From 263eabd9489c58a57b3349c012f7747175c0cdb0 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 19 Jul 2024 15:33:52 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-9pf8-qqhm-7w64.json | 6 ++- .../GHSA-38fg-rh2c-fh5c.json | 6 ++- .../GHSA-5gg5-9r5r-wpgh.json | 6 ++- .../GHSA-g589-q56x-4rhp.json | 2 +- .../GHSA-w7q3-c7q5-xfgf.json | 3 +- .../GHSA-3fr5-8rrj-9rf2.json | 6 ++- .../GHSA-23cc-8qjh-m5rg.json | 6 ++- .../GHSA-49m8-f75j-fw3p.json | 6 ++- .../GHSA-8vwj-6qr9-pvp7.json | 6 ++- .../GHSA-m5jq-qvgg-36pq.json | 6 ++- .../GHSA-pwfh-2pj9-f3rc.json | 11 +++-- .../GHSA-v575-95ph-534m.json | 6 ++- .../GHSA-xrrx-xr48-h4jv.json | 6 ++- .../GHSA-2m5h-vv32-6gjr.json | 46 +++++++++++++++++++ .../GHSA-4mqw-v4pq-hg97.json | 6 ++- .../GHSA-4rqr-f9qq-h7w3.json | 6 ++- .../GHSA-5qwh-g35c-5mmm.json | 3 +- .../GHSA-7prq-r42m-wfcx.json | 6 ++- .../GHSA-7rc8-rqg8-27m3.json | 11 +++-- .../GHSA-8f25-gjr3-mjjg.json | 11 +++-- .../GHSA-9v6p-294w-vpfg.json | 2 +- .../GHSA-9xvm-xmw3-2hm2.json | 6 ++- .../GHSA-ch4x-f5c4-36gv.json | 6 ++- .../GHSA-cmpj-4482-wc34.json | 11 +++-- .../GHSA-gmm6-5xx7-57r6.json | 10 +++- .../GHSA-h9cv-6mcv-ffr4.json | 38 +++++++++++++++ .../GHSA-hw83-24q6-v392.json | 6 ++- .../GHSA-j9gw-h8vh-cc5r.json | 35 ++++++++++++++ .../GHSA-jx8h-rc52-2jx8.json | 2 +- .../GHSA-m5m5-h3mf-ph9j.json | 2 +- .../GHSA-p5jm-j9rm-7m7m.json | 35 ++++++++++++++ .../GHSA-qvfw-rqcg-jh9g.json | 11 +++-- .../GHSA-rxm2-9pqc-4vv2.json | 11 +++-- .../GHSA-v5pp-g8vf-3fxg.json | 6 ++- .../GHSA-vwc8-7rg6-jffc.json | 42 +++++++++++++++++ .../GHSA-w3x2-w5xp-gm6x.json | 39 ++++++++++++++++ .../GHSA-w7m5-fr55-qch7.json | 6 ++- .../GHSA-x9px-jpvw-739v.json | 2 +- 38 files changed, 385 insertions(+), 50 deletions(-) create mode 100644 advisories/unreviewed/2024/07/GHSA-2m5h-vv32-6gjr/GHSA-2m5h-vv32-6gjr.json create mode 100644 advisories/unreviewed/2024/07/GHSA-h9cv-6mcv-ffr4/GHSA-h9cv-6mcv-ffr4.json create mode 100644 advisories/unreviewed/2024/07/GHSA-j9gw-h8vh-cc5r/GHSA-j9gw-h8vh-cc5r.json create mode 100644 advisories/unreviewed/2024/07/GHSA-p5jm-j9rm-7m7m/GHSA-p5jm-j9rm-7m7m.json create mode 100644 advisories/unreviewed/2024/07/GHSA-vwc8-7rg6-jffc/GHSA-vwc8-7rg6-jffc.json create mode 100644 advisories/unreviewed/2024/07/GHSA-w3x2-w5xp-gm6x/GHSA-w3x2-w5xp-gm6x.json diff --git a/advisories/github-reviewed/2022/05/GHSA-9pf8-qqhm-7w64/GHSA-9pf8-qqhm-7w64.json b/advisories/github-reviewed/2022/05/GHSA-9pf8-qqhm-7w64/GHSA-9pf8-qqhm-7w64.json index f042d5a122e..b68728e898e 100644 --- a/advisories/github-reviewed/2022/05/GHSA-9pf8-qqhm-7w64/GHSA-9pf8-qqhm-7w64.json +++ b/advisories/github-reviewed/2022/05/GHSA-9pf8-qqhm-7w64/GHSA-9pf8-qqhm-7w64.