diff --git a/advisories/github-reviewed/2024/03/GHSA-78hx-gp6g-7mj6/GHSA-78hx-gp6g-7mj6.json b/advisories/github-reviewed/2024/03/GHSA-78hx-gp6g-7mj6/GHSA-78hx-gp6g-7mj6.json index fbcd7014e28..403daafbc14 100644 --- a/advisories/github-reviewed/2024/03/GHSA-78hx-gp6g-7mj6/GHSA-78hx-gp6g-7mj6.json +++ b/advisories/github-reviewed/2024/03/GHSA-78hx-gp6g-7mj6/GHSA-78hx-gp6g-7mj6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-78hx-gp6g-7mj6", - "modified": "2024-07-25T18:32:35Z", + "modified": "2024-08-07T18:30:39Z", "published": "2024-03-20T18:10:36Z", "aliases": [ "CVE-2024-1394" @@ -134,10 +134,6 @@ "type": "WEB", "url": "https://github.com/golang-fips/openssl/commit/85d31d0d257ce842c8a1e63c4d230ae850348136" }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:1462" - }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:4146" @@ -182,6 +178,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:4762" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4960" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-1394" @@ -210,6 +210,10 @@ "type": "WEB", "url": "https://vuln.go.dev/ID/GO-2024-2660.json" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1462" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:1468" diff --git a/advisories/github-reviewed/2024/05/GHSA-6wvf-f2vw-3425/GHSA-6wvf-f2vw-3425.json b/advisories/github-reviewed/2024/05/GHSA-6wvf-f2vw-3425/GHSA-6wvf-f2vw-3425.json index a53c7eabdab..c412fb1ea41 100644 --- a/advisories/github-reviewed/2024/05/GHSA-6wvf-f2vw-3425/GHSA-6wvf-f2vw-3425.json +++ b/advisories/github-reviewed/2024/05/GHSA-6wvf-f2vw-3425/GHSA-6wvf-f2vw-3425.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6wvf-f2vw-3425", - "modified": "2024-08-02T18:31:09Z", + "modified": "2024-08-07T18:30:38Z", "published": "2024-05-14T18:30:52Z", "aliases": [ "CVE-2024-3727" @@ -142,6 +142,10 @@ "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-3727" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4960" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:4850" diff --git a/advisories/unreviewed/2022/02/GHSA-8fgv-frq2-3468/GHSA-8fgv-frq2-3468.json b/advisories/unreviewed/2022/02/GHSA-8fgv-frq2-3468/GHSA-8fgv-frq2-3468.json index 0050f14083b..c9fb2b23119 100644 --- a/advisories/unreviewed/2022/02/GHSA-8fgv-frq2-3468/GHSA-8fgv-frq2-3468.json +++ b/advisories/unreviewed/2022/02/GHSA-8fgv-frq2-3468/GHSA-8fgv-frq2-3468.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8fgv-frq2-3468", - "modified": "2022-03-04T00:00:47Z", + "modified": "2024-08-07T18:30:37Z", "published": "2022-02-17T00:00:31Z", "aliases": [ "CVE-2021-3557" ], "details": "A flaw was found in argocd. Any unprivileged user is able to deploy argocd in their namespace and with the created ServiceAccount argocd-argocd-server, the unprivileged user is able to read all resources of the cluster including all secrets which might enable privilege escalations. The highest threat from this vulnerability is to data confidentiality.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-g4gx-6fjc-vv49/GHSA-g4gx-6fjc-vv49.json b/advisories/unreviewed/2022/05/GHSA-g4gx-6fjc-vv49/GHSA-g4gx-6fjc-vv49.json index ed1ab616650..ffc2a41d0b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-g4gx-6fjc-vv49/GHSA-g4gx-6fjc-vv49.json +++ b/advisories/unreviewed/2022/05/GHSA-g4gx-6fjc-vv49/GHSA-g4gx-6fjc-vv49.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g4gx-6fjc-vv49", - "modified": "2022-05-24T22:28:38Z", + "modified": "2024-08-07T18:30:36Z", "published": "2022-05-24T22:28:38Z", "aliases": [ "CVE-2020-8826" ], "details": "As of v1.5.0, the Argo web interface authentication system issued immutable tokens. Authentication tokens, once issued, were usable forever without expiration—there was no refresh or forced re-authentication.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-384" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-4v5g-xjvw-59g6/GHSA-4v5g-xjvw-59g6.json b/advisories/unreviewed/2023/12/GHSA-4v5g-xjvw-59g6/GHSA-4v5g-xjvw-59g6.json index 3cbd154499a..11be1b0ef67 100644 --- a/advisories/unreviewed/2023/12/GHSA-4v5g-xjvw-59g6/GHSA-4v5g-xjvw-59g6.json +++ b/advisories/unreviewed/2023/12/GHSA-4v5g-xjvw-59g6/GHSA-4v5g-xjvw-59g6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4v5g-xjvw-59g6", - "modified": "2024-04-30T15:30:35Z", + "modified": "2024-08-07T18:30:38Z", "published": "2023-12-28T18:30:32Z", "aliases": [ "CVE-2023-6228" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:2289" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:5079" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-6228" diff --git a/advisories/unreviewed/2024/01/GHSA-cx8g-4cf5-cjv3/GHSA-cx8g-4cf5-cjv3.json b/advisories/unreviewed/2024/01/GHSA-cx8g-4cf5-cjv3/GHSA-cx8g-4cf5-cjv3.json index 6784d761215..6575a6867e5 100644 --- a/advisories/unreviewed/2024/01/GHSA-cx8g-4cf5-cjv3/GHSA-cx8g-4cf5-cjv3.json +++ b/advisories/unreviewed/2024/01/GHSA-cx8g-4cf5-cjv3/GHSA-cx8g-4cf5-cjv3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cx8g-4cf5-cjv3", - "modified": "2024-07-30T03:30:51Z", + "modified": "2024-08-07T18:30:38Z", "published": "2024-01-25T21:32:14Z", "aliases": [ "CVE-2023-52356" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52356" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:5079" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-52356" diff --git a/advisories/unreviewed/2024/02/GHSA-c8v5-2jcx-x4j2/GHSA-c8v5-2jcx-x4j2.json b/advisories/unreviewed/2024/02/GHSA-c8v5-2jcx-x4j2/GHSA-c8v5-2jcx-x4j2.json index 3273432a306..9bbafdb5d81 100644 --- a/advisories/unreviewed/2024/02/GHSA-c8v5-2jcx-x4j2/GHSA-c8v5-2jcx-x4j2.json +++ b/advisories/unreviewed/2024/02/GHSA-c8v5-2jcx-x4j2/GHSA-c8v5-2jcx-x4j2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c8v5-2jcx-x4j2", - "modified": "2024-02-28T09:30:37Z", + "modified": "2024-08-07T18:30:38Z", "published": "2024-02-28T09:30:37Z", "aliases": [ "CVE-2021-47010" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: Only allow init netns to set default tcp cong to a restricted algo\n\ntcp_set_default_congestion_control() is netns-safe in that it writes\nto &net->ipv4.tcp_congestion_control, but it also sets\nca->flags |= TCP_CONG_NON_RESTRICTED which is not namespaced.\nThis has the unintended side-effect of changing the global\nnet.ipv4.tcp_allowed_congestion_control sysctl, despite the fact that it\nis read-only: 97684f0970f6 (\"net: Make tcp_allowed_congestion_control\nreadonly in non-init netns\")\n\nResolve this netns \"leak\" by only allowing the init netns to set the\ndefault algorithm to one that is restricted. This restriction could be\nremoved if tcp_allowed_congestion_control were namespace-ified in the\nfuture.\n\nThis bug was uncovered with\nhttps://github.com/JonathonReinhart/linux-netns-sysctl-verify", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:38Z" diff --git a/advisories/unreviewed/2024/04/GHSA-3cjj-693r-8cc3/GHSA-3cjj-693r-8cc3.json b/advisories/unreviewed/2024/04/GHSA-3cjj-693r-8cc3/GHSA-3cjj-693r-8cc3.json index f7cd6553c29..90ac24d4d45 100644 --- a/advisories/unreviewed/2024/04/GHSA-3cjj-693r-8cc3/GHSA-3cjj-693r-8cc3.json +++ b/advisories/unreviewed/2024/04/GHSA-3cjj-693r-8cc3/GHSA-3cjj-693r-8cc3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3cjj-693r-8cc3", - "modified": "2024-04-24T00:30:32Z", + "modified": "2024-08-07T18:30:38Z", "published": "2024-04-24T00:30:32Z", "aliases": [ "CVE-2024-30886" ], "details": "A stored cross-site scripting (XSS) vulnerability in the remotelink function of HadSky v7.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the url parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-23T22:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-5wrj-rjjw-w232/GHSA-5wrj-rjjw-w232.json b/advisories/unreviewed/2024/04/GHSA-5wrj-rjjw-w232/GHSA-5wrj-rjjw-w232.json index b87e207e588..bcaa735cb5b 100644 --- a/advisories/unreviewed/2024/04/GHSA-5wrj-rjjw-w232/GHSA-5wrj-rjjw-w232.json +++ b/advisories/unreviewed/2024/04/GHSA-5wrj-rjjw-w232/GHSA-5wrj-rjjw-w232.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5wrj-rjjw-w232", - "modified": "2024-04-23T15:30:36Z", + "modified": "2024-08-07T18:30:38Z", "published": "2024-04-23T15:30:36Z", "aliases": [ "CVE-2024-33217" ], "details": "Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter in ip/goform/addressNat.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-23T15:15:50Z" diff --git a/advisories/unreviewed/2024/06/GHSA-26v6-wwwv-j4cc/GHSA-26v6-wwwv-j4cc.json b/advisories/unreviewed/2024/06/GHSA-26v6-wwwv-j4cc/GHSA-26v6-wwwv-j4cc.json index 742de397809..77f189fa79b 100644 --- a/advisories/unreviewed/2024/06/GHSA-26v6-wwwv-j4cc/GHSA-26v6-wwwv-j4cc.json +++ b/advisories/unreviewed/2024/06/GHSA-26v6-wwwv-j4cc/GHSA-26v6-wwwv-j4cc.json @@ -1,14 +1,21 @@ { "schema_version": "1.4.0", "id": "GHSA-26v6-wwwv-j4cc", - "modified": "2024-06-12T18:30:41Z", + "modified": "2024-08-07T18:30:39Z", "published": "2024-06-12T18:30:41Z", "aliases": [ "CVE-2024-5909" ], "details": "A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber" + } ], "affected": [ @@ -27,7 +34,7 @@ "cwe_ids": [ "CWE-269" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-12T17:15:53Z" diff --git a/advisories/unreviewed/2024/06/GHSA-34w9-6vpg-vp3g/GHSA-34w9-6vpg-vp3g.json b/advisories/unreviewed/2024/06/GHSA-34w9-6vpg-vp3g/GHSA-34w9-6vpg-vp3g.json index 3f8c83a7439..e6ac8687aa4 100644 --- a/advisories/unreviewed/2024/06/GHSA-34w9-6vpg-vp3g/GHSA-34w9-6vpg-vp3g.json +++ b/advisories/unreviewed/2024/06/GHSA-34w9-6vpg-vp3g/GHSA-34w9-6vpg-vp3g.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-3chh-q8fx-pc2w/GHSA-3chh-q8fx-pc2w.json b/advisories/unreviewed/2024/06/GHSA-3chh-q8fx-pc2w/GHSA-3chh-q8fx-pc2w.json index b0c0514bebe..482451b3982 100644 --- a/advisories/unreviewed/2024/06/GHSA-3chh-q8fx-pc2w/GHSA-3chh-q8fx-pc2w.json +++ b/advisories/unreviewed/2024/06/GHSA-3chh-q8fx-pc2w/GHSA-3chh-q8fx-pc2w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3chh-q8fx-pc2w", - "modified": "2024-06-16T18:31:21Z", + "modified": "2024-08-07T18:30:40Z", "published": "2024-06-16T18:31:21Z", "aliases": [ "CVE-2024-38468" ], "details": "Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-640" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-16T16:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-4fmc-fv58-6r76/GHSA-4fmc-fv58-6r76.json b/advisories/unreviewed/2024/06/GHSA-4fmc-fv58-6r76/GHSA-4fmc-fv58-6r76.json index 177c7823bc5..fcb31685a71 100644 --- a/advisories/unreviewed/2024/06/GHSA-4fmc-fv58-6r76/GHSA-4fmc-fv58-6r76.json +++ b/advisories/unreviewed/2024/06/GHSA-4fmc-fv58-6r76/GHSA-4fmc-fv58-6r76.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-63x5-xm57-f2cw/GHSA-63x5-xm57-f2cw.json b/advisories/unreviewed/2024/06/GHSA-63x5-xm57-f2cw/GHSA-63x5-xm57-f2cw.json index ac471c8d52a..b2053484bf0 100644 --- a/advisories/unreviewed/2024/06/GHSA-63x5-xm57-f2cw/GHSA-63x5-xm57-f2cw.json +++ b/advisories/unreviewed/2024/06/GHSA-63x5-xm57-f2cw/GHSA-63x5-xm57-f2cw.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-6q37-cp6x-mhfw/GHSA-6q37-cp6x-mhfw.json b/advisories/unreviewed/2024/06/GHSA-6q37-cp6x-mhfw/GHSA-6q37-cp6x-mhfw.json index 1cc80232903..80d8144cc59 100644 --- a/advisories/unreviewed/2024/06/GHSA-6q37-cp6x-mhfw/GHSA-6q37-cp6x-mhfw.json +++ b/advisories/unreviewed/2024/06/GHSA-6q37-cp6x-mhfw/GHSA-6q37-cp6x-mhfw.json @@ -1,14 +1,21 @@ { "schema_version": "1.4.0", "id": "GHSA-6q37-cp6x-mhfw", - "modified": "2024-06-12T18:30:41Z", + "modified": "2024-08-07T18:30:39Z", "published": "2024-06-12T18:30:41Z", "aliases": [ "CVE-2024-5908" ], "details": "A problem with the Palo Alto Networks GlobalProtect app can result in exposure of encrypted user credentials, used for connecting to GlobalProtect, in application logs. Normally, these application logs are only viewable by local users and are included when generating logs for troubleshooting purposes. This means that these encrypted credentials are exposed to recipients of the application logs.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber" + } ], "affected": [ @@ -27,7 +34,7 @@ "cwe_ids": [ "CWE-532" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-12T17:15:53Z" diff --git a/advisories/unreviewed/2024/06/GHSA-7p4r-33p9-q666/GHSA-7p4r-33p9-q666.json b/advisories/unreviewed/2024/06/GHSA-7p4r-33p9-q666/GHSA-7p4r-33p9-q666.json index 16621ac59d6..4f5912bd3fb 100644 --- a/advisories/unreviewed/2024/06/GHSA-7p4r-33p9-q666/GHSA-7p4r-33p9-q666.json +++ b/advisories/unreviewed/2024/06/GHSA-7p4r-33p9-q666/GHSA-7p4r-33p9-q666.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7p4r-33p9-q666", - "modified": "2024-06-16T18:31:21Z", + "modified": "2024-08-07T18:30:40Z", "published": "2024-06-16T18:31:21Z", "aliases": [ "CVE-2024-38466" ], "details": "Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-16T16:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-82h5-9gw3-q456/GHSA-82h5-9gw3-q456.json b/advisories/unreviewed/2024/06/GHSA-82h5-9gw3-q456/GHSA-82h5-9gw3-q456.json index cc302fe5d80..454bf32b0cf 100644 --- a/advisories/unreviewed/2024/06/GHSA-82h5-9gw3-q456/GHSA-82h5-9gw3-q456.json +++ b/advisories/unreviewed/2024/06/GHSA-82h5-9gw3-q456/GHSA-82h5-9gw3-q456.