From 100a9df38db7654da5d023342bf8fdf69cef80f3 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 25 Dec 2024 15:32:29 +0000 Subject: [PATCH] Publish Advisories GHSA-289c-42q5-rfhv GHSA-3835-4hmw-pgj9 GHSA-6p6j-6hvm-6fqm GHSA-8qcf-755r-4vhw GHSA-fqvv-mh7w-3jq3 GHSA-hcvh-mwx3-f4mp GHSA-pwvw-rggj-f74r GHSA-qjxq-6v9g-fx7f GHSA-r3m5-v6wj-p838 GHSA-xvw3-fvp9-cwjw --- .../GHSA-289c-42q5-rfhv.json | 36 +++++++++++++++++++ .../GHSA-3835-4hmw-pgj9.json | 36 +++++++++++++++++++ .../GHSA-6p6j-6hvm-6fqm.json | 36 +++++++++++++++++++ .../GHSA-8qcf-755r-4vhw.json | 36 +++++++++++++++++++ .../GHSA-fqvv-mh7w-3jq3.json | 1 + .../GHSA-hcvh-mwx3-f4mp.json | 36 +++++++++++++++++++ .../GHSA-pwvw-rggj-f74r.json | 36 +++++++++++++++++++ .../GHSA-qjxq-6v9g-fx7f.json | 36 +++++++++++++++++++ .../GHSA-r3m5-v6wj-p838.json | 36 +++++++++++++++++++ .../GHSA-xvw3-fvp9-cwjw.json | 36 +++++++++++++++++++ 10 files changed, 325 insertions(+) create mode 100644 advisories/unreviewed/2024/12/GHSA-289c-42q5-rfhv/GHSA-289c-42q5-rfhv.json create mode 100644 advisories/unreviewed/2024/12/GHSA-3835-4hmw-pgj9/GHSA-3835-4hmw-pgj9.json create mode 100644 advisories/unreviewed/2024/12/GHSA-6p6j-6hvm-6fqm/GHSA-6p6j-6hvm-6fqm.json create mode 100644 advisories/unreviewed/2024/12/GHSA-8qcf-755r-4vhw/GHSA-8qcf-755r-4vhw.json create mode 100644 advisories/unreviewed/2024/12/GHSA-hcvh-mwx3-f4mp/GHSA-hcvh-mwx3-f4mp.json create mode 100644 advisories/unreviewed/2024/12/GHSA-pwvw-rggj-f74r/GHSA-pwvw-rggj-f74r.json create mode 100644 advisories/unreviewed/2024/12/GHSA-qjxq-6v9g-fx7f/GHSA-qjxq-6v9g-fx7f.json create mode 100644 advisories/unreviewed/2024/12/GHSA-r3m5-v6wj-p838/GHSA-r3m5-v6wj-p838.json create mode 100644 advisories/unreviewed/2024/12/GHSA-xvw3-fvp9-cwjw/GHSA-xvw3-fvp9-cwjw.json diff --git a/advisories/unreviewed/2024/12/GHSA-289c-42q5-rfhv/GHSA-289c-42q5-rfhv.json b/advisories/unreviewed/2024/12/GHSA-289c-42q5-rfhv/GHSA-289c-42q5-rfhv.json new file mode 100644 index 00000000000..0605a794848 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-289c-42q5-rfhv/GHSA-289c-42q5-rfhv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-289c-42q5-rfhv", + "modified": "2024-12-25T15:30:42Z", + "published": "2024-12-25T15:30:42Z", + "aliases": [ + "CVE-2024-8950" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arne Informatics Piramit Automation allows Blind SQL Injection.This issue affects Piramit Automation: before 27.09.2024.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8950" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1898" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-25T13:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3835-4hmw-pgj9/GHSA-3835-4hmw-pgj9.json b/advisories/unreviewed/2024/12/GHSA-3835-4hmw-pgj9/GHSA-3835-4hmw-pgj9.json new file mode 100644 index 00000000000..50c537631bc --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3835-4hmw-pgj9/GHSA-3835-4hmw-pgj9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3835-4hmw-pgj9", + "modified": "2024-12-25T15:30:42Z", + "published": "2024-12-25T15:30:42Z", + "aliases": [ + "CVE-2024-39725" + ], + "details": "IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39725" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7176782" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-25T14:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6p6j-6hvm-6fqm/GHSA-6p6j-6hvm-6fqm.json b/advisories/unreviewed/2024/12/GHSA-6p6j-6hvm-6fqm/GHSA-6p6j-6hvm-6fqm.json new file mode 100644 index 00000000000..c0442960b06 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6p6j-6hvm-6fqm/GHSA-6p6j-6hvm-6fqm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6p6j-6hvm-6fqm", + "modified": "2024-12-25T15:30:42Z", + "published": "2024-12-25T15:30:42Z", + "aliases": [ + "CVE-2024-47978" + ], + "details": "Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47978" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000258904/dsa-2024-488-security-update-for-dell-nativeedge-multiple-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-250" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-25T15:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8qcf-755r-4vhw/GHSA-8qcf-755r-4vhw.json b/advisories/unreviewed/2024/12/GHSA-8qcf-755r-4vhw/GHSA-8qcf-755r-4vhw.json new file mode 100644 index 00000000000..cd1f849e57d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8qcf-755r-4vhw/GHSA-8qcf-755r-4vhw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qcf-755r-4vhw", + "modified": "2024-12-25T15:30:42Z", + "published": "2024-12-25T15:30:42Z", + "aliases": [ + "CVE-2024-39727" + ], + "details": "IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victims’ web browser.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39727" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7176783" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1022" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-25T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fqvv-mh7w-3jq3/GHSA-fqvv-mh7w-3jq3.json b/advisories/unreviewed/2024/12/GHSA-fqvv-mh7w-3jq3/GHSA-fqvv-mh7w-3jq3.json index 404757088e5..8f8b6fd3bbe 100644 --- a/advisories/unreviewed/2024/12/GHSA-fqvv-mh7w-3jq3/GHSA-fqvv-mh7w-3jq3.json +++ b/advisories/unreviewed/2024/12/GHSA-fqvv-mh7w-3jq3/GHSA-fqvv-mh7w-3jq3.