From 1522866be58279f2a5428cac30045cd2ebabe6a9 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 29 Nov 2024 06:37:24 +0000 Subject: [PATCH] Publish Advisories GHSA-xcx3-wvhg-c3h3 GHSA-288p-75q5-6gj7 GHSA-ccrr-hx7g-hmm4 GHSA-6gqq-xj74-45f9 GHSA-8c3c-gvf8-p7v2 GHSA-c75m-w45q-rj2j GHSA-cfjc-m7fv-63xj GHSA-cqqg-qhcp-9mqr GHSA-cv6w-7hvv-mf8v GHSA-gq9c-8cr6-3qh3 GHSA-mw3w-3jx9-mhff GHSA-pvjp-3rj2-p4ww GHSA-q89f-q98p-7vmj GHSA-qmpq-m6m5-57hh GHSA-w4vv-pf24-vw92 GHSA-x4x5-jx9j-mmv7 --- .../GHSA-xcx3-wvhg-c3h3.json | 10 ++++- .../GHSA-288p-75q5-6gj7.json | 6 ++- .../GHSA-ccrr-hx7g-hmm4.json | 6 ++- .../GHSA-6gqq-xj74-45f9.json | 29 ++++++++++++++ .../GHSA-8c3c-gvf8-p7v2.json | 14 +++++-- .../GHSA-c75m-w45q-rj2j.json | 29 ++++++++++++++ .../GHSA-cfjc-m7fv-63xj.json | 18 +++++---- .../GHSA-cqqg-qhcp-9mqr.json | 33 +++++++++++++++ .../GHSA-cv6w-7hvv-mf8v.json | 40 +++++++++++++++++++ .../GHSA-gq9c-8cr6-3qh3.json | 10 +++-- .../GHSA-mw3w-3jx9-mhff.json | 33 +++++++++++++++ .../GHSA-pvjp-3rj2-p4ww.json | 40 +++++++++++++++++++ .../GHSA-q89f-q98p-7vmj.json | 33 +++++++++++++++ .../GHSA-qmpq-m6m5-57hh.json | 29 ++++++++++++++ .../GHSA-w4vv-pf24-vw92.json | 29 ++++++++++++++ .../GHSA-x4x5-jx9j-mmv7.json | 37 +++++++++++++++++ 16 files changed, 378 insertions(+), 18 deletions(-) create mode 100644 advisories/unreviewed/2024/11/GHSA-6gqq-xj74-45f9/GHSA-6gqq-xj74-45f9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-c75m-w45q-rj2j/GHSA-c75m-w45q-rj2j.json create mode 100644 advisories/unreviewed/2024/11/GHSA-cqqg-qhcp-9mqr/GHSA-cqqg-qhcp-9mqr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-cv6w-7hvv-mf8v/GHSA-cv6w-7hvv-mf8v.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mw3w-3jx9-mhff/GHSA-mw3w-3jx9-mhff.json create mode 100644 advisories/unreviewed/2024/11/GHSA-pvjp-3rj2-p4ww/GHSA-pvjp-3rj2-p4ww.json create mode 100644 advisories/unreviewed/2024/11/GHSA-q89f-q98p-7vmj/GHSA-q89f-q98p-7vmj.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qmpq-m6m5-57hh/GHSA-qmpq-m6m5-57hh.json create mode 100644 advisories/unreviewed/2024/11/GHSA-w4vv-pf24-vw92/GHSA-w4vv-pf24-vw92.json create mode 100644 advisories/unreviewed/2024/11/GHSA-x4x5-jx9j-mmv7/GHSA-x4x5-jx9j-mmv7.json diff --git a/advisories/unreviewed/2023/04/GHSA-xcx3-wvhg-c3h3/GHSA-xcx3-wvhg-c3h3.json b/advisories/unreviewed/2023/04/GHSA-xcx3-wvhg-c3h3/GHSA-xcx3-wvhg-c3h3.json index d83cddf0d12..49736ddd00b 100644 --- a/advisories/unreviewed/2023/04/GHSA-xcx3-wvhg-c3h3/GHSA-xcx3-wvhg-c3h3.json +++ b/advisories/unreviewed/2023/04/GHSA-xcx3-wvhg-c3h3/GHSA-xcx3-wvhg-c3h3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xcx3-wvhg-c3h3", - "modified": "2024-04-04T03:35:18Z", + "modified": "2024-11-29T06:35:28Z", "published": "2023-04-19T15:30:21Z", "aliases": [ "CVE-2023-29586" @@ -30,6 +30,14 @@ { "type": "WEB", "url": "https://securityandstuff.com/posts/teracopy_arbitrary_read" + }, + { + "type": "WEB", + "url": "https://support.codesector.com/en/articles/10088479-cve-2023-29586" + }, + { + "type": "WEB", + "url": "https://www.youtube.com/watch?v=mrOHtWWFhJI" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/09/GHSA-288p-75q5-6gj7/GHSA-288p-75q5-6gj7.json b/advisories/unreviewed/2024/09/GHSA-288p-75q5-6gj7/GHSA-288p-75q5-6gj7.json index 22a36bd2dc8..c4c691edfd3 100644 --- a/advisories/unreviewed/2024/09/GHSA-288p-75q5-6gj7/GHSA-288p-75q5-6gj7.json +++ b/advisories/unreviewed/2024/09/GHSA-288p-75q5-6gj7/GHSA-288p-75q5-6gj7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-288p-75q5-6gj7", - "modified": "2024-09-10T06:30:49Z", + "modified": "2024-11-29T06:35:28Z", "published": "2024-09-10T06:30:49Z", "aliases": [ "CVE-2024-6173" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://www.axis.com/dam/public/33/0c/c8/cve-2024-6173-en-US-448995.pdf" + }, + { + "type": "WEB", + "url": "https://www.axis.com/dam/public/5a/87/a2/cve-2024-6173-en-US-458042.pdf" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/09/GHSA-ccrr-hx7g-hmm4/GHSA-ccrr-hx7g-hmm4.json b/advisories/unreviewed/2024/09/GHSA-ccrr-hx7g-hmm4/GHSA-ccrr-hx7g-hmm4.json index 3ffd0b8c957..e5bf7abf2f4 100644 --- a/advisories/unreviewed/2024/09/GHSA-ccrr-hx7g-hmm4/GHSA-ccrr-hx7g-hmm4.json +++ b/advisories/unreviewed/2024/09/GHSA-ccrr-hx7g-hmm4/GHSA-ccrr-hx7g-hmm4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ccrr-hx7g-hmm4", - "modified": "2024-09-10T06:30:49Z", + "modified": "2024-11-29T06:35:28Z", "published": "2024-09-10T06:30:49Z", "aliases": [ "CVE-2024-6509" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://www.axis.com/dam/public/47/bf/2c/cve-2024-6509-en-US-448996.pdf" + }, + { + "type": "WEB", + "url": "https://www.axis.com/dam/public/f6/c6/f5/cve-2024-6509-en-US-458043.pdf" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/11/GHSA-6gqq-xj74-45f9/GHSA-6gqq-xj74-45f9.json b/advisories/unreviewed/2024/11/GHSA-6gqq-xj74-45f9/GHSA-6gqq-xj74-45f9.json new file mode 100644 index 00000000000..950bfab9502 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6gqq-xj74-45f9/GHSA-6gqq-xj74-45f9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gqq-xj74-45f9", + "modified": "2024-11-29T06:35:29Z", + "published": "2024-11-29T06:35:29Z", + "aliases": [ + "CVE-2024-54123" + ], + "details": "Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG document, if the SVG tag is allowed for a text format.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54123" + }, + { + "type": "WEB", + "url": "https://backdropcms.org/security/backdrop-sa-core-2024-002" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T04:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8c3c-gvf8-p7v2/GHSA-8c3c-gvf8-p7v2.json b/advisories/unreviewed/2024/11/GHSA-8c3c-gvf8-p7v2/GHSA-8c3c-gvf8-p7v2.json index aeeace17a55..4e89162f5ad 100644 --- a/advisories/unreviewed/2024/11/GHSA-8c3c-gvf8-p7v2/GHSA-8c3c-gvf8-p7v2.json +++ b/advisories/unreviewed/2024/11/GHSA-8c3c-gvf8-p7v2/GHSA-8c3c-gvf8-p7v2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8c3c-gvf8-p7v2", - "modified": "2024-11-26T21:32:24Z", + "modified": "2024-11-29T06:35:29Z", "published": "2024-11-26T18:38:52Z", "aliases": [ "CVE-2024-52337" @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,6 +34,14 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2324541" + }, + { + "type": "WEB", + "url": "https://security.opensuse.org/2024/11/26/tuned-instance-create.html" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/11/28/2" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/11/GHSA-c75m-w45q-rj2j/GHSA-c75m-w45q-rj2j.json b/advisories/unreviewed/2024/11/GHSA-c75m-w45q-rj2j/GHSA-c75m-w45q-rj2j.json new file mode 100644 index 00000000000..d7cfaaab11d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-c75m-w45q-rj2j/GHSA-c75m-w45q-rj2j.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c75m-w45q-rj2j", + "modified": "2024-11-29T06:35:29Z", + "published": "2024-11-29T06:35:29Z", + "aliases": [ + "CVE-2024-10980" + ], + "details": "The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) WordPress plugin before 5.10.3 does not validate and escape some of its Cookie Consent block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10980" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/915daad8-d14c-4457-a3a0-aa21744f4ae0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T06:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cfjc-m7fv-63xj/GHSA-cfjc-m7fv-63xj.json b/advisories/unreviewed/2024/11/GHSA-cfjc-m7fv-63xj/GHSA-cfjc-m7fv-63xj.json index 4cc6f7ae24c..585b0819c17 100644 --- a/advisories/unreviewed/2024/11/GHSA-cfjc-m7fv-63xj/GHSA-cfjc-m7fv-63xj.json +++ b/advisories/unreviewed/2024/11/GHSA-cfjc-m7fv-63xj/GHSA-cfjc-m7fv-63xj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cfjc-m7fv-63xj", - "modified": "2024-11-26T21:32:24Z", + "modified": "2024-11-29T06:35:29Z", "published": "2024-11-26T18:38:52Z", "aliases": [ "CVE-2024-52336" @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,12 +30,18 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2324540" + }, + { + "type": "WEB", + "url": "https://security.opensuse.org/2024/11/26/tuned-instance-create.html" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/11/28/2" } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-cqqg-qhcp-9mqr/GHSA-cqqg-qhcp-9mqr.json b/advisories/unreviewed/2024/11/GHSA-cqqg-qhcp-9mqr/GHSA-cqqg-qhcp-9mqr.json new file mode 100644 index 00000000000..f620bf37940 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cqqg-qhcp-9mqr/GHSA-cqqg-qhcp-9mqr.