From 0f4dc4c0cfb91f28c8dbf4f1ef9f6b38405b6e7d Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 19 Aug 2024 15:33:27 +0000 Subject: [PATCH] Publish Advisories GHSA-3m9m-c43p-g4h3 GHSA-m676-gr96-hhhh GHSA-pr97-pp48-gmqg GHSA-8p7c-2mvg-g9v9 GHSA-j6gh-w55p-c22w GHSA-mm3h-cmqv-736j GHSA-2m3v-5ccr-mrmf GHSA-2xh5-xw95-xh7p GHSA-6x2v-5hv4-7j4r GHSA-g5p7-39ff-j5mv GHSA-mw3w-8r3q-gm92 GHSA-qhm8-r99p-v4h8 GHSA-wrfv-q4v6-cw3x --- .../GHSA-3m9m-c43p-g4h3.json | 6 +- .../GHSA-m676-gr96-hhhh.json | 11 ++-- .../GHSA-pr97-pp48-gmqg.json | 3 +- .../GHSA-8p7c-2mvg-g9v9.json | 2 +- .../GHSA-j6gh-w55p-c22w.json | 11 ++-- .../GHSA-mm3h-cmqv-736j.json | 2 +- .../GHSA-2m3v-5ccr-mrmf.json | 2 +- .../GHSA-2xh5-xw95-xh7p.json | 2 +- .../GHSA-6x2v-5hv4-7j4r.json | 62 +++++++++++++++++++ .../GHSA-g5p7-39ff-j5mv.json | 11 ++-- .../GHSA-mw3w-8r3q-gm92.json | 11 ++-- .../GHSA-qhm8-r99p-v4h8.json | 2 +- .../GHSA-wrfv-q4v6-cw3x.json | 5 +- 13 files changed, 105 insertions(+), 25 deletions(-) create mode 100644 advisories/unreviewed/2024/08/GHSA-6x2v-5hv4-7j4r/GHSA-6x2v-5hv4-7j4r.json diff --git a/advisories/unreviewed/2024/06/GHSA-3m9m-c43p-g4h3/GHSA-3m9m-c43p-g4h3.json b/advisories/unreviewed/2024/06/GHSA-3m9m-c43p-g4h3/GHSA-3m9m-c43p-g4h3.json index 61a73b058cb..cf13647bdcb 100644 --- a/advisories/unreviewed/2024/06/GHSA-3m9m-c43p-g4h3/GHSA-3m9m-c43p-g4h3.json +++ b/advisories/unreviewed/2024/06/GHSA-3m9m-c43p-g4h3/GHSA-3m9m-c43p-g4h3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3m9m-c43p-g4h3", - "modified": "2024-06-20T06:30:54Z", + "modified": "2024-08-19T15:31:33Z", "published": "2024-06-20T06:30:54Z", "aliases": [ "CVE-2024-6113" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-m676-gr96-hhhh/GHSA-m676-gr96-hhhh.json b/advisories/unreviewed/2024/06/GHSA-m676-gr96-hhhh/GHSA-m676-gr96-hhhh.json index 1781837f771..4b3652019fb 100644 --- a/advisories/unreviewed/2024/06/GHSA-m676-gr96-hhhh/GHSA-m676-gr96-hhhh.json +++ b/advisories/unreviewed/2024/06/GHSA-m676-gr96-hhhh/GHSA-m676-gr96-hhhh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m676-gr96-hhhh", - "modified": "2024-06-03T21:30:43Z", + "modified": "2024-08-19T15:31:33Z", "published": "2024-06-03T21:30:43Z", "aliases": [ "CVE-2021-3899" ], "details": "There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary code as root.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-367" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-03T19:15:08Z" diff --git a/advisories/unreviewed/2024/06/GHSA-pr97-pp48-gmqg/GHSA-pr97-pp48-gmqg.json b/advisories/unreviewed/2024/06/GHSA-pr97-pp48-gmqg/GHSA-pr97-pp48-gmqg.json index fcaead7f4b1..cae50889d5d 100644 --- a/advisories/unreviewed/2024/06/GHSA-pr97-pp48-gmqg/GHSA-pr97-pp48-gmqg.json +++ b/advisories/unreviewed/2024/06/GHSA-pr97-pp48-gmqg/GHSA-pr97-pp48-gmqg.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-416" + "CWE-416", + "CWE-667" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-8p7c-2mvg-g9v9/GHSA-8p7c-2mvg-g9v9.json b/advisories/unreviewed/2024/07/GHSA-8p7c-2mvg-g9v9/GHSA-8p7c-2mvg-g9v9.json index 090e5a9177e..517ee25f4fa 100644 --- a/advisories/unreviewed/2024/07/GHSA-8p7c-2mvg-g9v9/GHSA-8p7c-2mvg-g9v9.json +++ b/advisories/unreviewed/2024/07/GHSA-8p7c-2mvg-g9v9/GHSA-8p7c-2mvg-g9v9.