From 2033ebc777bb5a16568cc555ee13b8ea41e00b14 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 20 Feb 2024 15:32:22 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-4m6w-vxqg-9rmm.json | 10 +++- .../GHSA-jr4h-682w-x2ph.json | 10 +++- .../GHSA-qmff-49xc-7rf6.json | 10 +++- .../GHSA-29xx-fhff-36m7.json | 38 +++++++++++++++ .../GHSA-2mvj-q2q3-wxjv.json | 38 +++++++++++++++ .../GHSA-36xr-4x2f-cfj9.json | 35 ++++++++++++++ .../GHSA-372x-c6rw-v8f9.json | 43 +++++++++++++++++ .../GHSA-37gx-jqx9-fwmg.json | 6 ++- .../GHSA-3hwp-p2jw-j4xh.json | 38 +++++++++++++++ .../GHSA-43mr-mm46-m2qq.json | 42 +++++++++++++++++ .../GHSA-4mgv-g5j9-fr8q.json | 42 +++++++++++++++++ .../GHSA-625h-2cj8-8g77.json | 39 +++++++++++++++ .../GHSA-62vc-2f72-vcj3.json | 43 +++++++++++++++++ .../GHSA-7v7g-38mv-3237.json | 42 +++++++++++++++++ .../GHSA-8q5j-74vg-j4hr.json | 43 +++++++++++++++++ .../GHSA-92f7-c7hw-58cr.json | 47 +++++++++++++++++++ .../GHSA-98fx-x879-qp6f.json | 10 +++- .../GHSA-9m3j-vpcw-4f37.json | 43 +++++++++++++++++ .../GHSA-c2qq-2j48-5pr5.json | 38 +++++++++++++++ .../GHSA-ccq4-9qhm-55xx.json | 38 +++++++++++++++ .../GHSA-cmph-x6r4-4whr.json | 39 +++++++++++++++ .../GHSA-cq85-4f5h-qqc4.json | 43 +++++++++++++++++ .../GHSA-ff2w-wm48-jhqj.json | 6 ++- .../GHSA-g24h-xx4p-jc7j.json | 43 +++++++++++++++++ .../GHSA-gqrh-wgmr-mm7v.json | 39 +++++++++++++++ .../GHSA-hmqj-rccj-3q53.json | 43 +++++++++++++++++ .../GHSA-j494-r8wx-qpjr.json | 42 +++++++++++++++++ .../GHSA-j6qq-7xp7-c5p5.json | 39 +++++++++++++++ .../GHSA-m43p-55rf-8c2j.json | 35 ++++++++++++++ .../GHSA-mf2m-vhfh-2qjv.json | 43 +++++++++++++++++ .../GHSA-qm43-g2xj-hvg5.json | 38 +++++++++++++++ .../GHSA-qwxx-xww6-8q8m.json | 6 ++- .../GHSA-r3h6-h7mc-hvh5.json | 47 +++++++++++++++++++ .../GHSA-rmqp-82v9-w7q3.json | 43 +++++++++++++++++ .../GHSA-rmwg-qccm-r36q.json | 35 ++++++++++++++ .../GHSA-v3xc-v2g4-h75g.json | 46 ++++++++++++++++++ .../GHSA-v8xr-j3gp-fmxj.json | 10 +++- .../GHSA-vjqc-g788-f378.json | 6 ++- .../GHSA-vvpf-53qx-cxhh.json | 38 +++++++++++++++ .../GHSA-vw87-wrx2-xwxq.json | 42 +++++++++++++++++ .../GHSA-w267-2gcr-ggcp.json | 43 +++++++++++++++++ .../GHSA-wp8h-p32h-fwvc.json | 39 +++++++++++++++ .../GHSA-xq4r-4xfh-vch8.json | 38 +++++++++++++++ .../GHSA-xv5g-jfvh-hgph.json | 43 +++++++++++++++++ .../GHSA-xw3g-x45j-xxhh.json | 10 +++- 45 files changed, 1501 insertions(+), 10 deletions(-) create mode 100644 advisories/unreviewed/2024/02/GHSA-29xx-fhff-36m7/GHSA-29xx-fhff-36m7.json create mode 100644 advisories/unreviewed/2024/02/GHSA-2mvj-q2q3-wxjv/GHSA-2mvj-q2q3-wxjv.json create mode 100644 advisories/unreviewed/2024/02/GHSA-36xr-4x2f-cfj9/GHSA-36xr-4x2f-cfj9.json create mode 100644 advisories/unreviewed/2024/02/GHSA-372x-c6rw-v8f9/GHSA-372x-c6rw-v8f9.json create mode 100644 advisories/unreviewed/2024/02/GHSA-3hwp-p2jw-j4xh/GHSA-3hwp-p2jw-j4xh.json create mode 100644 advisories/unreviewed/2024/02/GHSA-43mr-mm46-m2qq/GHSA-43mr-mm46-m2qq.json create mode 100644 advisories/unreviewed/2024/02/GHSA-4mgv-g5j9-fr8q/GHSA-4mgv-g5j9-fr8q.json create mode 100644 advisories/unreviewed/2024/02/GHSA-625h-2cj8-8g77/GHSA-625h-2cj8-8g77.json create mode 100644 advisories/unreviewed/2024/02/GHSA-62vc-2f72-vcj3/GHSA-62vc-2f72-vcj3.json create mode 100644 advisories/unreviewed/2024/02/GHSA-7v7g-38mv-3237/GHSA-7v7g-38mv-3237.json create mode 100644 advisories/unreviewed/2024/02/GHSA-8q5j-74vg-j4hr/GHSA-8q5j-74vg-j4hr.json create mode 100644 advisories/unreviewed/2024/02/GHSA-92f7-c7hw-58cr/GHSA-92f7-c7hw-58cr.json create mode 100644 advisories/unreviewed/2024/02/GHSA-9m3j-vpcw-4f37/GHSA-9m3j-vpcw-4f37.json create mode 100644 advisories/unreviewed/2024/02/GHSA-c2qq-2j48-5pr5/GHSA-c2qq-2j48-5pr5.json create mode 100644 advisories/unreviewed/2024/02/GHSA-ccq4-9qhm-55xx/GHSA-ccq4-9qhm-55xx.json create mode 100644 advisories/unreviewed/2024/02/GHSA-cmph-x6r4-4whr/GHSA-cmph-x6r4-4whr.json create mode 100644 advisories/unreviewed/2024/02/GHSA-cq85-4f5h-qqc4/GHSA-cq85-4f5h-qqc4.json create mode 100644 advisories/unreviewed/2024/02/GHSA-g24h-xx4p-jc7j/GHSA-g24h-xx4p-jc7j.json create mode 100644 advisories/unreviewed/2024/02/GHSA-gqrh-wgmr-mm7v/GHSA-gqrh-wgmr-mm7v.json create mode 100644 advisories/unreviewed/2024/02/GHSA-hmqj-rccj-3q53/GHSA-hmqj-rccj-3q53.json create mode 100644 advisories/unreviewed/2024/02/GHSA-j494-r8wx-qpjr/GHSA-j494-r8wx-qpjr.json create mode 100644 advisories/unreviewed/2024/02/GHSA-j6qq-7xp7-c5p5/GHSA-j6qq-7xp7-c5p5.json create mode 100644 advisories/unreviewed/2024/02/GHSA-m43p-55rf-8c2j/GHSA-m43p-55rf-8c2j.json create mode 100644 advisories/unreviewed/2024/02/GHSA-mf2m-vhfh-2qjv/GHSA-mf2m-vhfh-2qjv.json create mode 100644 advisories/unreviewed/2024/02/GHSA-qm43-g2xj-hvg5/GHSA-qm43-g2xj-hvg5.json create mode 100644 advisories/unreviewed/2024/02/GHSA-r3h6-h7mc-hvh5/GHSA-r3h6-h7mc-hvh5.json create mode 100644 advisories/unreviewed/2024/02/GHSA-rmqp-82v9-w7q3/GHSA-rmqp-82v9-w7q3.json create mode 100644 advisories/unreviewed/2024/02/GHSA-rmwg-qccm-r36q/GHSA-rmwg-qccm-r36q.json create mode 100644 advisories/unreviewed/2024/02/GHSA-v3xc-v2g4-h75g/GHSA-v3xc-v2g4-h75g.json create mode 100644 advisories/unreviewed/2024/02/GHSA-vvpf-53qx-cxhh/GHSA-vvpf-53qx-cxhh.json create mode 100644 advisories/unreviewed/2024/02/GHSA-vw87-wrx2-xwxq/GHSA-vw87-wrx2-xwxq.json create mode 100644 advisories/unreviewed/2024/02/GHSA-w267-2gcr-ggcp/GHSA-w267-2gcr-ggcp.json create mode 100644 advisories/unreviewed/2024/02/GHSA-wp8h-p32h-fwvc/GHSA-wp8h-p32h-fwvc.json create mode 100644 advisories/unreviewed/2024/02/GHSA-xq4r-4xfh-vch8/GHSA-xq4r-4xfh-vch8.json create mode 100644 advisories/unreviewed/2024/02/GHSA-xv5g-jfvh-hgph/GHSA-xv5g-jfvh-hgph.json diff --git a/advisories/unreviewed/2023/12/GHSA-4m6w-vxqg-9rmm/GHSA-4m6w-vxqg-9rmm.json