Publish Advisories

GHSA-7f88-5hhx-67m2
GHSA-67c5-gg2x-j6wg
GHSA-3qrf-2xj8-m9mv
GHSA-6mg4-m676-rm67
GHSA-73gq-35g9-rpwr
GHSA-7wfp-r36g-m8hf
GHSA-9fhj-wr42-mmv6
GHSA-h8jw-v8m2-669r
GHSA-j8p2-5922-rxpr
GHSA-mpfv-w8fh-9hfv
GHSA-mx67-gpgv-qm6w
GHSA-pfqm-9375-7qwm
GHSA-rwhw-2ccq-46p7
GHSA-rwvw-fh44-w2r2
This commit is contained in:
advisory-database[bot]
2024-11-26 03:37:59 +00:00
parent 4dcce2eda7
commit 17beb28e47
14 changed files with 446 additions and 5 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7f88-5hhx-67m2",
"modified": "2024-05-08T09:30:50Z",
"modified": "2024-11-26T03:36:37Z",
"published": "2024-03-22T21:30:56Z",
"aliases": [
"CVE-2023-5685"
@@ -63,6 +63,14 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2023:7641"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:10207"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:10208"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2707"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-67c5-gg2x-j6wg",
"modified": "2024-08-21T18:31:28Z",
"modified": "2024-11-26T03:36:37Z",
"published": "2024-08-21T18:31:28Z",
"aliases": [
"CVE-2024-5725"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5725"
},
{
"type": "WEB",
"url": "https://thewatch.centreon.com/latest-security-bulletins-64/security-bulletin-for-centreon-web-3744"
},
{
"type": "WEB",
"url": "https://www.zerodayinitiative.com/advisories/ZDI-24-597"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3qrf-2xj8-m9mv",
"modified": "2024-11-26T03:36:38Z",
"published": "2024-11-26T03:36:38Z",
"aliases": [
"CVE-2024-52899"
],
"details": "IBM Data Virtualization Manager for z/OS 1.1 and 1.2 could allow an authenticated user to inject malicious JDBC URL parameters and execute code on the server.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52899"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7177091"
}
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-26T01:15:07Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6mg4-m676-rm67",
"modified": "2024-11-26T03:36:39Z",
"published": "2024-11-26T03:36:39Z",
"aliases": [
"CVE-2024-49597"
],
"details": "Dell Wyse Management Suite, versions WMS 4.4 and prior, contain an Improper Restriction of Excessive Authentication Attempts vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49597"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000244453/dsa-2024-440"
}
],
"database_specific": {
"cwe_ids": [
"CWE-307"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-26T03:15:06Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-73gq-35g9-rpwr",
"modified": "2024-11-26T03:36:38Z",
"published": "2024-11-26T03:36:38Z",
"aliases": [
"CVE-2024-49596"
],
"details": "Dell Wyse Management Suite, version WMS 4.4 and prior, contain a Missing Authorization vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service and arbitrary file deletion",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49596"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000244453/dsa-2024-440"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-26T03:15:06Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7wfp-r36g-m8hf",
"modified": "2024-11-26T03:36:38Z",
"published": "2024-11-26T03:36:38Z",
"aliases": [
"CVE-2024-49595"
],
"details": "Dell Wyse Management Suite, version WMS 4.4 and before, contain an Authentication Bypass by Capture-replay vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49595"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000244453/dsa-2024-440"
}
],
"database_specific": {
"cwe_ids": [
"CWE-294"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-26T03:15:06Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9fhj-wr42-mmv6",
"modified": "2024-11-26T03:36:38Z",
"published": "2024-11-26T03:36:38Z",
"aliases": [
"CVE-2024-10729"
],
"details": "The Booking & Appointment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_google_calendar_data' function in versions up to, and including, 6.9.0. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update the site options arbitrarily.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10729"
},
{
"type": "WEB",
"url": "https://www.tychesoftwares.com/docs/docs/booking-appointment-plugin-for-woocommerce-new/changelog"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6ed215da-10c5-469b-bab2-923808feebd4?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-285"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-26T02:15:16Z"
}
}
@@ -0,0 +1,58 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h8jw-v8m2-669r",
"modified": "2024-11-26T03:36:38Z",
"published": "2024-11-26T03:36:38Z",
"aliases": [
"CVE-2024-11676"
],
"details": "A vulnerability was found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /backend/admin/his_admin_add_lab_equipment.php of the component Add Laboratory Equipment Page. The manipulation of the argument eqp_code/eqp_name/eqp_vendor/eqp_desc/eqp_dept/eqp_status/eqp_qty leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11676"
},
{
"type": "WEB",
"url": "https://codeastro.com"
},
{
"type": "WEB",
"url": "https://github.com/EmilGallajov/zero-day/blob/main/codeastro_hms_stored_xss.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.286016"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.286016"
},
{
"type": "WEB",
"url": "https://www.youtube.com/watch?v=UsScmd8Xzuw"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-26T01:15:06Z"
}
}
@@ -0,0 +1,58 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j8p2-5922-rxpr",
"modified": "2024-11-26T03:36:38Z",
"published": "2024-11-26T03:36:38Z",
"aliases": [
"CVE-2024-11678"
],
"details": "A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /backend/doc/his_doc_register_patient.php. The manipulation of the argument pat_fname/pat_ailment/pat_lname/pat_age/pat_dob/pat_number/pat_phone/pat_type/pat_addr leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11678"
},
{
"type": "WEB",
"url": "https://codeastro.com"
},
{
"type": "WEB",
"url": "https://github.com/EmilGallajov/zero-day/blob/main/codeastro_hms_stored_xss.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.286018"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.286018"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.448789"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-26T02:15:18Z"
}
}
@@ -52,7 +52,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-120"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -0,0 +1,58 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mx67-gpgv-qm6w",
"modified": "2024-11-26T03:36:38Z",
"published": "2024-11-26T03:36:38Z",
"aliases": [
"CVE-2024-11677"
],
"details": "A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /backend/admin/his_admin_add_vendor.php of the component Add Vendor Details Page. The manipulation of the argument v_name/v_adr/v_number/v_email/v_phone/v_desc leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11677"
},
{
"type": "WEB",
"url": "https://codeastro.com"
},
{
"type": "WEB",
"url": "https://github.com/EmilGallajov/zero-day/blob/main/codeastro_hms_stored_xss.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.286017"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.286017"
},
{
"type": "WEB",
"url": "https://www.youtube.com/watch?v=UsScmd8Xzuw"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-26T02:15:17Z"
}
}
@@ -44,7 +44,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -48,7 +48,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -0,0 +1,58 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rwvw-fh44-w2r2",
"modified": "2024-11-26T03:36:38Z",
"published": "2024-11-26T03:36:38Z",
"aliases": [
"CVE-2024-11675"
],
"details": "A vulnerability has been found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /backend/admin/his_admin_register_patient.php of the component Add Patient Details Page. The manipulation of the argument pat_fname/pat_ailment/pat_lname/pat_age/pat_dob/pat_number/pat_phone/pat_type/pat_addr leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11675"
},
{
"type": "WEB",
"url": "https://codeastro.com"
},
{
"type": "WEB",
"url": "https://github.com/EmilGallajov/zero-day/blob/main/codeastro_hms_stored_xss.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.286015"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.286015"
},
{
"type": "WEB",
"url": "https://www.youtube.com/watch?v=UsScmd8Xzuw"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-26T01:15:04Z"
}
}