Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-03-19 18:33:26 +00:00
parent 5e3ee7be86
commit 0a7458f537
53 changed files with 1564 additions and 44 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-68mj-9pjq-mc85",
"modified": "2024-03-18T20:30:22Z",
"modified": "2024-03-19T18:31:29Z",
"published": "2024-03-18T20:30:22Z",
"aliases": [
"CVE-2024-28248"
@@ -78,18 +78,38 @@
"type": "WEB",
"url": "https://github.com/cilium/cilium/security/advisories/GHSA-68mj-9pjq-mc85"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28248"
},
{
"type": "WEB",
"url": "https://docs.cilium.io/en/stable/security/policy/language/#http"
},
{
"type": "PACKAGE",
"url": "https://github.com/cilium/cilium"
},
{
"type": "WEB",
"url": "https://github.com/cilium/cilium/releases/tag/v1.13.13"
},
{
"type": "WEB",
"url": "https://github.com/cilium/cilium/releases/tag/v1.14.8"
},
{
"type": "WEB",
"url": "https://github.com/cilium/cilium/releases/tag/v1.15.2"
}
],
"database_specific": {
"cwe_ids": [
"CWE-693"
],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-03-18T20:30:22Z",
"nvd_published_at": null
"nvd_published_at": "2024-03-18T22:15:08Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hfrg-4jwr-jfpj",
"modified": "2024-03-18T20:34:00Z",
"modified": "2024-03-19T18:31:08Z",
"published": "2024-03-18T20:34:00Z",
"aliases": [
"CVE-2024-28855"
@@ -160,18 +160,50 @@
"type": "WEB",
"url": "https://github.com/zitadel/zitadel/security/advisories/GHSA-hfrg-4jwr-jfpj"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28855"
},
{
"type": "PACKAGE",
"url": "https://github.com/zitadel/zitadel"
},
{
"type": "WEB",
"url": "https://github.com/zitadel/zitadel/releases/tag/v2.41.15"
},
{
"type": "WEB",
"url": "https://github.com/zitadel/zitadel/releases/tag/v2.42.15"
},
{
"type": "WEB",
"url": "https://github.com/zitadel/zitadel/releases/tag/v2.43.9"
},
{
"type": "WEB",
"url": "https://github.com/zitadel/zitadel/releases/tag/v2.44.3"
},
{
"type": "WEB",
"url": "https://github.com/zitadel/zitadel/releases/tag/v2.45.1"
},
{
"type": "WEB",
"url": "https://github.com/zitadel/zitadel/releases/tag/v2.46.1"
},
{
"type": "WEB",
"url": "https://github.com/zitadel/zitadel/releases/tag/v2.47.3"
}
],
"database_specific": {
"cwe_ids": [
"CWE-20"
],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-03-18T20:34:00Z",
"nvd_published_at": null
"nvd_published_at": "2024-03-18T22:15:08Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j89h-qrvr-xc36",
"modified": "2024-03-18T20:30:41Z",
"modified": "2024-03-19T18:31:22Z",
"published": "2024-03-18T20:30:41Z",
"aliases": [
"CVE-2024-28249"
@@ -78,18 +78,34 @@
"type": "WEB",
"url": "https://github.com/cilium/cilium/security/advisories/GHSA-j89h-qrvr-xc36"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28249"
},
{
"type": "PACKAGE",
"url": "https://github.com/cilium/cilium"
},
{
"type": "WEB",
"url": "https://github.com/cilium/cilium/releases/tag/v1.13.13"
},
{
"type": "WEB",
"url": "https://github.com/cilium/cilium/releases/tag/v1.14.8"
},
{
"type": "WEB",
"url": "https://github.com/cilium/cilium/releases/tag/v1.15.2"
}
],
"database_specific": {
"cwe_ids": [
"CWE-311"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-03-18T20:30:41Z",
"nvd_published_at": null
"nvd_published_at": "2024-03-18T22:15:08Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rj29-j2g4-77q8",
"modified": "2024-03-18T20:39:00Z",
"modified": "2024-03-19T18:30:48Z",
"published": "2024-03-18T20:39:00Z",
"aliases": [
"CVE-2024-28864"
@@ -40,6 +40,10 @@
"type": "WEB",
"url": "https://github.com/IlicMiljan/Secure-Props/security/advisories/GHSA-rj29-j2g4-77q8"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28864"
},
{
"type": "WEB",
"url": "https://github.com/IlicMiljan/Secure-Props/issues/20"
@@ -59,11 +63,11 @@
],
"database_specific": {
"cwe_ids": [
"CWE-1333"
],
"severity": "LOW",
"github_reviewed": true,
"github_reviewed_at": "2024-03-18T20:39:00Z",
"nvd_published_at": null
"nvd_published_at": "2024-03-18T22:15:09Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v6q2-4qr3-5cw6",
"modified": "2024-03-18T20:33:32Z",
"modified": "2024-03-19T18:31:16Z",
"published": "2024-03-18T20:33:32Z",
"aliases": [
"CVE-2024-28250"
@@ -59,18 +59,34 @@
"type": "WEB",
"url": "https://github.com/cilium/cilium/security/advisories/GHSA-v6q2-4qr3-5cw6"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28250"