b/advisories/unreviewed/2023/12/GHSA-4m6w-vxqg-9rmm/GHSA-4m6w-vxqg-9rmm.json index 85722bca059..000139a3fa3 100644 --- a/advisories/unreviewed/2023/12/GHSA-4m6w-vxqg-9rmm/GHSA-4m6w-vxqg-9rmm.json +++ b/advisories/unreviewed/2023/12/GHSA-4m6w-vxqg-9rmm/GHSA-4m6w-vxqg-9rmm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4m6w-vxqg-9rmm", - "modified": "2023-12-08T18:30:42Z", + "modified": "2024-02-20T15:31:02Z", "published": "2023-12-08T18:30:42Z", "aliases": [ "CVE-2023-6606" @@ -29,6 +29,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:0725" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0881" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0897" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-6606" diff --git a/advisories/unreviewed/2023/12/GHSA-jr4h-682w-x2ph/GHSA-jr4h-682w-x2ph.json b/advisories/unreviewed/2023/12/GHSA-jr4h-682w-x2ph/GHSA-jr4h-682w-x2ph.json index 5eb36c14348..9c8f8441a35 100644 --- a/advisories/unreviewed/2023/12/GHSA-jr4h-682w-x2ph/GHSA-jr4h-682w-x2ph.json +++ b/advisories/unreviewed/2023/12/GHSA-jr4h-682w-x2ph/GHSA-jr4h-682w-x2ph.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jr4h-682w-x2ph", - "modified": "2023-12-08T18:30:42Z", + "modified": "2024-02-20T15:31:02Z", "published": "2023-12-08T18:30:42Z", "aliases": [ "CVE-2023-6610" @@ -33,6 +33,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:0725" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0881" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0897" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-6610" diff --git a/advisories/unreviewed/2024/01/GHSA-qmff-49xc-7rf6/GHSA-qmff-49xc-7rf6.json b/advisories/unreviewed/2024/01/GHSA-qmff-49xc-7rf6/GHSA-qmff-49xc-7rf6.json index c6666a9dc4b..0d25d6be762 100644 --- a/advisories/unreviewed/2024/01/GHSA-qmff-49xc-7rf6/GHSA-qmff-49xc-7rf6.json +++ b/advisories/unreviewed/2024/01/GHSA-qmff-49xc-7rf6/GHSA-qmff-49xc-7rf6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qmff-49xc-7rf6", - "modified": "2024-02-20T09:30:30Z", + "modified": "2024-02-20T15:31:02Z", "published": "2024-01-17T18:31:36Z", "aliases": [ "CVE-2024-0646" @@ -45,6 +45,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:0876" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0881" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0897" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-0646" diff --git a/advisories/unreviewed/2024/02/GHSA-29xx-fhff-36m7/GHSA-29xx-fhff-36m7.json b/advisories/unreviewed/2024/02/GHSA-29xx-fhff-36m7/GHSA-29xx-fhff-36m7.json new file mode 100644 index 00000000000..8a84ee73297 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-29xx-fhff-36m7/GHSA-29xx-fhff-36m7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29xx-fhff-36m7", + "modified": "2024-02-20T15:31:03Z", + "published": "2024-02-20T15:31:03Z", + "aliases": [ + "CVE-2024-26265" + ], + "details": "The Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions relies on a request parameter to limit the size of files that can be uploaded, which allows remote authenticated users to upload arbitrarily large files to the system's temp folder by modifying the `maxFileSize` parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26265" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-26265" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-2mvj-q2q3-wxjv/GHSA-2mvj-q2q3-wxjv.json b/advisories/unreviewed/2024/02/GHSA-2mvj-q2q3-wxjv/GHSA-2mvj-q2q3-wxjv.json new file mode 100644 index 00000000000..c1778511cbb --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-2mvj-q2q3-wxjv/GHSA-2mvj-q2q3-wxjv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mvj-q2q3-wxjv", + "modified": "2024-02-20T15:31:03Z", + "published": "2024-02-20T15:31:03Z", + "aliases": [ + "CVE-2024-26267" + ], + "details": "In Liferay Portal 7.2.0 through 7.4.3.25, and older unsupported versions, and Liferay DXP 7.4 before update 26, 7.3 before update 5, 7.2 before fix pack 19, and older unsupported versions the default value of the portal property `http.header.version.verbosity` is set to `full`, which allows remote attackers to easily identify the version of the application that is running and the vulnerabilities that affect that version via 'Liferay-Portal` response header.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26267" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-26267" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1188" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-36xr-4x2f-cfj9/GHSA-36xr-4x2f-cfj9.json b/advisories/unreviewed/2024/02/GHSA-36xr-4x2f-cfj9/GHSA-36xr-4x2f-cfj9.json new file mode 100644 index 00000000000..aa4c848c05a --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-36xr-4x2f-cfj9/GHSA-36xr-4x2f-cfj9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36xr-4x2f-cfj9", + "modified": "2024-02-20T15:31:06Z", + "published": "2024-02-20T15:31:06Z", + "aliases": [ + "CVE-2024-22369" + ], + "details": "Deserialization of Untrusted Data vulnerability in Apache Camel SQL ComponentThis issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 before 3.22.1, from 4.0.0 before 4.0.4, from 4.1.0 before 4.4.0.\n\nUsers are recommended to upgrade to version 4.4.0, which fixes the issue. If users are on the 4.0.x LTS releases stream, then they are suggested to upgrade to 4.0.4. If users are on 3.x, they are suggested to move to 3.21.4 or 3.22.1\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22369" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/3dko781dy2gy5l3fs48p56fgp429yb0f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-372x-c6rw-v8f9/GHSA-372x-c6rw-v8f9.json b/advisories/unreviewed/2024/02/GHSA-372x-c6rw-v8f9/GHSA-372x-c6rw-v8f9.json new file mode 100644 index 00000000000..6842857c58d --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-372x-c6rw-v8f9/GHSA-372x-c6rw-v8f9.