From 0c5457193e4d22b2c250d34bc59e3ba0050d65fe Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 24 Feb 2024 00:31:50 +0000 Subject: [PATCH] Publish Advisories GHSA-3rcm-9xw5-hpx9 GHSA-3v79-q7ph-j75h GHSA-4rwq-456r-x2vq GHSA-5g9g-vh54-q73c GHSA-6749-m5cp-6cg7 GHSA-6gr8-w5jx-65mj GHSA-8rj6-cwhf-4c77 GHSA-gfq7-h592-v3xj GHSA-h92p-2jv6-wm6r GHSA-hwrx-p9h9-fpfj GHSA-p868-fvgw-52x4 GHSA-vp85-c393-q66r --- .../GHSA-3rcm-9xw5-hpx9.json | 38 ++++++++++++ .../GHSA-3v79-q7ph-j75h.json | 42 +++++++++++++ .../GHSA-4rwq-456r-x2vq.json | 59 +++++++++++++++++++ .../GHSA-5g9g-vh54-q73c.json | 39 ++++++++++++ .../GHSA-6749-m5cp-6cg7.json | 42 +++++++++++++ .../GHSA-6gr8-w5jx-65mj.json | 39 ++++++++++++ .../GHSA-8rj6-cwhf-4c77.json | 39 ++++++++++++ .../GHSA-gfq7-h592-v3xj.json | 35 +++++++++++ .../GHSA-h92p-2jv6-wm6r.json | 38 ++++++++++++ .../GHSA-hwrx-p9h9-fpfj.json | 38 ++++++++++++ .../GHSA-p868-fvgw-52x4.json | 38 ++++++++++++ .../GHSA-vp85-c393-q66r.json | 39 ++++++++++++ 12 files changed, 486 insertions(+) create mode 100644 advisories/unreviewed/2024/02/GHSA-3rcm-9xw5-hpx9/GHSA-3rcm-9xw5-hpx9.json create mode 100644 advisories/unreviewed/2024/02/GHSA-3v79-q7ph-j75h/GHSA-3v79-q7ph-j75h.json create mode 100644 advisories/unreviewed/2024/02/GHSA-4rwq-456r-x2vq/GHSA-4rwq-456r-x2vq.json create mode 100644 advisories/unreviewed/2024/02/GHSA-5g9g-vh54-q73c/GHSA-5g9g-vh54-q73c.json create mode 100644 advisories/unreviewed/2024/02/GHSA-6749-m5cp-6cg7/GHSA-6749-m5cp-6cg7.json create mode 100644 advisories/unreviewed/2024/02/GHSA-6gr8-w5jx-65mj/GHSA-6gr8-w5jx-65mj.json create mode 100644 advisories/unreviewed/2024/02/GHSA-8rj6-cwhf-4c77/GHSA-8rj6-cwhf-4c77.json create mode 100644 advisories/unreviewed/2024/02/GHSA-gfq7-h592-v3xj/GHSA-gfq7-h592-v3xj.json create mode 100644 advisories/unreviewed/2024/02/GHSA-h92p-2jv6-wm6r/GHSA-h92p-2jv6-wm6r.json create mode 100644 advisories/unreviewed/2024/02/GHSA-hwrx-p9h9-fpfj/GHSA-hwrx-p9h9-fpfj.json create mode 100644 advisories/unreviewed/2024/02/GHSA-p868-fvgw-52x4/GHSA-p868-fvgw-52x4.json create mode 100644 advisories/unreviewed/2024/02/GHSA-vp85-c393-q66r/GHSA-vp85-c393-q66r.json diff --git a/advisories/unreviewed/2024/02/GHSA-3rcm-9xw5-hpx9/GHSA-3rcm-9xw5-hpx9.json b/advisories/unreviewed/2024/02/GHSA-3rcm-9xw5-hpx9/GHSA-3rcm-9xw5-hpx9.json new file mode 100644 index 00000000000..1eea3e0fee8 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-3rcm-9xw5-hpx9/GHSA-3rcm-9xw5-hpx9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rcm-9xw5-hpx9", + "modified": "2024-02-24T00:30:20Z", + "published": "2024-02-24T00:30:20Z", + "aliases": [ + "CVE-2024-26192" + ], + "details": "Microsoft Edge (Chromium-based) Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26192" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26192" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-23T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-3v79-q7ph-j75h/GHSA-3v79-q7ph-j75h.json b/advisories/unreviewed/2024/02/GHSA-3v79-q7ph-j75h/GHSA-3v79-q7ph-j75h.json new file mode 100644 index 00000000000..4ffc8bae7c8 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-3v79-q7ph-j75h/GHSA-3v79-q7ph-j75h.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3v79-q7ph-j75h", + "modified": "2024-02-24T00:30:20Z", + "published": "2024-02-24T00:30:20Z", + "aliases": [ + "CVE-2024-27133" + ], + "details": "Insufficient sanitization in MLflow leads to XSS when running a recipe that uses an untrusted dataset. This issue leads to a client-side RCE when running the recipe in Jupyter Notebook. The vulnerability stems from lack of sanitization over dataset table fields.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27133" + }, + { + "type": "WEB", + "url": "https://github.com/mlflow/mlflow/pull/10893" + }, + { + "type": "WEB", + "url": "https://research.jfrog.com/vulnerabilities/mlflow-untrusted-dataset-xss-jfsa-2024-000631932" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-23T22:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-4rwq-456r-x2vq/GHSA-4rwq-456r-x2vq.json b/advisories/unreviewed/2024/02/GHSA-4rwq-456r-x2vq/GHSA-4rwq-456r-x2vq.json new file mode 100644 index 00000000000..b58c7995e18 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-4rwq-456r-x2vq/GHSA-4rwq-456r-x2vq.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rwq-456r-x2vq", + "modified": "2024-02-24T00:30:20Z", + "published": "2024-02-24T00:30:20Z", + "aliases": [ + "CVE-2024-25730" + ], + "details": "Hitron CODA-4582 and CODA-4589 devices have default PSKs that are generated from 5-digit hex values concatenated with a \"Hitron\" substring, resulting in insufficient entropy (only about one million possibilities).