diff --git a/advisories/github-reviewed/2024/03/GHSA-68mj-9pjq-mc85/GHSA-68mj-9pjq-mc85.json b/advisories/github-reviewed/2024/03/GHSA-68mj-9pjq-mc85/GHSA-68mj-9pjq-mc85.json index 37c7b3ac8dd..78172d06793 100644 --- a/advisories/github-reviewed/2024/03/GHSA-68mj-9pjq-mc85/GHSA-68mj-9pjq-mc85.json +++ b/advisories/github-reviewed/2024/03/GHSA-68mj-9pjq-mc85/GHSA-68mj-9pjq-mc85.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-68mj-9pjq-mc85", - "modified": "2024-03-18T20:30:22Z", + "modified": "2024-03-19T18:31:29Z", "published": "2024-03-18T20:30:22Z", "aliases": [ "CVE-2024-28248" @@ -78,18 +78,38 @@ "type": "WEB", "url": "https://github.com/cilium/cilium/security/advisories/GHSA-68mj-9pjq-mc85" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28248" + }, + { + "type": "WEB", + "url": "https://docs.cilium.io/en/stable/security/policy/language/#http" + }, { "type": "PACKAGE", "url": "https://github.com/cilium/cilium" + }, + { + "type": "WEB", + "url": "https://github.com/cilium/cilium/releases/tag/v1.13.13" + }, + { + "type": "WEB", + "url": "https://github.com/cilium/cilium/releases/tag/v1.14.8" + }, + { + "type": "WEB", + "url": "https://github.com/cilium/cilium/releases/tag/v1.15.2" } ], "database_specific": { "cwe_ids": [ - + "CWE-693" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-03-18T20:30:22Z", - "nvd_published_at": null + "nvd_published_at": "2024-03-18T22:15:08Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2024/03/GHSA-hfrg-4jwr-jfpj/GHSA-hfrg-4jwr-jfpj.json b/advisories/github-reviewed/2024/03/GHSA-hfrg-4jwr-jfpj/GHSA-hfrg-4jwr-jfpj.json index 1e83c174509..1561962021e 100644 --- a/advisories/github-reviewed/2024/03/GHSA-hfrg-4jwr-jfpj/GHSA-hfrg-4jwr-jfpj.json +++ b/advisories/github-reviewed/2024/03/GHSA-hfrg-4jwr-jfpj/GHSA-hfrg-4jwr-jfpj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hfrg-4jwr-jfpj", - "modified": "2024-03-18T20:34:00Z", + "modified": "2024-03-19T18:31:08Z", "published": "2024-03-18T20:34:00Z", "aliases": [ "CVE-2024-28855" @@ -160,18 +160,50 @@ "type": "WEB", "url": "https://github.com/zitadel/zitadel/security/advisories/GHSA-hfrg-4jwr-jfpj" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28855" + }, { "type": "PACKAGE", "url": "https://github.com/zitadel/zitadel" + }, + { + "type": "WEB", + "url": "https://github.com/zitadel/zitadel/releases/tag/v2.41.15" + }, + { + "type": "WEB", + "url": "https://github.com/zitadel/zitadel/releases/tag/v2.42.15" + }, + { + "type": "WEB", + "url": "https://github.com/zitadel/zitadel/releases/tag/v2.43.9" + }, + { + "type": "WEB", + "url": "https://github.com/zitadel/zitadel/releases/tag/v2.44.3" + }, + { + "type": "WEB", + "url": "https://github.com/zitadel/zitadel/releases/tag/v2.45.1" + }, + { + "type": "WEB", + "url": "https://github.com/zitadel/zitadel/releases/tag/v2.46.1" + }, + { + "type": "WEB", + "url": "https://github.com/zitadel/zitadel/releases/tag/v2.47.3" } ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-03-18T20:34:00Z", - "nvd_published_at": null + "nvd_published_at": "2024-03-18T22:15:08Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2024/03/GHSA-j89h-qrvr-xc36/GHSA-j89h-qrvr-xc36.json b/advisories/github-reviewed/2024/03/GHSA-j89h-qrvr-xc36/GHSA-j89h-qrvr-xc36.json index 9f4afb260ec..23495c43718 100644 --- a/advisories/github-reviewed/2024/03/GHSA-j89h-qrvr-xc36/GHSA-j89h-qrvr-xc36.json +++ b/advisories/github-reviewed/2024/03/GHSA-j89h-qrvr-xc36/GHSA-j89h-qrvr-xc36.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j89h-qrvr-xc36", - "modified": "2024-03-18T20:30:41Z", + "modified": "2024-03-19T18:31:22Z", "published": "2024-03-18T20:30:41Z", "aliases": [ "CVE-2024-28249" @@ -78,18 +78,34 @@ "type": "WEB", "url": "https://github.com/cilium/cilium/security/advisories/GHSA-j89h-qrvr-xc36" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28249" + }, { "type": "PACKAGE", "url": "https://github.com/cilium/cilium" + }, + { + "type": "WEB", + "url": "https://github.com/cilium/cilium/releases/tag/v1.13.13" + }, + { + "type": "WEB", + "url": "https://github.com/cilium/cilium/releases/tag/v1.14.8" + }, + { + "type": "WEB", + "url": "https://github.com/cilium/cilium/releases/tag/v1.15.2" } ], "database_specific": { "cwe_ids": [ - + "CWE-311" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-03-18T20:30:41Z", - "nvd_published_at": null + "nvd_published_at": "2024-03-18T22:15:08Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2024/03/GHSA-rj29-j2g4-77q8/GHSA-rj29-j2g4-77q8.json b/advisories/github-reviewed/2024/03/GHSA-rj29-j2g4-77q8/GHSA-rj29-j2g4-77q8.json index 450c52f564d..87d68d00dd8 100644 --- a/advisories/github-reviewed/2024/03/GHSA-rj29-j2g4-77q8/GHSA-rj29-j2g4-77q8.json +++ b/advisories/github-reviewed/2024/03/GHSA-rj29-j2g4-77q8/GHSA-rj29-j2g4-77q8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rj29-j2g4-77q8", - "modified": "2024-03-18T20:39:00Z", + "modified": "2024-03-19T18:30:48Z", "published": "2024-03-18T20:39:00Z", "aliases": [ "CVE-2024-28864" @@ -40,6 +40,10 @@ "type": "WEB", "url": "https://github.com/IlicMiljan/Secure-Props/security/advisories/GHSA-rj29-j2g4-77q8" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28864" + }, { "type": "WEB", "url": "https://github.com/IlicMiljan/Secure-Props/issues/20" @@ -59,11 +63,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1333" ], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2024-03-18T20:39:00Z", - "nvd_published_at": null + "nvd_published_at": "2024-03-18T22:15:09Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2024/03/GHSA-v6q2-4qr3-5cw6/GHSA-v6q2-4qr3-5cw6.json b/advisories/github-reviewed/2024/03/GHSA-v6q2-4qr3-5cw6/GHSA-v6q2-4qr3-5cw6.json index 07b84d9c4a0..33f63e913f9 100644 --- a/advisories/github-reviewed/2024/03/GHSA-v6q2-4qr3-5cw6/GHSA-v6q2-4qr3-5cw6.json +++ b/advisories/github-reviewed/2024/03/GHSA-v6q2-4qr3-5cw6/GHSA-v6q2-4qr3-5cw6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v6q2-4qr3-5cw6", - "modified": "2024-03-18T20:33:32Z", + "modified": "2024-03-19T18:31:16Z", "published": "2024-03-18T20:33:32Z", "aliases": [ "CVE-2024-28250" @@ -59,18 +59,34 @@ "type": "WEB", "url": "https://github.com/cilium/cilium/security/advisories/GHSA-v6q2-4qr3-5cw6" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28250" + }, { "type": "PACKAGE", "url": "https://github.com/cilium/cilium" + }, + { + "type": "WEB", + "url": "https://github.com/cilium/cilium/releases/tag/v1.13.13" + }, + { + "type": "WEB", + "url": "https://github.com/cilium/cilium/releases/tag/v1.14.8" + }, + { + "type": "WEB", + "url": "https://github.com/cilium/cilium/releases/tag/v1.15.2" } ], "database_specific": { "cwe_ids": [ - + "CWE-311" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-03-18T20:33:32Z", - "nvd_published_at": null + "nvd_published_at": "2024-03-18T22:15:08Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2024/03/GHSA-wj85-w4f4-xh8h/GHSA-wj85-w4f4-xh8h.json b/advisories/github-reviewed/2024/03/GHSA-wj85-w4f4-xh8h/GHSA-wj85-w4f4-xh8h.json index da9e6ed9a93..53f4f48734d 100644 --- a/advisories/github-reviewed/2024/03/GHSA-wj85-w4f4-xh8h/GHSA-wj85-w4f4-xh8h.json +++ b/advisories/github-reviewed/2024/03/GHSA-wj85-w4f4-xh8h/GHSA-wj85-w4f4-xh8h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wj85-w4f4-xh8h", - "modified": "2024-03-18T20:37:48Z", + "modified": "2024-03-19T18:30:57Z", "published": "2024-03-18T20:37:48Z", "aliases": [ "CVE-2024-28865" @@ -40,6 +40,10 @@ "type": "WEB", "url": "https://github.com/django-wiki/django-wiki/security/advisories/GHSA-wj85-w4f4-xh8h" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28865" + }, { "type": "WEB", "url": "https://github.com/django-wiki/django-wiki/commit/8e280fd6c0bd27ce847c67b2d216c6cbf920f88c" @@ -56,6 +60,6 @@ "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-03-18T20:37:48Z", - "nvd_published_at": null + "nvd_published_at": "2024-03-18T22:15:09Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2024/03/GHSA-x7mf-wrh9-r76c/GHSA-x7mf-wrh9-r76c.json b/advisories/github-reviewed/2024/03/GHSA-x7mf-wrh9-r76c/GHSA-x7mf-wrh9-r76c.json index cbc97b21525..4ec181cbdf6 100644 --- a/advisories/github-reviewed/2024/03/GHSA-x7mf-wrh9-r76c/GHSA-x7mf-wrh9-r76c.json +++ b/advisories/github-reviewed/2024/03/GHSA-x7mf-wrh9-r76c/GHSA-x7mf-wrh9-r76c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x7mf-wrh9-r76c", - "modified": "2024-03-18T20:29:45Z", + "modified": "2024-03-19T18:31:36Z", "published": "2024-03-18T20:29:45Z", "aliases": [ "CVE-2024-28237" @@ -43,6 +43,10 @@ "type": "WEB", "url": "https://github.com/OctoPrint/OctoPrint/security/advisories/GHSA-x7mf-wrh9-r76c" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28237" + }, { "type": "WEB", "url": "https://github.com/OctoPrint/OctoPrint/commit/779894c1bc6478332d14bc9ed1006df1354eb517" @@ -59,6 +63,6 @@ "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-03-18T20:29:45Z", - "nvd_published_at": null + "nvd_published_at": "2024-03-18T22:15:07Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-53qf-272p-ghf6/GHSA-53qf-272p-ghf6.json b/advisories/unreviewed/2022/05/GHSA-53qf-272p-ghf6/GHSA-53qf-272p-ghf6.json index efb662a9fd1..a59ac8fc0bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-53qf-272p-ghf6/GHSA-53qf-272p-ghf6.json +++ b/advisories/unreviewed/2022/05/GHSA-53qf-272p-ghf6/GHSA-53qf-272p-ghf6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-53qf-272p-ghf6", - "modified": "2022-05-24T19:08:11Z", + "modified": "2024-03-19T18:31:58Z", "published": "2022-05-24T19:08:11Z", "aliases": [ "CVE-2021-29725" ], "details": "IBM Secure External Authentication Server 2.4.3.2, 6.0.1, 6.0.2 and IBM Secure Proxy 3.4.3.2, 6.0.1, 6.0.2 could allow a remote user to consume resources causing a denial of service due to a resource leak.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-6q52-mr9g-rhrv/GHSA-6q52-mr9g-rhrv.json b/advisories/unreviewed/2022/05/GHSA-6q52-mr9g-rhrv/GHSA-6q52-mr9g-rhrv.json index 38a6e0a3f6d..c4ea86bffca 100644 --- a/advisories/unreviewed/2022/05/GHSA-6q52-mr9g-rhrv/GHSA-6q52-mr9g-rhrv.json +++ b/advisories/unreviewed/2022/05/GHSA-6q52-mr9g-rhrv/GHSA-6q52-mr9g-rhrv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6q52-mr9g-rhrv", - "modified": "2022-05-24T19:08:11Z", + "modified": "2024-03-19T18:31:58Z", "published": "2022-05-24T19:08:11Z", "aliases": [ "CVE-2021-29749" ], "details": "IBM Secure External Authentication Server 6.0.2 and IBM Secure Proxy 6.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 201777.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-vgxc-rq2p-x5qw/GHSA-vgxc-rq2p-x5qw.json b/advisories/unreviewed/2022/05/GHSA-vgxc-rq2p-x5qw/GHSA-vgxc-rq2p-x5qw.json index ece0e3b50c5..55469a1a9f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-vgxc-rq2p-x5qw/GHSA-vgxc-rq2p-x5qw.json +++ b/advisories/unreviewed/2022/05/GHSA-vgxc-rq2p-x5qw/GHSA-vgxc-rq2p-x5qw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vgxc-rq2p-x5qw", - "modified": "2022-05-24T17:16:59Z", + "modified": "2024-03-19T18:31:58Z", "published": "2022-05-24T17:16:59Z", "aliases": [ "CVE-2020-12101" ], "details": "The address-management feature in xt:Commerce 5.1 to 6.2.2 allows remote authenticated users to zero out other user's stored addresses by manipulating an id field in the POST request for altering an address.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -37,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-xwf4-g3q4-g8hc/GHSA-xwf4-g3q4-g8hc.json b/advisories/unreviewed/2022/05/GHSA-xwf4-g3q4-g8hc/GHSA-xwf4-g3q4-g8hc.json index bb4c81ea924..c8da338c1da 100644 --- a/advisories/unreviewed/2022/05/GHSA-xwf4-g3q4-g8hc/GHSA-xwf4-g3q4-g8hc.json +++ b/advisories/unreviewed/2022/05/GHSA-xwf4-g3q4-g8hc/GHSA-xwf4-g3q4-g8hc.json @@ -49,7 +49,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-p788-v6c7-5vqg/GHSA-p788-v6c7-5vqg.json b/advisories/unreviewed/2023/08/GHSA-p788-v6c7-5vqg/GHSA-p788-v6c7-5vqg.json index 3597ef28ee6..5b9988b6fab 100644 --- a/advisories/unreviewed/2023/08/GHSA-p788-v6c7-5vqg/GHSA-p788-v6c7-5vqg.json +++ b/advisories/unreviewed/2023/08/GHSA-p788-v6c7-5vqg/GHSA-p788-v6c7-5vqg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p788-v6c7-5vqg", - "modified": "2024-03-19T06:30:52Z", + "modified": "2024-03-19T18:31:58Z", "published": "2023-08-21T21:31:23Z", "aliases": [ "CVE-2023-4459" @@ -41,6 +41,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:1367" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1382" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-4459" diff --git a/advisories/unreviewed/2024/01/GHSA-mmc5-hgpc-m8q5/GHSA-mmc5-hgpc-m8q5.json b/advisories/unreviewed/2024/01/GHSA-mmc5-hgpc-m8q5/GHSA-mmc5-hgpc-m8q5.json index d7efb112772..ad28b559895 100644 --- a/advisories/unreviewed/2024/01/GHSA-mmc5-hgpc-m8q5/GHSA-mmc5-hgpc-m8q5.json +++ b/advisories/unreviewed/2024/01/GHSA-mmc5-hgpc-m8q5/GHSA-mmc5-hgpc-m8q5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mmc5-hgpc-m8q5", - "modified": "2024-03-19T06:30:52Z", + "modified": "2024-03-19T18:31:58Z", "published": "2024-01-02T21:30:25Z", "aliases": [ "CVE-2023-7192" @@ -45,6 +45,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:1367" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1382" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-7192" diff --git a/advisories/unreviewed/2024/01/GHSA-qmff-49xc-7rf6/GHSA-qmff-49xc-7rf6.json b/advisories/unreviewed/2024/01/GHSA-qmff-49xc-7rf6/GHSA-qmff-49xc-7rf6.json index 805d2323ad0..cfdd0aff14a 100644 --- a/advisories/unreviewed/2024/01/GHSA-qmff-49xc-7rf6/GHSA-qmff-49xc-7rf6.json +++ b/advisories/unreviewed/2024/01/GHSA-qmff-49xc-7rf6/GHSA-qmff-49xc-7rf6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qmff-49xc-7rf6", - "modified": "2024-03-19T06:30:52Z", + "modified": "2024-03-19T18:31:58Z", "published": "2024-01-17T18:31:36Z", "aliases": [ "CVE-2024-0646" @@ -33,6 +33,14 @@ "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-0646" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1382" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1377" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:1368" diff --git a/advisories/unreviewed/2024/02/GHSA-6v6c-gc45-x65c/GHSA-6v6c-gc45-x65c.json b/advisories/unreviewed/2024/02/GHSA-6v6c-gc45-x65c/GHSA-6v6c-gc45-x65c.json index e34c0a0e2c3..71cab406400 100644 --- a/advisories/unreviewed/2024/02/GHSA-6v6c-gc45-x65c/GHSA-6v6c-gc45-x65c.json +++ b/advisories/unreviewed/2024/02/GHSA-6v6c-gc45-x65c/GHSA-6v6c-gc45-x65c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6v6c-gc45-x65c", - "modified": "2024-03-05T06:30:41Z", + "modified": "2024-03-19T18:31:58Z", "published": "2024-02-12T15:30:23Z", "aliases": [ "CVE-2024-1062" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:1074" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1372" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-1062" diff --git a/advisories/unreviewed/2024/02/GHSA-cjwx-wwmv-rqgc/GHSA-cjwx-wwmv-rqgc.json b/advisories/unreviewed/2024/02/GHSA-cjwx-wwmv-rqgc/GHSA-cjwx-wwmv-rqgc.json index dceb5116614..5bbadf72b6a 100644 --- a/advisories/unreviewed/2024/02/GHSA-cjwx-wwmv-rqgc/GHSA-cjwx-wwmv-rqgc.json +++ b/advisories/unreviewed/2024/02/GHSA-cjwx-wwmv-rqgc/GHSA-cjwx-wwmv-rqgc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cjwx-wwmv-rqgc", - "modified": "2024-02-21T18:31:00Z", + "modified": "2024-03-19T18:31:58Z", "published": "2024-02-21T18:31:00Z", "aliases": [ "CVE-2022-45169" ], "details": "An issue was discovered in LIVEBOX Collaboration vDesk through v031. A URL Redirection to an Untrusted Site (Open Redirect) can occur under the /api/v1/notification/createnotification endpoint, allowing an authenticated user to send an arbitrary push notification to any other user of the system. This push notification can include an (invisible) clickable link.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-601" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T16:15:49Z" diff --git a/advisories/unreviewed/2024/02/GHSA-g759-2x5w-f89c/GHSA-g759-2x5w-f89c.json b/advisories/unreviewed/2024/02/GHSA-g759-2x5w-f89c/GHSA-g759-2x5w-f89c.json index db9165a5aff..df48e72f046 100644 --- a/advisories/unreviewed/2024/02/GHSA-g759-2x5w-f89c/GHSA-g759-2x5w-f89c.json +++ b/advisories/unreviewed/2024/02/GHSA-g759-2x5w-f89c/GHSA-g759-2x5w-f89c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g759-2x5w-f89c", - "modified": "2024-02-21T18:31:00Z", + "modified": "2024-03-19T18:31:58Z", "published": "2024-02-21T18:31:00Z", "aliases": [ "CVE-2022-45177" ], "details": "An issue was discovered in LIVEBOX Collaboration vDesk through v031. An Observable Response Discrepancy can occur under the /api/v1/vdeskintegration/user/isenableuser endpoint, the /api/v1/sharedsearch?search={NAME]+{SURNAME] endpoint, and the /login endpoint. The web application provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-203" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T16:15:49Z" diff --git a/advisories/unreviewed/2024/02/GHSA-w32h-6ffq-r68m/GHSA-w32h-6ffq-r68m.json b/advisories/unreviewed/2024/02/GHSA-w32h-6ffq-r68m/GHSA-w32h-6ffq-r68m.json index 31eefabaabe..dc532c9941c 100644 --- a/advisories/unreviewed/2024/02/GHSA-w32h-6ffq-r68m/GHSA-w32h-6ffq-r68m.json +++ b/advisories/unreviewed/2024/02/GHSA-w32h-6ffq-r68m/GHSA-w32h-6ffq-r68m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w32h-6ffq-r68m", - "modified": "2024-02-21T18:31:00Z", + "modified": "2024-03-19T18:31:58Z", "published": "2024-02-21T18:31:00Z", "aliases": [ "CVE-2022-45179" ], "details": "An issue was discovered in LIVEBOX Collaboration vDesk through v031. A basic XSS vulnerability exists under the /api/v1/vdeskintegration/todo/createorupdate endpoint via the title parameter and /dashboard/reminders. A remote user (authenticated to the product) can store arbitrary HTML code in the reminder section title in order to corrupt the web page (for example, by creating phishing sections to exfiltrate victims' credentials).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T16:15:49Z" diff --git a/advisories/unreviewed/2024/03/GHSA-23h2-xqvf-mj5r/GHSA-23h2-xqvf-mj5r.json b/advisories/unreviewed/2024/03/GHSA-23h2-xqvf-mj5r/GHSA-23h2-xqvf-mj5r.json new file mode 100644 index 00000000000..7a950158b5d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-23h2-xqvf-mj5r/GHSA-23h2-xqvf-mj5r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23h2-xqvf-mj5r", + "modified": "2024-03-19T18:32:01Z", + "published": "2024-03-19T18:32:01Z", + "aliases": [ + "CVE-2024-27996" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Survey Maker team Survey Maker allows Stored XSS.This issue affects Survey Maker: from n/a through 4.0.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27996" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/survey-maker/wordpress-survey-maker-plugin-4-0-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-258w-hr8p-8679/GHSA-258w-hr8p-8679.json b/advisories/unreviewed/2024/03/GHSA-258w-hr8p-8679/GHSA-258w-hr8p-8679.json new file mode 100644 index 00000000000..402104ea345 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-258w-hr8p-8679/GHSA-258w-hr8p-8679.