From 24d4c8a265eecf75045b67aa26c7ffbb1c1568d3 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 18 Apr 2024 18:31:51 +0000 Subject: [PATCH] Publish Advisories GHSA-9ph3-v2vh-3qx7 GHSA-2cww-rcpx-vmvj GHSA-36pg-p326-9j9j GHSA-6qpm-68vc-gfr6 GHSA-8rg3-xv33-hfpc GHSA-h3hp-g22h-899v GHSA-j69w-hqg4-wcw5 GHSA-m37q-xj87-cf4v GHSA-w74q-jj94-wcp5 --- .../GHSA-9ph3-v2vh-3qx7.json | 6 ++- .../GHSA-2cww-rcpx-vmvj.json | 39 +++++++++++++++++++ .../GHSA-36pg-p326-9j9j.json | 39 +++++++++++++++++++ .../GHSA-6qpm-68vc-gfr6.json | 39 +++++++++++++++++++ .../GHSA-8rg3-xv33-hfpc.json | 35 +++++++++++++++++ .../GHSA-h3hp-g22h-899v.json | 39 +++++++++++++++++++ .../GHSA-j69w-hqg4-wcw5.json | 39 +++++++++++++++++++ .../GHSA-m37q-xj87-cf4v.json | 39 +++++++++++++++++++ .../GHSA-w74q-jj94-wcp5.json | 39 +++++++++++++++++++ 9 files changed, 313 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2024/04/GHSA-2cww-rcpx-vmvj/GHSA-2cww-rcpx-vmvj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-36pg-p326-9j9j/GHSA-36pg-p326-9j9j.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6qpm-68vc-gfr6/GHSA-6qpm-68vc-gfr6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8rg3-xv33-hfpc/GHSA-8rg3-xv33-hfpc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-h3hp-g22h-899v/GHSA-h3hp-g22h-899v.json create mode 100644 advisories/unreviewed/2024/04/GHSA-j69w-hqg4-wcw5/GHSA-j69w-hqg4-wcw5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-m37q-xj87-cf4v/GHSA-m37q-xj87-cf4v.json create mode 100644 advisories/unreviewed/2024/04/GHSA-w74q-jj94-wcp5/GHSA-w74q-jj94-wcp5.json diff --git a/advisories/github-reviewed/2024/04/GHSA-9ph3-v2vh-3qx7/GHSA-9ph3-v2vh-3qx7.json b/advisories/github-reviewed/2024/04/GHSA-9ph3-v2vh-3qx7/GHSA-9ph3-v2vh-3qx7.json index e96af1a6378..243679f9a1b 100644 --- a/advisories/github-reviewed/2024/04/GHSA-9ph3-v2vh-3qx7/GHSA-9ph3-v2vh-3qx7.json +++ b/advisories/github-reviewed/2024/04/GHSA-9ph3-v2vh-3qx7/GHSA-9ph3-v2vh-3qx7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9ph3-v2vh-3qx7", - "modified": "2024-04-09T12:30:46Z", + "modified": "2024-04-18T18:30:40Z", "published": "2024-04-02T09:30:42Z", "aliases": [ "CVE-2024-1300" @@ -87,6 +87,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:1706" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1923" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-1300" diff --git a/advisories/unreviewed/2024/04/GHSA-2cww-rcpx-vmvj/GHSA-2cww-rcpx-vmvj.json b/advisories/unreviewed/2024/04/GHSA-2cww-rcpx-vmvj/GHSA-2cww-rcpx-vmvj.json new file mode 100644 index 00000000000..367726d6803 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2cww-rcpx-vmvj/GHSA-2cww-rcpx-vmvj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cww-rcpx-vmvj", + "modified": "2024-04-18T18:30:41Z", + "published": "2024-04-18T18:30:41Z", + "aliases": [ + "CVE-2024-32325" + ], + "details": "TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the ssid parameter in the setWiFiExtenderConfig function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32325" + }, + { + "type": "WEB", + "url": "https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/EX200/XSS_ssid/README.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net/home/menu/newstpl/menu_newstpl/products/id/144.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-18T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-36pg-p326-9j9j/GHSA-36pg-p326-9j9j.json b/advisories/unreviewed/2024/04/GHSA-36pg-p326-9j9j/GHSA-36pg-p326-9j9j.json new file mode 100644 index 00000000000..ab0065437b3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-36pg-p326-9j9j/GHSA-36pg-p326-9j9j.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36pg-p326-9j9j", + "modified": "2024-04-18T18:30:42Z", + "published": "2024-04-18T18:30:42Z", + "aliases": [ + "CVE-2024-32327" + ], + "details": "TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Port Forwarding under the Firewall Page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32327" + }, + { + "type": "WEB", + "url": "https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/N300RT/XSS_5_Port_Forwarding/README.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net/home/menu/newstpl/menu_newstpl/products/id/154.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-18T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6qpm-68vc-gfr6/GHSA-6qpm-68vc-gfr6.json b/advisories/unreviewed/2024/04/GHSA-6qpm-68vc-gfr6/GHSA-6qpm-68vc-gfr6.json new file mode 100644 index 00000000000..6f497cd3e1c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6qpm-68vc-gfr6/GHSA-6qpm-68vc-gfr6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6qpm-68vc-gfr6", + "modified": "2024-04-18T18:30:42Z", + "published": "2024-04-18T18:30:42Z", + "aliases": [ + "CVE-2024-32332" + ], + "details": "TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in WDS Settings under the Wireless Page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32332" + }, + { + "type": "WEB", + "url": "https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/N300RT/XSS_1_WDS_Settings/README.