From 0ae14ebdbf218de6aebdd34448e71a97df1b1e79 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 17 Sep 2024 15:32:55 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-pm8r-m739-j4wf.json | 2 +- .../GHSA-3cch-g7r8-54q2.json | 2 +- .../GHSA-428f-47px-r24v.json | 2 +- .../GHSA-442h-g8gm-9284.json | 2 +- .../GHSA-462r-849p-cx7c.json | 2 +- .../GHSA-5gpr-3236-xvjx.json | 2 +- .../GHSA-5x38-7r9g-7mr7.json | 2 +- .../GHSA-62hx-77pf-xr46.json | 2 +- .../GHSA-7h2f-j5w7-xp8c.json | 2 +- .../GHSA-868v-4v5r-xmhh.json | 2 +- .../GHSA-9j5c-cgmx-gr22.json | 2 +- .../GHSA-9v45-q2j7-r89w.json | 2 +- .../GHSA-f8x3-c29w-wfmj.json | 2 +- .../GHSA-mvqh-rjw3-3ppc.json | 2 +- .../GHSA-p48h-3fvq-h2c5.json | 2 +- .../GHSA-q869-5pvh-pxg9.json | 2 +- .../GHSA-r23h-h8pw-fc6p.json | 2 +- .../GHSA-v5c9-q3g2-rw6f.json | 2 +- .../GHSA-v87v-fqxx-3fpf.json | 2 +- .../GHSA-xq64-r3j5-hcfg.json | 2 +- .../GHSA-59mr-825p-2g28.json | 2 +- .../GHSA-3g8h-47mp-4839.json | 2 +- .../GHSA-3pc3-vcqg-prf6.json | 2 +- .../GHSA-gch4-6c9x-v2fr.json | 6 ++- .../GHSA-hf94-2x3f-x6rc.json | 6 ++- .../GHSA-xrcw-9q57-9frw.json | 6 ++- .../GHSA-2rr2-57v3-7cvx.json | 38 ++++++++++++++++++ .../GHSA-62pp-53wf-pprq.json | 38 ++++++++++++++++++ .../GHSA-653g-mc33-gq3r.json | 9 +++-- .../GHSA-67qp-fprc-rhx4.json | 35 +++++++++++++++++ .../GHSA-6rgh-r6j3-3223.json | 35 +++++++++++++++++ .../GHSA-7v6r-jgcw-v2j9.json | 11 ++++-- .../GHSA-83j8-7m3h-36p8.json | 38 ++++++++++++++++++ .../GHSA-9rm6-368p-665h.json | 38 ++++++++++++++++++ .../GHSA-c5v7-54mg-82m2.json | 38 ++++++++++++++++++ .../GHSA-cwj6-8v2q-g52w.json | 35 +++++++++++++++++ .../GHSA-fvjr-4pf9-7pjq.json | 6 ++- .../GHSA-hj65-9wfc-jmf4.json | 39 +++++++++++++++++++ .../GHSA-j6v2-m8w2-27f8.json | 2 +- .../GHSA-q25c-r482-77p9.json | 35 +++++++++++++++++ .../GHSA-wjg2-c55h-phf5.json | 9 +++-- 41 files changed, 432 insertions(+), 38 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-2rr2-57v3-7cvx/GHSA-2rr2-57v3-7cvx.json create mode 100644 advisories/unreviewed/2024/09/GHSA-62pp-53wf-pprq/GHSA-62pp-53wf-pprq.json create mode 100644 advisories/unreviewed/2024/09/GHSA-67qp-fprc-rhx4/GHSA-67qp-fprc-rhx4.json create mode 100644 advisories/unreviewed/2024/09/GHSA-6rgh-r6j3-3223/GHSA-6rgh-r6j3-3223.json create mode 100644 advisories/unreviewed/2024/09/GHSA-83j8-7m3h-36p8/GHSA-83j8-7m3h-36p8.json create mode 100644 advisories/unreviewed/2024/09/GHSA-9rm6-368p-665h/GHSA-9rm6-368p-665h.json create mode 100644 advisories/unreviewed/2024/09/GHSA-c5v7-54mg-82m2/GHSA-c5v7-54mg-82m2.json create mode 100644 advisories/unreviewed/2024/09/GHSA-cwj6-8v2q-g52w/GHSA-cwj6-8v2q-g52w.json create mode 100644 advisories/unreviewed/2024/09/GHSA-hj65-9wfc-jmf4/GHSA-hj65-9wfc-jmf4.json create mode 100644 advisories/unreviewed/2024/09/GHSA-q25c-r482-77p9/GHSA-q25c-r482-77p9.json diff --git a/advisories/unreviewed/2022/10/GHSA-pm8r-m739-j4wf/GHSA-pm8r-m739-j4wf.json b/advisories/unreviewed/2022/10/GHSA-pm8r-m739-j4wf/GHSA-pm8r-m739-j4wf.json index 3f6c51d9ab7..4194ce125e3 100644 --- a/advisories/unreviewed/2022/10/GHSA-pm8r-m739-j4wf/GHSA-pm8r-m739-j4wf.json +++ b/advisories/unreviewed/2022/10/GHSA-pm8r-m739-j4wf/GHSA-pm8r-m739-j4wf.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-3cch-g7r8-54q2/GHSA-3cch-g7r8-54q2.json b/advisories/unreviewed/2023/01/GHSA-3cch-g7r8-54q2/GHSA-3cch-g7r8-54q2.json index c69a2cce8d8..2adc038d3f9 100644 --- a/advisories/unreviewed/2023/01/GHSA-3cch-g7r8-54q2/GHSA-3cch-g7r8-54q2.json +++ b/advisories/unreviewed/2023/01/GHSA-3cch-g7r8-54q2/GHSA-3cch-g7r8-54q2.