From 1376a5afd4f1ba8a5af6955212d47ea4e4d3afa3 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 10 Apr 2024 18:42:05 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-c69x-5xmw-v44x.json | 6 +- .../GHSA-2858-8cfx-69m9.json | 111 ++++++++++++++++ .../GHSA-34fj-r5gq-7395.json | 111 ++++++++++++++++ .../GHSA-37m4-hqxv-w26g.json | 112 ++++++++++++++++ .../GHSA-9wwp-q7wq-jx35.json | 61 +++++++++ .../GHSA-c2gg-4gq4-jv5j.json | 111 ++++++++++++++++ .../GHSA-cv55-v6rw-7r5v.json | 111 ++++++++++++++++ .../GHSA-hf43-47q4-fhq5.json | 115 ++++++++++++++++ .../GHSA-hjq6-52gw-2g7p.json | 81 ++++++++++++ .../GHSA-hp8h-7x69-4wmv.json | 69 ++++++++++ .../GHSA-j2r6-r929-v6gf.json | 115 ++++++++++++++++ .../GHSA-j5vm-7qcc-2wwg.json | 65 +++++++++ .../GHSA-r5vh-gc3r-r24w.json | 115 ++++++++++++++++ .../GHSA-v782-xr4w-3vqx.json | 111 ++++++++++++++++ .../GHSA-vxwr-wpjv-qjq7.json | 111 ++++++++++++++++ .../GHSA-xm4h-3jxr-m3c6.json | 123 ++++++++++++++++++ .../GHSA-xxp2-9c9g-7wmj.json | 111 ++++++++++++++++ .../GHSA-4f2m-qf8w-84rw.json | 11 +- .../GHSA-5gwx-vhc7-55r8.json | 11 +- .../GHSA-5gx7-f5j6-6r9q.json | 11 +- .../GHSA-5rmh-6fjp-jmcp.json | 11 +- .../GHSA-7674-fj4m-c42f.json | 11 +- .../GHSA-cj4f-m7fj-58gv.json | 11 +- .../GHSA-g85h-w3x6-7g28.json | 9 +- .../GHSA-j525-244m-q96j.json | 11 +- .../GHSA-x9rp-8j88-vh76.json | 11 +- .../GHSA-23r4-x5xc-qw4f.json | 39 ++++++ .../GHSA-24m8-r3wq-c97x.json | 42 ++++++ .../GHSA-27w6-8m77-x3qf.json | 38 ++++++ .../GHSA-2ch6-m8wh-67f2.json | 42 ++++++ .../GHSA-35hx-x7f3-cr36.json | 38 ++++++ .../GHSA-35m6-rf3v-8cxx.json | 38 ++++++ .../GHSA-37q5-v5qm-c9v8.json | 42 ++++++ .../GHSA-3f95-mxq2-2f63.json | 42 ++++++ .../GHSA-3fmq-xqpg-7wmg.json | 38 ++++++ .../GHSA-3jvg-6v8m-chpp.json | 38 ++++++ .../GHSA-3qj4-9cvg-gv2q.json | 38 ++++++ .../GHSA-42cr-cm2x-xxxj.json | 42 ++++++ .../GHSA-46cm-pfwv-cgf8.json | 38 ++++++ .../GHSA-52w9-whm3-f76c.json | 38 ++++++ .../GHSA-55c4-h3q7-f6wp.json | 38 ++++++ .../GHSA-5j77-g9r7-hpx3.json | 42 ++++++ .../GHSA-68qv-4jc5-hr7h.json | 38 ++++++ .../GHSA-6cq5-38vf-h3g2.json | 39 ++++++ .../GHSA-7v8g-rfp5-x3hm.json | 38 ++++++ .../GHSA-882m-54cg-63q7.json | 42 ++++++ .../GHSA-8wv4-58g4-2v58.json | 42 ++++++ .../GHSA-8x2m-vwxp-r65j.json | 38 ++++++ .../GHSA-99w2-67h8-5948.json | 38 ++++++ .../GHSA-9xch-xvj3-fmf3.json | 59 +++++++++ .../GHSA-cffw-pr5g-439r.json | 42 ++++++ .../GHSA-chwx-r397-6ww4.json | 38 ++++++ .../GHSA-cqgx-qm2w-88qc.json | 38 ++++++ .../GHSA-cqvp-qf4w-3mpx.json | 38 ++++++ .../GHSA-crgc-qfch-jgr7.json | 42 ++++++ .../GHSA-f525-qqcm-4ww9.json | 38 ++++++ .../GHSA-f7cx-hq8m-95w6.json | 42 ++++++ .../GHSA-f874-8386-mf62.json | 38 ++++++ .../GHSA-gqmf-gxrq-3j6q.json | 38 ++++++ .../GHSA-gv6g-p8pg-jx2h.json | 38 ++++++ .../GHSA-h9h2-jmvv-fr8c.json | 42 ++++++ .../GHSA-h9w4-3hv9-j8r3.json | 42 ++++++ .../GHSA-hcgv-gpgg-9mmm.json | 38 ++++++ .../GHSA-hm95-xqg2-4w57.json | 42 ++++++ .../GHSA-hp3w-grg4-233f.json | 42 ++++++ .../GHSA-hwc4-2rmw-hcvq.json | 38 ++++++ .../GHSA-jmw2-399f-6mwg.json | 38 ++++++ .../GHSA-m9h7-m3c9-xxfm.json | 38 ++++++ .../GHSA-mxvw-cj37-8g2h.json | 38 ++++++ .../GHSA-p52c-jr7p-8c89.json | 38 ++++++ .../GHSA-pj43-gpqr-fhm8.json | 38 ++++++ .../GHSA-pm8c-xqrr-62h2.json | 38 ++++++ .../GHSA-prc3-79c5-8h62.json | 38 ++++++ .../GHSA-pw2h-m7pw-m9c6.json | 38 ++++++ .../GHSA-q8mj-9x2v-j7w5.json | 38 ++++++ .../GHSA-rqcq-2f32-4q3g.json | 42 ++++++ .../GHSA-rrpg-fwx7-jf88.json | 38 ++++++ .../GHSA-v293-3p6g-j7w7.json | 38 ++++++ .../GHSA-v6wm-cwm9-2486.json | 38 ++++++ .../GHSA-vvx7-xv93-4vqx.json | 38 ++++++ .../GHSA-w6xp-gc2w-28hx.json | 42 ++++++ .../GHSA-wgqj-wx2p-22jm.json | 38 ++++++ .../GHSA-wh9j-8hrm-2g7r.json | 38 ++++++ .../GHSA-wmmf-r63x-5jrw.json | 38 ++++++ .../GHSA-wvjp-4x3w-pvqx.json | 38 ++++++ .../GHSA-wvpx-g427-q9wc.json | 42 ++++++ .../GHSA-wx43-g55g-2jf4.json | 42 ++++++ .../GHSA-wx55-ppw9-52p9.json | 42 ++++++ .../GHSA-x8m7-f4f6-46c2.json | 38 ++++++ .../GHSA-xw8r-2c2x-7j88.json | 42 ++++++ 90 files changed, 4237 insertions(+), 38 deletions(-) create mode 100644 advisories/github-reviewed/2024/04/GHSA-2858-8cfx-69m9/GHSA-2858-8cfx-69m9.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-34fj-r5gq-7395/GHSA-34fj-r5gq-7395.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-37m4-hqxv-w26g/GHSA-37m4-hqxv-w26g.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-9wwp-q7wq-jx35/GHSA-9wwp-q7wq-jx35.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-c2gg-4gq4-jv5j/GHSA-c2gg-4gq4-jv5j.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-cv55-v6rw-7r5v/GHSA-cv55-v6rw-7r5v.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-hf43-47q4-fhq5/GHSA-hf43-47q4-fhq5.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-hjq6-52gw-2g7p/GHSA-hjq6-52gw-2g7p.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-hp8h-7x69-4wmv/GHSA-hp8h-7x69-4wmv.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-j2r6-r929-v6gf/GHSA-j2r6-r929-v6gf.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-j5vm-7qcc-2wwg/GHSA-j5vm-7qcc-2wwg.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-r5vh-gc3r-r24w/GHSA-r5vh-gc3r-r24w.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-v782-xr4w-3vqx/GHSA-v782-xr4w-3vqx.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-vxwr-wpjv-qjq7/GHSA-vxwr-wpjv-qjq7.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-xm4h-3jxr-m3c6/GHSA-xm4h-3jxr-m3c6.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-xxp2-9c9g-7wmj/GHSA-xxp2-9c9g-7wmj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-23r4-x5xc-qw4f/GHSA-23r4-x5xc-qw4f.json create mode 100644 advisories/unreviewed/2024/04/GHSA-24m8-r3wq-c97x/GHSA-24m8-r3wq-c97x.json create mode 100644 advisories/unreviewed/2024/04/GHSA-27w6-8m77-x3qf/GHSA-27w6-8m77-x3qf.json create mode 100644 advisories/unreviewed/2024/04/GHSA-2ch6-m8wh-67f2/GHSA-2ch6-m8wh-67f2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-35hx-x7f3-cr36/GHSA-35hx-x7f3-cr36.json create mode 100644 advisories/unreviewed/2024/04/GHSA-35m6-rf3v-8cxx/GHSA-35m6-rf3v-8cxx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-37q5-v5qm-c9v8/GHSA-37q5-v5qm-c9v8.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3f95-mxq2-2f63/GHSA-3f95-mxq2-2f63.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3fmq-xqpg-7wmg/GHSA-3fmq-xqpg-7wmg.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3jvg-6v8m-chpp/GHSA-3jvg-6v8m-chpp.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3qj4-9cvg-gv2q/GHSA-3qj4-9cvg-gv2q.json create mode 100644 advisories/unreviewed/2024/04/GHSA-42cr-cm2x-xxxj/GHSA-42cr-cm2x-xxxj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-46cm-pfwv-cgf8/GHSA-46cm-pfwv-cgf8.json create mode 100644 advisories/unreviewed/2024/04/GHSA-52w9-whm3-f76c/GHSA-52w9-whm3-f76c.json create mode 100644 advisories/unreviewed/2024/04/GHSA-55c4-h3q7-f6wp/GHSA-55c4-h3q7-f6wp.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5j77-g9r7-hpx3/GHSA-5j77-g9r7-hpx3.json create mode 100644 advisories/unreviewed/2024/04/GHSA-68qv-4jc5-hr7h/GHSA-68qv-4jc5-hr7h.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6cq5-38vf-h3g2/GHSA-6cq5-38vf-h3g2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-7v8g-rfp5-x3hm/GHSA-7v8g-rfp5-x3hm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-882m-54cg-63q7/GHSA-882m-54cg-63q7.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8wv4-58g4-2v58/GHSA-8wv4-58g4-2v58.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8x2m-vwxp-r65j/GHSA-8x2m-vwxp-r65j.json create mode 100644 advisories/unreviewed/2024/04/GHSA-99w2-67h8-5948/GHSA-99w2-67h8-5948.json create mode 100644 advisories/unreviewed/2024/04/GHSA-9xch-xvj3-fmf3/GHSA-9xch-xvj3-fmf3.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cffw-pr5g-439r/GHSA-cffw-pr5g-439r.json create mode 100644 advisories/unreviewed/2024/04/GHSA-chwx-r397-6ww4/GHSA-chwx-r397-6ww4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cqgx-qm2w-88qc/GHSA-cqgx-qm2w-88qc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cqvp-qf4w-3mpx/GHSA-cqvp-qf4w-3mpx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-crgc-qfch-jgr7/GHSA-crgc-qfch-jgr7.json create mode 100644 advisories/unreviewed/2024/04/GHSA-f525-qqcm-4ww9/GHSA-f525-qqcm-4ww9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-f7cx-hq8m-95w6/GHSA-f7cx-hq8m-95w6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-f874-8386-mf62/GHSA-f874-8386-mf62.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gqmf-gxrq-3j6q/GHSA-gqmf-gxrq-3j6q.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gv6g-p8pg-jx2h/GHSA-gv6g-p8pg-jx2h.json create mode 100644 advisories/unreviewed/2024/04/GHSA-h9h2-jmvv-fr8c/GHSA-h9h2-jmvv-fr8c.json create mode 100644 advisories/unreviewed/2024/04/GHSA-h9w4-3hv9-j8r3/GHSA-h9w4-3hv9-j8r3.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hcgv-gpgg-9mmm/GHSA-hcgv-gpgg-9mmm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hm95-xqg2-4w57/GHSA-hm95-xqg2-4w57.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hp3w-grg4-233f/GHSA-hp3w-grg4-233f.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hwc4-2rmw-hcvq/GHSA-hwc4-2rmw-hcvq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-jmw2-399f-6mwg/GHSA-jmw2-399f-6mwg.json create mode 100644 advisories/unreviewed/2024/04/GHSA-m9h7-m3c9-xxfm/GHSA-m9h7-m3c9-xxfm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mxvw-cj37-8g2h/GHSA-mxvw-cj37-8g2h.json create mode 100644 advisories/unreviewed/2024/04/GHSA-p52c-jr7p-8c89/GHSA-p52c-jr7p-8c89.json create mode 100644 advisories/unreviewed/2024/04/GHSA-pj43-gpqr-fhm8/GHSA-pj43-gpqr-fhm8.json create mode 100644 advisories/unreviewed/2024/04/GHSA-pm8c-xqrr-62h2/GHSA-pm8c-xqrr-62h2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-prc3-79c5-8h62/GHSA-prc3-79c5-8h62.json create mode 100644 advisories/unreviewed/2024/04/GHSA-pw2h-m7pw-m9c6/GHSA-pw2h-m7pw-m9c6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-q8mj-9x2v-j7w5/GHSA-q8mj-9x2v-j7w5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rqcq-2f32-4q3g/GHSA-rqcq-2f32-4q3g.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rrpg-fwx7-jf88/GHSA-rrpg-fwx7-jf88.json create mode 100644 advisories/unreviewed/2024/04/GHSA-v293-3p6g-j7w7/GHSA-v293-3p6g-j7w7.json create mode 100644 advisories/unreviewed/2024/04/GHSA-v6wm-cwm9-2486/GHSA-v6wm-cwm9-2486.json create mode 100644 advisories/unreviewed/2024/04/GHSA-vvx7-xv93-4vqx/GHSA-vvx7-xv93-4vqx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-w6xp-gc2w-28hx/GHSA-w6xp-gc2w-28hx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wgqj-wx2p-22jm/GHSA-wgqj-wx2p-22jm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wh9j-8hrm-2g7r/GHSA-wh9j-8hrm-2g7r.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wmmf-r63x-5jrw/GHSA-wmmf-r63x-5jrw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wvjp-4x3w-pvqx/GHSA-wvjp-4x3w-pvqx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wvpx-g427-q9wc/GHSA-wvpx-g427-q9wc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wx43-g55g-2jf4/GHSA-wx43-g55g-2jf4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wx55-ppw9-52p9/GHSA-wx55-ppw9-52p9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-x8m7-f4f6-46c2/GHSA-x8m7-f4f6-46c2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-xw8r-2c2x-7j88/GHSA-xw8r-2c2x-7j88.json diff --git a/advisories/github-reviewed/2024/03/GHSA-c69x-5xmw-v44x/GHSA-c69x-5xmw-v44x.json b/advisories/github-reviewed/2024/03/GHSA-c69x-5xmw-v44x/GHSA-c69x-5xmw-v44x.json index 9047d01a1ae..43a524ed7d8 100644 --- a/advisories/github-reviewed/2024/03/GHSA-c69x-5xmw-v44x/GHSA-c69x-5xmw-v44x.json +++ b/advisories/github-reviewed/2024/03/GHSA-c69x-5xmw-v44x/GHSA-c69x-5xmw-v44x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c69x-5xmw-v44x", - "modified": "2024-03-18T19:58:17Z", + "modified": "2024-04-10T16:42:59Z", "published": "2024-03-06T15:25:08Z", "aliases": [ "CVE-2024-24767" @@ -11,7 +11,7 @@ "severity": [ { "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], "affected": [ @@ -65,7 +65,7 @@ "cwe_ids": [ "CWE-307" ], - "severity": "CRITICAL", + "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-03-06T15:25:08Z", "nvd_published_at": "2024-03-06T18:15:46Z" diff --git a/advisories/github-reviewed/2024/04/GHSA-2858-8cfx-69m9/GHSA-2858-8cfx-69m9.json b/advisories/github-reviewed/2024/04/GHSA-2858-8cfx-69m9/GHSA-2858-8cfx-69m9.json new file mode 100644 index 00000000000..f83ad7fb32d --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-2858-8cfx-69m9/GHSA-2858-8cfx-69m9.json @@ -0,0 +1,111 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2858-8cfx-69m9", + "modified": "2024-04-10T17:12:47Z", + "published": "2024-04-10T17:12:47Z", + "aliases": [ + "CVE-2024-31982" + ], + "summary": "XWiki Platform: Remote code execution as guest via DatabaseSearch", + "details": "### Impact\nXWiki's database search allows remote code execution through the search text. This allows remote code execution for any visitor of a public wiki or user of a closed wiki as the database search is by default accessible for all users. This impacts the confidentiality, integrity and availability of the whole XWiki installation.\n\nTo reproduce on an instance, without being logged in, go to `/xwiki/bin/get/Main/DatabaseSearch?outputSyntax=plain&text=%7D%7D%7D%7B%7Basync%20async%3Dfalse%7D%7D%7B%7Bgroovy%7D%7Dprintln%28%22Hello%20from%22%20%2B%20%22%20search%20text%3A%22%20%2B%20%2823%20%2B%2019%29%29%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D%20`. If the title of the RSS channel contains `Hello from search text:42`, the instance is vulnerable.\n\n### Patches\nThis vulnerability has been patched in XWiki 14.10.20, 15.5.4 and 15.10RC1.\n\n### Workarounds\nIt is possible to manually apply [this patch](https://github.com/xwiki/xwiki-platform/commit/95bdd6cc6298acdf7f8f21298d40eeb8390a8565#diff-ef3314b8bb489e5368618ea1940c59098b18ec2246cc65fe337ae636de87e404) to the page `Main.DatabaseSearch`. Alternatively, unless database search is explicitly used by users, this page can be deleted as this is not the default search interface of XWiki.\n\n### References\n* https://jira.xwiki.org/browse/XWIKI-21472\n* https://github.com/xwiki/xwiki-platform/commit/95bdd6cc6298acdf7f8f21298d40eeb8390a8565\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-search-ui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4-milestone-1" + }, + { + "fixed": "14.10.20" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-search-ui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "15.0-rc-1" + }, + { + "fixed": "15.5.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-search-ui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "15.6-rc-1" + }, + { + "fixed": "15.10-rc-1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-2858-8cfx-69m9" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/3c9e4bb04286de94ad24854026a09fa967538e31" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/459e968be8740c8abc2a168196ce21e5ba93cfb8" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/95bdd6cc6298acdf7f8f21298d40eeb8390a8565" + }, + { + "type": "PACKAGE", + "url": "https://github.com/xwiki/xwiki-platform" + }, + { + "type": "WEB", + "url": "https://jira.xwiki.org/browse/XWIKI-21472" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-95" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-04-10T17:12:47Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-34fj-r5gq-7395/GHSA-34fj-r5gq-7395.json b/advisories/github-reviewed/2024/04/GHSA-34fj-r5gq-7395/GHSA-34fj-r5gq-7395.json new file mode 100644 index 00000000000..3f5e1686371 --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-34fj-r5gq-7395/GHSA-34fj-r5gq-7395.json @@ -0,0 +1,111 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-34fj-r5gq-7395", + "modified": "2024-04-10T17:11:32Z", + "published": "2024-04-10T17:11:32Z", + "aliases": [ + "CVE-2024-31465" + ], + "summary": "XWiki Platform: Remote code execution from account via SearchSuggestSourceSheet", + "details": "### Impact\nAny user with edit right on any page can execute any code on the server by adding an object of type `XWiki.SearchSuggestSourceClass` to their user profile or any other page. This compromises the confidentiality, integrity and availability of the whole XWiki installation.\n\nTo reproduce on an instance, as a user without script nor programming rights, add an object of type `XWiki.SearchSuggestSourceClass` to your profile page. On this object, set every possible property to `}}}{{async}}{{groovy}}println(\"Hello from Groovy!\"){{/groovy}}{{/async}}` (i.e., name, engine, service, query, limit and icon). Save and display the page, then append `?sheet=XWiki.SearchSuggestSourceSheet` to the URL. If any property displays as `Hello from Groovy!}}}`, then the instance is vulnerable.\n\n### Patches\nThis vulnerability has been patched in XWiki 14.10.20, 15.5.4 and 15.10 RC1.\n\n### Workarounds\n[This patch](https://github.com/xwiki/xwiki-platform/commit/6a7f19f6424036fce3d703413137adde950ae809#diff-67b473d2b6397d65b7726c6a13555850b11b10128321adf9e627e656e1d130a5) can be manually applied to the document `XWiki.SearchSuggestSourceSheet`.\n\n### References\n* https://jira.xwiki.org/browse/XWIKI-21474\n* https://github.com/xwiki/xwiki-platform/commit/6a7f19f6424036fce3d703413137adde950ae809\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-search-ui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "5.2-milestone-2" + }, + { + "fixed": "14.10.20" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-search-ui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "15.0-rc-1" + }, + { + "fixed": "15.5.