From 165c6d3fa9169e4a5bceba6430428879211b2bd8 Mon Sep 17 00:00:00 2001
From: "advisory-database[bot]"
<45398580+advisory-database[bot]@users.noreply.github.com>
Date: Wed, 6 Nov 2024 18:32:03 +0000
Subject: [PATCH] Advisory Database Sync
---
.../GHSA-c2x5-jhjr-43mp.json | 2 +-
.../GHSA-cp83-x35v-hf28.json | 2 +-
.../GHSA-h5rx-j572-xrp9.json | 2 +-
.../GHSA-v686-hww2-hffw.json | 2 +-
.../GHSA-wjj2-vm9f-cg48.json | 2 +-
.../GHSA-m6f4-gmx3-wr5w.json | 2 +-
.../GHSA-4mvh-rcqj-42gx.json | 9 ++--
.../GHSA-5355-6wp2-29w4.json | 9 ++--
.../GHSA-8wcv-54w6-5c6v.json | 9 ++--
.../GHSA-g568-mc4g-cm6f.json | 11 ++--
.../GHSA-hpjc-53pc-jh5v.json | 9 ++--
.../GHSA-mw6g-mf3x-8xg2.json | 11 ++--
.../GHSA-2rqp-mqvp-96gv.json | 11 ++--
.../GHSA-4c64-w6qg-97qw.json | 11 ++--
.../GHSA-4hjm-m2c9-868g.json | 9 ++--
.../GHSA-7xc9-cvgw-h77p.json | 2 +-
.../GHSA-8j2x-98w6-cr3m.json | 11 ++--
.../GHSA-fvm2-fqg3-334j.json | 9 ++--
.../GHSA-g248-66hq-4f22.json | 11 ++--
.../GHSA-g3ch-355r-26mp.json | 11 ++--
.../GHSA-jc3j-vf3f-q43p.json | 9 ++--
.../GHSA-jjpg-4x84-prmp.json | 11 ++--
.../GHSA-m647-h22j-v38q.json | 11 ++--
.../GHSA-mfc2-pm34-9x3q.json | 11 ++--
.../GHSA-mpx6-5vmm-97rr.json | 11 ++--
.../GHSA-mq9m-4hg9-c34x.json | 2 +-
.../GHSA-q96w-v39p-hcjw.json | 11 ++--
.../GHSA-vpfj-63v7-3qcq.json | 9 ++--
.../GHSA-5c46-ggmc-6j5m.json | 9 ++--
.../GHSA-9x83-3j29-pjf2.json | 11 ++--
.../GHSA-fw35-8hjm-jw2p.json | 11 ++--
.../GHSA-g7pg-ghhx-ph55.json | 9 ++--
.../GHSA-hwgv-8256-p54x.json | 9 ++--
.../GHSA-ph95-6589-h2hv.json | 11 ++--
.../GHSA-q8qv-35px-5j77.json | 9 ++--
.../GHSA-qvgv-g72v-425q.json | 9 ++--
.../GHSA-wpgg-qfwq-fwj4.json | 11 ++--
.../GHSA-x5g8-4m4m-8jgf.json | 2 +-
.../GHSA-29pq-gr25-8674.json | 9 ++--
.../GHSA-2r8j-rf53-9g72.json | 9 ++--
.../GHSA-5g4g-hgmr-mqrx.json | 9 ++--
.../GHSA-5mwv-x2qc-g5cj.json | 9 ++--
.../GHSA-7m8f-jj48-x349.json | 9 ++--
.../GHSA-8qjm-4vw9-3w5g.json | 9 ++--
.../GHSA-gjv4-282p-cm98.json | 9 ++--
.../GHSA-mcp4-w22q-6q4h.json | 9 ++--
.../GHSA-pqp3-8qxf-mjx8.json | 9 ++--
.../GHSA-rmx7-cw76-79w4.json | 9 ++--
.../GHSA-vx2v-mjff-9hjf.json | 9 ++--
.../GHSA-wpgm-g43f-rx6f.json | 11 ++--
.../GHSA-x9mx-786j-jh4p.json | 11 ++--
.../GHSA-xhf8-m475-367r.json | 9 ++--
.../GHSA-gjhw-gp72-3cj2.json | 9 ++--
.../GHSA-h8fv-x4w5-c9mc.json | 11 ++--
.../GHSA-hxp8-xjhv-r6wv.json | 11 ++--
.../GHSA-mc7v-wpqv-v4g2.json | 9 ++--
.../GHSA-mqxf-7jx4-2h8p.json | 9 ++--
.../GHSA-x3jm-2wx8-ccv4.json | 9 ++--
.../GHSA-6fq4-3v58-2pfx.json | 11 ++--
.../GHSA-x2q3-f99c-25ff.json | 11 ++--
.../GHSA-prg4-487r-rr8w.json | 11 ++--
.../GHSA-qpx5-6ww4-hp56.json | 2 +-
.../GHSA-32jw-rrh7-q59g.json | 2 +-
.../GHSA-5362-r6fh-h45f.json | 6 ++-
.../GHSA-8c7g-vx5g-cmpg.json | 11 ++--
.../GHSA-w88c-j332-rfjj.json | 11 ++--
.../GHSA-36q8-mfw8-2m98.json | 9 ++--
.../GHSA-38gf-q933-q62g.json | 38 +++++++++++++
.../GHSA-3c6f-r64x-4f7r.json | 38 +++++++++++++
.../GHSA-3f53-hv33-hf39.json | 38 +++++++++++++
.../GHSA-47cf-pjqq-7626.json | 38 +++++++++++++
.../GHSA-4p84-57xr-x7v6.json | 2 +-
.../GHSA-5589-5vr7-rjh2.json | 38 +++++++++++++
.../GHSA-58wv-w3hc-2c76.json | 42 +++++++++++++++
.../GHSA-5grf-38mv-vxvv.json | 11 ++--
.../GHSA-5h6c-4hvj-43pr.json | 2 +-
.../GHSA-5w27-pxmv-rgxx.json | 38 +++++++++++++
.../GHSA-5x5j-83rp-44hj.json | 38 +++++++++++++
.../GHSA-62f5-j9hj-j5w2.json | 2 +-
.../GHSA-66rq-9x8p-ghcr.json | 2 +-
.../GHSA-6xw2-v987-mq7h.json | 54 +++++++++++++++++++
.../GHSA-75gp-f39c-g44v.json | 11 ++--
.../GHSA-7v36-f3gj-qcg5.json | 54 +++++++++++++++++++
.../GHSA-7wfp-w5xf-g7mm.json | 42 +++++++++++++++
.../GHSA-8mqv-23wv-wqfg.json | 42 +++++++++++++++
.../GHSA-8qc4-f7m5-569p.json | 2 +-
.../GHSA-8xq5-r7g5-m3f8.json | 38 +++++++++++++
.../GHSA-9m98-8pf8-hfc4.json | 38 +++++++++++++
.../GHSA-cgwv-mmpx-f92h.json | 38 +++++++++++++
.../GHSA-cjhr-gw79-v8fh.json | 11 ++--
.../GHSA-cjrc-86h3-3hxh.json | 4 +-
.../GHSA-fj4q-693m-8fx4.json | 38 +++++++++++++
.../GHSA-fqm6-hhvg-fmrr.json | 38 +++++++++++++
.../GHSA-g337-g667-mjvw.json | 9 ++--
.../GHSA-gcp7-c8fr-5c36.json | 38 +++++++++++++
.../GHSA-gpj2-23jf-pgq2.json | 1 +
.../GHSA-hg63-44hg-r9q3.json | 4 +-
.../GHSA-hm9x-5qmp-g6fq.json | 11 ++--
.../GHSA-hmw9-9w7c-2pm4.json | 38 +++++++++++++
.../GHSA-hrrg-wvpp-2p2q.json | 11 ++--
.../GHSA-hv6m-qj65-26q3.json | 43 +++++++++++++++
.../GHSA-jghq-wq8j-hqc4.json | 7 ++-
.../GHSA-jhvq-gr6c-9fw6.json | 38 +++++++++++++
.../GHSA-jvmc-2wg5-j9pw.json | 38 +++++++++++++
.../GHSA-mwr4-4gh4-7m8j.json | 38 +++++++++++++
.../GHSA-p53v-8c78-56qf.json | 38 +++++++++++++
.../GHSA-p7hr-frqp-rm5j.json | 38 +++++++++++++
.../GHSA-q5mq-2xwr-j447.json | 11 ++--
.../GHSA-q79j-6grx-x9p9.json | 2 +-
.../GHSA-q7hr-x75r-2mp7.json | 38 +++++++++++++
.../GHSA-qh2h-wv23-f83f.json | 2 +-
.../GHSA-qjmh-rvm8-v24c.json | 38 +++++++++++++
.../GHSA-qvc8-jp6r-8639.json | 11 ++--
.../GHSA-qx29-vw3w-p54v.json | 9 ++--
.../GHSA-r49w-9hvc-8fg7.json | 38 +++++++++++++
.../GHSA-r6pw-ffg9-984j.json | 38 +++++++++++++
.../GHSA-r8cr-jx69-43ff.json | 11 ++--
.../GHSA-rg92-pqp9-j6jp.json | 38 +++++++++++++
.../GHSA-rv5p-p324-cxv2.json | 38 +++++++++++++
.../GHSA-w9pr-cvj2-cxfc.json | 11 ++--
.../GHSA-wjjv-5wqm-9j59.json | 6 ++-
.../GHSA-xqww-45ww-cw2p.json | 12 +++--
122 files changed, 1704 insertions(+), 261 deletions(-)
create mode 100644 advisories/unreviewed/2024/11/GHSA-38gf-q933-q62g/GHSA-38gf-q933-q62g.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-3c6f-r64x-4f7r/GHSA-3c6f-r64x-4f7r.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-3f53-hv33-hf39/GHSA-3f53-hv33-hf39.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-47cf-pjqq-7626/GHSA-47cf-pjqq-7626.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-5589-5vr7-rjh2/GHSA-5589-5vr7-rjh2.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-58wv-w3hc-2c76/GHSA-58wv-w3hc-2c76.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-5w27-pxmv-rgxx/GHSA-5w27-pxmv-rgxx.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-5x5j-83rp-44hj/GHSA-5x5j-83rp-44hj.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-6xw2-v987-mq7h/GHSA-6xw2-v987-mq7h.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-7v36-f3gj-qcg5/GHSA-7v36-f3gj-qcg5.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-7wfp-w5xf-g7mm/GHSA-7wfp-w5xf-g7mm.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-8mqv-23wv-wqfg/GHSA-8mqv-23wv-wqfg.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-8xq5-r7g5-m3f8/GHSA-8xq5-r7g5-m3f8.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-9m98-8pf8-hfc4/GHSA-9m98-8pf8-hfc4.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-cgwv-mmpx-f92h/GHSA-cgwv-mmpx-f92h.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-fj4q-693m-8fx4/GHSA-fj4q-693m-8fx4.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-fqm6-hhvg-fmrr/GHSA-fqm6-hhvg-fmrr.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-gcp7-c8fr-5c36/GHSA-gcp7-c8fr-5c36.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-hmw9-9w7c-2pm4/GHSA-hmw9-9w7c-2pm4.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-hv6m-qj65-26q3/GHSA-hv6m-qj65-26q3.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-jhvq-gr6c-9fw6/GHSA-jhvq-gr6c-9fw6.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-jvmc-2wg5-j9pw/GHSA-jvmc-2wg5-j9pw.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-mwr4-4gh4-7m8j/GHSA-mwr4-4gh4-7m8j.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-p53v-8c78-56qf/GHSA-p53v-8c78-56qf.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-p7hr-frqp-rm5j/GHSA-p7hr-frqp-rm5j.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-q7hr-x75r-2mp7/GHSA-q7hr-x75r-2mp7.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-qjmh-rvm8-v24c/GHSA-qjmh-rvm8-v24c.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-r49w-9hvc-8fg7/GHSA-r49w-9hvc-8fg7.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-r6pw-ffg9-984j/GHSA-r6pw-ffg9-984j.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-rg92-pqp9-j6jp/GHSA-rg92-pqp9-j6jp.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-rv5p-p324-cxv2/GHSA-rv5p-p324-cxv2.json
diff --git a/advisories/unreviewed/2023/07/GHSA-c2x5-jhjr-43mp/GHSA-c2x5-jhjr-43mp.json b/advisories/unreviewed/2023/07/GHSA-c2x5-jhjr-43mp/GHSA-c2x5-jhjr-43mp.json
index c2c5625cf48..e47a57ccba3 100644
--- a/advisories/unreviewed/2023/07/GHSA-c2x5-jhjr-43mp/GHSA-c2x5-jhjr-43mp.json
+++ b/advisories/unreviewed/2023/07/GHSA-c2x5-jhjr-43mp/GHSA-c2x5-jhjr-43mp.json
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-384"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2023/07/GHSA-cp83-x35v-hf28/GHSA-cp83-x35v-hf28.json b/advisories/unreviewed/2023/07/GHSA-cp83-x35v-hf28/GHSA-cp83-x35v-hf28.json
index 423de777e8a..9adb5887866 100644
--- a/advisories/unreviewed/2023/07/GHSA-cp83-x35v-hf28/GHSA-cp83-x35v-hf28.json
+++ b/advisories/unreviewed/2023/07/GHSA-cp83-x35v-hf28/GHSA-cp83-x35v-hf28.json
@@ -40,7 +40,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-611"
],
"severity": "CRITICAL",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2023/07/GHSA-h5rx-j572-xrp9/GHSA-h5rx-j572-xrp9.json b/advisories/unreviewed/2023/07/GHSA-h5rx-j572-xrp9/GHSA-h5rx-j572-xrp9.json
index e23d02926b0..3bcc71e9b6e 100644
--- a/advisories/unreviewed/2023/07/GHSA-h5rx-j572-xrp9/GHSA-h5rx-j572-xrp9.json
+++ b/advisories/unreviewed/2023/07/GHSA-h5rx-j572-xrp9/GHSA-h5rx-j572-xrp9.json
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-863"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2023/07/GHSA-v686-hww2-hffw/GHSA-v686-hww2-hffw.json b/advisories/unreviewed/2023/07/GHSA-v686-hww2-hffw/GHSA-v686-hww2-hffw.json
index 8ee0143e1e1..4a46600d3ed 100644
--- a/advisories/unreviewed/2023/07/GHSA-v686-hww2-hffw/GHSA-v686-hww2-hffw.json
+++ b/advisories/unreviewed/2023/07/GHSA-v686-hww2-hffw/GHSA-v686-hww2-hffw.json
@@ -40,7 +40,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-326"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2023/07/GHSA-wjj2-vm9f-cg48/GHSA-wjj2-vm9f-cg48.json b/advisories/unreviewed/2023/07/GHSA-wjj2-vm9f-cg48/GHSA-wjj2-vm9f-cg48.json
index bd7e5095fd1..68d4710ec95 100644
--- a/advisories/unreviewed/2023/07/GHSA-wjj2-vm9f-cg48/GHSA-wjj2-vm9f-cg48.json
+++ b/advisories/unreviewed/2023/07/GHSA-wjj2-vm9f-cg48/GHSA-wjj2-vm9f-cg48.json
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-384"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2023/08/GHSA-m6f4-gmx3-wr5w/GHSA-m6f4-gmx3-wr5w.json b/advisories/unreviewed/2023/08/GHSA-m6f4-gmx3-wr5w/GHSA-m6f4-gmx3-wr5w.json
index 489d22b33d2..bf4b6705859 100644
--- a/advisories/unreviewed/2023/08/GHSA-m6f4-gmx3-wr5w/GHSA-m6f4-gmx3-wr5w.json
+++ b/advisories/unreviewed/2023/08/GHSA-m6f4-gmx3-wr5w/GHSA-m6f4-gmx3-wr5w.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-863"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/02/GHSA-4mvh-rcqj-42gx/GHSA-4mvh-rcqj-42gx.json b/advisories/unreviewed/2024/02/GHSA-4mvh-rcqj-42gx/GHSA-4mvh-rcqj-42gx.json
index b3cce329f5a..7f41f6fddf6 100644
--- a/advisories/unreviewed/2024/02/GHSA-4mvh-rcqj-42gx/GHSA-4mvh-rcqj-42gx.json
+++ b/advisories/unreviewed/2024/02/GHSA-4mvh-rcqj-42gx/GHSA-4mvh-rcqj-42gx.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4mvh-rcqj-42gx",
- "modified": "2024-02-28T09:30:36Z",
+ "modified": "2024-11-06T18:31:03Z",
"published": "2024-02-28T09:30:36Z",
"aliases": [
"CVE-2020-36780"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: sprd: fix reference leak when pm_runtime_get_sync fails\n\nThe PM reference count is not expected to be incremented on\nreturn in sprd_i2c_master_xfer() and sprd_i2c_remove().\n\nHowever, pm_runtime_get_sync will increment the PM reference\ncount even failed. Forgetting to putting operation will result\nin a reference leak here.\n\nReplace it with pm_runtime_resume_and_get to keep usage\ncounter balanced.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -43,7 +46,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-28T09:15:36Z"
diff --git a/advisories/unreviewed/2024/02/GHSA-5355-6wp2-29w4/GHSA-5355-6wp2-29w4.json b/advisories/unreviewed/2024/02/GHSA-5355-6wp2-29w4/GHSA-5355-6wp2-29w4.json
index f3e05ad2f64..157778241cb 100644
--- a/advisories/unreviewed/2024/02/GHSA-5355-6wp2-29w4/GHSA-5355-6wp2-29w4.json
+++ b/advisories/unreviewed/2024/02/GHSA-5355-6wp2-29w4/GHSA-5355-6wp2-29w4.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5355-6wp2-29w4",
- "modified": "2024-04-19T09:30:47Z",
+ "modified": "2024-11-06T18:31:02Z",
"published": "2024-02-19T06:30:33Z",
"aliases": [
"CVE-2024-26328"
],
"details": "An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c does not set NumVFs to PCI_SRIOV_TOTAL_VF, and thus interaction with hw/nvme/ctrl.c is mishandled.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-19T05:15:26Z"
diff --git a/advisories/unreviewed/2024/02/GHSA-8wcv-54w6-5c6v/GHSA-8wcv-54w6-5c6v.json b/advisories/unreviewed/2024/02/GHSA-8wcv-54w6-5c6v/GHSA-8wcv-54w6-5c6v.json
index 688cb77d312..eb39ba5bf9f 100644
--- a/advisories/unreviewed/2024/02/GHSA-8wcv-54w6-5c6v/GHSA-8wcv-54w6-5c6v.json
+++ b/advisories/unreviewed/2024/02/GHSA-8wcv-54w6-5c6v/GHSA-8wcv-54w6-5c6v.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8wcv-54w6-5c6v",
- "modified": "2024-02-21T09:31:00Z",
+ "modified": "2024-11-06T18:31:02Z",
"published": "2024-02-21T09:31:00Z",
"aliases": [
"CVE-2023-42834"
],
"details": "A privacy issue was addressed with improved handling of files. This issue is fixed in watchOS 10.1, macOS Sonoma 14.1, macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.1 and iPadOS 17.1. An app may be able to access sensitive user data.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -43,7 +46,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-21T07:15:47Z"
diff --git a/advisories/unreviewed/2024/02/GHSA-g568-mc4g-cm6f/GHSA-g568-mc4g-cm6f.json b/advisories/unreviewed/2024/02/GHSA-g568-mc4g-cm6f/GHSA-g568-mc4g-cm6f.json
index 45bf875276f..cbd2d10c7e8 100644
--- a/advisories/unreviewed/2024/02/GHSA-g568-mc4g-cm6f/GHSA-g568-mc4g-cm6f.json
+++ b/advisories/unreviewed/2024/02/GHSA-g568-mc4g-cm6f/GHSA-g568-mc4g-cm6f.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g568-mc4g-cm6f",
- "modified": "2024-02-29T03:33:18Z",
+ "modified": "2024-11-06T18:31:03Z",
"published": "2024-02-29T03:33:18Z",
"aliases": [
"CVE-2024-26473"
],
"details": "A reflected cross-site scripting (XSS) vulnerability in SocialMediaWebsite v1.0.1 allows attackers to inject malicious JavaScript into the web browser of a victim via the poll parameter in poll.php.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-29T01:44:19Z"
diff --git a/advisories/unreviewed/2024/02/GHSA-hpjc-53pc-jh5v/GHSA-hpjc-53pc-jh5v.json b/advisories/unreviewed/2024/02/GHSA-hpjc-53pc-jh5v/GHSA-hpjc-53pc-jh5v.json
index 76c9531ac1d..d38a3c50463 100644
--- a/advisories/unreviewed/2024/02/GHSA-hpjc-53pc-jh5v/GHSA-hpjc-53pc-jh5v.json
+++ b/advisories/unreviewed/2024/02/GHSA-hpjc-53pc-jh5v/GHSA-hpjc-53pc-jh5v.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hpjc-53pc-jh5v",
- "modified": "2024-02-21T15:30:45Z",
+ "modified": "2024-11-06T18:31:03Z",
"published": "2024-02-21T15:30:45Z",
"aliases": [
"CVE-2024-22778"
],
"details": "HackMD CodiMD <2.5.2 is vulnerable to Denial of Service.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-21T15:15:09Z"
diff --git a/advisories/unreviewed/2024/02/GHSA-mw6g-mf3x-8xg2/GHSA-mw6g-mf3x-8xg2.json b/advisories/unreviewed/2024/02/GHSA-mw6g-mf3x-8xg2/GHSA-mw6g-mf3x-8xg2.json
index d54c3777f25..520a6d983d8 100644
--- a/advisories/unreviewed/2024/02/GHSA-mw6g-mf3x-8xg2/GHSA-mw6g-mf3x-8xg2.json
+++ b/advisories/unreviewed/2024/02/GHSA-mw6g-mf3x-8xg2/GHSA-mw6g-mf3x-8xg2.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mw6g-mf3x-8xg2",
- "modified": "2024-02-26T18:30:31Z",
+ "modified": "2024-11-06T18:31:03Z",
"published": "2024-02-26T18:30:31Z",
"aliases": [
"CVE-2024-26468"
],
"details": "A DOM based cross-site scripting (XSS) vulnerability in the component index.html of jstrieb/urlpages before commit 035b647 allows attackers to execute arbitrary Javascript via sending a crafted URL.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-26T16:27:59Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-2rqp-mqvp-96gv/GHSA-2rqp-mqvp-96gv.json b/advisories/unreviewed/2024/03/GHSA-2rqp-mqvp-96gv/GHSA-2rqp-mqvp-96gv.json
index b84f319910b..edacb6c1b4e 100644
--- a/advisories/unreviewed/2024/03/GHSA-2rqp-mqvp-96gv/GHSA-2rqp-mqvp-96gv.json
+++ b/advisories/unreviewed/2024/03/GHSA-2rqp-mqvp-96gv/GHSA-2rqp-mqvp-96gv.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2rqp-mqvp-96gv",
- "modified": "2024-03-27T06:30:31Z",
+ "modified": "2024-11-06T18:31:04Z",
"published": "2024-03-27T06:30:31Z",
"aliases": [
"CVE-2023-45929"
],
"details": "S-Lang 2.3.2 was discovered to contain a segmentation fault via the function fixup_tgetstr().",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-120"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-27T04:15:11Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-4c64-w6qg-97qw/GHSA-4c64-w6qg-97qw.json b/advisories/unreviewed/2024/03/GHSA-4c64-w6qg-97qw/GHSA-4c64-w6qg-97qw.json
index a78538a42c7..e1ac847b5a5 100644
--- a/advisories/unreviewed/2024/03/GHSA-4c64-w6qg-97qw/GHSA-4c64-w6qg-97qw.json
+++ b/advisories/unreviewed/2024/03/GHSA-4c64-w6qg-97qw/GHSA-4c64-w6qg-97qw.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4c64-w6qg-97qw",
- "modified": "2024-03-03T00:30:32Z",
+ "modified": "2024-11-06T18:31:03Z",
"published": "2024-03-03T00:30:32Z",
"aliases": [
"CVE-2023-52566"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix potential use after free in nilfs_gccache_submit_read_data()\n\nIn nilfs_gccache_submit_read_data(), brelse(bh) is called to drop the\nreference count of bh when the call to nilfs_dat_translate() fails. If\nthe reference count hits 0 and its owner page gets unlocked, bh may be\nfreed. However, bh->b_page is dereferenced to put the page after that,\nwhich may result in a use-after-free bug. This patch moves the release\noperation after unlocking and putting the page.\n\nNOTE: The function in question is only called in GC, and in combination\nwith current userland tools, address translation using DAT does not occur\nin that function, so the code path that causes this issue will not be\nexecuted. However, it is possible to run that code path by intentionally\nmodifying the userland GC library or by calling the GC ioctl directly.\n\n[konishi.ryusuke@gmail.com: NOTE added to the commit log]",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -53,9 +56,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-416"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-02T22:15:49Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-4hjm-m2c9-868g/GHSA-4hjm-m2c9-868g.json b/advisories/unreviewed/2024/03/GHSA-4hjm-m2c9-868g/GHSA-4hjm-m2c9-868g.json
