From 17d8b5fc039c13b442bd0738e13d417bffb998c0 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 16 Feb 2024 09:31:35 +0000 Subject: [PATCH] Publish Advisories GHSA-7299-g634-x782 GHSA-394m-vxwj-363j GHSA-936r-cg7h-crfg GHSA-gqv6-f424-3g7h GHSA-pmgm-h3cc-m4hj GHSA-xmmg-4cv8-23px --- .../GHSA-7299-g634-x782.json | 8 +++- .../GHSA-394m-vxwj-363j.json | 43 +++++++++++++++++++ .../GHSA-936r-cg7h-crfg.json | 35 +++++++++++++++ .../GHSA-gqv6-f424-3g7h.json | 39 +++++++++++++++++ .../GHSA-pmgm-h3cc-m4hj.json | 39 +++++++++++++++++ .../GHSA-xmmg-4cv8-23px.json | 35 +++++++++++++++ 6 files changed, 197 insertions(+), 2 deletions(-) create mode 100644 advisories/unreviewed/2024/02/GHSA-394m-vxwj-363j/GHSA-394m-vxwj-363j.json create mode 100644 advisories/unreviewed/2024/02/GHSA-936r-cg7h-crfg/GHSA-936r-cg7h-crfg.json create mode 100644 advisories/unreviewed/2024/02/GHSA-gqv6-f424-3g7h/GHSA-gqv6-f424-3g7h.json create mode 100644 advisories/unreviewed/2024/02/GHSA-pmgm-h3cc-m4hj/GHSA-pmgm-h3cc-m4hj.json create mode 100644 advisories/unreviewed/2024/02/GHSA-xmmg-4cv8-23px/GHSA-xmmg-4cv8-23px.json diff --git a/advisories/unreviewed/2024/01/GHSA-7299-g634-x782/GHSA-7299-g634-x782.json b/advisories/unreviewed/2024/01/GHSA-7299-g634-x782/GHSA-7299-g634-x782.json index d994cce3e90..661e0bb1a98 100644 --- a/advisories/unreviewed/2024/01/GHSA-7299-g634-x782/GHSA-7299-g634-x782.json +++ b/advisories/unreviewed/2024/01/GHSA-7299-g634-x782/GHSA-7299-g634-x782.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7299-g634-x782", - "modified": "2024-01-30T18:30:19Z", + "modified": "2024-02-16T09:30:24Z", "published": "2024-01-23T12:30:30Z", "aliases": [ "CVE-2024-22076" @@ -23,11 +23,15 @@ }, { "type": "WEB", - "url": "https://docs.myq-solution.com/en/print-server/8.2/" + "url": "https://docs.myq-solution.com/en/print-server/8.2" }, { "type": "WEB", "url": "https://docs.myq-solution.com/en/print-server/8.2/technical-changelog#id-%288.2%29ReleaseNotes-8.2%28Patch43%29" + }, + { + "type": "WEB", + "url": "https://www.access42.nl/nieuws/unmasking-web-vulnerabilities-a-tale-of-default-admin-credentials-and-php-command-execution-cve-2024-22076" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-394m-vxwj-363j/GHSA-394m-vxwj-363j.json b/advisories/unreviewed/2024/02/GHSA-394m-vxwj-363j/GHSA-394m-vxwj-363j.json new file mode 100644 index 00000000000..ff720060832 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-394m-vxwj-363j/GHSA-394m-vxwj-363j.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-394m-vxwj-363j", + "modified": "2024-02-16T09:30:25Z", + "published": "2024-02-16T09:30:25Z", + "aliases": [ + "CVE-2023-49508" + ], + "details": "Directory Traversal vulnerability in YetiForceCompany YetiForceCRM versions 6.4.0 and before allows a remote authenticated attacker to obtain sensitive information via the license parameter in the LibraryLicense.php component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49508" + }, + { + "type": "WEB", + "url": "https://github.com/YetiForceCompany/YetiForceCRM/commit/ba3a348aa6ecdf0a1d8b289cbb679bebcda7a132" + }, + { + "type": "WEB", + "url": "https://github.com/c4v4r0n/Research/tree/main/CVE-2023-49508" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/29ed641d-eb03-4532-aed4-f96e11f78983" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-16T08:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-936r-cg7h-crfg/GHSA-936r-cg7h-crfg.json b/advisories/unreviewed/2024/02/GHSA-936r-cg7h-crfg/GHSA-936r-cg7h-crfg.json new file mode 100644 index 00000000000..020cec549f4 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-936r-cg7h-crfg/GHSA-936r-cg7h-crfg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-936r-cg7h-crfg", + "modified": "2024-02-16T09:30:26Z", + "published": "2024-02-16T09:30:26Z", + "aliases": [ + "CVE-2024-24377" + ], + "details": "An issue in idocv v.14.1.3_20231228 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted script.