From 1e56ffcd4783aec9b40a3ab3ceae4b87c801926a Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 14 Oct 2024 18:31:32 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-3jr7-qfmv-8m22.json | 39 +++++++++++++++ .../GHSA-3pc3-p9j7-xvq6.json | 42 +++++++++++++++++ .../GHSA-443j-grxv-2pgv.json | 35 ++++++++++++++ .../GHSA-4vmx-gm8x-gpjr.json | 42 +++++++++++++++++ .../GHSA-587p-xc7x-rjh8.json | 42 +++++++++++++++++ .../GHSA-5f4q-95cp-q722.json | 42 +++++++++++++++++ .../GHSA-5g3x-vvf6-gwg2.json | 35 ++++++++++++++ .../GHSA-72c9-vcqr-cxj8.json | 39 +++++++++++++++ .../GHSA-7p24-phjr-m5fc.json | 42 +++++++++++++++++ .../GHSA-8h7j-q956-7h6g.json | 39 +++++++++++++++ .../GHSA-8ppq-7m96-536p.json | 39 +++++++++++++++ .../GHSA-f98v-q2j5-v4qc.json | 42 +++++++++++++++++ .../GHSA-fj8g-7f3j-g879.json | 39 +++++++++++++++ .../GHSA-fqcp-xv9m-hcq2.json | 35 ++++++++++++++ .../GHSA-j6xh-hx47-7x23.json | 42 +++++++++++++++++ .../GHSA-j9m2-gxgg-6g4q.json | 39 +++++++++++++++ .../GHSA-m8vr-gvfq-cv5f.json | 39 +++++++++++++++ .../GHSA-p26r-gfgc-c47h.json | 39 +++++++++++++++ .../GHSA-p7rw-j46f-fvpg.json | 35 ++++++++++++++ .../GHSA-p8rh-8mh7-w4xh.json | 42 +++++++++++++++++ .../GHSA-ppxj-8w78-35rf.json | 39 +++++++++++++++ .../GHSA-q3q7-5v7p-vvhh.json | 42 +++++++++++++++++ .../GHSA-qg2h-xcfx-85gx.json | 35 ++++++++++++++ .../GHSA-r7cm-7xjc-5g35.json | 39 +++++++++++++++ .../GHSA-rg9v-8hp2-6q4g.json | 39 +++++++++++++++ .../GHSA-v8xh-475x-4q58.json | 42 +++++++++++++++++ .../GHSA-wf7c-j44x-2379.json | 42 +++++++++++++++++ .../GHSA-x25g-7892-q6v6.json | 47 +++++++++++++++++++ 28 files changed, 1113 insertions(+) create mode 100644 advisories/unreviewed/2024/10/GHSA-3jr7-qfmv-8m22/GHSA-3jr7-qfmv-8m22.json create mode 100644 advisories/unreviewed/2024/10/GHSA-3pc3-p9j7-xvq6/GHSA-3pc3-p9j7-xvq6.json create mode 100644 advisories/unreviewed/2024/10/GHSA-443j-grxv-2pgv/GHSA-443j-grxv-2pgv.json create mode 100644 advisories/unreviewed/2024/10/GHSA-4vmx-gm8x-gpjr/GHSA-4vmx-gm8x-gpjr.json create mode 100644 advisories/unreviewed/2024/10/GHSA-587p-xc7x-rjh8/GHSA-587p-xc7x-rjh8.json create mode 100644 advisories/unreviewed/2024/10/GHSA-5f4q-95cp-q722/GHSA-5f4q-95cp-q722.json create mode 100644 advisories/unreviewed/2024/10/GHSA-5g3x-vvf6-gwg2/GHSA-5g3x-vvf6-gwg2.json create mode 100644 advisories/unreviewed/2024/10/GHSA-72c9-vcqr-cxj8/GHSA-72c9-vcqr-cxj8.json create mode 100644 advisories/unreviewed/2024/10/GHSA-7p24-phjr-m5fc/GHSA-7p24-phjr-m5fc.json create mode 100644 advisories/unreviewed/2024/10/GHSA-8h7j-q956-7h6g/GHSA-8h7j-q956-7h6g.json create mode 100644 advisories/unreviewed/2024/10/GHSA-8ppq-7m96-536p/GHSA-8ppq-7m96-536p.json create mode 100644 advisories/unreviewed/2024/10/GHSA-f98v-q2j5-v4qc/GHSA-f98v-q2j5-v4qc.json create mode 100644 advisories/unreviewed/2024/10/GHSA-fj8g-7f3j-g879/GHSA-fj8g-7f3j-g879.json create mode 100644 advisories/unreviewed/2024/10/GHSA-fqcp-xv9m-hcq2/GHSA-fqcp-xv9m-hcq2.json create mode 100644 advisories/unreviewed/2024/10/GHSA-j6xh-hx47-7x23/GHSA-j6xh-hx47-7x23.json create mode 100644 advisories/unreviewed/2024/10/GHSA-j9m2-gxgg-6g4q/GHSA-j9m2-gxgg-6g4q.json create mode 100644 advisories/unreviewed/2024/10/GHSA-m8vr-gvfq-cv5f/GHSA-m8vr-gvfq-cv5f.json create mode 100644 advisories/unreviewed/2024/10/GHSA-p26r-gfgc-c47h/GHSA-p26r-gfgc-c47h.json create mode 100644 advisories/unreviewed/2024/10/GHSA-p7rw-j46f-fvpg/GHSA-p7rw-j46f-fvpg.json create mode 100644 advisories/unreviewed/2024/10/GHSA-p8rh-8mh7-w4xh/GHSA-p8rh-8mh7-w4xh.json create mode 100644 advisories/unreviewed/2024/10/GHSA-ppxj-8w78-35rf/GHSA-ppxj-8w78-35rf.json create mode 100644 advisories/unreviewed/2024/10/GHSA-q3q7-5v7p-vvhh/GHSA-q3q7-5v7p-vvhh.json create mode 100644 advisories/unreviewed/2024/10/GHSA-qg2h-xcfx-85gx/GHSA-qg2h-xcfx-85gx.json create mode 100644 advisories/unreviewed/2024/10/GHSA-r7cm-7xjc-5g35/GHSA-r7cm-7xjc-5g35.json create mode 100644 advisories/unreviewed/2024/10/GHSA-rg9v-8hp2-6q4g/GHSA-rg9v-8hp2-6q4g.json create mode 100644 advisories/unreviewed/2024/10/GHSA-v8xh-475x-4q58/GHSA-v8xh-475x-4q58.json create mode 100644 advisories/unreviewed/2024/10/GHSA-wf7c-j44x-2379/GHSA-wf7c-j44x-2379.json create mode 100644 advisories/unreviewed/2024/10/GHSA-x25g-7892-q6v6/GHSA-x25g-7892-q6v6.json diff --git a/advisories/unreviewed/2024/10/GHSA-3jr7-qfmv-8m22/GHSA-3jr7-qfmv-8m22.json b/advisories/unreviewed/2024/10/GHSA-3jr7-qfmv-8m22/GHSA-3jr7-qfmv-8m22.json new file mode 100644 index 00000000000..9e89d364344 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3jr7-qfmv-8m22/GHSA-3jr7-qfmv-8m22.