mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-xcx3-wvhg-c3h3 GHSA-288p-75q5-6gj7 GHSA-ccrr-hx7g-hmm4 GHSA-6gqq-xj74-45f9 GHSA-8c3c-gvf8-p7v2 GHSA-c75m-w45q-rj2j GHSA-cfjc-m7fv-63xj GHSA-cqqg-qhcp-9mqr GHSA-cv6w-7hvv-mf8v GHSA-gq9c-8cr6-3qh3 GHSA-mw3w-3jx9-mhff GHSA-pvjp-3rj2-p4ww GHSA-q89f-q98p-7vmj GHSA-qmpq-m6m5-57hh GHSA-w4vv-pf24-vw92 GHSA-x4x5-jx9j-mmv7
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-xcx3-wvhg-c3h3",
|
||||
"modified": "2024-04-04T03:35:18Z",
|
||||
"modified": "2024-11-29T06:35:28Z",
|
||||
"published": "2023-04-19T15:30:21Z",
|
||||
"aliases": [
|
||||
"CVE-2023-29586"
|
||||
@@ -30,6 +30,14 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://securityandstuff.com/posts/teracopy_arbitrary_read"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://support.codesector.com/en/articles/10088479-cve-2023-29586"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.youtube.com/watch?v=mrOHtWWFhJI"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-288p-75q5-6gj7",
|
||||
"modified": "2024-09-10T06:30:49Z",
|
||||
"modified": "2024-11-29T06:35:28Z",
|
||||
"published": "2024-09-10T06:30:49Z",
|
||||
"aliases": [
|
||||
"CVE-2024-6173"
|
||||
@@ -22,6 +22,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.axis.com/dam/public/33/0c/c8/cve-2024-6173-en-US-448995.pdf"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.axis.com/dam/public/5a/87/a2/cve-2024-6173-en-US-458042.pdf"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-ccrr-hx7g-hmm4",
|
||||
"modified": "2024-09-10T06:30:49Z",
|
||||
"modified": "2024-11-29T06:35:28Z",
|
||||
"published": "2024-09-10T06:30:49Z",
|
||||
"aliases": [
|
||||
"CVE-2024-6509"
|
||||
@@ -22,6 +22,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.axis.com/dam/public/47/bf/2c/cve-2024-6509-en-US-448996.pdf"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.axis.com/dam/public/f6/c6/f5/cve-2024-6509-en-US-458043.pdf"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -0,0 +1,29 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-6gqq-xj74-45f9",
|
||||
"modified": "2024-11-29T06:35:29Z",
|
||||
"published": "2024-11-29T06:35:29Z",
|
||||
"aliases": [
|
||||
"CVE-2024-54123"
|
||||
],
|
||||
"details": "Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG document, if the SVG tag is allowed for a text format.",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54123"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://backdropcms.org/security/backdrop-sa-core-2024-002"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-11-29T04:15:03Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-8c3c-gvf8-p7v2",
|
||||
"modified": "2024-11-26T21:32:24Z",
|
||||
"modified": "2024-11-29T06:35:29Z",
|
||||
"published": "2024-11-26T18:38:52Z",
|
||||
"aliases": [
|
||||
"CVE-2024-52337"
|
||||
@@ -13,9 +13,7 @@
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
@@ -36,6 +34,14 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2324541"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.opensuse.org/2024/11/26/tuned-instance-create.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.openwall.com/lists/oss-security/2024/11/28/2"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -0,0 +1,29 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-c75m-w45q-rj2j",
|
||||
"modified": "2024-11-29T06:35:29Z",
|
||||
"published": "2024-11-29T06:35:29Z",
|
||||
"aliases": [
|
||||
"CVE-2024-10980"
|
||||
],
|
||||
"details": "The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) WordPress plugin before 5.10.3 does not validate and escape some of its Cookie Consent block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10980"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://wpscan.com/vulnerability/915daad8-d14c-4457-a3a0-aa21744f4ae0"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-11-29T06:15:06Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-cfjc-m7fv-63xj",
|
||||
"modified": "2024-11-26T21:32:24Z",
|
||||
"modified": "2024-11-29T06:35:29Z",
|
||||
"published": "2024-11-26T18:38:52Z",
|
||||
"aliases": [
|
||||
"CVE-2024-52336"
|
||||
@@ -13,9 +13,7 @@
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
@@ -32,12 +30,18 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2324540"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.opensuse.org/2024/11/26/tuned-instance-create.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.openwall.com/lists/oss-security/2024/11/28/2"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"cwe_ids": [],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
|
||||
@@ -0,0 +1,33 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-cqqg-qhcp-9mqr",
|
||||
"modified": "2024-11-29T06:35:29Z",
|
||||
"published": "2024-11-29T06:35:29Z",
|
||||
"aliases": [
|
||||
"CVE-2024-54124"
|
||||
],
|
||||
"details": "In Click Studios Passwordstate before build 9920, there is a potential permission escalation on the edit folder screen.",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54124"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.clickstudios.com.au/passwordstate-changelog.aspx"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.clickstudios.com.au/security/advisories"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-11-29T04:15:04Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,40 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-cv6w-7hvv-mf8v",
|
||||
"modified": "2024-11-29T06:35:29Z",
|
||||
"published": "2024-11-29T06:35:29Z",
|
||||
"aliases": [
|
||||
"CVE-2024-11980"
|
||||
],
|
||||