index da80d72bb3b..6b878fcd1e5 100644
--- a/advisories/unreviewed/2024/03/GHSA-4hjm-m2c9-868g/GHSA-4hjm-m2c9-868g.json
+++ b/advisories/unreviewed/2024/03/GHSA-4hjm-m2c9-868g/GHSA-4hjm-m2c9-868g.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4hjm-m2c9-868g",
- "modified": "2024-03-03T00:30:32Z",
+ "modified": "2024-11-06T18:31:03Z",
"published": "2024-03-03T00:30:32Z",
"aliases": [
"CVE-2023-52571"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: rk817: Fix node refcount leak\n\nDan Carpenter reports that the Smatch static checker warning has found\nthat there is another refcount leak in the probe function. While\nof_node_put() was added in one of the return paths, it should in\nfact be added for ALL return paths that return an error and at driver\nremoval time.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
+ }
],
"affected": [
@@ -35,7 +38,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-02T22:15:49Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-7xc9-cvgw-h77p/GHSA-7xc9-cvgw-h77p.json b/advisories/unreviewed/2024/03/GHSA-7xc9-cvgw-h77p/GHSA-7xc9-cvgw-h77p.json
index 2daa44b886b..9cfa57946b3 100644
--- a/advisories/unreviewed/2024/03/GHSA-7xc9-cvgw-h77p/GHSA-7xc9-cvgw-h77p.json
+++ b/advisories/unreviewed/2024/03/GHSA-7xc9-cvgw-h77p/GHSA-7xc9-cvgw-h77p.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-770"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/03/GHSA-8j2x-98w6-cr3m/GHSA-8j2x-98w6-cr3m.json b/advisories/unreviewed/2024/03/GHSA-8j2x-98w6-cr3m/GHSA-8j2x-98w6-cr3m.json
index 786cd980e85..33979b6fea6 100644
--- a/advisories/unreviewed/2024/03/GHSA-8j2x-98w6-cr3m/GHSA-8j2x-98w6-cr3m.json
+++ b/advisories/unreviewed/2024/03/GHSA-8j2x-98w6-cr3m/GHSA-8j2x-98w6-cr3m.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8j2x-98w6-cr3m",
- "modified": "2024-03-03T00:30:31Z",
+ "modified": "2024-11-06T18:31:03Z",
"published": "2024-03-03T00:30:31Z",
"aliases": [
"CVE-2023-52512"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\npinctrl: nuvoton: wpcm450: fix out of bounds write\n\nWrite into 'pctrl->gpio_bank' happens before the check for GPIO index\nvalidity, so out of bounds write may happen.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-787"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-02T22:15:47Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-fvm2-fqg3-334j/GHSA-fvm2-fqg3-334j.json b/advisories/unreviewed/2024/03/GHSA-fvm2-fqg3-334j/GHSA-fvm2-fqg3-334j.json
index 81b198c8842..18592cf7252 100644
--- a/advisories/unreviewed/2024/03/GHSA-fvm2-fqg3-334j/GHSA-fvm2-fqg3-334j.json
+++ b/advisories/unreviewed/2024/03/GHSA-fvm2-fqg3-334j/GHSA-fvm2-fqg3-334j.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fvm2-fqg3-334j",
- "modified": "2024-03-14T00:31:05Z",
+ "modified": "2024-11-06T18:31:03Z",
"published": "2024-03-08T03:31:25Z",
"aliases": [
"CVE-2024-23289"
],
"details": "A lock screen issue was addressed with improved state management. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. A person with physical access to a device may be able to use Siri to access private calendar information.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -47,7 +50,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-08T02:15:50Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-g248-66hq-4f22/GHSA-g248-66hq-4f22.json b/advisories/unreviewed/2024/03/GHSA-g248-66hq-4f22/GHSA-g248-66hq-4f22.json
index ac54e1952a7..5056592093b 100644
--- a/advisories/unreviewed/2024/03/GHSA-g248-66hq-4f22/GHSA-g248-66hq-4f22.json
+++ b/advisories/unreviewed/2024/03/GHSA-g248-66hq-4f22/GHSA-g248-66hq-4f22.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g248-66hq-4f22",
- "modified": "2024-03-11T18:31:10Z",
+ "modified": "2024-11-06T18:31:03Z",
"published": "2024-03-11T18:31:09Z",
"aliases": [
"CVE-2024-26612"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs, fscache: Prevent Oops in fscache_put_cache()\n\nThis function dereferences \"cache\" and then checks if it's\nIS_ERR_OR_NULL(). Check first, then dereference.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-476"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-11T18:15:19Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-g3ch-355r-26mp/GHSA-g3ch-355r-26mp.json b/advisories/unreviewed/2024/03/GHSA-g3ch-355r-26mp/GHSA-g3ch-355r-26mp.json
index da50425cdc1..ec4a6c3a83c 100644
--- a/advisories/unreviewed/2024/03/GHSA-g3ch-355r-26mp/GHSA-g3ch-355r-26mp.json
+++ b/advisories/unreviewed/2024/03/GHSA-g3ch-355r-26mp/GHSA-g3ch-355r-26mp.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g3ch-355r-26mp",
- "modified": "2024-06-27T15:30:38Z",
+ "modified": "2024-11-06T18:31:03Z",
"published": "2024-03-06T09:30:26Z",
"aliases": [
"CVE-2023-52585"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix possible NULL dereference in amdgpu_ras_query_error_status_helper()\n\nReturn invalid error code -EINVAL for invalid block id.\n\nFixes the below:\n\ndrivers/gpu/drm/amd/amdgpu/amdgpu_ras.c:1183 amdgpu_ras_query_error_status_helper() error: we previously assumed 'info' could be null (see line 1176)",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -53,9 +56,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-476"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-06T07:15:07Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-jc3j-vf3f-q43p/GHSA-jc3j-vf3f-q43p.json b/advisories/unreviewed/2024/03/GHSA-jc3j-vf3f-q43p/GHSA-jc3j-vf3f-q43p.json
index 32ff5100d18..09e29950301 100644
--- a/advisories/unreviewed/2024/03/GHSA-jc3j-vf3f-q43p/GHSA-jc3j-vf3f-q43p.json
+++ b/advisories/unreviewed/2024/03/GHSA-jc3j-vf3f-q43p/GHSA-jc3j-vf3f-q43p.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jc3j-vf3f-q43p",
- "modified": "2024-06-26T00:31:35Z",
+ "modified": "2024-11-06T18:31:03Z",
"published": "2024-03-11T18:31:09Z",
"aliases": [
"CVE-2024-26614"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: make sure init the accept_queue's spinlocks once\n\nWhen I run syz's reproduction C program locally, it causes the following\nissue:\npvqspinlock: lock 0xffff9d181cd5c660 has corrupted value 0x0!\nWARNING: CPU: 19 PID: 21160 at __pv_queued_spin_unlock_slowpath (kernel/locking/qspinlock_paravirt.h:508)\nHardware name: Red Hat KVM, BIOS 0.5.1 01/01/2011\nRIP: 0010:__pv_queued_spin_unlock_slowpath (kernel/locking/qspinlock_paravirt.h:508)\nCode: 73 56 3a ff 90 c3 cc cc cc cc 8b 05 bb 1f 48 01 85 c0 74 05 c3 cc cc cc cc 8b 17 48 89 fe 48 c7 c7\n30 20 ce 8f e8 ad 56 42 ff <0f> 0b c3 cc cc cc cc 0f 0b 0f 1f 40 00 90 90 90 90 90 90 90 90 90\nRSP: 0018:ffffa8d200604cb8 EFLAGS: 00010282\nRAX: 0000000000000000 RBX: 0000000000000000 RCX: ffff9d1ef60e0908\nRDX: 00000000ffffffd8 RSI: 0000000000000027 RDI: ffff9d1ef60e0900\nRBP: ffff9d181cd5c280 R08: 0000000000000000 R09: 00000000ffff7fff\nR10: ffffa8d200604b68 R11: ffffffff907dcdc8 R12: 0000000000000000\nR13: ffff9d181cd5c660 R14: ffff9d1813a3f330 R15: 0000000000001000\nFS: 00007fa110184640(0000) GS:ffff9d1ef60c0000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000020000000 CR3: 000000011f65e000 CR4: 00000000000006f0\nCall Trace:\n\n _raw_spin_unlock (kernel/locking/spinlock.c:186)\n inet_csk_reqsk_queue_add (net/ipv4/inet_connection_sock.c:1321)\n inet_csk_complete_hashdance (net/ipv4/inet_connection_sock.c:1358)\n tcp_check_req (net/ipv4/tcp_minisocks.c:868)\n tcp_v4_rcv (net/ipv4/tcp_ipv4.c:2260)\n ip_protocol_deliver_rcu (net/ipv4/ip_input.c:205)\n ip_local_deliver_finish (net/ipv4/ip_input.c:234)\n __netif_receive_skb_one_core (net/core/dev.c:5529)\n process_backlog (./include/linux/rcupdate.h:779)\n __napi_poll (net/core/dev.c:6533)\n net_rx_action (net/core/dev.c:6604)\n __do_softirq (./arch/x86/include/asm/jump_label.h:27)\n do_softirq (kernel/softirq.c:454 kernel/softirq.c:441)\n\n\n __local_bh_enable_ip (kernel/softirq.c:381)\n __dev_queue_xmit (net/core/dev.c:4374)\n ip_finish_output2 (./include/net/neighbour.h:540 net/ipv4/ip_output.c:235)\n __ip_queue_xmit (net/ipv4/ip_output.c:535)\n __tcp_transmit_skb (net/ipv4/tcp_output.c:1462)\n tcp_rcv_synsent_state_process (net/ipv4/tcp_input.c:6469)\n tcp_rcv_state_process (net/ipv4/tcp_input.c:6657)\n tcp_v4_do_rcv (net/ipv4/tcp_ipv4.c:1929)\n __release_sock (./include/net/sock.h:1121 net/core/sock.c:2968)\n release_sock (net/core/sock.c:3536)\n inet_wait_for_connect (net/ipv4/af_inet.c:609)\n __inet_stream_connect (net/ipv4/af_inet.c:702)\n inet_stream_connect (net/ipv4/af_inet.c:748)\n __sys_connect (./include/linux/file.h:45 net/socket.c:2064)\n __x64_sys_connect (net/socket.c:2073 net/socket.c:2070 net/socket.c:2070)\n do_syscall_64 (arch/x86/entry/common.c:51 arch/x86/entry/common.c:82)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:129)\n RIP: 0033:0x7fa10ff05a3d\n Code: 5b 41 5c c3 66 0f 1f 84 00 00 00 00 00 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89\n c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d ab a3 0e 00 f7 d8 64 89 01 48\n RSP: 002b:00007fa110183de8 EFLAGS: 00000202 ORIG_RAX: 000000000000002a\n RAX: ffffffffffffffda RBX: 0000000020000054 RCX: 00007fa10ff05a3d\n RDX: 000000000000001c RSI: 0000000020000040 RDI: 0000000000000003\n RBP: 00007fa110183e20 R08: 0000000000000000 R09: 0000000000000000\n R10: 0000000000000000 R11: 0000000000000202 R12: 00007fa110184640\n R13: 0000000000000000 R14: 00007fa10fe8b060 R15: 00007fff73e23b20\n\n\nThe issue triggering process is analyzed as follows:\nThread A Thread B\ntcp_v4_rcv\t//receive ack TCP packet inet_shutdown\n tcp_check_req tcp_disconnect //disconnect sock\n ... tcp_set_state(sk, TCP_CLOSE)\n inet_csk_complete_hashdance ...\n inet_csk_reqsk_queue_add \n---truncated---",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -51,7 +54,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-11T18:15:19Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-jjpg-4x84-prmp/GHSA-jjpg-4x84-prmp.json b/advisories/unreviewed/2024/03/GHSA-jjpg-4x84-prmp/GHSA-jjpg-4x84-prmp.json
index 5a8c1d61fbc..203eb0c20e9 100644
--- a/advisories/unreviewed/2024/03/GHSA-jjpg-4x84-prmp/GHSA-jjpg-4x84-prmp.json
+++ b/advisories/unreviewed/2024/03/GHSA-jjpg-4x84-prmp/GHSA-jjpg-4x84-prmp.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jjpg-4x84-prmp",
- "modified": "2024-03-25T12:30:51Z",
+ "modified": "2024-11-06T18:31:04Z",
"published": "2024-03-25T12:30:51Z",
"aliases": [
"CVE-2021-47161"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: spi-fsl-dspi: Fix a resource leak in an error handling path\n\n'dspi_request_dma()' should be undone by a 'dspi_release_dma()' call in the\nerror handling path of the probe function, as already done in the remove\nfunction",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -45,9 +48,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-209"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T10:15:08Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-m647-h22j-v38q/GHSA-m647-h22j-v38q.json b/advisories/unreviewed/2024/03/GHSA-m647-h22j-v38q/GHSA-m647-h22j-v38q.json
index 51903b708ce..c609fdec10d 100644
--- a/advisories/unreviewed/2024/03/GHSA-m647-h22j-v38q/GHSA-m647-h22j-v38q.json
+++ b/advisories/unreviewed/2024/03/GHSA-m647-h22j-v38q/GHSA-m647-h22j-v38q.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m647-h22j-v38q",
- "modified": "2024-03-01T00:30:28Z",
+ "modified": "2024-11-06T18:31:03Z",
"published": "2024-03-01T00:30:28Z",
"aliases": [
"CVE-2021-47057"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: sun8i-ss - Fix memory leak of object d when dma_iv fails to map\n\nIn the case where the dma_iv mapping fails, the return error path leaks\nthe memory allocated to object d. Fix this by adding a new error return\nlabel and jumping to this to ensure d is free'd before the return.\n\nAddresses-Coverity: (\"Resource leak\")",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-770"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-29T23:15:07Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-mfc2-pm34-9x3q/GHSA-mfc2-pm34-9x3q.json b/advisories/unreviewed/2024/03/GHSA-mfc2-pm34-9x3q/GHSA-mfc2-pm34-9x3q.json
index d49058f42b8..a45839c77ac 100644
--- a/advisories/unreviewed/2024/03/GHSA-mfc2-pm34-9x3q/GHSA-mfc2-pm34-9x3q.json
+++ b/advisories/unreviewed/2024/03/GHSA-mfc2-pm34-9x3q/GHSA-mfc2-pm34-9x3q.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mfc2-pm34-9x3q",
- "modified": "2024-03-11T21:31:27Z",
+ "modified": "2024-11-06T18:31:03Z",
"published": "2024-03-11T21:31:27Z",
"aliases": [
"CVE-2024-27235"
],
"details": "In plugin_extern_func of TBD, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-125"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-11T19:15:49Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-mpx6-5vmm-97rr/GHSA-mpx6-5vmm-97rr.json b/advisories/unreviewed/2024/03/GHSA-mpx6-5vmm-97rr/GHSA-mpx6-5vmm-97rr.json
index 3e371b3bb78..ce6ebb90963 100644
--- a/advisories/unreviewed/2024/03/GHSA-mpx6-5vmm-97rr/GHSA-mpx6-5vmm-97rr.json
+++ b/advisories/unreviewed/2024/03/GHSA-mpx6-5vmm-97rr/GHSA-mpx6-5vmm-97rr.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mpx6-5vmm-97rr",
- "modified": "2024-03-25T12:30:52Z",
+ "modified": "2024-11-06T18:31:04Z",
"published": "2024-03-25T12:30:52Z",
"aliases": [
"CVE-2021-47172"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: ad7124: Fix potential overflow due to non sequential channel numbers\n\nChannel numbering must start at 0 and then not have any holes, or\nit is possible to overflow the available storage. Note this bug was\nintroduced as part of a fix to ensure we didn't rely on the ordering\nof child nodes. So we need to support arbitrary ordering but they all\nneed to be there somewhere.\n\nNote I hit this when using qemu to test the rest of this series.\nArguably this isn't the best fix, but it is probably the most minimal\noption for backporting etc.\n\nAlexandru's sign-off is here because he carried this patch in a larger\nset that Jonathan then applied.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-120"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T10:15:08Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-mq9m-4hg9-c34x/GHSA-mq9m-4hg9-c34x.json b/advisories/unreviewed/2024/03/GHSA-mq9m-4hg9-c34x/GHSA-mq9m-4hg9-c34x.json
index 9318623c156..23faeb19ef2 100644
--- a/advisories/unreviewed/2024/03/GHSA-mq9m-4hg9-c34x/GHSA-mq9m-4hg9-c34x.json
+++ b/advisories/unreviewed/2024/03/GHSA-mq9m-4hg9-c34x/GHSA-mq9m-4hg9-c34x.json
@@ -48,7 +48,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-94"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/03/GHSA-q96w-v39p-hcjw/GHSA-q96w-v39p-hcjw.json b/advisories/unreviewed/2024/03/GHSA-q96w-v39p-hcjw/GHSA-q96w-v39p-hcjw.json
index aa037d52b15..8c22f8e6230 100644
--- a/advisories/unreviewed/2024/03/GHSA-q96w-v39p-hcjw/GHSA-q96w-v39p-hcjw.json
+++ b/advisories/unreviewed/2024/03/GHSA-q96w-v39p-hcjw/GHSA-q96w-v39p-hcjw.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q96w-v39p-hcjw",
- "modified": "2024-03-15T21:30:44Z",
+ "modified": "2024-11-06T18:31:03Z",
"published": "2024-03-15T21:30:44Z",
"aliases": [
"CVE-2021-47126"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: Fix KASAN: slab-out-of-bounds Read in fib6_nh_flush_exceptions\n\nReported by syzbot:\nHEAD commit: 90c911ad Merge tag 'fixes' of git://git.kernel.org/pub/scm..\ngit tree: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master\ndashboard link: https://syzkaller.appspot.com/bug?extid=123aa35098fd3c000eb7\ncompiler: Debian clang version 11.0.1-2\n\n==================================================================\nBUG: KASAN: slab-out-of-bounds in fib6_nh_get_excptn_bucket net/ipv6/route.c:1604 [inline]\nBUG: KASAN: slab-out-of-bounds in fib6_nh_flush_exceptions+0xbd/0x360 net/ipv6/route.c:1732\nRead of size 8 at addr ffff8880145c78f8 by task syz-executor.4/17760\n\nCPU: 0 PID: 17760 Comm: syz-executor.4 Not tainted 5.12.0-rc8-syzkaller #0\nCall Trace:\n \n __dump_stack lib/dump_stack.c:79 [inline]\n dump_stack+0x202/0x31e lib/dump_stack.c:120\n print_address_description+0x5f/0x3b0 mm/kasan/report.c:232\n __kasan_report mm/kasan/report.c:399 [inline]\n kasan_report+0x15c/0x200 mm/kasan/report.c:416\n fib6_nh_get_excptn_bucket net/ipv6/route.c:1604 [inline]\n fib6_nh_flush_exceptions+0xbd/0x360 net/ipv6/route.c:1732\n fib6_nh_release+0x9a/0x430 net/ipv6/route.c:3536\n fib6_info_destroy_rcu+0xcb/0x1c0 net/ipv6/ip6_fib.c:174\n rcu_do_batch kernel/rcu/tree.c:2559 [inline]\n rcu_core+0x8f6/0x1450 kernel/rcu/tree.c:2794\n __do_softirq+0x372/0x7a6 kernel/softirq.c:345\n invoke_softirq kernel/softirq.c:221 [inline]\n __irq_exit_rcu+0x22c/0x260 kernel/softirq.c:422\n irq_exit_rcu+0x5/0x20 kernel/softirq.c:434\n sysvec_apic_timer_interrupt+0x91/0xb0 arch/x86/kernel/apic/apic.c:1100\n \n asm_sysvec_apic_timer_interrupt+0x12/0x20 arch/x86/include/asm/idtentry.h:632\nRIP: 0010:lock_acquire+0x1f6/0x720 kernel/locking/lockdep.c:5515\nCode: f6 84 24 a1 00 00 00 02 0f 85 8d 02 00 00 f7 c3 00 02 00 00 49 bd 00 00 00 00 00 fc ff df 74 01 fb 48 c7 44 24 40 0e 36 e0 45 <4b> c7 44 3d 00 00 00 00 00 4b c7 44 3d 09 00 00 00 00 43 c7 44 3d\nRSP: 0018:ffffc90009e06560 EFLAGS: 00000206\nRAX: 1ffff920013c0cc0 RBX: 0000000000000246 RCX: dffffc0000000000\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000\nRBP: ffffc90009e066e0 R08: dffffc0000000000 R09: fffffbfff1f992b1\nR10: fffffbfff1f992b1 R11: 0000000000000000 R12: 0000000000000000\nR13: dffffc0000000000 R14: 0000000000000000 R15: 1ffff920013c0cb4\n rcu_lock_acquire+0x2a/0x30 include/linux/rcupdate.h:267\n rcu_read_lock include/linux/rcupdate.h:656 [inline]\n ext4_get_group_info+0xea/0x340 fs/ext4/ext4.h:3231\n ext4_mb_prefetch+0x123/0x5d0 fs/ext4/mballoc.c:2212\n ext4_mb_regular_allocator+0x8a5/0x28f0 fs/ext4/mballoc.c:2379\n ext4_mb_new_blocks+0xc6e/0x24f0 fs/ext4/mballoc.c:4982\n ext4_ext_map_blocks+0x2be3/0x7210 fs/ext4/extents.c:4238\n ext4_map_blocks+0xab3/0x1cb0 fs/ext4/inode.c:638\n ext4_getblk+0x187/0x6c0 fs/ext4/inode.c:848\n ext4_bread+0x2a/0x1c0 fs/ext4/inode.c:900\n ext4_append+0x1a4/0x360 fs/ext4/namei.c:67\n ext4_init_new_dir+0x337/0xa10 fs/ext4/namei.c:2768\n ext4_mkdir+0x4b8/0xc00 fs/ext4/namei.c:2814\n vfs_mkdir+0x45b/0x640 fs/namei.c:3819\n ovl_do_mkdir fs/overlayfs/overlayfs.h:161 [inline]\n ovl_mkdir_real+0x53/0x1a0 fs/overlayfs/dir.c:146\n ovl_create_real+0x280/0x490 fs/overlayfs/dir.c:193\n ovl_workdir_create+0x425/0x600 fs/overlayfs/super.c:788\n ovl_make_workdir+0xed/0x1140 fs/overlayfs/super.c:1355\n ovl_get_workdir fs/overlayfs/super.c:1492 [inline]\n ovl_fill_super+0x39ee/0x5370 fs/overlayfs/super.c:2035\n mount_nodev+0x52/0xe0 fs/super.c:1413\n legacy_get_tree+0xea/0x180 fs/fs_context.c:592\n vfs_get_tree+0x86/0x270 fs/super.c:1497\n do_new_mount fs/namespace.c:2903 [inline]\n path_mount+0x196f/0x2be0 fs/namespace.c:3233\n do_mount fs/namespace.c:3246 [inline]\n __do_sys_mount fs/namespace.c:3454 [inline]\n __se_sys_mount+0x2f9/0x3b0 fs/namespace.c:3431\n do_syscall_64+0x2d/0x70 arch/x86/entry/common.c:46\n entry_SYSCALL_64_after_hwframe+0x44/0xae\nRIP: 0033:0x4665f9\nCode: ff ff c3 66 2e 0f 1f 84 \n---truncated---",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-125"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-15T21:15:07Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-vpfj-63v7-3qcq/GHSA-vpfj-63v7-3qcq.json b/advisories/unreviewed/2024/03/GHSA-vpfj-63v7-3qcq/GHSA-vpfj-63v7-3qcq.json
