diff --git a/advisories/unreviewed/2022/05/GHSA-7hr6-j3qm-7p23/GHSA-7hr6-j3qm-7p23.json b/advisories/unreviewed/2022/05/GHSA-7hr6-j3qm-7p23/GHSA-7hr6-j3qm-7p23.json index 0b2114cc859..71e8f7c389e 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hr6-j3qm-7p23/GHSA-7hr6-j3qm-7p23.json +++ b/advisories/unreviewed/2022/05/GHSA-7hr6-j3qm-7p23/GHSA-7hr6-j3qm-7p23.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7hr6-j3qm-7p23", - "modified": "2022-05-24T19:17:34Z", + "modified": "2024-05-14T21:34:39Z", "published": "2022-05-24T19:17:34Z", "aliases": [ "CVE-2021-36387" ], "details": "In Yellowfin before 9.6.1 there is a Stored Cross-Site Scripting vulnerability in the video embed functionality exploitable through a specially crafted HTTP POST request to the page \"ActivityStreamAjax.i4\".", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -18,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-36387" }, + { + "type": "WEB", + "url": "https://cyberaz0r.info/2021/10/yellowfin-multiple-vulnerabilities" + }, { "type": "WEB", "url": "https://github.com/cyberaz0r/Yellowfin-Multiple-Vulnerabilities/blob/main/README.md" diff --git a/advisories/unreviewed/2022/05/GHSA-c3vp-6j3v-43r7/GHSA-c3vp-6j3v-43r7.json b/advisories/unreviewed/2022/05/GHSA-c3vp-6j3v-43r7/GHSA-c3vp-6j3v-43r7.json index a6a30c70d04..7f3f60fc97a 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3vp-6j3v-43r7/GHSA-c3vp-6j3v-43r7.json +++ b/advisories/unreviewed/2022/05/GHSA-c3vp-6j3v-43r7/GHSA-c3vp-6j3v-43r7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c3vp-6j3v-43r7", - "modified": "2022-05-24T17:16:51Z", + "modified": "2024-05-14T21:34:39Z", "published": "2022-05-24T17:16:51Z", "aliases": [ "CVE-2020-12103" ], "details": "In Tiny File Manager 2.4.1, there is a vulnerability in the ajax file backup copy functionality that allows authenticated users to place backup copies of files (with the .bak extension) into different directories.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N" + } ], "affected": [ @@ -26,6 +29,10 @@ "type": "WEB", "url": "https://github.com/prasathmani/tinyfilemanager/commit/a0c595a8e11e55a43eeaa68e1a3ce76365f29d06" }, + { + "type": "WEB", + "url": "https://cyberaz0r.info/2020/04/tiny-file-manager-multiple-vulnerabilities" + }, { "type": "WEB", "url": "https://www.quantumleap.it/news/advisory" @@ -37,7 +44,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-chj8-vpxq-7rvm/GHSA-chj8-vpxq-7rvm.json b/advisories/unreviewed/2022/05/GHSA-chj8-vpxq-7rvm/GHSA-chj8-vpxq-7rvm.json index 229d968bd76..8b114b5f739 100644 --- a/advisories/unreviewed/2022/05/GHSA-chj8-vpxq-7rvm/GHSA-chj8-vpxq-7rvm.json +++ b/advisories/unreviewed/2022/05/GHSA-chj8-vpxq-7rvm/GHSA-chj8-vpxq-7rvm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-chj8-vpxq-7rvm", - "modified": "2022-05-24T19:17:34Z", + "modified": "2024-05-14T21:34:39Z", "published": "2022-05-24T19:17:34Z", "aliases": [ "CVE-2021-36388" ], "details": "In Yellowfin before 9.6.1 it is possible to enumerate and download users profile pictures through an Insecure Direct Object Reference vulnerability exploitable by sending a specially crafted HTTP GET request to the page \"MIIAvatarImage.i4\".", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -18,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-36388" }, + { + "type": "WEB", + "url": "https://cyberaz0r.info/2021/10/yellowfin-multiple-vulnerabilities" + }, { "type": "WEB", "url": "https://github.com/cyberaz0r/Yellowfin-Multiple-Vulnerabilities/blob/main/README.md" diff --git a/advisories/unreviewed/2022/05/GHSA-cqcc-c563-84qx/GHSA-cqcc-c563-84qx.json b/advisories/unreviewed/2022/05/GHSA-cqcc-c563-84qx/GHSA-cqcc-c563-84qx.json index 99e3965178b..de5de105678 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqcc-c563-84qx/GHSA-cqcc-c563-84qx.json +++ b/advisories/unreviewed/2022/05/GHSA-cqcc-c563-84qx/GHSA-cqcc-c563-84qx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cqcc-c563-84qx", - "modified": "2022-05-24T19:17:34Z", + "modified": "2024-05-14T21:34:39Z", "published": "2022-05-24T19:17:34Z", "aliases": [ "CVE-2021-36389" ], "details": "In Yellowfin before 9.6.1 it is possible to enumerate and download uploaded images through an Insecure Direct Object Reference vulnerability exploitable by sending a specially crafted HTTP GET request to the page \"MIImage.i4\".", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -18,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-36389" }, + { + "type": "WEB", + "url": "https://cyberaz0r.info/2021/10/yellowfin-multiple-vulnerabilities" + }, { "type": "WEB", "url": "https://github.com/cyberaz0r/Yellowfin-Multiple-Vulnerabilities/blob/main/README.md" diff --git a/advisories/unreviewed/2022/05/GHSA-jx3m-xmr8-wjqx/GHSA-jx3m-xmr8-wjqx.json b/advisories/unreviewed/2022/05/GHSA-jx3m-xmr8-wjqx/GHSA-jx3m-xmr8-wjqx.json index c6aaa130173..5619e604d2d 100644 --- a/advisories/unreviewed/2022/05/GHSA-jx3m-xmr8-wjqx/GHSA-jx3m-xmr8-wjqx.json +++ b/advisories/unreviewed/2022/05/GHSA-jx3m-xmr8-wjqx/GHSA-jx3m-xmr8-wjqx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jx3m-xmr8-wjqx", - "modified": "2022-05-24T17:16:45Z", + "modified": "2024-05-14T21:34:39Z", "published": "2022-05-24T17:16:45Z", "aliases": [ "CVE-2020-12102" ], "details": "In Tiny File Manager 2.4.1, there is a Path Traversal vulnerability in the ajax recursive directory listing functionality. This allows authenticated users to enumerate directories and files on the filesystem (outside of the application scope).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } ], "affected": [ @@ -26,6 +29,10 @@ "type": "WEB", "url": "https://github.com/prasathmani/tinyfilemanager/commit/a0c595a8e11e55a43eeaa68e1a3ce76365f29d06" }, + { + "type": "WEB", + "url": "https://cyberaz0r.info/2020/04/tiny-file-manager-multiple-vulnerabilities" + }, { "type": "WEB", "url": "https://www.quantumleap.it/news/advisory" @@ -37,7 +44,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-2q2f-h83x-cx3x/GHSA-2q2f-h83x-cx3x.json b/advisories/unreviewed/2024/05/GHSA-2q2f-h83x-cx3x/GHSA-2q2f-h83x-cx3x.json new file mode 100644 index 00000000000..242e1a6eb17 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-2q2f-h83x-cx3x/GHSA-2q2f-h83x-cx3x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2q2f-h83x-cx3x", + "modified": "2024-05-14T21:34:44Z", + "published": "2024-05-14T21:34:44Z", + "aliases": [ + "CVE-2024-31556" + ], + "details": "An issue in Reportico Web before v.8.1.0 allows a local attacker to execute arbitrary code and obtain sensitive information via the sessionid function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31556" + }, + { + "type": "WEB", + "url": "https://github.com/reportico-web/reportico/issues/53" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-14T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-3j7w-h2jh-289j/GHSA-3j7w-h2jh-289j.json b/advisories/unreviewed/2024/05/GHSA-3j7w-h2jh-289j/GHSA-3j7w-h2jh-289j.json new file mode 100644 index 00000000000..f2176ca60ee --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-3j7w-h2jh-289j/GHSA-3j7w-h2jh-289j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3j7w-h2jh-289j", + "modified": "2024-05-14T21:34:44Z", + "published": "2024-05-14T21:34:44Z", + "aliases": [ + "CVE-2024-3044" + ], + "details": "Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted.\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3044" + }, + { + "type": "WEB", + "url": "https://www.libreoffice.org/about-us/security/advisories/CVE-2024-3044" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-14T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-fxxm-g8j5-2w88/GHSA-fxxm-g8j5-2w88.json b/advisories/unreviewed/2024/05/GHSA-fxxm-g8j5-2w88/GHSA-fxxm-g8j5-2w88.json new file mode 100644 index 00000000000..f53e15d3339 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-fxxm-g8j5-2w88/GHSA-fxxm-g8j5-2w88.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fxxm-g8j5-2w88", + "modified": "2024-05-14T21:34:44Z", + "published": "2024-05-14T21:34:44Z", + "aliases": [ + "CVE-2024-3676" + ], + "details": "The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an unauthenticated remote attacker with a specially crafted HTTP request to create additional Encryption user accounts under the attacker's control.  These accounts are able to send spoofed email to any users within the domains configured by the Administrator.