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-search-ui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "15.6-rc-1" + }, + { + "fixed": "15.10-rc-1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-34fj-r5gq-7395" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/0317a3aa78065e66c86fc725976b06bf7f9b446e" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/2740974c32dbb7cc565546d0f04e2374b32b36f7" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/6a7f19f6424036fce3d703413137adde950ae809" + }, + { + "type": "PACKAGE", + "url": "https://github.com/xwiki/xwiki-platform" + }, + { + "type": "WEB", + "url": "https://jira.xwiki.org/browse/XWIKI-21474" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-95" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-04-10T17:11:32Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-37m4-hqxv-w26g/GHSA-37m4-hqxv-w26g.json b/advisories/github-reviewed/2024/04/GHSA-37m4-hqxv-w26g/GHSA-37m4-hqxv-w26g.json new file mode 100644 index 00000000000..f7efcc827cf --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-37m4-hqxv-w26g/GHSA-37m4-hqxv-w26g.json @@ -0,0 +1,112 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37m4-hqxv-w26g", + "modified": "2024-04-10T17:14:35Z", + "published": "2024-04-10T17:14:35Z", + "aliases": [ + "CVE-2024-31986" + ], + "summary": "XWiki Platform CSRF remote code execution through scheduler job's document reference", + "details": "### Impact\nBy creating a document with a special crafted documented reference and an `XWiki.SchedulerJobClass` XObject, it is possible to execute arbitrary code on the server whenever an admin visits the scheduler page or the scheduler page is referenced, e.g., via an image in a comment on a page in the wiki.\n\nTo reproduce on an XWiki installation, click on this link to create a new document : `/xwiki/bin/view/%22%3E%5D%5D%7B%7B%2Fhtml%7D%7D%7B%7Basync%20context%3D%22request/parameters%22%7D%7D%7B%7Bvelocity%7D%7D%23evaluate%28%24request/eval%29/`.\nThen, add to this document an object of type `XWiki.SchedulerJobClass`.\nFinally, as an admin, go to `/xwiki/bin/view/Scheduler/?eval=$services.logging.getLogger(%22attacker%22).error(%22Hello%20from%20URL%20Parameter!%20I%20got%20programming:%20$services.security.authorization.hasAccess(%27programming%27)%22)`.\nIf the logs contain `ERROR attacker - Hello from URL Parameter! I got programming: true`, the installation is vulnerable.\n\n### Patches\nThe vulnerability has been fixed on XWiki 14.10.19, 15.5.5, and 15.9.\n\n### Workarounds\nModify the Scheduler.WebHome page following this [patch](https://github.com/xwiki/xwiki-platform/commit/f16ca4ef1513f84ce2e685d4a05d689bd3a2ab4c#diff-1e2995eacccbbbdcc4987ff64f46ac74837d166cf9e92920b4a4f8af0f10bd47).\n\n### References\n- https://jira.xwiki.org/browse/XWIKI-21416\n- https://github.com/xwiki/xwiki-platform/commit/f16ca4ef1513f84ce2e685d4a05d689bd3a2ab4c\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-scheduler-ui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.1" + }, + { + "fixed": "14.10.19" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-scheduler-ui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "15.0-rc-1" + }, + { + "fixed": "15.5.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-scheduler-ui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "15.6-rc-1" + }, + { + "fixed": "15.9" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-37m4-hqxv-w26g" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/8a92cb4bef7e5f244ae81eed3e64fe9be95827cf" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/efd3570f3e5e944ec0ad0899bf799bf9563aef87" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/f30d9c641750a3f034b5910c6a3a7724ae8f2269" + }, + { + "type": "PACKAGE", + "url": "https://github.com/xwiki/xwiki-platform" + }, + { + "type": "WEB", + "url": "https://jira.xwiki.org/browse/XWIKI-21416" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352", + "CWE-95" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-04-10T17:14:35Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-9wwp-q7wq-jx35/GHSA-9wwp-q7wq-jx35.json b/advisories/github-reviewed/2024/04/GHSA-9wwp-q7wq-jx35/GHSA-9wwp-q7wq-jx35.json new file mode 100644 index 00000000000..bb079dda1a5 --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-9wwp-q7wq-jx35/GHSA-9wwp-q7wq-jx35.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wwp-q7wq-jx35", + "modified": "2024-04-10T17:15:50Z", + "published": "2024-04-10T17:15:50Z", + "aliases": [ + "CVE-2024-31999" + ], + "summary": "@fastify/secure-session: Reuse of destroyed secure session cookie", + "details": "### Impact\n\nAt the end of the request handling, it will encrypt all data in the session with a secret key and attach the ciphertext as a cookie value with the defined cookie name. After that, the session on the server side is destroyed. When an encrypted cookie with matching session name is provided with subsequent requests, it will decrypt the ciphertext to get the data. The plugin then creates a new session with the data in the ciphertext. Thus theoretically the web instance is still accessing the data from a server-side session, but technically that session is generated solely from a user provided cookie (which is assumed to be non-craftable because it is encrypted with a secret key not known to the user).\n\nThe issue exists in the session removal process. In the delete function of the code, when the session is deleted, it is marked for deletion. However, if an attacker could gain access to the cookie, they could keep using it forever.\n\n### Patches\n\nFixed in 56d66642ecc633cff0606927601e81cdac361370.\nUpdate to v7.3.0.\n\n### Workarounds\n\nInclude a \"last update\" field in the session, and treat \"old sessions\" as expired. \nMake sure to configure your cookie as \"http only\".\n\n### References\n\n* https://hackerone.com/reports/2374253\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "npm", + "name": "@fastify/secure-session" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "7.3.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/fastify/fastify-secure-session/security/advisories/GHSA-9wwp-q7wq-jx35" + }, + { + "type": "WEB", + "url": "https://github.com/fastify/fastify-secure-session/commit/56d66642ecc633cff0606927601e81cdac361370" + }, + { + "type": "PACKAGE", + "url": "https://github.com/fastify/fastify-secure-session" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-613" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-04-10T17:15:50Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-c2gg-4gq4-jv5j/GHSA-c2gg-4gq4-jv5j.json b/advisories/github-reviewed/2024/04/GHSA-c2gg-4gq4-jv5j/GHSA-c2gg-4gq4-jv5j.json new file mode 100644 index 00000000000..3ad027b266b --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-c2gg-4gq4-jv5j/GHSA-c2gg-4gq4-jv5j.json @@ -0,0 +1,111 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2gg-4gq4-jv5j", + "modified": "2024-04-10T17:16:53Z", + "published": "2024-04-10T17:16:53Z", + "aliases": [ + "CVE-2024-31997" + ], + "summary": "XWiki Platform remote code execution from account through UIExtension parameters", + "details": "### Impact\nParameters of UI extensions are always interpreted as Velocity code and executed with programming rights. Any user with edit right on any document like the user's own profile can create UI extensions. This allows remote code execution and thereby impacts the confidentiality, integrity and availability of the whole XWiki installation.\n\nTo reproduce, edit your user profile with the object editor and add a UIExtension object with the following values:\n```\nExtension Point ID: org.xwiki.platform.panels.Applications\nExtension ID: platform.panels.myFakeApplication\nExtension parameters: \nlabel=I got programming right: $services.security.authorization.hasAccess('programming')\ntarget=Main.WebHome\ntargetQueryString=\nicon=icon:bomb\nExtension Scope: \"Current User\".\n```\n\nSave the document and open any document. If an application entry with the text \"I got programming right: true\" is displayed, the attack succeeded, if the code in \"label\" is displayed literally, the XWiki installation isn't vulnerable.\n\n### Patches\nThis vulnerability has been patched in XWiki 14.10.19, 15.5.4 and 15.9-RC1.\n\n### Workarounds\nWe're not aware of any workarounds apart from upgrading.\n\n### References\n* https://jira.xwiki.org/browse/XWIKI-21335\n* https://github.com/xwiki/xwiki-platform/commit/171e7c7d0e56deaa7b3678657ae26ef95379b1ea\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-uiextension-api" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "14.10.19" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-uiextension-api" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "15.0-rc-1" + }, + { + "fixed": "15.5.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-uiextension-api" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "15.6-rc-1" + }, + { + "fixed": "15.9-rc-1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-c2gg-4gq4-jv5j" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/171e7c7d0e56deaa7b3678657ae26ef95379b1ea" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/1b2574eb966457ca4ef34e557376b8751d1be90d" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/56748e154a9011f0d6239bec0823eaaeab6ec3f7" + }, + { + "type": "PACKAGE", + "url": "https://github.com/xwiki/xwiki-platform" + }, + { + "type": "WEB", + "url": "https://jira.xwiki.org/browse/XWIKI-21335" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-04-10T17:16:53Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-cv55-v6rw-7r5v/GHSA-cv55-v6rw-7r5v.json b/advisories/github-reviewed/2024/04/GHSA-cv55-v6rw-7r5v/GHSA-cv55-v6rw-7r5v.json new file mode 100644 index 00000000000..ff4f3c9e66e --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-cv55-v6rw-7r5v/GHSA-cv55-v6rw-7r5v.json @@ -0,0 +1,111 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cv55-v6rw-7r5v", + "modified": "2024-04-10T17:14:47Z", + "published": "2024-04-10T17:14:47Z", + "aliases": [ + "CVE-2024-31987" + ], + "summary": "XWiki Platform remote code execution from account via custom skins support", + "details": "### Impact\nAny user who can edit any page like their profile can create a custom skin with a template override that is executed with programming right, thus allowing remote code execution. \n\nTo reproduce, as a user without edit, script or admin right, add an object of class `XWiki.XWikiSkins` to your profile. Name it whatever you want and set the Base Skin to `flamingo`.\nAdd an object of class `XWikiSkinFileOverrideClass` and set the path to `macros.vm` and the content to:\n```\n#macro(mediumUserAvatar $username)\n #resizedUserAvatar($username 50)\n $services.logging.getLogger('Skin').error(\"I got programming: $services.security.authorization.hasAccess('programming')\")\n#end\n```\nBack to your profile, click `Test this skin`. Force a refresh, just in case.\nIf the error \"Skin - I got programming: true\" gets logged, the installation is vulnerable.\n\n### Patches\nThis has been patched in XWiki 14.10.19, 15.5.4 and 15.10RC1.\n\n### Workarounds\nWe're not aware of any workaround except upgrading.\n\n### References\n* https://jira.xwiki.org/browse/XWIKI-21478\n* https://github.com/xwiki/xwiki-platform/commit/3d4dbb41f52d1a6e39835cfb1695ca6668605a39 (>= 15.8 RC1)\n* https://github.com/xwiki/xwiki-platform/commit/da177c3c972e797d92c1a31e278f946012c41b56 (< 15.8 RC1)\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-oldcore" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "6.4-milestone-1" + }, + { + "fixed": "14.10.19" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-oldcore" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "15.0-rc-1" + }, + { + "fixed": "15.5.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-oldcore" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "15.6-rc-1" + }, + { + "fixed": "15.10-rc-1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-cv55-v6rw-7r5v" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/3d4dbb41f52d1a6e39835cfb1695ca6668605a39" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/626d2a5dbf95b4e719ae13bf1a0a9c76e4edd5a2" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/da177c3c972e797d92c1a31e278f946012c41b56" + }, + { + "type": "PACKAGE", + "url": "https://github.com/xwiki/xwiki-platform" + }, + { + "type": "WEB", + "url": "https://jira.xwiki.org/browse/XWIKI-21478" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-04-10T17:14:47Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-hf43-47q4-fhq5/GHSA-hf43-47q4-fhq5.json b/advisories/github-reviewed/2024/04/GHSA-hf43-47q4-fhq5/GHSA-hf43-47q4-fhq5.json new file mode 100644 index 00000000000..72b6cd4d443 --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-hf43-47q4-fhq5/GHSA-hf43-47q4-fhq5.json @@ -0,0 +1,115 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf43-47q4-fhq5", + "modified": "2024-04-10T17:16:37Z", + "published": "2024-04-10T17:16:37Z", + "aliases": [ + "CVE-2024-31996" + ], + "summary": "XWiki Commons missing escaping of `{` in Velocity escapetool allows remote code execution", + "details": "### Impact\nThe HTML escaping of escaping tool that is used in XWiki doesn't escape `{`, which, when used in certain places, allows XWiki syntax injection and thereby remote code execution.\n\nTo reproduce in an XWiki installation, open `/xwiki/bin/view/Panels/PanelLayoutUpdate?place=%7B%7B%2Fhtml%7D%7D%7B%7Basync%20async%3Dfalse%7D%7D%7B%7Bvelocity%7D%7D%23evaluate(%24request.eval)%7B%7B%2Fvelocity%7D%7D%7B%7B%2Fasync%7D%7D&eval=Hello%20from%20URL%20Parameter!%20I%20got%20programming%3A%20%24services.security.authorization.hasAccess(%27programming%27)` where `` is the URL of your XWiki installation. If this displays `You are not admin on this place Hello from URL Parameter! I got programming: true`, the installation is vulnerable.\n\n### Patches\nThe vulnerability has been fixed on XWiki 14.10.19, 15.5.5, and 15.9 RC1.\n\n### Workarounds\nApart from upgrading, there is no generic workaround. However, replacing `$escapetool.html` by `$escapetool.xml` in XWiki documents fixes the vulnerability. In a standard XWiki installation, we're only aware of the document `Panels.PanelLayoutUpdate` that exposes this vulnerability, patching this document is thus a workaround. Any extension could expose this vulnerability and might thus require patching, too.\n\n### References\n- https://github.com/xwiki/xwiki-commons/commit/b94142e2a66ec32e89eacab67c3da8d91f5ef93a\n- https://jira.xwiki.org/browse/XCOMMONS-2828\n- https://jira.xwiki.org/browse/XWIKI-21438", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.commons:xwiki-commons-velocity" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.0.1" + }, + { + "fixed": "14.10.19" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.commons:xwiki-commons-velocity" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "15.0-rc-1" + }, + { + "fixed": "15.5.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.commons:xwiki-commons-velocity" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "15.6-rc-1" + }, + { + "fixed": "15.9-rc-1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-commons/security/advisories/GHSA-hf43-47q4-fhq5" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-commons/commit/b0805160ec7b01ee12417e79cb384e60ae4817aa" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-commons/commit/b94142e2a66ec32e89eacab67c3da8d91f5ef93a" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-commons/commit/ed7ff515a2436a1c6dcbd0c6ca0c41e434d58915" + }, + { + "type": "PACKAGE", + "url": "https://github.com/xwiki/xwiki-commons" + }, + { + "type": "WEB", + "url": "https://jira.xwiki.org/browse/XCOMMONS-2828" + }, + { + "type": "WEB", + "url": "https://jira.xwiki.org/browse/XWIKI-21438" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-95" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-04-10T17:16:37Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-hjq6-52gw-2g7p/GHSA-hjq6-52gw-2g7p.json b/advisories/github-reviewed/2024/04/GHSA-hjq6-52gw-2g7p/GHSA-hjq6-52gw-2g7p.json new file mode 100644 index 00000000000..b6bcb349f7d --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-hjq6-52gw-2g7p/GHSA-hjq6-52gw-2g7p.json @@ -0,0 +1,81 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjq6-52gw-2g7p", + "modified": "2024-04-10T17:07:09Z", + "published": "2024-04-10T17:07:09Z", + "aliases": [ + "CVE-2024-22423" + ], + "summary": "yt-dlp: `--exec` command injection when using `%q` in yt-dlp on Windows (Bypass of CVE-2023-40581)", + "details": "### Summary\nThe [patch that addressed CVE-2023-40581](https://github.com/yt-dlp/yt-dlp/commit/de015e930747165dbb8fcd360f8775fd973b7d6e) attempted to prevent RCE when using `--exec` with `%q` by replacing double quotes with two double quotes.\nHowever, this escaping is not sufficient, and still allows expansion of environment variables.\n\nSupport for output template expansion in `--exec`, along with this vulnerable behavior, was added to `yt-dlp` in version [2021.04.11](https://github.com/yt-dlp/yt-dlp/releases/tag/2021.04.11).\n\n```cmd\n> yt-dlp \"https://youtu.be/42xO6rVqf2E\" --ignore-config -f 18 --exec \"echo %(title)q\"\n[youtube] Extracting URL: https://youtu.be/42xO6rVqf2E\n[youtube] 42xO6rVqf2E: Downloading webpage\n[youtube] 42xO6rVqf2E: Downloading ios player API JSON\n[youtube] 42xO6rVqf2E: Downloading android player API JSON\n[youtube] 42xO6rVqf2E: Downloading m3u8 information\n[info] 42xO6rVqf2E: Downloading 1 format(s): 18\n[download] Destination: %CMDCMDLINE:~-1%&echo pwned&calc.exe [42xO6rVqf2E].mp4\n[download] 100% of 126.16KiB in 00:00:00 at 2.46MiB/s\n[Exec] Executing command: echo \"%CMDCMDLINE:~-1%&echo pwned&calc.exe\"\n\"\"\npwned\n```\n\n### Patches\nyt-dlp version 2024.04.09 fixes this issue by properly escaping `%`. It replaces them with `%%cd:~,%`, a variable that expands to nothing, leaving only the leading percent.\n\n### Workarounds\nIt is recommended to upgrade yt-dlp to version 2024.04.09 as soon as possible. Also, always be careful when using `--exec`, because while this specific vulnerability has been patched, using unvalidated input in shell commands is inherently dangerous.\n\nFor Windows users who are not able to upgrade:\n- Avoid using any output template expansion in `--exec` other than `{}` (filepath).\n- If expansion in `--exec` is needed, verify the fields you are using do not contain `%`, `\"`, `|` or `&`.\n- Instead of using `--exec`, write the info json and load the fields from it instead.