index 835f3f40768..c8ee3bef4ee 100644
--- a/advisories/unreviewed/2024/03/GHSA-vpfj-63v7-3qcq/GHSA-vpfj-63v7-3qcq.json
+++ b/advisories/unreviewed/2024/03/GHSA-vpfj-63v7-3qcq/GHSA-vpfj-63v7-3qcq.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vpfj-63v7-3qcq",
- "modified": "2024-03-06T00:31:26Z",
+ "modified": "2024-11-06T18:31:03Z",
"published": "2024-03-06T00:31:26Z",
"aliases": [
"CVE-2024-1901"
],
"details": "Denial of service in PAM password rotation during the check-in process in Devolutions Server 2023.3.14.0 allows an authenticated user with specific PAM permissions to make PAM credentials unavailable.\n\n\n",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-05T22:15:47Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-5c46-ggmc-6j5m/GHSA-5c46-ggmc-6j5m.json b/advisories/unreviewed/2024/04/GHSA-5c46-ggmc-6j5m/GHSA-5c46-ggmc-6j5m.json
index 5d17d736311..e7be33263e7 100644
--- a/advisories/unreviewed/2024/04/GHSA-5c46-ggmc-6j5m/GHSA-5c46-ggmc-6j5m.json
+++ b/advisories/unreviewed/2024/04/GHSA-5c46-ggmc-6j5m/GHSA-5c46-ggmc-6j5m.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5c46-ggmc-6j5m",
- "modified": "2024-04-03T15:30:42Z",
+ "modified": "2024-11-06T18:31:04Z",
"published": "2024-04-03T15:30:42Z",
"aliases": [
"CVE-2024-26690"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: stmmac: protect updates of 64-bit statistics counters\n\nAs explained by a comment in , write side of struct\nu64_stats_sync must ensure mutual exclusion, or one seqcount update could\nbe lost on 32-bit platforms, thus blocking readers forever. Such lockups\nhave been observed in real world after stmmac_xmit() on one CPU raced with\nstmmac_napi_poll_tx() on another CPU.\n\nTo fix the issue without introducing a new lock, split the statics into\nthree parts:\n\n1. fields updated only under the tx queue lock,\n2. fields updated only during NAPI poll,\n3. fields updated only from interrupt context,\n\nUpdates to fields in the first two groups are already serialized through\nother locks. It is sufficient to split the existing struct u64_stats_sync\nso that each group has its own.\n\nNote that tx_set_ic_bit is updated from both contexts. Split this counter\nso that each context gets its own, and calculate their sum to get the total\nvalue in stmmac_get_ethtool_stats().\n\nFor the third group, multiple interrupts may be processed by different CPUs\nat the same time, but interrupts on the same CPU will not nest. Move fields\nfrom this group to a newly created per-cpu struct stmmac_pcpu_stats.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
+ }
],
"affected": [
@@ -35,7 +38,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-03T15:15:52Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-9x83-3j29-pjf2/GHSA-9x83-3j29-pjf2.json b/advisories/unreviewed/2024/04/GHSA-9x83-3j29-pjf2/GHSA-9x83-3j29-pjf2.json
index a7ca63bd2a6..a991e5b20fd 100644
--- a/advisories/unreviewed/2024/04/GHSA-9x83-3j29-pjf2/GHSA-9x83-3j29-pjf2.json
+++ b/advisories/unreviewed/2024/04/GHSA-9x83-3j29-pjf2/GHSA-9x83-3j29-pjf2.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9x83-3j29-pjf2",
- "modified": "2024-04-15T06:30:34Z",
+ "modified": "2024-11-06T18:31:04Z",
"published": "2024-04-15T06:30:34Z",
"aliases": [
"CVE-2024-1746"
],
"details": "The Testimonial Slider WordPress plugin before 2.3.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-15T05:15:14Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-fw35-8hjm-jw2p/GHSA-fw35-8hjm-jw2p.json b/advisories/unreviewed/2024/04/GHSA-fw35-8hjm-jw2p/GHSA-fw35-8hjm-jw2p.json
index 0c70851f643..d2a7829979f 100644
--- a/advisories/unreviewed/2024/04/GHSA-fw35-8hjm-jw2p/GHSA-fw35-8hjm-jw2p.json
+++ b/advisories/unreviewed/2024/04/GHSA-fw35-8hjm-jw2p/GHSA-fw35-8hjm-jw2p.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fw35-8hjm-jw2p",
- "modified": "2024-04-10T15:30:40Z",
+ "modified": "2024-11-06T18:31:04Z",
"published": "2024-04-10T15:30:40Z",
"aliases": [
"CVE-2024-27477"
],
"details": "In Leantime 3.0.6, a Cross-Site Scripting vulnerability exists within the ticket creation and modification functionality, allowing attackers to inject malicious JavaScript code into the title field of tickets (also known as to-dos). This stored XSS vulnerability can be exploited to perform Server-Side Request Forgery (SSRF) attacks.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-10T15:16:04Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-g7pg-ghhx-ph55/GHSA-g7pg-ghhx-ph55.json b/advisories/unreviewed/2024/04/GHSA-g7pg-ghhx-ph55/GHSA-g7pg-ghhx-ph55.json
index 6c99122c217..e425b0f1440 100644
--- a/advisories/unreviewed/2024/04/GHSA-g7pg-ghhx-ph55/GHSA-g7pg-ghhx-ph55.json
+++ b/advisories/unreviewed/2024/04/GHSA-g7pg-ghhx-ph55/GHSA-g7pg-ghhx-ph55.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g7pg-ghhx-ph55",
- "modified": "2024-04-17T18:31:33Z",
+ "modified": "2024-11-06T18:31:04Z",
"published": "2024-04-17T18:31:33Z",
"aliases": [
"CVE-2024-32305"
],
"details": "Tenda A18 v15.03.05.05 firmware has a stack overflow vulnerability located via the PPW parameter in the fromWizardHandle function.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
"CWE-121"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-17T16:15:08Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-hwgv-8256-p54x/GHSA-hwgv-8256-p54x.json b/advisories/unreviewed/2024/04/GHSA-hwgv-8256-p54x/GHSA-hwgv-8256-p54x.json
index 40e06f3f23b..6b4ce9cdb34 100644
--- a/advisories/unreviewed/2024/04/GHSA-hwgv-8256-p54x/GHSA-hwgv-8256-p54x.json
+++ b/advisories/unreviewed/2024/04/GHSA-hwgv-8256-p54x/GHSA-hwgv-8256-p54x.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hwgv-8256-p54x",
- "modified": "2024-04-17T18:31:32Z",
+ "modified": "2024-11-06T18:31:04Z",
"published": "2024-04-17T18:31:32Z",
"aliases": [
"CVE-2024-26915"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Reset IH OVERFLOW_CLEAR bit\n\nAllows us to detect subsequent IH ring buffer overflows as well.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -43,7 +46,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-17T16:15:08Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-ph95-6589-h2hv/GHSA-ph95-6589-h2hv.json b/advisories/unreviewed/2024/04/GHSA-ph95-6589-h2hv/GHSA-ph95-6589-h2hv.json
index 971deac8060..be697c26df2 100644
--- a/advisories/unreviewed/2024/04/GHSA-ph95-6589-h2hv/GHSA-ph95-6589-h2hv.json
+++ b/advisories/unreviewed/2024/04/GHSA-ph95-6589-h2hv/GHSA-ph95-6589-h2hv.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ph95-6589-h2hv",
- "modified": "2024-04-03T09:30:32Z",
+ "modified": "2024-11-06T18:31:04Z",
"published": "2024-04-03T09:30:32Z",
"aliases": [
"CVE-2023-34423"
],
"details": "Survey Maker prior to 3.6.4 contains a stored cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in to the website using the product with the administrative privilege.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-03T08:15:48Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-q8qv-35px-5j77/GHSA-q8qv-35px-5j77.json b/advisories/unreviewed/2024/04/GHSA-q8qv-35px-5j77/GHSA-q8qv-35px-5j77.json
index 28f82d1787c..4e7f22d5d45 100644
--- a/advisories/unreviewed/2024/04/GHSA-q8qv-35px-5j77/GHSA-q8qv-35px-5j77.json
+++ b/advisories/unreviewed/2024/04/GHSA-q8qv-35px-5j77/GHSA-q8qv-35px-5j77.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q8qv-35px-5j77",
- "modified": "2024-06-27T15:30:38Z",
+ "modified": "2024-11-06T18:31:04Z",
"published": "2024-04-17T12:32:04Z",
"aliases": [
"CVE-2024-26857"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngeneve: make sure to pull inner header in geneve_rx()\n\nsyzbot triggered a bug in geneve_rx() [1]\n\nIssue is similar to the one I fixed in commit 8d975c15c0cd\n(\"ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv()\")\n\nWe have to save skb->network_header in a temporary variable\nin order to be able to recompute the network_header pointer\nafter a pskb_inet_may_pull() call.\n\npskb_inet_may_pull() makes sure the needed headers are in skb->head.\n\n[1]\nBUG: KMSAN: uninit-value in IP_ECN_decapsulate include/net/inet_ecn.h:302 [inline]\n BUG: KMSAN: uninit-value in geneve_rx drivers/net/geneve.c:279 [inline]\n BUG: KMSAN: uninit-value in geneve_udp_encap_recv+0x36f9/0x3c10 drivers/net/geneve.c:391\n IP_ECN_decapsulate include/net/inet_ecn.h:302 [inline]\n geneve_rx drivers/net/geneve.c:279 [inline]\n geneve_udp_encap_recv+0x36f9/0x3c10 drivers/net/geneve.c:391\n udp_queue_rcv_one_skb+0x1d39/0x1f20 net/ipv4/udp.c:2108\n udp_queue_rcv_skb+0x6ae/0x6e0 net/ipv4/udp.c:2186\n udp_unicast_rcv_skb+0x184/0x4b0 net/ipv4/udp.c:2346\n __udp4_lib_rcv+0x1c6b/0x3010 net/ipv4/udp.c:2422\n udp_rcv+0x7d/0xa0 net/ipv4/udp.c:2604\n ip_protocol_deliver_rcu+0x264/0x1300 net/ipv4/ip_input.c:205\n ip_local_deliver_finish+0x2b8/0x440 net/ipv4/ip_input.c:233\n NF_HOOK include/linux/netfilter.h:314 [inline]\n ip_local_deliver+0x21f/0x490 net/ipv4/ip_input.c:254\n dst_input include/net/dst.h:461 [inline]\n ip_rcv_finish net/ipv4/ip_input.c:449 [inline]\n NF_HOOK include/linux/netfilter.h:314 [inline]\n ip_rcv+0x46f/0x760 net/ipv4/ip_input.c:569\n __netif_receive_skb_one_core net/core/dev.c:5534 [inline]\n __netif_receive_skb+0x1a6/0x5a0 net/core/dev.c:5648\n process_backlog+0x480/0x8b0 net/core/dev.c:5976\n __napi_poll+0xe3/0x980 net/core/dev.c:6576\n napi_poll net/core/dev.c:6645 [inline]\n net_rx_action+0x8b8/0x1870 net/core/dev.c:6778\n __do_softirq+0x1b7/0x7c5 kernel/softirq.c:553\n do_softirq+0x9a/0xf0 kernel/softirq.c:454\n __local_bh_enable_ip+0x9b/0xa0 kernel/softirq.c:381\n local_bh_enable include/linux/bottom_half.h:33 [inline]\n rcu_read_unlock_bh include/linux/rcupdate.h:820 [inline]\n __dev_queue_xmit+0x2768/0x51c0 net/core/dev.c:4378\n dev_queue_xmit include/linux/netdevice.h:3171 [inline]\n packet_xmit+0x9c/0x6b0 net/packet/af_packet.c:276\n packet_snd net/packet/af_packet.c:3081 [inline]\n packet_sendmsg+0x8aef/0x9f10 net/packet/af_packet.c:3113\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg net/socket.c:745 [inline]\n __sys_sendto+0x735/0xa10 net/socket.c:2191\n __do_sys_sendto net/socket.c:2203 [inline]\n __se_sys_sendto net/socket.c:2199 [inline]\n __x64_sys_sendto+0x125/0x1c0 net/socket.c:2199\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcf/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nUninit was created at:\n slab_post_alloc_hook mm/slub.c:3819 [inline]\n slab_alloc_node mm/slub.c:3860 [inline]\n kmem_cache_alloc_node+0x5cb/0xbc0 mm/slub.c:3903\n kmalloc_reserve+0x13d/0x4a0 net/core/skbuff.c:560\n __alloc_skb+0x352/0x790 net/core/skbuff.c:651\n alloc_skb include/linux/skbuff.h:1296 [inline]\n alloc_skb_with_frags+0xc8/0xbd0 net/core/skbuff.c:6394\n sock_alloc_send_pskb+0xa80/0xbf0 net/core/sock.c:2783\n packet_alloc_skb net/packet/af_packet.c:2930 [inline]\n packet_snd net/packet/af_packet.c:3024 [inline]\n packet_sendmsg+0x70c2/0x9f10 net/packet/af_packet.c:3113\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg net/socket.c:745 [inline]\n __sys_sendto+0x735/0xa10 net/socket.c:2191\n __do_sys_sendto net/socket.c:2203 [inline]\n __se_sys_sendto net/socket.c:2199 [inline]\n __x64_sys_sendto+0x125/0x1c0 net/socket.c:2199\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcf/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x63/0x6b",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -63,7 +66,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-17T11:15:08Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-qvgv-g72v-425q/GHSA-qvgv-g72v-425q.json b/advisories/unreviewed/2024/04/GHSA-qvgv-g72v-425q/GHSA-qvgv-g72v-425q.json
index 5a9d5cac696..e15874b9402 100644
--- a/advisories/unreviewed/2024/04/GHSA-qvgv-g72v-425q/GHSA-qvgv-g72v-425q.json
+++ b/advisories/unreviewed/2024/04/GHSA-qvgv-g72v-425q/GHSA-qvgv-g72v-425q.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qvgv-g72v-425q",
- "modified": "2024-04-30T00:30:35Z",
+ "modified": "2024-11-06T18:31:04Z",
"published": "2024-04-30T00:30:35Z",
"aliases": [
"CVE-2024-34047"
],
"details": "O-RAN RIC I-Release e2mgr lacks array size checks in RicServiceUpdateHandler.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
+ }
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-30T00:15:07Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-wpgg-qfwq-fwj4/GHSA-wpgg-qfwq-fwj4.json b/advisories/unreviewed/2024/04/GHSA-wpgg-qfwq-fwj4/GHSA-wpgg-qfwq-fwj4.json
index 1d773de9d0e..4eb8fc97a00 100644
--- a/advisories/unreviewed/2024/04/GHSA-wpgg-qfwq-fwj4/GHSA-wpgg-qfwq-fwj4.json
+++ b/advisories/unreviewed/2024/04/GHSA-wpgg-qfwq-fwj4/GHSA-wpgg-qfwq-fwj4.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wpgg-qfwq-fwj4",
- "modified": "2024-04-16T18:31:36Z",
+ "modified": "2024-11-06T18:31:04Z",
"published": "2024-04-16T18:31:36Z",
"aliases": [
"CVE-2024-32254"
],
"details": "Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via tms/admin/create-package.php. When creating a new package, there is no checks for what types of files are uploaded from the image.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-434"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-16T17:15:10Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-x5g8-4m4m-8jgf/GHSA-x5g8-4m4m-8jgf.json b/advisories/unreviewed/2024/04/GHSA-x5g8-4m4m-8jgf/GHSA-x5g8-4m4m-8jgf.json
index cf67846dffe..5a8433bc2a2 100644
--- a/advisories/unreviewed/2024/04/GHSA-x5g8-4m4m-8jgf/GHSA-x5g8-4m4m-8jgf.json
+++ b/advisories/unreviewed/2024/04/GHSA-x5g8-4m4m-8jgf/GHSA-x5g8-4m4m-8jgf.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-94"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-29pq-gr25-8674/GHSA-29pq-gr25-8674.json b/advisories/unreviewed/2024/05/GHSA-29pq-gr25-8674/GHSA-29pq-gr25-8674.json
index 90b9badf763..9228920635a 100644
--- a/advisories/unreviewed/2024/05/GHSA-29pq-gr25-8674/GHSA-29pq-gr25-8674.json
+++ b/advisories/unreviewed/2024/05/GHSA-29pq-gr25-8674/GHSA-29pq-gr25-8674.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-29pq-gr25-8674",
- "modified": "2024-06-27T15:30:39Z",
+ "modified": "2024-11-06T18:31:04Z",
"published": "2024-05-19T12:30:38Z",
"aliases": [
"CVE-2023-52699"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsysv: don't call sb_bread() with pointers_lock held\n\nsyzbot is reporting sleep in atomic context in SysV filesystem [1], for\nsb_bread() is called with rw_spinlock held.\n\nA \"write_lock(&pointers_lock) => read_lock(&pointers_lock) deadlock\" bug\nand a \"sb_bread() with write_lock(&pointers_lock)\" bug were introduced by\n\"Replace BKL for chain locking with sysvfs-private rwlock\" in Linux 2.5.12.\n\nThen, \"[PATCH] err1-40: sysvfs locking fix\" in Linux 2.6.8 fixed the\nformer bug by moving pointers_lock lock to the callers, but instead\nintroduced a \"sb_bread() with read_lock(&pointers_lock)\" bug (which made\nthis problem easier to hit).\n\nAl Viro suggested that why not to do like get_branch()/get_block()/\nfind_shared() in Minix filesystem does. And doing like that is almost a\nrevert of \"[PATCH] err1-40: sysvfs locking fix\" except that get_branch()\n from with find_shared() is called without write_lock(&pointers_lock).",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
+ }
],
"affected": [
@@ -63,7 +66,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-19T11:15:47Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-2r8j-rf53-9g72/GHSA-2r8j-rf53-9g72.json b/advisories/unreviewed/2024/05/GHSA-2r8j-rf53-9g72/GHSA-2r8j-rf53-9g72.json
index e74f7ef09b3..812458842ff 100644
--- a/advisories/unreviewed/2024/05/GHSA-2r8j-rf53-9g72/GHSA-2r8j-rf53-9g72.json
+++ b/advisories/unreviewed/2024/05/GHSA-2r8j-rf53-9g72/GHSA-2r8j-rf53-9g72.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2r8j-rf53-9g72",
- "modified": "2024-05-22T18:30:40Z",
+ "modified": "2024-11-06T18:31:04Z",
"published": "2024-05-19T00:30:45Z",
"aliases": [
"CVE-2024-36050"
],
"details": "Nix through 2.22.1 mishandles certain usage of hash caches, which makes it easier for attackers to replace current source code with attacker-controlled source code by luring a maintainer into accepting a malicious pull request.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
],
"affected": [
@@ -35,7 +38,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-18T22:15:07Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-5g4g-hgmr-mqrx/GHSA-5g4g-hgmr-mqrx.json b/advisories/unreviewed/2024/05/GHSA-5g4g-hgmr-mqrx/GHSA-5g4g-hgmr-mqrx.json
