diff --git a/advisories/unreviewed/2024/10/GHSA-3768-v944-h92f/GHSA-3768-v944-h92f.json b/advisories/unreviewed/2024/10/GHSA-3768-v944-h92f/GHSA-3768-v944-h92f.json index aef006f14d9..51ea27d6f32 100644 --- a/advisories/unreviewed/2024/10/GHSA-3768-v944-h92f/GHSA-3768-v944-h92f.json +++ b/advisories/unreviewed/2024/10/GHSA-3768-v944-h92f/GHSA-3768-v944-h92f.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3768-v944-h92f", - "modified": "2024-10-11T18:32:50Z", + "modified": "2024-11-15T18:30:47Z", "published": "2024-10-11T18:32:50Z", "aliases": [ "CVE-2024-9539" ], "details": "An information disclosure vulnerability was identified in GitHub Enterprise Server via attacker uploaded asset URL allowing the attacker to retrieve metadata information of a user who clicks on the URL and further exploit it to create a convincing phishing page. This required the attacker to upload malicious SVG files and phish a victim user to click on that uploaded asset URL. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in versions 3.14.2, 3.13.5, 3.12.10, 3.11.16. This vulnerability was reported via the GitHub Bug Bounty program.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/10/GHSA-72qw-2vp3-gvg9/GHSA-72qw-2vp3-gvg9.json b/advisories/unreviewed/2024/10/GHSA-72qw-2vp3-gvg9/GHSA-72qw-2vp3-gvg9.json index aaf325434e5..bbd9821270d 100644 --- a/advisories/unreviewed/2024/10/GHSA-72qw-2vp3-gvg9/GHSA-72qw-2vp3-gvg9.json +++ b/advisories/unreviewed/2024/10/GHSA-72qw-2vp3-gvg9/GHSA-72qw-2vp3-gvg9.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-72qw-2vp3-gvg9", - "modified": "2024-10-31T12:30:32Z", + "modified": "2024-11-15T18:30:47Z", "published": "2024-10-11T18:32:50Z", "aliases": [ "CVE-2024-8376" ], "details": "In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific sequences of \"CONNECT\", \"DISCONNECT\", \"SUBSCRIBE\", \"UNSUBSCRIBE\" and \"PUBLISH\" packets.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/10/GHSA-g83h-4727-5rpv/GHSA-g83h-4727-5rpv.json b/advisories/unreviewed/2024/10/GHSA-g83h-4727-5rpv/GHSA-g83h-4727-5rpv.json index d243f524ea8..d99a62b0a09 100644 --- a/advisories/unreviewed/2024/10/GHSA-g83h-4727-5rpv/GHSA-g83h-4727-5rpv.json +++ b/advisories/unreviewed/2024/10/GHSA-g83h-4727-5rpv/GHSA-g83h-4727-5rpv.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g83h-4727-5rpv", - "modified": "2024-10-11T00:31:34Z", + "modified": "2024-11-15T18:30:47Z", "published": "2024-10-11T00:31:34Z", "aliases": [ "CVE-2024-9487" ], "details": "An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed resulting in unauthorized provisioning of users and access to the instance. Exploitation required the encrypted assertions feature to be enabled, and the attacker would require direct network access as well as a signed SAML response or metadata document. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.15 and was fixed in versions 3.11.16, 3.12.10, 3.13.5, and 3.14.2. This vulnerability was reported via the GitHub Bug Bounty program.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:C/RE:M/U:Red" diff --git a/advisories/unreviewed/2024/11/GHSA-2237-2j5h-553w/GHSA-2237-2j5h-553w.json b/advisories/unreviewed/2024/11/GHSA-2237-2j5h-553w/GHSA-2237-2j5h-553w.json new file mode 100644 index 00000000000..50622fb2f9e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2237-2j5h-553w/GHSA-2237-2j5h-553w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2237-2j5h-553w", + "modified": "2024-11-15T18:30:50Z", + "published": "2024-11-15T18:30:50Z", + "aliases": [ + "CVE-2023-20090" + ], + "details": "A vulnerability in Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to elevate privileges to root on an affected device.\n\nThis vulnerability is due to improper access control on certain CLI commands. An attacker could exploit this vulnerability by running a series of crafted commands. A successful exploit could allow the attacker to elevate privileges to root.\nCisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20090" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-file-write-rHKwegKf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-27" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-2wh9-xh8x-vvv4/GHSA-2wh9-xh8x-vvv4.json b/advisories/unreviewed/2024/11/GHSA-2wh9-xh8x-vvv4/GHSA-2wh9-xh8x-vvv4.json new file mode 100644 index 00000000000..3c1f0bf55b9 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2wh9-xh8x-vvv4/GHSA-2wh9-xh8x-vvv4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2wh9-xh8x-vvv4", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2021-34752" + ], + "details": "A vulnerability in the CLI of Cisco FTD Software could allow an authenticated, local attacker with administrative privileges to execute arbitrary commands with root privileges on the underlying operating system of an affected device. \n\nThis vulnerability is due to insufficient validation of user-supplied command arguments. An attacker could exploit this vulnerability by submitting crafted input to the affected commands. A successful exploit could allow the attacker to execute commands with root privileges on the underlying operating system.\nCisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-34752" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-cmdinject-FmzsLN8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-33j7-h653-5rrc/GHSA-33j7-h653-5rrc.json b/advisories/unreviewed/2024/11/GHSA-33j7-h653-5rrc/GHSA-33j7-h653-5rrc.json new file mode 100644 index 00000000000..fe594209617 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-33j7-h653-5rrc/GHSA-33j7-h653-5rrc.json @@ -0,0 +1,70 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33j7-h653-5rrc", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2021-1464" + ], + "details": "A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization checking and gain restricted access to the configuration information of an affected system.\nThis vulnerability exists because the affected software has insufficient input validation for certain commands. An attacker could exploit this vulnerability by sending crafted requests to the affected commands of an affected system. A successful exploit could allow the attacker to bypass authorization checking and gain restricted access to the configuration data of the affected system.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-1464" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdw-sqlinj-HDJUeEAX" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-vdaemon-bo-RuzzEA2" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vman-auth-bypass-Z3Zze5XC" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vman-authorization-b-GUEpSLK" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vman-cmdinj-nRHKgfHX" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vman-dir-trav-Bpwc5gtm" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vman-xml-ext-entity-q6Z7uVUg" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanage-cql-inject-c7z9QqyB" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanage-info-disclos-gGvm9Mfu" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-37xg-wj5r-mvrr/GHSA-37xg-wj5r-mvrr.json b/advisories/unreviewed/2024/11/GHSA-37xg-wj5r-mvrr/GHSA-37xg-wj5r-mvrr.json new file mode 100644 index 00000000000..ec3eca29ddf --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-37xg-wj5r-mvrr/GHSA-37xg-wj5r-mvrr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37xg-wj5r-mvrr", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2024-46462" + ], + "details": "By default, dedicated folders of ZEDMAIL for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ZEDMAIL has to be modified to prevent this vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46462" + }, + { + "type": "WEB", + "url": "https://www.primx.eu/en/bulletins/security-bulletin-24931936" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-39j2-2qp4-6rgc/GHSA-39j2-2qp4-6rgc.json b/advisories/unreviewed/2024/11/GHSA-39j2-2qp4-6rgc/GHSA-39j2-2qp4-6rgc.json new file mode 100644 index 00000000000..ca4d265e176 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-39j2-2qp4-6rgc/GHSA-39j2-2qp4-6rgc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39j2-2qp4-6rgc", + "modified": "2024-11-15T18:30:52Z", + "published": "2024-11-15T18:30:52Z", + "aliases": [ + "CVE-2024-50800" + ], + "details": "Cross Site Scripting vulnerability in M2000 Smart4Web before v.5.020241004 allows a remote attacker to execute arbitrary code via the error parameter in URL", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50800" + }, + { + "type": "WEB", + "url": "https://github.com/Jellyfishxoxo/vulnerability-research/tree/main/CVE-2024-50800" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3jv8-hvr8-2qwh/GHSA-3jv8-hvr8-2qwh.json b/advisories/unreviewed/2024/11/GHSA-3jv8-hvr8-2qwh/GHSA-3jv8-hvr8-2qwh.json new file mode 100644 index 00000000000..294a1513c02 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3jv8-hvr8-2qwh/GHSA-3jv8-hvr8-2qwh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jv8-hvr8-2qwh", + "modified": "2024-11-15T18:30:50Z", + "published": "2024-11-15T18:30:50Z", + "aliases": [ + "CVE-2023-20091" + ], + "details": "A vulnerability in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device.\n\nThis vulnerability is due to improper access controls on files that are on the local file system. An attacker could exploit this vulnerability by placing a symbolic link in a specific location on the local file system of an affected device. A successful exploit could allow the attacker to overwrite arbitrary files on the affected device. To exploit this vulnerability, an attacker would need to have a remote support user account.\nCisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20091" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-file-write-rHKwegKf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-61" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3pc7-c3mc-73r6/GHSA-3pc7-c3mc-73r6.json b/advisories/unreviewed/2024/11/GHSA-3pc7-c3mc-73r6/GHSA-3pc7-c3mc-73r6.json new file mode 100644 index 00000000000..f58dd0d37dc --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3pc7-c3mc-73r6/GHSA-3pc7-c3mc-73r6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3pc7-c3mc-73r6", + "modified": "2024-11-15T18:30:52Z", + "published": "2024-11-15T18:30:52Z", + "aliases": [ + "CVE-2024-46465" + ], + "details": "By default, dedicated folders of CRYHOD for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of CRYHOD has to be modified to prevent this vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46465" + }, + { + "type": "WEB", + "url": "https://www.primx.eu/en/bulletins/security-bulletin-24932296" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3rrh-hp3f-9r6p/GHSA-3rrh-hp3f-9r6p.json b/advisories/unreviewed/2024/11/GHSA-3rrh-hp3f-9r6p/GHSA-3rrh-hp3f-9r6p.json new file mode 100644 index 00000000000..147c0740a9b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3rrh-hp3f-9r6p/GHSA-3rrh-hp3f-9r6p.