From 18ec3d34d65a84bf228ae317f5c17482b18a0cb1 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 14 Oct 2024 15:32:26 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-mc76-5925-c5p6.json | 6 ++- .../GHSA-3p3x-vg38-6g9q.json | 3 +- .../GHSA-c945-cqj5-wfv6.json | 1 + .../GHSA-hpqg-7fjp-436p.json | 5 +- .../GHSA-53wr-cx66-4578.json | 2 +- .../GHSA-xw78-pcr6-wrg8.json | 4 +- .../GHSA-2cj7-mg3x-9mhq.json | 1 + .../GHSA-rj8q-prqp-jwfg.json | 1 + .../GHSA-299c-jvhc-gxj8.json | 2 +- .../GHSA-hvc4-mjv4-5mw6.json | 2 +- .../GHSA-85xr-ghj6-6m46.json | 1 + .../GHSA-3cr3-v8qm-wfcv.json | 43 +++++++++++++++++ .../GHSA-3xj2-mwp8-qr4q.json | 31 +++++++++++++ .../GHSA-528v-jf9w-58xh.json | 43 +++++++++++++++++ .../GHSA-5624-47cx-2qwc.json | 43 +++++++++++++++++ .../GHSA-8c7g-vx5g-cmpg.json | 39 ++++++++++++++++ .../GHSA-8g38-jgjc-p9jh.json | 38 +++++++++++++++ .../GHSA-96gx-8f8g-cr5v.json | 35 ++++++++++++++ .../GHSA-99cw-3x24-r8wh.json | 43 +++++++++++++++++ .../GHSA-hcvw-99gq-xhq8.json | 31 +++++++++++++ .../GHSA-j26w-f9rq-mr2q.json | 46 +++++++++++++++++++ .../GHSA-m34r-7vq3-hcmm.json | 35 ++++++++++++++ .../GHSA-v7q3-h4r2-3g3j.json | 43 +++++++++++++++++ .../GHSA-w475-fv8v-qxrm.json | 43 +++++++++++++++++ .../GHSA-wr43-q2v2-949w.json | 42 +++++++++++++++++ 25 files changed, 574 insertions(+), 9 deletions(-) create mode 100644 advisories/unreviewed/2024/10/GHSA-3cr3-v8qm-wfcv/GHSA-3cr3-v8qm-wfcv.json create mode 100644 advisories/unreviewed/2024/10/GHSA-3xj2-mwp8-qr4q/GHSA-3xj2-mwp8-qr4q.json create mode 100644 advisories/unreviewed/2024/10/GHSA-528v-jf9w-58xh/GHSA-528v-jf9w-58xh.json create mode 100644 advisories/unreviewed/2024/10/GHSA-5624-47cx-2qwc/GHSA-5624-47cx-2qwc.json create mode 100644 advisories/unreviewed/2024/10/GHSA-8c7g-vx5g-cmpg/GHSA-8c7g-vx5g-cmpg.json create mode 100644 advisories/unreviewed/2024/10/GHSA-8g38-jgjc-p9jh/GHSA-8g38-jgjc-p9jh.json create mode 100644 advisories/unreviewed/2024/10/GHSA-96gx-8f8g-cr5v/GHSA-96gx-8f8g-cr5v.json create mode 100644 advisories/unreviewed/2024/10/GHSA-99cw-3x24-r8wh/GHSA-99cw-3x24-r8wh.json create mode 100644 advisories/unreviewed/2024/10/GHSA-hcvw-99gq-xhq8/GHSA-hcvw-99gq-xhq8.json create mode 100644 advisories/unreviewed/2024/10/GHSA-j26w-f9rq-mr2q/GHSA-j26w-f9rq-mr2q.json create mode 100644 advisories/unreviewed/2024/10/GHSA-m34r-7vq3-hcmm/GHSA-m34r-7vq3-hcmm.json create mode 100644 advisories/unreviewed/2024/10/GHSA-v7q3-h4r2-3g3j/GHSA-v7q3-h4r2-3g3j.json create mode 100644 advisories/unreviewed/2024/10/GHSA-w475-fv8v-qxrm/GHSA-w475-fv8v-qxrm.json create mode 100644 advisories/unreviewed/2024/10/GHSA-wr43-q2v2-949w/GHSA-wr43-q2v2-949w.json diff --git a/advisories/github-reviewed/2024/10/GHSA-mc76-5925-c5p6/GHSA-mc76-5925-c5p6.json b/advisories/github-reviewed/2024/10/GHSA-mc76-5925-c5p6/GHSA-mc76-5925-c5p6.json index d2c44785bac..8a65474314d 100644 --- a/advisories/github-reviewed/2024/10/GHSA-mc76-5925-c5p6/GHSA-mc76-5925-c5p6.json +++ b/advisories/github-reviewed/2024/10/GHSA-mc76-5925-c5p6/GHSA-mc76-5925-c5p6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mc76-5925-c5p6", - "modified": "2024-10-01T22:31:14Z", + "modified": "2024-10-14T15:30:45Z", "published": "2024-10-01T21:31:34Z", "aliases": [ "CVE-2024-9341" @@ -48,6 +48,10 @@ "type": "WEB", "url": "https://github.com/containers/common/commit/e7db06585c32e1a782c1d9aa3b71ccd708f5e23f" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:8039" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-9341" diff --git a/advisories/unreviewed/2023/07/GHSA-3p3x-vg38-6g9q/GHSA-3p3x-vg38-6g9q.json b/advisories/unreviewed/2023/07/GHSA-3p3x-vg38-6g9q/GHSA-3p3x-vg38-6g9q.json index fda53e258f6..051c71ee15b 100644 --- a/advisories/unreviewed/2023/07/GHSA-3p3x-vg38-6g9q/GHSA-3p3x-vg38-6g9q.json +++ b/advisories/unreviewed/2023/07/GHSA-3p3x-vg38-6g9q/GHSA-3p3x-vg38-6g9q.json @@ -76,7 +76,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1333" + "CWE-1333", + "CWE-606" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-c945-cqj5-wfv6/GHSA-c945-cqj5-wfv6.json b/advisories/unreviewed/2023/07/GHSA-c945-cqj5-wfv6/GHSA-c945-cqj5-wfv6.json index 922d333bf82..e9a4caf6101 100644 --- a/advisories/unreviewed/2023/07/GHSA-c945-cqj5-wfv6/GHSA-c945-cqj5-wfv6.json +++ b/advisories/unreviewed/2023/07/GHSA-c945-cqj5-wfv6/GHSA-c945-cqj5-wfv6.json @@ -84,6 +84,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-606", "CWE-834" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/07/GHSA-hpqg-7fjp-436p/GHSA-hpqg-7fjp-436p.json b/advisories/unreviewed/2023/07/GHSA-hpqg-7fjp-436p/GHSA-hpqg-7fjp-436p.json index d387e2b9245..b74b832c31d 100644 --- a/advisories/unreviewed/2023/07/GHSA-hpqg-7fjp-436p/GHSA-hpqg-7fjp-436p.json +++ b/advisories/unreviewed/2023/07/GHSA-hpqg-7fjp-436p/GHSA-hpqg-7fjp-436p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hpqg-7fjp-436p", - "modified": "2024-02-04T09:30:41Z", + "modified": "2024-10-14T15:30:44Z", "published": "2023-07-14T12:30:21Z", "aliases": [ "CVE-2023-2975" @@ -52,7 +52,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-354" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-53wr-cx66-4578/GHSA-53wr-cx66-4578.json b/advisories/unreviewed/2023/09/GHSA-53wr-cx66-4578/GHSA-53wr-cx66-4578.json index 5206e1082ea..ce70484165b 100644 --- a/advisories/unreviewed/2023/09/GHSA-53wr-cx66-4578/GHSA-53wr-cx66-4578.json +++ b/advisories/unreviewed/2023/09/GHSA-53wr-cx66-4578/GHSA-53wr-cx66-4578.json @@ -56,7 +56,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-440" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-xw78-pcr6-wrg8/GHSA-xw78-pcr6-wrg8.json b/advisories/unreviewed/2023/10/GHSA-xw78-pcr6-wrg8/GHSA-xw78-pcr6-wrg8.json index aa49b346c22..142680b891d 100644 --- a/advisories/unreviewed/2023/10/GHSA-xw78-pcr6-wrg8/GHSA-xw78-pcr6-wrg8.json +++ b/advisories/unreviewed/2023/10/GHSA-xw78-pcr6-wrg8/GHSA-xw78-pcr6-wrg8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xw78-pcr6-wrg8", - "modified": "2023-11-09T15:30:26Z", + "modified": "2024-10-14T15:30:45Z", "published": "2023-10-25T18:32:26Z", "aliases": [ "CVE-2023-5363" @@ -56,7 +56,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-684" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-2cj7-mg3x-9mhq/GHSA-2cj7-mg3x-9mhq.json b/advisories/unreviewed/2023/11/GHSA-2cj7-mg3x-9mhq/GHSA-2cj7-mg3x-9mhq.json index ef614ce45d1..65443b11462 100644 --- a/advisories/unreviewed/2023/11/GHSA-2cj7-mg3x-9mhq/GHSA-2cj7-mg3x-9mhq.json +++ b/advisories/unreviewed/2023/11/GHSA-2cj7-mg3x-9mhq/GHSA-2cj7-mg3x-9mhq.json @@ -56,6 +56,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-606", "CWE-754" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/01/GHSA-rj8q-prqp-jwfg/GHSA-rj8q-prqp-jwfg.json b/advisories/unreviewed/2024/01/GHSA-rj8q-prqp-jwfg/GHSA-rj8q-prqp-jwfg.json index 207c69458bc..8948caef9a5 100644 --- a/advisories/unreviewed/2024/01/GHSA-rj8q-prqp-jwfg/GHSA-rj8q-prqp-jwfg.json +++ b/advisories/unreviewed/2024/01/GHSA-rj8q-prqp-jwfg/GHSA-rj8q-prqp-jwfg.json @@ -64,6 +64,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-440", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/04/GHSA-299c-jvhc-gxj8/GHSA-299c-jvhc-gxj8.json b/advisories/unreviewed/2024/04/GHSA-299c-jvhc-gxj8/GHSA-299c-jvhc-gxj8.json index 4e167fef0a7..6691d986c9f 100644 --- a/advisories/unreviewed/2024/04/GHSA-299c-jvhc-gxj8/GHSA-299c-jvhc-gxj8.json +++ b/advisories/unreviewed/2024/04/GHSA-299c-jvhc-gxj8/GHSA-299c-jvhc-gxj8.json @@ -49,7 +49,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1325" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-hvc4-mjv4-5mw6/GHSA-hvc4-mjv4-5mw6.json