From 17a10f76b75cd85549ba0fe16e918d1124203e44 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 8 Jan 2025 03:32:13 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-9x8q-p3qp-r24w.json | 2 +- .../GHSA-2f4v-4h68-m25j.json | 34 ++++++++++++++ .../GHSA-2mjp-jj8g-xrmh.json | 36 +++++++++++++++ .../GHSA-2vqc-674h-xh9w.json | 44 +++++++++++++++++++ .../GHSA-35jq-jf9g-9jg7.json | 36 +++++++++++++++ .../GHSA-3rhv-g3x9-jcp9.json | 25 +++++++++++ .../GHSA-5fq8-m7q2-5jfh.json | 36 +++++++++++++++ .../GHSA-6fvh-vvx6-69v5.json | 36 +++++++++++++++ .../GHSA-6m3j-pcg3-cx2r.json | 36 +++++++++++++++ .../GHSA-8ff2-7hgc-rm8c.json | 36 +++++++++++++++ .../GHSA-96wc-w7p5-g6wj.json | 36 +++++++++++++++ .../GHSA-9ccw-9r9h-qmpr.json | 34 ++++++++++++++ .../GHSA-9g92-whv2-g846.json | 36 +++++++++++++++ .../GHSA-cp8g-mv9m-5m2f.json | 25 +++++++++++ .../GHSA-cxx9-9r7j-84cg.json | 36 +++++++++++++++ .../GHSA-g66q-9wwq-w559.json | 34 ++++++++++++++ .../GHSA-jmq6-2q85-fwg2.json | 34 ++++++++++++++ .../GHSA-jvrp-8jqj-97w9.json | 36 +++++++++++++++ .../GHSA-mw39-rvm5-p6j8.json | 36 +++++++++++++++ .../GHSA-ph3g-qv2v-ccjf.json | 40 +++++++++++++++++ .../GHSA-q722-mhcx-9m8w.json | 36 +++++++++++++++ .../GHSA-vmvx-m6xv-8fw6.json | 36 +++++++++++++++ .../GHSA-wfp9-2x23-wxw4.json | 34 ++++++++++++++ .../GHSA-xc39-v86c-vh9g.json | 34 ++++++++++++++ .../GHSA-xwx4-gp8x-6vg5.json | 34 ++++++++++++++ 25 files changed, 841 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2025/01/GHSA-2f4v-4h68-m25j/GHSA-2f4v-4h68-m25j.json create mode 100644 advisories/unreviewed/2025/01/GHSA-2mjp-jj8g-xrmh/GHSA-2mjp-jj8g-xrmh.json create mode 100644 advisories/unreviewed/2025/01/GHSA-2vqc-674h-xh9w/GHSA-2vqc-674h-xh9w.json create mode 100644 advisories/unreviewed/2025/01/GHSA-35jq-jf9g-9jg7/GHSA-35jq-jf9g-9jg7.json create mode 100644 advisories/unreviewed/2025/01/GHSA-3rhv-g3x9-jcp9/GHSA-3rhv-g3x9-jcp9.json create mode 100644 advisories/unreviewed/2025/01/GHSA-5fq8-m7q2-5jfh/GHSA-5fq8-m7q2-5jfh.json create mode 100644 advisories/unreviewed/2025/01/GHSA-6fvh-vvx6-69v5/GHSA-6fvh-vvx6-69v5.json create mode 100644 advisories/unreviewed/2025/01/GHSA-6m3j-pcg3-cx2r/GHSA-6m3j-pcg3-cx2r.json create mode 100644 advisories/unreviewed/2025/01/GHSA-8ff2-7hgc-rm8c/GHSA-8ff2-7hgc-rm8c.json create mode 100644 advisories/unreviewed/2025/01/GHSA-96wc-w7p5-g6wj/GHSA-96wc-w7p5-g6wj.json create mode 100644 advisories/unreviewed/2025/01/GHSA-9ccw-9r9h-qmpr/GHSA-9ccw-9r9h-qmpr.json create mode 100644 advisories/unreviewed/2025/01/GHSA-9g92-whv2-g846/GHSA-9g92-whv2-g846.json create mode 100644 advisories/unreviewed/2025/01/GHSA-cp8g-mv9m-5m2f/GHSA-cp8g-mv9m-5m2f.json create mode 100644 advisories/unreviewed/2025/01/GHSA-cxx9-9r7j-84cg/GHSA-cxx9-9r7j-84cg.json create mode 100644 advisories/unreviewed/2025/01/GHSA-g66q-9wwq-w559/GHSA-g66q-9wwq-w559.json create mode 100644 advisories/unreviewed/2025/01/GHSA-jmq6-2q85-fwg2/GHSA-jmq6-2q85-fwg2.json create mode 100644 advisories/unreviewed/2025/01/GHSA-jvrp-8jqj-97w9/GHSA-jvrp-8jqj-97w9.json create mode 100644 advisories/unreviewed/2025/01/GHSA-mw39-rvm5-p6j8/GHSA-mw39-rvm5-p6j8.json create mode 100644 advisories/unreviewed/2025/01/GHSA-ph3g-qv2v-ccjf/GHSA-ph3g-qv2v-ccjf.json create mode 100644 advisories/unreviewed/2025/01/GHSA-q722-mhcx-9m8w/GHSA-q722-mhcx-9m8w.json create mode 100644 advisories/unreviewed/2025/01/GHSA-vmvx-m6xv-8fw6/GHSA-vmvx-m6xv-8fw6.json create mode 100644 advisories/unreviewed/2025/01/GHSA-wfp9-2x23-wxw4/GHSA-wfp9-2x23-wxw4.json create mode 100644 advisories/unreviewed/2025/01/GHSA-xc39-v86c-vh9g/GHSA-xc39-v86c-vh9g.json create mode 100644 advisories/unreviewed/2025/01/GHSA-xwx4-gp8x-6vg5/GHSA-xwx4-gp8x-6vg5.json diff --git a/advisories/unreviewed/2022/05/GHSA-9x8q-p3qp-r24w/GHSA-9x8q-p3qp-r24w.json b/advisories/unreviewed/2022/05/GHSA-9x8q-p3qp-r24w/GHSA-9x8q-p3qp-r24w.json index