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rrh-hp3f-9r6p", + "modified": "2024-11-15T18:30:49Z", + "published": "2024-11-15T18:30:49Z", + "aliases": [ + "CVE-2022-20649" + ], + "details": "A vulnerability in Cisco RCM for Cisco StarOS Software could allow an unauthenticated, remote attacker to perform remote code execution on the application with root-level privileges in the context of the configured container.\n\nThis vulnerability exists because the debug mode is incorrectly enabled for specific services. An attacker could exploit this vulnerability by connecting to the device and navigating to the service with debug mode enabled. A successful exploit could allow the attacker to execute arbitrary commands as the root user.\nThe attacker would need to perform detailed reconnaissance to allow for unauthenticated access. The vulnerability can also be exploited by an authenticated attacker.\nCisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-20649" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rcm-vuls-7cS3Nuq" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-tetr-cmd-injc-skrwGO" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-xss-FmbPu2pe" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-489" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-42jm-px5r-4qxq/GHSA-42jm-px5r-4qxq.json b/advisories/unreviewed/2024/11/GHSA-42jm-px5r-4qxq/GHSA-42jm-px5r-4qxq.json new file mode 100644 index 00000000000..e05de5e61e4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-42jm-px5r-4qxq/GHSA-42jm-px5r-4qxq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42jm-px5r-4qxq", + "modified": "2024-11-15T18:30:50Z", + "published": "2024-11-15T18:30:50Z", + "aliases": [ + "CVE-2024-41784" + ], + "details": "IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, and 6.1.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing \"dot dot dot\" sequences (/.../) to view arbitrary files on the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41784" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7173631" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-32" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4383-m935-j5wh/GHSA-4383-m935-j5wh.json b/advisories/unreviewed/2024/11/GHSA-4383-m935-j5wh/GHSA-4383-m935-j5wh.json new file mode 100644 index 00000000000..334633f98e1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4383-m935-j5wh/GHSA-4383-m935-j5wh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4383-m935-j5wh", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2021-34753" + ], + "details": "A vulnerability in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured rules for ENIP traffic.\n\nThis vulnerability is due to incomplete processing during deep packet inspection for ENIP packets. An attacker could exploit this vulnerability by sending a crafted ENIP packet to the targeted interface. A successful exploit could allow the attacker to bypass configured access control and intrusion policies that should trigger and drop for the ENIP packet.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-34753" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-enip-bypass-eFsxd8KP" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4789-39gm-mc98/GHSA-4789-39gm-mc98.json b/advisories/unreviewed/2024/11/GHSA-4789-39gm-mc98/GHSA-4789-39gm-mc98.json new file mode 100644 index 00000000000..5cf66ba56c8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4789-39gm-mc98/GHSA-4789-39gm-mc98.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4789-39gm-mc98", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2021-1483" + ], + "details": "A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system.\nThis vulnerability is due to improper handling of XML External Entity (XXE) entries when the affected software parses certain XML files. An attacker could exploit this vulnerability by persuading a user to import a crafted XML file with malicious entries. A successful exploit could allow the attacker to read and write files within the affected application.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-1483" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vman-cmdinj-nRHKgfHX" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vman-xml-ext-entity-q6Z7uVUg" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanage-info-disclos-gGvm9Mfu" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-497w-6wcv-pw45/GHSA-497w-6wcv-pw45.json b/advisories/unreviewed/2024/11/GHSA-497w-6wcv-pw45/GHSA-497w-6wcv-pw45.json new file mode 100644 index 00000000000..24019dea82c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-497w-6wcv-pw45/GHSA-497w-6wcv-pw45.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-497w-6wcv-pw45", + "modified": "2024-11-15T18:30:50Z", + "published": "2024-11-15T18:30:50Z", + "aliases": [ + "CVE-2022-20939" + ], + "details": "A vulnerability in the web-based management interface of Cisco Smart Software Manager On-Prem could allow an authenticated, remote attacker to elevate privileges on an affected system.\nThis vulnerability is due to inadequate protection of sensitive user information. An attacker could exploit this vulnerability by accessing certain logs on an affected system. A successful exploit could allow the attacker to use the obtained information to elevate privileges to System Admin.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-20939" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bw-thinrcpt-xss-gSj4CecU" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cssm-priv-esc-SEjz69dv" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-922" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4c63-9j96-375q/GHSA-4c63-9j96-375q.json b/advisories/unreviewed/2024/11/GHSA-4c63-9j96-375q/GHSA-4c63-9j96-375q.json new file mode 100644 index 00000000000..3646cc40149 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4c63-9j96-375q/GHSA-4c63-9j96-375q.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4c63-9j96-375q", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2021-1484" + ], + "details": "A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to inject arbitrary commands on an affected system and cause a denial of service (DoS) condition.\nThis vulnerability is due to improper input validation of user-supplied input to the device template configuration. An attacker could exploit this vulnerability by submitting crafted input to the device template configuration. A successful exploit could allow the attacker to cause a DoS condition on the affected system.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-1484" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vman-cmdinj-nRHKgfHX" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanage-info-disclos-gGvm9Mfu" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-88" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4fp3-wrmc-3g2x/GHSA-4fp3-wrmc-3g2x.json b/advisories/unreviewed/2024/11/GHSA-4fp3-wrmc-3g2x/GHSA-4fp3-wrmc-3g2x.json new file mode 100644 index 00000000000..48fea641a8c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4fp3-wrmc-3g2x/GHSA-4fp3-wrmc-3g2x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fp3-wrmc-3g2x", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2021-1491" + ], + "details": "A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to read arbitrary files on the underlying file system of the device.\nThis vulnerability is due to insufficient file scope limiting. An attacker could exploit this vulnerability by creating a specific file reference on the file system and then accessing it through the web-based management interface. A successful exploit could allow the attacker to read arbitrary files from the file system of the underlying operating system.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-1491" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanage-info-disclos-gGvm9Mfu" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4rr7-4fw4-qcwc/GHSA-4rr7-4fw4-qcwc.json b/advisories/unreviewed/2024/11/GHSA-4rr7-4fw4-qcwc/GHSA-4rr7-4fw4-qcwc.json new file mode 100644 index 00000000000..937bd286f62 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4rr7-4fw4-qcwc/GHSA-4rr7-4fw4-qcwc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rr7-4fw4-qcwc", + "modified": "2024-11-15T18:30:50Z", + "published": "2024-11-15T18:30:50Z", + "aliases": [ + "CVE-2023-20060" + ], + "details": "A vulnerability in the web-based management interface of Cisco Prime Collaboration Deployment could allow an unauthenticated, remote attacker to conduct a cross-site scripting attack against a user of the interface.\n\nThis vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.\nCisco plans to release software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20060" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-pcd-xss-jDXpjm7" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-58gm-hrw8-j9xg/GHSA-58gm-hrw8-j9xg.json b/advisories/unreviewed/2024/11/GHSA-58gm-hrw8-j9xg/GHSA-58gm-hrw8-j9xg.json new file mode 100644 index 00000000000..56520450988 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-58gm-hrw8-j9xg/GHSA-58gm-hrw8-j9xg.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58gm-hrw8-j9xg", + "modified": "2024-11-15T18:30:50Z", + "published": "2024-11-15T18:30:50Z", + "aliases": [ + "CVE-2024-11246" + ], + "details": "A vulnerability, which was classified as problematic, was found in code-projects Farmacia 1.0. Affected is an unknown function of the file /adicionar-cliente.php. The manipulation of the argument nome/cpf/dataNascimento leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions the parameter \"nome\" to be affected. But further inspection indicates that other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11246" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/curry136/cve/blob/main/xss8.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.284682" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.284682" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.443189" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5pj6-3hcq-wv78/GHSA-5pj6-3hcq-wv78.json b/advisories/unreviewed/2024/11/GHSA-5pj6-3hcq-wv78/GHSA-5pj6-3hcq-wv78.json new file mode 100644 index 00000000000..40415861649 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5pj6-3hcq-wv78/GHSA-5pj6-3hcq-wv78.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5pj6-3hcq-wv78", + "modified": "2024-11-15T18:30:49Z", + "published": "2024-11-15T18:30:49Z", + "aliases": [ + "CVE-2022-20685" + ], + "details": "A vulnerability in the Modbus preprocessor of the Snort detection engine could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.\nThis vulnerability is due to an integer overflow while processing Modbus traffic. An attacker could exploit this vulnerability by sending crafted Modbus traffic through an affected device. A successful exploit could allow the attacker to cause the Snort process to hang, causing traffic inspection to stop.