"details": "Certain modes of in-vehicle routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access the specific functionality to obtain partial device information, modify the WiFi SSID, and restart the device.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11980"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.twcert.org.tw/en/cp-139-8274-01e55-2.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.twcert.org.tw/tw/cp-132-8273-95a07-1.html"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-306"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-11-29T06:15:06Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-gq9c-8cr6-3qh3",
|
||||
"modified": "2024-11-26T09:30:49Z",
|
||||
"modified": "2024-11-29T06:35:28Z",
|
||||
"published": "2024-11-26T09:30:49Z",
|
||||
"aliases": [
|
||||
"CVE-2024-47257"
|
||||
@@ -13,14 +13,16 @@
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47257"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.axis.com/dam/public/b7/76/b2/cve-2024-47257pdf-en-US-458044.pdf"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.axis.com/dam/public/permalink/231088/cve-2024-47257pdf-en-US_InternalID-231088.pdf"
|
||||
|
||||
@@ -0,0 +1,33 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-mw3w-3jx9-mhff",
|
||||
"modified": "2024-11-29T06:35:29Z",
|
||||
"published": "2024-11-29T06:35:29Z",
|
||||
"aliases": [
|
||||
"CVE-2024-48651"
|
||||
],
|
||||
"details": "In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48651"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/proftpd/proftpd/issues/1830"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/proftpd/proftpd/commit/cec01cc0a2523453e5da5a486bc6d977c3768db1"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-11-29T05:15:05Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,40 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-pvjp-3rj2-p4ww",
|
||||
"modified": "2024-11-29T06:35:29Z",
|
||||
"published": "2024-11-29T06:35:29Z",
|
||||
"aliases": [
|
||||
"CVE-2024-53701"
|
||||
],
|
||||
"details": "Multiple FCNT Android devices provide the original security features such as \"privacy mode\" where arbitrary applications can be set not to be displayed, etc.\nUnder certain conditions, and when an attacker can directly operate the device which its screen is unlocked by a user, the provided security features' setting pages may be exposed and/or the settings may be altered, without authentication. For example, specific applications in the device configured to be hidden may be displayed and/or activated.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53701"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://jvn.jp/en/jp/JVN43845108"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.fcnt.com/consumernotice/20741"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-306"
|
||||
],
|
||||
"severity": "LOW",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-11-29T06:15:07Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,33 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-q89f-q98p-7vmj",
|
||||
"modified": "2024-11-29T06:35:29Z",
|
||||
"published": "2024-11-29T06:35:29Z",
|
||||
"aliases": [
|
||||
"CVE-2024-45495"
|
||||
],
|
||||
"details": "MSA FieldServer Gateway 5.0.0 through 6.5.2 allows cross-origin WebSocket hijacking.",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45495"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://us.msasafety.com/fieldserver"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://us.msasafety.com/security-notices"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-11-29T05:15:05Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,29 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-qmpq-m6m5-57hh",
|
||||
"modified": "2024-11-29T06:35:29Z",
|
||||
"published": "2024-11-29T06:35:29Z",
|
||||
"aliases": [
|
||||
"CVE-2024-35451"
|
||||
],
|
||||
"details": "LinkStack 2.7.9 through 4.7.7 allows resources\\views\\components\\favicon.blade.php link SSRF.",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35451"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://datafarm.co.th/blog/CVE-2024-35451:-From-%28Authenticated%29-SSRF-to-Remote-Code-Execution"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-11-29T05:15:05Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,29 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-w4vv-pf24-vw92",
|
||||
"modified": "2024-11-29T06:35:29Z",
|
||||
"published": "2024-11-29T06:35:29Z",
|
||||
"aliases": [
|
||||
"CVE-2024-10704"
|
||||
],
|
||||
"details": "The Photo Gallery by 10Web WordPress plugin before 1.8.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10704"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://wpscan.com/vulnerability/6c115117-11c0-4c9e-9988-8547c9364c01"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-11-29T06:15:06Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,37 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-x4x5-jx9j-mmv7",
|
||||
"modified": "2024-11-29T06:35:29Z",
|
||||
"published": "2024-11-29T06:35:29Z",
|
||||
"aliases": [
|
||||
"CVE-2024-39162"
|
||||
],
|
||||
"details": "pyspider through 0.3.10 allows /update XSS. NOTE: This vulnerability only affects products that are no longer supported by the maintainer",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39162"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://docs.pyspider.org/en/latest"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/binux/pyspider"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.sonarsource.com/blog/basic-http-authentication-risk-uncovering-pyspider-vulnerabilities"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-11-29T06:15:06Z"
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user