ee1b226b05d..298f8f525c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-9x8q-p3qp-r24w/GHSA-9x8q-p3qp-r24w.json +++ b/advisories/unreviewed/2022/05/GHSA-9x8q-p3qp-r24w/GHSA-9x8q-p3qp-r24w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9x8q-p3qp-r24w", - "modified": "2022-10-14T19:00:17Z", + "modified": "2025-01-08T03:30:23Z", "published": "2022-05-24T17:15:05Z", "aliases": [ "CVE-2020-2883" diff --git a/advisories/unreviewed/2025/01/GHSA-2f4v-4h68-m25j/GHSA-2f4v-4h68-m25j.json b/advisories/unreviewed/2025/01/GHSA-2f4v-4h68-m25j/GHSA-2f4v-4h68-m25j.json new file mode 100644 index 00000000000..faae857ef1c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2f4v-4h68-m25j/GHSA-2f4v-4h68-m25j.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2f4v-4h68-m25j", + "modified": "2025-01-08T03:30:23Z", + "published": "2025-01-08T03:30:23Z", + "aliases": [ + "CVE-2024-56436" + ], + "details": "Cross-process screen stack vulnerability in the UIExtension module\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56436" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2025/1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T02:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2mjp-jj8g-xrmh/GHSA-2mjp-jj8g-xrmh.json b/advisories/unreviewed/2025/01/GHSA-2mjp-jj8g-xrmh/GHSA-2mjp-jj8g-xrmh.json new file mode 100644 index 00000000000..4bbd87c0403 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2mjp-jj8g-xrmh/GHSA-2mjp-jj8g-xrmh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mjp-jj8g-xrmh", + "modified": "2025-01-08T03:30:24Z", + "published": "2025-01-08T03:30:24Z", + "aliases": [ + "CVE-2024-56447" + ], + "details": "Vulnerability of improper permission control in the window management module\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56447" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2025/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T03:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2vqc-674h-xh9w/GHSA-2vqc-674h-xh9w.json b/advisories/unreviewed/2025/01/GHSA-2vqc-674h-xh9w/GHSA-2vqc-674h-xh9w.json new file mode 100644 index 00000000000..274c035383a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2vqc-674h-xh9w/GHSA-2vqc-674h-xh9w.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2vqc-674h-xh9w", + "modified": "2025-01-08T03:30:23Z", + "published": "2025-01-08T03:30:23Z", + "aliases": [ + "CVE-2024-50603" + ], + "details": "An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50603" + }, + { + "type": "WEB", + "url": "https://docs.aviatrix.com/documentation/latest/network-security/index.html" + }, + { + "type": "WEB", + "url": "https://docs.aviatrix.com/documentation/latest/release-notices/psirt-advisories/psirt-advisories.html?expand=true#remote-code-execution-vulnerability-in-aviatrix-controllers" + }, + { + "type": "WEB", + "url": "https://www.securing.pl/en/cve-2024-50603-aviatrix-network-controller-command-injection-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T01:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-35jq-jf9g-9jg7/GHSA-35jq-jf9g-9jg7.json b/advisories/unreviewed/2025/01/GHSA-35jq-jf9g-9jg7/GHSA-35jq-jf9g-9jg7.json new file mode 100644 index 00000000000..9bb76d501e9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-35jq-jf9g-9jg7/GHSA-35jq-jf9g-9jg7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35jq-jf9g-9jg7", + "modified": "2025-01-08T03:30:24Z", + "published": "2025-01-08T03:30:24Z", + "aliases": [ + "CVE-2024-56437" + ], + "details": "Vulnerability of input parameters not being verified in the widget framework module\nImpact: Successful exploitation of this vulnerability may affect availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56437" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2025/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3rhv-g3x9-jcp9/GHSA-3rhv-g3x9-jcp9.json b/advisories/unreviewed/2025/01/GHSA-3rhv-g3x9-jcp9/GHSA-3rhv-g3x9-jcp9.json new file mode 100644 index 00000000000..3bb858bda0b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3rhv-g3x9-jcp9/GHSA-3rhv-g3x9-jcp9.