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-20685" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sna-xss-NXOxDhRQ" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort-dos-9D3hJLuj" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-62mp-w633-xcfv/GHSA-62mp-w633-xcfv.json b/advisories/unreviewed/2024/11/GHSA-62mp-w633-xcfv/GHSA-62mp-w633-xcfv.json new file mode 100644 index 00000000000..82fe165e58d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-62mp-w633-xcfv/GHSA-62mp-w633-xcfv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62mp-w633-xcfv", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2024-24450" + ], + "details": "Stack-based memcpy buffer overflow in the ngap_handle_pdu_session_resource_setup_response routine in OpenAirInterface CN5G AMF <= 2.0.0 allows a remote attacker with access to the N2 interface to carry out denial of service against the AMF and potentially execute code by sending a PDU Session Resource Setup Response with a suffciently large FailedToSetupList IE.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24450" + }, + { + "type": "WEB", + "url": "https://cellularsecurity.org/ransacked" + }, + { + "type": "WEB", + "url": "https://openairinterface.org" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-69hg-2xq4-4m8v/GHSA-69hg-2xq4-4m8v.json b/advisories/unreviewed/2024/11/GHSA-69hg-2xq4-4m8v/GHSA-69hg-2xq4-4m8v.json new file mode 100644 index 00000000000..ff24a6e2eca --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-69hg-2xq4-4m8v/GHSA-69hg-2xq4-4m8v.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69hg-2xq4-4m8v", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2024-24449" + ], + "details": "An uninitialized pointer dereference in the NasPdu::NasPdu component of OpenAirInterface CN5G AMF up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted InitialUEMessage message sent to the AMF.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24449" + }, + { + "type": "WEB", + "url": "https://cellularsecurity.org/ransacked" + }, + { + "type": "WEB", + "url": "https://openairinterface.org" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6fj3-23hj-67pw/GHSA-6fj3-23hj-67pw.json b/advisories/unreviewed/2024/11/GHSA-6fj3-23hj-67pw/GHSA-6fj3-23hj-67pw.json new file mode 100644 index 00000000000..dc156d02716 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6fj3-23hj-67pw/GHSA-6fj3-23hj-67pw.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6fj3-23hj-67pw", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2021-1481" + ], + "details": "A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct Cypher query language injection attacks on an affected system.\nThis vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to the interface of an affected system. A successful exploit could allow the attacker to obtain sensitive information.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-1481" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vman-auth-bypass-Z3Zze5XC" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanage-cql-inject-c7z9QqyB" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-943" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6v73-jj37-xggm/GHSA-6v73-jj37-xggm.json b/advisories/unreviewed/2024/11/GHSA-6v73-jj37-xggm/GHSA-6v73-jj37-xggm.json new file mode 100644 index 00000000000..aa1e32f4588 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6v73-jj37-xggm/GHSA-6v73-jj37-xggm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v73-jj37-xggm", + "modified": "2024-11-15T18:30:50Z", + "published": "2024-11-15T18:30:50Z", + "aliases": [ + "CVE-2023-20093" + ], + "details": "Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device.\n\nThese vulnerabilities are due to improper access controls on files that are on the local file system. An attacker could exploit these vulnerabilities by placing a symbolic link in a specific location on the local file system of an affected device. A successful exploit could allow the attacker to overwrite arbitrary files on the affected device. To exploit these vulnerabilities, an attacker would need to have a remote support user account.\nNote: CVE-2023-20092 does not affect Cisco DX70, DX80, TelePresence MX Series, or TelePresence SX Series devices.\nCisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20093" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-file-write-rHKwegKf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-61" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6w87-fwmq-3h7f/GHSA-6w87-fwmq-3h7f.json b/advisories/unreviewed/2024/11/GHSA-6w87-fwmq-3h7f/GHSA-6w87-fwmq-3h7f.json new file mode 100644 index 00000000000..0927f8c628a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6w87-fwmq-3h7f/GHSA-6w87-fwmq-3h7f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6w87-fwmq-3h7f", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2024-39726" + ], + "details": "IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39726" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7176208" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-77g8-jx2r-h4w8/GHSA-77g8-jx2r-h4w8.json b/advisories/unreviewed/2024/11/GHSA-77g8-jx2r-h4w8/GHSA-77g8-jx2r-h4w8.json new file mode 100644 index 00000000000..23b0cae24b5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-77g8-jx2r-h4w8/GHSA-77g8-jx2r-h4w8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77g8-jx2r-h4w8", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2024-46463" + ], + "details": "By default, dedicated folders of ORIZON for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ORIZON has to be modified to prevent this vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46463" + }, + { + "type": "WEB", + "url": "https://www.primx.eu/en/bulletins/security-bulletin-24932297" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7hx2-pgg7-f6rg/GHSA-7hx2-pgg7-f6rg.json b/advisories/unreviewed/2024/11/GHSA-7hx2-pgg7-f6rg/GHSA-7hx2-pgg7-f6rg.json new file mode 100644 index 00000000000..0fe4518c5ca --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7hx2-pgg7-f6rg/GHSA-7hx2-pgg7-f6rg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hx2-pgg7-f6rg", + "modified": "2024-11-15T18:30:49Z", + "published": "2024-11-15T18:30:49Z", + "aliases": [ + "CVE-2022-20654" + ], + "details": "A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface.\nThis vulnerability is due to insufficient validation of user-supplied input by the web-based interface of Cisco Webex Meetings. An attacker could exploit this vulnerability by persuading a user of the interface to click a maliciously crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-20654" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-xss-FmbPu2pe" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7q63-79xq-2jj4/GHSA-7q63-79xq-2jj4.json b/advisories/unreviewed/2024/11/GHSA-7q63-79xq-2jj4/GHSA-7q63-79xq-2jj4.json new file mode 100644 index 00000000000..f204e9a5eae --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7q63-79xq-2jj4/GHSA-7q63-79xq-2jj4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q63-79xq-2jj4", + "modified": "2024-11-15T18:30:49Z", + "published": "2024-11-15T18:30:49Z", + "aliases": [ + "CVE-2022-20766" + ], + "details": "A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adaptive Telephone Adapter firmware could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.\nThis vulnerability is due to an out-of-bounds read when processing Cisco Discovery Protocol packets. An attacker could exploit this vulnerability by sending crafted Cisco Discovery Protocol packets to an affected device. A successful exploit could allow the attacker to cause a service restart.Cisco has released firmware updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-20766" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ata19x-multivuln-GEZYVvs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7q82-fxvh-gf2x/GHSA-7q82-fxvh-gf2x.json b/advisories/unreviewed/2024/11/GHSA-7q82-fxvh-gf2x/GHSA-7q82-fxvh-gf2x.json new file mode 100644 index 00000000000..b4b81591ed1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7q82-fxvh-gf2x/GHSA-7q82-fxvh-gf2x.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q82-fxvh-gf2x", + "modified": "2024-11-15T18:30:50Z", + "published": "2024-11-15T18:30:50Z", + "aliases": [ + "CVE-2024-51164" + ], + "details": "Multiple parameters have SQL injection vulnerability in JEPaaS 7.2.8 via /je/login/btnLog/insertBtnLog, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51164" + }, + { + "type": "WEB", + "url": "https://gitee.com/ketr/jepaas-release" + }, + { + "type": "WEB", + "url": "https://github.com/abcc111/vulns/blob/main/JEPaaS/Multiple%20parameters%20have%20SQL%20injection%20issues%20in%20JEPAAS.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-922x-h9px-jp85/GHSA-922x-h9px-jp85.json b/advisories/unreviewed/2024/11/GHSA-922x-h9px-jp85/GHSA-922x-h9px-jp85.json new file mode 100644 index 00000000000..76c29cbc504 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-922x-h9px-jp85/GHSA-922x-h9px-jp85.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-922x-h9px-jp85", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2021-1482" + ], + "details": "A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization checking and gain access to sensitive information on an affected system.\nThis vulnerability is due to insufficient authorization checks. An attacker could exploit this vulnerability by sending crafted HTTP requests to the web-based management interface of an affected system. A successful exploit could allow the attacker to bypass authorization checking and gain access to sensitive information on the affected system.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-1482" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vman-auth-bypass-Z3Zze5XC" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-92gj-2wf7-h87v/GHSA-92gj-2wf7-h87v.json b/advisories/unreviewed/2024/11/GHSA-92gj-2wf7-h87v/GHSA-92gj-2wf7-h87v.json new file mode 100644 index 00000000000..d4a7aeec161 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-92gj-2wf7-h87v/GHSA-92gj-2wf7-h87v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92gj-2wf7-h87v", + "modified": "2024-11-15T18:30:50Z", + "published": "2024-11-15T18:30:50Z", + "aliases": [ + "CVE-2022-20931" + ], + "details": "A vulnerability in the version control of Cisco TelePresence CE Software for Cisco Touch 10 Devices could allow an unauthenticated, adjacent attacker to install an older version of the software on an affected device.\nThis vulnerability is due to insufficient version control. An attacker could exploit this vulnerability by installing an older version of Cisco TelePresence CE Software on an affected device. A successful exploit could allow the attacker to take advantage of vulnerabilities in older versions of the software.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-20931" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-CTT-DAV-HSvEHHEt" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-527" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-95xp-3pj7-m5fh/GHSA-95xp-3pj7-m5fh.json b/advisories/unreviewed/2024/11/GHSA-95xp-3pj7-m5fh/GHSA-95xp-3pj7-m5fh.json new file mode 100644 index 00000000000..6054c8dab00 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-95xp-3pj7-m5fh/GHSA-95xp-3pj7-m5fh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95xp-3pj7-m5fh", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2021-34751" + ], + "details": "A vulnerability in the administrative web-based GUI configuration manager of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to access sensitive configuration information. The attacker would require low privilege credentials on an affected device.