},
{
"type": "PACKAGE",
"url": "https://github.com/cilium/cilium"
},
{
"type": "WEB",
"url": "https://github.com/cilium/cilium/releases/tag/v1.13.13"
},
{
"type": "WEB",
"url": "https://github.com/cilium/cilium/releases/tag/v1.14.8"
},
{
"type": "WEB",
"url": "https://github.com/cilium/cilium/releases/tag/v1.15.2"
}
],
"database_specific": {
"cwe_ids": [
"CWE-311"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-03-18T20:33:32Z",
"nvd_published_at": null
"nvd_published_at": "2024-03-18T22:15:08Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wj85-w4f4-xh8h",
"modified": "2024-03-18T20:37:48Z",
"modified": "2024-03-19T18:30:57Z",
"published": "2024-03-18T20:37:48Z",
"aliases": [
"CVE-2024-28865"
@@ -40,6 +40,10 @@
"type": "WEB",
"url": "https://github.com/django-wiki/django-wiki/security/advisories/GHSA-wj85-w4f4-xh8h"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28865"
},
{
"type": "WEB",
"url": "https://github.com/django-wiki/django-wiki/commit/8e280fd6c0bd27ce847c67b2d216c6cbf920f88c"
@@ -56,6 +60,6 @@
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-03-18T20:37:48Z",
"nvd_published_at": null
"nvd_published_at": "2024-03-18T22:15:09Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x7mf-wrh9-r76c",
"modified": "2024-03-18T20:29:45Z",
"modified": "2024-03-19T18:31:36Z",
"published": "2024-03-18T20:29:45Z",
"aliases": [
"CVE-2024-28237"
@@ -43,6 +43,10 @@
"type": "WEB",
"url": "https://github.com/OctoPrint/OctoPrint/security/advisories/GHSA-x7mf-wrh9-r76c"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28237"
},
{
"type": "WEB",
"url": "https://github.com/OctoPrint/OctoPrint/commit/779894c1bc6478332d14bc9ed1006df1354eb517"
@@ -59,6 +63,6 @@
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-03-18T20:29:45Z",
"nvd_published_at": null
"nvd_published_at": "2024-03-18T22:15:07Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-53qf-272p-ghf6",
"modified": "2022-05-24T19:08:11Z",
"modified": "2024-03-19T18:31:58Z",
"published": "2022-05-24T19:08:11Z",
"aliases": [
"CVE-2021-29725"
],
"details": "IBM Secure External Authentication Server 2.4.3.2, 6.0.1, 6.0.2 and IBM Secure Proxy 3.4.3.2, 6.0.1, 6.0.2 could allow a remote user to consume resources causing a denial of service due to a resource leak.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6q52-mr9g-rhrv",
"modified": "2022-05-24T19:08:11Z",
"modified": "2024-03-19T18:31:58Z",
"published": "2022-05-24T19:08:11Z",
"aliases": [
"CVE-2021-29749"
],
"details": "IBM Secure External Authentication Server 6.0.2 and IBM Secure Proxy 6.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 201777.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vgxc-rq2p-x5qw",
"modified": "2022-05-24T17:16:59Z",
"modified": "2024-03-19T18:31:58Z",
"published": "2022-05-24T17:16:59Z",
"aliases": [
"CVE-2020-12101"
],
"details": "The address-management feature in xt:Commerce 5.1 to 6.2.2 allows remote authenticated users to zero out other user's stored addresses by manipulating an id field in the POST request for altering an address.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [
@@ -37,7 +40,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-276"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -49,7 +49,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p788-v6c7-5vqg",
"modified": "2024-03-19T06:30:52Z",
"modified": "2024-03-19T18:31:58Z",
"published": "2023-08-21T21:31:23Z",
"aliases": [
"CVE-2023-4459"
@@ -41,6 +41,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1367"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1382"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-4459"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mmc5-hgpc-m8q5",
"modified": "2024-03-19T06:30:52Z",
"modified": "2024-03-19T18:31:58Z",
"published": "2024-01-02T21:30:25Z",
"aliases": [
"CVE-2023-7192"
@@ -45,6 +45,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1367"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1382"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-7192"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qmff-49xc-7rf6",
"modified": "2024-03-19T06:30:52Z",
"modified": "2024-03-19T18:31:58Z",
"published": "2024-01-17T18:31:36Z",
"aliases": [
"CVE-2024-0646"
@@ -33,6 +33,14 @@