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-82h5-9gw3-q456", - "modified": "2024-06-14T18:31:45Z", + "modified": "2024-08-07T18:30:40Z", "published": "2024-06-14T18:31:45Z", "aliases": [ "CVE-2024-24320" ], "details": "Directory Traversal vulnerability in Mgt-commerce CloudPanel v.2.0.0 thru v.2.4.0 allows a remote attacker to obtain sensitive information and execute arbitrary code via the service parameter of the load-logfiles function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-14T18:15:27Z" diff --git a/advisories/unreviewed/2024/06/GHSA-9v7r-qg2v-5vfc/GHSA-9v7r-qg2v-5vfc.json b/advisories/unreviewed/2024/06/GHSA-9v7r-qg2v-5vfc/GHSA-9v7r-qg2v-5vfc.json index f320dfd5202..9883ea3624a 100644 --- a/advisories/unreviewed/2024/06/GHSA-9v7r-qg2v-5vfc/GHSA-9v7r-qg2v-5vfc.json +++ b/advisories/unreviewed/2024/06/GHSA-9v7r-qg2v-5vfc/GHSA-9v7r-qg2v-5vfc.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-525" + "CWE-525", + "CWE-668" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-c8xv-94wg-v5h7/GHSA-c8xv-94wg-v5h7.json b/advisories/unreviewed/2024/06/GHSA-c8xv-94wg-v5h7/GHSA-c8xv-94wg-v5h7.json index 5aac3ef6ebd..67f4c17209c 100644 --- a/advisories/unreviewed/2024/06/GHSA-c8xv-94wg-v5h7/GHSA-c8xv-94wg-v5h7.json +++ b/advisories/unreviewed/2024/06/GHSA-c8xv-94wg-v5h7/GHSA-c8xv-94wg-v5h7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c8xv-94wg-v5h7", - "modified": "2024-06-13T21:30:52Z", + "modified": "2024-08-07T18:30:39Z", "published": "2024-06-13T21:30:52Z", "aliases": [ "CVE-2024-37635" ], "details": "TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiBasicCfg", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T19:15:52Z" diff --git a/advisories/unreviewed/2024/06/GHSA-ffh4-92gv-qvv5/GHSA-ffh4-92gv-qvv5.json b/advisories/unreviewed/2024/06/GHSA-ffh4-92gv-qvv5/GHSA-ffh4-92gv-qvv5.json index fa91740f8cd..939a0a403bb 100644 --- a/advisories/unreviewed/2024/06/GHSA-ffh4-92gv-qvv5/GHSA-ffh4-92gv-qvv5.json +++ b/advisories/unreviewed/2024/06/GHSA-ffh4-92gv-qvv5/GHSA-ffh4-92gv-qvv5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ffh4-92gv-qvv5", - "modified": "2024-06-13T21:30:53Z", + "modified": "2024-08-07T18:30:39Z", "published": "2024-06-13T21:30:53Z", "aliases": [ "CVE-2024-38312" ], "details": "When browsing private tabs, some data related to location history or webpage thumbnails could be persisted incorrectly within the sandboxed app bundle after app termination This vulnerability affects Firefox for iOS < 127.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T20:15:15Z" diff --git a/advisories/unreviewed/2024/06/GHSA-gf86-2hwm-rmxm/GHSA-gf86-2hwm-rmxm.json b/advisories/unreviewed/2024/06/GHSA-gf86-2hwm-rmxm/GHSA-gf86-2hwm-rmxm.json index 1d7c7635e95..a7a8249375d 100644 --- a/advisories/unreviewed/2024/06/GHSA-gf86-2hwm-rmxm/GHSA-gf86-2hwm-rmxm.json +++ b/advisories/unreviewed/2024/06/GHSA-gf86-2hwm-rmxm/GHSA-gf86-2hwm-rmxm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gf86-2hwm-rmxm", - "modified": "2024-06-16T18:31:21Z", + "modified": "2024-08-07T18:30:40Z", "published": "2024-06-16T18:31:21Z", "aliases": [ "CVE-2024-38465" ], "details": "Shenzhen Guoxin Synthesis image system before 8.3.0 allows username enumeration because of the response discrepancy of incorrect versus error.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-203" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-16T16:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-gh9j-f3p4-fwf2/GHSA-gh9j-f3p4-fwf2.json b/advisories/unreviewed/2024/06/GHSA-gh9j-f3p4-fwf2/GHSA-gh9j-f3p4-fwf2.json index 184f70b0bdc..389cf2443ec 100644 --- a/advisories/unreviewed/2024/06/GHSA-gh9j-f3p4-fwf2/GHSA-gh9j-f3p4-fwf2.json +++ b/advisories/unreviewed/2024/06/GHSA-gh9j-f3p4-fwf2/GHSA-gh9j-f3p4-fwf2.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-256" + "CWE-256", + "CWE-522" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-hmx2-hcwv-2chg/GHSA-hmx2-hcwv-2chg.json b/advisories/unreviewed/2024/06/GHSA-hmx2-hcwv-2chg/GHSA-hmx2-hcwv-2chg.json index 1fc3e8d3bf7..8fa9ae3f2d9 100644 --- a/advisories/unreviewed/2024/06/GHSA-hmx2-hcwv-2chg/GHSA-hmx2-hcwv-2chg.json +++ b/advisories/unreviewed/2024/06/GHSA-hmx2-hcwv-2chg/GHSA-hmx2-hcwv-2chg.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-qjwc-rqjc-76pj/GHSA-qjwc-rqjc-76pj.json b/advisories/unreviewed/2024/06/GHSA-qjwc-rqjc-76pj/GHSA-qjwc-rqjc-76pj.json index 27b15ddaddf..d1d83afe7b1 100644 --- a/advisories/unreviewed/2024/06/GHSA-qjwc-rqjc-76pj/GHSA-qjwc-rqjc-76pj.json +++ b/advisories/unreviewed/2024/06/GHSA-qjwc-rqjc-76pj/GHSA-qjwc-rqjc-76pj.json @@ -1,14 +1,21 @@ { "schema_version": "1.4.0", "id": "GHSA-qjwc-rqjc-76pj", - "modified": "2024-06-12T18:30:41Z", + "modified": "2024-08-07T18:30:38Z", "published": "2024-06-12T18:30:41Z", "aliases": [ "CVE-2024-5905" ], "details": "A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local low privileged Windows user to disrupt some functionality of the agent. However, they are not able to disrupt Cortex XDR agent protection mechanisms using this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:D/RE:M/U:Amber" + } ], "affected": [ @@ -27,7 +34,7 @@ "cwe_ids": [ "CWE-346" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-12T17:15:52Z" diff --git a/advisories/unreviewed/2024/06/GHSA-vh98-48jw-fxwj/GHSA-vh98-48jw-fxwj.json b/advisories/unreviewed/2024/06/GHSA-vh98-48jw-fxwj/GHSA-vh98-48jw-fxwj.json index e16af64303c..4ceb82b603c 100644 --- a/advisories/unreviewed/2024/06/GHSA-vh98-48jw-fxwj/GHSA-vh98-48jw-fxwj.json +++ b/advisories/unreviewed/2024/06/GHSA-vh98-48jw-fxwj/GHSA-vh98-48jw-fxwj.json @@ -1,14 +1,21 @@ { "schema_version": "1.4.0", "id": "GHSA-vh98-48jw-fxwj", - "modified": "2024-06-12T18:30:41Z", + "modified": "2024-08-07T18:30:39Z", "published": "2024-06-12T18:30:41Z", "aliases": [ "CVE-2024-5907" ], "details": "A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with elevated privileges. However, execution does require the local user to successfully exploit a race condition, which makes this vulnerability difficult to exploit.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber" + } ], "affected": [ @@ -27,7 +34,7 @@ "cwe_ids": [ "CWE-269" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-12T17:15:53Z" diff --git a/advisories/unreviewed/2024/06/GHSA-whj9-g8q3-623p/GHSA-whj9-g8q3-623p.json b/advisories/unreviewed/2024/06/GHSA-whj9-g8q3-623p/GHSA-whj9-g8q3-623p.json index 14867e2c243..16f24505d29 100644 --- a/advisories/unreviewed/2024/06/GHSA-whj9-g8q3-623p/GHSA-whj9-g8q3-623p.json +++ b/advisories/unreviewed/2024/06/GHSA-whj9-g8q3-623p/GHSA-whj9-g8q3-623p.json @@ -1,14 +1,21 @@ { "schema_version": "1.4.0", "id": "GHSA-whj9-g8q3-623p", - "modified": "2024-06-12T18:30:41Z", + "modified": "2024-08-07T18:30:38Z", "published": "2024-06-12T18:30:41Z", "aliases": [ "CVE-2024-5906" ], "details": "A cross-site scripting (XSS) vulnerability in Palo Alto Networks Prisma Cloud Compute software enables a malicious administrator with add/edit permissions for identity providers to store a JavaScript payload using the web interface on Prisma Cloud Compute. This enables a malicious administrator to perform actions in the context of another user's browser when accessed by that other user.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:Amber" + } ], "affected": [ @@ -27,7 +34,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-12T17:15:53Z" diff --git a/advisories/unreviewed/2024/06/GHSA-x9fg-8gx4-j4x2/GHSA-x9fg-8gx4-j4x2.json b/advisories/unreviewed/2024/06/GHSA-x9fg-8gx4-j4x2/GHSA-x9fg-8gx4-j4x2.json index ead6eb65db0..1b7a5206c72 100644 --- a/advisories/unreviewed/2024/06/GHSA-x9fg-8gx4-j4x2/GHSA-x9fg-8gx4-j4x2.json +++ b/advisories/unreviewed/2024/06/GHSA-x9fg-8gx4-j4x2/GHSA-x9fg-8gx4-j4x2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x9fg-8gx4-j4x2", - "modified": "2024-06-20T18:34:09Z", + "modified": "2024-08-07T18:30:40Z", "published": "2024-06-20T18:34:09Z", "aliases": [ "CVE-2024-37348" diff --git a/advisories/unreviewed/2024/07/GHSA-79hg-h6r6-64mm/GHSA-79hg-h6r6-64mm.json b/advisories/unreviewed/2024/07/GHSA-79hg-h6r6-64mm/GHSA-79hg-h6r6-64mm.json index 3feaba99b6b..37fdb6a1e2c 100644 --- a/advisories/unreviewed/2024/07/GHSA-79hg-h6r6-64mm/GHSA-79hg-h6r6-64mm.json +++ b/advisories/unreviewed/2024/07/GHSA-79hg-h6r6-64mm/GHSA-79hg-h6r6-64mm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-79hg-h6r6-64mm", - "modified": "2024-08-07T06:31:09Z", + "modified": "2024-08-07T18:30:40Z", "published": "2024-07-08T18:31:18Z", "aliases": [ "CVE-2024-6409" @@ -65,6 +65,10 @@ "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-6409" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4960" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:4955" diff --git a/advisories/unreviewed/2024/07/GHSA-vpjf-pg9h-vm9f/GHSA-vpjf-pg9h-vm9f.json b/advisories/unreviewed/2024/07/GHSA-vpjf-pg9h-vm9f/GHSA-vpjf-pg9h-vm9f.json index cf0107b8d4d..e3f2c0d2431 100644 --- a/advisories/unreviewed/2024/07/GHSA-vpjf-pg9h-vm9f/GHSA-vpjf-pg9h-vm9f.json +++ b/advisories/unreviewed/2024/07/GHSA-vpjf-pg9h-vm9f/GHSA-vpjf-pg9h-vm9f.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-187" + "CWE-187", + "CWE-697" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-2pv9-pqcj-rmfm/GHSA-2pv9-pqcj-rmfm.json b/advisories/unreviewed/2024/08/GHSA-2pv9-pqcj-rmfm/GHSA-2pv9-pqcj-rmfm.json new file mode 100644 index 00000000000..eaf8f04de87 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2pv9-pqcj-rmfm/GHSA-2pv9-pqcj-rmfm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2pv9-pqcj-rmfm", + "modified": "2024-08-07T18:30:42Z", + "published": "2024-08-07T18:30:42Z", + "aliases": [ + "CVE-2024-34480" + ], + "details": "SourceCodester Computer Laboratory Management System 1.0 allows admin/category/view_category.php id SQL Injection.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34480" + }, + { + "type": "WEB", + "url": "https://cxsecurity.com/issue/WLB-2024080003" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-2rr5-68hg-rwmh/GHSA-2rr5-68hg-rwmh.json b/advisories/unreviewed/2024/08/GHSA-2rr5-68hg-rwmh/GHSA-2rr5-68hg-rwmh.json new file mode 100644 index 00000000000..84634361ff1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2rr5-68hg-rwmh/GHSA-2rr5-68hg-rwmh.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rr5-68hg-rwmh", + "modified": "2024-08-07T18:30:43Z", + "published": "2024-08-07T18:30:43Z", + "aliases": [ + "CVE-2024-42233" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfilemap: replace pte_offset_map() with pte_offset_map_nolock()\n\nThe vmf->ptl in filemap_fault_recheck_pte_none() is still set from\nhandle_pte_fault(). But at the same time, we did a pte_unmap(vmf->pte). \nAfter a pte_unmap(vmf->pte) unmap and rcu_read_unlock(), the page table\nmay be racily changed and vmf->ptl maybe fails to protect the actual page\ntable. Fix this by replacing pte_offset_map() with\npte_offset_map_nolock().\n\nAs David said, the PTL pointer might be stale so if we continue to use\nit infilemap_fault_recheck_pte_none(), it might trigger UAF. Also, if\nthe PTL fails, the issue fixed by commit 58f327f2ce80 (\"filemap: avoid\nunnecessary major faults in filemap_fault()\") might reappear.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42233" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/24be02a42181f0707be0498045c4c4b13273b16d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6a6c2aec1a89506595801b4cf7e8eef035f33748" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-366c-rrqj-7gmp/GHSA-366c-rrqj-7gmp.json b/advisories/unreviewed/2024/08/GHSA-366c-rrqj-7gmp/GHSA-366c-rrqj-7gmp.json index d768b9fdfa5..628fbebc91f 100644 --- a/advisories/unreviewed/2024/08/GHSA-366c-rrqj-7gmp/GHSA-366c-rrqj-7gmp.json +++ b/advisories/unreviewed/2024/08/GHSA-366c-rrqj-7gmp/GHSA-366c-rrqj-7gmp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-366c-rrqj-7gmp", - "modified": "2024-08-06T18:30:57Z", + "modified": "2024-08-07T18:30:41Z", "published": "2024-08-06T18:30:57Z", "aliases": [ "CVE-2024-6994" ], "details": "Heap buffer overflow in Layout in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T16:15:50Z" diff --git a/advisories/unreviewed/2024/08/GHSA-3gj8-mpqg-gqrv/GHSA-3gj8-mpqg-gqrv.json b/advisories/unreviewed/2024/08/GHSA-3gj8-mpqg-gqrv/GHSA-3gj8-mpqg-gqrv.json new file mode 100644 index 00000000000..447844ed5f4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3gj8-mpqg-gqrv/GHSA-3gj8-mpqg-gqrv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gj8-mpqg-gqrv", + "modified": "2024-08-07T18:30:44Z", + "published": "2024-08-07T18:30:44Z", + "aliases": [ + "CVE-2024-20451" + ], + "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly.\n\nThese vulnerabilities exist because HTTP packets are not properly checked for errors. An attacker could exploit this vulnerability by sending a crafted HTTP packet to the remote interface of an affected device. A successful exploit could allow the attacker to cause a DoS condition on the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20451" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-spa-http-vulns-RJZmX2Xz" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-474x-3vv5-5q3g/GHSA-474x-3vv5-5q3g.json b/advisories/unreviewed/2024/08/GHSA-474x-3vv5-5q3g/GHSA-474x-3vv5-5q3g.json new file mode 100644 index 00000000000..fdf94209240 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-474x-3vv5-5q3g/GHSA-474x-3vv5-5q3g.