\nThis vulnerability exists because of improper encryption of sensitive information stored within the GUI configuration manager. An attacker could exploit this vulnerability by logging into the GUI of Cisco FMC Software and navigating to certain sensitive configurations. A successful exploit could allow the attacker to view sensitive configuration parameters in clear text.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.[[Publication_URL{Layout()}]]This advisory is part of the October 2021 release of the Cisco ASA, FTD, and FMC Security Advisory Bundled publication. For a complete list of the advisories and links to them, see . ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-34751" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-infodisc-Ft2WVmNU" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-317" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9hgf-jcfq-gvxc/GHSA-9hgf-jcfq-gvxc.json b/advisories/unreviewed/2024/11/GHSA-9hgf-jcfq-gvxc/GHSA-9hgf-jcfq-gvxc.json index 0d2b618e5c5..7135774d034 100644 --- a/advisories/unreviewed/2024/11/GHSA-9hgf-jcfq-gvxc/GHSA-9hgf-jcfq-gvxc.json +++ b/advisories/unreviewed/2024/11/GHSA-9hgf-jcfq-gvxc/GHSA-9hgf-jcfq-gvxc.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-9qmw-4j8r-7jvx/GHSA-9qmw-4j8r-7jvx.json b/advisories/unreviewed/2024/11/GHSA-9qmw-4j8r-7jvx/GHSA-9qmw-4j8r-7jvx.json new file mode 100644 index 00000000000..e978f3bfc52 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9qmw-4j8r-7jvx/GHSA-9qmw-4j8r-7jvx.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qmw-4j8r-7jvx", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2024-11248" + ], + "details": "A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. Affected by this issue is the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg. The manipulation of the argument rebootTime leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11248" + }, + { + "type": "WEB", + "url": "https://tasty-foxtrot-3a8.notion.site/Tenda-AC10v4-formSetRebootTimer-stack-overflow-13d0448e619580bf8ab1df7cfb6c018b" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.284684" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.284684" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.443204" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9rg9-5x45-8r53/GHSA-9rg9-5x45-8r53.json b/advisories/unreviewed/2024/11/GHSA-9rg9-5x45-8r53/GHSA-9rg9-5x45-8r53.json new file mode 100644 index 00000000000..d04b1dc5928 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9rg9-5x45-8r53/GHSA-9rg9-5x45-8r53.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rg9-5x45-8r53", + "modified": "2024-11-15T18:30:50Z", + "published": "2024-11-15T18:30:50Z", + "aliases": [ + "CVE-2024-50649" + ], + "details": "The user avatar upload function in python_book V1.0 has an arbitrary file upload vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50649" + }, + { + "type": "WEB", + "url": "https://github.com/Yllxx03/CVE/blob/main/python_book/FileUpload.md" + }, + { + "type": "WEB", + "url": "https://github.com/Yllxx03/CVE/tree/main/CVE-2024-50649" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9rq6-3xh4-jjch/GHSA-9rq6-3xh4-jjch.json b/advisories/unreviewed/2024/11/GHSA-9rq6-3xh4-jjch/GHSA-9rq6-3xh4-jjch.json new file mode 100644 index 00000000000..dc7dbc5b99b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9rq6-3xh4-jjch/GHSA-9rq6-3xh4-jjch.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rq6-3xh4-jjch", + "modified": "2024-11-15T18:30:50Z", + "published": "2024-11-15T18:30:50Z", + "aliases": [ + "CVE-2024-11244" + ], + "details": "A vulnerability classified as critical was found in code-projects Farmacia 1.0. This vulnerability affects unknown code of the file /editar-cliente.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11244" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/zsx020121/cve/blob/main/sql.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.284680" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.284680" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.443177" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9rr6-vq6q-pwwr/GHSA-9rr6-vq6q-pwwr.json b/advisories/unreviewed/2024/11/GHSA-9rr6-vq6q-pwwr/GHSA-9rr6-vq6q-pwwr.json new file mode 100644 index 00000000000..291131bc0e2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9rr6-vq6q-pwwr/GHSA-9rr6-vq6q-pwwr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rr6-vq6q-pwwr", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2024-46383" + ], + "details": "Hathway Skyworth Router CM5100-511 v4.1.1.24 was discovered to store sensitive information about USB and Wifi connected devices in plaintext.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46383" + }, + { + "type": "WEB", + "url": "https://github.com/nitinronge91/Sensitive-Information-disclosure-via-SPI-flash-firmware-for-Hathway-router-CVE-2024-46383" + }, + { + "type": "WEB", + "url": "http://skyworth.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-c6cm-r234-phmq/GHSA-c6cm-r234-phmq.json b/advisories/unreviewed/2024/11/GHSA-c6cm-r234-phmq/GHSA-c6cm-r234-phmq.json new file mode 100644 index 00000000000..c53de34f9d9 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-c6cm-r234-phmq/GHSA-c6cm-r234-phmq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6cm-r234-phmq", + "modified": "2024-11-15T18:30:50Z", + "published": "2024-11-15T18:30:50Z", + "aliases": [ + "CVE-2023-20036" + ], + "details": "A vulnerability in the web UI of Cisco IND could allow an authenticated, remote attacker to execute arbitrary commands with administrative privileges on the underlying operating system of an affected device.\n\nThis vulnerability is due to improper input validation when uploading a Device Pack. An attacker could exploit this vulnerability by altering the request that is sent when uploading a Device Pack. A successful exploit could allow the attacker to execute arbitrary commands as NT AUTHORITY\\SYSTEM on the underlying operating system of an affected device.\nCisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20036" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ind-CAeLFk6V" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cgr4-9xhv-p6x6/GHSA-cgr4-9xhv-p6x6.json b/advisories/unreviewed/2024/11/GHSA-cgr4-9xhv-p6x6/GHSA-cgr4-9xhv-p6x6.json new file mode 100644 index 00000000000..48a3def58b4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cgr4-9xhv-p6x6/GHSA-cgr4-9xhv-p6x6.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cgr4-9xhv-p6x6", + "modified": "2024-11-15T18:30:50Z", + "published": "2024-11-15T18:30:50Z", + "aliases": [ + "CVE-2024-11245" + ], + "details": "A vulnerability, which was classified as critical, has been found in code-projects Farmacia 1.0. This issue affects some unknown processing of the file /editar-produto.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11245" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/WEFNNTT/cve/blob/main/sql.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.284681" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.284681" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.443188" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cp82-336p-fjw5/GHSA-cp82-336p-fjw5.json b/advisories/unreviewed/2024/11/GHSA-cp82-336p-fjw5/GHSA-cp82-336p-fjw5.json new file mode 100644 index 00000000000..f3a911aeca8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cp82-336p-fjw5/GHSA-cp82-336p-fjw5.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp82-336p-fjw5", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2024-11251" + ], + "details": "A vulnerability was found in erzhongxmu Jeewms up to 20241108. It has been rated as critical. This issue affects some unknown processing of the file cgReportController.do of the component AuthInterceptor. The manipulation of the argument begin_date leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11251" + }, + { + "type": "WEB", + "url": "https://gitee.com/erzhongxmu/JEEWMS/issues/IB2XZG" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.284687" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.284687" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-crhm-9fh5-299j/GHSA-crhm-9fh5-299j.json b/advisories/unreviewed/2024/11/GHSA-crhm-9fh5-299j/GHSA-crhm-9fh5-299j.json new file mode 100644 index 00000000000..0d4972b00b3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-crhm-9fh5-299j/GHSA-crhm-9fh5-299j.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crhm-9fh5-299j", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2024-24447" + ], + "details": "Stack-based memcpy buffer overflow in the ngap_handle_pdu_session_resource_setup_response routine in OpenAirInterface CN5G AMF <= 2.0.0 allows a remote attacker with access to the N2 interface to carry out denial of service against the AMF and potentially execute code by sending a PDU Session Resource Setup Response with a ResourceFailedToSetupList containing zero elements.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24447" + }, + { + "type": "WEB", + "url": "https://cellularsecurity.org/ransacked" + }, + { + "type": "WEB", + "url": "https://openairinterface.org" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cxr4-643w-mfv3/GHSA-cxr4-643w-mfv3.json b/advisories/unreviewed/2024/11/GHSA-cxr4-643w-mfv3/GHSA-cxr4-643w-mfv3.json new file mode 100644 index 00000000000..1895dac121e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cxr4-643w-mfv3/GHSA-cxr4-643w-mfv3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxr4-643w-mfv3", + "modified": "2024-11-15T18:30:50Z", + "published": "2024-11-15T18:30:50Z", + "aliases": [ + "CVE-2024-50651" + ], + "details": "java_shop 1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50651" + }, + { + "type": "WEB", + "url": "https://github.com/Yllxx03/CVE/blob/main/java_shop/BrokenAccessControl.md" + }, + { + "type": "WEB", + "url": "https://github.com/Yllxx03/CVE/tree/main/CVE-2024-50651" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f2mp-jf9g-wxgx/GHSA-f2mp-jf9g-wxgx.json b/advisories/unreviewed/2024/11/GHSA-f2mp-jf9g-wxgx/GHSA-f2mp-jf9g-wxgx.json new file mode 100644 index 00000000000..479133f919f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f2mp-jf9g-wxgx/GHSA-f2mp-jf9g-wxgx.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2mp-jf9g-wxgx", + "modified": "2024-11-15T18:30:49Z", + "published": "2024-11-15T18:30:49Z", + "aliases": [ + "CVE-2022-20652" + ], + "details": "A vulnerability in the web-based management interface and in the API subsystem of Cisco Tetration could allow an authenticated, remote attacker to inject arbitrary commands to be executed with root-level privileges on the underlying operating system.\nThis vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by submitting a crafted HTTP message to the affected system. A successful exploit could allow the attacker to execute commands with root-level privileges. To exploit this vulnerability, an attacker would need valid administrator-level credentials.