Publish Advisories

GHSA-3m9m-c43p-g4h3
GHSA-m676-gr96-hhhh
GHSA-pr97-pp48-gmqg
GHSA-8p7c-2mvg-g9v9
GHSA-j6gh-w55p-c22w
GHSA-mm3h-cmqv-736j
GHSA-2m3v-5ccr-mrmf
GHSA-2xh5-xw95-xh7p
GHSA-6x2v-5hv4-7j4r
GHSA-g5p7-39ff-j5mv
GHSA-mw3w-8r3q-gm92
GHSA-qhm8-r99p-v4h8
GHSA-wrfv-q4v6-cw3x
This commit is contained in:
advisory-database[bot]
2024-08-19 15:33:27 +00:00
parent e9db96350d
commit 0f4dc4c0cf
13 changed files with 105 additions and 25 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3m9m-c43p-g4h3",
"modified": "2024-06-20T06:30:54Z",
"modified": "2024-08-19T15:31:33Z",
"published": "2024-06-20T06:30:54Z",
"aliases": [
"CVE-2024-6113"
@@ -11,6 +11,10 @@
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m676-gr96-hhhh",
"modified": "2024-06-03T21:30:43Z",
"modified": "2024-08-19T15:31:33Z",
"published": "2024-06-03T21:30:43Z",
"aliases": [
"CVE-2021-3899"
],
"details": "There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary code as root.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-367"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-03T19:15:08Z"
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-416"
"CWE-416",
"CWE-667"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-434"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j6gh-w55p-c22w",
"modified": "2024-07-09T21:30:39Z",
"modified": "2024-08-19T15:31:34Z",
"published": "2024-07-09T21:30:39Z",
"aliases": [
"CVE-2024-37865"
],
"details": "An issue in S3Browser v.11.4.5 and v.10.9.9 and fixed in v.11.5.7 allows a remote attacker to obtain sensitive information via the S3 compatible storage component.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-295"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-09T21:15:14Z"
@@ -36,7 +36,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2m3v-5ccr-mrmf",
"modified": "2024-08-17T15:30:24Z",
"modified": "2024-08-19T15:31:39Z",
"published": "2024-08-17T15:30:24Z",
"aliases": [
"CVE-2024-7897"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2xh5-xw95-xh7p",
"modified": "2024-08-17T15:30:24Z",
"modified": "2024-08-19T15:31:39Z",
"published": "2024-08-17T15:30:24Z",
"aliases": [
"CVE-2024-7896"
@@ -0,0 +1,62 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6x2v-5hv4-7j4r",
"modified": "2024-08-19T15:31:40Z",
"published": "2024-08-19T15:31:40Z",
"aliases": [
"CVE-2024-7922"
],
"details": "A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814 and classified as critical. Affected by this issue is the function cgi_audio_search/cgi_create_playlist/cgi_get_album_all_tracks/cgi_get_alltracks_editlist/cgi_get_artist_all_album/cgi_get_genre_all_tracks/cgi_get_tracks_list/cgi_set_airplay_content/cgi_write_playlist of the file /cgi-bin/myMusic.cgi. The manipulation leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7922"
},
{
"type": "WEB",
"url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_create_playlist.md"
},
{
"type": "WEB",
"url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_get_tracks_list.md"
},
{
"type": "WEB",
"url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.275108"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.275108"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.391669"
}
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-19T15:15:09Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g5p7-39ff-j5mv",
"modified": "2024-08-16T21:32:36Z",
"modified": "2024-08-19T15:31:35Z",
"published": "2024-08-16T21:32:36Z",
"aliases": [
"CVE-2024-43009"
],
"details": "A reflected cross-site scripting (XSS) vulnerability exists in user/login.php at line 24 in ZZCMS 2023 and earlier. The application directly inserts the value of the HTTP_REFERER header into the HTML response without proper sanitization. An attacker can exploit this vulnerability by tricking a user into visiting a specially crafted URL, which includes a malicious Referer header. This can lead to the execution of arbitrary JavaScript code in the context of the victim's browser, potentially resulting in session hijacking, defacement, or other malicious activities.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-16T20:15:13Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mw3w-8r3q-gm92",
"modified": "2024-08-16T21:32:36Z",
"modified": "2024-08-19T15:31:35Z",
"published": "2024-08-16T21:32:36Z",
"aliases": [
"CVE-2024-43011"
],
"details": "An arbitrary file deletion vulnerability exists in the admin/del.php file at line 62 in ZZCMS 2023 and earlier. Due to insufficient validation and sanitization of user input for file paths, an attacker can exploit this vulnerability by using directory traversal techniques to delete arbitrary files on the server. This can lead to the deletion of critical files, potentially disrupting the normal operation of the system.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-16T20:15:13Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qhm8-r99p-v4h8",
"modified": "2024-08-17T12:30:32Z",
"modified": "2024-08-19T15:31:39Z",
"published": "2024-08-17T12:30:32Z",
"aliases": [
"CVE-2024-43826"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wrfv-q4v6-cw3x",
"modified": "2024-08-12T21:31:34Z",
"modified": "2024-08-19T15:31:34Z",
"published": "2024-08-07T09:31:08Z",
"aliases": [
"CVE-2024-42062"
@@ -37,7 +37,8 @@
"database_specific": {
"cwe_ids": [
"CWE-200",
"CWE-276"
"CWE-276",
"CWE-863"
],
"severity": "HIGH",
"github_reviewed": false,