b/advisories/unreviewed/2024/04/GHSA-hvc4-mjv4-5mw6/GHSA-hvc4-mjv4-5mw6.json index fc901cbae27..cc0f6aaeacf 100644 --- a/advisories/unreviewed/2024/04/GHSA-hvc4-mjv4-5mw6/GHSA-hvc4-mjv4-5mw6.json +++ b/advisories/unreviewed/2024/04/GHSA-hvc4-mjv4-5mw6/GHSA-hvc4-mjv4-5mw6.json @@ -45,7 +45,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-606" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-85xr-ghj6-6m46/GHSA-85xr-ghj6-6m46.json b/advisories/unreviewed/2024/05/GHSA-85xr-ghj6-6m46/GHSA-85xr-ghj6-6m46.json index 30a4ad38b01..172f0683bf6 100644 --- a/advisories/unreviewed/2024/05/GHSA-85xr-ghj6-6m46/GHSA-85xr-ghj6-6m46.json +++ b/advisories/unreviewed/2024/05/GHSA-85xr-ghj6-6m46/GHSA-85xr-ghj6-6m46.json @@ -52,6 +52,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-606", "CWE-834" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/10/GHSA-3cr3-v8qm-wfcv/GHSA-3cr3-v8qm-wfcv.json b/advisories/unreviewed/2024/10/GHSA-3cr3-v8qm-wfcv/GHSA-3cr3-v8qm-wfcv.json new file mode 100644 index 00000000000..dfe351dcd4e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3cr3-v8qm-wfcv/GHSA-3cr3-v8qm-wfcv.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3cr3-v8qm-wfcv", + "modified": "2024-10-14T15:30:46Z", + "published": "2024-10-14T15:30:46Z", + "aliases": [ + "CVE-2024-48251" + ], + "details": "Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48251" + }, + { + "type": "WEB", + "url": "https://github.com/wavelog/wavelog/commit/0bf2675d93602b591850790c8fcfced886eca423" + }, + { + "type": "WEB", + "url": "https://chiggerlor.substack.com/p/unauthenticated-sql-injection-in" + }, + { + "type": "WEB", + "url": "https://www.wavelog.org" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3xj2-mwp8-qr4q/GHSA-3xj2-mwp8-qr4q.json b/advisories/unreviewed/2024/10/GHSA-3xj2-mwp8-qr4q/GHSA-3xj2-mwp8-qr4q.json new file mode 100644 index 00000000000..c4ab90bcb1e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3xj2-mwp8-qr4q/GHSA-3xj2-mwp8-qr4q.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xj2-mwp8-qr4q", + "modified": "2024-10-14T15:30:46Z", + "published": "2024-10-14T15:30:46Z", + "aliases": [ + "CVE-2024-48261" + ], + "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-48251. Reason: This candidate is a reservation duplicate of CVE-2024-48251. Notes: All CVE users should reference CVE-2024-48251 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48261" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-528v-jf9w-58xh/GHSA-528v-jf9w-58xh.json b/advisories/unreviewed/2024/10/GHSA-528v-jf9w-58xh/GHSA-528v-jf9w-58xh.json new file mode 100644 index 00000000000..2792022394a --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-528v-jf9w-58xh/GHSA-528v-jf9w-58xh.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-528v-jf9w-58xh", + "modified": "2024-10-14T15:30:46Z", + "published": "2024-10-14T15:30:46Z", + "aliases": [ + "CVE-2024-48257" + ], + "details": "Wavelog 1.8.5 allows Oqrs_model.php get_worked_modes station_id SQL injectioin.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48257" + }, + { + "type": "WEB", + "url": "https://github.com/wavelog/wavelog/commit/0bf2675d93602b591850790c8fcfced886eca423" + }, + { + "type": "WEB", + "url": "https://chiggerlor.substack.com/p/unauthenticated-sql-injection-in" + }, + { + "type": "WEB", + "url": "https://www.wavelog.org" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5624-47cx-2qwc/GHSA-5624-47cx-2qwc.json b/advisories/unreviewed/2024/10/GHSA-5624-47cx-2qwc/GHSA-5624-47cx-2qwc.json new file mode 100644 index 00000000000..be8f6f7bcb1 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5624-47cx-2qwc/GHSA-5624-47cx-2qwc.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5624-47cx-2qwc", + "modified": "2024-10-14T15:30:45Z", + "published": "2024-10-14T15:30:45Z", + "aliases": [ + "CVE-2024-48253" + ], + "details": "Cloudlog 2.6.15 allows Oqrs.php delete_oqrs_line id SQL injection.