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-20652" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-tetr-cmd-injc-skrwGO" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-xss-FmbPu2pe" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f927-34r4-vxxw/GHSA-f927-34r4-vxxw.json b/advisories/unreviewed/2024/11/GHSA-f927-34r4-vxxw/GHSA-f927-34r4-vxxw.json new file mode 100644 index 00000000000..c9a2b71808b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f927-34r4-vxxw/GHSA-f927-34r4-vxxw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f927-34r4-vxxw", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2024-50653" + ], + "details": "CRMEB <=5.4.0 is vulnerable to Incorrect Access Control. Users can bypass the front-end restriction of only being able to claim coupons once by capturing packets and sending a large number of data packets for coupon collection, achieving unlimited coupon collection.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50653" + }, + { + "type": "WEB", + "url": "https://github.com/Yllxx03/CVE/tree/main/CVE-2024-50653" + }, + { + "type": "WEB", + "url": "https://github.com/crmeb" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fvq9-6j72-7gcv/GHSA-fvq9-6j72-7gcv.json b/advisories/unreviewed/2024/11/GHSA-fvq9-6j72-7gcv/GHSA-fvq9-6j72-7gcv.json new file mode 100644 index 00000000000..92dc26091d2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fvq9-6j72-7gcv/GHSA-fvq9-6j72-7gcv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvq9-6j72-7gcv", + "modified": "2024-11-15T18:30:50Z", + "published": "2024-11-15T18:30:50Z", + "aliases": [ + "CVE-2023-20004" + ], + "details": "Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device.\n\nThese vulnerabilities are due to improper access controls on files that are on the local file system. An attacker could exploit these vulnerabilities by placing a symbolic link in a specific location on the local file system of an affected device. A successful exploit could allow the attacker to overwrite arbitrary files on the affected device. To exploit these vulnerabilities, an attacker would need to have a remote support user account.\nNote: CVE-2023-20092 does not affect Cisco DX70, DX80, TelePresence MX Series, or TelePresence SX Series devices.\nCisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20004" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-file-write-rHKwegKf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fw7g-x8q3-h9pr/GHSA-fw7g-x8q3-h9pr.json b/advisories/unreviewed/2024/11/GHSA-fw7g-x8q3-h9pr/GHSA-fw7g-x8q3-h9pr.json new file mode 100644 index 00000000000..1e9c97c4ef3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fw7g-x8q3-h9pr/GHSA-fw7g-x8q3-h9pr.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fw7g-x8q3-h9pr", + "modified": "2024-11-15T18:30:49Z", + "published": "2024-11-15T18:30:49Z", + "aliases": [ + "CVE-2022-20845" + ], + "details": "A vulnerability in the TL1 function of Cisco Network Convergence System (NCS) 4000 Series could allow an authenticated, local attacker to cause a memory leak in the TL1 process.\nThis vulnerability is due to TL1 not freeing memory under some conditions. An attacker could exploit this vulnerability by connecting to the device and issuing TL1 commands after being authenticated. A successful exploit could allow the attacker to cause the TL1 process to consume large amounts of memory. When the memory reaches a threshold, the Resource Monitor (Resmon) process will begin to restart or shutdown the top five consumers of memory, resulting in a denial of service (DoS).Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.This advisory is part of the September 2022 release of the Cisco IOS XR Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see .", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-20845" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-789" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-g3v8-p89r-mf62/GHSA-g3v8-p89r-mf62.json b/advisories/unreviewed/2024/11/GHSA-g3v8-p89r-mf62/GHSA-g3v8-p89r-mf62.json new file mode 100644 index 00000000000..5c9d1286744 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g3v8-p89r-mf62/GHSA-g3v8-p89r-mf62.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3v8-p89r-mf62", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2021-34750" + ], + "details": "A vulnerability in the administrative web-based GUI configuration manager of Cisco Firepower Management Center Software could allow an authenticated, remote attacker to access sensitive configuration information. The attacker would require low privilege credentials on an affected device.\nThis vulnerability is due to lack of proper encryption of sensitive information stored within the GUI configuration manager. An attacker could exploit this vulnerability by logging into the FMC GUI and navigating to certain sensitive configurations. A successful exploit could allow the attacker to view sensitive configuration parameters in clear text.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.[[Publication_URL{Layout()}]]This advisory is part of the October 2021 release of the Cisco ASA, FTD, and FMC Security Advisory Bundled publication. For a complete list of the advisories and links to them, see .", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-34750" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-infodisc-Ft2WVmNU" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-317" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-g4f9-hf22-85j8/GHSA-g4f9-hf22-85j8.json b/advisories/unreviewed/2024/11/GHSA-g4f9-hf22-85j8/GHSA-g4f9-hf22-85j8.json new file mode 100644 index 00000000000..988939e9527 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g4f9-hf22-85j8/GHSA-g4f9-hf22-85j8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4f9-hf22-85j8", + "modified": "2024-11-15T18:30:50Z", + "published": "2024-11-15T18:30:50Z", + "aliases": [ + "CVE-2024-50648" + ], + "details": "yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50648" + }, + { + "type": "WEB", + "url": "https://github.com/Yllxx03/CVE/blob/main/yshop_fileu_pload.md" + }, + { + "type": "WEB", + "url": "https://github.com/Yllxx03/CVE/tree/main/CVE-2024-50648" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-g8rg-m62r-h7gq/GHSA-g8rg-m62r-h7gq.json b/advisories/unreviewed/2024/11/GHSA-g8rg-m62r-h7gq/GHSA-g8rg-m62r-h7gq.json new file mode 100644 index 00000000000..e8617c27213 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g8rg-m62r-h7gq/GHSA-g8rg-m62r-h7gq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8rg-m62r-h7gq", + "modified": "2024-11-15T18:30:52Z", + "published": "2024-11-15T18:30:52Z", + "aliases": [ + "CVE-2024-46467" + ], + "details": "By default, dedicated folders of ZONEPOINT for Windows up to 2024.1 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ZONEPOINT has to be modified to prevent this vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46467" + }, + { + "type": "WEB", + "url": "https://www.primx.eu/en/bulletins/security-bulletin-24932299" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gg8c-67xr-mxhv/GHSA-gg8c-67xr-mxhv.json b/advisories/unreviewed/2024/11/GHSA-gg8c-67xr-mxhv/GHSA-gg8c-67xr-mxhv.json new file mode 100644 index 00000000000..0cb96cb04aa --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gg8c-67xr-mxhv/GHSA-gg8c-67xr-mxhv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gg8c-67xr-mxhv", + "modified": "2024-11-15T18:30:49Z", + "published": "2024-11-15T18:30:49Z", + "aliases": [ + "CVE-2022-20657" + ], + "details": "A vulnerability in the web-based management interface of Cisco PI and Cisco EPNM could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface of an affected device.\nThis vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-20657" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-pi-epnm-path-trav-zws324yn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-h8qc-rfpw-g45j/GHSA-h8qc-rfpw-g45j.json b/advisories/unreviewed/2024/11/GHSA-h8qc-rfpw-g45j/GHSA-h8qc-rfpw-g45j.json new file mode 100644 index 00000000000..75f5eb053cb --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-h8qc-rfpw-g45j/GHSA-h8qc-rfpw-g45j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8qc-rfpw-g45j", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:50Z", + "aliases": [ + "CVE-2024-50724" + ], + "details": "KASO v9.0 was discovered to contain a SQL injection vulnerability via the person_id parameter at /cardcase/editcard.jsp.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50724" + }, + { + "type": "WEB", + "url": "https://github.com/youyuzhongli/KASO-SQL/blob/main/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-h9rr-c3mp-g793/GHSA-h9rr-c3mp-g793.json b/advisories/unreviewed/2024/11/GHSA-h9rr-c3mp-g793/GHSA-h9rr-c3mp-g793.json new file mode 100644 index 00000000000..5f13017ddbe --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-h9rr-c3mp-g793/GHSA-h9rr-c3mp-g793.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9rr-c3mp-g793", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2022-20632" + ], + "details": "A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface of an affected device.\nThe vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-20632" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ece-multivulns-kbK2yVhR" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hm47-g5j3-8f32/GHSA-hm47-g5j3-8f32.json b/advisories/unreviewed/2024/11/GHSA-hm47-g5j3-8f32/GHSA-hm47-g5j3-8f32.json new file mode 100644 index 00000000000..4cd12496b06 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hm47-g5j3-8f32/GHSA-hm47-g5j3-8f32.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hm47-g5j3-8f32", + "modified": "2024-11-15T18:30:49Z", + "published": "2024-11-15T18:30:49Z", + "aliases": [ + "CVE-2022-20655" + ], + "details": "A vulnerability in the implementation of the CLI on a device that is running ConfD could allow an authenticated, local attacker to perform a command injection attack.\n The vulnerability is due to insufficient validation of a process argument on an affected device. An attacker could exploit this vulnerability by injecting commands during the execution of this process. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privilege level of ConfD, which is commonly root.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-20655" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cli-cmdinj-4MttWZPB" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-confdcli-cmdinj-wybQDSSh" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hmc5-79qw-62gj/GHSA-hmc5-79qw-62gj.json b/advisories/unreviewed/2024/11/GHSA-hmc5-79qw-62gj/GHSA-hmc5-79qw-62gj.json new file mode 100644 index 00000000000..bcd612cef97 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hmc5-79qw-62gj/GHSA-hmc5-79qw-62gj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmc5-79qw-62gj", + "modified": "2024-11-15T18:30:48Z", + "published": "2024-11-15T18:30:48Z", + "aliases": [ + "CVE-2022-20626" + ], + "details": "A vulnerability in the web-based management interface of Cisco Prime Access Registrar Appliance could allow an authenticated, remote attacker to conduct a cross-site scripting attack against a user of the interface. The attacker would require valid credentials for the device.