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jr7-qfmv-8m22", + "modified": "2024-10-14T18:30:26Z", + "published": "2024-10-14T18:30:26Z", + "aliases": [ + "CVE-2024-48798" + ], + "details": "An issue in Hubble Connected (com.hubbleconnected.vervelife) 2.00.81 allows a remote attacker to obtain sensitive information via the firmware update process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48798" + }, + { + "type": "WEB", + "url": "https://github.com/HankJames/Vul-Reports/blob/main/FirmwareLeakage/com.hubbleconnected.vervelife/com.hubbleconnected.vervelife.md" + }, + { + "type": "WEB", + "url": "https://hubbleconnected.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3pc3-p9j7-xvq6/GHSA-3pc3-p9j7-xvq6.json b/advisories/unreviewed/2024/10/GHSA-3pc3-p9j7-xvq6/GHSA-3pc3-p9j7-xvq6.json new file mode 100644 index 00000000000..9c8933da40b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3pc3-p9j7-xvq6/GHSA-3pc3-p9j7-xvq6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3pc3-p9j7-xvq6", + "modified": "2024-10-14T18:30:25Z", + "published": "2024-10-14T18:30:25Z", + "aliases": [ + "CVE-2024-45737" + ], + "details": "In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108, and 9.1.2312.204, a low-privileged user that does not hold the \"admin\" or \"power\" Splunk roles could change the maintenance mode state of App Key Value Store (KVStore) through a Cross-Site Request Forgery (CSRF).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45737" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2024-1007" + }, + { + "type": "WEB", + "url": "https://research.splunk.com/application/34bac267-a89b-4bd7-a072-a48eef1f15b8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-443j-grxv-2pgv/GHSA-443j-grxv-2pgv.json b/advisories/unreviewed/2024/10/GHSA-443j-grxv-2pgv/GHSA-443j-grxv-2pgv.json new file mode 100644 index 00000000000..851ad109df2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-443j-grxv-2pgv/GHSA-443j-grxv-2pgv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-443j-grxv-2pgv", + "modified": "2024-10-14T18:30:25Z", + "published": "2024-10-14T18:30:25Z", + "aliases": [ + "CVE-2023-50780" + ], + "details": "Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia endpoint. Before version 2.29.0, this also included the Log4J2 MBean. This MBean is not meant for exposure to non-administrative users. This could eventually allow an authenticated attacker to write arbitrary files to the filesystem and indirectly achieve RCE.\n\n\nUsers are recommended to upgrade to version 2.29.0 or later, which fixes the issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50780" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/63b78shqz312phsx7v1ryr7jv7bprg58" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T16:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-4vmx-gm8x-gpjr/GHSA-4vmx-gm8x-gpjr.json b/advisories/unreviewed/2024/10/GHSA-4vmx-gm8x-gpjr/GHSA-4vmx-gm8x-gpjr.json new file mode 100644 index 00000000000..451d04f3edf --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-4vmx-gm8x-gpjr/GHSA-4vmx-gm8x-gpjr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vmx-gm8x-gpjr", + "modified": "2024-10-14T18:30:25Z", + "published": "2024-10-14T18:30:25Z", + "aliases": [ + "CVE-2024-45740" + ], + "details": "In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403, a low-privileged user that does not hold the \"admin\" or \"power\" Splunk roles could craft a malicious payload through Scheduled Views that could