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-474x-3vv5-5q3g", + "modified": "2024-08-07T18:30:44Z", + "published": "2024-08-07T18:30:44Z", + "aliases": [ + "CVE-2024-41242" + ], + "details": "A Reflected Cross Site Scripting (XSS) vulnerability was found in /smsa/student_login.php in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via \"error\" parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41242" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Responsive%20School%20Management%20System%20v3.2.0/Reflected%20XSS%20-%20Student.pdf" + }, + { + "type": "WEB", + "url": "https://www.kashipara.com/project/php/12362/responsive-school-management-system-php-project-source-code" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T18:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4c65-phqf-cq3w/GHSA-4c65-phqf-cq3w.json b/advisories/unreviewed/2024/08/GHSA-4c65-phqf-cq3w/GHSA-4c65-phqf-cq3w.json index 12ded5c347f..d74e1d1336f 100644 --- a/advisories/unreviewed/2024/08/GHSA-4c65-phqf-cq3w/GHSA-4c65-phqf-cq3w.json +++ b/advisories/unreviewed/2024/08/GHSA-4c65-phqf-cq3w/GHSA-4c65-phqf-cq3w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4c65-phqf-cq3w", - "modified": "2024-08-06T21:30:48Z", + "modified": "2024-08-07T18:30:42Z", "published": "2024-08-06T21:30:47Z", "aliases": [ "CVE-2024-7532" ], "details": "Out of bounds memory access in ANGLE in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T21:16:03Z" diff --git a/advisories/unreviewed/2024/08/GHSA-4cpx-q734-j233/GHSA-4cpx-q734-j233.json b/advisories/unreviewed/2024/08/GHSA-4cpx-q734-j233/GHSA-4cpx-q734-j233.json index cfe43b68d27..3bfec39f85d 100644 --- a/advisories/unreviewed/2024/08/GHSA-4cpx-q734-j233/GHSA-4cpx-q734-j233.json +++ b/advisories/unreviewed/2024/08/GHSA-4cpx-q734-j233/GHSA-4cpx-q734-j233.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4cpx-q734-j233", - "modified": "2024-08-03T21:30:34Z", + "modified": "2024-08-07T18:30:41Z", "published": "2024-08-02T15:31:19Z", "aliases": [ "CVE-2024-38890" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38890" }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/179892/Caterease-Software-SQL-Injection-Command-Injection-Bypass.html" + }, { "type": "WEB", "url": "https://vuldb.com/?id.273374" diff --git a/advisories/unreviewed/2024/08/GHSA-4r77-5qxj-vjjj/GHSA-4r77-5qxj-vjjj.json b/advisories/unreviewed/2024/08/GHSA-4r77-5qxj-vjjj/GHSA-4r77-5qxj-vjjj.json index db083af7086..524f1d7d86e 100644 --- a/advisories/unreviewed/2024/08/GHSA-4r77-5qxj-vjjj/GHSA-4r77-5qxj-vjjj.json +++ b/advisories/unreviewed/2024/08/GHSA-4r77-5qxj-vjjj/GHSA-4r77-5qxj-vjjj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4r77-5qxj-vjjj", - "modified": "2024-08-06T15:30:54Z", + "modified": "2024-08-07T18:30:41Z", "published": "2024-08-06T15:30:54Z", "aliases": [ "CVE-2023-40819" ], "details": "ID4Portais in version < V.2022.837.002a returns message parameter unsanitized in the response, resulting in a HTML Injection vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-233" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T14:16:03Z" diff --git a/advisories/unreviewed/2024/08/GHSA-4vx7-xmpj-mhxm/GHSA-4vx7-xmpj-mhxm.json b/advisories/unreviewed/2024/08/GHSA-4vx7-xmpj-mhxm/GHSA-4vx7-xmpj-mhxm.json new file mode 100644 index 00000000000..a63dbab2e4b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4vx7-xmpj-mhxm/GHSA-4vx7-xmpj-mhxm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vx7-xmpj-mhxm", + "modified": "2024-08-07T18:30:42Z", + "published": "2024-08-07T18:30:42Z", + "aliases": [ + "CVE-2024-41247" + ], + "details": "An Incorrect Access Control vulnerability was found in /smsa/add_class.php and /smsa/add_class_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to add a new class entry.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41247" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Responsive%20School%20Management%20System%20v3.2.0/Broken%20Access%20Control%20-%20Admin%20Master%20-%20Add%20Classes.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-54w4-6j43-whvq/GHSA-54w4-6j43-whvq.json b/advisories/unreviewed/2024/08/GHSA-54w4-6j43-whvq/GHSA-54w4-6j43-whvq.json new file mode 100644 index 00000000000..e399d42fd42 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-54w4-6j43-whvq/GHSA-54w4-6j43-whvq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54w4-6j43-whvq", + "modified": "2024-08-07T18:30:44Z", + "published": "2024-08-07T18:30:44Z", + "aliases": [ + "CVE-2024-41244" + ], + "details": "An Incorrect Access Control vulnerability was found in /smsa/view_class.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view CLASS details.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41244" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Responsive%20School%20Management%20System%20v3.2.0/Broken%20Access%20Control%20-%20Admin%20-%20View%20Class.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-557r-rm2w-qvrj/GHSA-557r-rm2w-qvrj.json b/advisories/unreviewed/2024/08/GHSA-557r-rm2w-qvrj/GHSA-557r-rm2w-qvrj.json new file mode 100644 index 00000000000..b9901df8cfc --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-557r-rm2w-qvrj/GHSA-557r-rm2w-qvrj.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-557r-rm2w-qvrj", + "modified": "2024-08-07T18:30:43Z", + "published": "2024-08-07T18:30:43Z", + "aliases": [ + "CVE-2024-42236" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: configfs: Prevent OOB read/write in usb_string_copy()\n\nUserspace provided string 's' could trivially have the length zero. Left\nunchecked this will firstly result in an OOB read in the form\n`if (str[0 - 1] == '\\n') followed closely by an OOB write in the form\n`str[0 - 1] = '\\0'`.\n\nThere is already a validating check to catch strings that are too long.\nLet's supply an additional check for invalid strings that are too short.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42236" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2d16f63d8030903e5031853e79d731ee5d474e70" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6d3c721e686ea6c59e18289b400cc95c76e927e0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/72b8ee0d9826e8ed00e0bdfce3e46b98419b37ce" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a444c3fc264119801575ab086e03fb4952f23fd0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c95fbdde87e39e5e0ae27f28bf6711edfb985caa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d1205033e912f9332c1dbefa812e6ceb0575ce0a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e8474a10c535e6a2024c3b06e37e4a3a23beb490" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/eecfefad0953b2f31aaefa058f7f348ff39c4bba" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5f4q-cvpm-g6rh/GHSA-5f4q-cvpm-g6rh.json b/advisories/unreviewed/2024/08/GHSA-5f4q-cvpm-g6rh/GHSA-5f4q-cvpm-g6rh.json new file mode 100644 index 00000000000..66cbdeba14f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5f4q-cvpm-g6rh/GHSA-5f4q-cvpm-g6rh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5f4q-cvpm-g6rh", + "modified": "2024-08-07T18:30:44Z", + "published": "2024-08-07T18:30:44Z", + "aliases": [ + "CVE-2024-20454" + ], + "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system with root privileges.\n\nThese vulnerabilities exist because incoming HTTP packets are not properly checked for errors, which could result in a buffer overflow. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to overflow an internal buffer and execute arbitrary commands at the root privilege level.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20454" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-spa-http-vulns-RJZmX2Xz" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5hgw-6w8f-3f58/GHSA-5hgw-6w8f-3f58.json b/advisories/unreviewed/2024/08/GHSA-5hgw-6w8f-3f58/GHSA-5hgw-6w8f-3f58.json new file mode 100644 index 00000000000..0ea0382305e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5hgw-6w8f-3f58/GHSA-5hgw-6w8f-3f58.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hgw-6w8f-3f58", + "modified": "2024-08-07T18:30:44Z", + "published": "2024-08-07T18:30:44Z", + "aliases": [ + "CVE-2024-41245" + ], + "details": "An Incorrect Access Control vulnerability was found in /smsa/view_teachers.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view TEACHER details.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41245" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Responsive%20School%20Management%20System%20v3.2.0/Broken%20Access%20Control%20-%20Admin%20-%20View%20Teachers.pdf" + }, + { + "type": "WEB", + "url": "https://www.kashipara.com/project/php/12362/responsive-school-management-system-php-project-source-code" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5vqw-wppf-x433/GHSA-5vqw-wppf-x433.json b/advisories/unreviewed/2024/08/GHSA-5vqw-wppf-x433/GHSA-5vqw-wppf-x433.json new file mode 100644 index 00000000000..fd3e834bfc1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5vqw-wppf-x433/GHSA-5vqw-wppf-x433.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vqw-wppf-x433", + "modified": "2024-08-07T18:30:43Z", + "published": "2024-08-07T18:30:43Z", + "aliases": [ + "CVE-2024-42232" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: fix race between delayed_work() and ceph_monc_stop()\n\nThe way the delayed work is handled in ceph_monc_stop() is prone to\nraces with mon_fault() and possibly also finish_hunting(). Both of\nthese can requeue the delayed work which wouldn't be canceled by any of\nthe following code in case that happens after cancel_delayed_work_sync()\nruns -- __close_session() doesn't mess with the delayed work in order\nto avoid interfering with the hunting interval logic. This part was\nmissed in commit b5d91704f53e (\"libceph: behave in mon_fault() if\ncur_mon < 0\") and use-after-free can still ensue on monc and objects\nthat hang off of it, with monc->auth and monc->monmap being\nparticularly susceptible to quickly being reused.\n\nTo fix this:\n\n- clear monc->cur_mon and monc->hunting as part of closing the session\n in ceph_monc_stop()\n- bail from delayed_work() if monc->cur_mon is cleared, similar to how\n it's done in mon_fault() and finish_hunting() (based on monc->hunting)\n- call cancel_delayed_work_sync() after the session is closed", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42232" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1177afeca833174ba83504688eec898c6214f4bf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/20cf67dcb7db842f941eff1af6ee5e9dc41796d7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2d33654d40a05afd91ab24c9a73ab512a0670a9a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/33d38c5da17f8db2d80e811b7829d2822c10625e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/34b76d1922e41da1fa73d43b764cddd82ac9733c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/63e5d035e3a7ab7412a008f202633c5e6a0a28ea" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/69c7b2fe4c9cc1d3b1186d1c5606627ecf0de883" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9525af1f58f67df387768770fcf6d6a8f23aee3d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-63v5-86j4-m83w/GHSA-63v5-86j4-m83w.json b/advisories/unreviewed/2024/08/GHSA-63v5-86j4-m83w/GHSA-63v5-86j4-m83w.json new file mode 100644 index 00000000000..b7519ad0a5e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-63v5-86j4-m83w/GHSA-63v5-86j4-m83w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63v5-86j4-m83w", + "modified": "2024-08-07T18:30:44Z", + "published": "2024-08-07T18:30:44Z", + "aliases": [ + "CVE-2024-20450" + ], + "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system with root privileges.\n\nThese vulnerabilities exist because incoming HTTP packets are not properly checked for errors, which could result in a buffer overflow. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to overflow an internal buffer and execute arbitrary commands at the root privilege level.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20450" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-spa-http-vulns-RJZmX2Xz" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-698w-c48m-rgg8/GHSA-698w-c48m-rgg8.json b/advisories/unreviewed/2024/08/GHSA-698w-c48m-rgg8/GHSA-698w-c48m-rgg8.json new file mode 100644 index 00000000000..a1a60ae3426 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-698w-c48m-rgg8/GHSA-698w-c48m-rgg8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-698w-c48m-rgg8", + "modified": "2024-08-07T18:30:42Z", + "published": "2024-08-07T18:30:42Z", + "aliases": [ + "CVE-2024-34479" + ], + "details": "SourceCodester Computer Laboratory Management System 1.0 allows classes/Master.php id SQL Injection.