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-372x-c6rw-v8f9", + "modified": "2024-02-20T15:31:05Z", + "published": "2024-02-20T15:31:05Z", + "aliases": [ + "CVE-2024-1552" + ], + "details": "Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior. *Note:* This issue only affects 32-bit ARM devices. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1552" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1874502" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-05" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-06" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-37gx-jqx9-fwmg/GHSA-37gx-jqx9-fwmg.json b/advisories/unreviewed/2024/02/GHSA-37gx-jqx9-fwmg/GHSA-37gx-jqx9-fwmg.json index ab4f5a49215..97d210f9a82 100644 --- a/advisories/unreviewed/2024/02/GHSA-37gx-jqx9-fwmg/GHSA-37gx-jqx9-fwmg.json +++ b/advisories/unreviewed/2024/02/GHSA-37gx-jqx9-fwmg/GHSA-37gx-jqx9-fwmg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-37gx-jqx9-fwmg", - "modified": "2024-02-20T12:31:00Z", + "modified": "2024-02-20T15:31:03Z", "published": "2024-02-20T12:31:00Z", "aliases": [ "CVE-2023-49250" @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/wgs2jvhbmq8xnd6rmg0ymz73nyj7b3qn" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/02/20/1" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-3hwp-p2jw-j4xh/GHSA-3hwp-p2jw-j4xh.json b/advisories/unreviewed/2024/02/GHSA-3hwp-p2jw-j4xh/GHSA-3hwp-p2jw-j4xh.json new file mode 100644 index 00000000000..1b950f8e3bd --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-3hwp-p2jw-j4xh/GHSA-3hwp-p2jw-j4xh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hwp-p2jw-j4xh", + "modified": "2024-02-20T15:31:06Z", + "published": "2024-02-20T15:31:06Z", + "aliases": [ + "CVE-2024-1155" + ], + "details": "Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enable escalation of privilege via local access. \n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1155" + }, + { + "type": "WEB", + "url": "https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/incorrect-permissions-for-shared-systemlink-elixir-based-service.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-43mr-mm46-m2qq/GHSA-43mr-mm46-m2qq.json b/advisories/unreviewed/2024/02/GHSA-43mr-mm46-m2qq/GHSA-43mr-mm46-m2qq.json new file mode 100644 index 00000000000..57e3a175dde --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-43mr-mm46-m2qq/GHSA-43mr-mm46-m2qq.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43mr-mm46-m2qq", + "modified": "2024-02-20T15:31:05Z", + "published": "2024-02-20T15:31:05Z", + "aliases": [ + "CVE-2023-38562" + ], + "details": "A double-free vulnerability exists in the IP header loopback parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted set of network packets can lead to memory corruption, potentially resulting in code execution. An attacker can send a sequence of unauthenticated packets to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38562" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1829" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1829" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-4mgv-g5j9-fr8q/GHSA-4mgv-g5j9-fr8q.json b/advisories/unreviewed/2024/02/GHSA-4mgv-g5j9-fr8q/GHSA-4mgv-g5j9-fr8q.json new file mode 100644 index 00000000000..2d3a12afcb3 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-4mgv-g5j9-fr8q/GHSA-4mgv-g5j9-fr8q.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mgv-g5j9-fr8q", + "modified": "2024-02-20T15:31:05Z", + "published": "2024-02-20T15:31:05Z", + "aliases": [ + "CVE-2023-39541" + ], + "details": "A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability concerns a denial of service within the parsing an IPv6 ICMPv6 packet.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39541" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1828" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1828" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-625h-2cj8-8g77/GHSA-625h-2cj8-8g77.json b/advisories/unreviewed/2024/02/GHSA-625h-2cj8-8g77/GHSA-625h-2cj8-8g77.json new file mode 100644 index 00000000000..a05985d235a --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-625h-2cj8-8g77/GHSA-625h-2cj8-8g77.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-625h-2cj8-8g77", + "modified": "2024-02-20T15:31:05Z", + "published": "2024-02-20T15:31:05Z", + "aliases": [ + "CVE-2024-1557" + ], + "details": "Memory safety bugs present in Firefox 122. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 123.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1557" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1746471%2C1848829%2C1864011%2C1869175%2C1869455%2C1869938%2C1871606" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-05" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-62vc-2f72-vcj3/GHSA-62vc-2f72-vcj3.json b/advisories/unreviewed/2024/02/GHSA-62vc-2f72-vcj3/GHSA-62vc-2f72-vcj3.json new file mode 100644 index 00000000000..49ba7f6c765 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-62vc-2f72-vcj3/GHSA-62vc-2f72-vcj3.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62vc-2f72-vcj3", + "modified": "2024-02-20T15:31:05Z", + "published": "2024-02-20T15:31:05Z", + "aliases": [ + "CVE-2024-1553" + ], + "details": "Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1553" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1855686%2C1867982%2C1871498%2C1872296%2C1873521%2C1873577%2C1873597%2C1873866%2C1874080%2C1874740%2C1875795%2C1875906%2C1876425%2C1878211%2C1878286" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-05" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-06" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-7v7g-38mv-3237/GHSA-7v7g-38mv-3237.json b/advisories/unreviewed/2024/02/GHSA-7v7g-38mv-3237/GHSA-7v7g-38mv-3237.json new file mode 100644 index 00000000000..fe0bf67b8a3 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-7v7g-38mv-3237/GHSA-7v7g-38mv-3237.