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25730" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/cve/blob/main/Hitron/CVE-2024-25730" + }, + { + "type": "WEB", + "url": "https://i.ebayimg.com/images/g/I-8AAOSwGE9lsGwI/s-l1600.webp" + }, + { + "type": "WEB", + "url": "https://i.ebayimg.com/images/g/MwMAAOSwjTFk3kpd/s-l1600.webp" + }, + { + "type": "WEB", + "url": "https://i.ebayimg.com/images/g/VDcAAOSwlodlSuz4/s-l1600.webp" + }, + { + "type": "WEB", + "url": "https://i.ebayimg.com/images/g/XaAAAOSwvMNkuESk/s-l1600.webp" + }, + { + "type": "WEB", + "url": "https://i.ebayimg.com/images/g/hzUAAOSwUwVllGMZ/s-l1600.webp" + }, + { + "type": "WEB", + "url": "https://i.ebayimg.com/images/g/qK8AAOSwbr9lq3PJ/s-l1600.webp" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-23T22:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-5g9g-vh54-q73c/GHSA-5g9g-vh54-q73c.json b/advisories/unreviewed/2024/02/GHSA-5g9g-vh54-q73c/GHSA-5g9g-vh54-q73c.json new file mode 100644 index 00000000000..b84c63efe29 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-5g9g-vh54-q73c/GHSA-5g9g-vh54-q73c.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g9g-vh54-q73c", + "modified": "2024-02-24T00:30:20Z", + "published": "2024-02-24T00:30:20Z", + "aliases": [ + "CVE-2024-25469" + ], + "details": "SQL Injection vulnerability in CRMEB crmeb_java v.1.3.4 and before allows a remote attacker to obtain sensitive information via the latitude and longitude parameters in the api/front/store/list component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25469" + }, + { + "type": "WEB", + "url": "https://github.com/crmeb/crmeb_java/issues/20" + }, + { + "type": "WEB", + "url": "https://github.com/crmeb/crmeb_java" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-23T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-6749-m5cp-6cg7/GHSA-6749-m5cp-6cg7.json b/advisories/unreviewed/2024/02/GHSA-6749-m5cp-6cg7/GHSA-6749-m5cp-6cg7.json new file mode 100644 index 00000000000..33c2cbc0007 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-6749-m5cp-6cg7/GHSA-6749-m5cp-6cg7.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6749-m5cp-6cg7", + "modified": "2024-02-24T00:30:20Z", + "published": "2024-02-24T00:30:20Z", + "aliases": [ + "CVE-2024-27132" + ], + "details": "Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe.\n\nThis issue leads to a client-side RCE when running an untrusted recipe in Jupyter Notebook.\n\nThe vulnerability stems from lack of sanitization over template variables.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27132" + }, + { + "type": "WEB", + "url": "https://github.com/mlflow/mlflow/pull/10873" + }, + { + "type": "WEB", + "url": "https://research.jfrog.com/vulnerabilities/mlflow-untrusted-recipe-xss-jfsa-2024-000631930" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-23T22:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-6gr8-w5jx-65mj/GHSA-6gr8-w5jx-65mj.json b/advisories/unreviewed/2024/02/GHSA-6gr8-w5jx-65mj/GHSA-6gr8-w5jx-65mj.json new file mode 100644 index 00000000000..9ca2ccc6734 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-6gr8-w5jx-65mj/GHSA-6gr8-w5jx-65mj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gr8-w5jx-65mj", + "modified": "2024-02-24T00:30:20Z", + "published": "2024-02-24T00:30:20Z", + "aliases": [ + "CVE-2024-24309" + ], + "details": "In the module \"Survey TMA\" (ecomiz_survey_tma) up to version 2.0.0 from Ecomiz for PrestaShop, a guest can download personal information without restriction.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24309" + }, + { + "type": "WEB", + "url": "https://security.friendsofpresta.org/modules/2024/02/20/ecomiz_survey_tma.html" + }, + { + "type": "WEB", + "url": "https://www.ecomiz.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-23T22:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-8rj6-cwhf-4c77/GHSA-8rj6-cwhf-4c77.json b/advisories/unreviewed/2024/02/GHSA-8rj6-cwhf-4c77/GHSA-8rj6-cwhf-4c77.json new file mode 100644 index 00000000000..f405870b602 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-8rj6-cwhf-4c77/GHSA-8rj6-cwhf-4c77.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rj6-cwhf-4c77", + "modified": "2024-02-24T00:30:20Z", + "published": "2024-02-24T00:30:20Z", + "aliases": [ + "CVE-2024-22988" + ], + "details": "An issue in zkteco zkbio WDMS v.8.0.5 allows an attacker to execute arbitrary code via the /files/backup/ component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22988" + }, + { + "type": "WEB", + "url": "https://gist.github.com/whiteman007/b50a9b64007a5d7bcb7a8bee61d2cb47" + }, + { + "type": "WEB", + "url": "https://zkteco.