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rhv-g3x9-jcp9", + "modified": "2025-01-08T03:30:23Z", + "published": "2025-01-08T03:30:23Z", + "aliases": [ + "CVE-2024-55355" + ], + "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55355" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T01:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5fq8-m7q2-5jfh/GHSA-5fq8-m7q2-5jfh.json b/advisories/unreviewed/2025/01/GHSA-5fq8-m7q2-5jfh/GHSA-5fq8-m7q2-5jfh.json new file mode 100644 index 00000000000..893fc70bc73 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5fq8-m7q2-5jfh/GHSA-5fq8-m7q2-5jfh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fq8-m7q2-5jfh", + "modified": "2025-01-08T03:30:24Z", + "published": "2025-01-08T03:30:24Z", + "aliases": [ + "CVE-2024-56443" + ], + "details": "Cross-process screen stack vulnerability in the UIExtension module\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56443" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2025/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6fvh-vvx6-69v5/GHSA-6fvh-vvx6-69v5.json b/advisories/unreviewed/2025/01/GHSA-6fvh-vvx6-69v5/GHSA-6fvh-vvx6-69v5.json new file mode 100644 index 00000000000..fbcdfd79243 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6fvh-vvx6-69v5/GHSA-6fvh-vvx6-69v5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6fvh-vvx6-69v5", + "modified": "2025-01-08T03:30:23Z", + "published": "2025-01-08T03:30:23Z", + "aliases": [ + "CVE-2024-56434" + ], + "details": "UAF vulnerability in the device node access module\nImpact: Successful exploitation of this vulnerability may cause service exceptions of the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56434" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2025/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-672" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T02:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6m3j-pcg3-cx2r/GHSA-6m3j-pcg3-cx2r.json b/advisories/unreviewed/2025/01/GHSA-6m3j-pcg3-cx2r/GHSA-6m3j-pcg3-cx2r.json new file mode 100644 index 00000000000..f99dbec2b2c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6m3j-pcg3-cx2r/GHSA-6m3j-pcg3-cx2r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6m3j-pcg3-cx2r", + "modified": "2025-01-08T03:30:24Z", + "published": "2025-01-08T03:30:24Z", + "aliases": [ + "CVE-2024-56446" + ], + "details": "Vulnerability of variables not being initialized in the notification module\nImpact: Successful exploitation of this vulnerability may affect availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56446" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2025/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-457" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T03:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8ff2-7hgc-rm8c/GHSA-8ff2-7hgc-rm8c.json b/advisories/unreviewed/2025/01/GHSA-8ff2-7hgc-rm8c/GHSA-8ff2-7hgc-rm8c.json new file mode 100644 index 00000000000..dcd562f9775 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8ff2-7hgc-rm8c/GHSA-8ff2-7hgc-rm8c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8ff2-7hgc-rm8c", + "modified": "2025-01-08T03:30:24Z", + "published": "2025-01-08T03:30:24Z", + "aliases": [ + "CVE-2024-56439" + ], + "details": "Access control vulnerability in the identity authentication module\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56439" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2025/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-96wc-w7p5-g6wj/GHSA-96wc-w7p5-g6wj.json b/advisories/unreviewed/2025/01/GHSA-96wc-w7p5-g6wj/GHSA-96wc-w7p5-g6wj.json new file mode 100644 index 