index 230396c0cda..61c6f615378 100644
--- a/advisories/unreviewed/2024/05/GHSA-5g4g-hgmr-mqrx/GHSA-5g4g-hgmr-mqrx.json
+++ b/advisories/unreviewed/2024/05/GHSA-5g4g-hgmr-mqrx/GHSA-5g4g-hgmr-mqrx.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5g4g-hgmr-mqrx",
- "modified": "2024-05-22T09:31:45Z",
+ "modified": "2024-11-06T18:31:04Z",
"published": "2024-05-22T09:31:45Z",
"aliases": [
"CVE-2021-47443"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFC: digital: fix possible memory leak in digital_tg_listen_mdaa()\n\n'params' is allocated in digital_tg_listen_mdaa(), but not free when\ndigital_send_cmd() failed, which will cause memory leak. Fix it by\nfreeing 'params' if digital_send_cmd() return failed.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -55,7 +58,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T07:15:09Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-5mwv-x2qc-g5cj/GHSA-5mwv-x2qc-g5cj.json b/advisories/unreviewed/2024/05/GHSA-5mwv-x2qc-g5cj/GHSA-5mwv-x2qc-g5cj.json
index f709c1dd262..55d67c94266 100644
--- a/advisories/unreviewed/2024/05/GHSA-5mwv-x2qc-g5cj/GHSA-5mwv-x2qc-g5cj.json
+++ b/advisories/unreviewed/2024/05/GHSA-5mwv-x2qc-g5cj/GHSA-5mwv-x2qc-g5cj.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5mwv-x2qc-g5cj",
- "modified": "2024-05-17T15:31:08Z",
+ "modified": "2024-11-06T18:31:04Z",
"published": "2024-05-17T15:31:08Z",
"aliases": [
"CVE-2024-27435"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvme: fix reconnection fail due to reserved tag allocation\n\nWe found a issue on production environment while using NVMe over RDMA,\nadmin_q reconnect failed forever while remote target and network is ok.\nAfter dig into it, we found it may caused by a ABBA deadlock due to tag\nallocation. In my case, the tag was hold by a keep alive request\nwaiting inside admin_q, as we quiesced admin_q while reset ctrl, so the\nrequest maked as idle and will not process before reset success. As\nfabric_q shares tagset with admin_q, while reconnect remote target, we\nneed a tag for connect command, but the only one reserved tag was held\nby keep alive command which waiting inside admin_q. As a result, we\nfailed to reconnect admin_q forever. In order to fix this issue, I\nthink we should keep two reserved tags for admin queue.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -43,7 +46,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T13:15:58Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-7m8f-jj48-x349/GHSA-7m8f-jj48-x349.json b/advisories/unreviewed/2024/05/GHSA-7m8f-jj48-x349/GHSA-7m8f-jj48-x349.json
index 10ff03055a0..9c189686fbd 100644
--- a/advisories/unreviewed/2024/05/GHSA-7m8f-jj48-x349/GHSA-7m8f-jj48-x349.json
+++ b/advisories/unreviewed/2024/05/GHSA-7m8f-jj48-x349/GHSA-7m8f-jj48-x349.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7m8f-jj48-x349",
- "modified": "2024-05-21T18:31:20Z",
+ "modified": "2024-11-06T18:31:04Z",
"published": "2024-05-21T18:31:20Z",
"aliases": [
"CVE-2023-52779"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs: Pass AT_GETATTR_NOSEC flag to getattr interface function\n\nWhen vfs_getattr_nosec() calls a filesystem's getattr interface function\nthen the 'nosec' should propagate into this function so that\nvfs_getattr_nosec() can again be called from the filesystem's gettattr\nrather than vfs_getattr(). The latter would add unnecessary security\nchecks that the initial vfs_getattr_nosec() call wanted to avoid.\nTherefore, introduce the getattr flag GETATTR_NOSEC and allow to pass\nwith the new getattr_flags parameter to the getattr interface function.\nIn overlayfs and ecryptfs use this flag to determine which one of the\ntwo functions to call.\n\nIn a recent code change introduced to IMA vfs_getattr_nosec() ended up\ncalling vfs_getattr() in overlayfs, which in turn called\nsecurity_inode_getattr() on an exiting process that did not have\ncurrent->fs set anymore, which then caused a kernel NULL pointer\ndereference. With this change the call to security_inode_getattr() can\nbe avoided, thus avoiding the NULL pointer dereference.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T16:15:16Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-8qjm-4vw9-3w5g/GHSA-8qjm-4vw9-3w5g.json b/advisories/unreviewed/2024/05/GHSA-8qjm-4vw9-3w5g/GHSA-8qjm-4vw9-3w5g.json
index beaffe78f6d..84ded4e46f7 100644
--- a/advisories/unreviewed/2024/05/GHSA-8qjm-4vw9-3w5g/GHSA-8qjm-4vw9-3w5g.json
+++ b/advisories/unreviewed/2024/05/GHSA-8qjm-4vw9-3w5g/GHSA-8qjm-4vw9-3w5g.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8qjm-4vw9-3w5g",
- "modified": "2024-06-27T15:30:39Z",
+ "modified": "2024-11-06T18:31:04Z",
"published": "2024-05-17T12:31:00Z",
"aliases": [
"CVE-2024-27412"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: bq27xxx-i2c: Do not free non existing IRQ\n\nThe bq27xxx i2c-client may not have an IRQ, in which case\nclient->irq will be 0. bq27xxx_battery_i2c_probe() already has\nan if (client->irq) check wrapping the request_threaded_irq().\n\nBut bq27xxx_battery_i2c_remove() unconditionally calls\nfree_irq(client->irq) leading to:\n\n[ 190.310742] ------------[ cut here ]------------\n[ 190.310843] Trying to free already-free IRQ 0\n[ 190.310861] WARNING: CPU: 2 PID: 1304 at kernel/irq/manage.c:1893 free_irq+0x1b8/0x310\n\nFollowed by a backtrace when unbinding the driver. Add\nan if (client->irq) to bq27xxx_battery_i2c_remove() mirroring\nprobe() to fix this.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -63,7 +66,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T12:15:12Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-gjv4-282p-cm98/GHSA-gjv4-282p-cm98.json b/advisories/unreviewed/2024/05/GHSA-gjv4-282p-cm98/GHSA-gjv4-282p-cm98.json
index 1c65daef1b4..68deaf7f2e7 100644
--- a/advisories/unreviewed/2024/05/GHSA-gjv4-282p-cm98/GHSA-gjv4-282p-cm98.json
+++ b/advisories/unreviewed/2024/05/GHSA-gjv4-282p-cm98/GHSA-gjv4-282p-cm98.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gjv4-282p-cm98",
- "modified": "2024-06-26T00:31:43Z",
+ "modified": "2024-11-06T18:31:04Z",
"published": "2024-05-20T12:30:30Z",
"aliases": [
"CVE-2024-36007"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmlxsw: spectrum_acl_tcam: Fix warning during rehash\n\nAs previously explained, the rehash delayed work migrates filters from\none region to another. This is done by iterating over all chunks (all\nthe filters with the same priority) in the region and in each chunk\niterating over all the filters.\n\nWhen the work runs out of credits it stores the current chunk and entry\nas markers in the per-work context so that it would know where to resume\nthe migration from the next time the work is scheduled.\n\nUpon error, the chunk marker is reset to NULL, but without resetting the\nentry markers despite being relative to it. This can result in migration\nbeing resumed from an entry that does not belong to the chunk being\nmigrated. In turn, this will eventually lead to a chunk being iterated\nover as if it is an entry. Because of how the two structures happen to\nbe defined, this does not lead to KASAN splats, but to warnings such as\n[1].\n\nFix by creating a helper that resets all the markers and call it from\nall the places the currently only reset the chunk marker. For good\nmeasures also call it when starting a completely new rehash. Add a\nwarning to avoid future cases.\n\n[1]\nWARNING: CPU: 7 PID: 1076 at drivers/net/ethernet/mellanox/mlxsw/core_acl_flex_keys.c:407 mlxsw_afk_encode+0x242/0x2f0\nModules linked in:\nCPU: 7 PID: 1076 Comm: kworker/7:24 Tainted: G W 6.9.0-rc3-custom-00880-g29e61d91b77b #29\nHardware name: Mellanox Technologies Ltd. MSN3700/VMOD0005, BIOS 5.11 01/06/2019\nWorkqueue: mlxsw_core mlxsw_sp_acl_tcam_vregion_rehash_work\nRIP: 0010:mlxsw_afk_encode+0x242/0x2f0\n[...]\nCall Trace:\n \n mlxsw_sp_acl_atcam_entry_add+0xd9/0x3c0\n mlxsw_sp_acl_tcam_entry_create+0x5e/0xa0\n mlxsw_sp_acl_tcam_vchunk_migrate_all+0x109/0x290\n mlxsw_sp_acl_tcam_vregion_rehash_work+0x6c/0x470\n process_one_work+0x151/0x370\n worker_thread+0x2cb/0x3e0\n kthread+0xd0/0x100\n ret_from_fork+0x34/0x50\n ",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -55,7 +58,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-20T10:15:14Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-mcp4-w22q-6q4h/GHSA-mcp4-w22q-6q4h.json b/advisories/unreviewed/2024/05/GHSA-mcp4-w22q-6q4h/GHSA-mcp4-w22q-6q4h.json
index 06c599a7382..ec90113c589 100644
--- a/advisories/unreviewed/2024/05/GHSA-mcp4-w22q-6q4h/GHSA-mcp4-w22q-6q4h.json
+++ b/advisories/unreviewed/2024/05/GHSA-mcp4-w22q-6q4h/GHSA-mcp4-w22q-6q4h.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mcp4-w22q-6q4h",
- "modified": "2024-06-27T12:30:46Z",
+ "modified": "2024-11-06T18:31:04Z",
"published": "2024-05-19T09:34:47Z",
"aliases": [
"CVE-2024-35888"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nerspan: make sure erspan_base_hdr is present in skb->head\n\nsyzbot reported a problem in ip6erspan_rcv() [1]\n\nIssue is that ip6erspan_rcv() (and erspan_rcv()) no longer make\nsure erspan_base_hdr is present in skb linear part (skb->head)\nbefore getting @ver field from it.\n\nAdd the missing pskb_may_pull() calls.\n\nv2: Reload iph pointer in erspan_rcv() after pskb_may_pull()\n because skb->head might have changed.\n\n[1]\n\n BUG: KMSAN: uninit-value in pskb_may_pull_reason include/linux/skbuff.h:2742 [inline]\n BUG: KMSAN: uninit-value in pskb_may_pull include/linux/skbuff.h:2756 [inline]\n BUG: KMSAN: uninit-value in ip6erspan_rcv net/ipv6/ip6_gre.c:541 [inline]\n BUG: KMSAN: uninit-value in gre_rcv+0x11f8/0x1930 net/ipv6/ip6_gre.c:610\n pskb_may_pull_reason include/linux/skbuff.h:2742 [inline]\n pskb_may_pull include/linux/skbuff.h:2756 [inline]\n ip6erspan_rcv net/ipv6/ip6_gre.c:541 [inline]\n gre_rcv+0x11f8/0x1930 net/ipv6/ip6_gre.c:610\n ip6_protocol_deliver_rcu+0x1d4c/0x2ca0 net/ipv6/ip6_input.c:438\n ip6_input_finish net/ipv6/ip6_input.c:483 [inline]\n NF_HOOK include/linux/netfilter.h:314 [inline]\n ip6_input+0x15d/0x430 net/ipv6/ip6_input.c:492\n ip6_mc_input+0xa7e/0xc80 net/ipv6/ip6_input.c:586\n dst_input include/net/dst.h:460 [inline]\n ip6_rcv_finish+0x955/0x970 net/ipv6/ip6_input.c:79\n NF_HOOK include/linux/netfilter.h:314 [inline]\n ipv6_rcv+0xde/0x390 net/ipv6/ip6_input.c:310\n __netif_receive_skb_one_core net/core/dev.c:5538 [inline]\n __netif_receive_skb+0x1da/0xa00 net/core/dev.c:5652\n netif_receive_skb_internal net/core/dev.c:5738 [inline]\n netif_receive_skb+0x58/0x660 net/core/dev.c:5798\n tun_rx_batched+0x3ee/0x980 drivers/net/tun.c:1549\n tun_get_user+0x5566/0x69e0 drivers/net/tun.c:2002\n tun_chr_write_iter+0x3af/0x5d0 drivers/net/tun.c:2048\n call_write_iter include/linux/fs.h:2108 [inline]\n new_sync_write fs/read_write.c:497 [inline]\n vfs_write+0xb63/0x1520 fs/read_write.c:590\n ksys_write+0x20f/0x4c0 fs/read_write.c:643\n __do_sys_write fs/read_write.c:655 [inline]\n __se_sys_write fs/read_write.c:652 [inline]\n __x64_sys_write+0x93/0xe0 fs/read_write.c:652\n do_syscall_64+0xd5/0x1f0\n entry_SYSCALL_64_after_hwframe+0x6d/0x75\n\nUninit was created at:\n slab_post_alloc_hook mm/slub.c:3804 [inline]\n slab_alloc_node mm/slub.c:3845 [inline]\n kmem_cache_alloc_node+0x613/0xc50 mm/slub.c:3888\n kmalloc_reserve+0x13d/0x4a0 net/core/skbuff.c:577\n __alloc_skb+0x35b/0x7a0 net/core/skbuff.c:668\n alloc_skb include/linux/skbuff.h:1318 [inline]\n alloc_skb_with_frags+0xc8/0xbf0 net/core/skbuff.c:6504\n sock_alloc_send_pskb+0xa81/0xbf0 net/core/sock.c:2795\n tun_alloc_skb drivers/net/tun.c:1525 [inline]\n tun_get_user+0x209a/0x69e0 drivers/net/tun.c:1846\n tun_chr_write_iter+0x3af/0x5d0 drivers/net/tun.c:2048\n call_write_iter include/linux/fs.h:2108 [inline]\n new_sync_write fs/read_write.c:497 [inline]\n vfs_write+0xb63/0x1520 fs/read_write.c:590\n ksys_write+0x20f/0x4c0 fs/read_write.c:643\n __do_sys_write fs/read_write.c:655 [inline]\n __se_sys_write fs/read_write.c:652 [inline]\n __x64_sys_write+0x93/0xe0 fs/read_write.c:652\n do_syscall_64+0xd5/0x1f0\n entry_SYSCALL_64_after_hwframe+0x6d/0x75\n\nCPU: 1 PID: 5045 Comm: syz-executor114 Not tainted 6.9.0-rc1-syzkaller-00021-g962490525cff #0",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -63,7 +66,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-19T09:15:09Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-pqp3-8qxf-mjx8/GHSA-pqp3-8qxf-mjx8.json b/advisories/unreviewed/2024/05/GHSA-pqp3-8qxf-mjx8/GHSA-pqp3-8qxf-mjx8.json
index db8affc99f0..18a63ff2dbd 100644
--- a/advisories/unreviewed/2024/05/GHSA-pqp3-8qxf-mjx8/GHSA-pqp3-8qxf-mjx8.json
+++ b/advisories/unreviewed/2024/05/GHSA-pqp3-8qxf-mjx8/GHSA-pqp3-8qxf-mjx8.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pqp3-8qxf-mjx8",
- "modified": "2024-05-17T15:31:11Z",
+ "modified": "2024-11-06T18:31:04Z",
"published": "2024-05-17T15:31:11Z",
"aliases": [
"CVE-2023-52674"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: scarlett2: Add clamp() in scarlett2_mixer_ctl_put()\n\nEnsure the value passed to scarlett2_mixer_ctl_put() is between 0 and\nSCARLETT2_MIXER_MAX_VALUE so we don't attempt to access outside\nscarlett2_mixer_values[].",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -43,7 +46,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T15:15:18Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-rmx7-cw76-79w4/GHSA-rmx7-cw76-79w4.json b/advisories/unreviewed/2024/05/GHSA-rmx7-cw76-79w4/GHSA-rmx7-cw76-79w4.json
index 3a86cd16bac..d104930730d 100644
--- a/advisories/unreviewed/2024/05/GHSA-rmx7-cw76-79w4/GHSA-rmx7-cw76-79w4.json
+++ b/advisories/unreviewed/2024/05/GHSA-rmx7-cw76-79w4/GHSA-rmx7-cw76-79w4.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rmx7-cw76-79w4",
- "modified": "2024-05-17T12:30:59Z",
+ "modified": "2024-11-06T18:31:04Z",
"published": "2024-05-01T06:31:42Z",
"aliases": [
"CVE-2024-26980"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix slab-out-of-bounds in smb2_allocate_rsp_buf\n\nIf ->ProtocolId is SMB2_TRANSFORM_PROTO_NUM, smb2 request size\nvalidation could be skipped. if request size is smaller than\nsizeof(struct smb2_query_info_req), slab-out-of-bounds read can happen in\nsmb2_allocate_rsp_buf(). This patch allocate response buffer after\ndecrypting transform request. smb3_decrypt_req() will validate transform\nrequest size and avoid slab-out-of-bound in smb2_allocate_rsp_buf().",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -55,7 +58,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-01T06:15:15Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-vx2v-mjff-9hjf/GHSA-vx2v-mjff-9hjf.json b/advisories/unreviewed/2024/05/GHSA-vx2v-mjff-9hjf/GHSA-vx2v-mjff-9hjf.json
index d306c12df4b..d338dcd406e 100644
--- a/advisories/unreviewed/2024/05/GHSA-vx2v-mjff-9hjf/GHSA-vx2v-mjff-9hjf.json
+++ b/advisories/unreviewed/2024/05/GHSA-vx2v-mjff-9hjf/GHSA-vx2v-mjff-9hjf.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vx2v-mjff-9hjf",
- "modified": "2024-05-17T15:31:11Z",
+ "modified": "2024-11-06T18:31:04Z",
"published": "2024-05-17T15:31:11Z",
"aliases": [
"CVE-2023-52687"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: safexcel - Add error handling for dma_map_sg() calls\n\nMacro dma_map_sg() may return 0 on error. This patch enables\nchecks in case of the macro failure and ensures unmapping of\npreviously mapped buffers with dma_unmap_sg().\n\nFound by Linux Verification Center (linuxtesting.org) with static\nanalysis tool SVACE.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -39,7 +42,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T15:15:19Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-wpgm-g43f-rx6f/GHSA-wpgm-g43f-rx6f.json b/advisories/unreviewed/2024/05/GHSA-wpgm-g43f-rx6f/GHSA-wpgm-g43f-rx6f.json
index 535fdb98f78..a9d3f0e693a 100644
--- a/advisories/unreviewed/2024/05/GHSA-wpgm-g43f-rx6f/GHSA-wpgm-g43f-rx6f.json
+++ b/advisories/unreviewed/2024/05/GHSA-wpgm-g43f-rx6f/GHSA-wpgm-g43f-rx6f.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wpgm-g43f-rx6f",
- "modified": "2024-05-21T18:31:23Z",
+ "modified": "2024-11-06T18:31:04Z",
"published": "2024-05-21T18:31:23Z",
"aliases": [
"CVE-2023-52872"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntty: n_gsm: fix race condition in status line change on dead connections\n\ngsm_cleanup_mux() cleans up the gsm by closing all DLCIs, stopping all\ntimers, removing the virtual tty devices and clearing the data queues.\nThis procedure, however, may cause subsequent changes of the virtual modem\nstatus lines of a DLCI. More data is being added the outgoing data queue\nand the deleted kick timer is restarted to handle this. At this point many\nresources have already been removed by the cleanup procedure. Thus, a\nkernel panic occurs.\n\nFix this by proving in gsm_modem_update() that the cleanup procedure has\nnot been started and the mux is still alive.\n\nNote that writing to a virtual tty is already protected by checks against\nthe DLCI specific connection state.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -41,9 +44,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-362"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T16:15:23Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-x9mx-786j-jh4p/GHSA-x9mx-786j-jh4p.json b/advisories/unreviewed/2024/05/GHSA-x9mx-786j-jh4p/GHSA-x9mx-786j-jh4p.json
index a894f3a5ed5..a582159bcb2 100644
--- a/advisories/unreviewed/2024/05/GHSA-x9mx-786j-jh4p/GHSA-x9mx-786j-jh4p.json
+++ b/advisories/unreviewed/2024/05/GHSA-x9mx-786j-jh4p/GHSA-x9mx-786j-jh4p.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x9mx-786j-jh4p",
- "modified": "2024-05-21T18:31:23Z",
+ "modified": "2024-11-06T18:31:04Z",
"published": "2024-05-21T18:31:22Z",
"aliases": [
"CVE-2023-52862"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix null pointer dereference in error message\n\nThis patch fixes a null pointer dereference in the error message that is\nprinted when the Display Core (DC) fails to initialize. The original\nmessage includes the DC version number, which is undefined if the DC is\nnot initialized.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-476"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T16:15:23Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-xhf8-m475-367r/GHSA-xhf8-m475-367r.json b/advisories/unreviewed/2024/05/GHSA-xhf8-m475-367r/GHSA-xhf8-m475-367r.json