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-258w-hr8p-8679", + "modified": "2024-03-19T18:31:59Z", + "published": "2024-03-19T18:31:59Z", + "aliases": [ + "CVE-2023-32260" + ], + "details": "Misinterpretation of Input vulnerability in OpenText™ Service Management Automation X (SMAX), OpenText™ Asset Management X (AMX), and OpenText™ Hybrid Cloud Management X (HCMX) products. The vulnerability could allow Input data manipulation.This issue affects Service Management Automation X (SMAX) versions: 2020.05, 2020.08, 2020.11, 2021.02, 2021.05, 2021.08, 2021.11, 2022.05, 2022.11, 2023.05; Asset Management X (AMX) versions: 2021.08, 2021.11, 2022.05, 2022.11, 2023.05; and Hybrid Cloud Management X (HCMX) versions: 2020.05, 2020.08, 2020.11, 2021.02, 2021.05, 2021.08, 2021.11, 2022.05, 2022.11, 2023.05.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32260" + }, + { + "type": "WEB", + "url": "https://portal.microfocus.com/s/article/KM000018804?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-115" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-2pjj-hxjr-qjx5/GHSA-2pjj-hxjr-qjx5.json b/advisories/unreviewed/2024/03/GHSA-2pjj-hxjr-qjx5/GHSA-2pjj-hxjr-qjx5.json new file mode 100644 index 00000000000..f65cc9ed3ee --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-2pjj-hxjr-qjx5/GHSA-2pjj-hxjr-qjx5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2pjj-hxjr-qjx5", + "modified": "2024-03-19T18:32:00Z", + "published": "2024-03-19T18:32:00Z", + "aliases": [ + "CVE-2024-29101" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jegtheme Jeg Elementor Kit allows Stored XSS.This issue affects Jeg Elementor Kit: from n/a through 2.6.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29101" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/jeg-elementor-kit/wordpress-jeg-elementor-kit-plugin-2-6-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T16:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-32wr-m3hg-4r8x/GHSA-32wr-m3hg-4r8x.json b/advisories/unreviewed/2024/03/GHSA-32wr-m3hg-4r8x/GHSA-32wr-m3hg-4r8x.json new file mode 100644 index 00000000000..63fc60393cc --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-32wr-m3hg-4r8x/GHSA-32wr-m3hg-4r8x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32wr-m3hg-4r8x", + "modified": "2024-03-19T18:32:00Z", + "published": "2024-03-19T18:32:00Z", + "aliases": [ + "CVE-2024-29108" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leevio Happy Addons for Elementor allows Stored XSS.This issue affects Happy Addons for Elementor: from n/a through 3.10.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29108" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/happy-elementor-addons/wordpress-happy-addons-for-elementor-plugin-3-10-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T16:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-3442-jw62-mjxj/GHSA-3442-jw62-mjxj.json b/advisories/unreviewed/2024/03/GHSA-3442-jw62-mjxj/GHSA-3442-jw62-mjxj.json new file mode 100644 index 00000000000..f33bcfc361a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-3442-jw62-mjxj/GHSA-3442-jw62-mjxj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3442-jw62-mjxj", + "modified": "2024-03-19T18:32:02Z", + "published": "2024-03-19T18:32:02Z", + "aliases": [ + "CVE-2024-29093" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Tobias Conrad Builder for WooCommerce reviews shortcodes – ReviewShort.This issue affects Builder for WooCommerce reviews shortcodes – ReviewShort: from n/a through 1.01.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29093" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woo-product-reviews-shortcode/wordpress-builder-for-woocommerce-reviews-shortcodes-reviewshort-plugin-1-01-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-34h5-53fh-qqxm/GHSA-34h5-53fh-qqxm.json b/advisories/unreviewed/2024/03/GHSA-34h5-53fh-qqxm/GHSA-34h5-53fh-qqxm.json new file mode 100644 index 00000000000..6733fa75cfb --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-34h5-53fh-qqxm/GHSA-34h5-53fh-qqxm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-34h5-53fh-qqxm", + "modified": "2024-03-19T18:31:59Z", + "published": "2024-03-19T18:31:59Z", + "aliases": [ + "CVE-2024-29099" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Evergreen Content Poster allows Reflected XSS.This issue affects Evergreen Content Poster: from n/a through 1.4.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29099" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/evergreen-content-poster/wordpress-evergreen-content-poster-plugin-1-4-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-38p6-v2j3-42g3/GHSA-38p6-v2j3-42g3.json b/advisories/unreviewed/2024/03/GHSA-38p6-v2j3-42g3/GHSA-38p6-v2j3-42g3.json new file mode 100644 index 00000000000..c43613f864c --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-38p6-v2j3-42g3/GHSA-38p6-v2j3-42g3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38p6-v2j3-42g3", + "modified": "2024-03-19T18:32:02Z", + "published": "2024-03-19T18:32:02Z", + "aliases": [ + "CVE-2024-27998" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager allows Reflected XSS.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27998" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/barcode-scanner-lite-pos-to-manage-products-inventory-and-orders/wordpress-barcode-scanner-and-inventory-manager-plugin-1-5-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-4f26-4vvc-h29q/GHSA-4f26-4vvc-h29q.json b/advisories/unreviewed/2024/03/GHSA-4f26-4vvc-h29q/GHSA-4f26-4vvc-h29q.json new file mode 100644 index 00000000000..7eafbefbadf --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-4f26-4vvc-h29q/GHSA-4f26-4vvc-h29q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4f26-4vvc-h29q", + "modified": "2024-03-19T18:31:59Z", + "published": "2024-03-19T18:31:59Z", + "aliases": [ + "CVE-2024-29096" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matt Manning MJM Clinic.This issue affects MJM Clinic: from n/a through 1.1.22.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29096" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mjm-clinic/wordpress-mjm-clinic-plugin-1-1-22-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-59qh-jj75-jj6w/GHSA-59qh-jj75-jj6w.json b/advisories/unreviewed/2024/03/GHSA-59qh-jj75-jj6w/GHSA-59qh-jj75-jj6w.json new file mode 100644 index 00000000000..b7440dfcd51 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-59qh-jj75-jj6w/GHSA-59qh-jj75-jj6w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59qh-jj75-jj6w", + "modified": "2024-03-19T18:31:59Z", + "published": "2024-03-19T18:31:59Z", + "aliases": [ + "CVE-2024-29098" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Calameo WP Calameo allows Stored XSS.This issue affects WP Calameo: from n/a through 2.1.