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-428f-47px-r24v/GHSA-428f-47px-r24v.json b/advisories/unreviewed/2023/01/GHSA-428f-47px-r24v/GHSA-428f-47px-r24v.json index d1ee151b0b6..e2f760c162a 100644 --- a/advisories/unreviewed/2023/01/GHSA-428f-47px-r24v/GHSA-428f-47px-r24v.json +++ b/advisories/unreviewed/2023/01/GHSA-428f-47px-r24v/GHSA-428f-47px-r24v.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-442h-g8gm-9284/GHSA-442h-g8gm-9284.json b/advisories/unreviewed/2023/01/GHSA-442h-g8gm-9284/GHSA-442h-g8gm-9284.json index a5c50c325bc..477ab7e29fe 100644 --- a/advisories/unreviewed/2023/01/GHSA-442h-g8gm-9284/GHSA-442h-g8gm-9284.json +++ b/advisories/unreviewed/2023/01/GHSA-442h-g8gm-9284/GHSA-442h-g8gm-9284.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-462r-849p-cx7c/GHSA-462r-849p-cx7c.json b/advisories/unreviewed/2023/01/GHSA-462r-849p-cx7c/GHSA-462r-849p-cx7c.json index b35c1d1f3e5..eb0dbf07a19 100644 --- a/advisories/unreviewed/2023/01/GHSA-462r-849p-cx7c/GHSA-462r-849p-cx7c.json +++ b/advisories/unreviewed/2023/01/GHSA-462r-849p-cx7c/GHSA-462r-849p-cx7c.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-5gpr-3236-xvjx/GHSA-5gpr-3236-xvjx.json b/advisories/unreviewed/2023/01/GHSA-5gpr-3236-xvjx/GHSA-5gpr-3236-xvjx.json index 9bb0a85ee56..9ec5451bfca 100644 --- a/advisories/unreviewed/2023/01/GHSA-5gpr-3236-xvjx/GHSA-5gpr-3236-xvjx.json +++ b/advisories/unreviewed/2023/01/GHSA-5gpr-3236-xvjx/GHSA-5gpr-3236-xvjx.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-5x38-7r9g-7mr7/GHSA-5x38-7r9g-7mr7.json b/advisories/unreviewed/2023/01/GHSA-5x38-7r9g-7mr7/GHSA-5x38-7r9g-7mr7.json index d5e4f0c6861..931349a34cc 100644 --- a/advisories/unreviewed/2023/01/GHSA-5x38-7r9g-7mr7/GHSA-5x38-7r9g-7mr7.json +++ b/advisories/unreviewed/2023/01/GHSA-5x38-7r9g-7mr7/GHSA-5x38-7r9g-7mr7.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-62hx-77pf-xr46/GHSA-62hx-77pf-xr46.json b/advisories/unreviewed/2023/01/GHSA-62hx-77pf-xr46/GHSA-62hx-77pf-xr46.json index 75002a0a531..13ce0d408cf 100644 --- a/advisories/unreviewed/2023/01/GHSA-62hx-77pf-xr46/GHSA-62hx-77pf-xr46.json +++ b/advisories/unreviewed/2023/01/GHSA-62hx-77pf-xr46/GHSA-62hx-77pf-xr46.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-7h2f-j5w7-xp8c/GHSA-7h2f-j5w7-xp8c.json b/advisories/unreviewed/2023/01/GHSA-7h2f-j5w7-xp8c/GHSA-7h2f-j5w7-xp8c.json index d0210ac874e..dc7e72a54cb 100644 --- a/advisories/unreviewed/2023/01/GHSA-7h2f-j5w7-xp8c/GHSA-7h2f-j5w7-xp8c.json +++ b/advisories/unreviewed/2023/01/GHSA-7h2f-j5w7-xp8c/GHSA-7h2f-j5w7-xp8c.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-868v-4v5r-xmhh/GHSA-868v-4v5r-xmhh.json b/advisories/unreviewed/2023/01/GHSA-868v-4v5r-xmhh/GHSA-868v-4v5r-xmhh.json index f58c1649a2c..2ec43aecf0a 100644 --- a/advisories/unreviewed/2023/01/GHSA-868v-4v5r-xmhh/GHSA-868v-4v5r-xmhh.json +++ b/advisories/unreviewed/2023/01/GHSA-868v-4v5r-xmhh/GHSA-868v-4v5r-xmhh.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-9j5c-cgmx-gr22/GHSA-9j5c-cgmx-gr22.json b/advisories/unreviewed/2023/01/GHSA-9j5c-cgmx-gr22/GHSA-9j5c-cgmx-gr22.json index 18894c5ba52..0b166273737 100644 --- a/advisories/unreviewed/2023/01/GHSA-9j5c-cgmx-gr22/GHSA-9j5c-cgmx-gr22.json +++ b/advisories/unreviewed/2023/01/GHSA-9j5c-cgmx-gr22/GHSA-9j5c-cgmx-gr22.