/en-us/articles/27569257123725-Hitachi-Vantara-Pentaho-Business-Analytics-Server-Improper-Neutralization-of-Input-During-Web-Page-Generation-Cross-site-Scripting-Versions-before-10-1-0-0-and-9-3-0-7-including-8-3-x-Impacted-CVE-2024-28983" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T23:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-c3ph-4hj5-r598/GHSA-c3ph-4hj5-r598.json b/advisories/unreviewed/2024/06/GHSA-c3ph-4hj5-r598/GHSA-c3ph-4hj5-r598.json new file mode 100644 index 00000000000..58bbacfde3c --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-c3ph-4hj5-r598/GHSA-c3ph-4hj5-r598.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3ph-4hj5-r598", + "modified": "2024-06-27T00:31:04Z", + "published": "2024-06-27T00:31:04Z", + "aliases": [ + "CVE-2024-1493" + ], + "details": "An issue was discovered in GitLab CE/EE affecting all versions starting from 9.2 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, with the processing logic for generating link in dependency files can lead to a regular expression DoS attack on the server", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1493" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2370084" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/441806" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-27T00:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-chjh-944f-687f/GHSA-chjh-944f-687f.json b/advisories/unreviewed/2024/06/GHSA-chjh-944f-687f/GHSA-chjh-944f-687f.json new file mode 100644 index 00000000000..aec9b421c83 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-chjh-944f-687f/GHSA-chjh-944f-687f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chjh-944f-687f", + "modified": "2024-06-27T00:31:05Z", + "published": "2024-06-27T00:31:05Z", + "aliases": [ + "CVE-2024-6323" + ], + "details": "Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to 16.11.5 and 17.0 prior to 17.0.3 and 17.1 prior to 17.1.1 allows an attacker leak content of a private repository in a public project.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6323" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/457912" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-653" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-27T00:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-fjc3-h6x3-cpx9/GHSA-fjc3-h6x3-cpx9.json b/advisories/unreviewed/2024/06/GHSA-fjc3-h6x3-cpx9/GHSA-fjc3-h6x3-cpx9.json new file mode 100644 index 00000000000..a1c8325d6b9 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-fjc3-h6x3-cpx9/GHSA-fjc3-h6x3-cpx9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjc3-h6x3-cpx9", + "modified": "2024-06-27T00:31:04Z", + "published": "2024-06-27T00:31:04Z", + "aliases": [ + "CVE-2024-2191" + ], + "details": "An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members only.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2191" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2357370" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/444655" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-27T00:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-gr98-7cg9-j7c7/GHSA-gr98-7cg9-j7c7.json b/advisories/unreviewed/2024/06/GHSA-gr98-7cg9-j7c7/GHSA-gr98-7cg9-j7c7.json new file mode 100644 index 00000000000..a633712836d --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-gr98-7cg9-j7c7/GHSA-gr98-7cg9-j7c7.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gr98-7cg9-j7c7", + "modified": "2024-06-27T00:31:05Z", + "published": "2024-06-27T00:31:05Z", + "aliases": [ + "CVE-2024-5655" + ], + "details": "An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeline as another user under certain circumstances.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5655" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2536320" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/465862" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-27T00:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-h836-7w37-2mwc/GHSA-h836-7w37-2mwc.json b/advisories/unreviewed/2024/06/GHSA-h836-7w37-2mwc/GHSA-h836-7w37-2mwc.json new file mode 100644 index 00000000000..c25ec3ae626 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-h836-7w37-2mwc/GHSA-h836-7w37-2mwc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h836-7w37-2mwc", + "modified": "2024-06-27T00:31:04Z", + "published": "2024-06-27T00:31:04Z", + "aliases": [ + "CVE-2024-28984" + ], + "details": "Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malicious URL to inject content into the Analyzer plugin interface.