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-23T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-gfq7-h592-v3xj/GHSA-gfq7-h592-v3xj.json b/advisories/unreviewed/2024/02/GHSA-gfq7-h592-v3xj/GHSA-gfq7-h592-v3xj.json new file mode 100644 index 00000000000..7af0e6e397a --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-gfq7-h592-v3xj/GHSA-gfq7-h592-v3xj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gfq7-h592-v3xj", + "modified": "2024-02-24T00:30:20Z", + "published": "2024-02-24T00:30:20Z", + "aliases": [ + "CVE-2024-24681" + ], + "details": "Insecure AES key in Yealink Configuration Encrypt Tool below verrsion 1.2. A single, vendorwide, hardcoded AES key in the configuration tool used to encrypt provisioning documents was leaked leading to a compromise of confidentiality of provisioning documents.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24681" + }, + { + "type": "WEB", + "url": "https://www.reddit.com/r/VOIP/comments/ys9mel/what_are_some_of_the_good_white_label_voip" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-23T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-h92p-2jv6-wm6r/GHSA-h92p-2jv6-wm6r.json b/advisories/unreviewed/2024/02/GHSA-h92p-2jv6-wm6r/GHSA-h92p-2jv6-wm6r.json new file mode 100644 index 00000000000..7f85600da67 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-h92p-2jv6-wm6r/GHSA-h92p-2jv6-wm6r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h92p-2jv6-wm6r", + "modified": "2024-02-24T00:30:20Z", + "published": "2024-02-24T00:30:20Z", + "aliases": [ + "CVE-2024-21423" + ], + "details": "Microsoft Edge (Chromium-based) Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21423" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21423" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-23T22:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-hwrx-p9h9-fpfj/GHSA-hwrx-p9h9-fpfj.json b/advisories/unreviewed/2024/02/GHSA-hwrx-p9h9-fpfj/GHSA-hwrx-p9h9-fpfj.json new file mode 100644 index 00000000000..82cdcd88a91 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-hwrx-p9h9-fpfj/GHSA-hwrx-p9h9-fpfj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwrx-p9h9-fpfj", + "modified": "2024-02-24T00:30:20Z", + "published": "2024-02-24T00:30:20Z", + "aliases": [ + "CVE-2024-26188" + ], + "details": "Microsoft Edge (Chromium-based) Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26188" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26188" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-23T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-p868-fvgw-52x4/GHSA-p868-fvgw-52x4.json b/advisories/unreviewed/2024/02/GHSA-p868-fvgw-52x4/GHSA-p868-fvgw-52x4.json new file mode 100644 index 00000000000..69ddc5df39b --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-p868-fvgw-52x4/GHSA-p868-fvgw-52x4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p868-fvgw-52x4", + "modified": "2024-02-24T00:30:20Z", + "published": "2024-02-24T00:30:20Z", + "aliases": [ + "CVE-2024-22395" + ], + "details": "Improper access control vulnerability has been identified in the SMA100 SSL-VPN virtual office portal, which in specific conditions could potentially enable a remote authenticated attacker to associate another user's MFA mobile application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22395" + }, + { + "type": "WEB", + "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0001" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-24T00:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-vp85-c393-q66r/GHSA-vp85-c393-q66r.json b/advisories/unreviewed/2024/02/GHSA-vp85-c393-q66r/GHSA-vp85-c393-q66r.json new file mode 100644 index 00000000000..7e70b6a2b6f --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-vp85-c393-q66r/GHSA-vp85-c393-q66r.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vp85-c393-q66r", + "modified": "2024-02-24T00:30:20Z", + "published": "2024-02-24T00:30:20Z", + "aliases": [ + "CVE-2024-24310" + ], + "details": "In the module \"Generate barcode on invoice / delivery slip\" (ecgeneratebarcode) from Ether Creation <= 1.2.0 for PrestaShop, a guest can perform SQL injection.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24310" + }, + { + "type": "WEB", + "url": "https://addons.prestashop.com/en/preparation-shipping/24123-generate-barcode-on-invoice-delivery-slip.html" + }, + { + "type": "WEB", + "url": "https://security.friendsofpresta.org/modules/2024/02/20/ecgeneratebarcode.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-23T22:15:54Z" + } +} \ No newline at end of file