Publish Advisories

GHSA-xcx3-wvhg-c3h3
GHSA-288p-75q5-6gj7
GHSA-ccrr-hx7g-hmm4
GHSA-6gqq-xj74-45f9
GHSA-8c3c-gvf8-p7v2
GHSA-c75m-w45q-rj2j
GHSA-cfjc-m7fv-63xj
GHSA-cqqg-qhcp-9mqr
GHSA-cv6w-7hvv-mf8v
GHSA-gq9c-8cr6-3qh3
GHSA-mw3w-3jx9-mhff
GHSA-pvjp-3rj2-p4ww
GHSA-q89f-q98p-7vmj
GHSA-qmpq-m6m5-57hh
GHSA-w4vv-pf24-vw92
GHSA-x4x5-jx9j-mmv7
This commit is contained in:
advisory-database[bot]
2024-11-29 06:37:24 +00:00
parent 1810e6a2e3
commit 1522866be5
16 changed files with 378 additions and 18 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xcx3-wvhg-c3h3",
"modified": "2024-04-04T03:35:18Z",
"modified": "2024-11-29T06:35:28Z",
"published": "2023-04-19T15:30:21Z",
"aliases": [
"CVE-2023-29586"
@@ -30,6 +30,14 @@
{
"type": "WEB",
"url": "https://securityandstuff.com/posts/teracopy_arbitrary_read"
},
{
"type": "WEB",
"url": "https://support.codesector.com/en/articles/10088479-cve-2023-29586"
},
{
"type": "WEB",
"url": "https://www.youtube.com/watch?v=mrOHtWWFhJI"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-288p-75q5-6gj7",
"modified": "2024-09-10T06:30:49Z",
"modified": "2024-11-29T06:35:28Z",
"published": "2024-09-10T06:30:49Z",
"aliases": [
"CVE-2024-6173"
@@ -22,6 +22,10 @@
{
"type": "WEB",
"url": "https://www.axis.com/dam/public/33/0c/c8/cve-2024-6173-en-US-448995.pdf"
},
{
"type": "WEB",
"url": "https://www.axis.com/dam/public/5a/87/a2/cve-2024-6173-en-US-458042.pdf"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ccrr-hx7g-hmm4",
"modified": "2024-09-10T06:30:49Z",
"modified": "2024-11-29T06:35:28Z",
"published": "2024-09-10T06:30:49Z",
"aliases": [
"CVE-2024-6509"
@@ -22,6 +22,10 @@
{
"type": "WEB",
"url": "https://www.axis.com/dam/public/47/bf/2c/cve-2024-6509-en-US-448996.pdf"
},
{
"type": "WEB",
"url": "https://www.axis.com/dam/public/f6/c6/f5/cve-2024-6509-en-US-458043.pdf"
}
],
"database_specific": {
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6gqq-xj74-45f9",
"modified": "2024-11-29T06:35:29Z",
"published": "2024-11-29T06:35:29Z",
"aliases": [
"CVE-2024-54123"
],
"details": "Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG document, if the SVG tag is allowed for a text format.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54123"
},
{
"type": "WEB",
"url": "https://backdropcms.org/security/backdrop-sa-core-2024-002"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-29T04:15:03Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8c3c-gvf8-p7v2",
"modified": "2024-11-26T21:32:24Z",
"modified": "2024-11-29T06:35:29Z",
"published": "2024-11-26T18:38:52Z",
"aliases": [
"CVE-2024-52337"
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,6 +34,14 @@
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2324541"
},
{
"type": "WEB",
"url": "https://security.opensuse.org/2024/11/26/tuned-instance-create.html"
},
{
"type": "WEB",
"url": "https://www.openwall.com/lists/oss-security/2024/11/28/2"
}
],
"database_specific": {
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c75m-w45q-rj2j",
"modified": "2024-11-29T06:35:29Z",
"published": "2024-11-29T06:35:29Z",
"aliases": [
"CVE-2024-10980"
],
"details": "The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) WordPress plugin before 5.10.3 does not validate and escape some of its Cookie Consent block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10980"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/915daad8-d14c-4457-a3a0-aa21744f4ae0"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-29T06:15:06Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cfjc-m7fv-63xj",
"modified": "2024-11-26T21:32:24Z",
"modified": "2024-11-29T06:35:29Z",
"published": "2024-11-26T18:38:52Z",
"aliases": [
"CVE-2024-52336"
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,12 +30,18 @@
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2324540"
},
{
"type": "WEB",
"url": "https://security.opensuse.org/2024/11/26/tuned-instance-create.html"
},
{
"type": "WEB",
"url": "https://www.openwall.com/lists/oss-security/2024/11/28/2"
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cqqg-qhcp-9mqr",
"modified": "2024-11-29T06:35:29Z",
"published": "2024-11-29T06:35:29Z",
"aliases": [
"CVE-2024-54124"
],
"details": "In Click Studios Passwordstate before build 9920, there is a potential permission escalation on the edit folder screen.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54124"
},
{
"type": "WEB",
"url": "https://www.clickstudios.com.au/passwordstate-changelog.aspx"
},
{
"type": "WEB",
"url": "https://www.clickstudios.com.au/security/advisories"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-29T04:15:04Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cv6w-7hvv-mf8v",
"modified": "2024-11-29T06:35:29Z",
"published": "2024-11-29T06:35:29Z",
"aliases": [
"CVE-2024-11980"
],