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-9v45-q2j7-r89w/GHSA-9v45-q2j7-r89w.json b/advisories/unreviewed/2023/01/GHSA-9v45-q2j7-r89w/GHSA-9v45-q2j7-r89w.json index 9f67596a139..d5325d9c1b3 100644 --- a/advisories/unreviewed/2023/01/GHSA-9v45-q2j7-r89w/GHSA-9v45-q2j7-r89w.json +++ b/advisories/unreviewed/2023/01/GHSA-9v45-q2j7-r89w/GHSA-9v45-q2j7-r89w.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-611" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-f8x3-c29w-wfmj/GHSA-f8x3-c29w-wfmj.json b/advisories/unreviewed/2023/01/GHSA-f8x3-c29w-wfmj/GHSA-f8x3-c29w-wfmj.json index 39cf4179d3c..f393a7f3d9c 100644 --- a/advisories/unreviewed/2023/01/GHSA-f8x3-c29w-wfmj/GHSA-f8x3-c29w-wfmj.json +++ b/advisories/unreviewed/2023/01/GHSA-f8x3-c29w-wfmj/GHSA-f8x3-c29w-wfmj.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-mvqh-rjw3-3ppc/GHSA-mvqh-rjw3-3ppc.json b/advisories/unreviewed/2023/01/GHSA-mvqh-rjw3-3ppc/GHSA-mvqh-rjw3-3ppc.json index 1aefaf3febe..f01dd2edf7a 100644 --- a/advisories/unreviewed/2023/01/GHSA-mvqh-rjw3-3ppc/GHSA-mvqh-rjw3-3ppc.json +++ b/advisories/unreviewed/2023/01/GHSA-mvqh-rjw3-3ppc/GHSA-mvqh-rjw3-3ppc.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-p48h-3fvq-h2c5/GHSA-p48h-3fvq-h2c5.json b/advisories/unreviewed/2023/01/GHSA-p48h-3fvq-h2c5/GHSA-p48h-3fvq-h2c5.json index 0e603c53bb2..ff08dc0d18d 100644 --- a/advisories/unreviewed/2023/01/GHSA-p48h-3fvq-h2c5/GHSA-p48h-3fvq-h2c5.json +++ b/advisories/unreviewed/2023/01/GHSA-p48h-3fvq-h2c5/GHSA-p48h-3fvq-h2c5.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-q869-5pvh-pxg9/GHSA-q869-5pvh-pxg9.json b/advisories/unreviewed/2023/01/GHSA-q869-5pvh-pxg9/GHSA-q869-5pvh-pxg9.json index 1857f932955..7938c64c07f 100644 --- a/advisories/unreviewed/2023/01/GHSA-q869-5pvh-pxg9/GHSA-q869-5pvh-pxg9.json +++ b/advisories/unreviewed/2023/01/GHSA-q869-5pvh-pxg9/GHSA-q869-5pvh-pxg9.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-r23h-h8pw-fc6p/GHSA-r23h-h8pw-fc6p.json b/advisories/unreviewed/2023/01/GHSA-r23h-h8pw-fc6p/GHSA-r23h-h8pw-fc6p.json index 4de00abd85f..ae6f45ad0a0 100644 --- a/advisories/unreviewed/2023/01/GHSA-r23h-h8pw-fc6p/GHSA-r23h-h8pw-fc6p.json +++ b/advisories/unreviewed/2023/01/GHSA-r23h-h8pw-fc6p/GHSA-r23h-h8pw-fc6p.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-v5c9-q3g2-rw6f/GHSA-v5c9-q3g2-rw6f.json b/advisories/unreviewed/2023/01/GHSA-v5c9-q3g2-rw6f/GHSA-v5c9-q3g2-rw6f.json index ac64b7060a5..763eae15870 100644 --- a/advisories/unreviewed/2023/01/GHSA-v5c9-q3g2-rw6f/GHSA-v5c9-q3g2-rw6f.json +++ b/advisories/unreviewed/2023/01/GHSA-v5c9-q3g2-rw6f/GHSA-v5c9-q3g2-rw6f.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-v87v-fqxx-3fpf/GHSA-v87v-fqxx-3fpf.json b/advisories/unreviewed/2023/01/GHSA-v87v-fqxx-3fpf/GHSA-v87v-fqxx-3fpf.json index 81ef0044db5..1970591a1c2 100644 --- a/advisories/unreviewed/2023/01/GHSA-v87v-fqxx-3fpf/GHSA-v87v-fqxx-3fpf.json +++ b/advisories/unreviewed/2023/01/GHSA-v87v-fqxx-3fpf/GHSA-v87v-fqxx-3fpf.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-xq64-r3j5-hcfg/GHSA-xq64-r3j5-hcfg.json b/advisories/unreviewed/2023/01/GHSA-xq64-r3j5-hcfg/GHSA-xq64-r3j5-hcfg.json index ac890e9852f..da8e525371f 100644 --- a/advisories/unreviewed/2023/01/GHSA-xq64-r3j5-hcfg/GHSA-xq64-r3j5-hcfg.json +++ b/advisories/unreviewed/2023/01/GHSA-xq64-r3j5-hcfg/GHSA-xq64-r3j5-hcfg.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-59mr-825p-2g28/GHSA-59mr-825p-2g28.json b/advisories/unreviewed/2023/10/GHSA-59mr-825p-2g28/GHSA-59mr-825p-2g28.json index 2f8458417a2..d2be1e5ff61 100644 --- a/advisories/unreviewed/2023/10/GHSA-59mr-825p-2g28/GHSA-59mr-825p-2g28.json +++ b/advisories/unreviewed/2023/10/GHSA-59mr-825p-2g28/GHSA-59mr-825p-2g28.