result in execution of unauthorized JavaScript code in the browser of a user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45740" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2024-1010" + }, + { + "type": "WEB", + "url": "https://research.splunk.com/application/d4f55f7c-6518-4122-a197-951fe0f21b25" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-587p-xc7x-rjh8/GHSA-587p-xc7x-rjh8.json b/advisories/unreviewed/2024/10/GHSA-587p-xc7x-rjh8/GHSA-587p-xc7x-rjh8.json new file mode 100644 index 00000000000..802df133bd2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-587p-xc7x-rjh8/GHSA-587p-xc7x-rjh8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-587p-xc7x-rjh8", + "modified": "2024-10-14T18:30:25Z", + "published": "2024-10-14T18:30:25Z", + "aliases": [ + "CVE-2024-45738" + ], + "details": "In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes sensitive HTTP parameters to the `_internal` index. This exposure could happen if you configure the Splunk Enterprise `REST_Calls` log channel at the DEBUG logging level.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45738" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2024-1008" + }, + { + "type": "WEB", + "url": "https://research.splunk.com/application/93dc7182-c5da-4085-82ec-401abf33d623" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5f4q-95cp-q722/GHSA-5f4q-95cp-q722.json b/advisories/unreviewed/2024/10/GHSA-5f4q-95cp-q722/GHSA-5f4q-95cp-q722.json new file mode 100644 index 00000000000..217b93955c7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5f4q-95cp-q722/GHSA-5f4q-95cp-q722.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5f4q-95cp-q722", + "modified": "2024-10-14T18:30:25Z", + "published": "2024-10-14T18:30:25Z", + "aliases": [ + "CVE-2024-45735" + ], + "details": "In Splunk Enterprise versions below 9.2.3 and 9.1.6, and Splunk Secure Gateway versions on Splunk Cloud Platform versions below 3.4.259, 3.6.17, and 3.7.0, a low-privileged user that does not hold the \"admin\" or \"power\" Splunk roles can see App Key Value Store (KV Store) deployment configuration and public/private keys in the Splunk Secure Gateway App.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45735" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2024-1005" + }, + { + "type": "WEB", + "url": "https://research.splunk.com/application/0a3d6035-7bef-4dfa-b01e-84349edac3b4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5g3x-vvf6-gwg2/GHSA-5g3x-vvf6-gwg2.json b/advisories/unreviewed/2024/10/GHSA-5g3x-vvf6-gwg2/GHSA-5g3x-vvf6-gwg2.json new file mode 100644 index 00000000000..c6c2757ce42 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5g3x-vvf6-gwg2/GHSA-5g3x-vvf6-gwg2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g3x-vvf6-gwg2", + "modified": "2024-10-14T18:30:25Z", + "published": "2024-10-14T18:30:25Z", + "aliases": [ + "CVE-2024-48150" + ], + "details": "D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_451208 function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48150" + }, + { + "type": "WEB", + "url": "https://github.com/fu37kola/cve/blob/main/D-Link/DIR-820L/D-Link%20DIR-820L%20Stack%20Overflow%20Vulnerability.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T16:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-72c9-vcqr-cxj8/GHSA-72c9-vcqr-cxj8.json b/advisories/unreviewed/2024/10/GHSA-72c9-vcqr-cxj8/GHSA-72c9-vcqr-cxj8.json new file mode 100644 index 00000000000..0e085f375de --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-72c9-vcqr-cxj8/GHSA-72c9-vcqr-cxj8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-72c9-vcqr-cxj8", + "modified": "2024-10-14T18:30:26Z", + "published": "2024-10-14T18:30:26Z", + "aliases": [ + "CVE-2024-48797" + ], + "details": "An issue in PCS Engineering Preston Cinema (com.prestoncinema.app) 0.2.0 allows a remote attacker to obtain sensitive information via the firmware update