"details": "Certain modes of in-vehicle routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access the specific functionality to obtain partial device information, modify the WiFi SSID, and restart the device.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11980"
},
{
"type": "WEB",
"url": "https://www.twcert.org.tw/en/cp-139-8274-01e55-2.html"
},
{
"type": "WEB",
"url": "https://www.twcert.org.tw/tw/cp-132-8273-95a07-1.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-306"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-29T06:15:06Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gq9c-8cr6-3qh3",
"modified": "2024-11-26T09:30:49Z",
"modified": "2024-11-29T06:35:28Z",
"published": "2024-11-26T09:30:49Z",
"aliases": [
"CVE-2024-47257"
@@ -13,14 +13,16 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47257"
},
{
"type": "WEB",
"url": "https://www.axis.com/dam/public/b7/76/b2/cve-2024-47257pdf-en-US-458044.pdf"
},
{
"type": "WEB",
"url": "https://www.axis.com/dam/public/permalink/231088/cve-2024-47257pdf-en-US_InternalID-231088.pdf"
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mw3w-3jx9-mhff",
"modified": "2024-11-29T06:35:29Z",
"published": "2024-11-29T06:35:29Z",
"aliases": [
"CVE-2024-48651"
],
"details": "In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48651"
},
{
"type": "WEB",
"url": "https://github.com/proftpd/proftpd/issues/1830"
},
{
"type": "WEB",
"url": "https://github.com/proftpd/proftpd/commit/cec01cc0a2523453e5da5a486bc6d977c3768db1"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-29T05:15:05Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pvjp-3rj2-p4ww",
"modified": "2024-11-29T06:35:29Z",
"published": "2024-11-29T06:35:29Z",
"aliases": [
"CVE-2024-53701"
],
"details": "Multiple FCNT Android devices provide the original security features such as \"privacy mode\" where arbitrary applications can be set not to be displayed, etc.\nUnder certain conditions, and when an attacker can directly operate the device which its screen is unlocked by a user, the provided security features' setting pages may be exposed and/or the settings may be altered, without authentication. For example, specific applications in the device configured to be hidden may be displayed and/or activated.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53701"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/jp/JVN43845108"
},
{
"type": "WEB",
"url": "https://www.fcnt.com/consumernotice/20741"
}
],
"database_specific": {
"cwe_ids": [
"CWE-306"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-29T06:15:07Z"
}
}
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q89f-q98p-7vmj",
"modified": "2024-11-29T06:35:29Z",
"published": "2024-11-29T06:35:29Z",
"aliases": [
"CVE-2024-45495"
],
"details": "MSA FieldServer Gateway 5.0.0 through 6.5.2 allows cross-origin WebSocket hijacking.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45495"
},
{
"type": "WEB",
"url": "https://us.msasafety.com/fieldserver"
},
{
"type": "WEB",
"url": "https://us.msasafety.com/security-notices"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-29T05:15:05Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qmpq-m6m5-57hh",
"modified": "2024-11-29T06:35:29Z",
"published": "2024-11-29T06:35:29Z",
"aliases": [
"CVE-2024-35451"
],
"details": "LinkStack 2.7.9 through 4.7.7 allows resources\\views\\components\\favicon.blade.php link SSRF.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35451"
},
{
"type": "WEB",
"url": "https://datafarm.co.th/blog/CVE-2024-35451:-From-%28Authenticated%29-SSRF-to-Remote-Code-Execution"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-29T05:15:05Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w4vv-pf24-vw92",
"modified": "2024-11-29T06:35:29Z",
"published": "2024-11-29T06:35:29Z",
"aliases": [
"CVE-2024-10704"
],
"details": "The Photo Gallery by 10Web WordPress plugin before 1.8.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10704"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/6c115117-11c0-4c9e-9988-8547c9364c01"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-29T06:15:06Z"
}
}
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x4x5-jx9j-mmv7",
"modified": "2024-11-29T06:35:29Z",
"published": "2024-11-29T06:35:29Z",
"aliases": [
"CVE-2024-39162"
],
"details": "pyspider through 0.3.10 allows /update XSS. NOTE: This vulnerability only affects products that are no longer supported by the maintainer",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39162"
},
{
"type": "WEB",
"url": "https://docs.pyspider.org/en/latest"
},
{
"type": "WEB",
"url": "https://github.com/binux/pyspider"
},
{
"type": "WEB",
"url": "https://www.sonarsource.com/blog/basic-http-authentication-risk-uncovering-pyspider-vulnerabilities"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-29T06:15:06Z"
}
}