mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-4658-4qfx-9295 GHSA-9h6f-343x-p726 GHSA-mj4q-j8hp-mw73 GHSA-mx5q-46h2-qqfw GHSA-336q-x7w8-cw7q GHSA-4q2x-2wp6-7jhh GHSA-m9m5-hfmm-xp78 GHSA-x64v-pq34-g3cq GHSA-4h6p-wphh-f8rf GHSA-4hvh-m426-wv8w GHSA-5xg9-v43g-xgcj GHSA-8pqc-xcjc-j8v3 GHSA-9gf5-vfx8-jvxx GHSA-c2jm-97rm-g3c3 GHSA-mh7j-x4vr-3mg3 GHSA-pmv2-3483-4jqw
This commit is contained in:
@@ -28,7 +28,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-284"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-9h6f-343x-p726",
|
||||
"modified": "2024-01-19T21:30:35Z",
|
||||
"modified": "2024-08-30T21:31:39Z",
|
||||
"published": "2024-01-17T00:30:19Z",
|
||||
"aliases": [
|
||||
"CVE-2023-52042"
|
||||
@@ -28,7 +28,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-77"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-mj4q-j8hp-mw73",
|
||||
"modified": "2024-01-23T15:30:57Z",
|
||||
"modified": "2024-08-30T21:31:39Z",
|
||||
"published": "2024-01-16T18:31:10Z",
|
||||
"aliases": [
|
||||
"CVE-2023-5558"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-mx5q-46h2-qqfw",
|
||||
"modified": "2024-01-23T18:31:11Z",
|
||||
"modified": "2024-08-30T21:31:39Z",
|
||||
"published": "2024-01-16T18:31:10Z",
|
||||
"aliases": [
|
||||
"CVE-2023-7154"
|
||||
|
||||
@@ -44,7 +44,8 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-121"
|
||||
"CWE-121",
|
||||
"CWE-787"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -44,7 +44,8 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-121"
|
||||
"CWE-121",
|
||||
"CWE-787"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-m9m5-hfmm-xp78",
|
||||
"modified": "2024-07-21T09:30:31Z",
|
||||
"modified": "2024-08-30T21:31:39Z",
|
||||
"published": "2024-07-21T09:30:31Z",
|
||||
"aliases": [
|
||||
"CVE-2024-37536"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-x64v-pq34-g3cq",
|
||||
"modified": "2024-07-21T09:30:32Z",
|
||||
"modified": "2024-08-30T21:31:40Z",
|
||||
"published": "2024-07-21T09:30:32Z",
|
||||
"aliases": [
|
||||
"CVE-2024-38435"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4h6p-wphh-f8rf",
|
||||
"modified": "2024-08-02T15:31:19Z",
|
||||
"modified": "2024-08-30T21:31:40Z",
|
||||
"published": "2024-08-02T15:31:19Z",
|
||||
"aliases": [
|
||||
"CVE-2024-7029"
|
||||
@@ -25,6 +25,10 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7029"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.akamai.com/blog/security-research/2024-corona-mirai-botnet-infects-zero-day-sirt"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-214-07"
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4hvh-m426-wv8w",
|
||||
"modified": "2024-08-30T03:30:44Z",
|
||||
"modified": "2024-08-30T21:31:40Z",
|
||||
"published": "2024-08-30T03:30:44Z",
|
||||
"aliases": [
|
||||
"CVE-2024-45490"
|
||||
],
|
||||
"details": "An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -31,7 +34,7 @@
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-08-30T03:15:03Z"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-5xg9-v43g-xgcj",
|
||||
"modified": "2024-08-26T21:30:34Z",
|
||||
"modified": "2024-08-30T21:31:40Z",
|
||||
"published": "2024-08-26T21:30:34Z",
|
||||
"aliases": [
|
||||
"CVE-2024-8105"
|
||||
@@ -22,6 +22,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/binarly-io/Vulnerability-REsearch/blob/main/PKfail/BRLY-2024-005.md"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://kb.cert.org/vuls/id/455367"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.ts.fujitsu.com/ProductSecurity/content/Fujitsu-PSIRT-FJ-ISS-2024-072412-Security-Notice.pdf"
|
||||
@@ -30,6 +34,14 @@
|
||||
"type": "WEB",
|
||||
"url": "https://uefi.org/specs/UEFI/2.9_A/32_Secure_Boot_and_Driver_Signing.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.binarly.io/advisories/brly-2024-005"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.gigabyte.com/us/Support/Security/2205"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-07-25-001.html"
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-8pqc-xcjc-j8v3",
|
||||
"modified": "2024-08-30T06:30:38Z",
|
||||
"modified": "2024-08-30T21:31:40Z",
|
||||
"published": "2024-08-30T06:30:38Z",
|
||||
"aliases": [
|
||||
"CVE-2024-3673"
|
||||
],
|
||||
"details": "The Web Directory Free WordPress plugin before 1.7.3 does not validate a parameter before using it in an include(), which could lead to Local File Inclusion issues.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -27,7 +30,7 @@
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-08-30T06:15:05Z"
|
||||
|
||||
@@ -0,0 +1,31 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-9gf5-vfx8-jvxx",
|
||||
"modified": "2024-08-30T21:31:40Z",
|
||||
"published": "2024-08-30T21:31:40Z",
|
||||
"aliases": [
|
||||
"CVE-2024-42379"
|
||||
],
|
||||
"details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42379"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-08-30T20:15:07Z"
|
||||
}
|
||||
}
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-c2jm-97rm-g3c3",
|
||||
"modified": "2024-08-30T03:30:44Z",
|
||||
"modified": "2024-08-30T21:31:40Z",
|
||||
"published": "2024-08-30T03:30:44Z",
|
||||
"aliases": [
|
||||
"CVE-2024-45488"
|
||||
],
|
||||
"details": "One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware or HyperV). The fixed versions are 7.0.5.1 LTS, 7.4.2, and 7.5.2.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -31,7 +34,7 @@
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-08-30T02:15:03Z"
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-mh7j-x4vr-3mg3",
|
||||
"modified": "2024-08-30T18:30:40Z",
|
||||
"modified": "2024-08-30T21:31:40Z",
|
||||
"published": "2024-08-30T18:30:40Z",
|
||||
"aliases": [
|
||||
"CVE-2024-44918"
|
||||
],
|
||||
"details": "A cross-site scripting (XSS) vulnerability in the component admin_datarelate.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -25,9 +28,9 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-79"
|
||||
],
|
||||
"severity": null,
|
||||
"severity": "LOW",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-08-30T17:15:15Z"
|
||||
|
||||
@@ -0,0 +1,58 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-pmv2-3483-4jqw",
|
||||
"modified": "2024-08-30T21:31:40Z",
|
||||
"published": "2024-08-30T21:31:40Z",
|
||||
"aliases": [
|
||||
"CVE-2024-8346"
|
||||
],
|
||||
"details": "A vulnerability classified as critical has been found in SourceCodester Computer Laboratory Management System 1.0. Affected is the function update_settings_info of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
|
||||
},
|
||||
{
|
||||
"type": "CVSS_V4",
|
||||
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8346"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/gaorenyusi/gaorenyusi/blob/main/lms1.md"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://vuldb.com/?ctiid.276228"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://vuldb.com/?id.276228"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://vuldb.com/?submit.400343"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.sourcecodester.com"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-89"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-08-30T21:15:16Z"
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user