00000000000..d4152e4675a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-96wc-w7p5-g6wj/GHSA-96wc-w7p5-g6wj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-96wc-w7p5-g6wj", + "modified": "2025-01-08T03:30:24Z", + "published": "2025-01-08T03:30:24Z", + "aliases": [ + "CVE-2024-56441" + ], + "details": "Race condition vulnerability in the Bastet module\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56441" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2025/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9ccw-9r9h-qmpr/GHSA-9ccw-9r9h-qmpr.json b/advisories/unreviewed/2025/01/GHSA-9ccw-9r9h-qmpr/GHSA-9ccw-9r9h-qmpr.json new file mode 100644 index 00000000000..c9bab8bf180 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9ccw-9r9h-qmpr/GHSA-9ccw-9r9h-qmpr.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9ccw-9r9h-qmpr", + "modified": "2025-01-08T03:30:24Z", + "published": "2025-01-08T03:30:24Z", + "aliases": [ + "CVE-2024-56442" + ], + "details": "Vulnerability of native APIs not being implemented in the NFC service module\nImpact: Successful exploitation of this vulnerability may cause features to perform abnormally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56442" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2025/1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9g92-whv2-g846/GHSA-9g92-whv2-g846.json b/advisories/unreviewed/2025/01/GHSA-9g92-whv2-g846/GHSA-9g92-whv2-g846.json new file mode 100644 index 00000000000..ab5b0cbc8fd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9g92-whv2-g846/GHSA-9g92-whv2-g846.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9g92-whv2-g846", + "modified": "2025-01-08T03:30:23Z", + "published": "2025-01-08T03:30:23Z", + "aliases": [ + "CVE-2023-52953" + ], + "details": "Path traversal vulnerability in the Medialibrary module\nImpact: Successful exploitation of this vulnerability will affect integrity and confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52953" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2025/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T03:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cp8g-mv9m-5m2f/GHSA-cp8g-mv9m-5m2f.json b/advisories/unreviewed/2025/01/GHSA-cp8g-mv9m-5m2f/GHSA-cp8g-mv9m-5m2f.json new file mode 100644 index 00000000000..1458591e441 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cp8g-mv9m-5m2f/GHSA-cp8g-mv9m-5m2f.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp8g-mv9m-5m2f", + "modified": "2025-01-08T03:30:23Z", + "published": "2025-01-08T03:30:23Z", + "aliases": [ + "CVE-2024-55356" + ], + "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55356" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T01:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cxx9-9r7j-84cg/GHSA-cxx9-9r7j-84cg.json b/advisories/unreviewed/2025/01/GHSA-cxx9-9r7j-84cg/GHSA-cxx9-9r7j-84cg.json new file mode 100644 index 00000000000..c4a60db08f7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cxx9-9r7j-84cg/GHSA-cxx9-9r7j-84cg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxx9-9r7j-84cg", + "modified": "2025-01-08T03:30:24Z", + "published": "2025-01-08T03:30:24Z", + "aliases": [ + "CVE-2024-56445" + ], + "details": "Instruction authentication bypass vulnerability in the Findnetwork module\nImpact: Successful exploitation of this vulnerability may cause features to perform abnormally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56445" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2025/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g66q-9wwq-w559/GHSA-g66q-9wwq-w559.json b/advisories/unreviewed/2025/01/GHSA-g66q-9wwq-w559/GHSA-g66q-9wwq-w559.json new file mode 100644 index 00000000000..7f8bf486287 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g66q-9wwq-w559/GHSA-g66q-9wwq-w559.