\n\n### Details\nWhen escaping variables, the following code is used for Windows.\n[`yt_dlp/compat/__init__.py` line 31-33](https://github.com/yt-dlp/yt-dlp/blob/8e6e3651727b0b85764857fc6329fe5e0a3f00de/yt_dlp/compat/__init__.py#L31-L33)\n```python\n def compat_shlex_quote(s):\n import re\n return s if re.match(r'^[-_\\w./]+$', s) else s.replace('\"', '\"\"').join('\"\"')\n```\nIt replaces `\"` with `\"\"` to balance out the quotes and keep quoting intact if non-allowed characters are included. However, the `%CMDCMDLINE%` variable can be used to generate a quote using `%CMDCMDLINE:~-1%`; since the value of `%CMDCMDLINE%` is the commandline with which `cmd.exe` was called, and it is always called with the command surrounded by quotes, `%CMDCMDLINE:~-1%` expands to `\"`. After the quotes have been unbalanced, special characters are no longer quoted and commands can be executed:\n```cmd\n%CMDCMDLINE:~-1%&calc.exe\n```\n\n### References\n- https://github.com/yt-dlp/yt-dlp/security/advisories/GHSA-hjq6-52gw-2g7p\n- https://nvd.nist.gov/vuln/detail/CVE-2024-22423\n- https://github.com/yt-dlp/yt-dlp/releases/tag/2024.04.09\n- https://github.com/yt-dlp/yt-dlp/commit/ff07792676f404ffff6ee61b5638c9dc1a33a37a", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "yt-dlp" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2021.04.11" + }, + { + "fixed": "2024.04.09" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/yt-dlp/yt-dlp/security/advisories/GHSA-42h4-v29r-42qg" + }, + { + "type": "WEB", + "url": "https://github.com/yt-dlp/yt-dlp/security/advisories/GHSA-hjq6-52gw-2g7p" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22423" + }, + { + "type": "WEB", + "url": "https://github.com/yt-dlp/yt-dlp/commit/de015e930747165dbb8fcd360f8775fd973b7d6e" + }, + { + "type": "WEB", + "url": "https://github.com/yt-dlp/yt-dlp/commit/ff07792676f404ffff6ee61b5638c9dc1a33a37a" + }, + { + "type": "PACKAGE", + "url": "https://github.com/yt-dlp/yt-dlp" + }, + { + "type": "WEB", + "url": "https://github.com/yt-dlp/yt-dlp/releases/tag/2021.04.11" + }, + { + "type": "WEB", + "url": "https://github.com/yt-dlp/yt-dlp/releases/tag/2024.04.09" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-04-10T17:07:09Z", + "nvd_published_at": "2024-04-09T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-hp8h-7x69-4wmv/GHSA-hp8h-7x69-4wmv.json b/advisories/github-reviewed/2024/04/GHSA-hp8h-7x69-4wmv/GHSA-hp8h-7x69-4wmv.json new file mode 100644 index 00000000000..63df3ded243 --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-hp8h-7x69-4wmv/GHSA-hp8h-7x69-4wmv.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp8h-7x69-4wmv", + "modified": "2024-04-10T17:16:15Z", + "published": "2024-04-10T17:16:15Z", + "aliases": [ + "CVE-2024-31995" + ], + "summary": "zcap has incomplete expiration checks in capability chains.", + "details": "### Impact\n\nWhen invoking a capability with a chain depth of 2, i.e., it is delegated directly from the root capability, the `expires` property is not properly checked against the current date or other `date` param. This can allow invocations outside of the original intended time period. A zcap still cannot be invoked without being able to use the associated private key material.\n\n### Patches\n\n`@digitalbazaar/zcap` v9.0.1 fixes expiration checking.\n\n### Workarounds\n\nA zcap could be revoked at any time.\n\n### References\n\nhttps://github.com/digitalbazaar/zcap/pull/82", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "npm", + "name": "@digitalbazaar/zcap" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "9.0.1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/digitalbazaar/zcap/security/advisories/GHSA-hp8h-7x69-4wmv" + }, + { + "type": "WEB", + "url": "https://github.com/digitalbazaar/zcap/pull/82" + }, + { + "type": "WEB", + "url": "https://github.com/digitalbazaar/zcap/commit/261eea040109b6e25159c88d8ed49d3c37f8fcfe" + }, + { + "type": "WEB", + "url": "https://github.com/digitalbazaar/zcap/commit/55f8549c80124b85dfb0f3dcf83f2c63f42532e5" + }, + { + "type": "PACKAGE", + "url": "https://github.com/digitalbazaar/zcap" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-613" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-10T17:16:15Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-j2r6-r929-v6gf/GHSA-j2r6-r929-v6gf.json b/advisories/github-reviewed/2024/04/GHSA-j2r6-r929-v6gf/GHSA-j2r6-r929-v6gf.json new file mode 100644 index 00000000000..b74696a8652 --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-j2r6-r929-v6gf/GHSA-j2r6-r929-v6gf.json @@ -0,0 +1,115 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2r6-r929-v6gf", + "modified": "2024-04-10T17:14:12Z", + "published": "2024-04-10T17:14:12Z", + "aliases": [ + "CVE-2024-31985" + ], + "summary": "XWiki Platform CSRF in the job scheduler", + "details": "### Impact\nIt is possible to schedule/trigger/unschedule existing jobs by having an admin visit the Job Scheduler page through a predictable URL, for example by embedding such an URL in any content as an image.\n\nTo reproduce in an XWiki installation, open `:/xwiki/bin/view/Scheduler/?do=trigger&which=Scheduler.NotificationEmailDailySender` as a user with admin rights. If there is no error message that indicates the CSRF token is invalid, the installation is vulnerable.\n\n### Patches\nThe vulnerability has been fixed on XWiki 14.10.19, 15.5.5, and 15.9.\n\n### Workarounds\nModify the Scheduler.WebHome page following this [patch](https://github.com/xwiki/xwiki-platform/commit/f16ca4ef1513f84ce2e685d4a05d689bd3a2ab4c#diff-1e2995eacccbbbdcc4987ff64f46ac74837d166cf9e92920b4a4f8af0f10bd47).\n\n### References\n- https://jira.xwiki.org/browse/XWIKI-20851\n- https://github.com/xwiki/xwiki-platform/commit/f16ca4ef1513f84ce2e685d4a05d689bd3a2ab4c", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-scheduler-ui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.1" + }, + { + "fixed": "14.10.19" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-scheduler-ui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "15.0-rc-1" + }, + { + "fixed": "15.5.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-scheduler-ui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "15.6-rc-1" + }, + { + "fixed": "15.9" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-j2r6-r929-v6gf" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/8a92cb4bef7e5f244ae81eed3e64fe9be95827cf" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/efd3570f3e5e944ec0ad0899bf799bf9563aef87" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/f16ca4ef1513f84ce2e685d4a05d689bd3a2ab4c" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/f30d9c641750a3f034b5910c6a3a7724ae8f2269" + }, + { + "type": "PACKAGE", + "url": "https://github.com/xwiki/xwiki-platform" + }, + { + "type": "WEB", + "url": "https://jira.xwiki.org/browse/XWIKI-20851" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-10T17:14:12Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-j5vm-7qcc-2wwg/GHSA-j5vm-7qcc-2wwg.json b/advisories/github-reviewed/2024/04/GHSA-j5vm-7qcc-2wwg/GHSA-j5vm-7qcc-2wwg.json new file mode 100644 index 00000000000..b0b3cc2cdb9 --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-j5vm-7qcc-2wwg/GHSA-j5vm-7qcc-2wwg.json @@ -0,0 +1,65 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5vm-7qcc-2wwg", + "modified": "2024-04-10T17:15:26Z", + "published": "2024-04-10T17:15:26Z", + "aliases": [ + + ], + "summary": "Kopia: Storage connection credentials written to console on \"repository status\" CLI command with JSON output", + "details": "### Impact\n\n_What kind of vulnerability is it? Who is impacted?_\n\nStorage credentials are written to the console.\n\n### Patches\n\n_Has the problem been patched?_ Yes, see #3589\n_What versions should users upgrade to?_\n- Any version after or including commit 1d6f852cd6534f4bea978cbdc85c583803d79f77\n- No release has been created yet.\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\n\n- Be aware that `kopia repo status --json` will write the credentials to the output without scrubbing them.\n- Avoid executing `kopia repo status` with the `--json` flag in an insecure environment where.\n- Avoid logging the output of the `kopia repo status --json` command. \n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Go", + "name": "github.com/kopia/kopia" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.16.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/kopia/kopia/security/advisories/GHSA-j5vm-7qcc-2wwg" + }, + { + "type": "WEB", + "url": "https://github.com/kopia/kopia/pull/3589" + }, + { + "type": "WEB", + "url": "https://github.com/kopia/kopia/commit/1d6f852cd6534f4bea978cbdc85c583803d79f77" + }, + { + "type": "PACKAGE", + "url": "https://github.com/kopia/kopia" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2024-04-10T17:15:26Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-r5vh-gc3r-r24w/GHSA-r5vh-gc3r-r24w.json b/advisories/github-reviewed/2024/04/GHSA-r5vh-gc3r-r24w/GHSA-r5vh-gc3r-r24w.json new file mode 100644 index 00000000000..483ebd040a8 --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-r5vh-gc3r-r24w/GHSA-r5vh-gc3r-r24w.json @@ -0,0 +1,115 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5vh-gc3r-r24w", + "modified": "2024-04-10T17:14:59Z", + "published": "2024-04-10T17:14:59Z", + "aliases": [ + "CVE-2024-31988" + ], + "summary": "XWiki Platform CSRF remote code execution through the realtime HTML Converter API", + "details": "### Impact\nWhen the realtime editor is installed in XWiki, it allows arbitrary remote code execution with the interaction of an admin user with programming right. More precisely, by getting an admin user to either visit a crafted URL or to view an image with this URL that could be in a comment, the attacker can get the admin to execute arbitrary XWiki syntax including scripting macros with Groovy or Python code. This compromises the confidentiality, integrity and availability of the whole XWiki installation.\n\nTo reproduce on an XWiki installation, as an admin, click on `/xwiki/bin/get/RTFrontend/ConvertHTML?wiki=xwiki&space=Main&page=WebHome&text=%7B%7Bvelocity%7D%7D%24logtool.error%28%22Hello%20from%20Velocity%20%21%22%29%7B%7B%2Fvelocity%7D%7D`. If the error \"Hello from Velocity!\" gets logged then the installation is vulnerable.\n\n### Patches\nThis vulnerability has been patched in XWiki 14.10.19, 15.5.4 and 15.9.\n\n### Workarounds\nUpdate `RTFrontend.ConvertHTML` following this [patch](https://github.com/xwiki/xwiki-platform/commit/4896712ee6483da623f131be2e618f1f2b79cb8d#diff-32a2a63950724b24e63587570cd95a41cf689111b8ba61c48dabee9effec6d61).\nThis will, however, break some synchronization processes in the realtime editor, so upgrading should be the preferred way on installations where this editor is used.\n\n### References\n* https://jira.xwiki.org/browse/XWIKI-21424\n* https://github.com/xwiki/xwiki-platform/commit/4896712ee6483da623f131be2e618f1f2b79cb8d\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-realtime-ui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "13.9-rc-1" + }, + { + "fixed": "14.10.19" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-realtime-ui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "15.0-rc-1" + }, + { + "fixed": "15.5.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-realtime-ui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "15.6-rc-1" + }, + { + "fixed": "15.9" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-r5vh-gc3r-r24w" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/4896712ee6483da623f131be2e618f1f2b79cb8d" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/9f8cc88497418750b09ce9fde5d67d840f038fbf" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/d88da4572fb7d4f95e1f54bb0cce33fce3df08d9" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/d9f5043da289ff106f08e23576746fd8baf98794" + }, + { + "type": "PACKAGE", + "url": "https://github.com/xwiki/xwiki-platform" + }, + { + "type": "WEB", + "url": "https://jira.xwiki.org/browse/XWIKI-21424" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-04-10T17:14:59Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-v782-xr4w-3vqx/GHSA-v782-xr4w-3vqx.json b/advisories/github-reviewed/2024/04/GHSA-v782-xr4w-3vqx/GHSA-v782-xr4w-3vqx.json new file mode 100644 index 00000000000..0477085c025 --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-v782-xr4w-3vqx/GHSA-v782-xr4w-3vqx.json @@ -0,0 +1,111 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v782-xr4w-3vqx", + "modified": "2024-04-10T17:07:27Z", + "published": "2024-04-10T17:07:27Z", + "aliases": [ + "CVE-2024-31464" + ], + "summary": "XWiki Platform: Password hash might be leaked by diff once the xobject holding them is deleted", + "details": "### Impact\n\nIt is possible to access the hash of a password by using the diff feature of the history whenever the object storing the password is deleted. Using that vulnerability it's possible for an attacker to have access to the hash password of a user if they have rights to edit the users' page. \n\nNow with the default right scheme in XWiki this vulnerability is normally prevented on user profiles, except by users with Admin rights. Note that this vulnerability also impacts any extensions that might use passwords stored in xobjects: for those usecases it depends on the right of those pages.\n\nThere is currently no way to be 100% sure that this vulnerability has been exploited, as an attacker with enough privilege could have deleted the revision where the xobject was deleted after rolling-back the deletion. But again, this operation requires high privileges on the target page (Admin right). A page with a user password xobject which have in its history a revision where the object has been deleted should be considered at risk and the password should be changed there.\n\n### Patches\n\nThe vulnerability has been patched in XWiki 14.10.19, 15.5.4 and 15.9-rc-1 by performing a better check before dislaying data of a diff, to ensure it's not coming from a password field. \n\n### Workarounds\n\nAdmins should ensure that the user pages are properly protected: the edit right shouldn't be allowed for other users than Admin and owner of the profile (which is the default right). \nNow there's not much workaround possible for a privileged user other than upgrading XWiki. \n\n### References\n\n* JIRA ticket: https://jira.xwiki.org/browse/XWIKI-19948\n* Commit: https://github.com/xwiki/xwiki-platform/commit/f1eaec1e512220fabd970d053c627e435a1652cf\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n* Open an issue in [Jira XWiki.org](https://jira.xwiki.org/)\n* Email us at [Security Mailing List](mailto:security@xwiki.org)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-oldcore" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "5.0-rc-1" + }, + { + "fixed": "14.10.19" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-oldcore" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "15.0-rc-1" + }, + { + "fixed": "15.5.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-oldcore" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "15.6-rc-1" + }, + { + "fixed": "15.9-rc-1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-v782-xr4w-3vqx" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/9075668a4135cce114ef2a4b72eba3161a9e94c4" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/955fb097e02a2a7153f527522ee9eef42447e5d7" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/f1eaec1e512220fabd970d053c627e435a1652cf" + }, + { + "type": "PACKAGE", + "url": "https://github.com/xwiki/xwiki-platform" + }, + { + "type": "WEB", + "url": "https://jira.xwiki.org/browse/XWIKI-19948" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-10T17:07:27Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-vxwr-wpjv-qjq7/GHSA-vxwr-wpjv-qjq7.json b/advisories/github-reviewed/2024/04/GHSA-vxwr-wpjv-qjq7/GHSA-vxwr-wpjv-qjq7.json new file mode 100644 index 00000000000..feff9d95eac --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-vxwr-wpjv-qjq7/GHSA-vxwr-wpjv-qjq7.json @@ -0,0 +1,111 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vxwr-wpjv-qjq7", + "modified": "2024-04-10T17:11:45Z", + "published": "2024-04-10T17:11:45Z", + "aliases": [ + "CVE-2024-31981" + ], + "summary": "XWiki Platform: Privilege escalation (PR) from user registration through PDFClass", + "details": "### Impact\nRemote code execution is possible via PDF export templates.\nTo reproduce on an installation, register a new user account with username `PDFClass` if `XWiki.PDFClass` does not exist.\nOn `XWiki.PDFClass`, use the class editor to add a \"style\" property of type \"TextArea\" and content type \"Plain Text\".\nThen, add an object of class `PDFClass` and set the \"style\" attribute to `$services.logging.getLogger('PDFClass').error(\"I got programming: $services.security.authorization.hasAccess('programming')\")`.\nFinally, go to `/xwiki/bin/export/Main/WebHome?format=pdf&pdftemplate=XWiki.PDFClass`. If the logs contain \"ERROR PDFClass - I got programming: true\", the instance is vulnerable.\n\n### Patches\nThis vulnerability has been patched in XWiki 14.10.20, 15.5.4 and 15.10-rc-1.\n\n### Workarounds\nIf PDF templates are not typically used on the instance, an administrator can create the document `XWiki.PDFClass` and block its edition, after making sure that it does not contain a `style` attribute.\nOtherwise, the instance needs to be updated.\n\n### References\n- https://jira.xwiki.org/browse/XWIKI-21337\n- https://github.com/xwiki/xwiki-platform/commit/d28e21a670c69880b951e415dd2ddd69d273eae9\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-oldcore" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.0.1" + }, + { + "fixed": "14.10.20" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-oldcore" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "15.0-rc-1" + }, + { + "fixed": "15.5.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-oldcore" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "15.6-rc-1" + }, + { + "fixed": "15.10-rc-1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-vxwr-wpjv-qjq7" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/480186f9d2fca880513da8bc5a609674d106cbd3" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/a4ad14d9c1605a5ab957237e505ebbb29f5b9d73" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/d28e21a670c69880b951e415dd2ddd69d273eae9" + }, + { + "type": "PACKAGE", + "url": "https://github.com/xwiki/xwiki-platform" + }, + { + "type": "WEB", + "url": "https://jira.xwiki.org/browse/XWIKI-21337" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-04-10T17:11:45Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-xm4h-3jxr-m3c6/GHSA-xm4h-3jxr-m3c6.json b/advisories/github-reviewed/2024/04/GHSA-xm4h-3jxr-m3c6/GHSA-xm4h-3jxr-m3c6.json new file mode 100644 index 00000000000..60eacd2e9f5 --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-xm4h-3jxr-m3c6/GHSA-xm4h-3jxr-m3c6.json @@ -0,0 +1,123 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xm4h-3jxr-m3c6", + "modified": "2024-04-10T17:13:16Z", + "published": "2024-04-10T17:13:15Z", + "aliases": [ + "CVE-2024-31984" + ], + "summary": "XWiki Platform: Remote code execution through space title and Solr space facet", + "details": "### Impact\nBy creating a document with a specially crafted title, it is possible to trigger remote code execution in the (Solr-based) search in XWiki. This allows any user who can edit the title of a space (all users by default) to execute any Groovy code in the XWiki installation which compromises the confidentiality, integrity and availability of the whole XWiki installation.\n\nTo reproduce, as a user without script nor programming rights, create a document with title `{{/html}}{{async}}{{groovy}}println(\"Hello from Groovy Title!\"){{/groovy}}{{/async}}` and content `Test Document`. Using the search UI, search for `\"Test Document\"`, then deploy the `Location` facet on the right of the screen, next to the search results. The installation is vulnerable if you see an item such as:\n```\nHello from Groovy Title!\n\n