\nThis vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-20626" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-prime-reg-xss-zLOz8PfB" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hwx8-x488-7jww/GHSA-hwx8-x488-7jww.json b/advisories/unreviewed/2024/11/GHSA-hwx8-x488-7jww/GHSA-hwx8-x488-7jww.json index ba854df4da2..c39814ca41e 100644 --- a/advisories/unreviewed/2024/11/GHSA-hwx8-x488-7jww/GHSA-hwx8-x488-7jww.json +++ b/advisories/unreviewed/2024/11/GHSA-hwx8-x488-7jww/GHSA-hwx8-x488-7jww.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hwx8-x488-7jww", - "modified": "2024-11-09T15:32:34Z", + "modified": "2024-11-15T18:30:48Z", "published": "2024-11-09T15:32:34Z", "aliases": [ "CVE-2024-51585" diff --git a/advisories/unreviewed/2024/11/GHSA-j74h-4p4v-6fp3/GHSA-j74h-4p4v-6fp3.json b/advisories/unreviewed/2024/11/GHSA-j74h-4p4v-6fp3/GHSA-j74h-4p4v-6fp3.json new file mode 100644 index 00000000000..4c55567cf4a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-j74h-4p4v-6fp3/GHSA-j74h-4p4v-6fp3.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j74h-4p4v-6fp3", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2021-1470" + ], + "details": "A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.\nThis vulnerability is due to improper input validation of SQL queries to an affected system. An attacker could exploit this vulnerability by authenticating to the application and sending malicious SQL queries to an affected system. A successful exploit could allow the attacker to modify values on or return values from the vManage database or the underlying operating system.Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-1470" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdw-sqlinj-HDJUeEAX" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vman-auth-bypass-Z3Zze5XC" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanage-cql-inject-c7z9QqyB" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20", + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jcmq-qjhc-h546/GHSA-jcmq-qjhc-h546.json b/advisories/unreviewed/2024/11/GHSA-jcmq-qjhc-h546/GHSA-jcmq-qjhc-h546.json new file mode 100644 index 00000000000..867048e0d86 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jcmq-qjhc-h546/GHSA-jcmq-qjhc-h546.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jcmq-qjhc-h546", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2024-46466" + ], + "details": "By default, dedicated folders of ZONECENTRAL for Windows up to 2024.3 or up to Q.2021.2 (ANSSI qualification submission) can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ZONECENTRAL has to be modified to prevent this vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46466" + }, + { + "type": "WEB", + "url": "https://www.primx.eu/en/bulletins/security-bulletin-24931934" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jmff-vhcc-w887/GHSA-jmff-vhcc-w887.json b/advisories/unreviewed/2024/11/GHSA-jmff-vhcc-w887/GHSA-jmff-vhcc-w887.json new file mode 100644 index 00000000000..35c270545fc --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jmff-vhcc-w887/GHSA-jmff-vhcc-w887.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jmff-vhcc-w887", + "modified": "2024-11-15T18:30:52Z", + "published": "2024-11-15T18:30:52Z", + "aliases": [ + "CVE-2024-11250" + ], + "details": "A vulnerability was found in code-projects Inventory Management up to 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /model/editProduct.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11250" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/sh3rl0ckpggp/0day/blob/main/inventory-management_authenticated_sqli.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.284686" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.284686" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.443272" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jrhg-66xp-fmhv/GHSA-jrhg-66xp-fmhv.json b/advisories/unreviewed/2024/11/GHSA-jrhg-66xp-fmhv/GHSA-jrhg-66xp-fmhv.json new file mode 100644 index 00000000000..0045075ae24 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jrhg-66xp-fmhv/GHSA-jrhg-66xp-fmhv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrhg-66xp-fmhv", + "modified": "2024-11-15T18:30:50Z", + "published": "2024-11-15T18:30:50Z", + "aliases": [ + "CVE-2023-20094" + ], + "details": "A vulnerability in Cisco TelePresence CE and RoomOS could allow an unauthenticated, adjacent attacker to view sensitive information on an affected device.\n\nThis vulnerability exists because the affected software performs improper bounds checks. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to cause an out-of-bounds read that discloses sensitive information.\nNote: This vulnerability only affects Cisco Webex Desk Hub.\nThere are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20094" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-file-write-rHKwegKf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jvfw-53c8-p9qg/GHSA-jvfw-53c8-p9qg.json b/advisories/unreviewed/2024/11/GHSA-jvfw-53c8-p9qg/GHSA-jvfw-53c8-p9qg.json new file mode 100644 index 00000000000..3379d979524 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jvfw-53c8-p9qg/GHSA-jvfw-53c8-p9qg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvfw-53c8-p9qg", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2022-20633" + ], + "details": "A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to perform a username enumeration attack against an affected device.\n\nThis vulnerability is due to differences in authentication responses that are sent back from the application as part of an authentication attempt. An attacker could exploit this vulnerability by sending authentication requests to an affected device. A successful exploit could allow the attacker to confirm existing user accounts, which could be used in further attacks.\nCisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-20633" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ece-multivulns-kbK2yVhR" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-204" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mpp6-vvqp-c35f/GHSA-mpp6-vvqp-c35f.json b/advisories/unreviewed/2024/11/GHSA-mpp6-vvqp-c35f/GHSA-mpp6-vvqp-c35f.json new file mode 100644 index 00000000000..66a4b5c6d10 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mpp6-vvqp-c35f/GHSA-mpp6-vvqp-c35f.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mpp6-vvqp-c35f", + "modified": "2024-11-15T18:30:50Z", + "published": "2024-11-15T18:30:50Z", + "aliases": [ + "CVE-2022-20948" + ], + "details": "A vulnerability in the web management interface of Cisco BroadWorks Hosted Thin Receptionist could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.\nThis vulnerability is due to insufficient user input validation. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-20948" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-CTT-DAV-HSvEHHEt" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bw-thinrcpt-xss-gSj4CecU" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pg6h-m56f-q74p/GHSA-pg6h-m56f-q74p.json b/advisories/unreviewed/2024/11/GHSA-pg6h-m56f-q74p/GHSA-pg6h-m56f-q74p.json new file mode 100644 index 00000000000..8e0c678275d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pg6h-m56f-q74p/GHSA-pg6h-m56f-q74p.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pg6h-m56f-q74p", + "modified": "2024-11-15T18:30:50Z", + "published": "2024-11-15T18:30:50Z", + "aliases": [ + "CVE-2022-20853" + ], + "details": "A vulnerability in the REST API of Cisco Expressway Series and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system.\n\nThis vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected system. An attacker could exploit this vulnerability by persuading a user of the REST API to follow a crafted link. A successful exploit could allow the attacker to cause the affected system to reload.\nCisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-20853" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bw-thinrcpt-xss-gSj4CecU" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cssm-priv-esc-SEjz69dv" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-csrf-sqpsSfY6" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wsa-prv-esc-8PdRU8t8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-phm4-wf3h-pc3r/GHSA-phm4-wf3h-pc3r.json b/advisories/unreviewed/2024/11/GHSA-phm4-wf3h-pc3r/GHSA-phm4-wf3h-pc3r.json new file mode 100644 index 00000000000..c965317d0d8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-phm4-wf3h-pc3r/GHSA-phm4-wf3h-pc3r.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phm4-wf3h-pc3r", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2024-44625" + ], + "details": "Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44625" + }, + { + "type": "WEB", + "url": "https://fysac.github.io/posts/2024/11/unpatched-remote-code-execution-in-gogs" + }, + { + "type": "WEB", + "url": "https://gogs.io" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pqqw-6g5g-6pqj/GHSA-pqqw-6g5g-6pqj.json b/advisories/unreviewed/2024/11/GHSA-pqqw-6g5g-6pqj/GHSA-pqqw-6g5g-6pqj.json new file mode 100644 index 00000000000..21064262654 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pqqw-6g5g-6pqj/GHSA-pqqw-6g5g-6pqj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqqw-6g5g-6pqj", + "modified": "2024-11-15T18:30:49Z", + "published": "2024-11-15T18:30:49Z", + "aliases": [ + "CVE-2022-20634" + ], + "details": "A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to redirect a user to an undesired web page.\nThis vulnerability is due to improper input validation of the URL parameters in an HTTP request that is sent to an affected system. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to cause the interface to redirect the user to a specific, malicious URL. This type of vulnerability is known as an open redirect and is used in phishing attacks that get users to unknowingly visit malicious sites.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-20634" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ece-multivulns-kbK2yVhR" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qf6r-242x-wpg6/GHSA-qf6r-242x-wpg6.json b/advisories/unreviewed/2024/11/GHSA-qf6r-242x-wpg6/GHSA-qf6r-242x-wpg6.json new file mode 100644 index 00000000000..10409692d1a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qf6r-242x-wpg6/GHSA-qf6r-242x-wpg6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qf6r-242x-wpg6", + "modified": "2024-11-15T18:30:50Z", + "published": "2024-11-15T18:30:50Z", + "aliases": [ + "CVE-2024-50650" + ], + "details": "python_book V1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50650" + }, + { + "type": "WEB", + "url": "https://github.com/Yllxx03/CVE/blob/main/python_book/BrokenAccessControl.md" + }, + { + "type": "WEB", + "url": "https://github.com/Yllxx03/CVE/tree/main/CVE-2024-50650" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qgrx-3ff6-vw5g/GHSA-qgrx-3ff6-vw5g.json b/advisories/unreviewed/2024/11/GHSA-qgrx-3ff6-vw5g/GHSA-qgrx-3ff6-vw5g.json new file mode 100644 index 00000000000..d7f197f2496 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qgrx-3ff6-vw5g/GHSA-qgrx-3ff6-vw5g.