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7v7g-38mv-3237", + "modified": "2024-02-20T15:31:05Z", + "published": "2024-02-20T15:31:05Z", + "aliases": [ + "CVE-2023-39540" + ], + "details": "A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability concerns a denial of service within the parsing an IPv4 ICMP packet.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39540" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1828" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1828" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-8q5j-74vg-j4hr/GHSA-8q5j-74vg-j4hr.json b/advisories/unreviewed/2024/02/GHSA-8q5j-74vg-j4hr/GHSA-8q5j-74vg-j4hr.json new file mode 100644 index 00000000000..ba8724cd862 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-8q5j-74vg-j4hr/GHSA-8q5j-74vg-j4hr.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8q5j-74vg-j4hr", + "modified": "2024-02-20T15:31:05Z", + "published": "2024-02-20T15:31:05Z", + "aliases": [ + "CVE-2024-1550" + ], + "details": "A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1550" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1860065" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-05" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-06" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-92f7-c7hw-58cr/GHSA-92f7-c7hw-58cr.json b/advisories/unreviewed/2024/02/GHSA-92f7-c7hw-58cr/GHSA-92f7-c7hw-58cr.json new file mode 100644 index 00000000000..7b1e48d0672 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-92f7-c7hw-58cr/GHSA-92f7-c7hw-58cr.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92f7-c7hw-58cr", + "modified": "2024-02-20T15:31:04Z", + "published": "2024-02-20T15:31:04Z", + "aliases": [ + "CVE-2024-26581" + ], + "details": "netfilter: nft_set_rbtree: skip end interval element from gc\n\nrbtree lazy gc on insert might collect an end interval element that has\nbeen just added in this transactions, skip end interval elements that\nare not yet active.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26581" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1296c110c5a0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/60c0c230c6f0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6eb14441f106" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b734f7a47aeb" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-98fx-x879-qp6f/GHSA-98fx-x879-qp6f.json b/advisories/unreviewed/2024/02/GHSA-98fx-x879-qp6f/GHSA-98fx-x879-qp6f.json index 9dddd3f88bf..01a7171107c 100644 --- a/advisories/unreviewed/2024/02/GHSA-98fx-x879-qp6f/GHSA-98fx-x879-qp6f.json +++ b/advisories/unreviewed/2024/02/GHSA-98fx-x879-qp6f/GHSA-98fx-x879-qp6f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-98fx-x879-qp6f", - "modified": "2024-02-07T21:30:27Z", + "modified": "2024-02-20T15:31:02Z", "published": "2024-02-07T21:30:27Z", "aliases": [ "CVE-2023-6356" @@ -33,6 +33,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:0725" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0881" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0897" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-6356" diff --git a/advisories/unreviewed/2024/02/GHSA-9m3j-vpcw-4f37/GHSA-9m3j-vpcw-4f37.json b/advisories/unreviewed/2024/02/GHSA-9m3j-vpcw-4f37/GHSA-9m3j-vpcw-4f37.json new file mode 100644 index 00000000000..9a4990a10d0 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-9m3j-vpcw-4f37/GHSA-9m3j-vpcw-4f37.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9m3j-vpcw-4f37", + "modified": "2024-02-20T15:31:04Z", + "published": "2024-02-20T15:31:04Z", + "aliases": [ + "CVE-2024-1548" + ], + "details": "A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1548" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1832627" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-05" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-06" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-c2qq-2j48-5pr5/GHSA-c2qq-2j48-5pr5.json b/advisories/unreviewed/2024/02/GHSA-c2qq-2j48-5pr5/GHSA-c2qq-2j48-5pr5.json new file mode 100644 index 00000000000..858aaa621ac --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-c2qq-2j48-5pr5/GHSA-c2qq-2j48-5pr5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2qq-2j48-5pr5", + "modified": "2024-02-20T15:31:04Z", + "published": "2024-02-20T15:31:04Z", + "aliases": [ + "CVE-2023-42791" + ], + "details": "A relative path traversal in Fortinet FortiManager version 7.4.0 and 7.2.0 through 7.2.3 and 7.0.0 through 7.0.8 and 6.4.0 through 6.4.12 and 6.2.0 through 6.2.11 allows attacker to execute unauthorized code or commands via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42791" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-189" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-ccq4-9qhm-55xx/GHSA-ccq4-9qhm-55xx.json b/advisories/unreviewed/2024/02/GHSA-ccq4-9qhm-55xx/GHSA-ccq4-9qhm-55xx.json new file mode 100644 index 00000000000..a9cf3dd5037 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-ccq4-9qhm-55xx/GHSA-ccq4-9qhm-55xx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccq4-9qhm-55xx", + "modified": "2024-02-20T15:31:06Z", + "published": "2024-02-20T15:31:06Z", + "aliases": [ + "CVE-2024-1156" + ], + "details": "Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information and potentially enable escalation of privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1156" + }, + { + "type": "WEB", + "url": "https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/incorrect-permissions-for-shared-systemlink-elixir-based-service.