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48253" + }, + { + "type": "WEB", + "url": "https://chiggerlor.substack.com/p/unauthenticated-sql-injection-in-9a3" + }, + { + "type": "WEB", + "url": "https://github.com/magicbug/Cloudlog" + }, + { + "type": "WEB", + "url": "https://www.magicbug.co.uk/cloudlog" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8c7g-vx5g-cmpg/GHSA-8c7g-vx5g-cmpg.json b/advisories/unreviewed/2024/10/GHSA-8c7g-vx5g-cmpg/GHSA-8c7g-vx5g-cmpg.json new file mode 100644 index 00000000000..d9e3cb12239 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8c7g-vx5g-cmpg/GHSA-8c7g-vx5g-cmpg.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8c7g-vx5g-cmpg", + "modified": "2024-10-14T15:30:46Z", + "published": "2024-10-14T15:30:46Z", + "aliases": [ + "CVE-2024-9936" + ], + "details": "When manipulating the selection node cache, an attacker may have been able to cause unexpected behavior, potentially leading to an exploitable crash. This vulnerability affects Firefox < 131.0.3.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9936" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1920381" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-53" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8g38-jgjc-p9jh/GHSA-8g38-jgjc-p9jh.json b/advisories/unreviewed/2024/10/GHSA-8g38-jgjc-p9jh/GHSA-8g38-jgjc-p9jh.json new file mode 100644 index 00000000000..b08c9d1b9fd --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8g38-jgjc-p9jh/GHSA-8g38-jgjc-p9jh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8g38-jgjc-p9jh", + "modified": "2024-10-14T15:30:45Z", + "published": "2024-10-14T15:30:45Z", + "aliases": [ + "CVE-2024-8602" + ], + "details": "When the XML is read from the codes in the PDF and parsed using a DocumentBuilder, the default settings of the DocumentBuilder allow for an XXE (XML External Entity) attack. Further information on this can be found on the website of the Open Worldwide Application Security Project (OWASP). An attacker could theoretically leverage this by delivering a manipulated PDF file to the target, and depending on the environment, various actions can be executed. These actions include:\n\n * Reading files from the operating system\n * Crashing the thread handling the parsing or causing it to enter an infinite loop\n * Executing HTTP requests\n * Loading additional DTDs or XML files\n * Under certain conditions, executing OS commands", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:A/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:X/V:X/RE:L/U:Green" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8602" + }, + { + "type": "WEB", + "url": "https://esteuer.ewv-ete.ch/fileadmin/esta/2024-10-09-update/24_09_esta_newsletter_de.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-96gx-8f8g-cr5v/GHSA-96gx-8f8g-cr5v.json b/advisories/unreviewed/2024/10/GHSA-96gx-8f8g-cr5v/GHSA-96gx-8f8g-cr5v.json new file mode 100644 index 00000000000..558606bea37 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-96gx-8f8g-cr5v/GHSA-96gx-8f8g-cr5v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-96gx-8f8g-cr5v", + "modified": "2024-10-14T15:30:45Z", + "published": "2024-10-14T15:30:45Z", + "aliases": [ + "CVE-2024-48120" + ], + "details": "X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the \"Opportunities\" module. An attacker can inject malicious JavaScript code into the \"Name\" field when creating a list.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48120" + }, + { + "type": "WEB", + "url": "https://okankurtulus.com.tr/2024/09/12/x2crm-v8-5-stored-cross-site-scripting-xss-authenticated" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-99cw-3x24-r8wh/GHSA-99cw-3x24-r8wh.json b/advisories/unreviewed/2024/10/GHSA-99cw-3x24-r8wh/GHSA-99cw-3x24-r8wh.json new file mode 100644 index 00000000000..4645689d76b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-99cw-3x24-r8wh/GHSA-99cw-3x24-r8wh.