Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-10-17 18:33:04 +00:00
parent 21313441e8
commit 16b1a4033a
78 changed files with 1985 additions and 47 deletions
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7q5w-8wg2-xwr7",
"modified": "2022-05-24T19:09:41Z",
"modified": "2024-10-17T18:31:30Z",
"published": "2022-05-24T19:09:41Z",
"aliases": [
"CVE-2017-18113"
],
"details": "The DefaultOSWorkflowConfigurator class in Jira Server and Jira Data Center before version 8.18.1 allows remote attackers who can trick a system administrator to import their malicious workflow to execute arbitrary code via a Remote Code Execution (RCE) vulnerability. The vulnerability allowed for various problematic OSWorkflow classes to be used as part of workflows. The fix for this issue blocks usage of unsafe conditions, validators, functions and registers that are build-in into OSWorkflow library and other Jira dependencies. Atlassian-made functions or functions provided by 3rd party plugins are not affected by this fix.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-200"
"CWE-200",
"CWE-863"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-1284"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -32,6 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-116",
"CWE-20"
],
"severity": "HIGH",
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-20"
"CWE-20",
"CWE-78"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-54qf-h346-xgmg",
"modified": "2024-02-13T21:30:29Z",
"modified": "2024-10-17T18:31:31Z",
"published": "2024-02-13T21:30:29Z",
"aliases": [
"CVE-2024-1082"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hwq5-wx3r-8r5g",
"modified": "2024-02-13T21:30:29Z",
"modified": "2024-10-17T18:31:31Z",
"published": "2024-02-13T21:30:29Z",
"aliases": [
"CVE-2024-1084"
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-269"
"CWE-269",
"CWE-280"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -32,6 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22",
"CWE-36"
],
"severity": "HIGH",
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22",
"CWE-36"
],
"severity": "CRITICAL",
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22",
"CWE-29"
],
"severity": "CRITICAL",
@@ -32,7 +32,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-20"
"CWE-20",
"CWE-755"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2239-h2rh-5fp9",
"modified": "2024-10-17T18:31:36Z",
"published": "2024-10-17T18:31:36Z",
"aliases": [
"CVE-2024-49220"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in Cookie Scanner Nikel Schubert Cookie Scanner allows Stored XSS.This issue affects Cookie Scanner: from n/a through 1.1.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49220"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/cookie-scanner/wordpress-cookie-scanner-plugin-1-1-csrf-to-stored-xss-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-17T18:15:09Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2289-64mg-g86w",
"modified": "2024-10-17T18:31:37Z",
"published": "2024-10-17T18:31:37Z",
"aliases": [
"CVE-2024-49297"
],
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zoho CRM Zoho CRM Lead Magnet allows SQL Injection.This issue affects Zoho CRM Lead Magnet: from n/a through 1.7.9.0.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49297"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/zoho-crm-forms/wordpress-zoho-crm-lead-magnet-plugin-1-7-9-0-sql-injection-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-17T18:15:13Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-22c8-79jr-rvwg",
"modified": "2024-10-17T18:31:36Z",
"published": "2024-10-17T18:31:36Z",
"aliases": [
"CVE-2024-48633"
],
"details": "D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the ExternalPort, InternalPort, ProtocolNumber, and LocalIPAddress parameters in the SetVirtualServerSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48633"
},
{
"type": "WEB",
"url": "https://github.com/pjqwudi1/my_vuln/blob/main/D-link4/vuln_40/40.md"
},
{
"type": "WEB",
"url": "https://www.dlink.com/en/security-bulletin"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-17T18:15:08Z"
}
}
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-37gm-h5wr-pf25",
"modified": "2024-10-16T21:31:09Z",
"modified": "2024-10-17T18:31:35Z",
"published": "2024-10-16T21:31:09Z",
"aliases": [
"CVE-2024-46212"
],
"details": "An issue in the component /index.php?page=backup/export of REDAXO CMS v5.17.1 allows attackers to execute a directory traversal.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-16T21:15:12Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3hqc-72mc-jjr3",
"modified": "2024-10-15T21:30:39Z",
"modified": "2024-10-17T18:31:35Z",
"published": "2024-10-15T21:30:39Z",
"aliases": [
"CVE-2024-48779"
],
"details": "An issue in Wanxing Technology's Yitu project Management Software 3.2.2 allows a remote attacker to execute arbitrary code via the platformpluginpath parameter to specify that the qt plugin loads the directory.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-15T21:15:11Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3p3h-5g54-qmc8",
"modified": "2024-10-16T21:31:09Z",
"modified": "2024-10-17T18:31:35Z",
"published": "2024-10-16T21:31:09Z",
"aliases": [
"CVE-2024-48180"
],
"details": "ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/template directory to execute PHP code.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-434"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-16T21:15:13Z"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4hrr-fjm6-xq9f",
"modified": "2024-10-17T18:31:36Z",
"published": "2024-10-17T18:31:36Z",
"aliases": [
"CVE-2024-49398"
],
"details": "The affected product is vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute code.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49398"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-291-01"
}
],
"database_specific": {
"cwe_ids": [
"CWE-434"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-17T17:15:12Z"
}
}

Some files were not shown because too many files have changed in this diff Show More