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-3g8h-47mp-4839/GHSA-3g8h-47mp-4839.json b/advisories/unreviewed/2023/11/GHSA-3g8h-47mp-4839/GHSA-3g8h-47mp-4839.json index 77cd16420eb..d3d56f8ae06 100644 --- a/advisories/unreviewed/2023/11/GHSA-3g8h-47mp-4839/GHSA-3g8h-47mp-4839.json +++ b/advisories/unreviewed/2023/11/GHSA-3g8h-47mp-4839/GHSA-3g8h-47mp-4839.json @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-3pc3-vcqg-prf6/GHSA-3pc3-vcqg-prf6.json b/advisories/unreviewed/2024/07/GHSA-3pc3-vcqg-prf6/GHSA-3pc3-vcqg-prf6.json index cde3127e1d8..0f9080413fc 100644 --- a/advisories/unreviewed/2024/07/GHSA-3pc3-vcqg-prf6/GHSA-3pc3-vcqg-prf6.json +++ b/advisories/unreviewed/2024/07/GHSA-3pc3-vcqg-prf6/GHSA-3pc3-vcqg-prf6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3pc3-vcqg-prf6", - "modified": "2024-07-22T21:30:40Z", + "modified": "2024-09-17T15:31:23Z", "published": "2024-07-22T21:30:40Z", "aliases": [ "CVE-2024-6793" diff --git a/advisories/unreviewed/2024/07/GHSA-gch4-6c9x-v2fr/GHSA-gch4-6c9x-v2fr.json b/advisories/unreviewed/2024/07/GHSA-gch4-6c9x-v2fr/GHSA-gch4-6c9x-v2fr.json index b188aaac133..139f2a3bd43 100644 --- a/advisories/unreviewed/2024/07/GHSA-gch4-6c9x-v2fr/GHSA-gch4-6c9x-v2fr.json +++ b/advisories/unreviewed/2024/07/GHSA-gch4-6c9x-v2fr/GHSA-gch4-6c9x-v2fr.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gch4-6c9x-v2fr", - "modified": "2024-07-17T00:32:53Z", + "modified": "2024-09-17T15:31:23Z", "published": "2024-07-17T00:32:53Z", "aliases": [ "CVE-2024-6336" ], "details": "A Security Misconfiguration vulnerability in GitHub Enterprise Server allowed sensitive information disclosure to unauthorized users in GitHub Enterprise Server by exploiting organization ruleset feature. This attack required an organization member to explicitly change the visibility of a dependent repository from private to public. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in versions 3.13.1, 3.12.6, 3.11.12, 3.10.14, and 3.9.17. This vulnerability was reported via the GitHub Bug Bounty program.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:X/RE:X/U:Amber" diff --git a/advisories/unreviewed/2024/07/GHSA-hf94-2x3f-x6rc/GHSA-hf94-2x3f-x6rc.json b/advisories/unreviewed/2024/07/GHSA-hf94-2x3f-x6rc/GHSA-hf94-2x3f-x6rc.json index 5558a27b834..e6754d68027 100644 --- a/advisories/unreviewed/2024/07/GHSA-hf94-2x3f-x6rc/GHSA-hf94-2x3f-x6rc.json +++ b/advisories/unreviewed/2024/07/GHSA-hf94-2x3f-x6rc/GHSA-hf94-2x3f-x6rc.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hf94-2x3f-x6rc", - "modified": "2024-07-17T00:32:53Z", + "modified": "2024-09-17T15:31:23Z", "published": "2024-07-17T00:32:53Z", "aliases": [ "CVE-2024-5817" ], "details": "An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed read access to issue content via GitHub Projects. This was only exploitable in internal repositories and required the attacker to have access to the corresponding project board. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in versions 3.13.1, 3.12.6, 3.11.12, 3.10.14, and 3.9.17. This vulnerability was reported via the GitHub Bug Bounty program.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber" diff --git a/advisories/unreviewed/2024/07/GHSA-xrcw-9q57-9frw/GHSA-xrcw-9q57-9frw.json b/advisories/unreviewed/2024/07/GHSA-xrcw-9q57-9frw/GHSA-xrcw-9q57-9frw.json index ffff99ac211..d623bfc5a5d 100644 --- a/advisories/unreviewed/2024/07/GHSA-xrcw-9q57-9frw/GHSA-xrcw-9q57-9frw.json +++ b/advisories/unreviewed/2024/07/GHSA-xrcw-9q57-9frw/GHSA-xrcw-9q57-9frw.