process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48797" + }, + { + "type": "WEB", + "url": "https://github.com/HankJames/Vul-Reports/blob/main/FirmwareLeakage/com.prestoncinema.app/com.prestoncinema.app.md" + }, + { + "type": "WEB", + "url": "http://www.pcsengineering.net" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7p24-phjr-m5fc/GHSA-7p24-phjr-m5fc.json b/advisories/unreviewed/2024/10/GHSA-7p24-phjr-m5fc/GHSA-7p24-phjr-m5fc.json new file mode 100644 index 00000000000..b0858cf70a2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7p24-phjr-m5fc/GHSA-7p24-phjr-m5fc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7p24-phjr-m5fc", + "modified": "2024-10-14T18:30:25Z", + "published": "2024-10-14T18:30:25Z", + "aliases": [ + "CVE-2024-45732" + ], + "details": "In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions below 9.2.3, and Splunk Cloud Platform versions below 9.2.2403.103, 9.1.2312.200, 9.1.2312.110 and 9.1.2308.208, a low-privileged user that does not hold the \"admin\" or \"power\" Splunk roles could run a search as the \"nobody\" Splunk user in the SplunkDeploymentServerConfig app. This could let the low-privileged user access potentially restricted data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45732" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2024-1002" + }, + { + "type": "WEB", + "url": "https://research.splunk.com/application/f765c3fe-c3b6-4afe-a932-11dd4f3a024f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8h7j-q956-7h6g/GHSA-8h7j-q956-7h6g.json b/advisories/unreviewed/2024/10/GHSA-8h7j-q956-7h6g/GHSA-8h7j-q956-7h6g.json new file mode 100644 index 00000000000..b00b6352d5f --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8h7j-q956-7h6g/GHSA-8h7j-q956-7h6g.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8h7j-q956-7h6g", + "modified": "2024-10-14T18:30:26Z", + "published": "2024-10-14T18:30:26Z", + "aliases": [ + "CVE-2024-48793" + ], + "details": "An issue in INATRONIC com.inatronic.bmw 2.7.1 allows a remote attacker to obtain sensitive information via the firmware update process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48793" + }, + { + "type": "WEB", + "url": "https://drivedeck.de" + }, + { + "type": "WEB", + "url": "https://github.com/HankJames/Vul-Reports/blob/main/FirmwareLeakage/com.inatronic.bmw/com.inatronic.bmw.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8ppq-7m96-536p/GHSA-8ppq-7m96-536p.json b/advisories/unreviewed/2024/10/GHSA-8ppq-7m96-536p/GHSA-8ppq-7m96-536p.json new file mode 100644 index 00000000000..c2133acedeb --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8ppq-7m96-536p/GHSA-8ppq-7m96-536p.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8ppq-7m96-536p", + "modified": "2024-10-14T18:30:26Z", + "published": "2024-10-14T18:30:26Z", + "aliases": [ + "CVE-2024-48799" + ], + "details": "An issue in LOREX TECHNOLOGY INC com.lorexcorp.lorexping 1.4.22 allows a remote attacker to obtain sensitive information via the firmware update process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48799" + }, + { + "type": "WEB", + "url": "https://github.com/HankJames/Vul-Reports/blob/main/FirmwareLeakage/com.lorexcorp.lorexping/com.lorexcorp.lorexping.md" + }, + { + "type": "WEB", + "url": "https://www.lorex.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-f98v-q2j5-v4qc/GHSA-f98v-q2j5-v4qc.json b/advisories/unreviewed/2024/10/GHSA-f98v-q2j5-v4qc/GHSA-f98v-q2j5-v4qc.json new file mode 100644 index 00000000000..e1b669aa981 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-f98v-q2j5-v4qc/GHSA-f98v-q2j5-v4qc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f98v-q2j5-v4qc", + "modified": "2024-10-14T18:30:25Z", + "published": "2024-10-14T18:30:25Z", + "aliases": [ + "CVE-2024-45733" + ], + "details": "In Splunk Enterprise for Windows versions below 9.2.3 and 9.1.6, a low-privileged user that does not hold the \"admin\" or \"power\" Splunk roles could perform a Remote Code Execution (RCE) due to an insecure session storage configuration.