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34479" + }, + { + "type": "WEB", + "url": "https://cxsecurity.com/issue/WLB-2024080004" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6p6f-gc59-4w3f/GHSA-6p6f-gc59-4w3f.json b/advisories/unreviewed/2024/08/GHSA-6p6f-gc59-4w3f/GHSA-6p6f-gc59-4w3f.json new file mode 100644 index 00000000000..9ce422a28bc --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6p6f-gc59-4w3f/GHSA-6p6f-gc59-4w3f.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6p6f-gc59-4w3f", + "modified": "2024-08-07T18:30:43Z", + "published": "2024-08-07T18:30:43Z", + "aliases": [ + "CVE-2024-42234" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: fix crashes from deferred split racing folio migration\n\nEven on 6.10-rc6, I've been seeing elusive \"Bad page state\"s (often on\nflags when freeing, yet the flags shown are not bad: PG_locked had been\nset and cleared??), and VM_BUG_ON_PAGE(page_ref_count(page) == 0)s from\ndeferred_split_scan()'s folio_put(), and a variety of other BUG and WARN\nsymptoms implying double free by deferred split and large folio migration.\n\n6.7 commit 9bcef5973e31 (\"mm: memcg: fix split queue list crash when large\nfolio migration\") was right to fix the memcg-dependent locking broken in\n85ce2c517ade (\"memcontrol: only transfer the memcg data for migration\"),\nbut missed a subtlety of deferred_split_scan(): it moves folios to its own\nlocal list to work on them without split_queue_lock, during which time\nfolio->_deferred_list is not empty, but even the \"right\" lock does nothing\nto secure the folio and the list it is on.\n\nFortunately, deferred_split_scan() is careful to use folio_try_get(): so\nfolio_migrate_mapping() can avoid the race by folio_undo_large_rmappable()\nwhile the old folio's reference count is temporarily frozen to 0 - adding\nsuch a freeze in the !mapping case too (originally, folio lock and\nunmapping and no swap cache left an anon folio unreachable, so no freezing\nwas needed there: but the deferred split queue offers a way to reach it).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42234" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/be9581ea8c058d81154251cb0695987098996cad" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fc7facce686b64201dbf0b9614cc1d0bfad70010" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6pq6-pgx4-rhpr/GHSA-6pq6-pgx4-rhpr.json b/advisories/unreviewed/2024/08/GHSA-6pq6-pgx4-rhpr/GHSA-6pq6-pgx4-rhpr.json index 5a1b1252a64..c2b2d0f5922 100644 --- a/advisories/unreviewed/2024/08/GHSA-6pq6-pgx4-rhpr/GHSA-6pq6-pgx4-rhpr.json +++ b/advisories/unreviewed/2024/08/GHSA-6pq6-pgx4-rhpr/GHSA-6pq6-pgx4-rhpr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6pq6-pgx4-rhpr", - "modified": "2024-08-03T21:30:34Z", + "modified": "2024-08-07T18:30:41Z", "published": "2024-08-02T18:31:12Z", "aliases": [ "CVE-2024-38883" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38883" }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/179892/Caterease-Software-SQL-Injection-Command-Injection-Bypass.html" + }, { "type": "WEB", "url": "https://vuldb.com/?id.273367" diff --git a/advisories/unreviewed/2024/08/GHSA-762p-xx25-g6mq/GHSA-762p-xx25-g6mq.json b/advisories/unreviewed/2024/08/GHSA-762p-xx25-g6mq/GHSA-762p-xx25-g6mq.json new file mode 100644 index 00000000000..f99054966d3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-762p-xx25-g6mq/GHSA-762p-xx25-g6mq.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-762p-xx25-g6mq", + "modified": "2024-08-07T18:30:44Z", + "published": "2024-08-07T18:30:44Z", + "aliases": [ + "CVE-2024-42245" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRevert \"sched/fair: Make sure to try to detach at least one movable task\"\n\nThis reverts commit b0defa7ae03ecf91b8bfd10ede430cff12fcbd06.\n\nb0defa7ae03ec changed the load balancing logic to ignore env.max_loop if\nall tasks examined to that point were pinned. The goal of the patch was\nto make it more likely to be able to detach a task buried in a long list\nof pinned tasks. However, this has the unfortunate side effect of\ncreating an O(n) iteration in detach_tasks(), as we now must fully\niterate every task on a cpu if all or most are pinned. Since this load\nbalance code is done with rq lock held, and often in softirq context, it\nis very easy to trigger hard lockups. We observed such hard lockups with\na user who affined O(10k) threads to a single cpu.\n\nWhen I discussed this with Vincent he initially suggested that we keep\nthe limit on the number of tasks to detach, but increase the number of\ntasks we can search. However, after some back and forth on the mailing\nlist, he recommended we instead revert the original patch, as it seems\nlikely no one was actually getting hit by the original issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42245" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0fa6dcbfa2e2b97c1e6febbea561badf0931a38b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1e116c18e32b035a2d1bd460800072c8bf96bc44" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2feab2492deb2f14f9675dd6388e9e2bf669c27a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d467194018dd536fe6c65a2fd3aedfcdb1424903" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7j6j-8jww-jc3g/GHSA-7j6j-8jww-jc3g.json b/advisories/unreviewed/2024/08/GHSA-7j6j-8jww-jc3g/GHSA-7j6j-8jww-jc3g.json new file mode 100644 index 00000000000..d90758383db --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7j6j-8jww-jc3g/GHSA-7j6j-8jww-jc3g.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7j6j-8jww-jc3g", + "modified": "2024-08-07T18:30:43Z", + "published": "2024-08-07T18:30:43Z", + "aliases": [ + "CVE-2024-42243" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/filemap: make MAX_PAGECACHE_ORDER acceptable to xarray\n\nPatch series \"mm/filemap: Limit page cache size to that supported by\nxarray\", v2.\n\nCurrently, xarray can't support arbitrary page cache size. More details\ncan be found from the WARN_ON() statement in xas_split_alloc(). In our\ntest whose code is attached below, we hit the WARN_ON() on ARM64 system\nwhere the base page size is 64KB and huge page size is 512MB. The issue\nwas reported long time ago and some discussions on it can be found here\n[1].\n\n[1] https://www.spinics.net/lists/linux-xfs/msg75404.html\n\nIn order to fix the issue, we need to adjust MAX_PAGECACHE_ORDER to one\nsupported by xarray and avoid PMD-sized page cache if needed. The code\nchanges are suggested by David Hildenbrand.\n\nPATCH[1] adjusts MAX_PAGECACHE_ORDER to that supported by xarray\nPATCH[2-3] avoids PMD-sized page cache in the synchronous readahead path\nPATCH[4] avoids PMD-sized page cache for shmem files if needed\n\nTest program\n============\n# cat test.c\n#define _GNU_SOURCE\n#include \n#include \n#include \n#include \n#include \n#include \n#include \n#include \n\n#define TEST_XFS_FILENAME\t\"/tmp/data\"\n#define TEST_SHMEM_FILENAME\t\"/dev/shm/data\"\n#define TEST_MEM_SIZE\t\t0x20000000\n\nint main(int argc, char **argv)\n{\n\tconst char *filename;\n\tint fd = 0;\n\tvoid *buf = (void *)-1, *p;\n\tint pgsize = getpagesize();\n\tint ret;\n\n\tif (pgsize != 0x10000) {\n\t\tfprintf(stderr, \"64KB base page size is required\\n\");\n\t\treturn -EPERM;\n\t}\n\n\tsystem(\"echo force > /sys/kernel/mm/transparent_hugepage/shmem_enabled\");\n\tsystem(\"rm -fr /tmp/data\");\n\tsystem(\"rm -fr /dev/shm/data\");\n\tsystem(\"echo 1 > /proc/sys/vm/drop_caches\");\n\n\t/* Open xfs or shmem file */\n\tfilename = TEST_XFS_FILENAME;\n\tif (argc > 1 && !strcmp(argv[1], \"shmem\"))\n\t\tfilename = TEST_SHMEM_FILENAME;\n\n\tfd = open(filename, O_CREAT | O_RDWR | O_TRUNC);\n\tif (fd < 0) {\n\t\tfprintf(stderr, \"Unable to open <%s>\\n\", filename);\n\t\treturn -EIO;\n\t}\n\n\t/* Extend file size */\n\tret = ftruncate(fd, TEST_MEM_SIZE);\n\tif (ret) {\n\t\tfprintf(stderr, \"Error %d to ftruncate()\\n\", ret);\n\t\tgoto cleanup;\n\t}\n\n\t/* Create VMA */\n\tbuf = mmap(NULL, TEST_MEM_SIZE,\n\t\t PROT_READ | PROT_WRITE, MAP_SHARED, fd, 0);\n\tif (buf == (void *)-1) {\n\t\tfprintf(stderr, \"Unable to mmap <%s>\\n\", filename);\n\t\tgoto cleanup;\n\t}\n\n\tfprintf(stdout, \"mapped buffer at 0x%p\\n\", buf);\n\tret = madvise(buf, TEST_MEM_SIZE, MADV_HUGEPAGE);\n if (ret) {\n\t\tfprintf(stderr, \"Unable to madvise(MADV_HUGEPAGE)\\n\");\n\t\tgoto cleanup;\n\t}\n\n\t/* Populate VMA */\n\tret = madvise(buf, TEST_MEM_SIZE, MADV_POPULATE_WRITE);\n\tif (ret) {\n\t\tfprintf(stderr, \"Error %d to madvise(MADV_POPULATE_WRITE)\\n\", ret);\n\t\tgoto cleanup;\n\t}\n\n\t/* Punch the file to enforce xarray split */\n\tret = fallocate(fd, FALLOC_FL_KEEP_SIZE | FALLOC_FL_PUNCH_HOLE,\n \t\tTEST_MEM_SIZE - pgsize, pgsize);\n\tif (ret)\n\t\tfprintf(stderr, \"Error %d to fallocate()\\n\", ret);\n\ncleanup:\n\tif (buf != (void *)-1)\n\t\tmunmap(buf, TEST_MEM_SIZE);\n\tif (fd > 0)\n\t\tclose(fd);\n\n\treturn 0;\n}\n\n# gcc test.c -o test\n# cat /proc/1/smaps | grep KernelPageSize | head -n 1\nKernelPageSize: 64 kB\n# ./test shmem\n :\n------------[ cut here ]------------\nWARNING: CPU: 17 PID: 5253 at lib/xarray.c:1025 xas_split_alloc+0xf8/0x128\nModules linked in: nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib \\\nnft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct \\\nnft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 \\\nip_set nf_tables rfkill nfnetlink vfat fat virtio_balloon \\\ndrm fuse xfs libcrc32c crct10dif_ce ghash_ce sha2_ce sha256_arm64 \\\nvirtio_net sha1_ce net_failover failover virtio_console virtio_blk \\\ndimlib virtio_mmio\nCPU: 17 PID: 5253 Comm: test Kdump: loaded Tainted: G W 6.10.0-rc5-gavin+ #12\nHardware name: QEMU KVM Virtual Machine, BIOS edk2-20240524-1.el9 05/24/2024\npstate: 83400005 (Nzcv daif +PAN -UAO +TC\n---truncated---", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42243" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/099d90642a711caae377f53309abfe27e8724a8b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/333c5539a31f48828456aa9997ec2808f06a699a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a0c42ddd0969fdc760a85e20e267776028a7ca4e" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7pp9-59r6-x3f6/GHSA-7pp9-59r6-x3f6.json b/advisories/unreviewed/2024/08/GHSA-7pp9-59r6-x3f6/GHSA-7pp9-59r6-x3f6.json index 82359965876..3b724c35f29 100644 --- a/advisories/unreviewed/2024/08/GHSA-7pp9-59r6-x3f6/GHSA-7pp9-59r6-x3f6.json +++ b/advisories/unreviewed/2024/08/GHSA-7pp9-59r6-x3f6/GHSA-7pp9-59r6-x3f6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7pp9-59r6-x3f6", - "modified": "2024-08-02T18:31:10Z", + "modified": "2024-08-07T18:30:41Z", "published": "2024-08-02T18:31:10Z", "aliases": [ "CVE-2024-41518" ], "details": "An Incorrect Access Control vulnerability in \"/admin/programm//export/statistics\" in Feripro <= v2.2.3 allows remote attackers to export an XLSX file with information about registrations and participants.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-02T17:16:38Z" diff --git a/advisories/unreviewed/2024/08/GHSA-868h-v466-p6jj/GHSA-868h-v466-p6jj.json b/advisories/unreviewed/2024/08/GHSA-868h-v466-p6jj/GHSA-868h-v466-p6jj.json new file mode 100644 index 00000000000..7c151e687dd --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-868h-v466-p6jj/GHSA-868h-v466-p6jj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-868h-v466-p6jj", + "modified": "2024-08-07T18:30:44Z", + "published": "2024-08-07T18:30:44Z", + "aliases": [ + "CVE-2024-20443" + ], + "details": "A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.\n\nThis vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have at least a low-privileged account on an affected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20443" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xss-V2bm9JCY" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-899c-qvc8-9hpp/GHSA-899c-qvc8-9hpp.json b/advisories/unreviewed/2024/08/GHSA-899c-qvc8-9hpp/GHSA-899c-qvc8-9hpp.json new file mode 100644 index 00000000000..9d563f04829 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-899c-qvc8-9hpp/GHSA-899c-qvc8-9hpp.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-899c-qvc8-9hpp", + "modified": "2024-08-07T18:30:44Z", + "published": "2024-08-07T18:30:44Z", + "aliases": [ + "CVE-2024-42246" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet, sunrpc: Remap EPERM in case of connection failure in xs_tcp_setup_socket\n\nWhen using a BPF program on kernel_connect(), the call can return -EPERM. This\ncauses xs_tcp_setup_socket() to loop forever, filling up the syslog and causing\nthe kernel to potentially freeze up.\n\nNeil suggested:\n\n This will propagate -EPERM up into other layers which might not be ready\n to handle it. It might be safer to map EPERM to an error we would be more\n likely to expect from the network system - such as ECONNREFUSED or ENETDOWN.