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqqg-qhcp-9mqr", + "modified": "2024-11-29T06:35:29Z", + "published": "2024-11-29T06:35:29Z", + "aliases": [ + "CVE-2024-54124" + ], + "details": "In Click Studios Passwordstate before build 9920, there is a potential permission escalation on the edit folder screen.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54124" + }, + { + "type": "WEB", + "url": "https://www.clickstudios.com.au/passwordstate-changelog.aspx" + }, + { + "type": "WEB", + "url": "https://www.clickstudios.com.au/security/advisories" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T04:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cv6w-7hvv-mf8v/GHSA-cv6w-7hvv-mf8v.json b/advisories/unreviewed/2024/11/GHSA-cv6w-7hvv-mf8v/GHSA-cv6w-7hvv-mf8v.json new file mode 100644 index 00000000000..e9bd0ce8392 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cv6w-7hvv-mf8v/GHSA-cv6w-7hvv-mf8v.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cv6w-7hvv-mf8v", + "modified": "2024-11-29T06:35:29Z", + "published": "2024-11-29T06:35:29Z", + "aliases": [ + "CVE-2024-11980" + ], + "details": "Certain modes of in-vehicle routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access the specific functionality to obtain partial device information, modify the WiFi SSID, and restart the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11980" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-8274-01e55-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-8273-95a07-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T06:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gq9c-8cr6-3qh3/GHSA-gq9c-8cr6-3qh3.json b/advisories/unreviewed/2024/11/GHSA-gq9c-8cr6-3qh3/GHSA-gq9c-8cr6-3qh3.json index fd249a229be..63c85da106a 100644 --- a/advisories/unreviewed/2024/11/GHSA-gq9c-8cr6-3qh3/GHSA-gq9c-8cr6-3qh3.json +++ b/advisories/unreviewed/2024/11/GHSA-gq9c-8cr6-3qh3/GHSA-gq9c-8cr6-3qh3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gq9c-8cr6-3qh3", - "modified": "2024-11-26T09:30:49Z", + "modified": "2024-11-29T06:35:28Z", "published": "2024-11-26T09:30:49Z", "aliases": [ "CVE-2024-47257" @@ -13,14 +13,16 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47257" }, + { + "type": "WEB", + "url": "https://www.axis.com/dam/public/b7/76/b2/cve-2024-47257pdf-en-US-458044.pdf" + }, { "type": "WEB", "url": "https://www.axis.com/dam/public/permalink/231088/cve-2024-47257pdf-en-US_InternalID-231088.pdf" diff --git a/advisories/unreviewed/2024/11/GHSA-mw3w-3jx9-mhff/GHSA-mw3w-3jx9-mhff.json b/advisories/unreviewed/2024/11/GHSA-mw3w-3jx9-mhff/GHSA-mw3w-3jx9-mhff.json new file mode 100644 index 00000000000..111bc5a0171 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mw3w-3jx9-mhff/GHSA-mw3w-3jx9-mhff.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw3w-3jx9-mhff", + "modified": "2024-11-29T06:35:29Z", + "published": "2024-11-29T06:35:29Z", + "aliases": [ + "CVE-2024-48651" + ], + "details": "In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48651" + }, + { + "type": "WEB", + "url": "https://github.com/proftpd/proftpd/issues/1830" + }, + { + "type": "WEB", + "url": "https://github.com/proftpd/proftpd/commit/cec01cc0a2523453e5da5a486bc6d977c3768db1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T05:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pvjp-3rj2-p4ww/GHSA-pvjp-3rj2-p4ww.json b/advisories/unreviewed/2024/11/GHSA-pvjp-3rj2-p4ww/GHSA-pvjp-3rj2-p4ww.json new file mode 100644 index 00000000000..13c922f92f2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pvjp-3rj2-p4ww/GHSA-pvjp-3rj2-p4ww.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pvjp-3rj2-p4ww", + "modified": "2024-11-29T06:35:29Z", + "published": "2024-11-29T06:35:29Z", + "aliases": [ + "CVE-2024-53701" + ], + "details": "Multiple FCNT Android devices provide the original security features such as \"privacy mode\" where arbitrary applications can be set not to be displayed, etc.