1
\n\n\n{{/html}}\n```\n\n### Patches\nThis has been patched in XWiki 14.10.20, 15.5.4 and 15.10 RC1.\n\n### Workarounds\nModify the `Main.SolrSpaceFacet` page following this [patch](https://github.com/xwiki/xwiki-platform/commit/acba74c149a041345b24dcca52c586f872ba97fb#diff-22dd1949ed9019a39f2550f5a953a1a967c30a374dc9eeddb74069bf229b17d5).\n\n### References\n* https://jira.xwiki.org/browse/XWIKI-21471\n* https://github.com/xwiki/xwiki-platform/commit/acba74c149a041345b24dcca52c586f872ba97fb\n* https://github.com/xwiki/xwiki-platform/commit/74e301c481e69eeea674dac7fed6af3614cf08c5\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-search-solr-ui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.2-rc-1" + }, + { + "fixed": "14.10.20" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-search-solr-ui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "15.0-rc-1" + }, + { + "fixed": "15.5.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-search-solr-ui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "15.6-rc-1" + }, + { + "fixed": "15.10-rc-1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-xm4h-3jxr-m3c6" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/43c9d551e3c11e9d8f176b556dd33bbe31fc66e0" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/5ef9d294d37be92ee22b2549e38663b29dce8767" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/74e301c481e69eeea674dac7fed6af3614cf08c5" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/94fc12db87c2431eb1335ecb9c2954b1905bde62" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/acba74c149a041345b24dcca52c586f872ba97fb" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/ef55105d6eeec5635fd693f0070c5aaaf3bdd940" + }, + { + "type": "PACKAGE", + "url": "https://github.com/xwiki/xwiki-platform" + }, + { + "type": "WEB", + "url": "https://jira.xwiki.org/browse/XWIKI-21471" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-95" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-04-10T17:13:15Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-xxp2-9c9g-7wmj/GHSA-xxp2-9c9g-7wmj.json b/advisories/github-reviewed/2024/04/GHSA-xxp2-9c9g-7wmj/GHSA-xxp2-9c9g-7wmj.json new file mode 100644 index 00000000000..09f0ad94361 --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-xxp2-9c9g-7wmj/GHSA-xxp2-9c9g-7wmj.json @@ -0,0 +1,111 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxp2-9c9g-7wmj", + "modified": "2024-04-10T17:13:00Z", + "published": "2024-04-10T17:13:00Z", + "aliases": [ + "CVE-2024-31983" + ], + "summary": "XWiki Platform: Remote code execution from edit in multilingual wikis via translations", + "details": "### Impact\n\nIn multilingual wikis, translations can be edited by any user who has edit right, circumventing the rights that are normally required for authoring translations (script right for user-scope translations, wiki admin for translations on the wiki). This can be exploited for remote code execution if the translation value is not properly escaped where it is used. To reproduce, in a multilingual wiki, as a user without script or admin right, edit a translation of `AppWithinMinutes.Translations` and in the line `platform.appwithinminutes.description=` add `{{async}}{{groovy}}println(\"Hello from Translation\"){{/groovy}}{{/async}}` at the end. Then open the app with in minutes home page (`AppWithinMinutes.WebHome`) in the same locale. If translations are still working and \"Hello from Translation\" is displayed at the end of the introduction, the installation is vulnerable.\n\n### Patches\nThis has been patched in XWiki 14.10.20, 15.5.4 and 15.10RC1.\n\n### Workarounds\nWe're not aware of any workaround except restricting edit right on documents that contain translations.\n\n### References\n* https://jira.xwiki.org/browse/XWIKI-21411\n* https://github.com/xwiki/xwiki-platform/commit/c4c8d61c30de72298d805ccc82df2a307f131c54\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-localization-source-wiki" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.3-milestone-2" + }, + { + "fixed": "14.10.20" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-localization-source-wiki" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "15.0-rc-1" + }, + { + "fixed": "15.5.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-localization-source-wiki" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "15.6-rc-1" + }, + { + "fixed": "15.10-rc-1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-xxp2-9c9g-7wmj" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/2a9ce88f33663c53c9c63b2ea573f4720ea2efb9" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/73aef9648bbff04b697837f1b906932f0d5caacb" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/c4c8d61c30de72298d805ccc82df2a307f131c54" + }, + { + "type": "PACKAGE", + "url": "https://github.com/xwiki/xwiki-platform" + }, + { + "type": "WEB", + "url": "https://jira.xwiki.org/browse/XWIKI-21411" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-04-10T17:13:00Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-4f2m-qf8w-84rw/GHSA-4f2m-qf8w-84rw.json b/advisories/unreviewed/2024/02/GHSA-4f2m-qf8w-84rw/GHSA-4f2m-qf8w-84rw.json index ffb07987b59..7f870cdb411 100644 --- a/advisories/unreviewed/2024/02/GHSA-4f2m-qf8w-84rw/GHSA-4f2m-qf8w-84rw.json +++ b/advisories/unreviewed/2024/02/GHSA-4f2m-qf8w-84rw/GHSA-4f2m-qf8w-84rw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4f2m-qf8w-84rw", - "modified": "2024-02-27T12:31:09Z", + "modified": "2024-04-10T18:30:46Z", "published": "2024-02-27T12:31:09Z", "aliases": [ "CVE-2021-46927" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnitro_enclaves: Use get_user_pages_unlocked() call to handle mmap assert\n\nAfter commit 5b78ed24e8ec (\"mm/pagemap: add mmap_assert_locked()\nannotations to find_vma*()\"), the call to get_user_pages() will trigger\nthe mmap assert.\n\nstatic inline void mmap_assert_locked(struct mm_struct *mm)\n{\n\tlockdep_assert_held(&mm->mmap_lock);\n\tVM_BUG_ON_MM(!rwsem_is_locked(&mm->mmap_lock), mm);\n}\n\n[ 62.521410] kernel BUG at include/linux/mmap_lock.h:156!\n...........................................................\n[ 62.538938] RIP: 0010:find_vma+0x32/0x80\n...........................................................\n[ 62.605889] Call Trace:\n[ 62.608502] \n[ 62.610956] ? lock_timer_base+0x61/0x80\n[ 62.614106] find_extend_vma+0x19/0x80\n[ 62.617195] __get_user_pages+0x9b/0x6a0\n[ 62.620356] __gup_longterm_locked+0x42d/0x450\n[ 62.623721] ? finish_wait+0x41/0x80\n[ 62.626748] ? __kmalloc+0x178/0x2f0\n[ 62.629768] ne_set_user_memory_region_ioctl.isra.0+0x225/0x6a0 [nitro_enclaves]\n[ 62.635776] ne_enclave_ioctl+0x1cf/0x6d7 [nitro_enclaves]\n[ 62.639541] __x64_sys_ioctl+0x82/0xb0\n[ 62.642620] do_syscall_64+0x3b/0x90\n[ 62.645642] entry_SYSCALL_64_after_hwframe+0x44/0xae\n\nUse get_user_pages_unlocked() when setting the enclave memory regions.\nThat's a similar pattern as mmap_read_lock() used together with\nget_user_pages().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T10:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-5gwx-vhc7-55r8/GHSA-5gwx-vhc7-55r8.json b/advisories/unreviewed/2024/02/GHSA-5gwx-vhc7-55r8/GHSA-5gwx-vhc7-55r8.json index 4b99d4d4ab2..48b58f2a113 100644 --- a/advisories/unreviewed/2024/02/GHSA-5gwx-vhc7-55r8/GHSA-5gwx-vhc7-55r8.json +++ b/advisories/unreviewed/2024/02/GHSA-5gwx-vhc7-55r8/GHSA-5gwx-vhc7-55r8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5gwx-vhc7-55r8", - "modified": "2024-02-27T12:31:10Z", + "modified": "2024-04-10T18:30:47Z", "published": "2024-02-27T12:31:10Z", "aliases": [ "CVE-2021-46934" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: validate user data in compat ioctl\n\nWrong user data may cause warning in i2c_transfer(), ex: zero msgs.\nUserspace should not be able to trigger warnings, so this patch adds\nvalidation checks for user data in compact ioctl to prevent reported\nwarnings", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-754" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T10:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-5gx7-f5j6-6r9q/GHSA-5gx7-f5j6-6r9q.json b/advisories/unreviewed/2024/02/GHSA-5gx7-f5j6-6r9q/GHSA-5gx7-f5j6-6r9q.json index 436ba434e2b..c165941c567 100644 --- a/advisories/unreviewed/2024/02/GHSA-5gx7-f5j6-6r9q/GHSA-5gx7-f5j6-6r9q.json +++ b/advisories/unreviewed/2024/02/GHSA-5gx7-f5j6-6r9q/GHSA-5gx7-f5j6-6r9q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5gx7-f5j6-6r9q", - "modified": "2024-02-27T12:31:10Z", + "modified": "2024-04-10T18:30:47Z", "published": "2024-02-27T12:31:10Z", "aliases": [ "CVE-2021-46931" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Wrap the tx reporter dump callback to extract the sq\n\nFunction mlx5e_tx_reporter_dump_sq() casts its void * argument to struct\nmlx5e_txqsq *, but in TX-timeout-recovery flow the argument is actually\nof type struct mlx5e_tx_timeout_ctx *.\n\n mlx5_core 0000:08:00.1 enp8s0f1: TX timeout detected\n mlx5_core 0000:08:00.1 enp8s0f1: TX timeout on queue: 1, SQ: 0x11ec, CQ: 0x146d, SQ Cons: 0x0 SQ Prod: 0x1, usecs since last trans: 21565000\n BUG: stack guard page was hit at 0000000093f1a2de (stack is 00000000b66ea0dc..000000004d932dae)\n kernel stack overflow (page fault): 0000 [#1] SMP NOPTI\n CPU: 5 PID: 95 Comm: kworker/u20:1 Tainted: G W OE 5.13.0_mlnx #1\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n Workqueue: mlx5e mlx5e_tx_timeout_work [mlx5_core]\n RIP: 0010:mlx5e_tx_reporter_dump_sq+0xd3/0x180\n [mlx5_core]\n Call Trace:\n mlx5e_tx_reporter_dump+0x43/0x1c0 [mlx5_core]\n devlink_health_do_dump.part.91+0x71/0xd0\n devlink_health_report+0x157/0x1b0\n mlx5e_reporter_tx_timeout+0xb9/0xf0 [mlx5_core]\n ? mlx5e_tx_reporter_err_cqe_recover+0x1d0/0x1d0\n [mlx5_core]\n ? mlx5e_health_queue_dump+0xd0/0xd0 [mlx5_core]\n ? update_load_avg+0x19b/0x550\n ? set_next_entity+0x72/0x80\n ? pick_next_task_fair+0x227/0x340\n ? finish_task_switch+0xa2/0x280\n mlx5e_tx_timeout_work+0x83/0xb0 [mlx5_core]\n process_one_work+0x1de/0x3a0\n worker_thread+0x2d/0x3c0\n ? process_one_work+0x3a0/0x3a0\n kthread+0x115/0x130\n ? kthread_park+0x90/0x90\n ret_from_fork+0x1f/0x30\n --[ end trace 51ccabea504edaff ]---\n RIP: 0010:mlx5e_tx_reporter_dump_sq+0xd3/0x180\n PKRU: 55555554\n Kernel panic - not syncing: Fatal exception\n Kernel Offset: disabled\n end Kernel panic - not syncing: Fatal exception\n\nTo fix this bug add a wrapper for mlx5e_tx_reporter_dump_sq() which\nextracts the sq from struct mlx5e_tx_timeout_ctx and set it as the\nTX-timeout-recovery flow dump callback.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T10:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-5rmh-6fjp-jmcp/GHSA-5rmh-6fjp-jmcp.json b/advisories/unreviewed/2024/02/GHSA-5rmh-6fjp-jmcp/GHSA-5rmh-6fjp-jmcp.json index 3b2aa730f15..ee736a070c5 100644 --- a/advisories/unreviewed/2024/02/GHSA-5rmh-6fjp-jmcp/GHSA-5rmh-6fjp-jmcp.json +++ b/advisories/unreviewed/2024/02/GHSA-5rmh-6fjp-jmcp/GHSA-5rmh-6fjp-jmcp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5rmh-6fjp-jmcp", - "modified": "2024-02-27T12:31:10Z", + "modified": "2024-04-10T18:30:47Z", "published": "2024-02-27T12:31:10Z", "aliases": [ "CVE-2021-46930" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: mtu3: fix list_head check warning\n\nThis is caused by uninitialization of list_head.\n\nBUG: KASAN: use-after-free in __list_del_entry_valid+0x34/0xe4\n\nCall trace:\ndump_backtrace+0x0/0x298\nshow_stack+0x24/0x34\ndump_stack+0x130/0x1a8\nprint_address_description+0x88/0x56c\n__kasan_report+0x1b8/0x2a0\nkasan_report+0x14/0x20\n__asan_load8+0x9c/0xa0\n__list_del_entry_valid+0x34/0xe4\nmtu3_req_complete+0x4c/0x300 [mtu3]\nmtu3_gadget_stop+0x168/0x448 [mtu3]\nusb_gadget_unregister_driver+0x204/0x3a0\nunregister_gadget_item+0x44/0xa4", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T10:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-7674-fj4m-c42f/GHSA-7674-fj4m-c42f.json b/advisories/unreviewed/2024/02/GHSA-7674-fj4m-c42f/GHSA-7674-fj4m-c42f.json index adae0c477de..e2327415b92 100644 --- a/advisories/unreviewed/2024/02/GHSA-7674-fj4m-c42f/GHSA-7674-fj4m-c42f.json +++ b/advisories/unreviewed/2024/02/GHSA-7674-fj4m-c42f/GHSA-7674-fj4m-c42f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7674-fj4m-c42f", - "modified": "2024-02-27T12:31:10Z", + "modified": "2024-04-10T18:30:47Z", "published": "2024-02-27T12:31:10Z", "aliases": [ "CVE-2021-46932" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: appletouch - initialize work before device registration\n\nSyzbot has reported warning in __flush_work(). This warning is caused by\nwork->func == NULL, which means missing work initialization.\n\nThis may happen, since input_dev->close() calls\ncancel_work_sync(&dev->work), but dev->work initalization happens _after_\ninput_register_device() call.\n\nSo this patch moves dev->work initialization before registering input\ndevice", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-665" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T10:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-cj4f-m7fj-58gv/GHSA-cj4f-m7fj-58gv.json b/advisories/unreviewed/2024/02/GHSA-cj4f-m7fj-58gv/GHSA-cj4f-m7fj-58gv.json index 5125d5525d9..f50229ae6a4 100644 --- a/advisories/unreviewed/2024/02/GHSA-cj4f-m7fj-58gv/GHSA-cj4f-m7fj-58gv.json +++ b/advisories/unreviewed/2024/02/GHSA-cj4f-m7fj-58gv/GHSA-cj4f-m7fj-58gv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cj4f-m7fj-58gv", - "modified": "2024-02-27T12:31:10Z", + "modified": "2024-04-10T18:30:46Z", "published": "2024-02-27T12:31:10Z", "aliases": [ "CVE-2021-46928" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nparisc: Clear stale IIR value on instruction access rights trap\n\nWhen a trap 7 (Instruction access rights) occurs, this means the CPU\ncouldn't execute an instruction due to missing execute permissions on\nthe memory region. In this case it seems the CPU didn't even fetched\nthe instruction from memory and thus did not store it in the cr19 (IIR)\nregister before calling the trap handler. So, the trap handler will find\nsome random old stale value in cr19.\n\nThis patch simply overwrites the stale IIR value with a constant magic\n\"bad food\" value (0xbaadf00d), in the hope people don't start to try to\nunderstand the various random IIR values in trap 7 dumps.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-755" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T10:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-g85h-w3x6-7g28/GHSA-g85h-w3x6-7g28.json b/advisories/unreviewed/2024/02/GHSA-g85h-w3x6-7g28/GHSA-g85h-w3x6-7g28.json index 875cf0e361d..67e6ded8c78 100644 --- a/advisories/unreviewed/2024/02/GHSA-g85h-w3x6-7g28/GHSA-g85h-w3x6-7g28.json +++ b/advisories/unreviewed/2024/02/GHSA-g85h-w3x6-7g28/GHSA-g85h-w3x6-7g28.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g85h-w3x6-7g28", - "modified": "2024-02-27T12:31:09Z", + "modified": "2024-04-10T18:30:46Z", "published": "2024-02-27T12:31:09Z", "aliases": [ "CVE-2021-46926" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: hda: intel-sdw-acpi: harden detection of controller\n\nThe existing code currently sets a pointer to an ACPI handle before\nchecking that it's actually a SoundWire controller. This can lead to\nissues where the graph walk continues and eventually fails, but the\npointer was set already.\n\nThis patch changes the logic so that the information provided to\nthe caller is set when a controller is found.