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-cmph-x6r4-4whr/GHSA-cmph-x6r4-4whr.json b/advisories/unreviewed/2024/02/GHSA-cmph-x6r4-4whr/GHSA-cmph-x6r4-4whr.json new file mode 100644 index 00000000000..0fe910ecb4b --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-cmph-x6r4-4whr/GHSA-cmph-x6r4-4whr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmph-x6r4-4whr", + "modified": "2024-02-20T15:31:03Z", + "published": "2024-02-20T15:31:03Z", + "aliases": [ + "CVE-2023-52433" + ], + "details": "netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction\n\nNew elements in this transaction might expired before such transaction\nends. Skip sync GC for such elements otherwise commit path might walk\nover an already released object. Once transaction is finished, async GC\nwill collect such expired element.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52433" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2ee52ae94baa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e3213ff99a35" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-cq85-4f5h-qqc4/GHSA-cq85-4f5h-qqc4.json b/advisories/unreviewed/2024/02/GHSA-cq85-4f5h-qqc4/GHSA-cq85-4f5h-qqc4.json new file mode 100644 index 00000000000..d71ee63208e --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-cq85-4f5h-qqc4/GHSA-cq85-4f5h-qqc4.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cq85-4f5h-qqc4", + "modified": "2024-02-20T15:31:05Z", + "published": "2024-02-20T15:31:05Z", + "aliases": [ + "CVE-2024-1551" + ], + "details": "Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well as control part of the response body, they could inject Set-Cookie response headers that would have been honored by the browser. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1551" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1864385" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-05" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-06" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-ff2w-wm48-jhqj/GHSA-ff2w-wm48-jhqj.json b/advisories/unreviewed/2024/02/GHSA-ff2w-wm48-jhqj/GHSA-ff2w-wm48-jhqj.json index 39aa897afe2..9821deaa31a 100644 --- a/advisories/unreviewed/2024/02/GHSA-ff2w-wm48-jhqj/GHSA-ff2w-wm48-jhqj.json +++ b/advisories/unreviewed/2024/02/GHSA-ff2w-wm48-jhqj/GHSA-ff2w-wm48-jhqj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ff2w-wm48-jhqj", - "modified": "2024-02-20T12:31:00Z", + "modified": "2024-02-20T15:31:03Z", "published": "2024-02-20T12:31:00Z", "aliases": [ "CVE-2023-51770" @@ -29,6 +29,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/gpks573kn00ofxn7n9gkg6o47d03p5rw" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/02/20/2" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-g24h-xx4p-jc7j/GHSA-g24h-xx4p-jc7j.json b/advisories/unreviewed/2024/02/GHSA-g24h-xx4p-jc7j/GHSA-g24h-xx4p-jc7j.json new file mode 100644 index 00000000000..9783af1df82 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-g24h-xx4p-jc7j/GHSA-g24h-xx4p-jc7j.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g24h-xx4p-jc7j", + "modified": "2024-02-20T15:31:05Z", + "published": "2024-02-20T15:31:05Z", + "aliases": [ + "CVE-2024-25196" + ], + "details": "Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_controller process. This vulnerability is triggerd via sending a crafted .yaml file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25196" + }, + { + "type": "WEB", + "url": "https://github.com/ros-planning/navigation2/issues/4005" + }, + { + "type": "WEB", + "url": "https://github.com/ros-planning/navigation2/pull/4017" + }, + { + "type": "WEB", + "url": "https://robotics.stackexchange.com/questions/106008/ros2nav2user-misconfiguration-of-parameters-may-cause-instantaneous-crashs" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-gqrh-wgmr-mm7v/GHSA-gqrh-wgmr-mm7v.json b/advisories/unreviewed/2024/02/GHSA-gqrh-wgmr-mm7v/GHSA-gqrh-wgmr-mm7v.json new file mode 100644 index 00000000000..36c0a638c31 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-gqrh-wgmr-mm7v/GHSA-gqrh-wgmr-mm7v.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqrh-wgmr-mm7v", + "modified": "2024-02-20T15:31:05Z", + "published": "2024-02-20T15:31:05Z", + "aliases": [ + "CVE-2024-1554" + ], + "details": "The `fetch()` API and navigation incorrectly shared the same cache, as the cache key did not include the optional headers `fetch()` may contain. Under the correct circumstances, an attacker may have been able to poison the local browser cache by priming it with a `fetch()` response controlled by the additional headers. Upon navigation to the same URL, the user would see the cached response instead of the expected response. This vulnerability affects Firefox < 123.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1554" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1816390" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-05" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-hmqj-rccj-3q53/GHSA-hmqj-rccj-3q53.json b/advisories/unreviewed/2024/02/GHSA-hmqj-rccj-3q53/GHSA-hmqj-rccj-3q53.json new file mode 100644 index 00000000000..6671edc36ce --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-hmqj-rccj-3q53/GHSA-hmqj-rccj-3q53.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmqj-rccj-3q53", + "modified": "2024-02-20T15:31:04Z", + "published": "2024-02-20T15:31:04Z", + "aliases": [ + "CVE-2024-1547" + ], + "details": "Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL shown). This vulnerability affects Firefox < 123 and Firefox ESR < 115.8.