\n\nECONNREFUSED as error seems reasonable. For programs setting a different error\ncan be out of reach (see handling in 4fbac77d2d09) in particular on kernels\nwhich do not have f10d05966196 (\"bpf: Make BPF_PROG_RUN_ARRAY return -err\ninstead of allow boolean\"), thus given that it is better to simply remap for\nconsistent behavior. UDP does handle EPERM in xs_udp_send_request().", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42246" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/626dfed5fa3bfb41e0dffd796032b555b69f9cde" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d6c686c01c5f12ff8f7264e0ddf71df6cb0d4414" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f2431e7db0fe0daccb2f06bb0d23740affcd2fa6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f388cfd913a2b96c05339a335f365795db1b36b6" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-8j3m-968h-m85q/GHSA-8j3m-968h-m85q.json b/advisories/unreviewed/2024/08/GHSA-8j3m-968h-m85q/GHSA-8j3m-968h-m85q.json index ba0b7a5778a..94f6c099e24 100644 --- a/advisories/unreviewed/2024/08/GHSA-8j3m-968h-m85q/GHSA-8j3m-968h-m85q.json +++ b/advisories/unreviewed/2024/08/GHSA-8j3m-968h-m85q/GHSA-8j3m-968h-m85q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8j3m-968h-m85q", - "modified": "2024-08-06T18:30:57Z", + "modified": "2024-08-07T18:30:41Z", "published": "2024-08-06T18:30:57Z", "aliases": [ "CVE-2024-39227" ], "details": "GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contain a shell injection vulnerability via the interface check_ovpn_client_config.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-75" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T17:15:53Z" diff --git a/advisories/unreviewed/2024/08/GHSA-8pvg-48x5-gxj6/GHSA-8pvg-48x5-gxj6.json b/advisories/unreviewed/2024/08/GHSA-8pvg-48x5-gxj6/GHSA-8pvg-48x5-gxj6.json new file mode 100644 index 00000000000..81dfe972c49 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8pvg-48x5-gxj6/GHSA-8pvg-48x5-gxj6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8pvg-48x5-gxj6", + "modified": "2024-08-07T18:30:42Z", + "published": "2024-08-07T18:30:42Z", + "aliases": [ + "CVE-2024-41248" + ], + "details": "An Incorrect Access Control vulnerability was found in /smsa/add_subject.php and /smsa/add_subject_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to add a new subject entry.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41248" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Responsive%20School%20Management%20System%20v3.2.0/Broken%20Access%20Control%20-%20Admin%20Master%20-%20Add%20Subject.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-97wv-h596-7vrg/GHSA-97wv-h596-7vrg.json b/advisories/unreviewed/2024/08/GHSA-97wv-h596-7vrg/GHSA-97wv-h596-7vrg.json index bfdef9dc26f..765869531b5 100644 --- a/advisories/unreviewed/2024/08/GHSA-97wv-h596-7vrg/GHSA-97wv-h596-7vrg.json +++ b/advisories/unreviewed/2024/08/GHSA-97wv-h596-7vrg/GHSA-97wv-h596-7vrg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-97wv-h596-7vrg", - "modified": "2024-08-03T21:30:34Z", + "modified": "2024-08-07T18:30:41Z", "published": "2024-08-02T18:31:12Z", "aliases": [ "CVE-2024-38881" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38881" }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/179892/Caterease-Software-SQL-Injection-Command-Injection-Bypass.html" + }, { "type": "WEB", "url": "https://vuldb.com/?id.273365" diff --git a/advisories/unreviewed/2024/08/GHSA-98x8-x9r6-f88w/GHSA-98x8-x9r6-f88w.json b/advisories/unreviewed/2024/08/GHSA-98x8-x9r6-f88w/GHSA-98x8-x9r6-f88w.json new file mode 100644 index 00000000000..18764c42e55 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-98x8-x9r6-f88w/GHSA-98x8-x9r6-f88w.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98x8-x9r6-f88w", + "modified": "2024-08-07T18:30:44Z", + "published": "2024-08-07T18:30:44Z", + "aliases": [ + "CVE-2024-42248" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntty: serial: ma35d1: Add a NULL check for of_node\n\nThe pdev->dev.of_node can be NULL if the \"serial\" node is absent.\nAdd a NULL check to return an error in such cases.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42248" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0e0e15ab2d3a094a38525d23c03d78ec7d14a40e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/23efa74cfe6eb923abb5b9bc51b2a04879013c67" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/acd09ac253b5de8fd79fc61a482ee19154914c7a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9jxc-w9wc-543j/GHSA-9jxc-w9wc-543j.json b/advisories/unreviewed/2024/08/GHSA-9jxc-w9wc-543j/GHSA-9jxc-w9wc-543j.json new file mode 100644 index 00000000000..2b95729ac6c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9jxc-w9wc-543j/GHSA-9jxc-w9wc-543j.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9jxc-w9wc-543j", + "modified": "2024-08-07T18:30:44Z", + "published": "2024-08-07T18:30:44Z", + "aliases": [ + "CVE-2024-7582" + ], + "details": "A vulnerability classified as critical was found in Tenda i22 1.0.0.3(4687). This vulnerability affects the function formApPortalAccessCodeAuth of the file /goform/apPortalAccessCodeAuth. The manipulation of the argument accessCode/data/acceInfo leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7582" + }, + { + "type": "WEB", + "url": "https://github.com/BeaCox/IoT_vuln/tree/main/tenda/i22/ApPortalAccessCodeAuth" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273862" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273862" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.382834" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9m5j-4xx9-44j9/GHSA-9m5j-4xx9-44j9.json b/advisories/unreviewed/2024/08/GHSA-9m5j-4xx9-44j9/GHSA-9m5j-4xx9-44j9.json new file mode 100644 index 00000000000..ec6aca2afc4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9m5j-4xx9-44j9/GHSA-9m5j-4xx9-44j9.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9m5j-4xx9-44j9", + "modified": "2024-08-07T18:30:44Z", + "published": "2024-08-07T18:30:44Z", + "aliases": [ + "CVE-2024-7143" + ], + "details": "A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permissions on its creation, it uses the `AutoAddObjPermsMixin` (typically the add_roles_for_object_creator method). This method finds the object creator by checking the current authenticated user. For objects that are created within a task, this current user is set by the first user with any permissions on the task object. This means the oldest user with model/domain-level task permissions will always be set as the current user of a task, even if they didn't dispatch the task. Therefore, all objects created in tasks will have their permissions assigned to this oldest user, and the creating user will receive nothing.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7143" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-7143" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2300125" + }, + { + "type": "WEB", + "url": "https://github.com/pulp/pulpcore/blob/93f241f34c503da0fbac94bdba739feda2636e12/pulpcore/tasking/_util.py#L108" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-277" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cr76-6p9f-9963/GHSA-cr76-6p9f-9963.json b/advisories/unreviewed/2024/08/GHSA-cr76-6p9f-9963/GHSA-cr76-6p9f-9963.json index ff76653a67e..3f0037c7f0f 100644 --- a/advisories/unreviewed/2024/08/GHSA-cr76-6p9f-9963/GHSA-cr76-6p9f-9963.json +++ b/advisories/unreviewed/2024/08/GHSA-cr76-6p9f-9963/GHSA-cr76-6p9f-9963.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cr76-6p9f-9963", - "modified": "2024-08-05T21:31:19Z", + "modified": "2024-08-07T18:30:41Z", "published": "2024-08-02T18:31:12Z", "aliases": [ "CVE-2024-38884" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38884" }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/179892/Caterease-Software-SQL-Injection-Command-Injection-Bypass.html" + }, { "type": "WEB", "url": "https://vuldb.com/?id.273368" diff --git a/advisories/unreviewed/2024/08/GHSA-cr8r-7g9p-hcx6/GHSA-cr8r-7g9p-hcx6.json b/advisories/unreviewed/2024/08/GHSA-cr8r-7g9p-hcx6/GHSA-cr8r-7g9p-hcx6.json index d89d0eb0b0d..6288bcdecec 100644 --- a/advisories/unreviewed/2024/08/GHSA-cr8r-7g9p-hcx6/GHSA-cr8r-7g9p-hcx6.json +++ b/advisories/unreviewed/2024/08/GHSA-cr8r-7g9p-hcx6/GHSA-cr8r-7g9p-hcx6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cr8r-7g9p-hcx6", - "modified": "2024-08-06T18:30:56Z", + "modified": "2024-08-07T18:30:41Z", "published": "2024-08-06T18:30:56Z", "aliases": [ "CVE-2024-43111" ], "details": "Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T16:15:49Z" diff --git a/advisories/unreviewed/2024/08/GHSA-f292-rrf7-hw2j/GHSA-f292-rrf7-hw2j.json b/advisories/unreviewed/2024/08/GHSA-f292-rrf7-hw2j/GHSA-f292-rrf7-hw2j.json new file mode 100644 index 00000000000..86b892a0d4e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f292-rrf7-hw2j/GHSA-f292-rrf7-hw2j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f292-rrf7-hw2j", + "modified": "2024-08-07T18:30:44Z", + "published": "2024-08-07T18:30:44Z", + "aliases": [ + "CVE-2024-20479" + ], + "details": "A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.\n\nThis vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have Admin privileges on an affected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20479" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xss-V2bm9JCY" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fj4r-983x-g27c/GHSA-fj4r-983x-g27c.json b/advisories/unreviewed/2024/08/GHSA-fj4r-983x-g27c/GHSA-fj4r-983x-g27c.json index 80b0ad4afbd..813d239b209 100644 --- a/advisories/unreviewed/2024/08/GHSA-fj4r-983x-g27c/GHSA-fj4r-983x-g27c.json +++ b/advisories/unreviewed/2024/08/GHSA-fj4r-983x-g27c/GHSA-fj4r-983x-g27c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fj4r-983x-g27c", - "modified": "2024-08-06T18:30:50Z", + "modified": "2024-08-07T18:30:41Z", "published": "2024-08-02T21:31:34Z", "aliases": [ "CVE-2024-38887" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38887" }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/179892/Caterease-Software-SQL-Injection-Command-Injection-Bypass.html" + }, { "type": "WEB", "url": "https://vuldb.com/?id.273371" diff --git a/advisories/unreviewed/2024/08/GHSA-fxrf-h5v6-vcj7/GHSA-fxrf-h5v6-vcj7.json b/advisories/unreviewed/2024/08/GHSA-fxrf-h5v6-vcj7/GHSA-fxrf-h5v6-vcj7.json new file mode 100644 index 00000000000..631592c15ef --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fxrf-h5v6-vcj7/GHSA-fxrf-h5v6-vcj7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fxrf-h5v6-vcj7", + "modified": "2024-08-07T18:30:44Z", + "published": "2024-08-07T18:30:44Z", + "aliases": [ + "CVE-2024-41241" + ], + "details": "A Reflected Cross Site Scripting (XSS) vulnerability was found in \" /smsa/admin_login.php\" in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via \"error\" parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41241" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Responsive%20School%20Management%20System%20v3.2.0/Reflected%20XSS%20-%20Admin.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T18:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g474-4q7c-cx7q/GHSA-g474-4q7c-cx7q.json b/advisories/unreviewed/2024/08/GHSA-g474-4q7c-cx7q/GHSA-g474-4q7c-cx7q.json new file mode 100644 index 00000000000..e6b56f0cd98 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-g474-4q7c-cx7q/GHSA-g474-4q7c-cx7q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g474-4q7c-cx7q", + "modified": "2024-08-07T18:30:44Z", + "published": "2024-08-07T18:30:44Z", + "aliases": [ + "CVE-2024-41250" + ], + "details": "An Incorrect Access Control vulnerability was found in /smsa/view_students.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view STUDENT details.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41250" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Responsive%20School%20Management%20System%20v3.2.0/Broken%20Access%20Control%20-%20Admin%20-%20View%20Students.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g92r-8x2f-9v8m/GHSA-g92r-8x2f-9v8m.json b/advisories/unreviewed/2024/08/GHSA-g92r-8x2f-9v8m/GHSA-g92r-8x2f-9v8m.json new file mode 100644 index 00000000000..37892297454 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-g92r-8x2f-9v8m/GHSA-g92r-8x2f-9v8m.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g92r-8x2f-9v8m", + "modified": "2024-08-07T18:30:43Z", + "published": "2024-08-07T18:30:43Z", + "aliases": [ + "CVE-2024-42242" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: sdhci: Fix max_seg_size for 64KiB PAGE_SIZE\n\nblk_queue_max_segment_size() ensured:\n\n\tif (max_size < PAGE_SIZE)\n\t\tmax_size = PAGE_SIZE;\n\nwhereas:\n\nblk_validate_limits() makes it an error:\n\n\tif (WARN_ON_ONCE(lim->max_segment_size < PAGE_SIZE))\n\t\treturn -EINVAL;\n\nThe change from one to the other, exposed sdhci which was setting maximum\nsegment size too low in some circumstances.\n\nFix the maximum segment size when it is too low.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42242" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/63d20a94f24fc1cbaf44d0e7c0e0a8077fde0aef" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bf78b1accef46efd9b624967cb74ae8d3c215a2b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g9q3-4xq5-wqcj/GHSA-g9q3-4xq5-wqcj.json b/advisories/unreviewed/2024/08/GHSA-g9q3-4xq5-wqcj/GHSA-g9q3-4xq5-wqcj.json new file mode 100644 index 00000000000..94ed66a5f8c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-g9q3-4xq5-wqcj/GHSA-g9q3-4xq5-wqcj.