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99cw-3x24-r8wh", + "modified": "2024-10-14T15:30:46Z", + "published": "2024-10-14T15:30:46Z", + "aliases": [ + "CVE-2024-48259" + ], + "details": "Cloudlog 2.6.15 allows Oqrs.php request_form SQL injection via station_id or callsign.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48259" + }, + { + "type": "WEB", + "url": "https://chiggerlor.substack.com/p/unauthenticated-sql-injection-in-9a3" + }, + { + "type": "WEB", + "url": "https://github.com/magicbug/Cloudlog" + }, + { + "type": "WEB", + "url": "https://www.magicbug.co.uk/cloudlog" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-hcvw-99gq-xhq8/GHSA-hcvw-99gq-xhq8.json b/advisories/unreviewed/2024/10/GHSA-hcvw-99gq-xhq8/GHSA-hcvw-99gq-xhq8.json new file mode 100644 index 00000000000..d0d7ec044ae --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-hcvw-99gq-xhq8/GHSA-hcvw-99gq-xhq8.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hcvw-99gq-xhq8", + "modified": "2024-10-14T15:30:46Z", + "published": "2024-10-14T15:30:46Z", + "aliases": [ + "CVE-2024-40616" + ], + "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40616" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-j26w-f9rq-mr2q/GHSA-j26w-f9rq-mr2q.json b/advisories/unreviewed/2024/10/GHSA-j26w-f9rq-mr2q/GHSA-j26w-f9rq-mr2q.json new file mode 100644 index 00000000000..9ca17f132de --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-j26w-f9rq-mr2q/GHSA-j26w-f9rq-mr2q.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j26w-f9rq-mr2q", + "modified": "2024-10-14T15:30:46Z", + "published": "2024-10-14T15:30:46Z", + "aliases": [ + "CVE-2024-9823" + ], + "details": "Description\nThere exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized\n\nusers to cause remote denial-of-service (DoS) attack on the server using DosFilter. By repeatedly sending crafted requests,\n\nattackers can trigger OutofMemory errors and exhaust the server's memory finally.\n\n\nVulnerability details\nThe Jetty DoSFilter (Denial of Service Filter) is a security filter designed to protect web\n\napplications against certain types of Denial of Service (DoS) attacks and other abusive behavior. It\n\nhelps to mitigate excessive resource consumption by limiting the rate at which clients can make\n\nrequests to the server. The DoSFilter monitors and tracks client request patterns, including\n\nrequest rates, and can take actions such as blocking or delaying requests from clients that exceed\n\npredefined thresholds. The internal tracking of requests in DoSFilter is the source of this OutOfMemory\n\ncondition.\n\n\nImpact\nUsers of the DoSFilter may be subject to DoS attacks that \nwill ultimately exhaust the memory of the server if they have not \nconfigured session passivation or an aggressive session inactivation \ntimeout.\n\n\nPatches\nThe DoSFilter has been patched in all active releases to no longer support the session tracking mode, even if configured.\n\n\nPatched releases:\n\n\n\n * 9.4.54\n\n * 10.0.18\n\n * 11.0.18\n\n * 12.0.3", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/jetty/jetty.project/security/advisories/GHSA-7hcf-ppf8-5w5h" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9823" + }, + { + "type": "WEB", + "url": "https://github.com/jetty/jetty.project/issues/1256" + }, + { + "type": "WEB", + "url": "https://gitlab.eclipse.org/security/cve-assignement/-/issues/39" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m34r-7vq3-hcmm/GHSA-m34r-7vq3-hcmm.json b/advisories/unreviewed/2024/10/GHSA-m34r-7vq3-hcmm/GHSA-m34r-7vq3-hcmm.json new file mode 100644 index 00000000000..d189ccaef44 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m34r-7vq3-hcmm/GHSA-m34r-7vq3-hcmm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m34r-7vq3-hcmm", + "modified": "2024-10-14T15:30:45Z", + "published": "2024-10-14T15:30:45Z", + "aliases": [ + "CVE-2024-48119" + ], + "details": "Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary HTML.