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1547" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1877879" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-05" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-06" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-j494-r8wx-qpjr/GHSA-j494-r8wx-qpjr.json b/advisories/unreviewed/2024/02/GHSA-j494-r8wx-qpjr/GHSA-j494-r8wx-qpjr.json new file mode 100644 index 00000000000..3a174beeac5 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-j494-r8wx-qpjr/GHSA-j494-r8wx-qpjr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j494-r8wx-qpjr", + "modified": "2024-02-20T15:31:05Z", + "published": "2024-02-20T15:31:05Z", + "aliases": [ + "CVE-2023-45318" + ], + "details": "A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A specially crafted network packet can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45318" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1843" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1843" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-j6qq-7xp7-c5p5/GHSA-j6qq-7xp7-c5p5.json b/advisories/unreviewed/2024/02/GHSA-j6qq-7xp7-c5p5/GHSA-j6qq-7xp7-c5p5.json new file mode 100644 index 00000000000..e8af3f606d4 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-j6qq-7xp7-c5p5/GHSA-j6qq-7xp7-c5p5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6qq-7xp7-c5p5", + "modified": "2024-02-20T15:31:05Z", + "published": "2024-02-20T15:31:05Z", + "aliases": [ + "CVE-2024-1555" + ], + "details": "When opening a website using the `firefox://` protocol handler, SameSite cookies were not properly respected. This vulnerability affects Firefox < 123.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1555" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1873223" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-05" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-m43p-55rf-8c2j/GHSA-m43p-55rf-8c2j.json b/advisories/unreviewed/2024/02/GHSA-m43p-55rf-8c2j/GHSA-m43p-55rf-8c2j.json new file mode 100644 index 00000000000..fbe9ac9ba4d --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-m43p-55rf-8c2j/GHSA-m43p-55rf-8c2j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m43p-55rf-8c2j", + "modified": "2024-02-20T15:31:06Z", + "published": "2024-02-20T15:31:06Z", + "aliases": [ + "CVE-2024-23114" + ], + "details": "Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRepository which is vulnerable to unsafe deserialization. Under specific conditions it is possible to deserialize malicious payload.This issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 before 3.22.1, from 4.0.0 before 4.0.4, from 4.1.0 before 4.4.0.\n\nUsers are recommended to upgrade to version 4.4.0, which fixes the issue. If users are on the 4.0.x LTS releases stream, then they are suggested to upgrade to 4.0.4. If users are on 3.x, they are suggested to move to 3.21.4 or 3.22.1\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23114" + }, + { + "type": "WEB", + "url": "https://camel.apache.org/security/CVE-2024-23114.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-mf2m-vhfh-2qjv/GHSA-mf2m-vhfh-2qjv.json b/advisories/unreviewed/2024/02/GHSA-mf2m-vhfh-2qjv/GHSA-mf2m-vhfh-2qjv.json new file mode 100644 index 00000000000..72fb5081e11 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-mf2m-vhfh-2qjv/GHSA-mf2m-vhfh-2qjv.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mf2m-vhfh-2qjv", + "modified": "2024-02-20T15:31:05Z", + "published": "2024-02-20T15:31:05Z", + "aliases": [ + "CVE-2024-1549" + ], + "details": "If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and unexpected granted permissions. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1549" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1833814" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-05" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-06" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-qm43-g2xj-hvg5/GHSA-qm43-g2xj-hvg5.json b/advisories/unreviewed/2024/02/GHSA-qm43-g2xj-hvg5/GHSA-qm43-g2xj-hvg5.json new file mode 100644 index 00000000000..2c715be5ad0 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-qm43-g2xj-hvg5/GHSA-qm43-g2xj-hvg5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qm43-g2xj-hvg5", + "modified": "2024-02-20T15:31:05Z", + "published": "2024-02-20T15:31:05Z", + "aliases": [ + "CVE-2024-26268" + ], + "details": "User enumeration vulnerability in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 8, 7.2 before fix pack 20, and older unsupported versions allows remote attackers to determine if an account exist in the application by comparing the request's response time.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26268" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-26268" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-203" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-qwxx-xww6-8q8m/GHSA-qwxx-xww6-8q8m.json b/advisories/unreviewed/2024/02/GHSA-qwxx-xww6-8q8m/GHSA-qwxx-xww6-8q8m.json index 6b79706eb24..1c8099b794c 100644 --- a/advisories/unreviewed/2024/02/GHSA-qwxx-xww6-8q8m/GHSA-qwxx-xww6-8q8m.json +++ b/advisories/unreviewed/2024/02/GHSA-qwxx-xww6-8q8m/GHSA-qwxx-xww6-8q8m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qwxx-xww6-8q8m", - "modified": "2024-02-20T12:30:58Z", + "modified": "2024-02-20T15:31:03Z", "published": "2024-02-20T12:30:58Z", "aliases": [ "CVE-2023-49109" @@ -29,6 +29,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/6kgsl93vtqlbdk6otttl0d8wmlspk0m5" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/02/20/4" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-r3h6-h7mc-hvh5/GHSA-r3h6-h7mc-hvh5.json b/advisories/unreviewed/2024/02/GHSA-r3h6-h7mc-hvh5/GHSA-r3h6-h7mc-hvh5.json new file mode 100644 index 00000000000..715e996c185 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-r3h6-h7mc-hvh5/GHSA-r3h6-h7mc-hvh5.