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45733" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2024-1003" + }, + { + "type": "WEB", + "url": "https://research.splunk.com/application/c97e0704-d9c6-454d-89ba-1510a987bf72" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-fj8g-7f3j-g879/GHSA-fj8g-7f3j-g879.json b/advisories/unreviewed/2024/10/GHSA-fj8g-7f3j-g879/GHSA-fj8g-7f3j-g879.json new file mode 100644 index 00000000000..f1611816892 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-fj8g-7f3j-g879/GHSA-fj8g-7f3j-g879.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fj8g-7f3j-g879", + "modified": "2024-10-14T18:30:26Z", + "published": "2024-10-14T18:30:26Z", + "aliases": [ + "CVE-2024-48791" + ], + "details": "An issue in Plug n Play Camera com.starvedia.mCamView.zwave 5.5.1 allows a remote attacker to obtain sensitive information via the firmware update process", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48791" + }, + { + "type": "WEB", + "url": "https://github.com/HankJames/Vul-Reports/blob/main/FirmwareLeakage/com.starvedia.mCamView.zwave/com.starvedia.mCamView.zwave.md" + }, + { + "type": "WEB", + "url": "http://www.starvedia.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-fqcp-xv9m-hcq2/GHSA-fqcp-xv9m-hcq2.json b/advisories/unreviewed/2024/10/GHSA-fqcp-xv9m-hcq2/GHSA-fqcp-xv9m-hcq2.json new file mode 100644 index 00000000000..bdc7fe8ce65 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-fqcp-xv9m-hcq2/GHSA-fqcp-xv9m-hcq2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqcp-xv9m-hcq2", + "modified": "2024-10-14T18:30:26Z", + "published": "2024-10-14T18:30:26Z", + "aliases": [ + "CVE-2024-46535" + ], + "details": "Jepaas v7.2.8 was discovered to contain a SQL injection vulnerability via the orderSQL parameter at /homePortal/loadUserMsg.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46535" + }, + { + "type": "WEB", + "url": "https://gitee.com/ketr/jepaas-release/issues/IAPJ8H?from=project-issue" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-j6xh-hx47-7x23/GHSA-j6xh-hx47-7x23.json b/advisories/unreviewed/2024/10/GHSA-j6xh-hx47-7x23/GHSA-j6xh-hx47-7x23.json new file mode 100644 index 00000000000..ea6303d4cbd --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-j6xh-hx47-7x23/GHSA-j6xh-hx47-7x23.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6xh-hx47-7x23", + "modified": "2024-10-14T18:30:25Z", + "published": "2024-10-14T18:30:25Z", + "aliases": [ + "CVE-2024-45731" + ], + "details": "In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-privileged user that does not hold the \"admin\" or \"power\" Splunk roles could write a file to the Windows system root directory, which has a default location in the Windows System32 folder, when Splunk Enterprise for Windows is installed on a separate drive.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45731" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2024-1001" + }, + { + "type": "WEB", + "url": "https://research.splunk.com/application/c97e0704-d9c6-454d-89ba-1510a987bf72" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-j9m2-gxgg-6g4q/GHSA-j9m2-gxgg-6g4q.json b/advisories/unreviewed/2024/10/GHSA-j9m2-gxgg-6g4q/GHSA-j9m2-gxgg-6g4q.json new file mode 100644 index 00000000000..ea8494c9570 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-j9m2-gxgg-6g4q/GHSA-j9m2-gxgg-6g4q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9m2-gxgg-6g4q", + "modified": "2024-10-14T18:30:26Z", + "published": "2024-10-14T18:30:26Z", + "aliases": [ + "CVE-2024-48796" + ], + "details": "An issue in EQUES com.eques.plug 1.0.1 allows a remote attacker to obtain sensitive information via the firmware update process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48796" + }, + { + "type": "WEB", + "url": "https://github.com/HankJames/Vul-Reports/blob/main/FirmwareLeakage/com.eques.plug/com.eques.plug.md" + }, + { + "type": "WEB", + "url": "http://www.eques.cn/?lang=en" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m8vr-gvfq-cv5f/GHSA-m8vr-gvfq-cv5f.json b/advisories/unreviewed/2024/10/GHSA-m8vr-gvfq-cv5f/GHSA-m8vr-gvfq-cv5f.json new file mode 100644 index 00000000000..eb1ffcef7a8 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m8vr-gvfq-cv5f/GHSA-m8vr-gvfq-cv5f.