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29098" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-calameo/wordpress-wp-calameo-plugin-2-1-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-64jx-m9pq-gr8c/GHSA-64jx-m9pq-gr8c.json b/advisories/unreviewed/2024/03/GHSA-64jx-m9pq-gr8c/GHSA-64jx-m9pq-gr8c.json new file mode 100644 index 00000000000..64c67a015d8 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-64jx-m9pq-gr8c/GHSA-64jx-m9pq-gr8c.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-64jx-m9pq-gr8c", + "modified": "2024-03-19T18:32:02Z", + "published": "2024-03-19T18:32:02Z", + "aliases": [ + "CVE-2024-2307" + ], + "details": "A flaw was found in osbuild-composer. A condition can be triggered that disables GPG verification for package repositories, which can expose the build phase to a Man-in-the-Middle attack, allowing untrusted code to be installed into an image being built.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2307" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-2307" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2268513" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-347" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-6jjp-3pp9-h253/GHSA-6jjp-3pp9-h253.json b/advisories/unreviewed/2024/03/GHSA-6jjp-3pp9-h253/GHSA-6jjp-3pp9-h253.json new file mode 100644 index 00000000000..fb7e77cceae --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-6jjp-3pp9-h253/GHSA-6jjp-3pp9-h253.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jjp-3pp9-h253", + "modified": "2024-03-19T18:31:59Z", + "published": "2024-03-19T18:31:59Z", + "aliases": [ + "CVE-2023-32259" + ], + "details": "Insufficient Granularity of Access Control vulnerability in OpenText™ Service Management Automation X (SMAX), OpenText™ Asset Management X (AMX) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Service Management Automation X (SMAX) versions 2020.05, 2020.08, 2020.11, 2021.02, 2021.05, 2021.08, 2021.11, 2022.05, 2022.11; and Asset Management X (AMX) versions 2021.08, 2021.11, 2022.05, 2022.11.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32259" + }, + { + "type": "WEB", + "url": "https://portal.microfocus.com/s/article/KM000018803?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1220" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-797f-63wg-8chv/GHSA-797f-63wg-8chv.json b/advisories/unreviewed/2024/03/GHSA-797f-63wg-8chv/GHSA-797f-63wg-8chv.json new file mode 100644 index 00000000000..41320c43398 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-797f-63wg-8chv/GHSA-797f-63wg-8chv.json @@ -0,0 +1,66 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-797f-63wg-8chv", + "modified": "2024-03-19T18:31:59Z", + "published": "2024-03-19T18:31:59Z", + "aliases": [ + "CVE-2023-6597" + ], + "details": "An issue was found in the CPython `tempfile.TemporaryDirectory` class affecting versions 3.12.2, 3.11.8, 3.10.13, 3.9.18, and 3.8.18 and prior.\n\nThe tempfile.TemporaryDirectory class would dereference symlinks during cleanup of permissions-related errors. This means users which can run privileged programs are potentially able to modify permissions of files referenced by symlinks in some circumstances.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6597" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/issues/91133" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/02a9259c717738dfe6b463c44d7e17f2b6d2cb3a" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/5585334d772b253a01a6730e8202ffb1607c3d25" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/6ceb8aeda504b079fef7a57b8d81472f15cdd9a5" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/81c16cd94ec38d61aa478b9a452436dc3b1b524d" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/8eaeefe49d179ca4908d052745e3bb8b6f238f82" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/d54e22a669ae6e987199bb5d2c69bb5a46b0083b" + }, + { + "type": "WEB", + "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/Q5C6ATFC67K53XFV4KE45325S7NS62LD" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-8wmf-4j4m-q5h7/GHSA-8wmf-4j4m-q5h7.json b/advisories/unreviewed/2024/03/GHSA-8wmf-4j4m-q5h7/GHSA-8wmf-4j4m-q5h7.json new file mode 100644 index 00000000000..e630f5ccd2a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-8wmf-4j4m-q5h7/GHSA-8wmf-4j4m-q5h7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wmf-4j4m-q5h7", + "modified": "2024-03-19T18:32:00Z", + "published": "2024-03-19T18:32:00Z", + "aliases": [ + "CVE-2023-41793" + ], + "details": ": Path Traversal vulnerability in Pandora FMS on all allows Path Traversal. This vulnerability allowed changing directories and creating files and downloading them outside the allowed directories. This issue affects Pandora FMS: from 700 through <776.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41793" + }, + { + "type": "WEB", + "url": "https://pandorafms.com/en/security/common-vulnerabilities-and-exposures" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-c65x-frp2-5rxx/GHSA-c65x-frp2-5rxx.json b/advisories/unreviewed/2024/03/GHSA-c65x-frp2-5rxx/GHSA-c65x-frp2-5rxx.json new file mode 100644 index 00000000000..db31eda483e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-c65x-frp2-5rxx/GHSA-c65x-frp2-5rxx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c65x-frp2-5rxx", + "modified": "2024-03-19T18:31:59Z", + "published": "2024-03-19T18:31:59Z", + "aliases": [ + "CVE-2024-29095" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Ryley Site Reviews allows Stored XSS.This issue affects Site Reviews: from n/a through 6.11.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29095" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/site-reviews/wordpress-site-reviews-plugin-6-11-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-cxcr-v85c-3586/GHSA-cxcr-v85c-3586.json b/advisories/unreviewed/2024/03/GHSA-cxcr-v85c-3586/GHSA-cxcr-v85c-3586.json new file mode 100644 index 00000000000..b555c165780 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-cxcr-v85c-3586/GHSA-cxcr-v85c-3586.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxcr-v85c-3586", + "modified": "2024-03-19T18:32:02Z", + "published": "2024-03-19T18:32:02Z", + "aliases": [ + "CVE-2024-2442" + ], + "details": "\nFranklin Fueling System EVO 550 and EVO 5000 are vulnerable to a Path Traversal vulnerability that could allow an attacker to access sensitive files on the system.