\nUnder certain conditions, and when an attacker can directly operate the device which its screen is unlocked by a user, the provided security features' setting pages may be exposed and/or the settings may be altered, without authentication. For example, specific applications in the device configured to be hidden may be displayed and/or activated.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53701" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN43845108" + }, + { + "type": "WEB", + "url": "https://www.fcnt.com/consumernotice/20741" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T06:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-q89f-q98p-7vmj/GHSA-q89f-q98p-7vmj.json b/advisories/unreviewed/2024/11/GHSA-q89f-q98p-7vmj/GHSA-q89f-q98p-7vmj.json new file mode 100644 index 00000000000..b247aeb91d3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-q89f-q98p-7vmj/GHSA-q89f-q98p-7vmj.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q89f-q98p-7vmj", + "modified": "2024-11-29T06:35:29Z", + "published": "2024-11-29T06:35:29Z", + "aliases": [ + "CVE-2024-45495" + ], + "details": "MSA FieldServer Gateway 5.0.0 through 6.5.2 allows cross-origin WebSocket hijacking.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45495" + }, + { + "type": "WEB", + "url": "https://us.msasafety.com/fieldserver" + }, + { + "type": "WEB", + "url": "https://us.msasafety.com/security-notices" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T05:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qmpq-m6m5-57hh/GHSA-qmpq-m6m5-57hh.json b/advisories/unreviewed/2024/11/GHSA-qmpq-m6m5-57hh/GHSA-qmpq-m6m5-57hh.json new file mode 100644 index 00000000000..76ff41271cf --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qmpq-m6m5-57hh/GHSA-qmpq-m6m5-57hh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qmpq-m6m5-57hh", + "modified": "2024-11-29T06:35:29Z", + "published": "2024-11-29T06:35:29Z", + "aliases": [ + "CVE-2024-35451" + ], + "details": "LinkStack 2.7.9 through 4.7.7 allows resources\\views\\components\\favicon.blade.php link SSRF.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35451" + }, + { + "type": "WEB", + "url": "https://datafarm.co.th/blog/CVE-2024-35451:-From-%28Authenticated%29-SSRF-to-Remote-Code-Execution" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T05:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w4vv-pf24-vw92/GHSA-w4vv-pf24-vw92.json b/advisories/unreviewed/2024/11/GHSA-w4vv-pf24-vw92/GHSA-w4vv-pf24-vw92.json new file mode 100644 index 00000000000..45287e7c2be --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-w4vv-pf24-vw92/GHSA-w4vv-pf24-vw92.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4vv-pf24-vw92", + "modified": "2024-11-29T06:35:29Z", + "published": "2024-11-29T06:35:29Z", + "aliases": [ + "CVE-2024-10704" + ], + "details": "The Photo Gallery by 10Web WordPress plugin before 1.8.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10704" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/6c115117-11c0-4c9e-9988-8547c9364c01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T06:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-x4x5-jx9j-mmv7/GHSA-x4x5-jx9j-mmv7.json b/advisories/unreviewed/2024/11/GHSA-x4x5-jx9j-mmv7/GHSA-x4x5-jx9j-mmv7.json new file mode 100644 index 00000000000..5562a436fe2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-x4x5-jx9j-mmv7/GHSA-x4x5-jx9j-mmv7.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x4x5-jx9j-mmv7", + "modified": "2024-11-29T06:35:29Z", + "published": "2024-11-29T06:35:29Z", + "aliases": [ + "CVE-2024-39162" + ], + "details": "pyspider through 0.3.10 allows /update XSS. NOTE: This vulnerability only affects products that are no longer supported by the maintainer", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39162" + }, + { + "type": "WEB", + "url": "https://docs.pyspider.org/en/latest" + }, + { + "type": "WEB", + "url": "https://github.com/binux/pyspider" + }, + { + "type": "WEB", + "url": "https://www.sonarsource.com/blog/basic-http-authentication-risk-uncovering-pyspider-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T06:15:06Z" + } +} \ No newline at end of file