diff --git a/advisories/unreviewed/2024/07/GHSA-44mp-wrcj-wjx3/GHSA-44mp-wrcj-wjx3.json b/advisories/unreviewed/2024/07/GHSA-44mp-wrcj-wjx3/GHSA-44mp-wrcj-wjx3.json new file mode 100644 index 00000000000..e1592c7ccfc --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-44mp-wrcj-wjx3/GHSA-44mp-wrcj-wjx3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44mp-wrcj-wjx3", + "modified": "2024-07-30T18:32:06Z", + "published": "2024-07-30T18:32:06Z", + "aliases": [ + "CVE-2023-26289" + ], + "details": "IBM Aspera Orchestrator 4.0.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 248478.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26289" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/248478" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7161537" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-644" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-52rx-8x3w-4qr2/GHSA-52rx-8x3w-4qr2.json b/advisories/unreviewed/2024/07/GHSA-52rx-8x3w-4qr2/GHSA-52rx-8x3w-4qr2.json new file mode 100644 index 00000000000..ace94069978 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-52rx-8x3w-4qr2/GHSA-52rx-8x3w-4qr2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52rx-8x3w-4qr2", + "modified": "2024-07-30T18:32:06Z", + "published": "2024-07-30T18:32:06Z", + "aliases": [ + "CVE-2024-7209" + ], + "details": "A vulnerability exists in the use of shared SPF records in multi-tenant hosting providers, allowing attackers to use network authorization to be abused to spoof the email identify of the sender.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7209" + }, + { + "type": "WEB", + "url": "https://kb.cert.org/vuls/id/244112" + }, + { + "type": "WEB", + "url": "https://www.kb.cert.org/vuls/id/244112" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-6j6g-j4qm-m9jf/GHSA-6j6g-j4qm-m9jf.json b/advisories/unreviewed/2024/07/GHSA-6j6g-j4qm-m9jf/GHSA-6j6g-j4qm-m9jf.json new file mode 100644 index 00000000000..326e829ce93 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-6j6g-j4qm-m9jf/GHSA-6j6g-j4qm-m9jf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6j6g-j4qm-m9jf", + "modified": "2024-07-30T18:32:06Z", + "published": "2024-07-30T18:32:06Z", + "aliases": [ + "CVE-2024-7297" + ], + "details": "Langflow versions prior to 1.0.13 suffer from a Privilege Escalation vulnerability, allowing a remote and low privileged attacker to gain super admin privileges by performing a mass assignment request on the '/api/v1/users' endpoint.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7297" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/research/tra-2024-26" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-913" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-8482-wc7m-w3q5/GHSA-8482-wc7m-w3q5.json b/advisories/unreviewed/2024/07/GHSA-8482-wc7m-w3q5/GHSA-8482-wc7m-w3q5.json new file mode 100644 index 00000000000..fd65168d2aa --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-8482-wc7m-w3q5/GHSA-8482-wc7m-w3q5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8482-wc7m-w3q5", + "modified": "2024-07-30T18:32:07Z", + "published": "2024-07-30T18:32:07Z", + "aliases": [ + "CVE-2024-41304" + ], + "details": "An arbitrary file upload vulnerability in the uploadFileAction() function of WonderCMS v3.4.3 allows attackers to execute arbitrary code via a crafted SVG file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41304" + }, + { + "type": "WEB", + "url": "https://github.com/patrickdeanramos/WonderCMS-version-3.4.3-SVG-Stored-Cross-Site-Scripting" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-86w3-pw2m-73fq/GHSA-86w3-pw2m-73fq.json b/advisories/unreviewed/2024/07/GHSA-86w3-pw2m-73fq/GHSA-86w3-pw2m-73fq.json new file mode 100644 index 00000000000..af2808adc91 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-86w3-pw2m-73fq/GHSA-86w3-pw2m-73fq.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86w3-pw2m-73fq", + "modified": "2024-07-30T18:32:06Z", + "published": "2024-07-30T18:32:06Z", + "aliases": [ + "CVE-2022-33167" + ], + "details": "IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 228587.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-33167" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/228587" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7161469" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1004" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-8fxj-5f25-469x/GHSA-8fxj-5f25-469x.json b/advisories/unreviewed/2024/07/GHSA-8fxj-5f25-469x/GHSA-8fxj-5f25-469x.json new file mode 100644 index 00000000000..57215742b78 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-8fxj-5f25-469x/GHSA-8fxj-5f25-469x.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8fxj-5f25-469x", + "modified": "2024-07-30T18:32:07Z", + "published": "2024-07-30T18:32:06Z", + "aliases": [ + "CVE-2024-7208" + ], + "details": "Hosted services do not verify the sender of an email against authenticated users, allowing an attacker to spoof the identify of another user's email address.