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgrx-3ff6-vw5g", + "modified": "2024-11-15T18:30:50Z", + "published": "2024-11-15T18:30:50Z", + "aliases": [ + "CVE-2024-50652" + ], + "details": "A file upload vulnerability in java_shop 1.0 allows attackers to upload arbitrary files by modifying the avatar function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50652" + }, + { + "type": "WEB", + "url": "https://github.com/Yllxx03/CVE/blob/main/java_shop/FileUpload.md" + }, + { + "type": "WEB", + "url": "https://github.com/Yllxx03/CVE/tree/main/CVE-2024-50652" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qr6c-gp8p-xcwh/GHSA-qr6c-gp8p-xcwh.json b/advisories/unreviewed/2024/11/GHSA-qr6c-gp8p-xcwh/GHSA-qr6c-gp8p-xcwh.json new file mode 100644 index 00000000000..cbbc1105882 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qr6c-gp8p-xcwh/GHSA-qr6c-gp8p-xcwh.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qr6c-gp8p-xcwh", + "modified": "2024-11-15T18:30:50Z", + "published": "2024-11-15T18:30:50Z", + "aliases": [ + "CVE-2024-50647" + ], + "details": "The python_food ordering system V1.0 has an unauthorized vulnerability that leads to the leakage of sensitive user information. Attackers can access it through https://ip:port/api/myapp/index/user/info?id=1 And modify the ID value to obtain sensitive user information beyond authorization.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50647" + }, + { + "type": "WEB", + "url": "https://github.com/Yllxx03/CVE/blob/main/python_food_Information_Disclosure.md" + }, + { + "type": "WEB", + "url": "https://github.com/Yllxx03/CVE/tree/main/CVE-2024-50647" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qw62-27cx-6cqg/GHSA-qw62-27cx-6cqg.json b/advisories/unreviewed/2024/11/GHSA-qw62-27cx-6cqg/GHSA-qw62-27cx-6cqg.json new file mode 100644 index 00000000000..56bd2713aff --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qw62-27cx-6cqg/GHSA-qw62-27cx-6cqg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qw62-27cx-6cqg", + "modified": "2024-11-15T18:30:50Z", + "published": "2024-11-15T18:30:50Z", + "aliases": [ + "CVE-2023-20039" + ], + "details": "A vulnerability in Cisco IND could allow an authenticated, local attacker to read application data.\n\nThis vulnerability is due to insufficient default file permissions that are applied to the application data directory. An attacker could exploit this vulnerability by accessing files in the application data directory. A successful exploit could allow the attacker to view sensitive information.\nCisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20039" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ind-CAeLFk6V" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-552" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-r2p4-pwjj-hqr4/GHSA-r2p4-pwjj-hqr4.json b/advisories/unreviewed/2024/11/GHSA-r2p4-pwjj-hqr4/GHSA-r2p4-pwjj-hqr4.json new file mode 100644 index 00000000000..005d34007db --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-r2p4-pwjj-hqr4/GHSA-r2p4-pwjj-hqr4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2p4-pwjj-hqr4", + "modified": "2024-11-15T18:30:50Z", + "published": "2024-11-15T18:30:50Z", + "aliases": [ + "CVE-2022-20849" + ], + "details": "A vulnerability in the Broadband Network Gateway PPP over Ethernet (PPPoE) feature of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the PPPoE process to continually crash.\nThis vulnerability exists because the PPPoE feature does not properly handle an error condition within a specific crafted packet sequence. An attacker could exploit this vulnerability by sending a sequence of specific PPPoE packets from controlled customer premises equipment (CPE). A successful exploit could allow the attacker to cause the PPPoE process to continually restart, resulting in a denial of service condition (DoS).Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.This advisory is part of the September 2022 release of the Cisco IOS XR Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see .", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-20849" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-bng-Gmg5Gxt" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-391" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rg5m-fc62-h68h/GHSA-rg5m-fc62-h68h.json b/advisories/unreviewed/2024/11/GHSA-rg5m-fc62-h68h/GHSA-rg5m-fc62-h68h.json new file mode 100644 index 00000000000..107b73d62ce --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rg5m-fc62-h68h/GHSA-rg5m-fc62-h68h.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rg5m-fc62-h68h", + "modified": "2024-11-15T18:30:49Z", + "published": "2024-11-15T18:30:49Z", + "aliases": [ + "CVE-2022-20814" + ], + "details": "A vulnerability in the certificate validation of Cisco Expressway-C and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data.  The vulnerability is due to a lack of validation of the SSL server certificate that an affected device receives when it establishes a connection to a Cisco Unified Communications Manager device. An attacker could exploit this vulnerability by using a man-in-the-middle technique to intercept the traffic between the devices, and then using a self-signed certificate to impersonate the endpoint. A successful exploit could allow the attacker to view the intercepted traffic in clear text or alter the contents of the traffic.\nNote: Cisco Expressway-E is not affected by this vulnerability.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-20814" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rg7m-23r6-4m52/GHSA-rg7m-23r6-4m52.json b/advisories/unreviewed/2024/11/GHSA-rg7m-23r6-4m52/GHSA-rg7m-23r6-4m52.json new file mode 100644 index 00000000000..bd58900d940 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rg7m-23r6-4m52/GHSA-rg7m-23r6-4m52.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rg7m-23r6-4m52", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2024-52555" + ], + "details": "In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer script", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52555" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-349" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rw66-6rgj-mwjh/GHSA-rw66-6rgj-mwjh.json b/advisories/unreviewed/2024/11/GHSA-rw66-6rgj-mwjh/GHSA-rw66-6rgj-mwjh.json new file mode 100644 index 00000000000..2eefc7d38e4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rw66-6rgj-mwjh/GHSA-rw66-6rgj-mwjh.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rw66-6rgj-mwjh", + "modified": "2024-11-15T18:30:50Z", + "published": "2024-11-15T18:30:50Z", + "aliases": [ + "CVE-2022-20871" + ], + "details": "A vulnerability in the web management interface of Cisco AsyncOS for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to perform a command injection and elevate privileges to root.\nThis vulnerability is due to insufficient validation of user-supplied input for the web interface. An attacker could exploit this vulnerability by authenticating to the system and sending a crafted HTTP packet to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system and elevate privileges to root. To successfully exploit this vulnerability, an attacker would need at least read-only credentials.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.Attention: Simplifying the Cisco portfolio includes the renaming of security products under one brand: Cisco Secure. For more information, see .", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-20871" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bw-thinrcpt-xss-gSj4CecU" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cssm-priv-esc-SEjz69dv" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wsa-prv-esc-8PdRU8t8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rx94-q7ch-5ww2/GHSA-rx94-q7ch-5ww2.json b/advisories/unreviewed/2024/11/GHSA-rx94-q7ch-5ww2/GHSA-rx94-q7ch-5ww2.json new file mode 100644 index 00000000000..461b3c95551 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rx94-q7ch-5ww2/GHSA-rx94-q7ch-5ww2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rx94-q7ch-5ww2", + "modified": "2024-11-15T18:30:49Z", + "published": "2024-11-15T18:30:49Z", + "aliases": [ + "CVE-2022-20656" + ], + "details": "A vulnerability in the web-based management interface of Cisco PI and Cisco EPNM could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device. To exploit this vulnerability, the attacker must have valid credentials on the system.\n\nThis vulnerability is due to insufficient input validation of the HTTPS URL by the web-based management interface. An attacker could exploit this vulnerability by sending a crafted request that contains directory traversal character sequences to an affected device. A successful exploit could allow the attacker to write arbitrary files to the host system.\nCisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-20656" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-pi-epnm-path-trav-zws324yn" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sna-xss-NXOxDhRQ" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-24" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-v8hj-h8mw-m6g6/GHSA-v8hj-h8mw-m6g6.json b/advisories/unreviewed/2024/11/GHSA-v8hj-h8mw-m6g6/GHSA-v8hj-h8mw-m6g6.json new file mode 100644 index 00000000000..67505b64667 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-v8hj-h8mw-m6g6/GHSA-v8hj-h8mw-m6g6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8hj-h8mw-m6g6", + "modified": "2024-11-15T18:30:50Z", + "published": "2024-11-15T18:30:50Z", + "aliases": [ + "CVE-2023-20092" + ], + "details": "Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device.\n\nThese vulnerabilities are due to improper access controls on files that are on the local file system. An attacker could exploit these vulnerabilities by placing a symbolic link in a specific location on the local file system of an affected device. A successful exploit could allow the attacker to overwrite arbitrary files on the affected device. To exploit these vulnerabilities, an attacker would need to have a remote support user account.\nNote: CVE-2023-20092 does not affect Cisco DX70, DX80, TelePresence MX Series, or TelePresence SX Series devices.\nCisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20092" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-file-write-rHKwegKf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-61" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-v999-55fc-w9ww/GHSA-v999-55fc-w9ww.json b/advisories/unreviewed/2024/11/GHSA-v999-55fc-w9ww/GHSA-v999-55fc-w9ww.json new file mode 100644 index 00000000000..33ab9509956 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-v999-55fc-w9ww/GHSA-v999-55fc-w9ww.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v999-55fc-w9ww", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2021-1466" + ], + "details": "A vulnerability in the vDaemon service of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to cause a buffer overflow on an affected system, resulting in a denial of service (DoS) condition.