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9q3-4xq5-wqcj", + "modified": "2024-08-07T18:30:44Z", + "published": "2024-08-07T18:30:44Z", + "aliases": [ + "CVE-2024-42244" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: mos7840: fix crash on resume\n\nSince commit c49cfa917025 (\"USB: serial: use generic method if no\nalternative is provided in usb serial layer\"), USB serial core calls the\ngeneric resume implementation when the driver has not provided one.\n\nThis can trigger a crash on resume with mos7840 since support for\nmultiple read URBs was added back in 2011. Specifically, both port read\nURBs are now submitted on resume for open ports, but the context pointer\nof the second URB is left set to the core rather than mos7840 port\nstructure.\n\nFix this by implementing dedicated suspend and resume functions for\nmos7840.\n\nTested with Delock 87414 USB 2.0 to 4x serial adapter.\n\n[ johan: analyse crash and rewrite commit message; set busy flag on\n resume; drop bulk-in check; drop unnecessary usb_kill_urb() ]", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42244" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1094ed500987e67a9d18b0f95e1812f1cc720856" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/553e67dec846323b5575e78a776cf594c13f98c4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5ae6a64f18211851c8df6b4221381c438b9a7348" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/932a86a711c722b45ed47ba2103adca34d225b33" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b14aa5673e0a8077ff4b74f0bb260735e7d5e6a4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c15a688e49987385baa8804bf65d570e362f8576" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-ggh4-5hvc-554r/GHSA-ggh4-5hvc-554r.json b/advisories/unreviewed/2024/08/GHSA-ggh4-5hvc-554r/GHSA-ggh4-5hvc-554r.json new file mode 100644 index 00000000000..ede99bbc10d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-ggh4-5hvc-554r/GHSA-ggh4-5hvc-554r.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggh4-5hvc-554r", + "modified": "2024-08-07T18:30:43Z", + "published": "2024-08-07T18:30:43Z", + "aliases": [ + "CVE-2024-42239" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fail bpf_timer_cancel when callback is being cancelled\n\nGiven a schedule:\n\ntimer1 cb\t\t\ttimer2 cb\n\nbpf_timer_cancel(timer2);\tbpf_timer_cancel(timer1);\n\nBoth bpf_timer_cancel calls would wait for the other callback to finish\nexecuting, introducing a lockup.\n\nAdd an atomic_t count named 'cancelling' in bpf_hrtimer. This keeps\ntrack of all in-flight cancellation requests for a given BPF timer.\nWhenever cancelling a BPF timer, we must check if we have outstanding\ncancellation requests, and if so, we must fail the operation with an\nerror (-EDEADLK) since cancellation is synchronous and waits for the\ncallback to finish executing. This implies that we can enter a deadlock\nsituation involving two or more timer callbacks executing in parallel\nand attempting to cancel one another.\n\nNote that we avoid incrementing the cancelling counter for the target\ntimer (the one being cancelled) if bpf_timer_cancel is not invoked from\na callback, to avoid spurious errors. The whole point of detecting\ncur->cancelling and returning -EDEADLK is to not enter a busy wait loop\n(which may or may not lead to a lockup). This does not apply in case the\ncaller is in a non-callback context, the other side can continue to\ncancel as it sees fit without running into errors.\n\nBackground on prior attempts:\n\nEarlier versions of this patch used a bool 'cancelling' bit and used the\nfollowing pattern under timer->lock to publish cancellation status.\n\nlock(t->lock);\nt->cancelling = true;\nmb();\nif (cur->cancelling)\n\treturn -EDEADLK;\nunlock(t->lock);\nhrtimer_cancel(t->timer);\nt->cancelling = false;\n\nThe store outside the critical section could overwrite a parallel\nrequests t->cancelling assignment to true, to ensure the parallely\nexecuting callback observes its cancellation status.\n\nIt would be necessary to clear this cancelling bit once hrtimer_cancel\nis done, but lack of serialization introduced races. Another option was\nexplored where bpf_timer_start would clear the bit when (re)starting the\ntimer under timer->lock. This would ensure serialized access to the\ncancelling bit, but may allow it to be cleared before in-flight\nhrtimer_cancel has finished executing, such that lockups can occur\nagain.\n\nThus, we choose an atomic counter to keep track of all outstanding\ncancellation requests and use it to prevent lockups in case callbacks\nattempt to cancel each other while executing in parallel.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42239" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3e4e8178a8666c56813bd167b848fca0f4c9af0a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9369830518688ecd5b08ffc08ab3302ce2b5d0f7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d4523831f07a267a943f0dde844bf8ead7495f13" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-gpcw-38mp-9ccf/GHSA-gpcw-38mp-9ccf.json b/advisories/unreviewed/2024/08/GHSA-gpcw-38mp-9ccf/GHSA-gpcw-38mp-9ccf.json new file mode 100644 index 00000000000..cdfd20f71bd --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-gpcw-38mp-9ccf/GHSA-gpcw-38mp-9ccf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpcw-38mp-9ccf", + "modified": "2024-08-07T18:30:42Z", + "published": "2024-08-07T18:30:42Z", + "aliases": [ + "CVE-2024-41308" + ], + "details": "An issue in the Ping feature of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level privileges on the underlying system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41308" + }, + { + "type": "WEB", + "url": "https://the-it-wonders.blogspot.com/2024/07/enjay-crm-10-multiple-code-executions.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j9x3-2fgg-9qgj/GHSA-j9x3-2fgg-9qgj.json b/advisories/unreviewed/2024/08/GHSA-j9x3-2fgg-9qgj/GHSA-j9x3-2fgg-9qgj.json new file mode 100644 index 00000000000..d36573e2966 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j9x3-2fgg-9qgj/GHSA-j9x3-2fgg-9qgj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9x3-2fgg-9qgj", + "modified": "2024-08-07T18:30:42Z", + "published": "2024-08-07T18:30:42Z", + "aliases": [ + "CVE-2024-41251" + ], + "details": "An Incorrect Access Control vulnerability was found in /smsa/admin_teacher_register_approval.php and /smsa/admin_teacher_register_approval_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view and approve Teacher registration.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41251" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Responsive%20School%20Management%20System%20v3.2.0/Broken%20Access%20Control%20-%20Admin%20Dashboard%20-%20Registered%20Teacher.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jh6g-rh4q-hcw2/GHSA-jh6g-rh4q-hcw2.json b/advisories/unreviewed/2024/08/GHSA-jh6g-rh4q-hcw2/GHSA-jh6g-rh4q-hcw2.json new file mode 100644 index 00000000000..0b0f3e6c585 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jh6g-rh4q-hcw2/GHSA-jh6g-rh4q-hcw2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jh6g-rh4q-hcw2", + "modified": "2024-08-07T18:30:44Z", + "published": "2024-08-07T18:30:44Z", + "aliases": [ + "CVE-2024-7061" + ], + "details": "Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta Verify for Windows version 5.0.2. To remediate this vulnerability, upgrade to 5.0.2 or greater.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7061" + }, + { + "type": "WEB", + "url": "https://help.okta.com/oie/en-us/content/topics/releasenotes/oie-ov-release-notes.htm#panel4" + }, + { + "type": "WEB", + "url": "https://trust.okta.com/security-advisories/okta-verify-for-windows-privilege-escalation-cve-2024-7061" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jvrg-cvpm-4p85/GHSA-jvrg-cvpm-4p85.json b/advisories/unreviewed/2024/08/GHSA-jvrg-cvpm-4p85/GHSA-jvrg-cvpm-4p85.json new file mode 100644 index 00000000000..07138b2196b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jvrg-cvpm-4p85/GHSA-jvrg-cvpm-4p85.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvrg-cvpm-4p85", + "modified": "2024-08-07T18:30:44Z", + "published": "2024-08-07T18:30:44Z", + "aliases": [ + "CVE-2024-42249" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: don't unoptimize message in spi_async()\n\nCalling spi_maybe_unoptimize_message() in spi_async() is wrong because\nthe message is likely to be in the queue and not transferred yet. This\ncan corrupt the message while it is being used by the controller driver.\n\nspi_maybe_unoptimize_message() is already called in the correct place\nin spi_finalize_current_message() to balance the call to\nspi_maybe_optimize_message() in spi_async().", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42249" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8b9af6d67517ce4a0015928b3cf35bfd2b1bc1c2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c86a918b1bdba78fb155184f8d88dfba1e63335d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jxv8-jmp2-87p8/GHSA-jxv8-jmp2-87p8.json b/advisories/unreviewed/2024/08/GHSA-jxv8-jmp2-87p8/GHSA-jxv8-jmp2-87p8.json new file mode 100644 index 00000000000..27c3f0b68e9 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jxv8-jmp2-87p8/GHSA-jxv8-jmp2-87p8.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxv8-jmp2-87p8", + "modified": "2024-08-07T18:30:43Z", + "published": "2024-08-07T18:30:43Z", + "aliases": [ + "CVE-2024-42240" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/bhi: Avoid warning in #DB handler due to BHI mitigation\n\nWhen BHI mitigation is enabled, if SYSENTER is invoked with the TF flag set\nthen entry_SYSENTER_compat() uses CLEAR_BRANCH_HISTORY and calls the\nclear_bhb_loop() before the TF flag is cleared. This causes the #DB handler\n(exc_debug_kernel()) to issue a warning because single-step is used outside the\nentry_SYSENTER_compat() function.\n\nTo address this issue, entry_SYSENTER_compat() should use CLEAR_BRANCH_HISTORY\nafter making sure the TF flag is cleared.\n\nThe problem can be reproduced with the following sequence:\n\n $ cat sysenter_step.c\n int main()\n { asm(\"pushf; pop %ax; bts $8,%ax; push %ax; popf; sysenter\"); }\n\n $ gcc -o sysenter_step sysenter_step.c\n\n $ ./sysenter_step\n Segmentation fault (core dumped)\n\nThe program is expected to crash, and the #DB handler will issue a warning.\n\nKernel log:\n\n WARNING: CPU: 27 PID: 7000 at arch/x86/kernel/traps.c:1009 exc_debug_kernel+0xd2/0x160\n ...\n RIP: 0010:exc_debug_kernel+0xd2/0x160\n ...\n Call Trace:\n <#DB>\n ? show_regs+0x68/0x80\n ? __warn+0x8c/0x140\n ? exc_debug_kernel+0xd2/0x160\n ? report_bug+0x175/0x1a0\n ? handle_bug+0x44/0x90\n ? exc_invalid_op+0x1c/0x70\n ? asm_exc_invalid_op+0x1f/0x30\n ? exc_debug_kernel+0xd2/0x160\n exc_debug+0x43/0x50\n asm_exc_debug+0x1e/0x40\n RIP: 0010:clear_bhb_loop+0x0/0xb0\n ...\n \n \n ? entry_SYSENTER_compat_after_hwframe+0x6e/0x8d\n \n\n [ bp: Massage commit message. ]", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42240" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/08518d48e5b744620524f0acd7c26c19bda7f513" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a765679defe1dc1b8fa01928a6ad6361e72a1364" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ac8b270b61d48fcc61f052097777e3b5e11591e0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dae3543db8f0cf8ac1a198c3bb4b6e3c24d576cf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/db56615e96c439e13783d7715330e824b4fd4b84" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jxwh-98r5-mx84/GHSA-jxwh-98r5-mx84.json b/advisories/unreviewed/2024/08/GHSA-jxwh-98r5-mx84/GHSA-jxwh-98r5-mx84.json index 7fc806777a5..0db404d7695 100644 --- a/advisories/unreviewed/2024/08/GHSA-jxwh-98r5-mx84/GHSA-jxwh-98r5-mx84.json +++ b/advisories/unreviewed/2024/08/GHSA-jxwh-98r5-mx84/GHSA-jxwh-98r5-mx84.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jxwh-98r5-mx84", - "modified": "2024-08-03T00:30:58Z", + "modified": "2024-08-07T18:30:41Z", "published": "2024-08-02T06:30:56Z", "aliases": [ "CVE-2024-42458" ], "details": "server.c in Neat VNC (aka neatvnc) before 0.8.1 does not properly validate the security type.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-02T04:17:30Z" diff --git a/advisories/unreviewed/2024/08/GHSA-m475-c2qh-xg8v/GHSA-m475-c2qh-xg8v.json b/advisories/unreviewed/2024/08/GHSA-m475-c2qh-xg8v/GHSA-m475-c2qh-xg8v.json new file mode 100644 index 00000000000..935489f7379 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-m475-c2qh-xg8v/GHSA-m475-c2qh-xg8v.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m475-c2qh-xg8v", + "modified": "2024-08-07T18:30:44Z", + "published": "2024-08-07T18:30:44Z", + "aliases": [ + "CVE-2024-42247" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwireguard: allowedips: avoid unaligned 64-bit memory accesses\n\nOn the parisc platform, the kernel issues kernel warnings because\nswap_endian() tries to load a 128-bit IPv6 address from an unaligned\nmemory location:\n\n Kernel: unaligned access to 0x55f4688c in wg_allowedips_insert_v6+0x2c/0x80 [wireguard] (iir 0xf3010df)\n Kernel: unaligned access to 0x55f46884 in wg_allowedips_insert_v6+0x38/0x80 [wireguard] (iir 0xf2010dc)\n\nAvoid such unaligned memory accesses by instead using the\nget_unaligned_be64() helper macro.