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2442" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-079-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-25" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-f66m-qchm-mq7g/GHSA-f66m-qchm-mq7g.json b/advisories/unreviewed/2024/03/GHSA-f66m-qchm-mq7g/GHSA-f66m-qchm-mq7g.json new file mode 100644 index 00000000000..8b351fc6a0d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-f66m-qchm-mq7g/GHSA-f66m-qchm-mq7g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f66m-qchm-mq7g", + "modified": "2024-03-19T18:31:59Z", + "published": "2024-03-19T18:31:59Z", + "aliases": [ + "CVE-2024-29097" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins User profile allows Stored XSS.This issue affects User profile: from n/a through 2.0.20.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29097" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/user-profile/wordpress-user-profile-plugin-2-0-20-subscriber-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-fm9f-6ch9-98r6/GHSA-fm9f-6ch9-98r6.json b/advisories/unreviewed/2024/03/GHSA-fm9f-6ch9-98r6/GHSA-fm9f-6ch9-98r6.json new file mode 100644 index 00000000000..01109f3ab18 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-fm9f-6ch9-98r6/GHSA-fm9f-6ch9-98r6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fm9f-6ch9-98r6", + "modified": "2024-03-19T18:32:02Z", + "published": "2024-03-19T18:32:02Z", + "aliases": [ + "CVE-2024-29091" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dnesscarkey WP Armour – Honeypot Anti Spam allows Reflected XSS.This issue affects WP Armour – Honeypot Anti Spam: from n/a through 2.1.13.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29091" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/honeypot/wordpress-wp-armour-plugin-2-1-13-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-fq86-8676-6j38/GHSA-fq86-8676-6j38.json b/advisories/unreviewed/2024/03/GHSA-fq86-8676-6j38/GHSA-fq86-8676-6j38.json new file mode 100644 index 00000000000..9872d7b01fb --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-fq86-8676-6j38/GHSA-fq86-8676-6j38.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fq86-8676-6j38", + "modified": "2024-03-19T18:32:00Z", + "published": "2024-03-19T18:32:00Z", + "aliases": [ + "CVE-2023-42920" + ], + "details": "Claris International has fixed a dylib hijacking vulnerability in the FileMaker Pro.app and Claris Pro.app versions on macOS.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42920" + }, + { + "type": "WEB", + "url": "https://support.claris.com/s/article/FileMaker-Security-Information?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-g8x5-cvgc-4hjw/GHSA-g8x5-cvgc-4hjw.json b/advisories/unreviewed/2024/03/GHSA-g8x5-cvgc-4hjw/GHSA-g8x5-cvgc-4hjw.json new file mode 100644 index 00000000000..0aa2651ac10 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-g8x5-cvgc-4hjw/GHSA-g8x5-cvgc-4hjw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8x5-cvgc-4hjw", + "modified": "2024-03-19T18:32:00Z", + "published": "2024-03-19T18:32:00Z", + "aliases": [ + "CVE-2024-29105" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Timersys WP Popups allows Stored XSS.This issue affects WP Popups: from n/a through 2.1.5.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29105" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-popups-lite/wordpress-wp-popups-wordpress-popup-builder-plugin-2-1-5-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T16:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-h385-vvhp-wmmp/GHSA-h385-vvhp-wmmp.json b/advisories/unreviewed/2024/03/GHSA-h385-vvhp-wmmp/GHSA-h385-vvhp-wmmp.json new file mode 100644 index 00000000000..6b1f89906de --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-h385-vvhp-wmmp/GHSA-h385-vvhp-wmmp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h385-vvhp-wmmp", + "modified": "2024-03-19T18:32:02Z", + "published": "2024-03-19T18:32:02Z", + "aliases": [ + "CVE-2024-29094" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Easy GA4 ( Google Analytics 4 ) allows Stored XSS.This issue affects HT Easy GA4 ( Google Analytics 4 ): from n/a through 1.1.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29094" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ht-easy-google-analytics/wordpress-ht-easy-ga4-plugin-1-1-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-jm46-725r-hh9v/GHSA-jm46-725r-hh9v.json b/advisories/unreviewed/2024/03/GHSA-jm46-725r-hh9v/GHSA-jm46-725r-hh9v.json new file mode 100644 index 00000000000..c1a80ccadfe --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-jm46-725r-hh9v/GHSA-jm46-725r-hh9v.json @@ -0,0 +1,70 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jm46-725r-hh9v", + "modified": "2024-03-19T18:31:59Z", + "published": "2024-03-19T18:31:59Z", + "aliases": [ + "CVE-2024-0450" + ], + "details": "An issue was found in the CPython `zipfile` module affecting versions 3.12.2, 3.11.8, 3.10.13, 3.9.18, and 3.8.18 and prior.\n\nThe zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0450" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/issues/109858" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/30fe5d853b56138dbec62432d370a1f99409fc85" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/66363b9a7b9fe7c99eba3a185b74c5fdbf842eba" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/a2c59992e9e8d35baba9695eb186ad6c6ff85c51" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/a956e510f6336d5ae111ba429a61c3ade30a7549" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/d05bac0b74153beb541b88b4fca33bf053990183" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/fa181fcf2156f703347b03a3b1966ce47be8ab3b" + }, + { + "type": "WEB", + "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/XELNUX2L3IOHBTFU7RQHCY6OUVEWZ2FG" + }, + { + "type": "WEB", + "url": "https://www.bamsoftware.com/hacks/zipbomb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-405" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-m246-cqg8-m3p3/GHSA-m246-cqg8-m3p3.json b/advisories/unreviewed/2024/03/GHSA-m246-cqg8-m3p3/GHSA-m246-cqg8-m3p3.json new file mode 100644 index 00000000000..3307619789f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-m246-cqg8-m3p3/GHSA-m246-cqg8-m3p3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m246-cqg8-m3p3", + "modified": "2024-03-19T18:32:00Z", + "published": "2024-03-19T18:32:00Z", + "aliases": [ + "CVE-2024-29106" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leap13 Premium Addons for Elementor allows Stored XSS.This issue affects Premium Addons for Elementor: from n/a through 4.10.16.