\nThe vulnerability is due to incomplete bounds checks for data that is provided to the vDaemon service of an affected system. An attacker could exploit this vulnerability by sending malicious data to the vDaemon listening service on the affected system. A successful exploit could allow the attacker to cause a buffer overflow condition on the affected system, which could allow the attacker to cause the vDaemon listening service to reload and result in a DoS condition.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-1466" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-vdaemon-bo-RuzzEA2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vc8r-hj67-4hv6/GHSA-vc8r-hj67-4hv6.json b/advisories/unreviewed/2024/11/GHSA-vc8r-hj67-4hv6/GHSA-vc8r-hj67-4hv6.json new file mode 100644 index 00000000000..43e265f4ca0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vc8r-hj67-4hv6/GHSA-vc8r-hj67-4hv6.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vc8r-hj67-4hv6", + "modified": "2024-11-15T18:30:49Z", + "published": "2024-11-15T18:30:49Z", + "aliases": [ + "CVE-2022-20648" + ], + "details": "A vulnerability in a debug function for Cisco RCM for Cisco StarOS Software could allow an unauthenticated, remote attacker to perform debug actions that could result in the disclosure of confidential information that should be restricted.\nThis vulnerability exists because of a debug service that incorrectly listens to and accepts incoming connections. An attacker could exploit this vulnerability by connecting to the debug port and executing debug commands. A successful exploit could allow the attacker to view sensitive debugging information.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-20648" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rcm-vuls-7cS3Nuq" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-tetr-cmd-injc-skrwGO" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-xss-FmbPu2pe" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vr4m-p38h-8h6w/GHSA-vr4m-p38h-8h6w.json b/advisories/unreviewed/2024/11/GHSA-vr4m-p38h-8h6w/GHSA-vr4m-p38h-8h6w.json new file mode 100644 index 00000000000..afa8ef1c20e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vr4m-p38h-8h6w/GHSA-vr4m-p38h-8h6w.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vr4m-p38h-8h6w", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2024-11247" + ], + "details": "A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /oews/classes/Master.php?f=save_product of the component Inventory Page. The manipulation of the argument brand leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11247" + }, + { + "type": "WEB", + "url": "https://github.com/Fl4g-Pshacker/cve/blob/main/xss.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.284683" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.284683" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.443194" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w4wv-5x8m-w2cf/GHSA-w4wv-5x8m-w2cf.json b/advisories/unreviewed/2024/11/GHSA-w4wv-5x8m-w2cf/GHSA-w4wv-5x8m-w2cf.json new file mode 100644 index 00000000000..7f9a876f862 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-w4wv-5x8m-w2cf/GHSA-w4wv-5x8m-w2cf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4wv-5x8m-w2cf", + "modified": "2024-11-15T18:30:49Z", + "published": "2024-11-15T18:30:49Z", + "aliases": [ + "CVE-2022-20793" + ], + "details": "A vulnerability in pairing process of Cisco TelePresence CE Software and RoomOS Software for Cisco Touch 10 Devices could allow an unauthenticated, remote attacker to impersonate a legitimate device and pair with an affected device.\nThis vulnerability is due to insufficient identity verification. An attacker could exploit this vulnerability by impersonating a legitimate device and responding to the pairing broadcast from an affected device. A successful exploit could allow the attacker to access the affected device while impersonating a legitimate device.There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-20793" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-CTT-IVV-4A66Dsfj" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-325" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wh72-9gx8-gwhv/GHSA-wh72-9gx8-gwhv.json b/advisories/unreviewed/2024/11/GHSA-wh72-9gx8-gwhv/GHSA-wh72-9gx8-gwhv.json new file mode 100644 index 00000000000..07060295c1d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wh72-9gx8-gwhv/GHSA-wh72-9gx8-gwhv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wh72-9gx8-gwhv", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2021-1494" + ], + "details": "Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP.\n The vulnerability is due to incorrect handling of specific HTTP header parameters. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass a configured file policy for HTTP packets and deliver a malicious payload.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-1494" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http-fp-bp-KfDdcQhc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-whfc-q27m-6qfm/GHSA-whfc-q27m-6qfm.json b/advisories/unreviewed/2024/11/GHSA-whfc-q27m-6qfm/GHSA-whfc-q27m-6qfm.json new file mode 100644 index 00000000000..09833bdfd59 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-whfc-q27m-6qfm/GHSA-whfc-q27m-6qfm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whfc-q27m-6qfm", + "modified": "2024-11-15T18:30:49Z", + "published": "2024-11-15T18:30:48Z", + "aliases": [ + "CVE-2022-20631" + ], + "details": "A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface of an affected device.\nThe vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by inserting malicious script code in a chat window. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-20631" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ece-multivulns-kbK2yVhR" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wp86-vvx6-h6hq/GHSA-wp86-vvx6-h6hq.json b/advisories/unreviewed/2024/11/GHSA-wp86-vvx6-h6hq/GHSA-wp86-vvx6-h6hq.json new file mode 100644 index 00000000000..123cad8d69a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wp86-vvx6-h6hq/GHSA-wp86-vvx6-h6hq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wp86-vvx6-h6hq", + "modified": "2024-11-15T18:30:49Z", + "published": "2024-11-15T18:30:49Z", + "aliases": [ + "CVE-2022-20663" + ], + "details": "A vulnerability in the web-based management interface of Cisco Secure Network Analytics, formerly Stealthwatch Enterprise, could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.\nThe vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.Attention: Simplifying the Cisco portfolio includes the renaming of security products under one brand: Cisco Secure. For more information, see .", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-20663" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sna-xss-NXOxDhRQ" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wrr5-xwcp-mrf2/GHSA-wrr5-xwcp-mrf2.json b/advisories/unreviewed/2024/11/GHSA-wrr5-xwcp-mrf2/GHSA-wrr5-xwcp-mrf2.json new file mode 100644 index 00000000000..0bbb0c2610c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wrr5-xwcp-mrf2/GHSA-wrr5-xwcp-mrf2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrr5-xwcp-mrf2", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2024-50654" + ], + "details": "lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quantity limit by capturing and sending the data packets for coupon collection in high concurrency.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50654" + }, + { + "type": "WEB", + "url": "https://github.com/Yllxx03/CVE/blob/main/lilishop/CouponLogicVulnerability.md" + }, + { + "type": "WEB", + "url": "https://github.com/Yllxx03/CVE/tree/main/CVE-2024-50654" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xh37-q5jv-v72j/GHSA-xh37-q5jv-v72j.json b/advisories/unreviewed/2024/11/GHSA-xh37-q5jv-v72j/GHSA-xh37-q5jv-v72j.json index f460ee81d71..74790a28305 100644 --- a/advisories/unreviewed/2024/11/GHSA-xh37-q5jv-v72j/GHSA-xh37-q5jv-v72j.json +++ b/advisories/unreviewed/2024/11/GHSA-xh37-q5jv-v72j/GHSA-xh37-q5jv-v72j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xh37-q5jv-v72j", - "modified": "2024-11-09T15:32:34Z", + "modified": "2024-11-15T18:30:48Z", "published": "2024-11-09T15:32:34Z", "aliases": [ "CVE-2024-51594" diff --git a/advisories/unreviewed/2024/11/GHSA-xpq3-q67q-mw45/GHSA-xpq3-q67q-mw45.json b/advisories/unreviewed/2024/11/GHSA-xpq3-q67q-mw45/GHSA-xpq3-q67q-mw45.json new file mode 100644 index 00000000000..bbc7d5a5f40 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xpq3-q67q-mw45/GHSA-xpq3-q67q-mw45.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpq3-q67q-mw45", + "modified": "2024-11-15T18:30:51Z", + "published": "2024-11-15T18:30:51Z", + "aliases": [ + "CVE-2024-50655" + ], + "details": "emlog pro <=2.3.18 is vulnerable to Cross Site Scripting (XSS), which allows attackers to write malicious JavaScript code in published articles.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50655" + }, + { + "type": "WEB", + "url": "https://github.com/Yllxx03/CVE/blob/main/emlog/XSS.md" + }, + { + "type": "WEB", + "url": "https://github.com/Yllxx03/CVE/tree/main/CVE-2024-50655" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xqfj-6ppw-2qw5/GHSA-xqfj-6ppw-2qw5.json b/advisories/unreviewed/2024/11/GHSA-xqfj-6ppw-2qw5/GHSA-xqfj-6ppw-2qw5.json new file mode 100644 index 00000000000..f2cdc04ea1a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xqfj-6ppw-2qw5/GHSA-xqfj-6ppw-2qw5.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqfj-6ppw-2qw5", + "modified": "2024-11-15T18:30:50Z", + "published": "2024-11-15T18:30:49Z", + "aliases": [ + "CVE-2022-20846" + ], + "details": "A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the Cisco Discovery Protocol process to reload on an affected device.\nThis vulnerability is due to a heap buffer overflow in certain Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to cause a heap overflow, which could cause the Cisco Discovery Protocol process to reload on the device. The bytes that can be written in the buffer overflow are restricted, which limits remote code execution.Note: Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).  Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.This advisory is part of the September 2022 release of the Cisco IOS XR Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see .", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-20846" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xwv4-chgp-x89p/GHSA-xwv4-chgp-x89p.json b/advisories/unreviewed/2024/11/GHSA-xwv4-chgp-x89p/GHSA-xwv4-chgp-x89p.json index 8c918d5a97f..b8351b5e22c 100644 --- a/advisories/unreviewed/2024/11/GHSA-xwv4-chgp-x89p/GHSA-xwv4-chgp-x89p.json +++ b/advisories/unreviewed/2024/11/GHSA-xwv4-chgp-x89p/GHSA-xwv4-chgp-x89p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xwv4-chgp-x89p", - "modified": "2024-11-11T09:30:41Z", + "modified": "2024-11-15T18:30:48Z", "published": "2024-11-11T09:30:41Z", "aliases": [ "CVE-2024-52355"