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-j6gh-w55p-c22w/GHSA-j6gh-w55p-c22w.json b/advisories/unreviewed/2024/07/GHSA-j6gh-w55p-c22w/GHSA-j6gh-w55p-c22w.json index 52905f68d89..ee4b02023ea 100644 --- a/advisories/unreviewed/2024/07/GHSA-j6gh-w55p-c22w/GHSA-j6gh-w55p-c22w.json +++ b/advisories/unreviewed/2024/07/GHSA-j6gh-w55p-c22w/GHSA-j6gh-w55p-c22w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j6gh-w55p-c22w", - "modified": "2024-07-09T21:30:39Z", + "modified": "2024-08-19T15:31:34Z", "published": "2024-07-09T21:30:39Z", "aliases": [ "CVE-2024-37865" ], "details": "An issue in S3Browser v.11.4.5 and v.10.9.9 and fixed in v.11.5.7 allows a remote attacker to obtain sensitive information via the S3 compatible storage component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-295" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-09T21:15:14Z" diff --git a/advisories/unreviewed/2024/07/GHSA-mm3h-cmqv-736j/GHSA-mm3h-cmqv-736j.json b/advisories/unreviewed/2024/07/GHSA-mm3h-cmqv-736j/GHSA-mm3h-cmqv-736j.json index 6ab340d6f9b..b3e7c18a82f 100644 --- a/advisories/unreviewed/2024/07/GHSA-mm3h-cmqv-736j/GHSA-mm3h-cmqv-736j.json +++ b/advisories/unreviewed/2024/07/GHSA-mm3h-cmqv-736j/GHSA-mm3h-cmqv-736j.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-2m3v-5ccr-mrmf/GHSA-2m3v-5ccr-mrmf.json b/advisories/unreviewed/2024/08/GHSA-2m3v-5ccr-mrmf/GHSA-2m3v-5ccr-mrmf.json index dc1684623e7..78884e80861 100644 --- a/advisories/unreviewed/2024/08/GHSA-2m3v-5ccr-mrmf/GHSA-2m3v-5ccr-mrmf.json +++ b/advisories/unreviewed/2024/08/GHSA-2m3v-5ccr-mrmf/GHSA-2m3v-5ccr-mrmf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2m3v-5ccr-mrmf", - "modified": "2024-08-17T15:30:24Z", + "modified": "2024-08-19T15:31:39Z", "published": "2024-08-17T15:30:24Z", "aliases": [ "CVE-2024-7897" diff --git a/advisories/unreviewed/2024/08/GHSA-2xh5-xw95-xh7p/GHSA-2xh5-xw95-xh7p.json b/advisories/unreviewed/2024/08/GHSA-2xh5-xw95-xh7p/GHSA-2xh5-xw95-xh7p.json index 5c97bd938d5..d4c1ca50413 100644 --- a/advisories/unreviewed/2024/08/GHSA-2xh5-xw95-xh7p/GHSA-2xh5-xw95-xh7p.json +++ b/advisories/unreviewed/2024/08/GHSA-2xh5-xw95-xh7p/GHSA-2xh5-xw95-xh7p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2xh5-xw95-xh7p", - "modified": "2024-08-17T15:30:24Z", + "modified": "2024-08-19T15:31:39Z", "published": "2024-08-17T15:30:24Z", "aliases": [ "CVE-2024-7896" diff --git a/advisories/unreviewed/2024/08/GHSA-6x2v-5hv4-7j4r/GHSA-6x2v-5hv4-7j4r.json b/advisories/unreviewed/2024/08/GHSA-6x2v-5hv4-7j4r/GHSA-6x2v-5hv4-7j4r.json new file mode 100644 index 00000000000..a6da24835c2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6x2v-5hv4-7j4r/GHSA-6x2v-5hv4-7j4r.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6x2v-5hv4-7j4r", + "modified": "2024-08-19T15:31:40Z", + "published": "2024-08-19T15:31:40Z", + "aliases": [ + "CVE-2024-7922" + ], + "details": "A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814 and classified as critical. Affected by this issue is the function cgi_audio_search/cgi_create_playlist/cgi_get_album_all_tracks/cgi_get_alltracks_editlist/cgi_get_artist_all_album/cgi_get_genre_all_tracks/cgi_get_tracks_list/cgi_set_airplay_content/cgi_write_playlist of the file /cgi-bin/myMusic.cgi. The manipulation leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7922" + }, + { + "type": "WEB", + "url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_create_playlist.md" + }, + { + "type": "WEB", + "url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_get_tracks_list.md" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.275108" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.275108" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.391669" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-19T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g5p7-39ff-j5mv/GHSA-g5p7-39ff-j5mv.json