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3h6-h7mc-hvh5", + "modified": "2024-02-20T15:31:05Z", + "published": "2024-02-20T15:31:05Z", + "aliases": [ + "CVE-2024-25197" + ], + "details": "Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a NULL pointer dereference via the isCurrent() function at /src/layered_costmap.cpp.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25197" + }, + { + "type": "WEB", + "url": "https://github.com/ros-planning/navigation2/issues/3940" + }, + { + "type": "WEB", + "url": "https://github.com/ros-planning/navigation2/issues/3958" + }, + { + "type": "WEB", + "url": "https://github.com/ros-planning/navigation2/issues/3971" + }, + { + "type": "WEB", + "url": "https://github.com/ros-planning/navigation2/issues/3972" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-rmqp-82v9-w7q3/GHSA-rmqp-82v9-w7q3.json b/advisories/unreviewed/2024/02/GHSA-rmqp-82v9-w7q3/GHSA-rmqp-82v9-w7q3.json new file mode 100644 index 00000000000..abf3fc668fd --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-rmqp-82v9-w7q3/GHSA-rmqp-82v9-w7q3.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmqp-82v9-w7q3", + "modified": "2024-02-20T15:31:05Z", + "published": "2024-02-20T15:31:05Z", + "aliases": [ + "CVE-2024-25198" + ], + "details": "Inappropriate pointer order of laser_scan_filter_.reset() and tf_listener_.reset() (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25198" + }, + { + "type": "WEB", + "url": "https://github.com/ros-planning/navigation2/pull/4068" + }, + { + "type": "WEB", + "url": "https://github.com/ros-planning/navigation2/pull/4070" + }, + { + "type": "WEB", + "url": "https://github.com/ros-planning/navigation2/blob/main/nav2_amcl/src/amcl_node.cpp#L331-L344" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-rmwg-qccm-r36q/GHSA-rmwg-qccm-r36q.json b/advisories/unreviewed/2024/02/GHSA-rmwg-qccm-r36q/GHSA-rmwg-qccm-r36q.json new file mode 100644 index 00000000000..40e4ce5a712 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-rmwg-qccm-r36q/GHSA-rmwg-qccm-r36q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmwg-qccm-r36q", + "modified": "2024-02-20T15:31:06Z", + "published": "2024-02-20T15:31:06Z", + "aliases": [ + "CVE-2024-22824" + ], + "details": "An issue in Timo v.2.0.3 allows a remote attacker to execute arbitrary code via the filetype restrictions in the UploadController.java component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22824" + }, + { + "type": "WEB", + "url": "https://github.com/auntvt/Timo/issues/6" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-v3xc-v2g4-h75g/GHSA-v3xc-v2g4-h75g.json b/advisories/unreviewed/2024/02/GHSA-v3xc-v2g4-h75g/GHSA-v3xc-v2g4-h75g.json new file mode 100644 index 00000000000..6e2e99d1ba0 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-v3xc-v2g4-h75g/GHSA-v3xc-v2g4-h75g.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3xc-v2g4-h75g", + "modified": "2024-02-20T15:31:03Z", + "published": "2024-02-20T15:31:03Z", + "aliases": [ + "CVE-2024-1661" + ], + "details": "A vulnerability classified as problematic was found in Totolink X6000R 9.4.0cu.852_B20230719. Affected by this vulnerability is an unknown functionality of the file /etc/shadow. The manipulation leads to hard-coded credentials. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-254179. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1661" + }, + { + "type": "WEB", + "url": "https://github.com/WoodManGitHub/MyCVEs/blob/main/2024-Totolink/X6000R-Hardcoded-Password.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.254179" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.254179" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-v8xr-j3gp-fmxj/GHSA-v8xr-j3gp-fmxj.json b/advisories/unreviewed/2024/02/GHSA-v8xr-j3gp-fmxj/GHSA-v8xr-j3gp-fmxj.json index d02750c66a6..2d36d27a2f7 100644 --- a/advisories/unreviewed/2024/02/GHSA-v8xr-j3gp-fmxj/GHSA-v8xr-j3gp-fmxj.json +++ b/advisories/unreviewed/2024/02/GHSA-v8xr-j3gp-fmxj/GHSA-v8xr-j3gp-fmxj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v8xr-j3gp-fmxj", - "modified": "2024-02-07T21:30:27Z", + "modified": "2024-02-20T15:31:03Z", "published": "2024-02-07T21:30:27Z", "aliases": [ "CVE-2023-6535" @@ -33,6 +33,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:0725" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0881" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0897" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-6535" diff --git a/advisories/unreviewed/2024/02/GHSA-vjqc-g788-f378/GHSA-vjqc-g788-f378.json b/advisories/unreviewed/2024/02/GHSA-vjqc-g788-f378/GHSA-vjqc-g788-f378.json index d12a396150e..5ac399c0e97 100644 --- a/advisories/unreviewed/2024/02/GHSA-vjqc-g788-f378/GHSA-vjqc-g788-f378.json +++ b/advisories/unreviewed/2024/02/GHSA-vjqc-g788-f378/GHSA-vjqc-g788-f378.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vjqc-g788-f378", - "modified": "2024-02-20T12:31:00Z", + "modified": "2024-02-20T15:31:03Z", "published": "2024-02-20T12:31:00Z", "aliases": [ "CVE-2023-50270" @@ -29,6 +29,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/lmnf21obyos920dnvbfpwq29c1sd2r9r" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/02/20/3" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-vvpf-53qx-cxhh/GHSA-vvpf-53qx-cxhh.json b/advisories/unreviewed/2024/02/GHSA-vvpf-53qx-cxhh/GHSA-vvpf-53qx-cxhh.json new file mode 100644 index 00000000000..ecc85fe33e5 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-vvpf-53qx-cxhh/GHSA-vvpf-53qx-cxhh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvpf-53qx-cxhh", + "modified": "2024-02-20T15:31:03Z", + "published": "2024-02-20T15:31:03Z", + "aliases": [ + "CVE-2024-25610" + ], + "details": "In Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions, the default configuration does not sanitize blog entries of JavaScript, which allows remote authenticated users to inject arbitrary web script or HTML (XSS) via a crafted payload injected into a blog entry’s content text field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25610" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-25610" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1188" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-vw87-wrx2-xwxq/GHSA-vw87-wrx2-xwxq.json b/advisories/unreviewed/2024/02/GHSA-vw87-wrx2-xwxq/GHSA-vw87-wrx2-xwxq.json new file mode 100644 index 00000000000..f4d24c3d20f --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-vw87-wrx2-xwxq/GHSA-vw87-wrx2-xwxq.