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3676" + }, + { + "type": "WEB", + "url": "https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2024-0002" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-14T19:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-hf54-fq2m-p9v6/GHSA-hf54-fq2m-p9v6.json b/advisories/unreviewed/2024/05/GHSA-hf54-fq2m-p9v6/GHSA-hf54-fq2m-p9v6.json new file mode 100644 index 00000000000..52a947be3e3 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-hf54-fq2m-p9v6/GHSA-hf54-fq2m-p9v6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf54-fq2m-p9v6", + "modified": "2024-05-14T21:34:44Z", + "published": "2024-05-14T21:34:44Z", + "aliases": [ + "CVE-2020-26312" + ], + "details": "Dotmesh is a git-like command-line interface for capturing, organizing and sharing application states. In versions 0.8.1 and prior, the unsafe handling of symbolic links in an unpacking routine may \nenable attackers to read and/or write to arbitrary locations outside the\n designated target folder. The routine `untarFile` attempts to guard against creating symbolic links that point outside the directory a tar archive is extracted to. However, a malicious tarball first linking `subdir/parent` to `..` (allowed, because `subdir/..` falls within the archive root) and then linking `subdir/parent/escapes` to `..` results in a symbolic link pointing to the tarball’s parent directory, contrary to the routine’s goals. This issue may lead to arbitrary file write (with same permissions as the program running the unpack operation) if the attacker can control the archive file. Additionally, if the attacker has read access to the unpacked files, they may be able to read arbitrary system files the parent process has permissions to read. As of time of publication, no patch for this issue is available.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-26312" + }, + { + "type": "WEB", + "url": "https://github.com/dotmesh-io/dotmesh/blob/master/pkg/archiver/tar.go#L255" + }, + { + "type": "ADVISORY", + "url": "https://securitylab.github.com/advisories/GHSL-2020-254-zipslip-dotmesh" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-14T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-hw37-xg77-53hx/GHSA-hw37-xg77-53hx.json b/advisories/unreviewed/2024/05/GHSA-hw37-xg77-53hx/GHSA-hw37-xg77-53hx.json new file mode 100644 index 00000000000..c96ed0754d5 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-hw37-xg77-53hx/GHSA-hw37-xg77-53hx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hw37-xg77-53hx", + "modified": "2024-05-14T21:34:44Z", + "published": "2024-05-14T21:34:44Z", + "aliases": [ + "CVE-2024-0862" + ], + "details": "The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains a Server-Side Request Forgery vulnerability that allows an authenticated user to relay HTTP requests from the Protection server to otherwise private network addresses.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0862" + }, + { + "type": "WEB", + "url": "https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2024-0001" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-14T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-jc5j-vx46-fpgv/GHSA-jc5j-vx46-fpgv.json b/advisories/unreviewed/2024/05/GHSA-jc5j-vx46-fpgv/GHSA-jc5j-vx46-fpgv.json new file mode 100644 index 00000000000..da26f6747a3 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-jc5j-vx46-fpgv/GHSA-jc5j-vx46-fpgv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jc5j-vx46-fpgv", + "modified": "2024-05-14T21:34:44Z", + "published": "2024-05-14T21:34:44Z", + "aliases": [ + "CVE-2024-2637" + ], + "details": "\nAn authenticated local attacker who successfully exploited this vulnerability could insert and run arbitrary code using legitimate B&R software's.\n\nAn Uncontrolled Search Path Element vulnerability in B&R Industrial Automation Scene Viewer, B&R Industrial  Automation Runtime, B&R Industrial Automation mapp Vision, B&R Industrial Automation mapp View, B&R Industrial Automation mapp Cockpit, B&R Industrial Automation mapp Safety, B&R Industrial Automation VC4 could allow an authenticated local attacker to execute malicious code by placing specially crafted files in the loading search path.\nThis issue affects Scene Viewer: before 4.4.0; Automation Runtime: before J4.93; mapp Vision: before 5.26.1; mapp View: before 5.24.2; mapp Cockpit: before 5.24.2; mapp Safety: before 5.24.2; VC4: before 4.73.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2637" + }, + { + "type": "WEB", + "url": "https://www.br-automation.com/fileadmin/SA24P005_Insecure_Loading_of_Code-c7d9e49c.