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g66q-9wwq-w559", + "modified": "2025-01-08T03:30:23Z", + "published": "2025-01-08T03:30:23Z", + "aliases": [ + "CVE-2023-52954" + ], + "details": "Vulnerability of improper permission control in the Gallery module\nImpact: Successful exploitation of this vulnerability may affect availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52954" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2025/1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jmq6-2q85-fwg2/GHSA-jmq6-2q85-fwg2.json b/advisories/unreviewed/2025/01/GHSA-jmq6-2q85-fwg2/GHSA-jmq6-2q85-fwg2.json new file mode 100644 index 00000000000..bfbc6dbeb30 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jmq6-2q85-fwg2/GHSA-jmq6-2q85-fwg2.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jmq6-2q85-fwg2", + "modified": "2025-01-08T03:30:24Z", + "published": "2025-01-08T03:30:24Z", + "aliases": [ + "CVE-2024-56444" + ], + "details": "Cross-process screen stack vulnerability in the UIExtension module\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56444" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2025/1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jvrp-8jqj-97w9/GHSA-jvrp-8jqj-97w9.json b/advisories/unreviewed/2025/01/GHSA-jvrp-8jqj-97w9/GHSA-jvrp-8jqj-97w9.json new file mode 100644 index 00000000000..5728efadb0e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jvrp-8jqj-97w9/GHSA-jvrp-8jqj-97w9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvrp-8jqj-97w9", + "modified": "2025-01-08T03:30:24Z", + "published": "2025-01-08T03:30:24Z", + "aliases": [ + "CVE-2024-47239" + ], + "details": "Dell PowerScale OneFS versions 8.2.2.x through 9.9.0.0 contain an uncontrolled resource consumption vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47239" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000269590/dsa-2024-480-security-update-for-dell-powerscale-onefs-security-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mw39-rvm5-p6j8/GHSA-mw39-rvm5-p6j8.json b/advisories/unreviewed/2025/01/GHSA-mw39-rvm5-p6j8/GHSA-mw39-rvm5-p6j8.json new file mode 100644 index 00000000000..b449cd8ef5a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mw39-rvm5-p6j8/GHSA-mw39-rvm5-p6j8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw39-rvm5-p6j8", + "modified": "2025-01-08T03:30:24Z", + "published": "2025-01-08T03:30:24Z", + "aliases": [ + "CVE-2024-54120" + ], + "details": "Race condition vulnerability in the distributed notification module\nImpact: Successful exploitation of this vulnerability may cause features to perform abnormally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54120" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2025/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-ph3g-qv2v-ccjf/GHSA-ph3g-qv2v-ccjf.json b/advisories/unreviewed/2025/01/GHSA-ph3g-qv2v-ccjf/GHSA-ph3g-qv2v-ccjf.json new file mode 100644 index 00000000000..9ac0432ccd2 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-ph3g-qv2v-ccjf/GHSA-ph3g-qv2v-ccjf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ph3g-qv2v-ccjf", + "modified": "2025-01-08T03:30:24Z", + "published": "2025-01-08T03:30:24Z", + "aliases": [ + "CVE-2024-47934" + ], + "details": "Improper Input Validation vulnerability in Management Program in TXOne Networks Portable Inspector and Portable Inspector Pro Edition allows remote attacker to crash management service. The Denial of Service situation can be resolved by restarting the management service.