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28984" + }, + { + "type": "WEB", + "url": "https://support.pentaho.com/hc/en-us/articles/27569319605901-Hitachi-Vantara-Pentaho-Business-Analytics-Server-Improper-Neutralization-of-Input-During-Web-Page-Generation-Cross-site-Scripting-Versions-before-10-1-0-0-and-9-3-0-7-including-8-3-x-Impacted-CVE-2024-28984" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T23:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-j3f4-rf7c-whp5/GHSA-j3f4-rf7c-whp5.json b/advisories/unreviewed/2024/06/GHSA-j3f4-rf7c-whp5/GHSA-j3f4-rf7c-whp5.json new file mode 100644 index 00000000000..f956b0262d5 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-j3f4-rf7c-whp5/GHSA-j3f4-rf7c-whp5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3f4-rf7c-whp5", + "modified": "2024-06-27T00:31:04Z", + "published": "2024-06-27T00:31:04Z", + "aliases": [ + "CVE-2024-37571" + ], + "details": "Buffer Overflow vulnerability in SAS Broker 9.2 build 1495 allows attackers to cause denial of service or obtain sensitive information via crafted payload to the '_debug' parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37571" + }, + { + "type": "WEB", + "url": "https://gist.github.com/MILPDS/e9da6d07ba1789defacec08f2f03293d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T22:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-mmw4-rfwh-wm5m/GHSA-mmw4-rfwh-wm5m.json b/advisories/unreviewed/2024/06/GHSA-mmw4-rfwh-wm5m/GHSA-mmw4-rfwh-wm5m.json new file mode 100644 index 00000000000..6083e218b45 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-mmw4-rfwh-wm5m/GHSA-mmw4-rfwh-wm5m.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mmw4-rfwh-wm5m", + "modified": "2024-06-27T00:31:04Z", + "published": "2024-06-27T00:31:04Z", + "aliases": [ + "CVE-2024-3959" + ], + "details": "An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows private job artifacts can be accessed by any user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3959" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2456845" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/456989" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-27T00:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-w7mv-9vp4-23mf/GHSA-w7mv-9vp4-23mf.json b/advisories/unreviewed/2024/06/GHSA-w7mv-9vp4-23mf/GHSA-w7mv-9vp4-23mf.json new file mode 100644 index 00000000000..e27008cbe36 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-w7mv-9vp4-23mf/GHSA-w7mv-9vp4-23mf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7mv-9vp4-23mf", + "modified": "2024-06-27T00:31:04Z", + "published": "2024-06-27T00:31:04Z", + "aliases": [ + "CVE-2024-37247" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in twinpictures, baden03 jQuery T(-) Countdown Widget allows Stored XSS.This issue affects jQuery T(-) Countdown Widget: from n/a through 2.3.25.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37247" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/jquery-t-countdown-widget/wordpress-jquery-t-countdown-widget-plugin-2-3-25-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T22:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-w9qv-xhc6-m43c/GHSA-w9qv-xhc6-m43c.json b/advisories/unreviewed/2024/06/GHSA-w9qv-xhc6-m43c/GHSA-w9qv-xhc6-m43c.json new file mode 100644 index 00000000000..a019114f512 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-w9qv-xhc6-m43c/GHSA-w9qv-xhc6-m43c.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9qv-xhc6-m43c", + "modified": "2024-06-27T00:31:04Z", + "published": "2024-06-27T00:31:04Z", + "aliases": [ + "CVE-2024-5430" + ], + "details": "An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delete the merge request approval policy via graphQL.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5430" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2520947" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/464017" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-27T00:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-wxj9-7p6q-955h/GHSA-wxj9-7p6q-955h.json b/advisories/unreviewed/2024/06/GHSA-wxj9-7p6q-955h/GHSA-wxj9-7p6q-955h.json new file mode 100644 index 00000000000..0da9edb3917 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-wxj9-7p6q-955h/GHSA-wxj9-7p6q-955h.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxj9-7p6q-955h", + "modified": "2024-06-27T00:31:04Z", + "published": "2024-06-27T00:31:04Z", + "aliases": [ + "CVE-2024-37734" + ], + "details": "An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37734" + }, + { + "type": "WEB", + "url": "https://github.com/openemr/openemr/pull/7435#event-12872646667" + }, + { + "type": "WEB", + "url": "https://github.com/A3h1nt/CVEs/tree/main/OpenEMR" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T22:15:10Z" + } +} \ No newline at end of file