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-14T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-q2xc-6c48-r5px/GHSA-q2xc-6c48-r5px.json b/advisories/unreviewed/2024/05/GHSA-q2xc-6c48-r5px/GHSA-q2xc-6c48-r5px.json new file mode 100644 index 00000000000..7e6236c02a5 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-q2xc-6c48-r5px/GHSA-q2xc-6c48-r5px.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2xc-6c48-r5px", + "modified": "2024-05-14T21:34:44Z", + "published": "2024-05-14T21:34:44Z", + "aliases": [ + "CVE-2022-28132" + ], + "details": "The T-Soft E-Commerce 4 web application is susceptible to SQL injection (SQLi) attacks when authenticated as an admin or privileged user. This vulnerability allows attackers to access and manipulate the database through crafted requests. By exploiting this flaw, attackers can bypass authentication mechanisms, view sensitive information stored in the database, and potentially exfiltrate data.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28132" + }, + { + "type": "WEB", + "url": "https://www.exploit-db.com/exploits/50939" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-14T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-q8gh-g2x4-x4cm/GHSA-q8gh-g2x4-x4cm.json b/advisories/unreviewed/2024/05/GHSA-q8gh-g2x4-x4cm/GHSA-q8gh-g2x4-x4cm.json new file mode 100644 index 00000000000..57b1604a9b5 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-q8gh-g2x4-x4cm/GHSA-q8gh-g2x4-x4cm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8gh-g2x4-x4cm", + "modified": "2024-05-14T21:34:45Z", + "published": "2024-05-14T21:34:44Z", + "aliases": [ + "CVE-2024-4562" + ], + "details": "\nIn WhatsUp Gold versions released before 2023.1.2 , \n\nan SSRF vulnerability exists in Whatsup Gold's \n\nIssue exists in the HTTP Monitoring functionality.  \n\nDue to the lack of proper authorization, any authenticated user can access the HTTP monitoring functionality, what leads to the Server Side Request Forgery.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4562" + }, + { + "type": "WEB", + "url": "https://community.progress.com/s/article/Announcing-WhatsUp-Gold-v2023-1-2" + }, + { + "type": "WEB", + "url": "https://www.progress.com/network-monitoring" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-14T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-vpj2-mh86-xpmv/GHSA-vpj2-mh86-xpmv.json b/advisories/unreviewed/2024/05/GHSA-vpj2-mh86-xpmv/GHSA-vpj2-mh86-xpmv.json new file mode 100644 index 00000000000..2f95b4e6d12 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-vpj2-mh86-xpmv/GHSA-vpj2-mh86-xpmv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vpj2-mh86-xpmv", + "modified": "2024-05-14T21:34:44Z", + "published": "2024-05-14T21:34:44Z", + "aliases": [ + "CVE-2024-4561" + ], + "details": "\nIn WhatsUp Gold versions released before 2023.1.2 , \n\na blind SSRF vulnerability exists in Whatsup Gold's FaviconController that allows an attacker to send arbitrary HTTP requests on behalf of the vulnerable server.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4561" + }, + { + "type": "WEB", + "url": "https://community.progress.com/s/article/Announcing-WhatsUp-Gold-v2023-1-2" + }, + { + "type": "WEB", + "url": "https://www.progress.com/network-monitoring" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-14T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-x53h-2cjp-mwcx/GHSA-x53h-2cjp-mwcx.json b/advisories/unreviewed/2024/05/GHSA-x53h-2cjp-mwcx/GHSA-x53h-2cjp-mwcx.json new file mode 100644 index 00000000000..0dd1fa519ae --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-x53h-2cjp-mwcx/GHSA-x53h-2cjp-mwcx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x53h-2cjp-mwcx", + "modified": "2024-05-14T21:34:44Z", + "published": "2024-05-14T21:34:44Z", + "aliases": [ + "CVE-2021-22280" + ], + "details": "\nImproper DLL loading algorithms in B&R Automation Studio may allow an authenticated local attacker to\nexecute code with elevated privileges.\n\nThis issue affects Automation Studio versions before 4.12.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-22280" + }, + { + "type": "WEB", + "url": "https://www.br-automation.com/fileadmin/2021-10_DLL_Hijacking_Vulnerability_in_Automation_Studio-7dd34511.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-14T20:15:11Z" + } +} \ No newline at end of file