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-0646"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1382"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1377"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1368"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6v6c-gc45-x65c",
"modified": "2024-03-05T06:30:41Z",
"modified": "2024-03-19T18:31:58Z",
"published": "2024-02-12T15:30:23Z",
"aliases": [
"CVE-2024-1062"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1074"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1372"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-1062"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cjwx-wwmv-rqgc",
"modified": "2024-02-21T18:31:00Z",
"modified": "2024-03-19T18:31:58Z",
"published": "2024-02-21T18:31:00Z",
"aliases": [
"CVE-2022-45169"
],
"details": "An issue was discovered in LIVEBOX Collaboration vDesk through v031. A URL Redirection to an Untrusted Site (Open Redirect) can occur under the /api/v1/notification/createnotification endpoint, allowing an authenticated user to send an arbitrary push notification to any other user of the system. This push notification can include an (invisible) clickable link.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-601"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-21T16:15:49Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g759-2x5w-f89c",
"modified": "2024-02-21T18:31:00Z",
"modified": "2024-03-19T18:31:58Z",
"published": "2024-02-21T18:31:00Z",
"aliases": [
"CVE-2022-45177"
],
"details": "An issue was discovered in LIVEBOX Collaboration vDesk through v031. An Observable Response Discrepancy can occur under the /api/v1/vdeskintegration/user/isenableuser endpoint, the /api/v1/sharedsearch?search={NAME]+{SURNAME] endpoint, and the /login endpoint. The web application provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-203"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-21T16:15:49Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w32h-6ffq-r68m",
"modified": "2024-02-21T18:31:00Z",
"modified": "2024-03-19T18:31:58Z",
"published": "2024-02-21T18:31:00Z",
"aliases": [
"CVE-2022-45179"
],
"details": "An issue was discovered in LIVEBOX Collaboration vDesk through v031. A basic XSS vulnerability exists under the /api/v1/vdeskintegration/todo/createorupdate endpoint via the title parameter and /dashboard/reminders. A remote user (authenticated to the product) can store arbitrary HTML code in the reminder section title in order to corrupt the web page (for example, by creating phishing sections to exfiltrate victims' credentials).",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-21T16:15:49Z"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-23h2-xqvf-mj5r",
"modified": "2024-03-19T18:32:01Z",
"published": "2024-03-19T18:32:01Z",
"aliases": [
"CVE-2024-27996"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Survey Maker team Survey Maker allows Stored XSS.This issue affects Survey Maker: from n/a through 4.0.5.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27996"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/survey-maker/wordpress-survey-maker-plugin-4-0-5-cross-site-scripting-xss-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-19T17:15:10Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-258w-hr8p-8679",
"modified": "2024-03-19T18:31:59Z",
"published": "2024-03-19T18:31:59Z",
"aliases": [
"CVE-2023-32260"
],
"details": "Misinterpretation of Input vulnerability in OpenText™ Service Management Automation X (SMAX), OpenText™ Asset Management X (AMX), and OpenText™ Hybrid Cloud Management X (HCMX) products. The vulnerability could allow Input data manipulation.This issue affects Service Management Automation X (SMAX) versions: 2020.05, 2020.08, 2020.11, 2021.02, 2021.05, 2021.08, 2021.11, 2022.05, 2022.11, 2023.05; Asset Management X (AMX) versions: 2021.08, 2021.11, 2022.05, 2022.11, 2023.05; and Hybrid Cloud Management X (HCMX) versions: 2020.05, 2020.08, 2020.11, 2021.02, 2021.05, 2021.08, 2021.11, 2022.05, 2022.11, 2023.05.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32260"
},
{
"type": "WEB",
"url": "https://portal.microfocus.com/s/article/KM000018804?language=en_US"
}
],
"database_specific": {
"cwe_ids": [
"CWE-115"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-19T16:15:08Z"
}
}

Some files were not shown because too many files have changed in this diff Show More