From 14a4847bb02aba83e5bc648a811810d2bffb2ae1 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 20 Dec 2024 00:32:47 +0000 Subject: [PATCH] Publish Advisories GHSA-35p2-v8mc-67vh GHSA-6r4g-xxf8-49wf GHSA-7x5p-m4v2-w5xp GHSA-jj6m-v8vh-9fgh GHSA-p6jc-3mc4-44wh GHSA-q8x8-9m2h-346g GHSA-r987-qmxw-4c9c --- .../GHSA-35p2-v8mc-67vh.json | 36 +++++++++++++++ .../GHSA-6r4g-xxf8-49wf.json | 4 +- .../GHSA-7x5p-m4v2-w5xp.json | 29 ++++++++++++ .../GHSA-jj6m-v8vh-9fgh.json | 29 ++++++++++++ .../GHSA-p6jc-3mc4-44wh.json | 29 ++++++++++++ .../GHSA-q8x8-9m2h-346g.json | 44 +++++++++++++++++++ .../GHSA-r987-qmxw-4c9c.json | 33 ++++++++++++++ 7 files changed, 203 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2024/12/GHSA-35p2-v8mc-67vh/GHSA-35p2-v8mc-67vh.json create mode 100644 advisories/unreviewed/2024/12/GHSA-7x5p-m4v2-w5xp/GHSA-7x5p-m4v2-w5xp.json create mode 100644 advisories/unreviewed/2024/12/GHSA-jj6m-v8vh-9fgh/GHSA-jj6m-v8vh-9fgh.json create mode 100644 advisories/unreviewed/2024/12/GHSA-p6jc-3mc4-44wh/GHSA-p6jc-3mc4-44wh.json create mode 100644 advisories/unreviewed/2024/12/GHSA-q8x8-9m2h-346g/GHSA-q8x8-9m2h-346g.json create mode 100644 advisories/unreviewed/2024/12/GHSA-r987-qmxw-4c9c/GHSA-r987-qmxw-4c9c.json diff --git a/advisories/unreviewed/2024/12/GHSA-35p2-v8mc-67vh/GHSA-35p2-v8mc-67vh.json b/advisories/unreviewed/2024/12/GHSA-35p2-v8mc-67vh/GHSA-35p2-v8mc-67vh.json new file mode 100644 index 00000000000..d2a85d283a0 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-35p2-v8mc-67vh/GHSA-35p2-v8mc-67vh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35p2-v8mc-67vh", + "modified": "2024-12-20T00:31:17Z", + "published": "2024-12-20T00:31:17Z", + "aliases": [ + "CVE-2024-54009" + ], + "details": "Remote authentication bypass vulnerability in HPE Alletra Storage MP B10000 in versions prior to version 10.4.5 could be remotely exploited to allow disclosure of information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54009" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbst04764en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T23:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6r4g-xxf8-49wf/GHSA-6r4g-xxf8-49wf.json b/advisories/unreviewed/2024/12/GHSA-6r4g-xxf8-49wf/GHSA-6r4g-xxf8-49wf.json index ba10315626a..70eff2ff391 100644 --- a/advisories/unreviewed/2024/12/GHSA-6r4g-xxf8-49wf/GHSA-6r4g-xxf8-49wf.json +++ b/advisories/unreviewed/2024/12/GHSA-6r4g-xxf8-49wf/GHSA-6r4g-xxf8-49wf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-7x5p-m4v2-w5xp/GHSA-7x5p-m4v2-w5xp.json b/advisories/unreviewed/2024/12/GHSA-7x5p-m4v2-w5xp/GHSA-7x5p-m4v2-w5xp.json new file mode 100644 index 00000000000..2fb8af39e6b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7x5p-m4v2-w5xp/GHSA-7x5p-m4v2-w5xp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7x5p-m4v2-w5xp", + "modified": "2024-12-20T00:31:17Z", + "published": "2024-12-20T00:31:17Z", + "aliases": [ + "CVE-2024-54984" + ], + "details": "An issue in Quectel BG96 BG96MAR02A08M1G allows attackers to bypass authentication via a crafted NAS message.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54984" + }, + { + "type": "WEB", + "url": "https://github.com/haroldfeng/nbiot-va/blob/master/Quecctel_BG96_Message_Auth_Bypass.