Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-08-07 18:32:30 +00:00
parent 33afa3bc32
commit 239b589351
97 changed files with 2310 additions and 117 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-78hx-gp6g-7mj6",
"modified": "2024-07-25T18:32:35Z",
"modified": "2024-08-07T18:30:39Z",
"published": "2024-03-20T18:10:36Z",
"aliases": [
"CVE-2024-1394"
@@ -134,10 +134,6 @@
"type": "WEB",
"url": "https://github.com/golang-fips/openssl/commit/85d31d0d257ce842c8a1e63c4d230ae850348136"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1462"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:4146"
@@ -182,6 +178,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:4762"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:4960"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-1394"
@@ -210,6 +210,10 @@
"type": "WEB",
"url": "https://vuln.go.dev/ID/GO-2024-2660.json"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1462"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1468"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6wvf-f2vw-3425",
"modified": "2024-08-02T18:31:09Z",
"modified": "2024-08-07T18:30:38Z",
"published": "2024-05-14T18:30:52Z",
"aliases": [
"CVE-2024-3727"
@@ -142,6 +142,10 @@
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-3727"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:4960"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:4850"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8fgv-frq2-3468",
"modified": "2022-03-04T00:00:47Z",
"modified": "2024-08-07T18:30:37Z",
"published": "2022-02-17T00:00:31Z",
"aliases": [
"CVE-2021-3557"
],
"details": "A flaw was found in argocd. Any unprivileged user is able to deploy argocd in their namespace and with the created ServiceAccount argocd-argocd-server, the unprivileged user is able to read all resources of the cluster including all secrets which might enable privilege escalations. The highest threat from this vulnerability is to data confidentiality.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g4gx-6fjc-vv49",
"modified": "2022-05-24T22:28:38Z",
"modified": "2024-08-07T18:30:36Z",
"published": "2022-05-24T22:28:38Z",
"aliases": [
"CVE-2020-8826"
],
"details": "As of v1.5.0, the Argo web interface authentication system issued immutable tokens. Authentication tokens, once issued, were usable forever without expiration—there was no refresh or forced re-authentication.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -33,7 +36,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-384"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4v5g-xjvw-59g6",
"modified": "2024-04-30T15:30:35Z",
"modified": "2024-08-07T18:30:38Z",
"published": "2023-12-28T18:30:32Z",
"aliases": [
"CVE-2023-6228"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2289"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:5079"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-6228"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cx8g-4cf5-cjv3",
"modified": "2024-07-30T03:30:51Z",
"modified": "2024-08-07T18:30:38Z",
"published": "2024-01-25T21:32:14Z",
"aliases": [
"CVE-2023-52356"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52356"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:5079"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-52356"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c8v5-2jcx-x4j2",
"modified": "2024-02-28T09:30:37Z",
"modified": "2024-08-07T18:30:38Z",
"published": "2024-02-28T09:30:37Z",
"aliases": [
"CVE-2021-47010"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: Only allow init netns to set default tcp cong to a restricted algo\n\ntcp_set_default_congestion_control() is netns-safe in that it writes\nto &net->ipv4.tcp_congestion_control, but it also sets\nca->flags |= TCP_CONG_NON_RESTRICTED which is not namespaced.\nThis has the unintended side-effect of changing the global\nnet.ipv4.tcp_allowed_congestion_control sysctl, despite the fact that it\nis read-only: 97684f0970f6 (\"net: Make tcp_allowed_congestion_control\nreadonly in non-init netns\")\n\nResolve this netns \"leak\" by only allowing the init netns to set the\ndefault algorithm to one that is restricted. This restriction could be\nremoved if tcp_allowed_congestion_control were namespace-ified in the\nfuture.\n\nThis bug was uncovered with\nhttps://github.com/JonathonReinhart/linux-netns-sysctl-verify",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -45,9 +48,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-400"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-28T09:15:38Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3cjj-693r-8cc3",