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xrcw-9q57-9frw", - "modified": "2024-07-17T00:32:53Z", + "modified": "2024-09-17T15:31:23Z", "published": "2024-07-17T00:32:53Z", "aliases": [ "CVE-2024-5816" ], "details": "An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a suspended GitHub App to retain access to the repository via a scoped user access token. This was only exploitable in public repositories while private repositories were not impacted. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in versions 3.9.17, 3.10.14, 3.11.12, 3.12.6, 3.13.1. This vulnerability was reported via the GitHub Bug Bounty program.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-2rr2-57v3-7cvx/GHSA-2rr2-57v3-7cvx.json b/advisories/unreviewed/2024/09/GHSA-2rr2-57v3-7cvx/GHSA-2rr2-57v3-7cvx.json new file mode 100644 index 00000000000..0a5a5edb8fa --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-2rr2-57v3-7cvx/GHSA-2rr2-57v3-7cvx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rr2-57v3-7cvx", + "modified": "2024-09-17T15:31:23Z", + "published": "2024-09-17T15:31:23Z", + "aliases": [ + "CVE-2024-7873" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escaping of Output, CWE - 83 Improper Neutralization of Script in Attributes in a Web Page vulnerability in Veribilim Software Veribase Order allows Stored XSS, Cross-Site Scripting (XSS), Exploit Script-Based APIs, XSS Through HTTP Headers.This issue affects Veribase Order: before v4.010.3.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7873" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1485" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-116" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T13:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-62pp-53wf-pprq/GHSA-62pp-53wf-pprq.json b/advisories/unreviewed/2024/09/GHSA-62pp-53wf-pprq/GHSA-62pp-53wf-pprq.json new file mode 100644 index 00000000000..49b300e9ee3 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-62pp-53wf-pprq/GHSA-62pp-53wf-pprq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62pp-53wf-pprq", + "modified": "2024-09-17T15:31:23Z", + "published": "2024-09-17T15:31:23Z", + "aliases": [ + "CVE-2024-7788" + ], + "details": "Improper Digital Signature InvalidationĀ  vulnerability in Zip Repair Mode of The Document Foundation LibreOffice allows Signature forgery vulnerability in LibreOfficeThis issue affects LibreOffice: from 24.2 before < 24.2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7788" + }, + { + "type": "WEB", + "url": "https://www.libreoffice.org/about-us/security/advisories/CVE-2024-7788" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-347" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-653g-mc33-gq3r/GHSA-653g-mc33-gq3r.json b/advisories/unreviewed/2024/09/GHSA-653g-mc33-gq3r/GHSA-653g-mc33-gq3r.json index 25bac84b78b..4a502dfd5d6 100644 --- a/advisories/unreviewed/2024/09/GHSA-653g-mc33-gq3r/GHSA-653g-mc33-gq3r.json +++ b/advisories/unreviewed/2024/09/GHSA-653g-mc33-gq3r/GHSA-653g-mc33-gq3r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-653g-mc33-gq3r", - "modified": "2024-09-17T06:30:37Z", + "modified": "2024-09-17T15:31:23Z", "published": "2024-09-17T06:30:37Z", "aliases": [ "CVE-2024-8093" ], "details": "The Posts reminder WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T06:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-67qp-fprc-rhx4/GHSA-67qp-fprc-rhx4.json b/advisories/unreviewed/2024/09/GHSA-67qp-fprc-rhx4/GHSA-67qp-fprc-rhx4.json new file mode 100644 index 00000000000..f59b516a938 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-67qp-fprc-rhx4/GHSA-67qp-fprc-rhx4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67qp-fprc-rhx4", + "modified": "2024-09-17T15:31:23Z", + "published": "2024-09-17T15:31:23Z", + "aliases": [ + "CVE-2024-46362" + ], + "details": "FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_directory", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46362" + }, + { + "type": "WEB", + "url": "https://github.com/ohuquq/cms/tree/main/13/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T13:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6rgh-r6j3-3223/GHSA-6rgh-r6j3-3223.json b/advisories/unreviewed/2024/09/GHSA-6rgh-r6j3-3223/GHSA-6rgh-r6j3-3223.json new file mode 100644 index 00000000000..db397babdb5 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6rgh-r6j3-3223/GHSA-6rgh-r6j3-3223.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rgh-r6j3-3223", + "modified": "2024-09-17T15:31:23Z", + "published": "2024-09-17T15:31:23Z", + "aliases": [ + "CVE-2024-47049" + ], + "details": "The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URLs within makeFromUrl and makeFromAny, leading to SSRF, and to directory traversal for the reading of local files.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47049" + }, + { + "type": "WEB", + "url": "https://github.com/czim/file-handling/blob/2.3.0/SECURITY.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-7v6r-jgcw-v2j9/GHSA-7v6r-jgcw-v2j9.json b/advisories/unreviewed/2024/09/GHSA-7v6r-jgcw-v2j9/GHSA-7v6r-jgcw-v2j9.json index 883a2498358..f7493d08c65 100644 --- a/advisories/unreviewed/2024/09/GHSA-7v6r-jgcw-v2j9/GHSA-7v6r-jgcw-v2j9.json +++ b/advisories/unreviewed/2024/09/GHSA-7v6r-jgcw-v2j9/GHSA-7v6r-jgcw-v2j9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7v6r-jgcw-v2j9", - "modified": "2024-09-16T14:37:29Z", + "modified": "2024-09-17T15:31:23Z", "published": "2024-09-16T14:37:28Z", "aliases": [ "CVE-2024-46937" ], "details": "An improper access control (IDOR) vulnerability in the /api-selfportal/get-info-token-properties endpoint in MFASOFT Secure Authentication Server (SAS) 1.8.x through 1.9.x before 1.9.040924 allows remote attackers gain access to user tokens without authentication. The is a brute-force attack on the serial parameter by number identifier: GA00001, GA00002, GA00003, etc.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-16T13:15:10Z" diff --git a/advisories/unreviewed/2024/09/GHSA-83j8-7m3h-36p8/GHSA-83j8-7m3h-36p8.json b/advisories/unreviewed/2024/09/GHSA-83j8-7m3h-36p8/GHSA-83j8-7m3h-36p8.json new file mode 100644 index 00000000000..5088e9dc91c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-83j8-7m3h-36p8/GHSA-83j8-7m3h-36p8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-83j8-7m3h-36p8", + "modified": "2024-09-17T15:31:23Z", + "published": "2024-09-17T15:31:23Z", + "aliases": [ + "CVE-2024-21743" + ], + "details": "Privilege Escalation vulnerability in favethemes Houzez Login Register houzez-login-register.This issue affects Houzez Login Register: from n/a through 