Publish Advisories

GHSA-3rcm-9xw5-hpx9
GHSA-3v79-q7ph-j75h
GHSA-4rwq-456r-x2vq
GHSA-5g9g-vh54-q73c
GHSA-6749-m5cp-6cg7
GHSA-6gr8-w5jx-65mj
GHSA-8rj6-cwhf-4c77
GHSA-gfq7-h592-v3xj
GHSA-h92p-2jv6-wm6r
GHSA-hwrx-p9h9-fpfj
GHSA-p868-fvgw-52x4
GHSA-vp85-c393-q66r
This commit is contained in:
advisory-database[bot]
2024-02-24 00:31:50 +00:00
parent 8f0164142e
commit 0c5457193e
12 changed files with 486 additions and 0 deletions
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3rcm-9xw5-hpx9",
"modified": "2024-02-24T00:30:20Z",
"published": "2024-02-24T00:30:20Z",
"aliases": [
"CVE-2024-26192"
],
"details": "Microsoft Edge (Chromium-based) Information Disclosure Vulnerability",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26192"
},
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26192"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-23T23:15:09Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3v79-q7ph-j75h",
"modified": "2024-02-24T00:30:20Z",
"published": "2024-02-24T00:30:20Z",
"aliases": [
"CVE-2024-27133"
],
"details": "Insufficient sanitization in MLflow leads to XSS when running a recipe that uses an untrusted dataset. This issue leads to a client-side RCE when running the recipe in Jupyter Notebook. The vulnerability stems from lack of sanitization over dataset table fields.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27133"
},
{
"type": "WEB",
"url": "https://github.com/mlflow/mlflow/pull/10893"
},
{
"type": "WEB",
"url": "https://research.jfrog.com/vulnerabilities/mlflow-untrusted-dataset-xss-jfsa-2024-000631932"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-23T22:15:55Z"
}
}
@@ -0,0 +1,59 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4rwq-456r-x2vq",
"modified": "2024-02-24T00:30:20Z",
"published": "2024-02-24T00:30:20Z",
"aliases": [
"CVE-2024-25730"
],
"details": "Hitron CODA-4582 and CODA-4589 devices have default PSKs that are generated from 5-digit hex values concatenated with a \"Hitron\" substring, resulting in insufficient entropy (only about one million possibilities).",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25730"
},
{
"type": "WEB",
"url": "https://github.com/actuator/cve/blob/main/Hitron/CVE-2024-25730"
},
{
"type": "WEB",
"url": "https://i.ebayimg.com/images/g/I-8AAOSwGE9lsGwI/s-l1600.webp"
},
{
"type": "WEB",
"url": "https://i.ebayimg.com/images/g/MwMAAOSwjTFk3kpd/s-l1600.webp"
},
{
"type": "WEB",
"url": "https://i.ebayimg.com/images/g/VDcAAOSwlodlSuz4/s-l1600.webp"
},
{
"type": "WEB",
"url": "https://i.ebayimg.com/images/g/XaAAAOSwvMNkuESk/s-l1600.webp"
},
{
"type": "WEB",
"url": "https://i.ebayimg.com/images/g/hzUAAOSwUwVllGMZ/s-l1600.webp"
},
{
"type": "WEB",
"url": "https://i.ebayimg.com/images/g/qK8AAOSwbr9lq3PJ/s-l1600.webp"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-23T22:15:55Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5g9g-vh54-q73c",
"modified": "2024-02-24T00:30:20Z",
"published": "2024-02-24T00:30:20Z",
"aliases": [
"CVE-2024-25469"
],
"details": "SQL Injection vulnerability in CRMEB crmeb_java v.1.3.4 and before allows a remote attacker to obtain sensitive information via the latitude and longitude parameters in the api/front/store/list component.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25469"
},
{
"type": "WEB",
"url": "https://github.com/crmeb/crmeb_java/issues/20"
},
{
"type": "WEB",
"url": "https://github.com/crmeb/crmeb_java"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-23T23:15:09Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6749-m5cp-6cg7",
"modified": "2024-02-24T00:30:20Z",
"published": "2024-02-24T00:30:20Z",
"aliases": [
"CVE-2024-27132"
],
"details": "Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe.\n\nThis issue leads to a client-side RCE when running an untrusted recipe in Jupyter Notebook.\n\nThe vulnerability stems from lack of sanitization over template variables.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27132"
},
{
"type": "WEB",
"url": "https://github.com/mlflow/mlflow/pull/10873"
},
{
"type": "WEB",
"url": "https://research.jfrog.com/vulnerabilities/mlflow-untrusted-recipe-xss-jfsa-2024-000631930"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-23T22:15:55Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6gr8-w5jx-65mj",
