Publish Advisories

GHSA-4658-4qfx-9295
GHSA-9h6f-343x-p726
GHSA-mj4q-j8hp-mw73
GHSA-mx5q-46h2-qqfw
GHSA-336q-x7w8-cw7q
GHSA-4q2x-2wp6-7jhh
GHSA-m9m5-hfmm-xp78
GHSA-x64v-pq34-g3cq
GHSA-4h6p-wphh-f8rf
GHSA-4hvh-m426-wv8w
GHSA-5xg9-v43g-xgcj
GHSA-8pqc-xcjc-j8v3
GHSA-9gf5-vfx8-jvxx
GHSA-c2jm-97rm-g3c3
GHSA-mh7j-x4vr-3mg3
GHSA-pmv2-3483-4jqw
This commit is contained in:
advisory-database[bot]
2024-08-30 21:33:03 +00:00
parent c7f68f5c68
commit 0c7da972ca
16 changed files with 143 additions and 24 deletions
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-284"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9h6f-343x-p726",
"modified": "2024-01-19T21:30:35Z",
"modified": "2024-08-30T21:31:39Z",
"published": "2024-01-17T00:30:19Z",
"aliases": [
"CVE-2023-52042"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mj4q-j8hp-mw73",
"modified": "2024-01-23T15:30:57Z",
"modified": "2024-08-30T21:31:39Z",
"published": "2024-01-16T18:31:10Z",
"aliases": [
"CVE-2023-5558"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mx5q-46h2-qqfw",
"modified": "2024-01-23T18:31:11Z",
"modified": "2024-08-30T21:31:39Z",
"published": "2024-01-16T18:31:10Z",
"aliases": [
"CVE-2023-7154"
@@ -44,7 +44,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-121"
"CWE-121",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -44,7 +44,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-121"
"CWE-121",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m9m5-hfmm-xp78",
"modified": "2024-07-21T09:30:31Z",
"modified": "2024-08-30T21:31:39Z",
"published": "2024-07-21T09:30:31Z",
"aliases": [
"CVE-2024-37536"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x64v-pq34-g3cq",
"modified": "2024-07-21T09:30:32Z",
"modified": "2024-08-30T21:31:40Z",
"published": "2024-07-21T09:30:32Z",
"aliases": [
"CVE-2024-38435"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4h6p-wphh-f8rf",
"modified": "2024-08-02T15:31:19Z",
"modified": "2024-08-30T21:31:40Z",
"published": "2024-08-02T15:31:19Z",
"aliases": [
"CVE-2024-7029"
@@ -25,6 +25,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7029"
},
{
"type": "WEB",
"url": "https://www.akamai.com/blog/security-research/2024-corona-mirai-botnet-infects-zero-day-sirt"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-214-07"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4hvh-m426-wv8w",
"modified": "2024-08-30T03:30:44Z",
"modified": "2024-08-30T21:31:40Z",
"published": "2024-08-30T03:30:44Z",
"aliases": [
"CVE-2024-45490"
],
"details": "An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-30T03:15:03Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5xg9-v43g-xgcj",
"modified": "2024-08-26T21:30:34Z",
"modified": "2024-08-30T21:31:40Z",
"published": "2024-08-26T21:30:34Z",
"aliases": [
"CVE-2024-8105"
@@ -22,6 +22,10 @@
"type": "WEB",
"url": "https://github.com/binarly-io/Vulnerability-REsearch/blob/main/PKfail/BRLY-2024-005.md"
},
{
"type": "WEB",
"url": "https://kb.cert.org/vuls/id/455367"
},
{
"type": "WEB",
"url": "https://security.ts.fujitsu.com/ProductSecurity/content/Fujitsu-PSIRT-FJ-ISS-2024-072412-Security-Notice.pdf"
@@ -30,6 +34,14 @@
"type": "WEB",
"url": "https://uefi.org/specs/UEFI/2.9_A/32_Secure_Boot_and_Driver_Signing.html"
},
{
"type": "WEB",
"url": "https://www.binarly.io/advisories/brly-2024-005"
},
{
"type": "WEB",
"url": "https://www.gigabyte.com/us/Support/Security/2205"
},
{
"type": "WEB",
"url": "https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-07-25-001.html"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8pqc-xcjc-j8v3",
"modified": "2024-08-30T06:30:38Z",
"modified": "2024-08-30T21:31:40Z",
"published": "2024-08-30T06:30:38Z",
"aliases": [
"CVE-2024-3673"
],
"details": "The Web Directory Free WordPress plugin before 1.7.3 does not validate a parameter before using it in an include(), which could lead to Local File Inclusion issues.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-30T06:15:05Z"
@@ -0,0 +1,31 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9gf5-vfx8-jvxx",
"modified": "2024-08-30T21:31:40Z",
"published": "2024-08-30T21:31:40Z",
"aliases": [
"CVE-2024-42379"
],
"details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42379"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-30T20:15:07Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c2jm-97rm-g3c3",
"modified": "2024-08-30T03:30:44Z",
"modified": "2024-08-30T21:31:40Z",
"published": "2024-08-30T03:30:44Z",
"aliases": [
"CVE-2024-45488"
],
"details": "One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware or HyperV). The fixed versions are 7.0.5.1 LTS, 7.4.2, and 7.5.2.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-30T02:15:03Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mh7j-x4vr-3mg3",
"modified": "2024-08-30T18:30:40Z",
"modified": "2024-08-30T21:31:40Z",
"published": "2024-08-30T18:30:40Z",
"aliases": [
"CVE-2024-44918"
],
"details": "A cross-site scripting (XSS) vulnerability in the component admin_datarelate.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-30T17:15:15Z"
@@ -0,0 +1,58 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pmv2-3483-4jqw",
"modified": "2024-08-30T21:31:40Z",
"published": "2024-08-30T21:31:40Z",
"aliases": [
"CVE-2024-8346"
],
"details": "A vulnerability classified as critical has been found in SourceCodester Computer Laboratory Management System 1.0. Affected is the function update_settings_info of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8346"
},
{
"type": "WEB",
"url": "https://github.com/gaorenyusi/gaorenyusi/blob/main/lms1.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.276228"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.276228"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.400343"
},
{
"type": "WEB",
"url": "https://www.sourcecodester.com"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-30T21:15:16Z"
}
}