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29106" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/premium-addons-for-elementor/wordpress-premium-addons-for-elementor-plugin-4-10-16-cross-site-scripting-xss-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T16:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-m489-r2q4-329w/GHSA-m489-r2q4-329w.json b/advisories/unreviewed/2024/03/GHSA-m489-r2q4-329w/GHSA-m489-r2q4-329w.json new file mode 100644 index 00000000000..39cfb7bb4e3 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-m489-r2q4-329w/GHSA-m489-r2q4-329w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m489-r2q4-329w", + "modified": "2024-03-19T18:32:01Z", + "published": "2024-03-19T18:32:01Z", + "aliases": [ + "CVE-2024-27997" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visualcomposer Visual Composer Website Builder allows Stored XSS.This issue affects Visual Composer Website Builder: from n/a through 45.6.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27997" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/visualcomposer/wordpress-visual-composer-website-builder-landing-page-builder-custom-theme-builder-maintenance-mode-coming-soon-pages-plugin-45-6-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-m59h-jq6c-5ph6/GHSA-m59h-jq6c-5ph6.json b/advisories/unreviewed/2024/03/GHSA-m59h-jq6c-5ph6/GHSA-m59h-jq6c-5ph6.json new file mode 100644 index 00000000000..2a90cef62cb --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-m59h-jq6c-5ph6/GHSA-m59h-jq6c-5ph6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m59h-jq6c-5ph6", + "modified": "2024-03-19T18:32:01Z", + "published": "2024-03-19T18:32:01Z", + "aliases": [ + "CVE-2023-44092" + ], + "details": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Pandora FMS on all allows OS Command Injection. This vulnerability allowed to create a reverse shell and execute commands in the OS. This issue affects Pandora FMS: from 700 through <776.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44092" + }, + { + "type": "WEB", + "url": "https://pandorafms.com/en/security/common-vulnerabilities-and-exposures" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-m6h6-pgm9-rw33/GHSA-m6h6-pgm9-rw33.json b/advisories/unreviewed/2024/03/GHSA-m6h6-pgm9-rw33/GHSA-m6h6-pgm9-rw33.json new file mode 100644 index 00000000000..590354b9166 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-m6h6-pgm9-rw33/GHSA-m6h6-pgm9-rw33.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6h6-pgm9-rw33", + "modified": "2024-03-19T18:32:01Z", + "published": "2024-03-19T18:32:01Z", + "aliases": [ + "CVE-2023-44091" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. This ulnerability allowed SQL injections to be made even if authentication failed.This issue affects Pandora FMS: from 700 through <776.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44091" + }, + { + "type": "WEB", + "url": "https://pandorafms.com/en/security/common-vulnerabilities-and-exposures" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-p67c-35g3-9pqc/GHSA-p67c-35g3-9pqc.json b/advisories/unreviewed/2024/03/GHSA-p67c-35g3-9pqc/GHSA-p67c-35g3-9pqc.json index 73066a77680..26c62bb060d 100644 --- a/advisories/unreviewed/2024/03/GHSA-p67c-35g3-9pqc/GHSA-p67c-35g3-9pqc.json +++ b/advisories/unreviewed/2024/03/GHSA-p67c-35g3-9pqc/GHSA-p67c-35g3-9pqc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p67c-35g3-9pqc", - "modified": "2024-03-12T18:31:15Z", + "modified": "2024-03-19T18:31:58Z", "published": "2024-03-12T18:31:15Z", "aliases": [ "CVE-2024-2182" @@ -21,6 +21,42 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2182" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1385" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1386" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1387" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1388" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1390" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1391" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1392" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1393" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1394" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-2182" diff --git a/advisories/unreviewed/2024/03/GHSA-p6m6-8fwj-8w24/GHSA-p6m6-8fwj-8w24.json b/advisories/unreviewed/2024/03/GHSA-p6m6-8fwj-8w24/GHSA-p6m6-8fwj-8w24.json new file mode 100644 index 00000000000..923510808d7 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-p6m6-8fwj-8w24/GHSA-p6m6-8fwj-8w24.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6m6-8fwj-8w24", + "modified": "2024-03-19T18:32:00Z", + "published": "2024-03-19T18:32:00Z", + "aliases": [ + "CVE-2024-29107" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPVibes Elementor Addon Elements allows Stored XSS.This issue affects Elementor Addon Elements: from n/a through 1.12.10.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29107" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/addon-elements-for-elementor-page-builder/wordpress-elementor-addon-elements-plugin-1-12-10-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T16:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-pr6v-87q4-3hj8/GHSA-pr6v-87q4-3hj8.json b/advisories/unreviewed/2024/03/GHSA-pr6v-87q4-3hj8/GHSA-pr6v-87q4-3hj8.json new file mode 100644 index 00000000000..05a374f7203 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-pr6v-87q4-3hj8/GHSA-pr6v-87q4-3hj8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pr6v-87q4-3hj8", + "modified": "2024-03-19T18:32:00Z", + "published": "2024-03-19T18:32:00Z", + "aliases": [ + "CVE-2024-29102" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes Extensions For CF7 allows Stored XSS.This issue affects Extensions For CF7: from n/a through 3.0.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29102" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/extensions-for-cf7/wordpress-extensions-for-cf7-plugin-3-0-6-unauthenticated-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T16:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-q8mf-j7cw-h829/GHSA-q8mf-j7cw-h829.json b/advisories/unreviewed/2024/03/GHSA-q8mf-j7cw-h829/GHSA-q8mf-j7cw-h829.json new file mode 100644 index 00000000000..d9661eea215 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-q8mf-j7cw-h829/GHSA-q8mf-j7cw-h829.