b/advisories/unreviewed/2024/08/GHSA-g5p7-39ff-j5mv/GHSA-g5p7-39ff-j5mv.json index b20b0e97ffc..bba54ca78b2 100644 --- a/advisories/unreviewed/2024/08/GHSA-g5p7-39ff-j5mv/GHSA-g5p7-39ff-j5mv.json +++ b/advisories/unreviewed/2024/08/GHSA-g5p7-39ff-j5mv/GHSA-g5p7-39ff-j5mv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g5p7-39ff-j5mv", - "modified": "2024-08-16T21:32:36Z", + "modified": "2024-08-19T15:31:35Z", "published": "2024-08-16T21:32:36Z", "aliases": [ "CVE-2024-43009" ], "details": "A reflected cross-site scripting (XSS) vulnerability exists in user/login.php at line 24 in ZZCMS 2023 and earlier. The application directly inserts the value of the HTTP_REFERER header into the HTML response without proper sanitization. An attacker can exploit this vulnerability by tricking a user into visiting a specially crafted URL, which includes a malicious Referer header. This can lead to the execution of arbitrary JavaScript code in the context of the victim's browser, potentially resulting in session hijacking, defacement, or other malicious activities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-16T20:15:13Z" diff --git a/advisories/unreviewed/2024/08/GHSA-mw3w-8r3q-gm92/GHSA-mw3w-8r3q-gm92.json b/advisories/unreviewed/2024/08/GHSA-mw3w-8r3q-gm92/GHSA-mw3w-8r3q-gm92.json index 19a937fcfe6..83f41bffd82 100644 --- a/advisories/unreviewed/2024/08/GHSA-mw3w-8r3q-gm92/GHSA-mw3w-8r3q-gm92.json +++ b/advisories/unreviewed/2024/08/GHSA-mw3w-8r3q-gm92/GHSA-mw3w-8r3q-gm92.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mw3w-8r3q-gm92", - "modified": "2024-08-16T21:32:36Z", + "modified": "2024-08-19T15:31:35Z", "published": "2024-08-16T21:32:36Z", "aliases": [ "CVE-2024-43011" ], "details": "An arbitrary file deletion vulnerability exists in the admin/del.php file at line 62 in ZZCMS 2023 and earlier. Due to insufficient validation and sanitization of user input for file paths, an attacker can exploit this vulnerability by using directory traversal techniques to delete arbitrary files on the server. This can lead to the deletion of critical files, potentially disrupting the normal operation of the system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-16T20:15:13Z" diff --git a/advisories/unreviewed/2024/08/GHSA-qhm8-r99p-v4h8/GHSA-qhm8-r99p-v4h8.json b/advisories/unreviewed/2024/08/GHSA-qhm8-r99p-v4h8/GHSA-qhm8-r99p-v4h8.json index 8b4e5e3ecc0..6943c1f4e00 100644 --- a/advisories/unreviewed/2024/08/GHSA-qhm8-r99p-v4h8/GHSA-qhm8-r99p-v4h8.json +++ b/advisories/unreviewed/2024/08/GHSA-qhm8-r99p-v4h8/GHSA-qhm8-r99p-v4h8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qhm8-r99p-v4h8", - "modified": "2024-08-17T12:30:32Z", + "modified": "2024-08-19T15:31:39Z", "published": "2024-08-17T12:30:32Z", "aliases": [ "CVE-2024-43826" diff --git a/advisories/unreviewed/2024/08/GHSA-wrfv-q4v6-cw3x/GHSA-wrfv-q4v6-cw3x.json b/advisories/unreviewed/2024/08/GHSA-wrfv-q4v6-cw3x/GHSA-wrfv-q4v6-cw3x.json index 173649bc004..b89948ddba4 100644 --- a/advisories/unreviewed/2024/08/GHSA-wrfv-q4v6-cw3x/GHSA-wrfv-q4v6-cw3x.json +++ b/advisories/unreviewed/2024/08/GHSA-wrfv-q4v6-cw3x/GHSA-wrfv-q4v6-cw3x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wrfv-q4v6-cw3x", - "modified": "2024-08-12T21:31:34Z", + "modified": "2024-08-19T15:31:34Z", "published": "2024-08-07T09:31:08Z", "aliases": [ "CVE-2024-42062" @@ -37,7 +37,8 @@ "database_specific": { "cwe_ids": [ "CWE-200", - "CWE-276" + "CWE-276", + "CWE-863" ], "severity": "HIGH", "github_reviewed": false,