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-288", "CWE-644" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/12/GHSA-hcvh-mwx3-f4mp/GHSA-hcvh-mwx3-f4mp.json b/advisories/unreviewed/2024/12/GHSA-hcvh-mwx3-f4mp/GHSA-hcvh-mwx3-f4mp.json new file mode 100644 index 00000000000..b8834c7831b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hcvh-mwx3-f4mp/GHSA-hcvh-mwx3-f4mp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hcvh-mwx3-f4mp", + "modified": "2024-12-25T15:30:43Z", + "published": "2024-12-25T15:30:43Z", + "aliases": [ + "CVE-2024-53291" + ], + "details": "Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Exposure of Sensitive Information Through Metadata vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53291" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000258904/dsa-2024-488-security-update-for-dell-nativeedge-multiple-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1230" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-25T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pwvw-rggj-f74r/GHSA-pwvw-rggj-f74r.json b/advisories/unreviewed/2024/12/GHSA-pwvw-rggj-f74r/GHSA-pwvw-rggj-f74r.json new file mode 100644 index 00000000000..4a8786e845f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pwvw-rggj-f74r/GHSA-pwvw-rggj-f74r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwvw-rggj-f74r", + "modified": "2024-12-25T15:30:42Z", + "published": "2024-12-25T15:30:42Z", + "aliases": [ + "CVE-2023-5117" + ], + "details": "An issue was discovered in GitLab CE/EE affecting all versions before 17.6.0 in which users were unaware that files uploaded to comments on confidential issues and epics of public projects could be accessed without authentication via a direct link to the uploaded file URL.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5117" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/398250" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-213" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-25T15:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qjxq-6v9g-fx7f/GHSA-qjxq-6v9g-fx7f.json b/advisories/unreviewed/2024/12/GHSA-qjxq-6v9g-fx7f/GHSA-qjxq-6v9g-fx7f.json new file mode 100644 index 00000000000..0952b7d6af5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qjxq-6v9g-fx7f/GHSA-qjxq-6v9g-fx7f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjxq-6v9g-fx7f", + "modified": "2024-12-25T15:30:42Z", + "published": "2024-12-25T15:30:42Z", + "aliases": [ + "CVE-2024-47102" + ], + "details": "IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1\n\ncould allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to cause a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47102" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7179826" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-25T15:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-r3m5-v6wj-p838/GHSA-r3m5-v6wj-p838.json b/advisories/unreviewed/2024/12/GHSA-r3m5-v6wj-p838/GHSA-r3m5-v6wj-p838.json new file mode 100644 index 00000000000..934e7989478 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-r3m5-v6wj-p838/GHSA-r3m5-v6wj-p838.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3m5-v6wj-p838", + "modified": "2024-12-25T15:30:43Z", + "published": "2024-12-25T15:30:43Z", + "aliases": [ + "CVE-2024-52906" + ], + "details": "IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1\n\n\n\ncould allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel extension to cause a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52906" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7179826" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-25T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xvw3-fvp9-cwjw/GHSA-xvw3-fvp9-cwjw.json b/advisories/unreviewed/2024/12/GHSA-xvw3-fvp9-cwjw/GHSA-xvw3-fvp9-cwjw.json new file mode 100644 index 00000000000..3b3fcd0037b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xvw3-fvp9-cwjw/GHSA-xvw3-fvp9-cwjw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xvw3-fvp9-cwjw", + "modified": "2024-12-25T15:30:42Z", + "published": "2024-12-25T15:30:42Z", + "aliases": [ + "CVE-2024-52535" + ], + "details": "Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolic link (symlink) attack vulnerability in the software remediation component. A low-privileged authenticated user could potentially exploit this vulnerability, gaining privileges escalation, leading to arbitrary deletion of files and folders from the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52535" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000261086/dsa-2024-470-security-update-for-dell-supportassist-for-home-pcs-and-dell-supportassist-for-business-pcs-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-61" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-25T15:15:07Z" + } +} \ No newline at end of file