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8mf-j7cw-h829", + "modified": "2024-03-19T18:32:01Z", + "published": "2024-03-19T18:32:00Z", + "aliases": [ + "CVE-2023-44090" + ], + "details": "\nImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows CVE-2008-5817. This vulnerability allowed SQL changes to be made to several files in the Grafana module. This issue affects Pandora FMS: from 700 through <776.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44090" + }, + { + "type": "WEB", + "url": "https://pandorafms.com/en/security/common-vulnerabilities-and-exposures" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-qvjv-fjg2-vjmh/GHSA-qvjv-fjg2-vjmh.json b/advisories/unreviewed/2024/03/GHSA-qvjv-fjg2-vjmh/GHSA-qvjv-fjg2-vjmh.json new file mode 100644 index 00000000000..17895636c67 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-qvjv-fjg2-vjmh/GHSA-qvjv-fjg2-vjmh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvjv-fjg2-vjmh", + "modified": "2024-03-19T18:32:00Z", + "published": "2024-03-19T18:32:00Z", + "aliases": [ + "CVE-2024-29104" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zimma Ltd. Ticket Tailor allows Stored XSS.This issue affects Ticket Tailor: from n/a through 1.10.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29104" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ticket-tailor/wordpress-ticket-tailor-plugin-1-10-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T16:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-r827-xvqc-w2g2/GHSA-r827-xvqc-w2g2.json b/advisories/unreviewed/2024/03/GHSA-r827-xvqc-w2g2/GHSA-r827-xvqc-w2g2.json new file mode 100644 index 00000000000..446bd37ae1e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-r827-xvqc-w2g2/GHSA-r827-xvqc-w2g2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r827-xvqc-w2g2", + "modified": "2024-03-19T18:32:02Z", + "published": "2024-03-19T18:32:02Z", + "aliases": [ + "CVE-2024-29089" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Five Star Plugins Five Star Restaurant Menu allows Stored XSS.This issue affects Five Star Restaurant Menu: from n/a through 2.4.14.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29089" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/food-and-drink-menu/wordpress-restaurant-menu-and-food-ordering-plugin-2-4-14-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-rw96-wm4j-gg9f/GHSA-rw96-wm4j-gg9f.json b/advisories/unreviewed/2024/03/GHSA-rw96-wm4j-gg9f/GHSA-rw96-wm4j-gg9f.json new file mode 100644 index 00000000000..efd34bf6ca1 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-rw96-wm4j-gg9f/GHSA-rw96-wm4j-gg9f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rw96-wm4j-gg9f", + "modified": "2024-03-19T18:32:02Z", + "published": "2024-03-19T18:32:02Z", + "aliases": [ + "CVE-2024-29092" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maciej Bis Permalink Manager Lite allows Reflected XSS.This issue affects Permalink Manager Lite: from n/a through 2.4.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29092" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/permalink-manager/wordpress-permalink-manager-lite-plugin-2-4-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-vcmw-wwpg-fvfx/GHSA-vcmw-wwpg-fvfx.json b/advisories/unreviewed/2024/03/GHSA-vcmw-wwpg-fvfx/GHSA-vcmw-wwpg-fvfx.json new file mode 100644 index 00000000000..1dd43025673 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-vcmw-wwpg-fvfx/GHSA-vcmw-wwpg-fvfx.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcmw-wwpg-fvfx", + "modified": "2024-03-19T18:32:01Z", + "published": "2024-03-19T18:32:01Z", + "aliases": [ + "CVE-2024-21677" + ], + "details": "This High severity Path Traversal vulnerability was introduced in version 6.13.0 of Confluence Data Center. This Path Traversal vulnerability, with a CVSS Score of 8.3, allows an unauthenticated attacker to exploit an undefinable vulnerability which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction.\n\nAtlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Data Center Atlassian recommends that Confluence Data Center customers upgrade to the latest version and that Confluence Server customers upgrade to the latest 8.5.x LTS version.\n\nIf you are unable to do so, upgrade your instance to one of the specified supported fixed versions See the release notes https://confluence.atlassian.com/doc/confluence-release-notes-327.html\n\nYou can download the latest version of Confluence Data Center and Server from the download center https://www.atlassian.com/software/confluence/download-archives. \n\nThis vulnerability was reported via our Bug Bounty program.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21677" + }, + { + "type": "WEB", + "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1369444862" + }, + { + "type": "WEB", + "url": "https://jira.atlassian.com/browse/CONFSERVER-94604" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-w7xc-x425-j39c/GHSA-w7xc-x425-j39c.json b/advisories/unreviewed/2024/03/GHSA-w7xc-x425-j39c/GHSA-w7xc-x425-j39c.json new file mode 100644 index 00000000000..3f2afe3c669 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-w7xc-x425-j39c/GHSA-w7xc-x425-j39c.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7xc-x425-j39c", + "modified": "2024-03-19T18:32:01Z", + "published": "2024-03-19T18:32:01Z", + "aliases": [ + "CVE-2023-4426" + ], + "details": "Rejected reason: **REJECT** Not a valid security issue - vendor unable to replicate.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4426" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-xj8c-f7qf-ch6p/GHSA-xj8c-f7qf-ch6p.json b/advisories/unreviewed/2024/03/GHSA-xj8c-f7qf-ch6p/GHSA-xj8c-f7qf-ch6p.json new file mode 100644 index 00000000000..12823b93485 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-xj8c-f7qf-ch6p/GHSA-xj8c-f7qf-ch6p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xj8c-f7qf-ch6p", + "modified": "2024-03-19T18:32:00Z", + "published": "2024-03-19T18:32:00Z", + "aliases": [ + "CVE-2024-29103" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NinjaTeam Database for Contact Form 7 allows Stored XSS.This issue affects Database for Contact Form 7: from n/a through 3.0.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29103" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cf7-database/wordpress-database-for-contact-form-7-plugin-3-0-6-unauthenticated-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T16:15:13Z" + } +} \ No newline at end of file