3.2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21743" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/houzez-login-register/wordpress-houzez-login-register-plugin-3-2-5-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-9rm6-368p-665h/GHSA-9rm6-368p-665h.json b/advisories/unreviewed/2024/09/GHSA-9rm6-368p-665h/GHSA-9rm6-368p-665h.json new file mode 100644 index 00000000000..c653ae1cd98 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-9rm6-368p-665h/GHSA-9rm6-368p-665h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rm6-368p-665h", + "modified": "2024-09-17T15:31:23Z", + "published": "2024-09-17T15:31:23Z", + "aliases": [ + "CVE-2024-38860" + ], + "details": "Improper neutralization of input in Checkmk before versions 2.3.0p16 and 2.2.0p34 allows attackers to craft malicious links that can facilitate phishing attacks.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38860" + }, + { + "type": "WEB", + "url": "https://checkmk.com/werk/17094" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-c5v7-54mg-82m2/GHSA-c5v7-54mg-82m2.json b/advisories/unreviewed/2024/09/GHSA-c5v7-54mg-82m2/GHSA-c5v7-54mg-82m2.json new file mode 100644 index 00000000000..872857aa4e5 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-c5v7-54mg-82m2/GHSA-c5v7-54mg-82m2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c5v7-54mg-82m2", + "modified": "2024-09-17T15:31:23Z", + "published": "2024-09-17T15:31:23Z", + "aliases": [ + "CVE-2024-22303" + ], + "details": "Incorrect Privilege Assignment vulnerability in favethemes Houzez houzez allows Privilege Escalation.This issue affects Houzez: from n/a through 3.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22303" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/houzez/wordpress-houzez-theme-3-2-4-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-cwj6-8v2q-g52w/GHSA-cwj6-8v2q-g52w.json b/advisories/unreviewed/2024/09/GHSA-cwj6-8v2q-g52w/GHSA-cwj6-8v2q-g52w.json new file mode 100644 index 00000000000..5fd25289602 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-cwj6-8v2q-g52w/GHSA-cwj6-8v2q-g52w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwj6-8v2q-g52w", + "modified": "2024-09-17T15:31:23Z", + "published": "2024-09-17T15:31:23Z", + "aliases": [ + "CVE-2024-46085" + ], + "details": "FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/rename", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46085" + }, + { + "type": "WEB", + "url": "https://github.com/RainingSEC/cms/tree/main/11/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T13:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-fvjr-4pf9-7pjq/GHSA-fvjr-4pf9-7pjq.json b/advisories/unreviewed/2024/09/GHSA-fvjr-4pf9-7pjq/GHSA-fvjr-4pf9-7pjq.json index 0bf9dc0dd26..1bbb374d3c0 100644 --- a/advisories/unreviewed/2024/09/GHSA-fvjr-4pf9-7pjq/GHSA-fvjr-4pf9-7pjq.json +++ b/advisories/unreviewed/2024/09/GHSA-fvjr-4pf9-7pjq/GHSA-fvjr-4pf9-7pjq.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fvjr-4pf9-7pjq", - "modified": "2024-09-02T21:30:30Z", + "modified": "2024-09-17T15:31:23Z", "published": "2024-09-02T21:30:30Z", "aliases": [ "CVE-2024-1621" ], "details": "The registration process of uniFLOW Online (NT-ware product) apps, prior to and including version 2024.1.0, can be compromised when email login is enabled on the tenant. Those tenants utilising email login in combination with Microsoft Safe Links or similar are impacted. This vulnerability may allow the attacker to register themselves against a genuine user in the system and allow malicious users with similar access and capabilities via the app to the existing genuine user.