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T10:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-j525-244m-q96j/GHSA-j525-244m-q96j.json b/advisories/unreviewed/2024/02/GHSA-j525-244m-q96j/GHSA-j525-244m-q96j.json index 68428bcf4c4..101b92a05ca 100644 --- a/advisories/unreviewed/2024/02/GHSA-j525-244m-q96j/GHSA-j525-244m-q96j.json +++ b/advisories/unreviewed/2024/02/GHSA-j525-244m-q96j/GHSA-j525-244m-q96j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j525-244m-q96j", - "modified": "2024-02-27T12:31:10Z", + "modified": "2024-04-10T18:30:46Z", "published": "2024-02-27T12:31:10Z", "aliases": [ "CVE-2021-46929" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: use call_rcu to free endpoint\n\nThis patch is to delay the endpoint free by calling call_rcu() to fix\nanother use-after-free issue in sctp_sock_dump():\n\n BUG: KASAN: use-after-free in __lock_acquire+0x36d9/0x4c20\n Call Trace:\n __lock_acquire+0x36d9/0x4c20 kernel/locking/lockdep.c:3218\n lock_acquire+0x1ed/0x520 kernel/locking/lockdep.c:3844\n __raw_spin_lock_bh include/linux/spinlock_api_smp.h:135 [inline]\n _raw_spin_lock_bh+0x31/0x40 kernel/locking/spinlock.c:168\n spin_lock_bh include/linux/spinlock.h:334 [inline]\n __lock_sock+0x203/0x350 net/core/sock.c:2253\n lock_sock_nested+0xfe/0x120 net/core/sock.c:2774\n lock_sock include/net/sock.h:1492 [inline]\n sctp_sock_dump+0x122/0xb20 net/sctp/diag.c:324\n sctp_for_each_transport+0x2b5/0x370 net/sctp/socket.c:5091\n sctp_diag_dump+0x3ac/0x660 net/sctp/diag.c:527\n __inet_diag_dump+0xa8/0x140 net/ipv4/inet_diag.c:1049\n inet_diag_dump+0x9b/0x110 net/ipv4/inet_diag.c:1065\n netlink_dump+0x606/0x1080 net/netlink/af_netlink.c:2244\n __netlink_dump_start+0x59a/0x7c0 net/netlink/af_netlink.c:2352\n netlink_dump_start include/linux/netlink.h:216 [inline]\n inet_diag_handler_cmd+0x2ce/0x3f0 net/ipv4/inet_diag.c:1170\n __sock_diag_cmd net/core/sock_diag.c:232 [inline]\n sock_diag_rcv_msg+0x31d/0x410 net/core/sock_diag.c:263\n netlink_rcv_skb+0x172/0x440 net/netlink/af_netlink.c:2477\n sock_diag_rcv+0x2a/0x40 net/core/sock_diag.c:274\n\nThis issue occurs when asoc is peeled off and the old sk is freed after\ngetting it by asoc->base.sk and before calling lock_sock(sk).\n\nTo prevent the sk free, as a holder of the sk, ep should be alive when\ncalling lock_sock(). This patch uses call_rcu() and moves sock_put and\nep free into sctp_endpoint_destroy_rcu(), so that it's safe to try to\nhold the ep under rcu_read_lock in sctp_transport_traverse_process().\n\nIf sctp_endpoint_hold() returns true, it means this ep is still alive\nand we have held it and can continue to dump it; If it returns false,\nit means this ep is dead and can be freed after rcu_read_unlock, and\nwe should skip it.\n\nIn sctp_sock_dump(), after locking the sk, if this ep is different from\ntsp->asoc->ep, it means during this dumping, this asoc was peeled off\nbefore calling lock_sock(), and the sk should be skipped; If this ep is\nthe same with tsp->asoc->ep, it means no peeloff happens on this asoc,\nand due to lock_sock, no peeloff will happen either until release_sock.\n\nNote that delaying endpoint free won't delay the port release, as the\nport release happens in sctp_endpoint_destroy() before calling call_rcu().\nAlso, freeing endpoint by call_rcu() makes it safe to access the sk by\nasoc->base.sk in sctp_assocs_seq_show() and sctp_rcv().\n\nThanks Jones to bring this issue up.\n\nv1->v2:\n - improve the changelog.\n - add kfree(ep) into sctp_endpoint_destroy_rcu(), as Jakub noticed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T10:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-x9rp-8j88-vh76/GHSA-x9rp-8j88-vh76.json b/advisories/unreviewed/2024/02/GHSA-x9rp-8j88-vh76/GHSA-x9rp-8j88-vh76.json index 74470d084e3..9b2e403abb3 100644 --- a/advisories/unreviewed/2024/02/GHSA-x9rp-8j88-vh76/GHSA-x9rp-8j88-vh76.json +++ b/advisories/unreviewed/2024/02/GHSA-x9rp-8j88-vh76/GHSA-x9rp-8j88-vh76.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x9rp-8j88-vh76", - "modified": "2024-02-27T12:31:10Z", + "modified": "2024-04-10T18:30:47Z", "published": "2024-02-27T12:31:10Z", "aliases": [ "CVE-2021-46935" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbinder: fix async_free_space accounting for empty parcels\n\nIn 4.13, commit 74310e06be4d (\"android: binder: Move buffer out of area shared with user space\")\nfixed a kernel structure visibility issue. As part of that patch,\nsizeof(void *) was used as the buffer size for 0-length data payloads so\nthe driver could detect abusive clients sending 0-length asynchronous\ntransactions to a server by enforcing limits on async_free_size.\n\nUnfortunately, on the \"free\" side, the accounting of async_free_space\ndid not add the sizeof(void *) back. The result was that up to 8-bytes of\nasync_free_space were leaked on every async transaction of 8-bytes or\nless. These small transactions are uncommon, so this accounting issue\nhas gone undetected for several years.\n\nThe fix is to use \"buffer_size\" (the allocated buffer size) instead of\n\"size\" (the logical buffer size) when updating the async_free_space\nduring the free operation. These are the same except for this\ncorner case of asynchronous transactions with payloads < 8 bytes.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-668" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T10:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-23r4-x5xc-qw4f/GHSA-23r4-x5xc-qw4f.json b/advisories/unreviewed/2024/04/GHSA-23r4-x5xc-qw4f/GHSA-23r4-x5xc-qw4f.json new file mode 100644 index 00000000000..f8e1f45a607 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-23r4-x5xc-qw4f/GHSA-23r4-x5xc-qw4f.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23r4-x5xc-qw4f", + "modified": "2024-04-10T18:30:47Z", + "published": "2024-04-10T18:30:47Z", + "aliases": [ + "CVE-2024-23735" + ], + "details": "Cross Site Scripting (XSS) vulnerability in in the S/MIME certificate upload functionality of the User Profile pages in savignano S/Notify before 4.0.0 for Confluence allows attackers to manipulate user data via specially crafted certificate.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23735" + }, + { + "type": "WEB", + "url": "https://help.savignano.net/snotify-email-encryption/sa-2023-11-02" + }, + { + "type": "WEB", + "url": "https://help.savignano.net/snotify-email-encryption/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-24m8-r3wq-c97x/GHSA-24m8-r3wq-c97x.json b/advisories/unreviewed/2024/04/GHSA-24m8-r3wq-c97x/GHSA-24m8-r3wq-c97x.json new file mode 100644 index 00000000000..e0787fbfaa7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-24m8-r3wq-c97x/GHSA-24m8-r3wq-c97x.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24m8-r3wq-c97x", + "modified": "2024-04-10T18:30:47Z", + "published": "2024-04-10T18:30:47Z", + "aliases": [ + "CVE-2024-1600" + ], + "details": "A Local File Inclusion (LFI) vulnerability exists in the parisneo/lollms-webui application, specifically within the `/personalities` route. An attacker can exploit this vulnerability by crafting a URL that includes directory traversal sequences (`../../`) followed by the desired system file path, URL encoded. Successful exploitation allows the attacker to read any file on the filesystem accessible by the web server. This issue arises due to improper control of filename for include/require statement in the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1600" + }, + { + "type": "WEB", + "url": "https://github.com/parisneo/lollms-webui/commit/49b0332e98d42dd5204dda53dee410b160106265" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/29ec621a-bd69-4225-ab0f-5bb8a1d10c67" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-27w6-8m77-x3qf/GHSA-27w6-8m77-x3qf.json b/advisories/unreviewed/2024/04/GHSA-27w6-8m77-x3qf/GHSA-27w6-8m77-x3qf.json new file mode 100644 index 00000000000..04cf49cfb4a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-27w6-8m77-x3qf/GHSA-27w6-8m77-x3qf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-27w6-8m77-x3qf", + "modified": "2024-04-10T18:30:47Z", + "published": "2024-04-10T18:30:47Z", + "aliases": [ + "CVE-2024-31254" + ], + "details": "Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration.This issue affects WordPress Backup & Migration: from n/a through 1.4.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31254" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-migration-duplicator/wordpress-wordpress-backup-migration-plugin-1-4-7-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T16:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-2ch6-m8wh-67f2/GHSA-2ch6-m8wh-67f2.json b/advisories/unreviewed/2024/04/GHSA-2ch6-m8wh-67f2/GHSA-2ch6-m8wh-67f2.json new file mode 100644 index 00000000000..56d34ed6d98 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2ch6-m8wh-67f2/GHSA-2ch6-m8wh-67f2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2ch6-m8wh-67f2", + "modified": "2024-04-10T18:30:47Z", + "published": "2024-04-10T18:30:47Z", + "aliases": [ + "CVE-2024-31872" + ], + "details": "IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Open Source scripts due to missing certificate validation. IBM X-Force ID: 287316.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31872" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/287316" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7147932" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-599" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T16:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-35hx-x7f3-cr36/GHSA-35hx-x7f3-cr36.json b/advisories/unreviewed/2024/04/GHSA-35hx-x7f3-cr36/GHSA-35hx-x7f3-cr36.json new file mode 100644 index 00000000000..05ac6962178 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-35hx-x7f3-cr36/GHSA-35hx-x7f3-cr36.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35hx-x7f3-cr36", + "modified": "2024-04-10T18:30:47Z", + "published": "2024-04-10T18:30:47Z", + "aliases": [ + "CVE-2024-1511" + ], + "details": "The parisneo/lollms-webui repository is susceptible to a path traversal vulnerability due to inadequate validation of user-supplied file paths. This flaw allows an unauthenticated attacker to read, write, and in certain configurations execute arbitrary files on the server by exploiting various endpoints. The vulnerability can be exploited even when the service is bound to localhost, through cross-site requests facilitated by malicious HTML/JS pages.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1511" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/62b77589-772d-4d6e-aef4-2aec4cfe5f8b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-35m6-rf3v-8cxx/GHSA-35m6-rf3v-8cxx.json b/advisories/unreviewed/2024/04/GHSA-35m6-rf3v-8cxx/GHSA-35m6-rf3v-8cxx.json new file mode 100644 index 00000000000..c1013bd99b3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-35m6-rf3v-8cxx/GHSA-35m6-rf3v-8cxx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35m6-rf3v-8cxx", + "modified": "2024-04-10T18:30:47Z", + "published": "2024-04-10T18:30:47Z", + "aliases": [ + "CVE-2024-0218" + ], + "details": "A Denial of Service (Dos) vulnerability in Nozomi Networks Guardian, caused by improper input validation in certain fields used in the Radius parsing functionality of our IDS, allows an unauthenticated attacker sending specially crafted malformed network packets to cause the IDS module to stop updating nodes, links, and assets.\n\nNetwork traffic may not be analyzed until the IDS module is restarted.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0218" + }, + { + "type": "WEB", + "url": "https://security.nozominetworks.com/NN-2024:1-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-37q5-v5qm-c9v8/GHSA-37q5-v5qm-c9v8.json b/advisories/unreviewed/2024/04/GHSA-37q5-v5qm-c9v8/GHSA-37q5-v5qm-c9v8.json new file mode 100644 index 00000000000..ab13990257a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-37q5-v5qm-c9v8/GHSA-37q5-v5qm-c9v8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37q5-v5qm-c9v8", + "modified": "2024-04-10T18:30:48Z", + "published": "2024-04-10T18:30:48Z", + "aliases": [ + "CVE-2024-3568" + ], + "details": "The huggingface/transformers library is vulnerable to arbitrary code execution through deserialization of untrusted data within the `load_repo_checkpoint()` function of the `TFPreTrainedModel()` class. Attackers can execute arbitrary code and commands by crafting a malicious serialized payload, exploiting the use of `pickle.load()` on data from potentially untrusted sources. This vulnerability allows for remote code execution (RCE) by deceiving victims into loading a seemingly harmless checkpoint during a normal training process, thereby enabling attackers to execute arbitrary code on the targeted machine.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3568" + }, + { + "type": "WEB", + "url": "https://github.com/huggingface/transformers/commit/693667b8ac8138b83f8adb6522ddaf42fa07c125" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/b3c36992-5264-4d7f-9906-a996efafba8f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3f95-mxq2-2f63/GHSA-3f95-mxq2-2f63.json b/advisories/unreviewed/2024/04/GHSA-3f95-mxq2-2f63/GHSA-3f95-mxq2-2f63.json new file mode 100644 index 00000000000..60c50ff0f04 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3f95-mxq2-2f63/GHSA-3f95-mxq2-2f63.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3f95-mxq2-2f63", + "modified": "2024-04-10T18:30:48Z", + "published": "2024-04-10T18:30:48Z", + "aliases": [ + "CVE-2024-1728" + ], + "details": "gradio-app/gradio is vulnerable to a local file inclusion vulnerability due to improper validation of user-supplied input in the UploadButton component. Attackers can exploit this vulnerability to read arbitrary files on the filesystem, such as private SSH keys, by manipulating the file path in the request to the `/queue/join` endpoint. This issue could potentially lead to remote code execution. The vulnerability is present in the handling of file upload paths, allowing attackers to redirect file uploads to unintended locations on the server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1728" + }, + { + "type": "WEB", + "url": "https://github.com/gradio-app/gradio/commit/16fbe9cd0cffa9f2a824a0165beb43446114eec7" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/9bb33b71-7995-425d-91cc-2c2a2f2a068a" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3fmq-xqpg-7wmg/GHSA-3fmq-xqpg-7wmg.json b/advisories/unreviewed/2024/04/GHSA-3fmq-xqpg-7wmg/GHSA-3fmq-xqpg-7wmg.json new file mode 100644 index 00000000000..6c896e6c01e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3fmq-xqpg-7wmg/GHSA-3fmq-xqpg-7wmg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3fmq-xqpg-7wmg", + "modified": "2024-04-10T18:30:48Z", + "published": "2024-04-10T18:30:48Z", + "aliases": [ + "CVE-2024-31356" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solwin Infotech User Activity Log.This issue affects User Activity Log: from n/a through 1.8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31356" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/user-activity-log/wordpress-user-activity-log-plugin-1-8-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3jvg-6v8m-chpp/GHSA-3jvg-6v8m-chpp.json b/advisories/unreviewed/2024/04/GHSA-3jvg-6v8m-chpp/GHSA-3jvg-6v8m-chpp.json new file mode 100644 index 00000000000..d1ed6fcce05 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3jvg-6v8m-chpp/GHSA-3jvg-6v8m-chpp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jvg-6v8m-chpp", + "modified": "2024-04-10T18:30:47Z", + "published": "2024-04-10T18:30:47Z", + "aliases": [ + "CVE-2024-31358" + ], + "details": "Missing Authorization vulnerability in Saleswonder.Biz 5 Stars Rating Funnel.This issue affects 5 Stars Rating Funnel: from n/a through 1.2.67.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31358" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/5-stars-rating-funnel/wordpress-5-stars-rating-funnel-plugin-1-2-67-arbitrary-content-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T16:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3qj4-9cvg-gv2q/GHSA-3qj4-9cvg-gv2q.json b/advisories/unreviewed/2024/04/GHSA-3qj4-9cvg-gv2q/GHSA-3qj4-9cvg-gv2q.json new file mode 100644 index 00000000000..2b1345b4f0f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3qj4-9cvg-gv2q/GHSA-3qj4-9cvg-gv2q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qj4-9cvg-gv2q", + "modified": "2024-04-10T18:30:48Z", + "published": "2024-04-10T18:30:48Z", + "aliases": [ + "CVE-2024-31230" + ], + "details": "Missing Authorization vulnerability in ShortPixel ShortPixel Adaptive Images.This issue affects ShortPixel Adaptive Images: from n/a through 3.8.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31230" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/shortpixel-adaptive-images/wordpress-shortpixel-adaptive-images-plugin-3-8-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-42cr-cm2x-xxxj/GHSA-42cr-cm2x-xxxj.json b/advisories/unreviewed/2024/04/GHSA-42cr-cm2x-xxxj/GHSA-42cr-cm2x-xxxj.json new file mode 100644 index 00000000000..cd5639ca948 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-42cr-cm2x-xxxj/GHSA-42cr-cm2x-xxxj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42cr-cm2x-xxxj", + "modified": "2024-04-10T18:30:47Z", + "published": "2024-04-10T18:30:47Z", + "aliases": [ + "CVE-2024-1599" + ], + "details": "lunary-ai/lunary version 0.3.0 is vulnerable to unauthorized project creation due to insufficient server-side validation of user account types during project creation. In the free account tier, users are limited to creating only two projects. However, this restriction is enforced only in the web UI and not on the server side, allowing users to bypass the limitation and create an unlimited number of projects without upgrading their account or incurring additional charges. This vulnerability is due to the lack of checks in the project creation endpoint.