index 538f68e1da6..32678356f9a 100644
--- a/advisories/unreviewed/2024/05/GHSA-xhf8-m475-367r/GHSA-xhf8-m475-367r.json
+++ b/advisories/unreviewed/2024/05/GHSA-xhf8-m475-367r/GHSA-xhf8-m475-367r.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xhf8-m475-367r",
- "modified": "2024-05-21T18:31:18Z",
+ "modified": "2024-11-06T18:31:04Z",
"published": "2024-05-21T18:31:18Z",
"aliases": [
"CVE-2023-52700"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix kernel warning when sending SYN message\n\nWhen sending a SYN message, this kernel stack trace is observed:\n\n...\n[ 13.396352] RIP: 0010:_copy_from_iter+0xb4/0x550\n...\n[ 13.398494] Call Trace:\n[ 13.398630] \n[ 13.398630] ? __alloc_skb+0xed/0x1a0\n[ 13.398630] tipc_msg_build+0x12c/0x670 [tipc]\n[ 13.398630] ? shmem_add_to_page_cache.isra.71+0x151/0x290\n[ 13.398630] __tipc_sendmsg+0x2d1/0x710 [tipc]\n[ 13.398630] ? tipc_connect+0x1d9/0x230 [tipc]\n[ 13.398630] ? __local_bh_enable_ip+0x37/0x80\n[ 13.398630] tipc_connect+0x1d9/0x230 [tipc]\n[ 13.398630] ? __sys_connect+0x9f/0xd0\n[ 13.398630] __sys_connect+0x9f/0xd0\n[ 13.398630] ? preempt_count_add+0x4d/0xa0\n[ 13.398630] ? fpregs_assert_state_consistent+0x22/0x50\n[ 13.398630] __x64_sys_connect+0x16/0x20\n[ 13.398630] do_syscall_64+0x42/0x90\n[ 13.398630] entry_SYSCALL_64_after_hwframe+0x63/0xcd\n\nIt is because commit a41dad905e5a (\"iov_iter: saner checks for attempt\nto copy to/from iterator\") has introduced sanity check for copying\nfrom/to iov iterator. Lacking of copy direction from the iterator\nviewpoint would lead to kernel stack trace like above.\n\nThis commit fixes this issue by initializing the iov iterator with\nthe correct copy direction when sending SYN or ACK without data.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T16:15:12Z"
diff --git a/advisories/unreviewed/2024/06/GHSA-gjhw-gp72-3cj2/GHSA-gjhw-gp72-3cj2.json b/advisories/unreviewed/2024/06/GHSA-gjhw-gp72-3cj2/GHSA-gjhw-gp72-3cj2.json
index 0e31d5f88bd..45f310fc4f2 100644
--- a/advisories/unreviewed/2024/06/GHSA-gjhw-gp72-3cj2/GHSA-gjhw-gp72-3cj2.json
+++ b/advisories/unreviewed/2024/06/GHSA-gjhw-gp72-3cj2/GHSA-gjhw-gp72-3cj2.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gjhw-gp72-3cj2",
- "modified": "2024-06-25T06:30:39Z",
+ "modified": "2024-11-06T18:31:05Z",
"published": "2024-06-25T06:30:39Z",
"aliases": [
"CVE-2024-23152"
],
"details": "A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
"CWE-125"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-25T04:15:12Z"
diff --git a/advisories/unreviewed/2024/06/GHSA-h8fv-x4w5-c9mc/GHSA-h8fv-x4w5-c9mc.json b/advisories/unreviewed/2024/06/GHSA-h8fv-x4w5-c9mc/GHSA-h8fv-x4w5-c9mc.json
index fed41e03507..0bfbdf08904 100644
--- a/advisories/unreviewed/2024/06/GHSA-h8fv-x4w5-c9mc/GHSA-h8fv-x4w5-c9mc.json
+++ b/advisories/unreviewed/2024/06/GHSA-h8fv-x4w5-c9mc/GHSA-h8fv-x4w5-c9mc.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h8fv-x4w5-c9mc",
- "modified": "2024-06-13T21:30:55Z",
+ "modified": "2024-11-06T18:31:05Z",
"published": "2024-06-13T21:30:55Z",
"aliases": [
"CVE-2024-32914"
],
"details": "In tpu_get_int_state of tpu.c, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-125"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-13T21:15:55Z"
diff --git a/advisories/unreviewed/2024/06/GHSA-hxp8-xjhv-r6wv/GHSA-hxp8-xjhv-r6wv.json b/advisories/unreviewed/2024/06/GHSA-hxp8-xjhv-r6wv/GHSA-hxp8-xjhv-r6wv.json
index 9731f38b32e..23e7f0c4a85 100644
--- a/advisories/unreviewed/2024/06/GHSA-hxp8-xjhv-r6wv/GHSA-hxp8-xjhv-r6wv.json
+++ b/advisories/unreviewed/2024/06/GHSA-hxp8-xjhv-r6wv/GHSA-hxp8-xjhv-r6wv.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hxp8-xjhv-r6wv",
- "modified": "2024-06-17T21:31:10Z",
+ "modified": "2024-11-06T18:31:05Z",
"published": "2024-06-17T21:31:10Z",
"aliases": [
"CVE-2024-38449"
],
"details": "A Directory Traversal vulnerability in KasmVNC 1.3.1.230e50f7b89663316c70de7b0e3db6f6b9340489 and possibly earlier versions allows remote authenticated attackers to browse parent directories and read the content of files outside the scope of the application.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-22"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-17T19:15:58Z"
diff --git a/advisories/unreviewed/2024/06/GHSA-mc7v-wpqv-v4g2/GHSA-mc7v-wpqv-v4g2.json b/advisories/unreviewed/2024/06/GHSA-mc7v-wpqv-v4g2/GHSA-mc7v-wpqv-v4g2.json
index f4429a337f9..d4189632098 100644
--- a/advisories/unreviewed/2024/06/GHSA-mc7v-wpqv-v4g2/GHSA-mc7v-wpqv-v4g2.json
+++ b/advisories/unreviewed/2024/06/GHSA-mc7v-wpqv-v4g2/GHSA-mc7v-wpqv-v4g2.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mc7v-wpqv-v4g2",
- "modified": "2024-06-21T12:31:19Z",
+ "modified": "2024-11-06T18:31:05Z",
"published": "2024-06-21T12:31:19Z",
"aliases": [
"CVE-2023-52884"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: cyapa - add missing input core locking to suspend/resume functions\n\nGrab input->mutex during suspend/resume functions like it is done in\nother input drivers. This fixes the following warning during system\nsuspend/resume cycle on Samsung Exynos5250-based Snow Chromebook:\n\n------------[ cut here ]------------\nWARNING: CPU: 1 PID: 1680 at drivers/input/input.c:2291 input_device_enabled+0x68/0x6c\nModules linked in: ...\nCPU: 1 PID: 1680 Comm: kworker/u4:12 Tainted: G W 6.6.0-rc5-next-20231009 #14109\nHardware name: Samsung Exynos (Flattened Device Tree)\nWorkqueue: events_unbound async_run_entry_fn\n unwind_backtrace from show_stack+0x10/0x14\n show_stack from dump_stack_lvl+0x58/0x70\n dump_stack_lvl from __warn+0x1a8/0x1cc\n __warn from warn_slowpath_fmt+0x18c/0x1b4\n warn_slowpath_fmt from input_device_enabled+0x68/0x6c\n input_device_enabled from cyapa_gen3_set_power_mode+0x13c/0x1dc\n cyapa_gen3_set_power_mode from cyapa_reinitialize+0x10c/0x15c\n cyapa_reinitialize from cyapa_resume+0x48/0x98\n cyapa_resume from dpm_run_callback+0x90/0x298\n dpm_run_callback from device_resume+0xb4/0x258\n device_resume from async_resume+0x20/0x64\n async_resume from async_run_entry_fn+0x40/0x15c\n async_run_entry_fn from process_scheduled_works+0xbc/0x6a8\n process_scheduled_works from worker_thread+0x188/0x454\n worker_thread from kthread+0x108/0x140\n kthread from ret_from_fork+0x14/0x28\nException stack(0xf1625fb0 to 0xf1625ff8)\n...\n---[ end trace 0000000000000000 ]---\n...\n------------[ cut here ]------------\nWARNING: CPU: 1 PID: 1680 at drivers/input/input.c:2291 input_device_enabled+0x68/0x6c\nModules linked in: ...\nCPU: 1 PID: 1680 Comm: kworker/u4:12 Tainted: G W 6.6.0-rc5-next-20231009 #14109\nHardware name: Samsung Exynos (Flattened Device Tree)\nWorkqueue: events_unbound async_run_entry_fn\n unwind_backtrace from show_stack+0x10/0x14\n show_stack from dump_stack_lvl+0x58/0x70\n dump_stack_lvl from __warn+0x1a8/0x1cc\n __warn from warn_slowpath_fmt+0x18c/0x1b4\n warn_slowpath_fmt from input_device_enabled+0x68/0x6c\n input_device_enabled from cyapa_gen3_set_power_mode+0x13c/0x1dc\n cyapa_gen3_set_power_mode from cyapa_reinitialize+0x10c/0x15c\n cyapa_reinitialize from cyapa_resume+0x48/0x98\n cyapa_resume from dpm_run_callback+0x90/0x298\n dpm_run_callback from device_resume+0xb4/0x258\n device_resume from async_resume+0x20/0x64\n async_resume from async_run_entry_fn+0x40/0x15c\n async_run_entry_fn from process_scheduled_works+0xbc/0x6a8\n process_scheduled_works from worker_thread+0x188/0x454\n worker_thread from kthread+0x108/0x140\n kthread from ret_from_fork+0x14/0x28\nException stack(0xf1625fb0 to 0xf1625ff8)\n...\n---[ end trace 0000000000000000 ]---",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -43,7 +46,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-21T11:15:09Z"
diff --git a/advisories/unreviewed/2024/06/GHSA-mqxf-7jx4-2h8p/GHSA-mqxf-7jx4-2h8p.json b/advisories/unreviewed/2024/06/GHSA-mqxf-7jx4-2h8p/GHSA-mqxf-7jx4-2h8p.json
index 2b317d94267..8dd18ad1eae 100644
--- a/advisories/unreviewed/2024/06/GHSA-mqxf-7jx4-2h8p/GHSA-mqxf-7jx4-2h8p.json
+++ b/advisories/unreviewed/2024/06/GHSA-mqxf-7jx4-2h8p/GHSA-mqxf-7jx4-2h8p.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mqxf-7jx4-2h8p",
- "modified": "2024-10-17T15:31:07Z",
+ "modified": "2024-11-06T18:31:05Z",
"published": "2024-06-19T15:30:52Z",
"aliases": [
"CVE-2024-38544"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Fix seg fault in rxe_comp_queue_pkt\n\nIn rxe_comp_queue_pkt() an incoming response packet skb is enqueued to the\nresp_pkts queue and then a decision is made whether to run the completer\ntask inline or schedule it. Finally the skb is dereferenced to bump a 'hw'\nperformance counter. This is wrong because if the completer task is\nalready running in a separate thread it may have already processed the skb\nand freed it which can cause a seg fault. This has been observed\ninfrequently in testing at high scale.\n\nThis patch fixes this by changing the order of enqueuing the packet until\nafter the counter is accessed.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H"
+ }
],
"affected": [
@@ -51,7 +54,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-19T14:15:14Z"
diff --git a/advisories/unreviewed/2024/06/GHSA-x3jm-2wx8-ccv4/GHSA-x3jm-2wx8-ccv4.json b/advisories/unreviewed/2024/06/GHSA-x3jm-2wx8-ccv4/GHSA-x3jm-2wx8-ccv4.json
index ef0d2a0f38c..b1f05d6cb22 100644
--- a/advisories/unreviewed/2024/06/GHSA-x3jm-2wx8-ccv4/GHSA-x3jm-2wx8-ccv4.json
+++ b/advisories/unreviewed/2024/06/GHSA-x3jm-2wx8-ccv4/GHSA-x3jm-2wx8-ccv4.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x3jm-2wx8-ccv4",
- "modified": "2024-06-25T06:30:39Z",
+ "modified": "2024-11-06T18:31:05Z",
"published": "2024-06-25T06:30:39Z",
"aliases": [
"CVE-2024-23155"
],
"details": "A maliciously crafted MODEL file, when parsed in atf_asm_interface.dll through Autodesk applications, can be used to cause a Heap-based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
"CWE-122"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-25T04:15:13Z"
diff --git a/advisories/unreviewed/2024/07/GHSA-6fq4-3v58-2pfx/GHSA-6fq4-3v58-2pfx.json b/advisories/unreviewed/2024/07/GHSA-6fq4-3v58-2pfx/GHSA-6fq4-3v58-2pfx.json
index a4a1e6f94c9..69045b7f2af 100644
--- a/advisories/unreviewed/2024/07/GHSA-6fq4-3v58-2pfx/GHSA-6fq4-3v58-2pfx.json
+++ b/advisories/unreviewed/2024/07/GHSA-6fq4-3v58-2pfx/GHSA-6fq4-3v58-2pfx.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6fq4-3v58-2pfx",
- "modified": "2024-07-30T09:32:09Z",
+ "modified": "2024-11-06T18:31:05Z",
"published": "2024-07-30T09:32:09Z",
"aliases": [
"CVE-2024-41141"
],
"details": "Stored cross-site scripting vulnerability exists in EC-CUBE Web API Plugin. When there are multiple users using OAuth Management feature and one of them inputs some crafted value on the OAuth Management page, an arbitrary script may be executed on the web browser of the other user who accessed the management page.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-30T09:15:04Z"
diff --git a/advisories/unreviewed/2024/07/GHSA-x2q3-f99c-25ff/GHSA-x2q3-f99c-25ff.json b/advisories/unreviewed/2024/07/GHSA-x2q3-f99c-25ff/GHSA-x2q3-f99c-25ff.json
index 7623b9e0257..090db9671a3 100644
--- a/advisories/unreviewed/2024/07/GHSA-x2q3-f99c-25ff/GHSA-x2q3-f99c-25ff.json
+++ b/advisories/unreviewed/2024/07/GHSA-x2q3-f99c-25ff/GHSA-x2q3-f99c-25ff.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x2q3-f99c-25ff",
- "modified": "2024-07-16T18:31:42Z",
+ "modified": "2024-11-06T18:31:05Z",
"published": "2024-07-09T15:30:55Z",
"aliases": [
"CVE-2024-6615"
],
"details": "Memory safety bugs present in Firefox 127. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-787"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-09T15:15:13Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-prg4-487r-rr8w/GHSA-prg4-487r-rr8w.json b/advisories/unreviewed/2024/08/GHSA-prg4-487r-rr8w/GHSA-prg4-487r-rr8w.json
index 65824ddb3f3..d42479a8a2f 100644
--- a/advisories/unreviewed/2024/08/GHSA-prg4-487r-rr8w/GHSA-prg4-487r-rr8w.json
+++ b/advisories/unreviewed/2024/08/GHSA-prg4-487r-rr8w/GHSA-prg4-487r-rr8w.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-prg4-487r-rr8w",
- "modified": "2024-08-22T18:31:23Z",
+ "modified": "2024-11-06T18:31:05Z",
"published": "2024-08-22T18:31:23Z",
"aliases": [
"CVE-2024-42773"
],
"details": "An Incorrect Access Control vulnerability was found in /admin/edit_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to edit the valid hotel room entries in the administrator section.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-863"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-22T18:15:10Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-qpx5-6ww4-hp56/GHSA-qpx5-6ww4-hp56.json b/advisories/unreviewed/2024/08/GHSA-qpx5-6ww4-hp56/GHSA-qpx5-6ww4-hp56.json
index 079df012da2..9665b6f8e6f 100644
--- a/advisories/unreviewed/2024/08/GHSA-qpx5-6ww4-hp56/GHSA-qpx5-6ww4-hp56.json
+++ b/advisories/unreviewed/2024/08/GHSA-qpx5-6ww4-hp56/GHSA-qpx5-6ww4-hp56.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-338"
],
"severity": "LOW",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/10/GHSA-32jw-rrh7-q59g/GHSA-32jw-rrh7-q59g.json b/advisories/unreviewed/2024/10/GHSA-32jw-rrh7-q59g/GHSA-32jw-rrh7-q59g.json
index c1aef3045b6..bcde2e350e5 100644
--- a/advisories/unreviewed/2024/10/GHSA-32jw-rrh7-q59g/GHSA-32jw-rrh7-q59g.json
+++ b/advisories/unreviewed/2024/10/GHSA-32jw-rrh7-q59g/GHSA-32jw-rrh7-q59g.json
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-404"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/10/GHSA-5362-r6fh-h45f/GHSA-5362-r6fh-h45f.json b/advisories/unreviewed/2024/10/GHSA-5362-r6fh-h45f/GHSA-5362-r6fh-h45f.json
index 98757b2dd14..f1026aa2227 100644
--- a/advisories/unreviewed/2024/10/GHSA-5362-r6fh-h45f/GHSA-5362-r6fh-h45f.json
+++ b/advisories/unreviewed/2024/10/GHSA-5362-r6fh-h45f/GHSA-5362-r6fh-h45f.json
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5362-r6fh-h45f",
- "modified": "2024-10-23T15:31:08Z",
+ "modified": "2024-11-06T18:31:05Z",
"published": "2024-10-23T15:31:08Z",
"aliases": [
"CVE-2024-5764"
],
"details": "Use of Hard-coded Credentials vulnerability in Sonatype Nexus Repository has been discovered in the code responsible for encrypting any secrets stored in the Nexus Repository configuration database (SMTP or HTTP proxy credentials, user tokens, tokens, among others). The affected versions relied on a static hard-coded encryption passphrase. While it was possible for an administrator to define an alternate encryption passphrase, it could only be done at first boot and not updated.\n\nThis issue affects Nexus Repository: from 3.0.0 through 3.72.0.",
"severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"
+ },
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
diff --git a/advisories/unreviewed/2024/10/GHSA-8c7g-vx5g-cmpg/GHSA-8c7g-vx5g-cmpg.json b/advisories/unreviewed/2024/10/GHSA-8c7g-vx5g-cmpg/GHSA-8c7g-vx5g-cmpg.json
index d9e3cb12239..9139756b1ef 100644
--- a/advisories/unreviewed/2024/10/GHSA-8c7g-vx5g-cmpg/GHSA-8c7g-vx5g-cmpg.json
+++ b/advisories/unreviewed/2024/10/GHSA-8c7g-vx5g-cmpg/GHSA-8c7g-vx5g-cmpg.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8c7g-vx5g-cmpg",
- "modified": "2024-10-14T15:30:46Z",
+ "modified": "2024-11-06T18:31:05Z",
"published": "2024-10-14T15:30:46Z",
"aliases": [
"CVE-2024-9936"
],
"details": "When manipulating the selection node cache, an attacker may have been able to cause unexpected behavior, potentially leading to an exploitable crash. This vulnerability affects Firefox < 131.0.3.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-362"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-14T14:15:12Z"
diff --git a/advisories/unreviewed/2024/10/GHSA-w88c-j332-rfjj/GHSA-w88c-j332-rfjj.json b/advisories/unreviewed/2024/10/GHSA-w88c-j332-rfjj/GHSA-w88c-j332-rfjj.json
index a1620870375..34e372f9477 100644
--- a/advisories/unreviewed/2024/10/GHSA-w88c-j332-rfjj/GHSA-w88c-j332-rfjj.json
+++ b/advisories/unreviewed/2024/10/GHSA-w88c-j332-rfjj/GHSA-w88c-j332-rfjj.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w88c-j332-rfjj",
- "modified": "2024-10-11T21:31:35Z",
+ "modified": "2024-11-06T18:31:05Z",
"published": "2024-10-11T21:31:35Z",
"aliases": [
"CVE-2024-45184"
],
"details": "An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with chipset Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, Modem 5123, and Modem 5300. A USAT out-of-bounds write due to a heap buffer overflow can lead to a Denial of Service.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-120"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-11T21:15:06Z"
diff --git a/advisories/unreviewed/2024/11/GHSA-36q8-mfw8-2m98/GHSA-36q8-mfw8-2m98.json b/advisories/unreviewed/2024/11/GHSA-36q8-mfw8-2m98/GHSA-36q8-mfw8-2m98.json
index 638daef3bde..d5010e17b7d 100644
--- a/advisories/unreviewed/2024/11/GHSA-36q8-mfw8-2m98/GHSA-36q8-mfw8-2m98.json
+++ b/advisories/unreviewed/2024/11/GHSA-36q8-mfw8-2m98/GHSA-36q8-mfw8-2m98.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-36q8-mfw8-2m98",
- "modified": "2024-11-06T06:30:31Z",
+ "modified": "2024-11-06T18:31:10Z",
"published": "2024-11-06T06:30:31Z",
"aliases": [
"CVE-2024-7879"
],
"details": "The WP ULike WordPress plugin before 4.7.5 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-06T06:15:03Z"
diff --git a/advisories/unreviewed/2024/11/GHSA-38gf-q933-q62g/GHSA-38gf-q933-q62g.json b/advisories/unreviewed/2024/11/GHSA-38gf-q933-q62g/GHSA-38gf-q933-q62g.json
new file mode 100644
index 00000000000..991109cacee
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-38gf-q933-q62g/GHSA-38gf-q933-q62g.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-38gf-q933-q62g",
+ "modified": "2024-11-06T18:31:11Z",
+ "published": "2024-11-06T18:31:11Z",
+ "aliases": [
+ "CVE-2024-20531"
+ ],
