Publish Advisories

GHSA-289c-42q5-rfhv
GHSA-3835-4hmw-pgj9
GHSA-6p6j-6hvm-6fqm
GHSA-8qcf-755r-4vhw
GHSA-fqvv-mh7w-3jq3
GHSA-hcvh-mwx3-f4mp
GHSA-pwvw-rggj-f74r
GHSA-qjxq-6v9g-fx7f
GHSA-r3m5-v6wj-p838
GHSA-xvw3-fvp9-cwjw
This commit is contained in:
advisory-database[bot]
2024-12-25 15:32:29 +00:00
parent 436a025cae
commit 100a9df38d
10 changed files with 325 additions and 0 deletions
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-289c-42q5-rfhv",
"modified": "2024-12-25T15:30:42Z",
"published": "2024-12-25T15:30:42Z",
"aliases": [
"CVE-2024-8950"
],
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arne Informatics Piramit Automation allows Blind SQL Injection.This issue affects Piramit Automation: before 27.09.2024.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8950"
},
{
"type": "WEB",
"url": "https://www.usom.gov.tr/bildirim/tr-24-1898"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-25T13:15:19Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3835-4hmw-pgj9",
"modified": "2024-12-25T15:30:42Z",
"published": "2024-12-25T15:30:42Z",
"aliases": [
"CVE-2024-39725"
],
"details": "IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39725"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7176782"
}
],
"database_specific": {
"cwe_ids": [
"CWE-209"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-25T14:15:21Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6p6j-6hvm-6fqm",
"modified": "2024-12-25T15:30:42Z",
"published": "2024-12-25T15:30:42Z",
"aliases": [
"CVE-2024-47978"
],
"details": "Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47978"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000258904/dsa-2024-488-security-update-for-dell-nativeedge-multiple-vulnerabilities"
}
],
"database_specific": {
"cwe_ids": [
"CWE-250"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-25T15:15:06Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8qcf-755r-4vhw",
"modified": "2024-12-25T15:30:42Z",
"published": "2024-12-25T15:30:42Z",
"aliases": [
"CVE-2024-39727"
],
"details": "IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victims web browser.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39727"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7176783"
}
],
"database_specific": {
"cwe_ids": [
"CWE-1022"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-25T14:15:22Z"
}
}
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-288",
"CWE-644"
],
"severity": "MODERATE",
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hcvh-mwx3-f4mp",
"modified": "2024-12-25T15:30:43Z",
"published": "2024-12-25T15:30:43Z",
"aliases": [
"CVE-2024-53291"
],
"details": "Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Exposure of Sensitive Information Through Metadata vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53291"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000258904/dsa-2024-488-security-update-for-dell-nativeedge-multiple-vulnerabilities"
}
],
"database_specific": {
"cwe_ids": [
"CWE-1230"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-25T15:15:07Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pwvw-rggj-f74r",
"modified": "2024-12-25T15:30:42Z",
"published": "2024-12-25T15:30:42Z",
"aliases": [
"CVE-2023-5117"
],
"details": "An issue was discovered in GitLab CE/EE affecting all versions before 17.6.0 in which users were unaware that files uploaded to comments on confidential issues and epics of public projects could be accessed without authentication via a direct link to the uploaded file URL.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5117"
},
{
"type": "WEB",
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/398250"
}
],
"database_specific": {
"cwe_ids": [
"CWE-213"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-25T15:15:05Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qjxq-6v9g-fx7f",
"modified": "2024-12-25T15:30:42Z",
"published": "2024-12-25T15:30:42Z",
"aliases": [
"CVE-2024-47102"
],
"details": "IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1\n\ncould allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to cause a denial of service.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47102"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7179826"
}
],
"database_specific": {
"cwe_ids": [
"CWE-20"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-25T15:15:06Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r3m5-v6wj-p838",
"modified": "2024-12-25T15:30:43Z",
"published": "2024-12-25T15:30:43Z",
"aliases": [
"CVE-2024-52906"
],
"details": "IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1\n\n\n\ncould allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel extension to cause a denial of service.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52906"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7179826"
}
],
"database_specific": {
"cwe_ids": [
"CWE-362"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-25T15:15:07Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xvw3-fvp9-cwjw",
"modified": "2024-12-25T15:30:42Z",
"published": "2024-12-25T15:30:42Z",
"aliases": [
"CVE-2024-52535"
],
"details": "Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolic link (symlink) attack vulnerability in the software remediation component. A low-privileged authenticated user could potentially exploit this vulnerability, gaining privileges escalation, leading to arbitrary deletion of files and folders from the system.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52535"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000261086/dsa-2024-470-security-update-for-dell-supportassist-for-home-pcs-and-dell-supportassist-for-business-pcs-vulnerabilities"
}
],
"database_specific": {
"cwe_ids": [
"CWE-61"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-25T15:15:07Z"
}
}