From 0f952fa26bb8e87680a2cc8e8b85482bfa94bbc4 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 11 Mar 2024 15:33:07 +0000 Subject: [PATCH] Publish Advisories GHSA-qfgr-f5j7-2xxf GHSA-cx8g-4cf5-cjv3 GHSA-2cj9-wjmr-5w57 GHSA-4pc9-wmrm-8p87 GHSA-fqf7-66f9-wqff GHSA-m7gg-q7qj-3r2r GHSA-xh94-49wq-7h2h --- .../GHSA-qfgr-f5j7-2xxf.json | 13 +++++- .../GHSA-cx8g-4cf5-cjv3.json | 6 ++- .../GHSA-2cj9-wjmr-5w57.json | 42 +++++++++++++++++++ .../GHSA-4pc9-wmrm-8p87.json | 38 +++++++++++++++++ .../GHSA-fqf7-66f9-wqff.json | 38 +++++++++++++++++ .../GHSA-m7gg-q7qj-3r2r.json | 6 ++- .../GHSA-xh94-49wq-7h2h.json | 6 ++- 7 files changed, 144 insertions(+), 5 deletions(-) create mode 100644 advisories/unreviewed/2024/03/GHSA-2cj9-wjmr-5w57/GHSA-2cj9-wjmr-5w57.json create mode 100644 advisories/unreviewed/2024/03/GHSA-4pc9-wmrm-8p87/GHSA-4pc9-wmrm-8p87.json create mode 100644 advisories/unreviewed/2024/03/GHSA-fqf7-66f9-wqff/GHSA-fqf7-66f9-wqff.json diff --git a/advisories/unreviewed/2023/10/GHSA-qfgr-f5j7-2xxf/GHSA-qfgr-f5j7-2xxf.json b/advisories/unreviewed/2023/10/GHSA-qfgr-f5j7-2xxf/GHSA-qfgr-f5j7-2xxf.json index 86aaa25fdc9..fb8fd624daf 100644 --- a/advisories/unreviewed/2023/10/GHSA-qfgr-f5j7-2xxf/GHSA-qfgr-f5j7-2xxf.json +++ b/advisories/unreviewed/2023/10/GHSA-qfgr-f5j7-2xxf/GHSA-qfgr-f5j7-2xxf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qfgr-f5j7-2xxf", - "modified": "2023-10-04T21:30:22Z", + "modified": "2024-03-11T15:31:23Z", "published": "2023-10-04T21:30:22Z", "aliases": [ "CVE-2023-3576" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3576" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:6575" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-3576" @@ -28,13 +32,18 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2219340" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00011.html" } ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-04T19:15:10Z" diff --git a/advisories/unreviewed/2024/01/GHSA-cx8g-4cf5-cjv3/GHSA-cx8g-4cf5-cjv3.json b/advisories/unreviewed/2024/01/GHSA-cx8g-4cf5-cjv3/GHSA-cx8g-4cf5-cjv3.json index 867f664a6e4..6b56ccc6eb3 100644 --- a/advisories/unreviewed/2024/01/GHSA-cx8g-4cf5-cjv3/GHSA-cx8g-4cf5-cjv3.json +++ b/advisories/unreviewed/2024/01/GHSA-cx8g-4cf5-cjv3/GHSA-cx8g-4cf5-cjv3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cx8g-4cf5-cjv3", - "modified": "2024-01-25T21:32:14Z", + "modified": "2024-03-11T15:31:23Z", "published": "2024-01-25T21:32:14Z", "aliases": [ "CVE-2023-52356" @@ -36,6 +36,10 @@ { "type": "WEB", "url": "https://gitlab.com/libtiff/libtiff/-/merge_requests/546" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00011.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-2cj9-wjmr-5w57/GHSA-2cj9-wjmr-5w57.json b/advisories/unreviewed/2024/03/GHSA-2cj9-wjmr-5w57/GHSA-2cj9-wjmr-5w57.json new file mode 100644 index 00000000000..1f76395992d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-2cj9-wjmr-5w57/GHSA-2cj9-wjmr-5w57.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cj9-wjmr-5w57", + "modified": "2024-03-11T15:31:24Z", + "published": "2024-03-11T15:31:24Z", + "aliases": [ + "CVE-2024-1441" + ], + "details": "An off-by-one error flaw was found in the udevListInterfacesByStatus() function in libvirt when the number of interfaces exceeds the size of the `names` array. This issue can be reproduced by sending specially crafted data to the libvirt daemon, allowing an unprivileged client to perform a denial of service attack by causing the libvirt daemon to crash.