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vw87-wrx2-xwxq", + "modified": "2024-02-20T15:31:04Z", + "published": "2024-02-20T15:31:04Z", + "aliases": [ + "CVE-2023-50306" + ], + "details": "IBM Common Licensing 9.0 could allow a local user to enumerate usernames due to an observable response discrepancy. IBM X-Force ID: 273337.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50306" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/273337" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7120660" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-204" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-w267-2gcr-ggcp/GHSA-w267-2gcr-ggcp.json b/advisories/unreviewed/2024/02/GHSA-w267-2gcr-ggcp/GHSA-w267-2gcr-ggcp.json new file mode 100644 index 00000000000..bd5f9628dc2 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-w267-2gcr-ggcp/GHSA-w267-2gcr-ggcp.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w267-2gcr-ggcp", + "modified": "2024-02-20T15:31:04Z", + "published": "2024-02-20T15:31:04Z", + "aliases": [ + "CVE-2024-1546" + ], + "details": "When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1546" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1843752" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-05" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-06" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-wp8h-p32h-fwvc/GHSA-wp8h-p32h-fwvc.json b/advisories/unreviewed/2024/02/GHSA-wp8h-p32h-fwvc/GHSA-wp8h-p32h-fwvc.json new file mode 100644 index 00000000000..2a94d61eb91 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-wp8h-p32h-fwvc/GHSA-wp8h-p32h-fwvc.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wp8h-p32h-fwvc", + "modified": "2024-02-20T15:31:05Z", + "published": "2024-02-20T15:31:05Z", + "aliases": [ + "CVE-2024-1556" + ], + "details": "The incorrect object was checked for NULL in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This issue only affects the application when the profiler is running. This vulnerability affects Firefox < 123.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1556" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1870414" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-05" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-xq4r-4xfh-vch8/GHSA-xq4r-4xfh-vch8.json b/advisories/unreviewed/2024/02/GHSA-xq4r-4xfh-vch8/GHSA-xq4r-4xfh-vch8.json new file mode 100644 index 00000000000..975ab949896 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-xq4r-4xfh-vch8/GHSA-xq4r-4xfh-vch8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xq4r-4xfh-vch8", + "modified": "2024-02-20T15:31:05Z", + "published": "2024-02-20T15:31:05Z", + "aliases": [ + "CVE-2024-26270" + ], + "details": "The Account Settings page in Liferay Portal 7.4.3.76 through 7.4.3.99, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 76 through 92 embeds the user’s hashed password in the page’s HTML source, which allows man-in-the-middle attackers to steal a user's hashed password.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26270" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-26270" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-201" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-xv5g-jfvh-hgph/GHSA-xv5g-jfvh-hgph.json b/advisories/unreviewed/2024/02/GHSA-xv5g-jfvh-hgph/GHSA-xv5g-jfvh-hgph.json new file mode 100644 index 00000000000..ac7011a1162 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-xv5g-jfvh-hgph/GHSA-xv5g-jfvh-hgph.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xv5g-jfvh-hgph", + "modified": "2024-02-20T15:31:05Z", + "published": "2024-02-20T15:31:05Z", + "aliases": [ + "CVE-2024-25199" + ], + "details": "Inappropriate pointer order of map_sub_ and map_free(map_) (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25199" + }, + { + "type": "WEB", + "url": "https://github.com/ros-planning/navigation2/pull/4078" + }, + { + "type": "WEB", + "url": "https://github.com/ros-planning/navigation2/pull/4079" + }, + { + "type": "WEB", + "url": "https://github.com/ros-planning/navigation2/blob/main/nav2_amcl/src/amcl_node.cpp#L331-L344" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-xw3g-x45j-xxhh/GHSA-xw3g-x45j-xxhh.json b/advisories/unreviewed/2024/02/GHSA-xw3g-x45j-xxhh/GHSA-xw3g-x45j-xxhh.json index 98b67dc3d8b..05ea1ae1151 100644 --- a/advisories/unreviewed/2024/02/GHSA-xw3g-x45j-xxhh/GHSA-xw3g-x45j-xxhh.json +++ b/advisories/unreviewed/2024/02/GHSA-xw3g-x45j-xxhh/GHSA-xw3g-x45j-xxhh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xw3g-x45j-xxhh", - "modified": "2024-02-07T21:30:27Z", + "modified": "2024-02-20T15:31:03Z", "published": "2024-02-07T21:30:27Z", "aliases": [ "CVE-2023-6536" @@ -33,6 +33,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:0725" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0881" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0897" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-6536"