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net/home/menu/newstpl/menu_newstpl/products/id/154.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-18T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8rg3-xv33-hfpc/GHSA-8rg3-xv33-hfpc.json b/advisories/unreviewed/2024/04/GHSA-8rg3-xv33-hfpc/GHSA-8rg3-xv33-hfpc.json new file mode 100644 index 00000000000..12f1419ff56 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8rg3-xv33-hfpc/GHSA-8rg3-xv33-hfpc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rg3-xv33-hfpc", + "modified": "2024-04-18T18:30:43Z", + "published": "2024-04-18T18:30:43Z", + "aliases": [ + "CVE-2024-24910" + ], + "details": "A local attacker can escalate privileges on affected Check Point ZoneAlarm Extreme Security NextGen, Identity Agent for Windows, and Identity Agent for Windows Terminal Server. To exploit this vulnerability, an attacker must first obtain the ability to execute local privileged code on the target system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24910" + }, + { + "type": "WEB", + "url": "https://support.checkpoint.com/results/sk/sk182219" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-18T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-h3hp-g22h-899v/GHSA-h3hp-g22h-899v.json b/advisories/unreviewed/2024/04/GHSA-h3hp-g22h-899v/GHSA-h3hp-g22h-899v.json new file mode 100644 index 00000000000..4d8bd6c55e1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-h3hp-g22h-899v/GHSA-h3hp-g22h-899v.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h3hp-g22h-899v", + "modified": "2024-04-18T18:30:41Z", + "published": "2024-04-18T18:30:41Z", + "aliases": [ + "CVE-2024-32326" + ], + "details": "TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the key parameter in the setWiFiExtenderConfig function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32326" + }, + { + "type": "WEB", + "url": "https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/EX200/XSS_key/README.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net/home/menu/newstpl/menu_newstpl/products/id/144.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-18T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-j69w-hqg4-wcw5/GHSA-j69w-hqg4-wcw5.json b/advisories/unreviewed/2024/04/GHSA-j69w-hqg4-wcw5/GHSA-j69w-hqg4-wcw5.json new file mode 100644 index 00000000000..6a73a27ff04 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-j69w-hqg4-wcw5/GHSA-j69w-hqg4-wcw5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j69w-hqg4-wcw5", + "modified": "2024-04-18T18:30:42Z", + "published": "2024-04-18T18:30:42Z", + "aliases": [ + "CVE-2024-32335" + ], + "details": "TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Access Control under the Wireless Page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32335" + }, + { + "type": "WEB", + "url": "https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/N300RT/XSS_2_Access_Control/README.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net/home/menu/newstpl/menu_newstpl/products/id/154.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-18T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-m37q-xj87-cf4v/GHSA-m37q-xj87-cf4v.json b/advisories/unreviewed/2024/04/GHSA-m37q-xj87-cf4v/GHSA-m37q-xj87-cf4v.json new file mode 100644 index 00000000000..178ad590e87 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-m37q-xj87-cf4v/GHSA-m37q-xj87-cf4v.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m37q-xj87-cf4v", + "modified": "2024-04-18T18:30:42Z", + "published": "2024-04-18T18:30:42Z", + "aliases": [ + "CVE-2024-32334" + ], + "details": "TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in IP/Port Filtering under the Firewall Page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32334" + }, + { + "type": "WEB", + "url": "https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/N300RT/XSS_4_IP_Port_Filtering/README.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net/home/menu/newstpl/menu_newstpl/products/id/154.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-18T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-w74q-jj94-wcp5/GHSA-w74q-jj94-wcp5.json b/advisories/unreviewed/2024/04/GHSA-w74q-jj94-wcp5/GHSA-w74q-jj94-wcp5.json new file mode 100644 index 00000000000..beb0e9f890c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-w74q-jj94-wcp5/GHSA-w74q-jj94-wcp5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w74q-jj94-wcp5", + "modified": "2024-04-18T18:30:42Z", + "published": "2024-04-18T18:30:42Z", + "aliases": [ + "CVE-2024-32333" + ], + "details": "TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in MAC Filtering under the Firewall Page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32333" + }, + { + "type": "WEB", + "url": "https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/N300RT/XSS_3_MAC_Filtering/README.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net/home/menu/newstpl/menu_newstpl/products/id/154.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-18T17:15:48Z" + } +} \ No newline at end of file