"modified": "2024-02-24T00:30:20Z",
"published": "2024-02-24T00:30:20Z",
"aliases": [
"CVE-2024-24309"
],
"details": "In the module \"Survey TMA\" (ecomiz_survey_tma) up to version 2.0.0 from Ecomiz for PrestaShop, a guest can download personal information without restriction.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24309"
},
{
"type": "WEB",
"url": "https://security.friendsofpresta.org/modules/2024/02/20/ecomiz_survey_tma.html"
},
{
"type": "WEB",
"url": "https://www.ecomiz.com"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-23T22:15:54Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8rj6-cwhf-4c77",
"modified": "2024-02-24T00:30:20Z",
"published": "2024-02-24T00:30:20Z",
"aliases": [
"CVE-2024-22988"
],
"details": "An issue in zkteco zkbio WDMS v.8.0.5 allows an attacker to execute arbitrary code via the /files/backup/ component.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22988"
},
{
"type": "WEB",
"url": "https://gist.github.com/whiteman007/b50a9b64007a5d7bcb7a8bee61d2cb47"
},
{
"type": "WEB",
"url": "https://zkteco.com"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-23T23:15:09Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gfq7-h592-v3xj",
"modified": "2024-02-24T00:30:20Z",
"published": "2024-02-24T00:30:20Z",
"aliases": [
"CVE-2024-24681"
],
"details": "Insecure AES key in Yealink Configuration Encrypt Tool below verrsion 1.2. A single, vendorwide, hardcoded AES key in the configuration tool used to encrypt provisioning documents was leaked leading to a compromise of confidentiality of provisioning documents.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24681"
},
{
"type": "WEB",
"url": "https://www.reddit.com/r/VOIP/comments/ys9mel/what_are_some_of_the_good_white_label_voip"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-23T23:15:09Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h92p-2jv6-wm6r",
"modified": "2024-02-24T00:30:20Z",
"published": "2024-02-24T00:30:20Z",
"aliases": [
"CVE-2024-21423"
],
"details": "Microsoft Edge (Chromium-based) Information Disclosure Vulnerability",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21423"
},
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21423"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-23T22:15:54Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hwrx-p9h9-fpfj",
"modified": "2024-02-24T00:30:20Z",
"published": "2024-02-24T00:30:20Z",
"aliases": [
"CVE-2024-26188"
],
"details": "Microsoft Edge (Chromium-based) Spoofing Vulnerability",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26188"
},
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26188"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-23T23:15:09Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p868-fvgw-52x4",
"modified": "2024-02-24T00:30:20Z",
"published": "2024-02-24T00:30:20Z",
"aliases": [
"CVE-2024-22395"
],
"details": "Improper access control vulnerability has been identified in the SMA100 SSL-VPN virtual office portal, which in specific conditions could potentially enable a remote authenticated attacker to associate another user's MFA mobile application.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22395"
},
{
"type": "WEB",
"url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0001"
}
],
"database_specific": {
"cwe_ids": [
"CWE-287"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-24T00:15:45Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vp85-c393-q66r",
"modified": "2024-02-24T00:30:20Z",
"published": "2024-02-24T00:30:20Z",
"aliases": [
"CVE-2024-24310"
],
"details": "In the module \"Generate barcode on invoice / delivery slip\" (ecgeneratebarcode) from Ether Creation <= 1.2.0 for PrestaShop, a guest can perform SQL injection.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24310"
},
{
"type": "WEB",
"url": "https://addons.prestashop.com/en/preparation-shipping/24123-generate-barcode-on-invoice-delivery-slip.html"
},
{
"type": "WEB",
"url": "https://security.friendsofpresta.org/modules/2024/02/20/ecgeneratebarcode.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-23T22:15:54Z"
}
}