Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-10-14 15:32:26 +00:00
parent a4684465de
commit 18ec3d34d6
25 changed files with 574 additions and 9 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mc76-5925-c5p6",
"modified": "2024-10-01T22:31:14Z",
"modified": "2024-10-14T15:30:45Z",
"published": "2024-10-01T21:31:34Z",
"aliases": [
"CVE-2024-9341"
@@ -48,6 +48,10 @@
"type": "WEB",
"url": "https://github.com/containers/common/commit/e7db06585c32e1a782c1d9aa3b71ccd708f5e23f"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:8039"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-9341"
@@ -76,7 +76,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-1333"
"CWE-1333",
"CWE-606"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -84,6 +84,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-606",
"CWE-834"
],
"severity": "MODERATE",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hpqg-7fjp-436p",
"modified": "2024-02-04T09:30:41Z",
"modified": "2024-10-14T15:30:44Z",
"published": "2023-07-14T12:30:21Z",
"aliases": [
"CVE-2023-2975"
@@ -52,7 +52,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-287"
"CWE-287",
"CWE-354"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -56,7 +56,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-440"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xw78-pcr6-wrg8",
"modified": "2023-11-09T15:30:26Z",
"modified": "2024-10-14T15:30:45Z",
"published": "2023-10-25T18:32:26Z",
"aliases": [
"CVE-2023-5363"
@@ -56,7 +56,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-684"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -56,6 +56,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-606",
"CWE-754"
],
"severity": "HIGH",
@@ -64,6 +64,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-440",
"CWE-787"
],
"severity": "MODERATE",
@@ -49,7 +49,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-1325"
],
"severity": null,
"github_reviewed": false,
@@ -45,7 +45,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-606"
],
"severity": null,
"github_reviewed": false,
@@ -52,6 +52,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-606",
"CWE-834"
],
"severity": "MODERATE",
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3cr3-v8qm-wfcv",
"modified": "2024-10-14T15:30:46Z",
"published": "2024-10-14T15:30:46Z",
"aliases": [
"CVE-2024-48251"
],
"details": "Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48251"
},
{
"type": "WEB",
"url": "https://github.com/wavelog/wavelog/commit/0bf2675d93602b591850790c8fcfced886eca423"
},
{
"type": "WEB",
"url": "https://chiggerlor.substack.com/p/unauthenticated-sql-injection-in"
},
{
"type": "WEB",
"url": "https://www.wavelog.org"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-14T15:15:13Z"
}
}
@@ -0,0 +1,31 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3xj2-mwp8-qr4q",
"modified": "2024-10-14T15:30:46Z",
"published": "2024-10-14T15:30:46Z",
"aliases": [
"CVE-2024-48261"
],
"details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-48251. Reason: This candidate is a reservation duplicate of CVE-2024-48251. Notes: All CVE users should reference CVE-2024-48251 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48261"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-14T15:15:14Z"
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-528v-jf9w-58xh",
"modified": "2024-10-14T15:30:46Z",
"published": "2024-10-14T15:30:46Z",
"aliases": [
"CVE-2024-48257"
],
"details": "Wavelog 1.8.5 allows Oqrs_model.php get_worked_modes station_id SQL injectioin.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48257"
},
{
"type": "WEB",
"url": "https://github.com/wavelog/wavelog/commit/0bf2675d93602b591850790c8fcfced886eca423"
},
{
"type": "WEB",
"url": "https://chiggerlor.substack.com/p/unauthenticated-sql-injection-in"
},
{
"type": "WEB",
"url": "https://www.wavelog.org"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-14T15:15:13Z"
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5624-47cx-2qwc",
"modified": "2024-10-14T15:30:45Z",
"published": "2024-10-14T15:30:45Z",
"aliases": [
"CVE-2024-48253"
],
"details": "Cloudlog 2.6.15 allows Oqrs.php delete_oqrs_line id SQL injection.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48253"
},
{
"type": "WEB",
"url": "https://chiggerlor.substack.com/p/unauthenticated-sql-injection-in-9a3"
},
{
"type": "WEB",
"url": "https://github.com/magicbug/Cloudlog"
},
{
"type": "WEB",
"url": "https://www.magicbug.co.uk/cloudlog"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-14T14:15:11Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8c7g-vx5g-cmpg",
"modified": "2024-10-14T15:30:46Z",
"published": "2024-10-14T15:30:46Z",
"aliases": [
"CVE-2024-9936"
],
"details": "When manipulating the selection node cache, an attacker may have been able to cause unexpected behavior, potentially leading to an exploitable crash. This vulnerability affects Firefox < 131.0.3.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9936"
},
{
"type": "WEB",
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1920381"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-53"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-14T14:15:12Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8g38-jgjc-p9jh",
"modified": "2024-10-14T15:30:45Z",
"published": "2024-10-14T15:30:45Z",
"aliases": [
"CVE-2024-8602"
],
"details": "When the XML is read from the codes in the PDF and parsed using a DocumentBuilder, the default settings of the DocumentBuilder allow for an XXE (XML External Entity) attack. Further information on this can be found on the website of the Open Worldwide Application Security Project (OWASP). An attacker could theoretically leverage this by delivering a manipulated PDF file to the target, and depending on the environment, various actions can be executed. These actions include:\n\n * Reading files from the operating system\n * Crashing the thread handling the parsing or causing it to enter an infinite loop\n * Executing HTTP requests\n * Loading additional DTDs or XML files\n * Under certain conditions, executing OS commands",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:A/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:X/V:X/RE:L/U:Green"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8602"
},
{
"type": "WEB",
"url": "https://esteuer.ewv-ete.ch/fileadmin/esta/2024-10-09-update/24_09_esta_newsletter_de.pdf"
}
],
"database_specific": {
"cwe_ids": [
"CWE-611"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-14T14:15:12Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-96gx-8f8g-cr5v",
"modified": "2024-10-14T15:30:45Z",
"published": "2024-10-14T15:30:45Z",
"aliases": [
"CVE-2024-48120"
],
"details": "X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the \"Opportunities\" module. An attacker can inject malicious JavaScript code into the \"Name\" field when creating a list.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48120"
},
{
"type": "WEB",
"url": "https://okankurtulus.com.tr/2024/09/12/x2crm-v8-5-stored-cross-site-scripting-xss-authenticated"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-14T14:15:11Z"
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-99cw-3x24-r8wh",
"modified": "2024-10-14T15:30:46Z",
"published": "2024-10-14T15:30:46Z",
"aliases": [
"CVE-2024-48259"
],
"details": "Cloudlog 2.6.15 allows Oqrs.php request_form SQL injection via station_id or callsign.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48259"
},
{
"type": "WEB",
"url": "https://chiggerlor.substack.com/p/unauthenticated-sql-injection-in-9a3"
},
{
"type": "WEB",
"url": "https://github.com/magicbug/Cloudlog"
},
{
"type": "WEB",
"url": "https://www.magicbug.co.uk/cloudlog"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-14T15:15:14Z"
}
}
@@ -0,0 +1,31 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hcvw-99gq-xhq8",
"modified": "2024-10-14T15:30:46Z",
"published": "2024-10-14T15:30:46Z",
"aliases": [
"CVE-2024-40616"
],
"details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40616"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-14T15:15:13Z"
}
}

Some files were not shown because too many files have changed in this diff Show More