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1599" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/48d66a3deef8788fda7621e88f0e3a8a4a1ddeb9" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/f1f9e9d6-de5f-48c4-b4f4-fbd192370417" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-46cm-pfwv-cgf8/GHSA-46cm-pfwv-cgf8.json b/advisories/unreviewed/2024/04/GHSA-46cm-pfwv-cgf8/GHSA-46cm-pfwv-cgf8.json new file mode 100644 index 00000000000..7fd1863040c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-46cm-pfwv-cgf8/GHSA-46cm-pfwv-cgf8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46cm-pfwv-cgf8", + "modified": "2024-04-10T18:30:48Z", + "published": "2024-04-10T18:30:48Z", + "aliases": [ + "CVE-2024-2952" + ], + "details": "BerriAI/litellm is vulnerable to Server-Side Template Injection (SSTI) via the `/completions` endpoint. The vulnerability arises from the `hf_chat_template` method processing the `chat_template` parameter from the `tokenizer_config.json` file through the Jinja template engine without proper sanitization. Attackers can exploit this by crafting malicious `tokenizer_config.json` files that execute arbitrary code on the server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2952" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/a9e0a164-6de0-43a4-a640-0cbfb54220a4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-76" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-52w9-whm3-f76c/GHSA-52w9-whm3-f76c.json b/advisories/unreviewed/2024/04/GHSA-52w9-whm3-f76c/GHSA-52w9-whm3-f76c.json new file mode 100644 index 00000000000..d7f8453ca5b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-52w9-whm3-f76c/GHSA-52w9-whm3-f76c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52w9-whm3-f76c", + "modified": "2024-04-10T18:30:48Z", + "published": "2024-04-10T18:30:48Z", + "aliases": [ + "CVE-2024-31343" + ], + "details": "Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 4.10.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31343" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mp3-music-player-by-sonaar/wordpress-mp3-audio-player-for-music-radio-podcast-by-sonaar-plugin-4-10-1-arbitrary-file-download-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-55c4-h3q7-f6wp/GHSA-55c4-h3q7-f6wp.json b/advisories/unreviewed/2024/04/GHSA-55c4-h3q7-f6wp/GHSA-55c4-h3q7-f6wp.json new file mode 100644 index 00000000000..b52fcd5ef7c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-55c4-h3q7-f6wp/GHSA-55c4-h3q7-f6wp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55c4-h3q7-f6wp", + "modified": "2024-04-10T18:30:48Z", + "published": "2024-04-10T18:30:48Z", + "aliases": [ + "CVE-2024-3382" + ], + "details": "A memory leak exists in Palo Alto Networks PAN-OS software that enables an attacker to send a burst of crafted packets through the firewall that eventually prevents the firewall from processing traffic. This issue applies only to PA-5400 Series devices that are running PAN-OS software with the SSL Forward Proxy feature enabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3382" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-3382" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5j77-g9r7-hpx3/GHSA-5j77-g9r7-hpx3.json b/advisories/unreviewed/2024/04/GHSA-5j77-g9r7-hpx3/GHSA-5j77-g9r7-hpx3.json new file mode 100644 index 00000000000..98ae28e6880 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5j77-g9r7-hpx3/GHSA-5j77-g9r7-hpx3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5j77-g9r7-hpx3", + "modified": "2024-04-10T18:30:48Z", + "published": "2024-04-10T18:30:48Z", + "aliases": [ + "CVE-2024-2217" + ], + "details": "gaizhenbiao/chuanhuchatgpt is vulnerable to improper access control, allowing unauthorized access to the `config.json` file. This vulnerability is present in both authenticated and unauthenticated versions of the application, enabling attackers to obtain sensitive information such as API keys (`openai_api_key`, `google_palm_api_key`, `xmchat_api_key`, etc.), configuration details, and user credentials. The issue stems from the application's handling of HTTP requests for the `config.json` file, which does not properly restrict access based on user authentication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2217" + }, + { + "type": "WEB", + "url": "https://github.com/gaizhenbiao/chuanhuchatgpt/commit/c5ae3b5ae6b47259e0ce8730e0a47e85121f4a7d" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/e4df74bf-b2ee-490f-a9c9-e5c8010b8b29" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-68qv-4jc5-hr7h/GHSA-68qv-4jc5-hr7h.json b/advisories/unreviewed/2024/04/GHSA-68qv-4jc5-hr7h/GHSA-68qv-4jc5-hr7h.json new file mode 100644 index 00000000000..79b72e68cea --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-68qv-4jc5-hr7h/GHSA-68qv-4jc5-hr7h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68qv-4jc5-hr7h", + "modified": "2024-04-10T18:30:47Z", + "published": "2024-04-10T18:30:47Z", + "aliases": [ + "CVE-2024-31353" + ], + "details": "Insertion of Sensitive Information into Log File vulnerability in Tribulant Slideshow Gallery.This issue affects Slideshow Gallery: from n/a through 1.7.8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31353" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/slideshow-gallery/wordpress-slideshow-gallery-lite-plugin-1-7-8-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T16:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6cq5-38vf-h3g2/GHSA-6cq5-38vf-h3g2.json b/advisories/unreviewed/2024/04/GHSA-6cq5-38vf-h3g2/GHSA-6cq5-38vf-h3g2.json new file mode 100644 index 00000000000..1a3a98b72b0 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6cq5-38vf-h3g2/GHSA-6cq5-38vf-h3g2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cq5-38vf-h3g2", + "modified": "2024-04-10T18:30:47Z", + "published": "2024-04-10T18:30:47Z", + "aliases": [ + "CVE-2024-23734" + ], + "details": "Cross Site Request Forgery vulnerability in in the upload functionality of the User Profile pages in savignano S/Notify before 2.0.1 for Bitbucket allow attackers to replace S/MIME certificate or PGP keys for arbitrary users via crafted link.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23734" + }, + { + "type": "WEB", + "url": "https://help.savignano.net/snotify-email-encryption/sa-2023-11-28" + }, + { + "type": "WEB", + "url": "https://help.savignano.net/snotify-email-encryption/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7v8g-rfp5-x3hm/GHSA-7v8g-rfp5-x3hm.json b/advisories/unreviewed/2024/04/GHSA-7v8g-rfp5-x3hm/GHSA-7v8g-rfp5-x3hm.json new file mode 100644 index 00000000000..0141e2c55ff --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7v8g-rfp5-x3hm/GHSA-7v8g-rfp5-x3hm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7v8g-rfp5-x3hm", + "modified": "2024-04-10T18:30:49Z", + "published": "2024-04-10T18:30:49Z", + "aliases": [ + "CVE-2024-31943" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Octolize USPS Shipping for WooCommerce – Live Rates.This issue affects USPS Shipping for WooCommerce – Live Rates: from n/a through 1.9.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31943" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/flexible-shipping-usps/wordpress-usps-shipping-for-woocommerce-plugin-1-9-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-882m-54cg-63q7/GHSA-882m-54cg-63q7.json b/advisories/unreviewed/2024/04/GHSA-882m-54cg-63q7/GHSA-882m-54cg-63q7.json new file mode 100644 index 00000000000..f90627a1b0a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-882m-54cg-63q7/GHSA-882m-54cg-63q7.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-882m-54cg-63q7", + "modified": "2024-04-10T18:30:48Z", + "published": "2024-04-10T18:30:48Z", + "aliases": [ + "CVE-2024-1625" + ], + "details": "An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary application version 0.3.0, allowing unauthorized deletion of any organization's project. The vulnerability is due to insufficient authorization checks in the project deletion endpoint, where the endpoint fails to verify if the project ID provided in the request belongs to the requesting user's organization. As a result, an attacker can delete projects belonging to any organization by sending a crafted DELETE request with the target project's ID. This issue affects the project deletion functionality implemented in the projects.delete route.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1625" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/88f98e29f19da9d1f5de45c5b163fd5b48e0bcec" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/cf6dd625-e6c9-44df-a072-13686816de21" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8wv4-58g4-2v58/GHSA-8wv4-58g4-2v58.json b/advisories/unreviewed/2024/04/GHSA-8wv4-58g4-2v58/GHSA-8wv4-58g4-2v58.json new file mode 100644 index 00000000000..6a28a515c84 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8wv4-58g4-2v58/GHSA-8wv4-58g4-2v58.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wv4-58g4-2v58", + "modified": "2024-04-10T18:30:47Z", + "published": "2024-04-10T18:30:47Z", + "aliases": [ + "CVE-2024-1520" + ], + "details": "An OS Command Injection vulnerability exists in the '/open_code_folder' endpoint of the parisneo/lollms-webui application, due to improper validation of user-supplied input in the 'discussion_id' parameter. Attackers can exploit this vulnerability by injecting malicious OS commands, leading to unauthorized command execution on the underlying operating system. This could result in unauthorized access, data leakage, or complete system compromise.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1520" + }, + { + "type": "WEB", + "url": "https://github.com/parisneo/lollms-webui/commit/2497d1a4fe5a09f003bf7a9bc426139e9295a934" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/405c2059-3fe9-4233-8eed-741ec847d181" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8x2m-vwxp-r65j/GHSA-8x2m-vwxp-r65j.json b/advisories/unreviewed/2024/04/GHSA-8x2m-vwxp-r65j/GHSA-8x2m-vwxp-r65j.json new file mode 100644 index 00000000000..1323dad6b6d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8x2m-vwxp-r65j/GHSA-8x2m-vwxp-r65j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8x2m-vwxp-r65j", + "modified": "2024-04-10T18:30:48Z", + "published": "2024-04-10T18:30:48Z", + "aliases": [ + "CVE-2024-3385" + ], + "details": "A packet processing mechanism in Palo Alto Networks PAN-OS software enables a remote attacker to reboot hardware-based firewalls. Repeated attacks eventually cause the firewall to enter maintenance mode, which requires manual intervention to bring the firewall back online.\n\nThis affects the following hardware firewall models:\n- PA-5400 Series firewalls\n- PA-7000 Series firewalls", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3385" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-3385" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-99w2-67h8-5948/GHSA-99w2-67h8-5948.json b/advisories/unreviewed/2024/04/GHSA-99w2-67h8-5948/GHSA-99w2-67h8-5948.json new file mode 100644 index 00000000000..3d92aeef9cd --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-99w2-67h8-5948/GHSA-99w2-67h8-5948.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99w2-67h8-5948", + "modified": "2024-04-10T18:30:48Z", + "published": "2024-04-10T18:30:48Z", + "aliases": [ + "CVE-2024-2196" + ], + "details": "aimhubio/aim is vulnerable to Cross-Site Request Forgery (CSRF), allowing attackers to perform actions such as deleting runs, updating data, and stealing data like log records and notes without the user's consent. The vulnerability stems from the lack of CSRF and CORS protection in the aim dashboard. An attacker can exploit this by tricking a user into executing a malicious script that sends unauthorized requests to the aim server, leading to potential data loss and unauthorized data manipulation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2196" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/e141e3f2-afbb-405f-a891-f66628c8b68f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-9xch-xvj3-fmf3/GHSA-9xch-xvj3-fmf3.json b/advisories/unreviewed/2024/04/GHSA-9xch-xvj3-fmf3/GHSA-9xch-xvj3-fmf3.json new file mode 100644 index 00000000000..96e81afb765 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-9xch-xvj3-fmf3/GHSA-9xch-xvj3-fmf3.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xch-xvj3-fmf3", + "modified": "2024-04-10T18:30:47Z", + "published": "2024-04-10T18:30:47Z", + "aliases": [ + "CVE-2024-3566" + ], + "details": "A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3566" + }, + { + "type": "WEB", + "url": "https://flatt.tech/research/posts/batbadbut-you-cant-securely-execute-commands-on-windows" + }, + { + "type": "WEB", + "url": "https://kb.cert.org/vuls/id/123335" + }, + { + "type": "WEB", + "url": "https://learn.microsoft.com/en-us/archive/blogs/twistylittlepassagesallalike/everyone-quotes-command-line-arguments-the-wrong-way" + }, + { + "type": "WEB", + "url": "https://www.cve.org/CVERecord?id=CVE-2024-1874" + }, + { + "type": "WEB", + "url": "https://www.cve.org/CVERecord?id=CVE-2024-22423" + }, + { + "type": "WEB", + "url": "https://www.cve.org/CVERecord?id=CVE-2024-24576" + }, + { + "type": "WEB", + "url": "https://www.kb.cert.org/vuls/id/123335" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T16:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cffw-pr5g-439r/GHSA-cffw-pr5g-439r.json b/advisories/unreviewed/2024/04/GHSA-cffw-pr5g-439r/GHSA-cffw-pr5g-439r.json new file mode 100644 index 00000000000..74bc026b7d9 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cffw-pr5g-439r/GHSA-cffw-pr5g-439r.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cffw-pr5g-439r", + "modified": "2024-04-10T18:30:48Z", + "published": "2024-04-10T18:30:48Z", + "aliases": [ + "CVE-2024-3283" + ], + "details": "A vulnerability in mintplex-labs/anything-llm allows users with manager roles to escalate their privileges to admin roles through a mass assignment issue. The '/admin/system-preferences' API endpoint improperly authorizes manager-level users to modify the 'multi_user_mode' system variable, enabling them to access the '/api/system/enable-multi-user' endpoint and create a new admin user. This issue results from the endpoint accepting a full JSON object in the request body without proper validation of modifiable fields, leading to unauthorized modification of system settings and subsequent privilege escalation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3283" + }, + { + "type": "WEB", + "url": "https://github.com/mintplex-labs/anything-llm/commit/52fac844221a9b951d08ceb93c4c014e9397b1f2" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/a8000cce-0ecb-4820-9cfb-57ba6f4d58a2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-915" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-chwx-r397-6ww4/GHSA-chwx-r397-6ww4.json b/advisories/unreviewed/2024/04/GHSA-chwx-r397-6ww4/GHSA-chwx-r397-6ww4.json new file mode 100644 index 00000000000..8ff3600f8dc --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-chwx-r397-6ww4/GHSA-chwx-r397-6ww4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chwx-r397-6ww4", + "modified": "2024-04-10T18:30:47Z", + "published": "2024-04-10T18:30:47Z", + "aliases": [ + "CVE-2024-31245" + ], + "details": "Insertion of Sensitive Information into Log File vulnerability in ConvertKit.This issue affects ConvertKit: from n/a through 2.4.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31245" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/convertkit/wordpress-convertkit-plugin-2-4-5-email-disclosure-in-log-file-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T16:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cqgx-qm2w-88qc/GHSA-cqgx-qm2w-88qc.json b/advisories/unreviewed/2024/04/GHSA-cqgx-qm2w-88qc/GHSA-cqgx-qm2w-88qc.json new file mode 100644 index 00000000000..b6e26b06cf3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cqgx-qm2w-88qc/GHSA-cqgx-qm2w-88qc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqgx-qm2w-88qc", + "modified": "2024-04-10T18:30:47Z", + "published": "2024-04-10T18:30:47Z", + "aliases": [ + "CVE-2024-31240" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in InfoTheme WP Poll Maker.This issue affects WP Poll Maker: from n/a through 3.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31240" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/epoll-wp-voting/wordpress-wp-poll-maker-plugin-3-1-subscriber-arbitrary-file-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T16:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cqvp-qf4w-3mpx/GHSA-cqvp-qf4w-3mpx.json b/advisories/unreviewed/2024/04/GHSA-cqvp-qf4w-3mpx/GHSA-cqvp-qf4w-3mpx.json new file mode 100644 index 00000000000..24e405c350b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cqvp-qf4w-3mpx/GHSA-cqvp-qf4w-3mpx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqvp-qf4w-3mpx", + "modified": "2024-04-10T18:30:47Z", + "published": "2024-04-10T18:30:47Z", + "aliases": [ + "CVE-2024-31297" + ], + "details": "Missing Authorization vulnerability in WPExperts Wholesale For WooCommerce.This issue affects Wholesale For WooCommerce: from n/a through 2.3.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31297" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woocommerce-wholesale-pricing/wordpress-wholesale-for-woocommerce-plugin-2-3-1-unauthenticated-arbitrary-post-page-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T16:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-crgc-qfch-jgr7/GHSA-crgc-qfch-jgr7.json b/advisories/unreviewed/2024/04/GHSA-crgc-qfch-jgr7/GHSA-crgc-qfch-jgr7.json new file mode 100644 index 00000000000..5bf03382fd1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-crgc-qfch-jgr7/GHSA-crgc-qfch-jgr7.