+ "details": "A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device and conduct a server-side request forgery (SSRF) attack through an affected device. To exploit this vulnerability, the attacker would need valid Super Admin credentials.\n\nThis vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing XML input. An attacker could exploit this vulnerability by sending a crafted API request to an affected device. A successful exploit could allow the attacker to read arbitrary files on the underlying operating system or conduct an SSRF attack through the affected device.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20531"
+ },
+ {
+ "type": "WEB",
+ "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-vuln-DBQdWRy"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-611"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T17:15:18Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-3c6f-r64x-4f7r/GHSA-3c6f-r64x-4f7r.json b/advisories/unreviewed/2024/11/GHSA-3c6f-r64x-4f7r/GHSA-3c6f-r64x-4f7r.json
new file mode 100644
index 00000000000..f833812eee3
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-3c6f-r64x-4f7r/GHSA-3c6f-r64x-4f7r.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3c6f-r64x-4f7r",
+ "modified": "2024-11-06T18:31:11Z",
+ "published": "2024-11-06T18:31:11Z",
+ "aliases": [
+ "CVE-2024-20457"
+ ],
+ "details": "A vulnerability in the logging component of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system.\n\nThis vulnerability is due to the storage of unencrypted credentials in certain logs. An attacker could exploit this vulnerability by accessing the logs on an affected system and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to access sensitive information from the device.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20457"
+ },
+ {
+ "type": "WEB",
+ "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-imp-inf-disc-cUPKuA5n"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-200"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T17:15:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-3f53-hv33-hf39/GHSA-3f53-hv33-hf39.json b/advisories/unreviewed/2024/11/GHSA-3f53-hv33-hf39/GHSA-3f53-hv33-hf39.json
new file mode 100644
index 00000000000..7a5812758f3
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-3f53-hv33-hf39/GHSA-3f53-hv33-hf39.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3f53-hv33-hf39",
+ "modified": "2024-11-06T18:31:11Z",
+ "published": "2024-11-06T18:31:11Z",
+ "aliases": [
+ "CVE-2024-20507"
+ ],
+ "details": "A vulnerability in the logging subsystem of Cisco Meeting Management could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system.\n\nThis vulnerability is due to improper storage of sensitive information within the web-based management interface of an affected device. An attacker could exploit this vulnerability by logging in to the web-based management interface. A successful exploit could allow the attacker to view sensitive data that is stored on the affected device.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20507"
+ },
+ {
+ "type": "WEB",
+ "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cmm-info-disc-9ZEMAhGA"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-200"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T17:15:16Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-47cf-pjqq-7626/GHSA-47cf-pjqq-7626.json b/advisories/unreviewed/2024/11/GHSA-47cf-pjqq-7626/GHSA-47cf-pjqq-7626.json
new file mode 100644
index 00000000000..bfc9cfead93
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-47cf-pjqq-7626/GHSA-47cf-pjqq-7626.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-47cf-pjqq-7626",
+ "modified": "2024-11-06T18:31:11Z",
+ "published": "2024-11-06T18:31:11Z",
+ "aliases": [
+ "CVE-2024-20534"
+ ],
+ "details": "A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 with Cisco Multiplatform Firmware could allow an authenticated, remote attacker to conduct stored cross-site scripting (XSS) attacks against users.\n\nThis vulnerability exists because the web UI of an affected device does not properly validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.\nNote: To exploit this vulnerability, Web Access must be enabled on the phone and the attacker must have Admin credentials on the device. Web Access is disabled by default.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20534"
+ },
+ {
+ "type": "WEB",
+ "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-mpp-xss-8tAV2TvF"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T17:15:18Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-4p84-57xr-x7v6/GHSA-4p84-57xr-x7v6.json b/advisories/unreviewed/2024/11/GHSA-4p84-57xr-x7v6/GHSA-4p84-57xr-x7v6.json
index 4b8c1c9895d..fbd554f3931 100644
--- a/advisories/unreviewed/2024/11/GHSA-4p84-57xr-x7v6/GHSA-4p84-57xr-x7v6.json
+++ b/advisories/unreviewed/2024/11/GHSA-4p84-57xr-x7v6/GHSA-4p84-57xr-x7v6.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/11/GHSA-5589-5vr7-rjh2/GHSA-5589-5vr7-rjh2.json b/advisories/unreviewed/2024/11/GHSA-5589-5vr7-rjh2/GHSA-5589-5vr7-rjh2.json
new file mode 100644
index 00000000000..bdc0e8ee621
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-5589-5vr7-rjh2/GHSA-5589-5vr7-rjh2.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5589-5vr7-rjh2",
+ "modified": "2024-11-06T18:31:11Z",
+ "published": "2024-11-06T18:31:11Z",
+ "aliases": [
+ "CVE-2024-20525"
+ ],
+ "details": "A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface.\n\nThis vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20525"
+ },
+ {
+ "type": "WEB",
+ "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-vuln-DBQdWRy"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T17:15:16Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-58wv-w3hc-2c76/GHSA-58wv-w3hc-2c76.json b/advisories/unreviewed/2024/11/GHSA-58wv-w3hc-2c76/GHSA-58wv-w3hc-2c76.json
new file mode 100644
index 00000000000..799ba0e4317
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-58wv-w3hc-2c76/GHSA-58wv-w3hc-2c76.json
@@ -0,0 +1,42 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-58wv-w3hc-2c76",
+ "modified": "2024-11-06T18:31:11Z",
+ "published": "2024-11-06T18:31:11Z",
+ "aliases": [
+ "CVE-2024-10827"
+ ],
+ "details": "Use after free in Serial in Google Chrome prior to 130.0.6723.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10827"
+ },
+ {
+ "type": "WEB",
+ "url": "https://chromereleases.googleblog.com/2024/11/stable-channel-update-for-desktop.html"
+ },
+ {
+ "type": "WEB",
+ "url": "https://issues.chromium.org/issues/375065084"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T17:15:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-5grf-38mv-vxvv/GHSA-5grf-38mv-vxvv.json b/advisories/unreviewed/2024/11/GHSA-5grf-38mv-vxvv/GHSA-5grf-38mv-vxvv.json
index db386a73c5b..995ee1ce6d7 100644
--- a/advisories/unreviewed/2024/11/GHSA-5grf-38mv-vxvv/GHSA-5grf-38mv-vxvv.json
+++ b/advisories/unreviewed/2024/11/GHSA-5grf-38mv-vxvv/GHSA-5grf-38mv-vxvv.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5grf-38mv-vxvv",
- "modified": "2024-11-05T21:30:43Z",
+ "modified": "2024-11-06T18:31:08Z",
"published": "2024-11-05T21:30:43Z",
"aliases": [
"CVE-2024-51382"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 allows an attacker to reset the administrator's password. This critical security flaw can result in unauthorized access to the platform, enabling attackers to hijack admin accounts and compromise the integrity and security of the system.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-05T19:15:07Z"
diff --git a/advisories/unreviewed/2024/11/GHSA-5h6c-4hvj-43pr/GHSA-5h6c-4hvj-43pr.json b/advisories/unreviewed/2024/11/GHSA-5h6c-4hvj-43pr/GHSA-5h6c-4hvj-43pr.json
index 4b80c84afa0..71e371453f9 100644
--- a/advisories/unreviewed/2024/11/GHSA-5h6c-4hvj-43pr/GHSA-5h6c-4hvj-43pr.json
+++ b/advisories/unreviewed/2024/11/GHSA-5h6c-4hvj-43pr/GHSA-5h6c-4hvj-43pr.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-77"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/11/GHSA-5w27-pxmv-rgxx/GHSA-5w27-pxmv-rgxx.json b/advisories/unreviewed/2024/11/GHSA-5w27-pxmv-rgxx/GHSA-5w27-pxmv-rgxx.json
new file mode 100644
index 00000000000..8ce3e51def7
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-5w27-pxmv-rgxx/GHSA-5w27-pxmv-rgxx.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5w27-pxmv-rgxx",
+ "modified": "2024-11-06T18:31:11Z",
+ "published": "2024-11-06T18:31:11Z",
+ "aliases": [
+ "CVE-2024-20536"
+ ],
+ "details": "A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with read-only privileges to execute arbitrary SQL commands on an affected device.\n\nThis vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to a specific REST API endpoint or web-based management interface. A successful exploit could allow the attacker to read, modify, or delete arbitrary data on an internal database, which could affect the availability of the device. ",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20536"
+ },
+ {
+ "type": "WEB",
+ "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndfc-sqli-CyPPAxrL"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T17:15:19Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-5x5j-83rp-44hj/GHSA-5x5j-83rp-44hj.json b/advisories/unreviewed/2024/11/GHSA-5x5j-83rp-44hj/GHSA-5x5j-83rp-44hj.json
new file mode 100644
index 00000000000..7c23adefce7
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-5x5j-83rp-44hj/GHSA-5x5j-83rp-44hj.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5x5j-83rp-44hj",
+ "modified": "2024-11-06T18:31:11Z",
+ "published": "2024-11-06T18:31:11Z",
+ "aliases": [
+ "CVE-2024-20527"
+ ],
+ "details": "A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and delete arbitrary files on an affected device. To exploit this vulnerability, the attacker would need valid Super Admin credentials.\n\nThis vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could exploit this vulnerability by sending a crafted API request to an affected device. A successful exploit could allow the attacker to read or delete arbitrary files on the underlying operating system.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20527"
+ },
+ {
+ "type": "WEB",
+ "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-vuln-DBQdWRy"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-22"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T17:15:17Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-62f5-j9hj-j5w2/GHSA-62f5-j9hj-j5w2.json b/advisories/unreviewed/2024/11/GHSA-62f5-j9hj-j5w2/GHSA-62f5-j9hj-j5w2.json
index b7bc311eee8..18f0c6bab52 100644
--- a/advisories/unreviewed/2024/11/GHSA-62f5-j9hj-j5w2/GHSA-62f5-j9hj-j5w2.json
+++ b/advisories/unreviewed/2024/11/GHSA-62f5-j9hj-j5w2/GHSA-62f5-j9hj-j5w2.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-77"
],
"severity": "CRITICAL",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/11/GHSA-66rq-9x8p-ghcr/GHSA-66rq-9x8p-ghcr.json b/advisories/unreviewed/2024/11/GHSA-66rq-9x8p-ghcr/GHSA-66rq-9x8p-ghcr.json
index ed457dea6e2..ad002a69c3c 100644
--- a/advisories/unreviewed/2024/11/GHSA-66rq-9x8p-ghcr/GHSA-66rq-9x8p-ghcr.json
+++ b/advisories/unreviewed/2024/11/GHSA-66rq-9x8p-ghcr/GHSA-66rq-9x8p-ghcr.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-77"
],
"severity": "CRITICAL",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/11/GHSA-6xw2-v987-mq7h/GHSA-6xw2-v987-mq7h.json b/advisories/unreviewed/2024/11/GHSA-6xw2-v987-mq7h/GHSA-6xw2-v987-mq7h.json
new file mode 100644
index 00000000000..b699e3994de
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-6xw2-v987-mq7h/GHSA-6xw2-v987-mq7h.json
@@ -0,0 +1,54 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6xw2-v987-mq7h",
+ "modified": "2024-11-06T18:31:10Z",
+ "published": "2024-11-06T18:31:10Z",
+ "aliases": [
+ "CVE-2024-10920"
+ ],
+ "details": "A vulnerability was found in mariazevedo88 travels-java-api up to 5.0.1 and classified as problematic. Affected by this issue is the function doFilterInternal of the file travels-java-api-master\\src\\main\\java\\io\\github\\mariazevedo88\\travelsjavaapi\\filters\\JwtAuthenticationTokenFilter.java of the component JWT Secret Handler. The manipulation leads to use of hard-coded cryptographic key\n . The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10920"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/mariazevedo88/travels-java-api/issues/23"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.283316"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.283316"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.433458"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": "LOW",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T16:15:05Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-75gp-f39c-g44v/GHSA-75gp-f39c-g44v.json b/advisories/unreviewed/2024/11/GHSA-75gp-f39c-g44v/GHSA-75gp-f39c-g44v.json
index 783471dfa53..769a77f0a1c 100644
--- a/advisories/unreviewed/2024/11/GHSA-75gp-f39c-g44v/GHSA-75gp-f39c-g44v.json
+++ b/advisories/unreviewed/2024/11/GHSA-75gp-f39c-g44v/GHSA-75gp-f39c-g44v.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-75gp-f39c-g44v",
- "modified": "2024-11-06T00:31:55Z",
+ "modified": "2024-11-06T18:31:08Z",
"published": "2024-11-06T00:31:55Z",
"aliases": [
"CVE-2024-51116"
],
"details": "Tenda AC6 v2.0 V15.03.06.50 was discovered to contain a buffer overflow in the function 'formSetPPTPServer'.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-120"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-05T22:15:21Z"
diff --git a/advisories/unreviewed/2024/11/GHSA-7v36-f3gj-qcg5/GHSA-7v36-f3gj-qcg5.json b/advisories/unreviewed/2024/11/GHSA-7v36-f3gj-qcg5/GHSA-7v36-f3gj-qcg5.json
new file mode 100644
index 00000000000..fd766389a34
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-7v36-f3gj-qcg5/GHSA-7v36-f3gj-qcg5.json
@@ -0,0 +1,54 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7v36-f3gj-qcg5",
+ "modified": "2024-11-06T18:31:10Z",
+ "published": "2024-11-06T18:31:10Z",
+ "aliases": [
+ "CVE-2024-10919"
+ ],
+ "details": "A vulnerability has been found in didi Super-Jacoco 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /cov/triggerUnitCover. The manipulation of the argument uuid leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10919"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/didi/super-jacoco/issues/49"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.283315"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.283315"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.432689"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-74"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T16:15:05Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-7wfp-w5xf-g7mm/GHSA-7wfp-w5xf-g7mm.json b/advisories/unreviewed/2024/11/GHSA-7wfp-w5xf-g7mm/GHSA-7wfp-w5xf-g7mm.json
new file mode 100644
index 00000000000..19c62b10632
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-7wfp-w5xf-g7mm/GHSA-7wfp-w5xf-g7mm.json
@@ -0,0 +1,42 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7wfp-w5xf-g7mm",
+ "modified": "2024-11-06T18:31:11Z",
+ "published": "2024-11-06T18:31:11Z",
+ "aliases": [
+ "CVE-2024-10826"
+ ],
+ "details": "Use after free in Family Experiences in Google Chrome on Android prior to 130.0.6723.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10826"
+ },
+ {
+ "type": "WEB",
+ "url": "https://chromereleases.googleblog.com/2024/11/stable-channel-update-for-desktop.html"
+ },
+ {
+ "type": "WEB",
+ "url": "https://issues.chromium.org/issues/370217726"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T17:15:13Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-8mqv-23wv-wqfg/GHSA-8mqv-23wv-wqfg.json b/advisories/unreviewed/2024/11/GHSA-8mqv-23wv-wqfg/GHSA-8mqv-23wv-wqfg.json
new file mode 100644
index 00000000000..b3946e1030f
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-8mqv-23wv-wqfg/GHSA-8mqv-23wv-wqfg.json
@@ -0,0 +1,42 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8mqv-23wv-wqfg",
+ "modified": "2024-11-06T18:31:11Z",
+ "published": "2024-11-06T18:31:11Z",
+ "aliases": [
+ "CVE-2024-10318"
+ ],
+ "details": "A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacker to fix a victim's session to an attacker-controlled account. As a result, although the attacker cannot log in as the victim, they can force the session to associate it with the attacker-controlled account, leading to potential misuse of the victim's session.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10318"
+ },
+ {
+ "type": "WEB",
+ "url": "https://my.f5.com/manage/s/article/K000148232"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-384"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T17:15:13Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-8qc4-f7m5-569p/GHSA-8qc4-f7m5-569p.json b/advisories/unreviewed/2024/11/GHSA-8qc4-f7m5-569p/GHSA-8qc4-f7m5-569p.json
index e40d023cf4e..b29cded9847 100644
--- a/advisories/unreviewed/2024/11/GHSA-8qc4-f7m5-569p/GHSA-8qc4-f7m5-569p.json
+++ b/advisories/unreviewed/2024/11/GHSA-8qc4-f7m5-569p/GHSA-8qc4-f7m5-569p.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8qc4-f7m5-569p",
- "modified": "2024-11-04T15:31:58Z",
+ "modified": "2024-11-06T18:31:05Z",
"published": "2024-11-04T15:31:58Z",
"aliases": [
"CVE-2024-50529"
diff --git a/advisories/unreviewed/2024/11/GHSA-8xq5-r7g5-m3f8/GHSA-8xq5-r7g5-m3f8.json b/advisories/unreviewed/2024/11/GHSA-8xq5-r7g5-m3f8/GHSA-8xq5-r7g5-m3f8.json
new file mode 100644
index 00000000000..c2613e4cd6c
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-8xq5-r7g5-m3f8/GHSA-8xq5-r7g5-m3f8.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8xq5-r7g5-m3f8",
+ "modified": "2024-11-06T18:31:11Z",
+ "published": "2024-11-06T18:31:11Z",
+ "aliases": [
+ "CVE-2024-20476"
+ ],
+ "details": "A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific file management functions.\n\nThis vulnerability is due to lack of server-side validation of Administrator permissions. An attacker could exploit this vulnerability by submitting a crafted HTTP request to an affected system. A successful exploit could allow the attacker to upload files to a location that should be restricted. To exploit this vulnerability, an attacker would need valid Read-Only Administrator credentials.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20476"