\nThis issue affects Portable Inspector: through 1.0.0; Portable Inspector Pro Edition: through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47934" + }, + { + "type": "WEB", + "url": "https://www.txone.com/psirt/advisories/cve-2024-47934" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q722-mhcx-9m8w/GHSA-q722-mhcx-9m8w.json b/advisories/unreviewed/2025/01/GHSA-q722-mhcx-9m8w/GHSA-q722-mhcx-9m8w.json new file mode 100644 index 00000000000..61207ba7dee --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q722-mhcx-9m8w/GHSA-q722-mhcx-9m8w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q722-mhcx-9m8w", + "modified": "2025-01-08T03:30:23Z", + "published": "2025-01-08T03:30:23Z", + "aliases": [ + "CVE-2024-40679" + ], + "details": "IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an information disclosure vulnerability as sensitive information may be included in a log file under specific conditions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40679" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7175957" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T01:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vmvx-m6xv-8fw6/GHSA-vmvx-m6xv-8fw6.json b/advisories/unreviewed/2025/01/GHSA-vmvx-m6xv-8fw6/GHSA-vmvx-m6xv-8fw6.json new file mode 100644 index 00000000000..cb240a92077 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vmvx-m6xv-8fw6/GHSA-vmvx-m6xv-8fw6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vmvx-m6xv-8fw6", + "modified": "2025-01-08T03:30:23Z", + "published": "2025-01-08T03:30:23Z", + "aliases": [ + "CVE-2024-56435" + ], + "details": "Cross-process screen stack vulnerability in the UIExtension module\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56435" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2025/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T02:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wfp9-2x23-wxw4/GHSA-wfp9-2x23-wxw4.json b/advisories/unreviewed/2025/01/GHSA-wfp9-2x23-wxw4/GHSA-wfp9-2x23-wxw4.json new file mode 100644 index 00000000000..c9c4bd1868b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wfp9-2x23-wxw4/GHSA-wfp9-2x23-wxw4.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfp9-2x23-wxw4", + "modified": "2025-01-08T03:30:24Z", + "published": "2025-01-08T03:30:24Z", + "aliases": [ + "CVE-2024-56438" + ], + "details": "Vulnerability of improper memory address protection in the HUKS module\nImpact: Successful exploitation of this vulnerability may affect availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56438" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2025/1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xc39-v86c-vh9g/GHSA-xc39-v86c-vh9g.json b/advisories/unreviewed/2025/01/GHSA-xc39-v86c-vh9g/GHSA-xc39-v86c-vh9g.json new file mode 100644 index 00000000000..a251c056097 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xc39-v86c-vh9g/GHSA-xc39-v86c-vh9g.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xc39-v86c-vh9g", + "modified": "2025-01-08T03:30:24Z", + "published": "2025-01-08T03:30:24Z", + "aliases": [ + "CVE-2023-52955" + ], + "details": "Vulnerability of improper authentication in the ANS system service module\nImpact: Successful exploitation of this vulnerability may cause features to perform abnormally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52955" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2025/1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xwx4-gp8x-6vg5/GHSA-xwx4-gp8x-6vg5.json b/advisories/unreviewed/2025/01/GHSA-xwx4-gp8x-6vg5/GHSA-xwx4-gp8x-6vg5.json new file mode 100644 index 00000000000..f91d340e655 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xwx4-gp8x-6vg5/GHSA-xwx4-gp8x-6vg5.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwx4-gp8x-6vg5", + "modified": "2025-01-08T03:30:24Z", + "published": "2025-01-08T03:30:24Z", + "aliases": [ + "CVE-2024-56440" + ], + "details": "Permission control vulnerability in the Connectivity module\nImpact: Successful exploitation of this vulnerability may cause features to perform abnormally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56440" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2025/1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T03:15:09Z" + } +} \ No newline at end of file