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m8vr-gvfq-cv5f", + "modified": "2024-10-14T18:30:26Z", + "published": "2024-10-14T18:30:26Z", + "aliases": [ + "CVE-2024-48789" + ], + "details": "An issue in INATRONIC com.inatronic.drivedeck.home 2.6.23 allows a remote attacker to obtain sensitve information via the firmware update process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48789" + }, + { + "type": "WEB", + "url": "https://drivedeck.de" + }, + { + "type": "WEB", + "url": "https://github.com/HankJames/Vul-Reports/blob/main/FirmwareLeakage/com.inatronic.drivedeck.home/com.inatronic.drivedeck.home.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-p26r-gfgc-c47h/GHSA-p26r-gfgc-c47h.json b/advisories/unreviewed/2024/10/GHSA-p26r-gfgc-c47h/GHSA-p26r-gfgc-c47h.json new file mode 100644 index 00000000000..1eddda4b945 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-p26r-gfgc-c47h/GHSA-p26r-gfgc-c47h.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p26r-gfgc-c47h", + "modified": "2024-10-14T18:30:26Z", + "published": "2024-10-14T18:30:26Z", + "aliases": [ + "CVE-2024-46528" + ], + "details": "An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere v3.4.1 and v4.1.1 allows low-privileged authenticated attackers to access sensitive resources without proper authorization checks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46528" + }, + { + "type": "WEB", + "url": "https://okankurtulus.com.tr/2024/09/09/idor-vulnerability-in-kubesphere" + }, + { + "type": "WEB", + "url": "http://kubesphere.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T18:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-p7rw-j46f-fvpg/GHSA-p7rw-j46f-fvpg.json b/advisories/unreviewed/2024/10/GHSA-p7rw-j46f-fvpg/GHSA-p7rw-j46f-fvpg.json new file mode 100644 index 00000000000..5c6731add2c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-p7rw-j46f-fvpg/GHSA-p7rw-j46f-fvpg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7rw-j46f-fvpg", + "modified": "2024-10-14T18:30:25Z", + "published": "2024-10-14T18:30:25Z", + "aliases": [ + "CVE-2024-48153" + ], + "details": "DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_subconfig function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48153" + }, + { + "type": "WEB", + "url": "https://github.com/tw11ty/CVE/blob/main/DrayTek/Vigor3900/Vigor3900%20command%20execution%20vulnerability.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T16:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-p8rh-8mh7-w4xh/GHSA-p8rh-8mh7-w4xh.json b/advisories/unreviewed/2024/10/GHSA-p8rh-8mh7-w4xh/GHSA-p8rh-8mh7-w4xh.json new file mode 100644 index 00000000000..81551526607 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-p8rh-8mh7-w4xh/GHSA-p8rh-8mh7-w4xh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8rh-8mh7-w4xh", + "modified": "2024-10-14T18:30:25Z", + "published": "2024-10-14T18:30:25Z", + "aliases": [ + "CVE-2024-45739" + ], + "details": "In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes plaintext passwords for local native authentication Splunk users. This exposure could happen when you configure the Splunk Enterprise AdminManager log channel at the DEBUG logging level.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45739" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2024-1009" + }, + { + "type": "WEB", + "url": "https://research.splunk.com/application/93dc7182-c5da-4085-82ec-401abf33d623" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-ppxj-8w78-35rf/GHSA-ppxj-8w78-35rf.json b/advisories/unreviewed/2024/10/GHSA-ppxj-8w78-35rf/GHSA-ppxj-8w78-35rf.json new file mode 100644 index 00000000000..4a2d646a6c7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-ppxj-8w78-35rf/GHSA-ppxj-8w78-35rf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ppxj-8w78-35rf", + "modified": "2024-10-14T18:30:26Z", + "published": "2024-10-14T18:30:26Z", + "aliases": [ + "CVE-2024-48795" + ], + "details": "An issue in Creative Labs Pte Ltd com.creative.apps.xficonnect 2.00.02 allows a remote attacker to obtain sensitive information via the firmware update process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48795" + }, + { + "type": "WEB", + "url": "https://github.com/HankJames/Vul-Reports/blob/main/FirmwareLeakage/com.creative.apps.xficonnect/com.creative.apps.xficonnect.md" + }, + { + "type": "WEB", + "url": "https://hk.creative.