+ },
+ {
+ "type": "WEB",
+ "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-vulns-AF544ED5"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-602"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T17:15:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-9m98-8pf8-hfc4/GHSA-9m98-8pf8-hfc4.json b/advisories/unreviewed/2024/11/GHSA-9m98-8pf8-hfc4/GHSA-9m98-8pf8-hfc4.json
new file mode 100644
index 00000000000..2191ecf1aa0
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-9m98-8pf8-hfc4/GHSA-9m98-8pf8-hfc4.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9m98-8pf8-hfc4",
+ "modified": "2024-11-06T18:31:11Z",
+ "published": "2024-11-06T18:31:11Z",
+ "aliases": [
+ "CVE-2024-20532"
+ ],
+ "details": "A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and delete arbitrary files on an affected device. To exploit this vulnerability, the attacker would need valid Super Admin credentials.\n\nThis vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could exploit this vulnerability by sending a crafted API request to an affected device. A successful exploit could allow the attacker to read or delete arbitrary files on the underlying operating system.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20532"
+ },
+ {
+ "type": "WEB",
+ "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-vuln-DBQdWRy"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-22"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T17:15:18Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-cgwv-mmpx-f92h/GHSA-cgwv-mmpx-f92h.json b/advisories/unreviewed/2024/11/GHSA-cgwv-mmpx-f92h/GHSA-cgwv-mmpx-f92h.json
new file mode 100644
index 00000000000..886f34db7db
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-cgwv-mmpx-f92h/GHSA-cgwv-mmpx-f92h.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cgwv-mmpx-f92h",
+ "modified": "2024-11-06T18:31:11Z",
+ "published": "2024-11-06T18:31:11Z",
+ "aliases": [
+ "CVE-2024-20514"
+ ],
+ "details": "A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, low-privileged, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.\n\nThis vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into a specific page of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information. To exploit this vulnerability, the attacker must have at least a low-privileged account on an affected device.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20514"
+ },
+ {
+ "type": "WEB",
+ "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-epnmpi-sxss-yyf2zkXs"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T17:15:16Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-cjhr-gw79-v8fh/GHSA-cjhr-gw79-v8fh.json b/advisories/unreviewed/2024/11/GHSA-cjhr-gw79-v8fh/GHSA-cjhr-gw79-v8fh.json
index c1f243f93e3..fc9b42ca752 100644
--- a/advisories/unreviewed/2024/11/GHSA-cjhr-gw79-v8fh/GHSA-cjhr-gw79-v8fh.json
+++ b/advisories/unreviewed/2024/11/GHSA-cjhr-gw79-v8fh/GHSA-cjhr-gw79-v8fh.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cjhr-gw79-v8fh",
- "modified": "2024-11-06T00:31:55Z",
+ "modified": "2024-11-06T18:31:09Z",
"published": "2024-11-06T00:31:55Z",
"aliases": [
"CVE-2024-48176"
],
"details": "Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of login attempts, and the verification code will not be refreshed after a failed login, which allows attackers to blast the username and password and log into the system backend.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-863"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-05T23:15:04Z"
diff --git a/advisories/unreviewed/2024/11/GHSA-cjrc-86h3-3hxh/GHSA-cjrc-86h3-3hxh.json b/advisories/unreviewed/2024/11/GHSA-cjrc-86h3-3hxh/GHSA-cjrc-86h3-3hxh.json
index 4c88ea8ad31..4e411745f29 100644
--- a/advisories/unreviewed/2024/11/GHSA-cjrc-86h3-3hxh/GHSA-cjrc-86h3-3hxh.json
+++ b/advisories/unreviewed/2024/11/GHSA-cjrc-86h3-3hxh/GHSA-cjrc-86h3-3hxh.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cjrc-86h3-3hxh",
- "modified": "2024-11-05T18:32:05Z",
+ "modified": "2024-11-06T18:31:05Z",
"published": "2024-11-05T06:30:34Z",
"aliases": [
"CVE-2024-7876"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/11/GHSA-fj4q-693m-8fx4/GHSA-fj4q-693m-8fx4.json b/advisories/unreviewed/2024/11/GHSA-fj4q-693m-8fx4/GHSA-fj4q-693m-8fx4.json
new file mode 100644
index 00000000000..4dc82c96a9b
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-fj4q-693m-8fx4/GHSA-fj4q-693m-8fx4.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fj4q-693m-8fx4",
+ "modified": "2024-11-06T18:31:11Z",
+ "published": "2024-11-06T18:31:11Z",
+ "aliases": [
+ "CVE-2024-20539"
+ ],
+ "details": "A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct a stored XSS attack against a user of the interface.\n\nThis vulnerability exists because the web-based management interface does not sufficiently validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker would need valid administrative credentials on an affected device.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20539"
+ },
+ {
+ "type": "WEB",
+ "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-auth-bypass-BBRf7mkE"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T17:15:19Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-fqm6-hhvg-fmrr/GHSA-fqm6-hhvg-fmrr.json b/advisories/unreviewed/2024/11/GHSA-fqm6-hhvg-fmrr/GHSA-fqm6-hhvg-fmrr.json
new file mode 100644
index 00000000000..dde33809d79
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-fqm6-hhvg-fmrr/GHSA-fqm6-hhvg-fmrr.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fqm6-hhvg-fmrr",
+ "modified": "2024-11-06T18:31:11Z",
+ "published": "2024-11-06T18:31:11Z",
+ "aliases": [
+ "CVE-2024-20537"
+ ],
+ "details": "A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific administrative functions.\n\nThis vulnerability is due to a lack of server-side validation of Administrator permissions. An attacker could exploit this vulnerability by submitting a crafted HTTP request to an affected system. A successful exploit could allow the attacker to conduct administrative functions beyond their intended access level. To exploit this vulnerability, an attacker would need Read-Only Administrator credentials.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20537"
+ },
+ {
+ "type": "WEB",
+ "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-auth-bypass-BBRf7mkE"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-863"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T17:15:19Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-g337-g667-mjvw/GHSA-g337-g667-mjvw.json b/advisories/unreviewed/2024/11/GHSA-g337-g667-mjvw/GHSA-g337-g667-mjvw.json
index a821a5bfdb3..0472288cfbe 100644
--- a/advisories/unreviewed/2024/11/GHSA-g337-g667-mjvw/GHSA-g337-g667-mjvw.json
+++ b/advisories/unreviewed/2024/11/GHSA-g337-g667-mjvw/GHSA-g337-g667-mjvw.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g337-g667-mjvw",
- "modified": "2024-11-06T09:31:22Z",
+ "modified": "2024-11-06T18:31:10Z",
"published": "2024-11-06T09:31:21Z",
"aliases": [
"CVE-2024-9681"
],
"details": "When curl is asked to use HSTS, the expiry time for a subdomain might\noverwrite a parent domain's cache entry, making it end sooner or later than\notherwise intended.\n\nThis affects curl using applications that enable HSTS and use URLs with the\ninsecure `HTTP://` scheme and perform transfers with hosts like\n`x.example.com` as well as `example.com` where the first host is a subdomain\nof the second host.\n\n(The HSTS cache either needs to have been populated manually or there needs to\nhave been previous HTTPS accesses done as the cache needs to have entries for\nthe domains involved to trigger this problem.)\n\nWhen `x.example.com` responds with `Strict-Transport-Security:` headers, this\nbug can make the subdomain's expiry timeout *bleed over* and get set for the\nparent domain `example.com` in curl's HSTS cache.\n\nThe result of a triggered bug is that HTTP accesses to `example.com` get\nconverted to HTTPS for a different period of time than what was asked for by\nthe origin server. If `example.com` for example stops supporting HTTPS at its\nexpiry time, curl might then fail to access `http://example.com` until the\n(wrongly set) timeout expires. This bug can also expire the parent's entry\n*earlier*, thus making curl inadvertently switch back to insecure HTTP earlier\nthan otherwise intended.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
+ }
],
"affected": [
@@ -35,7 +38,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-06T08:15:03Z"
diff --git a/advisories/unreviewed/2024/11/GHSA-gcp7-c8fr-5c36/GHSA-gcp7-c8fr-5c36.json b/advisories/unreviewed/2024/11/GHSA-gcp7-c8fr-5c36/GHSA-gcp7-c8fr-5c36.json
new file mode 100644
index 00000000000..03d054eda0c
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-gcp7-c8fr-5c36/GHSA-gcp7-c8fr-5c36.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gcp7-c8fr-5c36",
+ "modified": "2024-11-06T18:31:11Z",
+ "published": "2024-11-06T18:31:11Z",
+ "aliases": [
+ "CVE-2024-20487"
+ ],
+ "details": "A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct a stored XSS attack against a user of the interface.\n\nThis vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have at least a low-privileged account on an affected device.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20487"
+ },
+ {
+ "type": "WEB",
+ "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-vulns-AF544ED5"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T17:15:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-gpj2-23jf-pgq2/GHSA-gpj2-23jf-pgq2.json b/advisories/unreviewed/2024/11/GHSA-gpj2-23jf-pgq2/GHSA-gpj2-23jf-pgq2.json
index 6ea126da247..d6aa84e66ec 100644
--- a/advisories/unreviewed/2024/11/GHSA-gpj2-23jf-pgq2/GHSA-gpj2-23jf-pgq2.json
+++ b/advisories/unreviewed/2024/11/GHSA-gpj2-23jf-pgq2/GHSA-gpj2-23jf-pgq2.json
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
+ "CWE-22",
"CWE-35"
],
"severity": "HIGH",
diff --git a/advisories/unreviewed/2024/11/GHSA-hg63-44hg-r9q3/GHSA-hg63-44hg-r9q3.json b/advisories/unreviewed/2024/11/GHSA-hg63-44hg-r9q3/GHSA-hg63-44hg-r9q3.json
index 6757a38a859..105642bd94e 100644
--- a/advisories/unreviewed/2024/11/GHSA-hg63-44hg-r9q3/GHSA-hg63-44hg-r9q3.json
+++ b/advisories/unreviewed/2024/11/GHSA-hg63-44hg-r9q3/GHSA-hg63-44hg-r9q3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hg63-44hg-r9q3",
- "modified": "2024-11-05T18:32:05Z",
+ "modified": "2024-11-06T18:31:05Z",
"published": "2024-11-05T06:30:34Z",
"aliases": [
"CVE-2024-7877"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/11/GHSA-hm9x-5qmp-g6fq/GHSA-hm9x-5qmp-g6fq.json b/advisories/unreviewed/2024/11/GHSA-hm9x-5qmp-g6fq/GHSA-hm9x-5qmp-g6fq.json
index b7570a48975..ddd8754523a 100644
--- a/advisories/unreviewed/2024/11/GHSA-hm9x-5qmp-g6fq/GHSA-hm9x-5qmp-g6fq.json
+++ b/advisories/unreviewed/2024/11/GHSA-hm9x-5qmp-g6fq/GHSA-hm9x-5qmp-g6fq.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hm9x-5qmp-g6fq",
- "modified": "2024-11-05T21:30:43Z",
+ "modified": "2024-11-06T18:31:08Z",
"published": "2024-11-05T21:30:43Z",
"aliases": [
"CVE-2024-51381"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 that allows attackers to perform actions reserved for administrators, including creating admin accounts. This critical flaw can lead to unauthorized activities, compromising the security and integrity of the platform, especially if an attacker gains administrative control.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-05T19:15:07Z"
diff --git a/advisories/unreviewed/2024/11/GHSA-hmw9-9w7c-2pm4/GHSA-hmw9-9w7c-2pm4.json b/advisories/unreviewed/2024/11/GHSA-hmw9-9w7c-2pm4/GHSA-hmw9-9w7c-2pm4.json
new file mode 100644
index 00000000000..53c6d9995fe
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-hmw9-9w7c-2pm4/GHSA-hmw9-9w7c-2pm4.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hmw9-9w7c-2pm4",
+ "modified": "2024-11-06T18:31:11Z",
+ "published": "2024-11-06T18:31:11Z",
+ "aliases": [
+ "CVE-2024-20445"
+ ],
+ "details": "A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthenticated, remote attacker to access sensitive information on an affected device.\n\nThis vulnerability is due to improper storage of sensitive information within the web UI of Session Initiation Protocol (SIP)-based phone loads. An attacker could exploit this vulnerability by browsing to the IP address of a device that has Web Access enabled. A successful exploit could allow the attacker to access sensitive information, including incoming and outgoing call records.\nNote: Web Access is disabled by default.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20445"
+ },
+ {
+ "type": "WEB",
+ "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-phone-infodisc-sbyqQVbG"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-200"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T17:15:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-hrrg-wvpp-2p2q/GHSA-hrrg-wvpp-2p2q.json b/advisories/unreviewed/2024/11/GHSA-hrrg-wvpp-2p2q/GHSA-hrrg-wvpp-2p2q.json
index 7f1f9d646fa..3df6b38bbd6 100644
--- a/advisories/unreviewed/2024/11/GHSA-hrrg-wvpp-2p2q/GHSA-hrrg-wvpp-2p2q.json
+++ b/advisories/unreviewed/2024/11/GHSA-hrrg-wvpp-2p2q/GHSA-hrrg-wvpp-2p2q.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hrrg-wvpp-2p2q",
- "modified": "2024-11-01T18:31:33Z",
+ "modified": "2024-11-06T18:31:05Z",
"published": "2024-11-01T18:31:33Z",
"aliases": [
"CVE-2024-28265"
],
"details": "IBOS v4.5.5 has an arbitrary file deletion vulnerability via \\system\\modules\\dashboard\\controllers\\LoginController.php.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-459"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-01T16:15:08Z"
diff --git a/advisories/unreviewed/2024/11/GHSA-hv6m-qj65-26q3/GHSA-hv6m-qj65-26q3.json b/advisories/unreviewed/2024/11/GHSA-hv6m-qj65-26q3/GHSA-hv6m-qj65-26q3.json
new file mode 100644
index 00000000000..78bd150c2ca
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-hv6m-qj65-26q3/GHSA-hv6m-qj65-26q3.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hv6m-qj65-26q3",
+ "modified": "2024-11-06T18:31:11Z",
+ "published": "2024-11-06T18:31:11Z",
+ "aliases": [
+ "CVE-2024-50637"
+ ],
+ "details": "UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. ΒΆΒΆ The vulnerability allows attackers to perform XSS in SVG file extension, which can be used to stealing cookies.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50637"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/unopim/unopim/issues/41"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/unopim/unopim/releases/tag/v0.1.4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/yamerooo123/ResearchNBugBountyEncyclopedia/blob/main/Researches/Unopim/Findings.md"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T17:15:20Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-jghq-wq8j-hqc4/GHSA-jghq-wq8j-hqc4.json b/advisories/unreviewed/2024/11/GHSA-jghq-wq8j-hqc4/GHSA-jghq-wq8j-hqc4.json
index c5bc82a234b..3a185a9db0b 100644
--- a/advisories/unreviewed/2024/11/GHSA-jghq-wq8j-hqc4/GHSA-jghq-wq8j-hqc4.json
+++ b/advisories/unreviewed/2024/11/GHSA-jghq-wq8j-hqc4/GHSA-jghq-wq8j-hqc4.json
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jghq-wq8j-hqc4",
- "modified": "2024-11-04T15:31:57Z",
+ "modified": "2024-11-06T18:31:05Z",
"published": "2024-11-04T15:31:57Z",
"aliases": [
"CVE-2024-9147"
],
"details": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Bna Informatics PosPratik allows XSS Through HTTP Query Strings.This issue affects PosPratik: before v3.2.1.",
"severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ },
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
@@ -28,6 +32,7 @@
],
"database_specific": {
"cwe_ids": [
+ "CWE-79",
"CWE-80"
],
"severity": "MODERATE",
diff --git a/advisories/unreviewed/2024/11/GHSA-jhvq-gr6c-9fw6/GHSA-jhvq-gr6c-9fw6.json b/advisories/unreviewed/2024/11/GHSA-jhvq-gr6c-9fw6/GHSA-jhvq-gr6c-9fw6.json
new file mode 100644
index 00000000000..860a2546194
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-jhvq-gr6c-9fw6/GHSA-jhvq-gr6c-9fw6.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jhvq-gr6c-9fw6",
+ "modified": "2024-11-06T18:31:11Z",
+ "published": "2024-11-06T18:31:11Z",
+ "aliases": [
+ "CVE-2024-20418"
+ ],
+ "details": "A vulnerability in the web-based management interface of Cisco Unified Industrial Wireless Software for Cisco Ultra-Reliable Wireless Backhaul (URWB) Access Points could allow an unauthenticated, remote attacker to perform command injection attacks with root privileges on the underlying operating system.\n\nThis vulnerability is due to improper validation of input to the web-based management interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to the web-based management interface of an affected system. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system of the affected device.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20418"
+ },
+ {
+ "type": "WEB",
+ "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-backhaul-ap-cmdinj-R7E28Ecs"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-77"
+ ],
+ "severity": "CRITICAL",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T17:15:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-jvmc-2wg5-j9pw/GHSA-jvmc-2wg5-j9pw.json b/advisories/unreviewed/2024/11/GHSA-jvmc-2wg5-j9pw/GHSA-jvmc-2wg5-j9pw.json
new file mode 100644
index 00000000000..13620592361
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-jvmc-2wg5-j9pw/GHSA-jvmc-2wg5-j9pw.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jvmc-2wg5-j9pw",
+ "modified": "2024-11-06T18:31:11Z",
+ "published": "2024-11-06T18:31:11Z",
+ "aliases": [
+ "CVE-2024-20484"
+ ],