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48119" + }, + { + "type": "WEB", + "url": "https://okankurtulus.com.tr/2024/09/12/vtiger-crm-v8-2-0-html-injection-authenticated" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-v7q3-h4r2-3g3j/GHSA-v7q3-h4r2-3g3j.json b/advisories/unreviewed/2024/10/GHSA-v7q3-h4r2-3g3j/GHSA-v7q3-h4r2-3g3j.json new file mode 100644 index 00000000000..e319c2042b0 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-v7q3-h4r2-3g3j/GHSA-v7q3-h4r2-3g3j.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v7q3-h4r2-3g3j", + "modified": "2024-10-14T15:30:45Z", + "published": "2024-10-14T15:30:45Z", + "aliases": [ + "CVE-2024-48255" + ], + "details": "Cloudlog 2.6.15 allows Oqrs.php get_station_info station_id SQL injection.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48255" + }, + { + "type": "WEB", + "url": "https://chiggerlor.substack.com/p/unauthenticated-sql-injection-in-9a3" + }, + { + "type": "WEB", + "url": "https://github.com/magicbug/Cloudlog" + }, + { + "type": "WEB", + "url": "https://www.magicbug.co.uk/cloudlog" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w475-fv8v-qxrm/GHSA-w475-fv8v-qxrm.json b/advisories/unreviewed/2024/10/GHSA-w475-fv8v-qxrm/GHSA-w475-fv8v-qxrm.json new file mode 100644 index 00000000000..c9b7ca43cc4 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w475-fv8v-qxrm/GHSA-w475-fv8v-qxrm.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w475-fv8v-qxrm", + "modified": "2024-10-14T15:30:46Z", + "published": "2024-10-14T15:30:46Z", + "aliases": [ + "CVE-2024-48249" + ], + "details": "Wavelog 1.8.5 allows Gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48249" + }, + { + "type": "WEB", + "url": "https://github.com/wavelog/wavelog/commit/0bf2675d93602b591850790c8fcfced886eca423" + }, + { + "type": "WEB", + "url": "https://chiggerlor.substack.com/p/unauthenticated-sql-injection-in" + }, + { + "type": "WEB", + "url": "https://www.wavelog.org" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-wr43-q2v2-949w/GHSA-wr43-q2v2-949w.json b/advisories/unreviewed/2024/10/GHSA-wr43-q2v2-949w/GHSA-wr43-q2v2-949w.json new file mode 100644 index 00000000000..bb633efdfd4 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-wr43-q2v2-949w/GHSA-wr43-q2v2-949w.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wr43-q2v2-949w", + "modified": "2024-10-14T15:30:45Z", + "published": "2024-10-14T15:30:45Z", + "aliases": [ + "CVE-2024-7847" + ], + "details": "VULNERABILITY DETAILS\n\nRockwell Automation used the latest versions of the CVSS scoring system to assess the following vulnerabilities. The following vulnerabilities were reported to us by Sharon Brizinov of Claroty Research - Team82. \n\nA feature in the affected products enables users to prepare a project file with an embedded VBA script and can be configured to run once the project file has been opened without user intervention. This feature can be abused to trick a legitimate user into executing malicious code upon opening an infected RSP/RSS project file. If exploited, a threat actor may be able to perform a remote code execution. Connected devices may also be impacted by exploitation of this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7847" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1701.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-345" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T14:15:12Z" + } +} \ No newline at end of file