\n\n[Jason: replace src[8] in original patch with src+8]", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42247" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/217978a29c6ceca76d3c640bf94bdf50c268d801" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2fb34bf76431e831f9863cd59adc0bd1f67b0fbf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6638a203abad35fa636d59ac47bdbc4bc100fd74" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/948f991c62a4018fb81d85804eeab3029c6209f8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ae630de24efb123d7199a43256396d7758f4cb75" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b4764f0ad3d68de8a0b847c05f427afb86dd54e6" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-m4qj-p3wv-ph7c/GHSA-m4qj-p3wv-ph7c.json b/advisories/unreviewed/2024/08/GHSA-m4qj-p3wv-ph7c/GHSA-m4qj-p3wv-ph7c.json new file mode 100644 index 00000000000..6921577db0f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-m4qj-p3wv-ph7c/GHSA-m4qj-p3wv-ph7c.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4qj-p3wv-ph7c", + "modified": "2024-08-07T18:30:43Z", + "published": "2024-08-07T18:30:43Z", + "aliases": [ + "CVE-2024-42241" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/shmem: disable PMD-sized page cache if needed\n\nFor shmem files, it's possible that PMD-sized page cache can't be\nsupported by xarray. For example, 512MB page cache on ARM64 when the base\npage size is 64KB can't be supported by xarray. It leads to errors as the\nfollowing messages indicate when this sort of xarray entry is split.\n\nWARNING: CPU: 34 PID: 7578 at lib/xarray.c:1025 xas_split_alloc+0xf8/0x128\nModules linked in: binfmt_misc nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 \\\nnft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject \\\nnft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 \\\nip_set rfkill nf_tables nfnetlink vfat fat virtio_balloon drm fuse xfs \\\nlibcrc32c crct10dif_ce ghash_ce sha2_ce sha256_arm64 sha1_ce virtio_net \\\nnet_failover virtio_console virtio_blk failover dimlib virtio_mmio\nCPU: 34 PID: 7578 Comm: test Kdump: loaded Tainted: G W 6.10.0-rc5-gavin+ #9\nHardware name: QEMU KVM Virtual Machine, BIOS edk2-20240524-1.el9 05/24/2024\npstate: 83400005 (Nzcv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)\npc : xas_split_alloc+0xf8/0x128\nlr : split_huge_page_to_list_to_order+0x1c4/0x720\nsp : ffff8000882af5f0\nx29: ffff8000882af5f0 x28: ffff8000882af650 x27: ffff8000882af768\nx26: 0000000000000cc0 x25: 000000000000000d x24: ffff00010625b858\nx23: ffff8000882af650 x22: ffffffdfc0900000 x21: 0000000000000000\nx20: 0000000000000000 x19: ffffffdfc0900000 x18: 0000000000000000\nx17: 0000000000000000 x16: 0000018000000000 x15: 52f8004000000000\nx14: 0000e00000000000 x13: 0000000000002000 x12: 0000000000000020\nx11: 52f8000000000000 x10: 52f8e1c0ffff6000 x9 : ffffbeb9619a681c\nx8 : 0000000000000003 x7 : 0000000000000000 x6 : ffff00010b02ddb0\nx5 : ffffbeb96395e378 x4 : 0000000000000000 x3 : 0000000000000cc0\nx2 : 000000000000000d x1 : 000000000000000c x0 : 0000000000000000\nCall trace:\n xas_split_alloc+0xf8/0x128\n split_huge_page_to_list_to_order+0x1c4/0x720\n truncate_inode_partial_folio+0xdc/0x160\n shmem_undo_range+0x2bc/0x6a8\n shmem_fallocate+0x134/0x430\n vfs_fallocate+0x124/0x2e8\n ksys_fallocate+0x4c/0xa0\n __arm64_sys_fallocate+0x24/0x38\n invoke_syscall.constprop.0+0x7c/0xd8\n do_el0_svc+0xb4/0xd0\n el0_svc+0x44/0x1d8\n el0t_64_sync_handler+0x134/0x150\n el0t_64_sync+0x17c/0x180\n\nFix it by disabling PMD-sized page cache when HPAGE_PMD_ORDER is larger\nthan MAX_PAGECACHE_ORDER. As Matthew Wilcox pointed, the page cache in a\nshmem file isn't represented by a multi-index entry and doesn't have this\nlimitation when the xarry entry is split until commit 6b24ca4a1a8d (\"mm:\nUse multi-index entries in the page cache\").", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42241" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/93893eacb372b0a4a30f7de6609b08c3ba6c4fd9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9fd154ba926b34c833b7bfc4c14ee2e931b3d743" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cd25208ca9b0097f8e079d692fc678f36fdbc3f9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-m5rr-qpcg-cm8h/GHSA-m5rr-qpcg-cm8h.json b/advisories/unreviewed/2024/08/GHSA-m5rr-qpcg-cm8h/GHSA-m5rr-qpcg-cm8h.json new file mode 100644 index 00000000000..2273f7f1f03 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-m5rr-qpcg-cm8h/GHSA-m5rr-qpcg-cm8h.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5rr-qpcg-cm8h", + "modified": "2024-08-07T18:30:44Z", + "published": "2024-08-07T18:30:44Z", + "aliases": [ + "CVE-2024-7585" + ], + "details": "A vulnerability has been found in Tenda i22 1.0.0.3(4687) and classified as critical. Affected by this vulnerability is the function formApPortalWebAuth of the file /goform/apPortalAuth. The manipulation of the argument webUserName/webUserPassword leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7585" + }, + { + "type": "WEB", + "url": "https://github.com/BeaCox/IoT_vuln/tree/main/tenda/i22/ApPortalWebAuth" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273865" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273865" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.382837" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mp55-qmj4-xm5f/GHSA-mp55-qmj4-xm5f.json b/advisories/unreviewed/2024/08/GHSA-mp55-qmj4-xm5f/GHSA-mp55-qmj4-xm5f.json index e5aefdc7ae7..68595be0e41 100644 --- a/advisories/unreviewed/2024/08/GHSA-mp55-qmj4-xm5f/GHSA-mp55-qmj4-xm5f.json +++ b/advisories/unreviewed/2024/08/GHSA-mp55-qmj4-xm5f/GHSA-mp55-qmj4-xm5f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mp55-qmj4-xm5f", - "modified": "2024-08-05T06:30:37Z", + "modified": "2024-08-07T18:30:41Z", "published": "2024-08-05T06:30:37Z", "aliases": [ "CVE-2024-3636" ], "details": "The Pinpoint Booking System WordPress plugin before 2.9.9.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-05T06:16:41Z" diff --git a/advisories/unreviewed/2024/08/GHSA-pjph-5c8j-wm5g/GHSA-pjph-5c8j-wm5g.json b/advisories/unreviewed/2024/08/GHSA-pjph-5c8j-wm5g/GHSA-pjph-5c8j-wm5g.json new file mode 100644 index 00000000000..4e16397b8f7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-pjph-5c8j-wm5g/GHSA-pjph-5c8j-wm5g.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pjph-5c8j-wm5g", + "modified": "2024-08-07T18:30:44Z", + "published": "2024-08-07T18:30:44Z", + "aliases": [ + "CVE-2024-41243" + ], + "details": "An Incorrect Access Control vulnerability was found in /smsa/view_marks.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view MARKS details.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41243" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Responsive%20School%20Management%20System%20v3.2.0/Broken%20Access%20Control%20-%20Admin%20-%20View%20Marks.pdf" + }, + { + "type": "WEB", + "url": "https://www.kashipara.com/project/php/12362/responsive-school-management-system-php-project-source-code" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pwxm-h2xg-rwv6/GHSA-pwxm-h2xg-rwv6.json b/advisories/unreviewed/2024/08/GHSA-pwxm-h2xg-rwv6/GHSA-pwxm-h2xg-rwv6.json index 68042d0be67..e3518a8ca2a 100644 --- a/advisories/unreviewed/2024/08/GHSA-pwxm-h2xg-rwv6/GHSA-pwxm-h2xg-rwv6.json +++ b/advisories/unreviewed/2024/08/GHSA-pwxm-h2xg-rwv6/GHSA-pwxm-h2xg-rwv6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pwxm-h2xg-rwv6", - "modified": "2024-08-02T21:31:34Z", + "modified": "2024-08-07T18:30:41Z", "published": "2024-08-02T21:31:34Z", "aliases": [ "CVE-2024-38889" @@ -18,6 +18,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38889" }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/179892/Caterease-Software-SQL-Injection-Command-Injection-Bypass.html" + }, { "type": "WEB", "url": "https://vuldb.com/?id.273373" diff --git a/advisories/unreviewed/2024/08/GHSA-q4gh-23q4-v22c/GHSA-q4gh-23q4-v22c.json b/advisories/unreviewed/2024/08/GHSA-q4gh-23q4-v22c/GHSA-q4gh-23q4-v22c.json new file mode 100644 index 00000000000..61be15b106f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-q4gh-23q4-v22c/GHSA-q4gh-23q4-v22c.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4gh-23q4-v22c", + "modified": "2024-08-07T18:30:44Z", + "published": "2024-08-07T18:30:44Z", + "aliases": [ + "CVE-2024-7584" + ], + "details": "A vulnerability, which was classified as critical, was found in Tenda i22 1.0.0.3(4687). Affected is the function formApPortalPhoneAuth of the file /goform/apPortalPhoneAuth. The manipulation of the argument data leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7584" + }, + { + "type": "WEB", + "url": "https://github.com/BeaCox/IoT_vuln/tree/main/tenda/i22/ApPortalPhoneAuth" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273864" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273864" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.382836" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qw3c-q5mw-r893/GHSA-qw3c-q5mw-r893.json b/advisories/unreviewed/2024/08/GHSA-qw3c-q5mw-r893/GHSA-qw3c-q5mw-r893.json index 070451c3ef2..560cc49bf77 100644 --- a/advisories/unreviewed/2024/08/GHSA-qw3c-q5mw-r893/GHSA-qw3c-q5mw-r893.json +++ b/advisories/unreviewed/2024/08/GHSA-qw3c-q5mw-r893/GHSA-qw3c-q5mw-r893.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qw3c-q5mw-r893", - "modified": "2024-08-03T21:30:34Z", + "modified": "2024-08-07T18:30:41Z", "published": "2024-08-02T21:31:34Z", "aliases": [ "CVE-2024-38888" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38888" }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/179892/Caterease-Software-SQL-Injection-Command-Injection-Bypass.html" + }, { "type": "WEB", "url": "https://vuldb.com/?id.273372" diff --git a/advisories/unreviewed/2024/08/GHSA-r94j-mwf9-qj2r/GHSA-r94j-mwf9-qj2r.json b/advisories/unreviewed/2024/08/GHSA-r94j-mwf9-qj2r/GHSA-r94j-mwf9-qj2r.json index dc3da3da35d..68a375cb079 100644 --- a/advisories/unreviewed/2024/08/GHSA-r94j-mwf9-qj2r/GHSA-r94j-mwf9-qj2r.json +++ b/advisories/unreviewed/2024/08/GHSA-r94j-mwf9-qj2r/GHSA-r94j-mwf9-qj2r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r94j-mwf9-qj2r", - "modified": "2024-08-06T18:30:50Z", + "modified": "2024-08-07T18:30:41Z", "published": "2024-08-02T21:31:34Z", "aliases": [ "CVE-2024-38891" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38891" }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/179892/Caterease-Software-SQL-Injection-Command-Injection-Bypass.html" + }, { "type": "WEB", "url": "https://vuldb.com/?id.273375" diff --git a/advisories/unreviewed/2024/08/GHSA-rmhg-2pcx-wcr2/GHSA-rmhg-2pcx-wcr2.json b/advisories/unreviewed/2024/08/GHSA-rmhg-2pcx-wcr2/GHSA-rmhg-2pcx-wcr2.json index 051f42f1e1c..a049f38824d 100644 --- a/advisories/unreviewed/2024/08/GHSA-rmhg-2pcx-wcr2/GHSA-rmhg-2pcx-wcr2.json +++ b/advisories/unreviewed/2024/08/GHSA-rmhg-2pcx-wcr2/GHSA-rmhg-2pcx-wcr2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rmhg-2pcx-wcr2", - "modified": "2024-08-03T21:30:34Z", + "modified": "2024-08-07T18:30:41Z", "published": "2024-08-02T18:31:12Z", "aliases": [ "CVE-2024-38882" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38882" }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/179892/Caterease-Software-SQL-Injection-Command-Injection-Bypass.html" + }, { "type": "WEB", "url": "https://vuldb.com/?id.273366" diff --git a/advisories/unreviewed/2024/08/GHSA-rx9p-j44h-69cp/GHSA-rx9p-j44h-69cp.json b/advisories/unreviewed/2024/08/GHSA-rx9p-j44h-69cp/GHSA-rx9p-j44h-69cp.json new file mode 100644 index 00000000000..a8a17d5bb09 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rx9p-j44h-69cp/GHSA-rx9p-j44h-69cp.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rx9p-j44h-69cp", + "modified": "2024-08-07T18:30:43Z", + "published": "2024-08-07T18:30:43Z", + "aliases": [ + "CVE-2024-42235" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/mm: Add NULL pointer check to crst_table_free() base_crst_free()\n\ncrst_table_free() used to work with NULL pointers before the conversion\nto ptdescs. Since crst_table_free() can be called with a NULL pointer\n(error handling in crst_table_upgrade() add an explicit check.\n\nAlso add the same check to base_crst_free() for consistency reasons.\n\nIn real life this should not happen, since order two GFP_KERNEL\nallocations will not fail, unless FAIL_PAGE_ALLOC is enabled and used.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42235" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/794fa52b94637d6b2e8c9474fbe3983af5c9f046" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b5efb63acf7bddaf20eacfcac654c25c446eabe8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f80bd8bb6f380bc265834c46058d38b34174813e" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v66p-qc5x-9g87/GHSA-v66p-qc5x-9g87.json b/advisories/unreviewed/2024/08/GHSA-v66p-qc5x-9g87/GHSA-v66p-qc5x-9g87.json new file mode 100644 index 00000000000..cab71df3d4b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v66p-qc5x-9g87/GHSA-v66p-qc5x-9g87.