+ "details": "A vulnerability in the External Agent Assignment Service (EAAS) feature of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.\n\nThis vulnerability is due to insufficient validation of Media Routing Peripheral Interface Manager (MR PIM) traffic that is received by an affected device. An attacker could exploit this vulnerability by sending crafted MR PIM traffic to an affected device. A successful exploit could allow the attacker to trigger a failure on the MR PIM connection between Cisco ECE and Cisco Unified Contact Center Enterprise (CCE), leading to a DoS condition on EAAS that would prevent customers from starting chat, callback, or delayed callback sessions. Note: When the attack traffic stops, the EAAS process must be manually restarted to restore normal operation. To restart the process in the System Console, choose Shared Resources > Services > Unified CCE > EAAS, then click Start.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20484"
+ },
+ {
+ "type": "WEB",
+ "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ece-dos-Oqb9uFEv"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-20"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T17:15:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-mwr4-4gh4-7m8j/GHSA-mwr4-4gh4-7m8j.json b/advisories/unreviewed/2024/11/GHSA-mwr4-4gh4-7m8j/GHSA-mwr4-4gh4-7m8j.json
new file mode 100644
index 00000000000..c9140b9c596
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-mwr4-4gh4-7m8j/GHSA-mwr4-4gh4-7m8j.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mwr4-4gh4-7m8j",
+ "modified": "2024-11-06T18:31:11Z",
+ "published": "2024-11-06T18:31:11Z",
+ "aliases": [
+ "CVE-2024-20538"
+ ],
+ "details": "A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface.\n\nThis vulnerability exists because the web-based management interface does not sufficiently validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface on an affected system to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20538"
+ },
+ {
+ "type": "WEB",
+ "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-auth-bypass-BBRf7mkE"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T17:15:19Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-p53v-8c78-56qf/GHSA-p53v-8c78-56qf.json b/advisories/unreviewed/2024/11/GHSA-p53v-8c78-56qf/GHSA-p53v-8c78-56qf.json
new file mode 100644
index 00000000000..2e235a8dc1a
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-p53v-8c78-56qf/GHSA-p53v-8c78-56qf.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-p53v-8c78-56qf",
+ "modified": "2024-11-06T18:31:11Z",
+ "published": "2024-11-06T18:31:11Z",
+ "aliases": [
+ "CVE-2024-20511"
+ ],
+ "details": "A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.\n\nThis vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20511"
+ },
+ {
+ "type": "WEB",
+ "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-xss-SVCkMMW"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T17:15:16Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-p7hr-frqp-rm5j/GHSA-p7hr-frqp-rm5j.json b/advisories/unreviewed/2024/11/GHSA-p7hr-frqp-rm5j/GHSA-p7hr-frqp-rm5j.json
new file mode 100644
index 00000000000..341bb6facfd
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-p7hr-frqp-rm5j/GHSA-p7hr-frqp-rm5j.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-p7hr-frqp-rm5j",
+ "modified": "2024-11-06T18:31:11Z",
+ "published": "2024-11-06T18:31:11Z",
+ "aliases": [
+ "CVE-2024-20529"
+ ],
+ "details": "A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and delete arbitrary files on an affected device. To exploit this vulnerability, the attacker would need valid Super Admin credentials.\n\nThis vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could exploit this vulnerability by sending a crafted API request to an affected device. A successful exploit could allow the attacker to read or delete arbitrary files on the underlying operating system.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20529"
+ },
+ {
+ "type": "WEB",
+ "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-vuln-DBQdWRy"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-22"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T17:15:17Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-q5mq-2xwr-j447/GHSA-q5mq-2xwr-j447.json b/advisories/unreviewed/2024/11/GHSA-q5mq-2xwr-j447/GHSA-q5mq-2xwr-j447.json
index c4c65c7188f..1bfcd4e4a43 100644
--- a/advisories/unreviewed/2024/11/GHSA-q5mq-2xwr-j447/GHSA-q5mq-2xwr-j447.json
+++ b/advisories/unreviewed/2024/11/GHSA-q5mq-2xwr-j447/GHSA-q5mq-2xwr-j447.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q5mq-2xwr-j447",
- "modified": "2024-11-06T00:31:55Z",
+ "modified": "2024-11-06T18:31:10Z",
"published": "2024-11-06T00:31:55Z",
"aliases": [
"CVE-2024-51115"
],
"details": "DCME-320 v7.4.12.90 was discovered to contain a command injection vulnerability.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-77"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-05T23:15:04Z"
diff --git a/advisories/unreviewed/2024/11/GHSA-q79j-6grx-x9p9/GHSA-q79j-6grx-x9p9.json b/advisories/unreviewed/2024/11/GHSA-q79j-6grx-x9p9/GHSA-q79j-6grx-x9p9.json
index fe286315326..1c939c22e61 100644
--- a/advisories/unreviewed/2024/11/GHSA-q79j-6grx-x9p9/GHSA-q79j-6grx-x9p9.json
+++ b/advisories/unreviewed/2024/11/GHSA-q79j-6grx-x9p9/GHSA-q79j-6grx-x9p9.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/11/GHSA-q7hr-x75r-2mp7/GHSA-q7hr-x75r-2mp7.json b/advisories/unreviewed/2024/11/GHSA-q7hr-x75r-2mp7/GHSA-q7hr-x75r-2mp7.json
new file mode 100644
index 00000000000..80a24258f1d
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-q7hr-x75r-2mp7/GHSA-q7hr-x75r-2mp7.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-q7hr-x75r-2mp7",
+ "modified": "2024-11-06T18:31:11Z",
+ "published": "2024-11-06T18:31:11Z",
+ "aliases": [
+ "CVE-2024-20371"
+ ],
+ "details": "A vulnerability in the access control list (ACL) programming of Cisco Nexus 3550-F Switches could allow an unauthenticated, remote attacker to send traffic that should be blocked to the management interface of an affected device. \n\nThis vulnerability exists because ACL deny rules are not properly enforced at the time of device reboot. An attacker could exploit this vulnerability by attempting to send traffic to the management interface of an affected device. A successful exploit could allow the attacker to send traffic to the management interface of the affected device.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20371"
+ },
+ {
+ "type": "WEB",
+ "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-3550-acl-bypass-mhskZc2q"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T17:15:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-qh2h-wv23-f83f/GHSA-qh2h-wv23-f83f.json b/advisories/unreviewed/2024/11/GHSA-qh2h-wv23-f83f/GHSA-qh2h-wv23-f83f.json
index 82a39b52110..29a880955f8 100644
--- a/advisories/unreviewed/2024/11/GHSA-qh2h-wv23-f83f/GHSA-qh2h-wv23-f83f.json
+++ b/advisories/unreviewed/2024/11/GHSA-qh2h-wv23-f83f/GHSA-qh2h-wv23-f83f.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-22"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/11/GHSA-qjmh-rvm8-v24c/GHSA-qjmh-rvm8-v24c.json b/advisories/unreviewed/2024/11/GHSA-qjmh-rvm8-v24c/GHSA-qjmh-rvm8-v24c.json
new file mode 100644
index 00000000000..c6cc94f5b11
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-qjmh-rvm8-v24c/GHSA-qjmh-rvm8-v24c.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qjmh-rvm8-v24c",
+ "modified": "2024-11-06T18:31:11Z",
+ "published": "2024-11-06T18:31:11Z",
+ "aliases": [
+ "CVE-2024-20530"
+ ],
+ "details": "A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface.\n\nThis vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20530"
+ },
+ {
+ "type": "WEB",
+ "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-vuln-DBQdWRy"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T17:15:17Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-qvc8-jp6r-8639/GHSA-qvc8-jp6r-8639.json b/advisories/unreviewed/2024/11/GHSA-qvc8-jp6r-8639/GHSA-qvc8-jp6r-8639.json
index 24309bd472d..62f5db63085 100644
--- a/advisories/unreviewed/2024/11/GHSA-qvc8-jp6r-8639/GHSA-qvc8-jp6r-8639.json
+++ b/advisories/unreviewed/2024/11/GHSA-qvc8-jp6r-8639/GHSA-qvc8-jp6r-8639.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qvc8-jp6r-8639",
- "modified": "2024-11-05T21:30:43Z",
+ "modified": "2024-11-06T18:31:08Z",
"published": "2024-11-05T21:30:43Z",
"aliases": [
"CVE-2024-51380"
],
"details": "Stored Cross-Site Scripting (XSS) vulnerability discovered in the Properties Component of JATOS v3.9.3. This flaw allows an attacker to inject malicious JavaScript into the properties section of a study, specifically within the UUID field. When an admin user accesses the study's properties, the injected script is executed in the admin's browser, which could lead to unauthorized actions, including account compromise and privilege escalation.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-05T19:15:07Z"
diff --git a/advisories/unreviewed/2024/11/GHSA-qx29-vw3w-p54v/GHSA-qx29-vw3w-p54v.json b/advisories/unreviewed/2024/11/GHSA-qx29-vw3w-p54v/GHSA-qx29-vw3w-p54v.json
index 4da8a2057d1..21d829189fa 100644
--- a/advisories/unreviewed/2024/11/GHSA-qx29-vw3w-p54v/GHSA-qx29-vw3w-p54v.json
+++ b/advisories/unreviewed/2024/11/GHSA-qx29-vw3w-p54v/GHSA-qx29-vw3w-p54v.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qx29-vw3w-p54v",
- "modified": "2024-11-06T06:30:31Z",
+ "modified": "2024-11-06T18:31:10Z",
"published": "2024-11-06T06:30:31Z",
"aliases": [
"CVE-2024-9934"
],
"details": "The Wp-ImageZoom WordPress plugin through 1.1.0 does not sanitise and escape some parameters before outputting them back in a page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-06T06:15:03Z"
diff --git a/advisories/unreviewed/2024/11/GHSA-r49w-9hvc-8fg7/GHSA-r49w-9hvc-8fg7.json b/advisories/unreviewed/2024/11/GHSA-r49w-9hvc-8fg7/GHSA-r49w-9hvc-8fg7.json
new file mode 100644
index 00000000000..1046ca6c03c
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-r49w-9hvc-8fg7/GHSA-r49w-9hvc-8fg7.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-r49w-9hvc-8fg7",
+ "modified": "2024-11-06T18:31:11Z",
+ "published": "2024-11-06T18:31:11Z",
+ "aliases": [
+ "CVE-2024-20504"
+ ],
+ "details": "A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.\n\nThis vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20504"
+ },
+ {
+ "type": "WEB",
+ "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-wsa-sma-xss-zYm3f49n"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-80"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T17:15:16Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-r6pw-ffg9-984j/GHSA-r6pw-ffg9-984j.json b/advisories/unreviewed/2024/11/GHSA-r6pw-ffg9-984j/GHSA-r6pw-ffg9-984j.json
new file mode 100644
index 00000000000..b19391e795b
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-r6pw-ffg9-984j/GHSA-r6pw-ffg9-984j.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-r6pw-ffg9-984j",
+ "modified": "2024-11-06T18:31:11Z",
+ "published": "2024-11-06T18:31:11Z",
+ "aliases": [
+ "CVE-2024-20540"
+ ],
+ "details": "A vulnerability in the web-based management interface of Cisco Unified Contact Center Management Portal (Unified CCMP) could allow an authenticated, remote attacker with low privileges to conduct a stored cross-site scripting (XSS) attack against a user of the interface.\n\nThis vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into a specific page of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information. To exploit this vulnerability, the attacker must have at least a Supervisor role on an affected device.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20540"
+ },
+ {
+ "type": "WEB",
+ "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ccmp-sxss-qBTDBZDD"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T17:15:19Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-r8cr-jx69-43ff/GHSA-r8cr-jx69-43ff.json b/advisories/unreviewed/2024/11/GHSA-r8cr-jx69-43ff/GHSA-r8cr-jx69-43ff.json
index 5a98e4e728a..85bde78e0bd 100644
--- a/advisories/unreviewed/2024/11/GHSA-r8cr-jx69-43ff/GHSA-r8cr-jx69-43ff.json
+++ b/advisories/unreviewed/2024/11/GHSA-r8cr-jx69-43ff/GHSA-r8cr-jx69-43ff.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r8cr-jx69-43ff",
- "modified": "2024-11-06T00:31:55Z",
+ "modified": "2024-11-06T18:31:09Z",
"published": "2024-11-06T00:31:55Z",
"aliases": [
"CVE-2024-48746"
],
"details": "An issue in Lens Visual integration with Power BI v.4.0.0.3 allows a remote attacker to execute arbitrary code via the Natural language processing component",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-77"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-05T23:15:04Z"
diff --git a/advisories/unreviewed/2024/11/GHSA-rg92-pqp9-j6jp/GHSA-rg92-pqp9-j6jp.json b/advisories/unreviewed/2024/11/GHSA-rg92-pqp9-j6jp/GHSA-rg92-pqp9-j6jp.json
new file mode 100644
index 00000000000..d9546873478
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-rg92-pqp9-j6jp/GHSA-rg92-pqp9-j6jp.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-rg92-pqp9-j6jp",
+ "modified": "2024-11-06T18:31:11Z",
+ "published": "2024-11-06T18:31:11Z",
+ "aliases": [
+ "CVE-2024-20528"
+ ],
+ "details": "A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to upload files to arbitrary locations on the underlying operating system of an affected device. To exploit this vulnerability, an attacker would need valid Super Admin credentials.\n\nThis vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could exploit this vulnerability by sending a crafted API request to an affected device. A successful exploit could allow the attacker to upload custom files to arbitrary locations on the underlying operating system, execute arbitrary code, and elevate privileges to root.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20528"
+ },
+ {
+ "type": "WEB",
+ "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-vuln-DBQdWRy"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-22"
+ ],
+ "severity": "LOW",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T17:15:17Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-rv5p-p324-cxv2/GHSA-rv5p-p324-cxv2.json b/advisories/unreviewed/2024/11/GHSA-rv5p-p324-cxv2/GHSA-rv5p-p324-cxv2.json
new file mode 100644
index 00000000000..dc879b074e2
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-rv5p-p324-cxv2/GHSA-rv5p-p324-cxv2.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-rv5p-p324-cxv2",
+ "modified": "2024-11-06T18:31:11Z",
+ "published": "2024-11-06T18:31:11Z",
+ "aliases": [
+ "CVE-2024-20533"
+ ],
+ "details": "A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 with Cisco Multiplatform Firmware could allow an authenticated, remote attacker to conduct stored cross-site scripting (XSS) attacks against users.\n\nThis vulnerability exists because the web UI of an affected device does not properly validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.\nNote: To exploit this vulnerability, Web Access must be enabled on the phone and the attacker must have Admin credentials on the device. Web Access is disabled by default.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20533"
+ },
+ {
+ "type": "WEB",
+ "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-mpp-xss-8tAV2TvF"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-06T17:15:18Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-w9pr-cvj2-cxfc/GHSA-w9pr-cvj2-cxfc.json b/advisories/unreviewed/2024/11/GHSA-w9pr-cvj2-cxfc/GHSA-w9pr-cvj2-cxfc.json
index 2272acbc350..17f9d37eb04 100644
--- a/advisories/unreviewed/2024/11/GHSA-w9pr-cvj2-cxfc/GHSA-w9pr-cvj2-cxfc.json
+++ b/advisories/unreviewed/2024/11/GHSA-w9pr-cvj2-cxfc/GHSA-w9pr-cvj2-cxfc.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w9pr-cvj2-cxfc",
- "modified": "2024-11-05T21:30:43Z",
+ "modified": "2024-11-06T18:31:08Z",
"published": "2024-11-05T21:30:43Z",
"aliases": [
"CVE-2024-51379"
],
"details": "Stored Cross-Site Scripting (XSS) vulnerability discovered in JATOS v3.9.3. The vulnerability exists in the description component of the study section, where an attacker can inject JavaScript into the description field. This allows for the execution of malicious scripts when an admin views the description, potentially leading to account takeover and unauthorized actions.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-05T19:15:07Z"
diff --git a/advisories/unreviewed/2024/11/GHSA-wjjv-5wqm-9j59/GHSA-wjjv-5wqm-9j59.json b/advisories/unreviewed/2024/11/GHSA-wjjv-5wqm-9j59/GHSA-wjjv-5wqm-9j59.json
index e928e37a385..f8417ec17ef 100644
--- a/advisories/unreviewed/2024/11/GHSA-wjjv-5wqm-9j59/GHSA-wjjv-5wqm-9j59.json
+++ b/advisories/unreviewed/2024/11/GHSA-wjjv-5wqm-9j59/GHSA-wjjv-5wqm-9j59.json
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wjjv-5wqm-9j59",
- "modified": "2024-11-04T15:31:57Z",
+ "modified": "2024-11-06T18:31:05Z",
"published": "2024-11-04T15:31:57Z",
"aliases": [
"CVE-2024-51561"
],
"details": "This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by intercepting and manipulating the responses exchanged during the second factor authentication process. \n\nSuccessful exploitation of this vulnerability could allow the attacker to bypass OTP verification for accessing other user accounts.",
"severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ },
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
diff --git a/advisories/unreviewed/2024/11/GHSA-xqww-45ww-cw2p/GHSA-xqww-45ww-cw2p.json b/advisories/unreviewed/2024/11/GHSA-xqww-45ww-cw2p/GHSA-xqww-45ww-cw2p.json
index f4c33903ccd..6ccc77f00c9 100644
--- a/advisories/unreviewed/2024/11/GHSA-xqww-45ww-cw2p/GHSA-xqww-45ww-cw2p.json
+++ b/advisories/unreviewed/2024/11/GHSA-xqww-45ww-cw2p/GHSA-xqww-45ww-cw2p.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xqww-45ww-cw2p",
- "modified": "2024-11-04T15:31:57Z",
+ "modified": "2024-11-06T18:31:05Z",
"published": "2024-11-04T15:31:57Z",
"aliases": [
"CVE-2024-45164"
],
"details": "Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality on the ThreatAvert Policy page. An authenticated user can navigate directly to the /#app/intelligence/threatAvertPolicies URI and disable policy enforcement.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
+ }
],
"affected": [
@@ -29,9 +32,10 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-732",
+ "CWE-863"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-04T14:15:14Z"