"modified": "2024-04-24T00:30:32Z",
"modified": "2024-08-07T18:30:38Z",
"published": "2024-04-24T00:30:32Z",
"aliases": [
"CVE-2024-30886"
],
"details": "A stored cross-site scripting (XSS) vulnerability in the remotelink function of HadSky v7.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the url parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-23T22:15:07Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5wrj-rjjw-w232",
"modified": "2024-04-23T15:30:36Z",
"modified": "2024-08-07T18:30:38Z",
"published": "2024-04-23T15:30:36Z",
"aliases": [
"CVE-2024-33217"
],
"details": "Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter in ip/goform/addressNat.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-121"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-23T15:15:50Z"
@@ -1,14 +1,21 @@
{
"schema_version": "1.4.0",
"id": "GHSA-26v6-wwwv-j4cc",
"modified": "2024-06-12T18:30:41Z",
"modified": "2024-08-07T18:30:39Z",
"published": "2024-06-12T18:30:41Z",
"aliases": [
"CVE-2024-5909"
],
"details": "A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber"
}
],
"affected": [
@@ -27,7 +34,7 @@
"cwe_ids": [
"CWE-269"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-12T17:15:53Z"
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3chh-q8fx-pc2w",
"modified": "2024-06-16T18:31:21Z",
"modified": "2024-08-07T18:30:40Z",
"published": "2024-06-16T18:31:21Z",
"aliases": [
"CVE-2024-38468"
],
"details": "Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-640"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-16T16:15:09Z"
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-121"
"CWE-121",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-121"
"CWE-121",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,14 +1,21 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6q37-cp6x-mhfw",
"modified": "2024-06-12T18:30:41Z",
"modified": "2024-08-07T18:30:39Z",
"published": "2024-06-12T18:30:41Z",
"aliases": [
"CVE-2024-5908"
],
"details": "A problem with the Palo Alto Networks GlobalProtect app can result in exposure of encrypted user credentials, used for connecting to GlobalProtect, in application logs. Normally, these application logs are only viewable by local users and are included when generating logs for troubleshooting purposes. This means that these encrypted credentials are exposed to recipients of the application logs.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber"
}
],
"affected": [
@@ -27,7 +34,7 @@
"cwe_ids": [
"CWE-532"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-12T17:15:53Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7p4r-33p9-q666",
"modified": "2024-06-16T18:31:21Z",
"modified": "2024-08-07T18:30:40Z",
"published": "2024-06-16T18:31:21Z",
"aliases": [
"CVE-2024-38466"
],
"details": "Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-798"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-16T16:15:09Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-82h5-9gw3-q456",
"modified": "2024-06-14T18:31:45Z",
"modified": "2024-08-07T18:30:40Z",
"published": "2024-06-14T18:31:45Z",
"aliases": [
"CVE-2024-24320"
],
"details": "Directory Traversal vulnerability in Mgt-commerce CloudPanel v.2.0.0 thru v.2.4.0 allows a remote attacker to obtain sensitive information and execute arbitrary code via the service parameter of the load-logfiles function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-14T18:15:27Z"
@@ -36,7 +36,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-525"
"CWE-525",
"CWE-668"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c8xv-94wg-v5h7",
"modified": "2024-06-13T21:30:52Z",
"modified": "2024-08-07T18:30:39Z",
"published": "2024-06-13T21:30:52Z",
"aliases": [
"CVE-2024-37635"
],
"details": "TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiBasicCfg",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-13T19:15:52Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ffh4-92gv-qvv5",
"modified": "2024-06-13T21:30:53Z",
"modified": "2024-08-07T18:30:39Z",
"published": "2024-06-13T21:30:53Z",
"aliases": [
"CVE-2024-38312"
],
"details": "When browsing private tabs, some data related to location history or webpage thumbnails could be persisted incorrectly within the sandboxed app bundle after app termination This vulnerability affects Firefox for iOS < 127.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-13T20:15:15Z"

Some files were not shown because too many files have changed in this diff Show More