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T22:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jj6m-v8vh-9fgh/GHSA-jj6m-v8vh-9fgh.json b/advisories/unreviewed/2024/12/GHSA-jj6m-v8vh-9fgh/GHSA-jj6m-v8vh-9fgh.json new file mode 100644 index 00000000000..c5a439e5587 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jj6m-v8vh-9fgh/GHSA-jj6m-v8vh-9fgh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jj6m-v8vh-9fgh", + "modified": "2024-12-20T00:31:16Z", + "published": "2024-12-20T00:31:16Z", + "aliases": [ + "CVE-2024-54982" + ], + "details": "An issue in Quectel BC25 with firmware version BC25PAR01A06 allows attackers to bypass authentication via a crafted NAS message.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54982" + }, + { + "type": "WEB", + "url": "https://github.com/haroldfeng/nbiot-va/blob/master/Quectel_BC25_Subscriber_Auth_Bypass.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T22:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p6jc-3mc4-44wh/GHSA-p6jc-3mc4-44wh.json b/advisories/unreviewed/2024/12/GHSA-p6jc-3mc4-44wh/GHSA-p6jc-3mc4-44wh.json new file mode 100644 index 00000000000..1fcb6525172 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p6jc-3mc4-44wh/GHSA-p6jc-3mc4-44wh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6jc-3mc4-44wh", + "modified": "2024-12-20T00:31:16Z", + "published": "2024-12-20T00:31:16Z", + "aliases": [ + "CVE-2024-54983" + ], + "details": "An issue in Quectel BC95-CNV V100R001C00SPC051 allows attackers to bypass authentication via a crafted NAS message.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54983" + }, + { + "type": "WEB", + "url": "https://github.com/haroldfeng/nbiot-va/blob/master/Quecctel_BC95-CNV_Message_Auth_Bypass.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T22:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-q8x8-9m2h-346g/GHSA-q8x8-9m2h-346g.json b/advisories/unreviewed/2024/12/GHSA-q8x8-9m2h-346g/GHSA-q8x8-9m2h-346g.json new file mode 100644 index 00000000000..52a96155fd3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-q8x8-9m2h-346g/GHSA-q8x8-9m2h-346g.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8x8-9m2h-346g", + "modified": "2024-12-20T00:31:17Z", + "published": "2024-12-20T00:31:17Z", + "aliases": [ + "CVE-2024-12700" + ], + "details": "There is an unrestricted file upload vulnerability where it is possible for an authenticated user (low privileged) to upload an jsp shell and execute code with the privileges of user running the web server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12700" + }, + { + "type": "WEB", + "url": "https://aggregate.digital/downloads.html" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-354-05" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T23:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-r987-qmxw-4c9c/GHSA-r987-qmxw-4c9c.json b/advisories/unreviewed/2024/12/GHSA-r987-qmxw-4c9c/GHSA-r987-qmxw-4c9c.json new file mode 100644 index 00000000000..6e9f7e9cdc0 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-r987-qmxw-4c9c/GHSA-r987-qmxw-4c9c.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r987-qmxw-4c9c", + "modified": "2024-12-20T00:31:17Z", + "published": "2024-12-20T00:31:17Z", + "aliases": [ + "CVE-2024-54663" + ], + "details": "An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Inclusion (LFI) vulnerability exists in the /h/rest endpoint, allowing authenticated remote attackers to include and access sensitive files in the WebRoot directory. Exploitation requires a valid auth token and involves crafting a malicious request targeting specific file paths.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54663" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.11#Security_Fixes" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.3#Security_Fixes" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T23:15:07Z" + } +} \ No newline at end of file