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-q3q7-5v7p-vvhh/GHSA-q3q7-5v7p-vvhh.json b/advisories/unreviewed/2024/10/GHSA-q3q7-5v7p-vvhh/GHSA-q3q7-5v7p-vvhh.json new file mode 100644 index 00000000000..1b1c2841e97 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-q3q7-5v7p-vvhh/GHSA-q3q7-5v7p-vvhh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3q7-5v7p-vvhh", + "modified": "2024-10-14T18:30:25Z", + "published": "2024-10-14T18:30:25Z", + "aliases": [ + "CVE-2024-45734" + ], + "details": "In Splunk Enterprise versions 9.3.0, 9.2.3, and 9.1.6, a low-privileged user that does not hold the \"admin\" or \"power\" Splunk roles could view images on the machine that runs Splunk Enterprise by using the PDF export feature in Splunk classic dashboards. The images on the machine could be exposed by exporting the dashboard as a PDF, using the local image path in the img tag in the source extensible markup language (XML) code for the Splunk classic dashboard.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45734" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2024-1004" + }, + { + "type": "WEB", + "url": "https://research.splunk.com/application/7464e2dc-98a5-4af9-87a1-fa6d5a256fa6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qg2h-xcfx-85gx/GHSA-qg2h-xcfx-85gx.json b/advisories/unreviewed/2024/10/GHSA-qg2h-xcfx-85gx/GHSA-qg2h-xcfx-85gx.json new file mode 100644 index 00000000000..22ed1cafe15 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qg2h-xcfx-85gx/GHSA-qg2h-xcfx-85gx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qg2h-xcfx-85gx", + "modified": "2024-10-14T18:30:26Z", + "published": "2024-10-14T18:30:26Z", + "aliases": [ + "CVE-2024-48168" + ], + "details": "A stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link DCS-960L 1.09, allowing an attacker to execute arbitrary code.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48168" + }, + { + "type": "WEB", + "url": "https://github.com/fu37kola/cve/blob/main/D-Link/DCS-960L/D-Link%20DCS-960L%201.09%20Stack%20overflow_1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-r7cm-7xjc-5g35/GHSA-r7cm-7xjc-5g35.json b/advisories/unreviewed/2024/10/GHSA-r7cm-7xjc-5g35/GHSA-r7cm-7xjc-5g35.json new file mode 100644 index 00000000000..3ab150ab6b9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-r7cm-7xjc-5g35/GHSA-r7cm-7xjc-5g35.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7cm-7xjc-5g35", + "modified": "2024-10-14T18:30:26Z", + "published": "2024-10-14T18:30:26Z", + "aliases": [ + "CVE-2024-48790" + ], + "details": "An issue in ILIFE com.ilife.home.global 1.8.7 allows a remote attacker to obtain sensitive information via the firmware update process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48790" + }, + { + "type": "WEB", + "url": "https://github.com/HankJames/Vul-Reports/blob/main/FirmwareLeakage/com.ilife.home.global/com.ilife.home.global.md" + }, + { + "type": "WEB", + "url": "https://www.iliferobot.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-rg9v-8hp2-6q4g/GHSA-rg9v-8hp2-6q4g.json b/advisories/unreviewed/2024/10/GHSA-rg9v-8hp2-6q4g/GHSA-rg9v-8hp2-6q4g.json new file mode 100644 index 00000000000..90fd4501008 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rg9v-8hp2-6q4g/GHSA-rg9v-8hp2-6q4g.