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1441" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-1441" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2263841" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-193" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-11T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-4pc9-wmrm-8p87/GHSA-4pc9-wmrm-8p87.json b/advisories/unreviewed/2024/03/GHSA-4pc9-wmrm-8p87/GHSA-4pc9-wmrm-8p87.json new file mode 100644 index 00000000000..79df17022f5 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-4pc9-wmrm-8p87/GHSA-4pc9-wmrm-8p87.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pc9-wmrm-8p87", + "modified": "2024-03-11T15:31:24Z", + "published": "2024-03-11T15:31:24Z", + "aliases": [ + "CVE-2024-0670" + ], + "details": "Privilege escalation in windows agent plugin in Checkmk before 2.2.0p23, 2.1.0p40 and 2.0.0 (EOL) allows local user to escalate privileges", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0670" + }, + { + "type": "WEB", + "url": "https://checkmk.com/werk/16361" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-11T15:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-fqf7-66f9-wqff/GHSA-fqf7-66f9-wqff.json b/advisories/unreviewed/2024/03/GHSA-fqf7-66f9-wqff/GHSA-fqf7-66f9-wqff.json new file mode 100644 index 00000000000..03b6595bd56 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-fqf7-66f9-wqff/GHSA-fqf7-66f9-wqff.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqf7-66f9-wqff", + "modified": "2024-03-11T15:31:24Z", + "published": "2024-03-11T15:31:24Z", + "aliases": [ + "CVE-2024-2370" + ], + "details": "Unrestricted file upload vulnerability in ManageEngine Desktop Central affecting version 9, build 90055. This vulnerability could allow a remote attacker to upload a malicious file to the system without any credentials provided.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2370" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/unrestricted-file-upload-vulnerability-manageengine-desktop-central" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-11T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-m7gg-q7qj-3r2r/GHSA-m7gg-q7qj-3r2r.json b/advisories/unreviewed/2024/03/GHSA-m7gg-q7qj-3r2r/GHSA-m7gg-q7qj-3r2r.json index 3df245e3239..be364d306b0 100644 --- a/advisories/unreviewed/2024/03/GHSA-m7gg-q7qj-3r2r/GHSA-m7gg-q7qj-3r2r.json +++ b/advisories/unreviewed/2024/03/GHSA-m7gg-q7qj-3r2r/GHSA-m7gg-q7qj-3r2r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m7gg-q7qj-3r2r", - "modified": "2024-03-04T18:30:39Z", + "modified": "2024-03-11T15:31:24Z", "published": "2024-03-04T18:30:39Z", "aliases": [ "CVE-2024-27199" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27199" }, + { + "type": "WEB", + "url": "https://www.darkreading.com/cyberattacks-data-breaches/jetbrains-teamcity-mass-exploitation-underway-rogue-accounts-thrive" + }, { "type": "WEB", "url": "https://www.jetbrains.com/privacy-security/issues-fixed" diff --git a/advisories/unreviewed/2024/03/GHSA-xh94-49wq-7h2h/GHSA-xh94-49wq-7h2h.json b/advisories/unreviewed/2024/03/GHSA-xh94-49wq-7h2h/GHSA-xh94-49wq-7h2h.json index 337e78a626a..b69b1d39986 100644 --- a/advisories/unreviewed/2024/03/GHSA-xh94-49wq-7h2h/GHSA-xh94-49wq-7h2h.json +++ b/advisories/unreviewed/2024/03/GHSA-xh94-49wq-7h2h/GHSA-xh94-49wq-7h2h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xh94-49wq-7h2h", - "modified": "2024-03-04T18:30:39Z", + "modified": "2024-03-11T15:31:24Z", "published": "2024-03-04T18:30:39Z", "aliases": [ "CVE-2024-27198" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27198" }, + { + "type": "WEB", + "url": "https://www.darkreading.com/cyberattacks-data-breaches/jetbrains-teamcity-mass-exploitation-underway-rogue-accounts-thrive" + }, { "type": "WEB", "url": "https://www.jetbrains.com/privacy-security/issues-fixed"