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v66p-qc5x-9g87", + "modified": "2024-08-07T18:30:43Z", + "published": "2024-08-07T18:30:43Z", + "aliases": [ + "CVE-2024-41432" + ], + "details": "An IP Spoofing vulnerability has been discovered in Likeshop up to 2.5.7.20210811. This issue allows an attacker to replace their real IP address with any arbitrary IP address, specifically by adding a forged 'X-Forwarded' or 'Client-IP' header to requests. Exploiting IP spoofing, attackers can bypass account lockout mechanisms during attempts to log into admin accounts, spoof IP addresses in requests sent to the server, and impersonate IP addresses that have logged into user accounts, etc.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41432" + }, + { + "type": "WEB", + "url": "https://gitlab.com/c2at3/cve-2024-41432/-/blob/main/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v9rg-h6h9-q754/GHSA-v9rg-h6h9-q754.json b/advisories/unreviewed/2024/08/GHSA-v9rg-h6h9-q754/GHSA-v9rg-h6h9-q754.json index b42cc7c90be..5e30ee5ccfc 100644 --- a/advisories/unreviewed/2024/08/GHSA-v9rg-h6h9-q754/GHSA-v9rg-h6h9-q754.json +++ b/advisories/unreviewed/2024/08/GHSA-v9rg-h6h9-q754/GHSA-v9rg-h6h9-q754.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-vfhx-cqwc-hf57/GHSA-vfhx-cqwc-hf57.json b/advisories/unreviewed/2024/08/GHSA-vfhx-cqwc-hf57/GHSA-vfhx-cqwc-hf57.json new file mode 100644 index 00000000000..18037c20e2a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vfhx-cqwc-hf57/GHSA-vfhx-cqwc-hf57.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfhx-cqwc-hf57", + "modified": "2024-08-07T18:30:43Z", + "published": "2024-08-07T18:30:43Z", + "aliases": [ + "CVE-2024-42238" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: cs_dsp: Return error if block header overflows file\n\nReturn an error from cs_dsp_power_up() if a block header is longer\nthan the amount of data left in the file.\n\nThe previous code in cs_dsp_load() and cs_dsp_load_coeff() would loop\nwhile there was enough data left in the file for a valid region. This\nprotected against overrunning the end of the file data, but it didn't\nabort the file processing with an error.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42238" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6eabd23383805725eff416c203688b7a390d4153" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/90ab191b7d181057d71234e8632e06b5844ac38e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/959fe01e85b7241e3ec305d657febbe82da16a02" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b8be70566b33abbd0180105070b4c67cfef8c44f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vgxc-qp5x-8cv8/GHSA-vgxc-qp5x-8cv8.json b/advisories/unreviewed/2024/08/GHSA-vgxc-qp5x-8cv8/GHSA-vgxc-qp5x-8cv8.json new file mode 100644 index 00000000000..226753049ec --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vgxc-qp5x-8cv8/GHSA-vgxc-qp5x-8cv8.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vgxc-qp5x-8cv8", + "modified": "2024-08-07T18:30:44Z", + "published": "2024-08-07T18:30:44Z", + "aliases": [ + "CVE-2024-7583" + ], + "details": "A vulnerability, which was classified as critical, has been found in Tenda i22 1.0.0.3(4687). This issue affects the function formApPortalOneKeyAuth of the file /goform/apPortalOneKeyAuth. The manipulation of the argument data leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7583" + }, + { + "type": "WEB", + "url": "https://github.com/BeaCox/IoT_vuln/tree/main/tenda/i22/ApPortalOneKeyAuth" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273863" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273863" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.382835" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vhmm-vh3j-5vww/GHSA-vhmm-vh3j-5vww.json b/advisories/unreviewed/2024/08/GHSA-vhmm-vh3j-5vww/GHSA-vhmm-vh3j-5vww.json index b14681a86ac..4c521a2bcff 100644 --- a/advisories/unreviewed/2024/08/GHSA-vhmm-vh3j-5vww/GHSA-vhmm-vh3j-5vww.json +++ b/advisories/unreviewed/2024/08/GHSA-vhmm-vh3j-5vww/GHSA-vhmm-vh3j-5vww.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vhmm-vh3j-5vww", - "modified": "2024-08-07T00:30:47Z", + "modified": "2024-08-07T18:30:41Z", "published": "2024-08-02T18:31:12Z", "aliases": [ "CVE-2024-38886" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38886" }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/179892/Caterease-Software-SQL-Injection-Command-Injection-Bypass.html" + }, { "type": "WEB", "url": "https://vuldb.com/?id.273370" diff --git a/advisories/unreviewed/2024/08/GHSA-w52v-vrvm-954m/GHSA-w52v-vrvm-954m.json b/advisories/unreviewed/2024/08/GHSA-w52v-vrvm-954m/GHSA-w52v-vrvm-954m.json new file mode 100644 index 00000000000..a6cb1e21648 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w52v-vrvm-954m/GHSA-w52v-vrvm-954m.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w52v-vrvm-954m", + "modified": "2024-08-07T18:30:44Z", + "published": "2024-08-07T18:30:44Z", + "aliases": [ + "CVE-2024-42250" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncachefiles: add missing lock protection when polling\n\nAdd missing lock protection in poll routine when iterating xarray,\notherwise:\n\nEven with RCU read lock held, only the slot of the radix tree is\nensured to be pinned there, while the data structure (e.g. struct\ncachefiles_req) stored in the slot has no such guarantee. The poll\nroutine will iterate the radix tree and dereference cachefiles_req\naccordingly. Thus RCU read lock is not adequate in this case and\nspinlock is needed here.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42250" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6bb6bd3dd6f382dfd36220d4b210a0c77c066651" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8eadcab7f3dd809edbe5ae20533ff843dfea3a07" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/97cfd5e20ddc2e33e16ce369626ce76c9a475fd7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cf5bb09e742a9cf6349127e868329a8f69b7a014" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w6xf-p643-g6rw/GHSA-w6xf-p643-g6rw.json b/advisories/unreviewed/2024/08/GHSA-w6xf-p643-g6rw/GHSA-w6xf-p643-g6rw.json new file mode 100644 index 00000000000..8ca4edf364d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w6xf-p643-g6rw/GHSA-w6xf-p643-g6rw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6xf-p643-g6rw", + "modified": "2024-08-07T18:30:42Z", + "published": "2024-08-07T18:30:42Z", + "aliases": [ + "CVE-2024-41249" + ], + "details": "An Incorrect Access Control vulnerability was found in /smsa/view_subject.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view SUBJECT details.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41249" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Responsive%20School%20Management%20System%20v3.2.0/Broken%20Access%20Control%20-%20Admin%20-%20View%20Subjects.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w7h7-v3m9-rv75/GHSA-w7h7-v3m9-rv75.json b/advisories/unreviewed/2024/08/GHSA-w7h7-v3m9-rv75/GHSA-w7h7-v3m9-rv75.json new file mode 100644 index 00000000000..ba8b927cc9c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w7h7-v3m9-rv75/GHSA-w7h7-v3m9-rv75.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7h7-v3m9-rv75", + "modified": "2024-08-07T18:30:44Z", + "published": "2024-08-07T18:30:44Z", + "aliases": [ + "CVE-2024-41240" + ], + "details": "A Reflected Cross Site Scripting (XSS) vulnerability was found in \" /smsa/teacher_login.php\" in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via the \"error\" parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41240" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Responsive%20School%20Management%20System%20v3.2.0/Reflected%20XSS%20-%20Teacher.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T18:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wvp3-f576-fpv8/GHSA-wvp3-f576-fpv8.json b/advisories/unreviewed/2024/08/GHSA-wvp3-f576-fpv8/GHSA-wvp3-f576-fpv8.json new file mode 100644 index 00000000000..ea7a51cf328 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-wvp3-f576-fpv8/GHSA-wvp3-f576-fpv8.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvp3-f576-fpv8", + "modified": "2024-08-07T18:30:43Z", + "published": "2024-08-07T18:30:43Z", + "aliases": [ + "CVE-2024-42237" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: cs_dsp: Validate payload length before processing block\n\nMove the payload length check in cs_dsp_load() and cs_dsp_coeff_load()\nto be done before the block is processed.\n\nThe check that the length of a block payload does not exceed the number\nof remaining bytes in the firwmware file buffer was being done near the\nend of the loop iteration. However, some code before that check used the\nlength field without validating it.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42237" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/259955eca9b7acf1299b1ac077d8cfbe12df35d8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3a9cd924aec1288d675df721f244da4dd7e16cff" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6598afa9320b6ab13041616950ca5f8f938c0cf1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/71d9e313d8f7e18c543a9c80506fe6b1eb1fe0c8" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-x7x3-mj9c-m6x7/GHSA-x7x3-mj9c-m6x7.json b/advisories/unreviewed/2024/08/GHSA-x7x3-mj9c-m6x7/GHSA-x7x3-mj9c-m6x7.json new file mode 100644 index 00000000000..d5abf2c6723 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-x7x3-mj9c-m6x7/GHSA-x7x3-mj9c-m6x7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7x3-mj9c-m6x7", + "modified": "2024-08-07T18:30:42Z", + "published": "2024-08-07T18:30:42Z", + "aliases": [ + "CVE-2024-41246" + ], + "details": "An Incorrect Access Control vulnerability was found in /smsa/admin_dashboard.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view administrator dashboard.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41246" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Responsive%20School%20Management%20System%20v3.2.0/Broken%20Access%20Control%20-%20Admin%20Dashboard.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-x973-f6rm-j4v5/GHSA-x973-f6rm-j4v5.json b/advisories/unreviewed/2024/08/GHSA-x973-f6rm-j4v5/GHSA-x973-f6rm-j4v5.json index 80fdaed80ef..9df41f3747e 100644 --- a/advisories/unreviewed/2024/08/GHSA-x973-f6rm-j4v5/GHSA-x973-f6rm-j4v5.json +++ b/advisories/unreviewed/2024/08/GHSA-x973-f6rm-j4v5/GHSA-x973-f6rm-j4v5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x973-f6rm-j4v5", - "modified": "2024-08-02T18:31:10Z", + "modified": "2024-08-07T18:30:41Z", "published": "2024-08-02T18:31:10Z", "aliases": [ "CVE-2024-33892" ], "details": "Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are susceptible to leaking information through cookies. This is fixed in version 21.2s10 and 22.1s3", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-281" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-02T18:16:18Z" diff --git a/advisories/unreviewed/2024/08/GHSA-xg77-wrvc-q75c/GHSA-xg77-wrvc-q75c.json b/advisories/unreviewed/2024/08/GHSA-xg77-wrvc-q75c/GHSA-xg77-wrvc-q75c.json new file mode 100644 index 00000000000..3f2cdf785c1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xg77-wrvc-q75c/GHSA-xg77-wrvc-q75c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xg77-wrvc-q75c", + "modified": "2024-08-07T18:30:42Z", + "published": "2024-08-07T18:30:42Z", + "aliases": [ + "CVE-2024-41309" + ], + "details": "An issue in the Hardware info module of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level privileges on the underlying system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41309" + }, + { + "type": "WEB", + "url": "https://the-it-wonders.blogspot.com/2024/07/enjay-crm-10-multiple-code-executions.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xmx3-9jpm-34m4/GHSA-xmx3-9jpm-34m4.json b/advisories/unreviewed/2024/08/GHSA-xmx3-9jpm-34m4/GHSA-xmx3-9jpm-34m4.json new file mode 100644 index 00000000000..b6af18557bb --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xmx3-9jpm-34m4/GHSA-xmx3-9jpm-34m4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmx3-9jpm-34m4", + "modified": "2024-08-07T18:30:42Z", + "published": "2024-08-07T18:30:42Z", + "aliases": [ + "CVE-2024-41252" + ], + "details": "An Incorrect Access Control vulnerability was found in /smsa/admin_student_register_approval.php and /smsa/admin_student_register_approval_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view and approve student registration.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41252" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Responsive%20School%20Management%20System%20v3.2.0/Broken%20Access%20Control%20-%20Admin%20Dashboard%20-%20Registered%20Student.pdf" + }, + { + "type": "WEB", + "url": "https://www.kashipara.com/project/php/12362/responsive-school-management-system-php-project-source-code" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T16:15:45Z" + } +} \ No newline at end of file