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rg9v-8hp2-6q4g", + "modified": "2024-10-14T18:30:26Z", + "published": "2024-10-14T18:30:26Z", + "aliases": [ + "CVE-2024-48792" + ], + "details": "An issue in Hideez com.hideez 2.7.8.3 allows a remote attacker to obtain sensitive information via the firmware update process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48792" + }, + { + "type": "WEB", + "url": "https://github.com/HankJames/Vul-Reports/blob/main/FirmwareLeakage/com.hideez/com.hideez.md" + }, + { + "type": "WEB", + "url": "https://hideez.com/en-int" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-v8xh-475x-4q58/GHSA-v8xh-475x-4q58.json b/advisories/unreviewed/2024/10/GHSA-v8xh-475x-4q58/GHSA-v8xh-475x-4q58.json new file mode 100644 index 00000000000..e3e30e863ba --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-v8xh-475x-4q58/GHSA-v8xh-475x-4q58.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8xh-475x-4q58", + "modified": "2024-10-14T18:30:26Z", + "published": "2024-10-14T18:30:26Z", + "aliases": [ + "CVE-2024-45741" + ], + "details": "In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108 and 9.1.2312.205, a low-privileged user that does not hold the \"admin\" or \"power\" Splunk roles could create a malicious payload through a custom configuration file that the \"api.uri\" parameter from the \"/manager/search/apps/local\" endpoint in Splunk Web calls. This could result in execution of unauthorized JavaScript code in the browser of a user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45741" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2024-1011" + }, + { + "type": "WEB", + "url": "https://research.splunk.com/application/d7b5aa71-157f-4359-9c34-e35752b1d0a2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-wf7c-j44x-2379/GHSA-wf7c-j44x-2379.json b/advisories/unreviewed/2024/10/GHSA-wf7c-j44x-2379/GHSA-wf7c-j44x-2379.json new file mode 100644 index 00000000000..a3afb57d797 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-wf7c-j44x-2379/GHSA-wf7c-j44x-2379.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wf7c-j44x-2379", + "modified": "2024-10-14T18:30:25Z", + "published": "2024-10-14T18:30:25Z", + "aliases": [ + "CVE-2024-45736" + ], + "details": "In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.107, 9.1.2312.204, and 9.1.2312.111, a low-privileged user that does not hold the \"admin\" or \"power\" Splunk roles could craft a search query with an improperly formatted \"INGEST_EVAL\" parameter as part of a [Field Transformation](https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Managefieldtransforms) which could crash the Splunk daemon (splunkd).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45736" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2024-1006" + }, + { + "type": "WEB", + "url": "https://research.splunk.com/application/08978eca-caff-44c1-84dc-53f17def4e14" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-x25g-7892-q6v6/GHSA-x25g-7892-q6v6.json b/advisories/unreviewed/2024/10/GHSA-x25g-7892-q6v6/GHSA-x25g-7892-q6v6.json new file mode 100644 index 00000000000..458ee882012 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-x25g-7892-q6v6/GHSA-x25g-7892-q6v6.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x25g-7892-q6v6", + "modified": "2024-10-14T18:30:25Z", + "published": "2024-10-14T18:30:25Z", + "aliases": [ + "CVE-2024-41997" + ], + "details": "An issue was discovered in version of Warp Terminal prior to 2024.07.18 (v0.2024.07.16.08.02). A command injection vulnerability exists in the Docker integration functionality. An attacker can create a specially crafted hyperlink using the `warp://action/docker/open_subshell` intent that when clicked by the victim results in command execution on the victim's machine.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41997" + }, + { + "type": "WEB", + "url": "https://docs.warp.dev/features/integrations-and-plugins#docker" + }, + { + "type": "WEB", + "url": "https://docs.warp.dev/getting-started/changelog#id-2024.07.18-v0.2024.07.16.08.02" + }, + { + "type": "WEB", + "url": "https://gist.github.com/bhyh/d1ee7a825fce283bf8acbdb42c8a7832" + }, + { + "type": "WEB", + "url": "https://github.com/warpdotdev/warp" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-14T16:15:03Z" + } +} \ No newline at end of file