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crgc-qfch-jgr7", + "modified": "2024-04-10T18:30:48Z", + "published": "2024-04-10T18:30:48Z", + "aliases": [ + "CVE-2024-1740" + ], + "details": "In lunary-ai/lunary version 1.0.1, a vulnerability exists where a user removed from an organization can still read, create, modify, and delete logs by re-using an old authorization token. The lunary web application communicates with the server using an 'Authorization' token in the browser, which does not properly invalidate upon the user's removal from the organization. This allows the removed user to perform unauthorized actions on logs and access project and external user details without valid permissions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1740" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/c57cd50fa0477fd2a2efe60810c0099eebd66f54" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/c1a51f71-628e-4eb5-ac35-50bf64832cfd" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-f525-qqcm-4ww9/GHSA-f525-qqcm-4ww9.json b/advisories/unreviewed/2024/04/GHSA-f525-qqcm-4ww9/GHSA-f525-qqcm-4ww9.json new file mode 100644 index 00000000000..a5d42e53640 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-f525-qqcm-4ww9/GHSA-f525-qqcm-4ww9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f525-qqcm-4ww9", + "modified": "2024-04-10T18:30:47Z", + "published": "2024-04-10T18:30:47Z", + "aliases": [ + "CVE-2024-31249" + ], + "details": "Insertion of Sensitive Information into Log File vulnerability in WPKube Subscribe To Comments Reloaded.This issue affects Subscribe To Comments Reloaded: from n/a through 220725.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31249" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/subscribe-to-comments-reloaded/wordpress-subscribe-to-comments-reloaded-plugin-220725-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T16:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-f7cx-hq8m-95w6/GHSA-f7cx-hq8m-95w6.json b/advisories/unreviewed/2024/04/GHSA-f7cx-hq8m-95w6/GHSA-f7cx-hq8m-95w6.json new file mode 100644 index 00000000000..2db16fea96b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-f7cx-hq8m-95w6/GHSA-f7cx-hq8m-95w6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f7cx-hq8m-95w6", + "modified": "2024-04-10T18:30:48Z", + "published": "2024-04-10T18:30:48Z", + "aliases": [ + "CVE-2024-3101" + ], + "details": "In mintplex-labs/anything-llm, an improper input validation vulnerability allows attackers to escalate privileges by deactivating 'Multi-User Mode'. By sending a specially crafted curl request with the 'multi_user_mode' parameter set to false, an attacker can deactivate 'Multi-User Mode'. This action permits the creation of a new admin user without requiring a password, leading to unauthorized administrative access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3101" + }, + { + "type": "WEB", + "url": "https://github.com/mintplex-labs/anything-llm/commit/52fac844221a9b951d08ceb93c4c014e9397b1f2" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/c114c03e-3348-450f-88f7-538502047bcc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-f874-8386-mf62/GHSA-f874-8386-mf62.json b/advisories/unreviewed/2024/04/GHSA-f874-8386-mf62/GHSA-f874-8386-mf62.json new file mode 100644 index 00000000000..3a2c211aac3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-f874-8386-mf62/GHSA-f874-8386-mf62.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f874-8386-mf62", + "modified": "2024-04-10T18:30:47Z", + "published": "2024-04-10T18:30:47Z", + "aliases": [ + "CVE-2023-6916" + ], + "details": "Audit records for OpenAPI requests may include sensitive information.\n\nThis could lead to unauthorized accesses and privilege escalation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6916" + }, + { + "type": "WEB", + "url": "https://security.nozominetworks.com/NN-2023:17-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gqmf-gxrq-3j6q/GHSA-gqmf-gxrq-3j6q.json b/advisories/unreviewed/2024/04/GHSA-gqmf-gxrq-3j6q/GHSA-gqmf-gxrq-3j6q.json new file mode 100644 index 00000000000..aff3c72b15a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gqmf-gxrq-3j6q/GHSA-gqmf-gxrq-3j6q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqmf-gxrq-3j6q", + "modified": "2024-04-10T18:30:49Z", + "published": "2024-04-10T18:30:49Z", + "aliases": [ + "CVE-2024-31944" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Octolize WooCommerce UPS Shipping – Live Rates and Access Points.This issue affects WooCommerce UPS Shipping – Live Rates and Access Points: from n/a through 2.2.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31944" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/flexible-shipping-ups/wordpress-woocommerce-ups-shipping-plugin-2-2-4-cross-site-request-forgery-csrf-leading-to-notice-dismissal-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gv6g-p8pg-jx2h/GHSA-gv6g-p8pg-jx2h.json b/advisories/unreviewed/2024/04/GHSA-gv6g-p8pg-jx2h/GHSA-gv6g-p8pg-jx2h.json new file mode 100644 index 00000000000..22ac85c4c2c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gv6g-p8pg-jx2h/GHSA-gv6g-p8pg-jx2h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gv6g-p8pg-jx2h", + "modified": "2024-04-10T18:30:47Z", + "published": "2024-04-10T18:30:47Z", + "aliases": [ + "CVE-2024-31247" + ], + "details": "Insertion of Sensitive Information into Log File vulnerability in Frédéric GILLES FG Drupal to WordPress.This issue affects FG Drupal to WordPress: from n/a through 3.70.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31247" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/fg-drupal-to-wp/wordpress-fg-drupal-to-wordpress-plugin-3-70-3-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T16:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-h9h2-jmvv-fr8c/GHSA-h9h2-jmvv-fr8c.json b/advisories/unreviewed/2024/04/GHSA-h9h2-jmvv-fr8c/GHSA-h9h2-jmvv-fr8c.json new file mode 100644 index 00000000000..4c4aa49c778 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-h9h2-jmvv-fr8c/GHSA-h9h2-jmvv-fr8c.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9h2-jmvv-fr8c", + "modified": "2024-04-10T18:30:47Z", + "published": "2024-04-10T18:30:47Z", + "aliases": [ + "CVE-2024-31871" + ], + "details": "IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Python scripts due to improper certificate validation. IBM X-Force ID: 287306.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31871" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/287306" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7147932" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T16:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-h9w4-3hv9-j8r3/GHSA-h9w4-3hv9-j8r3.json b/advisories/unreviewed/2024/04/GHSA-h9w4-3hv9-j8r3/GHSA-h9w4-3hv9-j8r3.json new file mode 100644 index 00000000000..c2be9e6fcda --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-h9w4-3hv9-j8r3/GHSA-h9w4-3hv9-j8r3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9w4-3hv9-j8r3", + "modified": "2024-04-10T18:30:49Z", + "published": "2024-04-10T18:30:49Z", + "aliases": [ + "CVE-2024-3569" + ], + "details": "A Denial of Service (DoS) vulnerability exists in the mintplex-labs/anything-llm repository when the application is running in 'just me' mode with a password. An attacker can exploit this vulnerability by making a request to the endpoint using the [validatedRequest] middleware with a specially crafted 'Authorization:' header. This vulnerability leads to uncontrolled resource consumption, causing a DoS condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3569" + }, + { + "type": "WEB", + "url": "https://github.com/mintplex-labs/anything-llm/commit/efe9dfa5e3550d12abd34d06ab7f8fbcf2206cfa" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/619e13bd-b723-4727-9ccb-5099d698432e" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hcgv-gpgg-9mmm/GHSA-hcgv-gpgg-9mmm.json b/advisories/unreviewed/2024/04/GHSA-hcgv-gpgg-9mmm/GHSA-hcgv-gpgg-9mmm.json new file mode 100644 index 00000000000..9752877630f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hcgv-gpgg-9mmm/GHSA-hcgv-gpgg-9mmm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hcgv-gpgg-9mmm", + "modified": "2024-04-10T18:30:48Z", + "published": "2024-04-10T18:30:48Z", + "aliases": [ + "CVE-2024-3387" + ], + "details": "A weak (low bit strength) device certificate in Palo Alto Networks Panorama software enables an attacker to perform a meddler-in-the-middle (MitM) attack to capture encrypted traffic between the Panorama management server and the firewalls it manages. With sufficient computing resources, the attacker could break encrypted communication and expose sensitive information that is shared between the management server and the firewalls.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3387" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-3387" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-326" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hm95-xqg2-4w57/GHSA-hm95-xqg2-4w57.json b/advisories/unreviewed/2024/04/GHSA-hm95-xqg2-4w57/GHSA-hm95-xqg2-4w57.json new file mode 100644 index 00000000000..0002cd4a438 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hm95-xqg2-4w57/GHSA-hm95-xqg2-4w57.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hm95-xqg2-4w57", + "modified": "2024-04-10T18:30:48Z", + "published": "2024-04-10T18:30:48Z", + "aliases": [ + "CVE-2024-2221" + ], + "details": "qdrant/qdrant is vulnerable to a path traversal and arbitrary file upload vulnerability via the `/collections/{COLLECTION}/snapshots/upload` endpoint, specifically through the `snapshot` parameter. This vulnerability allows attackers to upload and overwrite any file on the filesystem, leading to potential remote code execution. This issue affects the integrity and availability of the system, enabling unauthorized access and potentially causing the server to malfunction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2221" + }, + { + "type": "WEB", + "url": "https://github.com/qdrant/qdrant/commit/e6411907f0ecf3c2f8ba44ab704b9e4597d9705d" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/6be8d4e3-67e6-4660-a8db-04215a1cff3e" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hp3w-grg4-233f/GHSA-hp3w-grg4-233f.json b/advisories/unreviewed/2024/04/GHSA-hp3w-grg4-233f/GHSA-hp3w-grg4-233f.json new file mode 100644 index 00000000000..dffff6a9f3c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hp3w-grg4-233f/GHSA-hp3w-grg4-233f.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp3w-grg4-233f", + "modified": "2024-04-10T18:30:48Z", + "published": "2024-04-10T18:30:48Z", + "aliases": [ + "CVE-2024-3025" + ], + "details": "mintplex-labs/anything-llm is vulnerable to path traversal attacks due to insufficient validation of user-supplied input in the logo filename functionality. Attackers can exploit this vulnerability by manipulating the logo filename to reference files outside of the restricted directory. This can lead to unauthorized reading or deletion of files by utilizing the `/api/system/upload-logo` and `/api/system/logo` endpoints. The issue stems from the lack of filtering or validation on the logo filename, allowing attackers to target sensitive files such as the application's database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3025" + }, + { + "type": "WEB", + "url": "https://github.com/mintplex-labs/anything-llm/commit/7de23dbb2da932fbfb39f56d981784d3702cf5ce" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/fb09a352-1016-4481-ae88-7460e2b6062b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hwc4-2rmw-hcvq/GHSA-hwc4-2rmw-hcvq.json b/advisories/unreviewed/2024/04/GHSA-hwc4-2rmw-hcvq/GHSA-hwc4-2rmw-hcvq.json new file mode 100644 index 00000000000..ed1b6f955de --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hwc4-2rmw-hcvq/GHSA-hwc4-2rmw-hcvq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwc4-2rmw-hcvq", + "modified": "2024-04-10T18:30:48Z", + "published": "2024-04-10T18:30:48Z", + "aliases": [ + "CVE-2024-3384" + ], + "details": "A vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to reboot PAN-OS firewalls when receiving Windows New Technology LAN Manager (NTLM) packets from Windows servers. Repeated attacks eventually cause the firewall to enter maintenance mode, which requires manual intervention to bring the firewall back online.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3384" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-3384" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1286" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jmw2-399f-6mwg/GHSA-jmw2-399f-6mwg.json b/advisories/unreviewed/2024/04/GHSA-jmw2-399f-6mwg/GHSA-jmw2-399f-6mwg.json new file mode 100644 index 00000000000..b3eb22b0b2d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jmw2-399f-6mwg/GHSA-jmw2-399f-6mwg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jmw2-399f-6mwg", + "modified": "2024-04-10T18:30:47Z", + "published": "2024-04-10T18:30:47Z", + "aliases": [ + "CVE-2024-1602" + ], + "details": "parisneo/lollms-webui is vulnerable to stored Cross-Site Scripting (XSS) that leads to Remote Code Execution (RCE). The vulnerability arises due to inadequate sanitization and validation of model output data, allowing an attacker to inject malicious JavaScript code. This code can be executed within the user's browser context, enabling the attacker to send a request to the `/execute_code` endpoint and establish a reverse shell to the attacker's host. The issue affects various components of the application, including the handling of user input and model output.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1602" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/59be0d5a-f18e-4418-8f29-72320269a097" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-m9h7-m3c9-xxfm/GHSA-m9h7-m3c9-xxfm.json b/advisories/unreviewed/2024/04/GHSA-m9h7-m3c9-xxfm/GHSA-m9h7-m3c9-xxfm.json new file mode 100644 index 00000000000..353e83e18ca --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-m9h7-m3c9-xxfm/GHSA-m9h7-m3c9-xxfm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9h7-m3c9-xxfm", + "modified": "2024-04-10T18:30:48Z", + "published": "2024-04-10T18:30:48Z", + "aliases": [ + "CVE-2024-31342" + ], + "details": "Missing Authorization vulnerability in WPcloudgallery WordPress Gallery Exporter.This issue affects WordPress Gallery Exporter: from n/a through 1.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31342" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-gallery-exporter/wordpress-gallery-exporter-plugin-1-3-arbitrary-file-download-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mxvw-cj37-8g2h/GHSA-mxvw-cj37-8g2h.json b/advisories/unreviewed/2024/04/GHSA-mxvw-cj37-8g2h/GHSA-mxvw-cj37-8g2h.json new file mode 100644 index 00000000000..77ea109e490 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mxvw-cj37-8g2h/GHSA-mxvw-cj37-8g2h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxvw-cj37-8g2h", + "modified": "2024-04-10T18:30:48Z", + "published": "2024-04-10T18:30:48Z", + "aliases": [ + "CVE-2024-2195" + ], + "details": "A critical Remote Code Execution (RCE) vulnerability was identified in the aimhubio/aim project, specifically within the `/api/runs/search/run/` endpoint, affecting versions >= 3.0.0. The vulnerability resides in the `run_search_api` function of the `aim/web/api/runs/views.py` file, where improper restriction of user access to the `RunView` object allows for the execution of arbitrary code via the `query` parameter. This issue enables attackers to execute arbitrary commands on the server, potentially leading to full system compromise.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2195" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/22f2355e-b875-4c01-b454-327e5951c018" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-p52c-jr7p-8c89/GHSA-p52c-jr7p-8c89.json b/advisories/unreviewed/2024/04/GHSA-p52c-jr7p-8c89/GHSA-p52c-jr7p-8c89.json new file mode 100644 index 00000000000..c9d87946316 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-p52c-jr7p-8c89/GHSA-p52c-jr7p-8c89.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p52c-jr7p-8c89", + "modified": "2024-04-10T18:30:47Z", + "published": "2024-04-10T18:30:47Z", + "aliases": [ + "CVE-2024-31287" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Max Foundry Media Library Folders.This issue affects Media Library Folders: from n/a through 8.1.8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31287" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/media-library-plus/wordpress-media-library-folders-plugin-8-1-8-directory-traversal-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T16:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pj43-gpqr-fhm8/GHSA-pj43-gpqr-fhm8.json b/advisories/unreviewed/2024/04/GHSA-pj43-gpqr-fhm8/GHSA-pj43-gpqr-fhm8.json new file mode 100644 index 00000000000..dad0ae42821 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pj43-gpqr-fhm8/GHSA-pj43-gpqr-fhm8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pj43-gpqr-fhm8", + "modified": "2024-04-10T18:30:47Z", + "published": "2024-04-10T18:30:47Z", + "aliases": [ + "CVE-2024-31259" + ], + "details": "Insertion of Sensitive Information into Log File vulnerability in Searchiq SearchIQ.This issue affects SearchIQ: from n/a through 4.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31259" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/searchiq/wordpress-searchiq-plugin-4-5-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T16:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pm8c-xqrr-62h2/GHSA-pm8c-xqrr-62h2.json b/advisories/unreviewed/2024/04/GHSA-pm8c-xqrr-62h2/GHSA-pm8c-xqrr-62h2.json new file mode 100644 index 00000000000..4c942dfd2fb --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pm8c-xqrr-62h2/GHSA-pm8c-xqrr-62h2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pm8c-xqrr-62h2", + "modified": "2024-04-10T18:30:49Z", + "published": "2024-04-10T18:30:49Z", + "aliases": [ + "CVE-2024-31242" + ], + "details": "Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31242" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bricksforge/wordpress-bricksforge-plugin-2-0-17-unauthenticated-arbitrary-email-sending-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-prc3-79c5-8h62/GHSA-prc3-79c5-8h62.json b/advisories/unreviewed/2024/04/GHSA-prc3-79c5-8h62/GHSA-prc3-79c5-8h62.json new file mode 100644 index 00000000000..b75ccbe7771 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-prc3-79c5-8h62/GHSA-prc3-79c5-8h62.