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-hj65-9wfc-jmf4/GHSA-hj65-9wfc-jmf4.json b/advisories/unreviewed/2024/09/GHSA-hj65-9wfc-jmf4/GHSA-hj65-9wfc-jmf4.json new file mode 100644 index 00000000000..c41cfeab8e4 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-hj65-9wfc-jmf4/GHSA-hj65-9wfc-jmf4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hj65-9wfc-jmf4", + "modified": "2024-09-17T15:31:23Z", + "published": "2024-09-17T15:31:23Z", + "aliases": [ + "CVE-2024-8897" + ], + "details": "Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be able to spoof the address bar contents. This can lead to a malicious site to appear to have the same URL as the trusted site.\n*This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox for Android < 130.0.1.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8897" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1862537" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-45" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T13:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-j6v2-m8w2-27f8/GHSA-j6v2-m8w2-27f8.json b/advisories/unreviewed/2024/09/GHSA-j6v2-m8w2-27f8/GHSA-j6v2-m8w2-27f8.json index fd34db8e247..ebd01283938 100644 --- a/advisories/unreviewed/2024/09/GHSA-j6v2-m8w2-27f8/GHSA-j6v2-m8w2-27f8.json +++ b/advisories/unreviewed/2024/09/GHSA-j6v2-m8w2-27f8/GHSA-j6v2-m8w2-27f8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j6v2-m8w2-27f8", - "modified": "2024-09-03T12:30:31Z", + "modified": "2024-09-17T15:31:23Z", "published": "2024-09-03T12:30:31Z", "aliases": [ "CVE-2024-38811" diff --git a/advisories/unreviewed/2024/09/GHSA-q25c-r482-77p9/GHSA-q25c-r482-77p9.json b/advisories/unreviewed/2024/09/GHSA-q25c-r482-77p9/GHSA-q25c-r482-77p9.json new file mode 100644 index 00000000000..c171cd63b77 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-q25c-r482-77p9/GHSA-q25c-r482-77p9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q25c-r482-77p9", + "modified": "2024-09-17T15:31:23Z", + "published": "2024-09-17T15:31:23Z", + "aliases": [ + "CVE-2024-47047" + ], + "details": "An issue was discovered in the powermail extension through 12.4.0 for TYPO3. It fails to validate the mail parameter of the createAction, resulting in Insecure Direct Object Reference (IDOR) in some configurations. An unauthenticated attacker can use this to display user-submitted data of all forms persisted by the extension. The fixed versions are 7.5.1, 8.5.1, 10.9.1, and 12.4.1.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47047" + }, + { + "type": "WEB", + "url": "https://typo3.org/security/advisory/typo3-ext-sa-2024-007" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-wjg2-c55h-phf5/GHSA-wjg2-c55h-phf5.json b/advisories/unreviewed/2024/09/GHSA-wjg2-c55h-phf5/GHSA-wjg2-c55h-phf5.json index 17821f5cd58..717e45c8d0f 100644 --- a/advisories/unreviewed/2024/09/GHSA-wjg2-c55h-phf5/GHSA-wjg2-c55h-phf5.json +++ b/advisories/unreviewed/2024/09/GHSA-wjg2-c55h-phf5/GHSA-wjg2-c55h-phf5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wjg2-c55h-phf5", - "modified": "2024-09-17T00:31:04Z", + "modified": "2024-09-17T15:31:23Z", "published": "2024-09-17T00:31:04Z", "aliases": [ "CVE-2024-40852" ], "details": "This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18 and iPadOS 18. An attacker may be able to see recent photos without authentication in Assistive Access.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:49Z"