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24377" + }, + { + "type": "WEB", + "url": "https://zhuabapa.top/2024/01/18/idocv_20231228_rce/#more" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-16T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-gqv6-f424-3g7h/GHSA-gqv6-f424-3g7h.json b/advisories/unreviewed/2024/02/GHSA-gqv6-f424-3g7h/GHSA-gqv6-f424-3g7h.json new file mode 100644 index 00000000000..195ebe0bd13 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-gqv6-f424-3g7h/GHSA-gqv6-f424-3g7h.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqv6-f424-3g7h", + "modified": "2024-02-16T09:30:25Z", + "published": "2024-02-16T09:30:25Z", + "aliases": [ + "CVE-2023-51931" + ], + "details": "An issue in alanclarke URLite v.3.1.0 allows an attacker to cause a denial of service (DoS) via a crafted payload to the parsing function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51931" + }, + { + "type": "WEB", + "url": "https://github.com/alanclarke/urlite/issues/61" + }, + { + "type": "WEB", + "url": "https://gist.github.com/6en6ar/c792d8337b63f095cbda907e834cb4ba" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-16T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-pmgm-h3cc-m4hj/GHSA-pmgm-h3cc-m4hj.json b/advisories/unreviewed/2024/02/GHSA-pmgm-h3cc-m4hj/GHSA-pmgm-h3cc-m4hj.json new file mode 100644 index 00000000000..9244c071391 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-pmgm-h3cc-m4hj/GHSA-pmgm-h3cc-m4hj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmgm-h3cc-m4hj", + "modified": "2024-02-16T09:30:26Z", + "published": "2024-02-16T09:30:26Z", + "aliases": [ + "CVE-2024-25466" + ], + "details": "Directory Traversal vulnerability in React Native Document Picker before v.9.1.1 and fixed in v.9.1.1 allows a local attacker to execute arbitrary code via a crafted script to the Android library component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25466" + }, + { + "type": "WEB", + "url": "https://github.com/FixedOctocat/CVE-2024-25466/tree/main" + }, + { + "type": "WEB", + "url": "https://github.com/rnmods/react-native-document-picker/blob/0be5a70c3b456e35c2454aaf4dc8c2d40eb2ab47/android/src/main/java/com/reactnativedocumentpicker/RNDocumentPickerModule.java" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-16T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-xmmg-4cv8-23px/GHSA-xmmg-4cv8-23px.json b/advisories/unreviewed/2024/02/GHSA-xmmg-4cv8-23px/GHSA-xmmg-4cv8-23px.json new file mode 100644 index 00000000000..3ff4f167ce1 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-xmmg-4cv8-23px/GHSA-xmmg-4cv8-23px.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmmg-4cv8-23px", + "modified": "2024-02-16T09:30:25Z", + "published": "2024-02-16T09:30:25Z", + "aliases": [ + "CVE-2024-22854" + ], + "details": "DOM-based HTML injection vulnerability in the main page of Darktrace Threat Visualizer version 6.1.27 (bundle version 61050) and before has been identified. A URL, crafted by a remote attacker and visited by an authenticated user, allows open redirect and potential credential stealing using an injected HTML form.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22854" + }, + { + "type": "WEB", + "url": "https://tomekwasiak.pl/cve-2024-22854" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-16T09:15:08Z" + } +} \ No newline at end of file