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prc3-79c5-8h62", + "modified": "2024-04-10T18:30:48Z", + "published": "2024-04-10T18:30:48Z", + "aliases": [ + "CVE-2024-1902" + ], + "details": "lunary-ai/lunary is vulnerable to a session reuse attack, allowing a removed user to change the organization name without proper authorization. The vulnerability stems from the lack of validation to check if a user is still part of an organization before allowing them to make changes. An attacker can exploit this by using an old authorization token to send a PATCH request, modifying the organization's name even after being removed from the organization. This issue is due to incorrect synchronization and affects the orgs.patch route.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1902" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/e536310e-abe7-4585-9cf6-21f77390a5e8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-821" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pw2h-m7pw-m9c6/GHSA-pw2h-m7pw-m9c6.json b/advisories/unreviewed/2024/04/GHSA-pw2h-m7pw-m9c6/GHSA-pw2h-m7pw-m9c6.json new file mode 100644 index 00000000000..ed1e57901d9 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pw2h-m7pw-m9c6/GHSA-pw2h-m7pw-m9c6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pw2h-m7pw-m9c6", + "modified": "2024-04-10T18:30:48Z", + "published": "2024-04-10T18:30:48Z", + "aliases": [ + "CVE-2024-31299" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Reservation Diary ReDi Restaurant Reservation allows Cross-Site Scripting (XSS).This issue affects ReDi Restaurant Reservation: from n/a through 24.0128.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31299" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/redi-restaurant-reservation/wordpress-redi-restaurant-reservation-plugin-24-0128-cross-site-request-forgery-csrf-to-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-q8mj-9x2v-j7w5/GHSA-q8mj-9x2v-j7w5.json b/advisories/unreviewed/2024/04/GHSA-q8mj-9x2v-j7w5/GHSA-q8mj-9x2v-j7w5.json new file mode 100644 index 00000000000..7c8ebf9e282 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-q8mj-9x2v-j7w5/GHSA-q8mj-9x2v-j7w5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8mj-9x2v-j7w5", + "modified": "2024-04-10T18:30:47Z", + "published": "2024-04-10T18:30:47Z", + "aliases": [ + "CVE-2024-31302" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in CodePeople Contact Form Email.This issue affects Contact Form Email: from n/a through 1.3.44.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31302" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/contact-form-to-email/wordpress-contact-form-email-plugin-1-3-44-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T16:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rqcq-2f32-4q3g/GHSA-rqcq-2f32-4q3g.json b/advisories/unreviewed/2024/04/GHSA-rqcq-2f32-4q3g/GHSA-rqcq-2f32-4q3g.json new file mode 100644 index 00000000000..2605b98f722 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rqcq-2f32-4q3g/GHSA-rqcq-2f32-4q3g.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqcq-2f32-4q3g", + "modified": "2024-04-10T18:30:47Z", + "published": "2024-04-10T18:30:47Z", + "aliases": [ + "CVE-2024-31873" + ], + "details": "IBM Security Verify Access Appliance 10.0.0 through 10.0.7 contains hard-coded credentials which it uses for its own inbound authentication that could be obtained by a malicious actor. IBM X-Force ID: 287317.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31873" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/287317" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7147932" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T16:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rrpg-fwx7-jf88/GHSA-rrpg-fwx7-jf88.json b/advisories/unreviewed/2024/04/GHSA-rrpg-fwx7-jf88/GHSA-rrpg-fwx7-jf88.json new file mode 100644 index 00000000000..2c3fd844794 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rrpg-fwx7-jf88/GHSA-rrpg-fwx7-jf88.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrpg-fwx7-jf88", + "modified": "2024-04-10T18:30:47Z", + "published": "2024-04-10T18:30:47Z", + "aliases": [ + "CVE-2024-31253" + ], + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WP OAuth Server OAuth Server.This issue affects OAuth Server: from n/a through 4.3.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31253" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/oauth2-provider/wordpress-wp-oauth-server-oauth-authentication-plugin-4-3-3-open-redirection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T16:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-v293-3p6g-j7w7/GHSA-v293-3p6g-j7w7.json b/advisories/unreviewed/2024/04/GHSA-v293-3p6g-j7w7/GHSA-v293-3p6g-j7w7.json new file mode 100644 index 00000000000..c6b1bd0b8d6 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-v293-3p6g-j7w7/GHSA-v293-3p6g-j7w7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v293-3p6g-j7w7", + "modified": "2024-04-10T18:30:48Z", + "published": "2024-04-10T18:30:48Z", + "aliases": [ + "CVE-2024-3386" + ], + "details": "An incorrect string comparison vulnerability in Palo Alto Networks PAN-OS software prevents Predefined Decryption Exclusions from functioning as intended. This can cause traffic destined for domains that are not specified in Predefined Decryption Exclusions to be unintentionally excluded from decryption.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3386" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-3386" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-436" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-v6wm-cwm9-2486/GHSA-v6wm-cwm9-2486.json b/advisories/unreviewed/2024/04/GHSA-v6wm-cwm9-2486/GHSA-v6wm-cwm9-2486.json new file mode 100644 index 00000000000..d83c2b82469 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-v6wm-cwm9-2486/GHSA-v6wm-cwm9-2486.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6wm-cwm9-2486", + "modified": "2024-04-10T18:30:48Z", + "published": "2024-04-10T18:30:48Z", + "aliases": [ + "CVE-2024-1741" + ], + "details": "lunary-ai/lunary version 1.0.1 is vulnerable to improper authorization, allowing removed members to read, create, modify, and delete prompt templates using an old authorization token. Despite being removed from an organization, these members can still perform operations on prompt templates by sending HTTP requests with their previously captured authorization token. This issue exposes organizations to unauthorized access and manipulation of sensitive template data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1741" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/671bd040-1cc5-4227-8182-5904e9c5ed3b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-vvx7-xv93-4vqx/GHSA-vvx7-xv93-4vqx.json b/advisories/unreviewed/2024/04/GHSA-vvx7-xv93-4vqx/GHSA-vvx7-xv93-4vqx.json new file mode 100644 index 00000000000..65dd95367b6 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vvx7-xv93-4vqx/GHSA-vvx7-xv93-4vqx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvx7-xv93-4vqx", + "modified": "2024-04-10T18:30:48Z", + "published": "2024-04-10T18:30:48Z", + "aliases": [ + "CVE-2024-31355" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tribulant Slideshow Gallery.This issue affects Slideshow Gallery: from n/a through 1.7.8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31355" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/slideshow-gallery/wordpress-slideshow-gallery-lite-plugin-1-7-8-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-w6xp-gc2w-28hx/GHSA-w6xp-gc2w-28hx.json b/advisories/unreviewed/2024/04/GHSA-w6xp-gc2w-28hx/GHSA-w6xp-gc2w-28hx.json new file mode 100644 index 00000000000..622a9a44bcc --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-w6xp-gc2w-28hx/GHSA-w6xp-gc2w-28hx.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6xp-gc2w-28hx", + "modified": "2024-04-10T18:30:47Z", + "published": "2024-04-10T18:30:47Z", + "aliases": [ + "CVE-2024-31874" + ], + "details": "IBM Security Verify Access Appliance 10.0.0 through 10.0.7 uses uninitialized variables when deploying that could allow a local user to cause a denial of service. IBM X-Force ID: 287318.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31874" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/287318" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7147932" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-457" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T16:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wgqj-wx2p-22jm/GHSA-wgqj-wx2p-22jm.json b/advisories/unreviewed/2024/04/GHSA-wgqj-wx2p-22jm/GHSA-wgqj-wx2p-22jm.json new file mode 100644 index 00000000000..3471f935120 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wgqj-wx2p-22jm/GHSA-wgqj-wx2p-22jm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wgqj-wx2p-22jm", + "modified": "2024-04-10T18:30:47Z", + "published": "2024-04-10T18:30:47Z", + "aliases": [ + "CVE-2024-31278" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Leap13 Premium Addons for Elementor.This issue affects Premium Addons for Elementor: from n/a through 4.10.22.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31278" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/premium-addons-for-elementor/wordpress-premium-addons-for-elementor-plugin-4-10-22-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T16:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wh9j-8hrm-2g7r/GHSA-wh9j-8hrm-2g7r.json b/advisories/unreviewed/2024/04/GHSA-wh9j-8hrm-2g7r/GHSA-wh9j-8hrm-2g7r.json new file mode 100644 index 00000000000..5a002f48767 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wh9j-8hrm-2g7r/GHSA-wh9j-8hrm-2g7r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wh9j-8hrm-2g7r", + "modified": "2024-04-10T18:30:47Z", + "published": "2024-04-10T18:30:47Z", + "aliases": [ + "CVE-2024-31282" + ], + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Appcheap.Io App Builder.This issue affects App Builder: from n/a through 3.8.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31282" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/app-builder/wordpress-app-builder-plugin-3-8-7-open-redirection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T16:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wmmf-r63x-5jrw/GHSA-wmmf-r63x-5jrw.json b/advisories/unreviewed/2024/04/GHSA-wmmf-r63x-5jrw/GHSA-wmmf-r63x-5jrw.json new file mode 100644 index 00000000000..80d32e0c196 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wmmf-r63x-5jrw/GHSA-wmmf-r63x-5jrw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmmf-r63x-5jrw", + "modified": "2024-04-10T18:30:48Z", + "published": "2024-04-10T18:30:48Z", + "aliases": [ + "CVE-2024-3388" + ], + "details": "A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and send network packets to internal assets. However, this vulnerability does not allow the attacker to receive response packets from those internal assets.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3388" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-3388" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wvjp-4x3w-pvqx/GHSA-wvjp-4x3w-pvqx.json b/advisories/unreviewed/2024/04/GHSA-wvjp-4x3w-pvqx/GHSA-wvjp-4x3w-pvqx.json new file mode 100644 index 00000000000..f1aaa75dc59 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wvjp-4x3w-pvqx/GHSA-wvjp-4x3w-pvqx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvjp-4x3w-pvqx", + "modified": "2024-04-10T18:30:48Z", + "published": "2024-04-10T18:30:48Z", + "aliases": [ + "CVE-2024-3383" + ], + "details": "A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agents enables modification of User-ID groups. This impacts user access to network resources where users may be inappropriately denied or allowed access to resources based on your existing Security Policy rules.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3383" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-3383" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-282" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wvpx-g427-q9wc/GHSA-wvpx-g427-q9wc.json b/advisories/unreviewed/2024/04/GHSA-wvpx-g427-q9wc/GHSA-wvpx-g427-q9wc.json new file mode 100644 index 00000000000..a2be2a733bb --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wvpx-g427-q9wc/GHSA-wvpx-g427-q9wc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvpx-g427-q9wc", + "modified": "2024-04-10T18:30:48Z", + "published": "2024-04-10T18:30:48Z", + "aliases": [ + "CVE-2024-3098" + ], + "details": "A vulnerability was identified in the `exec_utils` class of the `llama_index` package, specifically within the `safe_eval` function, allowing for prompt injection leading to arbitrary code execution. This issue arises due to insufficient validation of input, which can be exploited to bypass method restrictions and execute unauthorized code. The vulnerability is a bypass of the previously addressed CVE-2023-39662, demonstrated through a proof of concept that creates a file on the system by exploiting the flaw.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3098" + }, + { + "type": "WEB", + "url": "https://github.com/run-llama/llama_index/commit/5fbcb5a8b9f20f81b791c7fc8849e352613ab475" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/1bce0d61-ad03-4b22-bc32-8f99f92974e7" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wx43-g55g-2jf4/GHSA-wx43-g55g-2jf4.json b/advisories/unreviewed/2024/04/GHSA-wx43-g55g-2jf4/GHSA-wx43-g55g-2jf4.json new file mode 100644 index 00000000000..6204fd9af9f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wx43-g55g-2jf4/GHSA-wx43-g55g-2jf4.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wx43-g55g-2jf4", + "modified": "2024-04-10T18:30:48Z", + "published": "2024-04-10T18:30:48Z", + "aliases": [ + "CVE-2024-2029" + ], + "details": "A command injection vulnerability exists in the `TranscriptEndpoint` of mudler/localai, specifically within the `audioToWav` function used for converting audio files to WAV format for transcription. The vulnerability arises due to the lack of sanitization of user-supplied filenames before passing them to ffmpeg via a shell command, allowing an attacker to execute arbitrary commands on the host system. Successful exploitation could lead to unauthorized access, data breaches, or other detrimental impacts, depending on the privileges of the process executing the code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2029" + }, + { + "type": "WEB", + "url": "https://github.com/mudler/localai/commit/31a4c9c9d3abc58de2bdc5305419181c8b33eb1c" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/e092528a-ce3b-4e66-9b98-3f56d6b276b0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wx55-ppw9-52p9/GHSA-wx55-ppw9-52p9.json b/advisories/unreviewed/2024/04/GHSA-wx55-ppw9-52p9/GHSA-wx55-ppw9-52p9.json new file mode 100644 index 00000000000..8c986e0f46c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wx55-ppw9-52p9/GHSA-wx55-ppw9-52p9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wx55-ppw9-52p9", + "modified": "2024-04-10T18:30:49Z", + "published": "2024-04-10T18:30:49Z", + "aliases": [ + "CVE-2024-3570" + ], + "details": "A stored Cross-Site Scripting (XSS) vulnerability exists in the chat functionality of the mintplex-labs/anything-llm repository, allowing attackers to execute arbitrary JavaScript in the context of a user's session. By manipulating the ChatBot responses, an attacker can inject malicious scripts to perform actions on behalf of the user, such as creating a new admin account or changing the user's password, leading to a complete takeover of the AnythingLLM application. The vulnerability stems from the improper sanitization of user and ChatBot input, specifically through the use of `dangerouslySetInnerHTML`. Successful exploitation requires convincing an admin to add a malicious LocalAI ChatBot to their AnythingLLM instance.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3570" + }, + { + "type": "WEB", + "url": "https://github.com/mintplex-labs/anything-llm/commit/a4ace56a401ffc8ce0082d7444159dfd5dc28834" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/f0eaf552-aaf3-42b6-a5df-cfecd2de15ee" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-x8m7-f4f6-46c2/GHSA-x8m7-f4f6-46c2.json b/advisories/unreviewed/2024/04/GHSA-x8m7-f4f6-46c2/GHSA-x8m7-f4f6-46c2.json new file mode 100644 index 00000000000..82a94869f24 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-x8m7-f4f6-46c2/GHSA-x8m7-f4f6-46c2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x8m7-f4f6-46c2", + "modified": "2024-04-10T18:30:47Z", + "published": "2024-04-10T18:30:47Z", + "aliases": [ + "CVE-2024-31298" + ], + "details": "Insertion of Sensitive Information into Log File vulnerability in Joel Hardi User Spam Remover.This issue affects User Spam Remover: from n/a through 1.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31298" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/user-spam-remover/wordpress-user-spam-remover-plugin-1-0-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T16:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xw8r-2c2x-7j88/GHSA-xw8r-2c2x-7j88.json b/advisories/unreviewed/2024/04/GHSA-xw8r-2c2x-7j88/GHSA-xw8r-2c2x-7j88.json new file mode 100644 index 00000000000..833a3ccb1c5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xw8r-2c2x-7j88/GHSA-xw8r-2c2x-7j88.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xw8r-2c2x-7j88", + "modified": "2024-04-10T18:30:48Z", + "published": "2024-04-10T18:30:48Z", + "aliases": [ + "CVE-2024-1643" + ], + "details": "By knowing an organization's ID, an attacker can join the organization without permission and gain the ability to read and modify all data within that organization. This vulnerability allows unauthorized access and modification of sensitive information, posing a significant security risk. The flaw is due to insufficient verification of user permissions when joining an organization.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1643" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/67eaefe1c77c882c628780940c704a117b561d51" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/ce2563a2-3d81-4e2e-954e-abecb9332416" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T17:15:52Z" + } +} \ No newline at end of file