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7208" + }, + { + "type": "WEB", + "url": "https://kb.cert.org/vuls/id/244112" + }, + { + "type": "WEB", + "url": "https://www.kb.cert.org/vuls/id/244112" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-gvgv-928v-rm28/GHSA-gvgv-928v-rm28.json b/advisories/unreviewed/2024/07/GHSA-gvgv-928v-rm28/GHSA-gvgv-928v-rm28.json new file mode 100644 index 00000000000..5545f5ce35e --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-gvgv-928v-rm28/GHSA-gvgv-928v-rm28.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvgv-928v-rm28", + "modified": "2024-07-30T18:32:06Z", + "published": "2024-07-30T18:32:06Z", + "aliases": [ + "CVE-2024-41916" + ], + "details": "A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by ClearPass Policy Manager.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41916" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04675en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-hf55-3qqp-mphm/GHSA-hf55-3qqp-mphm.json b/advisories/unreviewed/2024/07/GHSA-hf55-3qqp-mphm/GHSA-hf55-3qqp-mphm.json new file mode 100644 index 00000000000..3569c5f3bb5 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-hf55-3qqp-mphm/GHSA-hf55-3qqp-mphm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf55-3qqp-mphm", + "modified": "2024-07-30T18:32:06Z", + "published": "2024-07-30T18:32:06Z", + "aliases": [ + "CVE-2024-41915" + ], + "details": "A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit this vulnerability to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the ClearPass Policy Manager cluster.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41915" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04675en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-p38c-8pg2-fqx5/GHSA-p38c-8pg2-fqx5.json b/advisories/unreviewed/2024/07/GHSA-p38c-8pg2-fqx5/GHSA-p38c-8pg2-fqx5.json new file mode 100644 index 00000000000..2365e4279a8 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-p38c-8pg2-fqx5/GHSA-p38c-8pg2-fqx5.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p38c-8pg2-fqx5", + "modified": "2024-07-30T18:32:06Z", + "published": "2024-07-30T18:32:06Z", + "aliases": [ + "CVE-2023-26288" + ], + "details": "IBM Aspera Orchestrator 4.0.1 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 248477.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26288" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/248477" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7161538" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-613" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-p3rw-8f54-fjgc/GHSA-p3rw-8f54-fjgc.json b/advisories/unreviewed/2024/07/GHSA-p3rw-8f54-fjgc/GHSA-p3rw-8f54-fjgc.json new file mode 100644 index 00000000000..d8e162fa086 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-p3rw-8f54-fjgc/GHSA-p3rw-8f54-fjgc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3rw-8f54-fjgc", + "modified": "2024-07-30T18:32:06Z", + "published": "2024-07-30T18:32:06Z", + "aliases": [ + "CVE-2023-38001" + ], + "details": "IBM Aspera Orchestrator 4.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 260206.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38001" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/260206" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7161538" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-ppp5-xp4m-gr3q/GHSA-ppp5-xp4m-gr3q.json b/advisories/unreviewed/2024/07/GHSA-ppp5-xp4m-gr3q/GHSA-ppp5-xp4m-gr3q.json new file mode 100644 index 00000000000..2c40a8b2f98 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-ppp5-xp4m-gr3q/GHSA-ppp5-xp4m-gr3q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ppp5-xp4m-gr3q", + "modified": "2024-07-30T18:32:07Z", + "published": "2024-07-30T18:32:06Z", + "aliases": [ + "CVE-2024-5486" + ], + "details": "A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by ClearPass Policy Manager", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5486" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04675en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-pqmv-6w3c-fgq2/GHSA-pqmv-6w3c-fgq2.json b/advisories/unreviewed/2024/07/GHSA-pqmv-6w3c-fgq2/GHSA-pqmv-6w3c-fgq2.json new file mode 100644 index 00000000000..b890894e749 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-pqmv-6w3c-fgq2/GHSA-pqmv-6w3c-fgq2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqmv-6w3c-fgq2", + "modified": "2024-07-30T18:32:07Z", + "published": "2024-07-30T18:32:07Z", + "aliases": [ + "CVE-2024-41305" + ], + "details": "A Server-Side Request Forgery (SSRF) in the Plugins Page of WonderCMS v3.4.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the pluginThemeUrl parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41305" + }, + { + "type": "WEB", + "url": "https://github.com/patrickdeanramos/WonderCMS-version-3.4.3-is-vulnerable-to-Server-Side-Request-Forgery" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T18:15:05Z" + } +} \ No newline at end of file