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9pf8-qqhm-7w64", - "modified": "2024-03-21T16:00:50Z", + "modified": "2024-07-19T15:31:45Z", "published": "2022-05-13T01:30:17Z", "aliases": [ "CVE-2018-10054" @@ -79,6 +79,10 @@ "type": "WEB", "url": "https://mthbernardes.github.io/rce/2018/03/14/abusing-h2-database-alias.html" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240719-0003" + }, { "type": "WEB", "url": "https://www.exploit-db.com/exploits/44422" diff --git a/advisories/unreviewed/2022/05/GHSA-38fg-rh2c-fh5c/GHSA-38fg-rh2c-fh5c.json b/advisories/unreviewed/2022/05/GHSA-38fg-rh2c-fh5c/GHSA-38fg-rh2c-fh5c.json index c4324cc1152..e226916ca11 100644 --- a/advisories/unreviewed/2022/05/GHSA-38fg-rh2c-fh5c/GHSA-38fg-rh2c-fh5c.json +++ b/advisories/unreviewed/2022/05/GHSA-38fg-rh2c-fh5c/GHSA-38fg-rh2c-fh5c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-38fg-rh2c-fh5c", - "modified": "2022-05-17T03:51:52Z", + "modified": "2024-07-19T15:31:45Z", "published": "2022-05-17T03:51:52Z", "aliases": [ "CVE-2016-3751" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://android.googlesource.com/platform/external/libpng/+/9d4853418ab2f754c2b63e091c29c5529b8b86ca" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240719-0004" + }, { "type": "WEB", "url": "http://source.android.com/security/bulletin/2016-07-01.html" diff --git a/advisories/unreviewed/2022/05/GHSA-5gg5-9r5r-wpgh/GHSA-5gg5-9r5r-wpgh.json b/advisories/unreviewed/2022/05/GHSA-5gg5-9r5r-wpgh/GHSA-5gg5-9r5r-wpgh.json index 7029d13777d..2f12a76ea42 100644 --- a/advisories/unreviewed/2022/05/GHSA-5gg5-9r5r-wpgh/GHSA-5gg5-9r5r-wpgh.json +++ b/advisories/unreviewed/2022/05/GHSA-5gg5-9r5r-wpgh/GHSA-5gg5-9r5r-wpgh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5gg5-9r5r-wpgh", - "modified": "2022-05-17T03:47:52Z", + "modified": "2024-07-19T15:31:45Z", "published": "2022-05-17T03:47:52Z", "aliases": [ "CVE-2015-0973" @@ -18,6 +18,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-0973" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240719-0005" + }, { "type": "WEB", "url": "https://support.apple.com/HT206167" diff --git a/advisories/unreviewed/2022/05/GHSA-g589-q56x-4rhp/GHSA-g589-q56x-4rhp.json b/advisories/unreviewed/2022/05/GHSA-g589-q56x-4rhp/GHSA-g589-q56x-4rhp.json index f13c260ea23..2cba7b65af6 100644 --- a/advisories/unreviewed/2022/05/GHSA-g589-q56x-4rhp/GHSA-g589-q56x-4rhp.json +++ b/advisories/unreviewed/2022/05/GHSA-g589-q56x-4rhp/GHSA-g589-q56x-4rhp.json @@ -93,7 +93,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-w7q3-c7q5-xfgf/GHSA-w7q3-c7q5-xfgf.json b/advisories/unreviewed/2022/05/GHSA-w7q3-c7q5-xfgf/GHSA-w7q3-c7q5-xfgf.json index 008f1957626..033640bb254 100644 --- a/advisories/unreviewed/2022/05/GHSA-w7q3-c7q5-xfgf/GHSA-w7q3-c7q5-xfgf.json +++ b/advisories/unreviewed/2022/05/GHSA-w7q3-c7q5-xfgf/GHSA-w7q3-c7q5-xfgf.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-3fr5-8rrj-9rf2/GHSA-3fr5-8rrj-9rf2.json b/advisories/unreviewed/2024/04/GHSA-3fr5-8rrj-9rf2/GHSA-3fr5-8rrj-9rf2.json index e3a503155f1..a52cc448a00 100644 --- a/advisories/unreviewed/2024/04/GHSA-3fr5-8rrj-9rf2/GHSA-3fr5-8rrj-9rf2.json +++ b/advisories/unreviewed/2024/04/GHSA-3fr5-8rrj-9rf2/GHSA-3fr5-8rrj-9rf2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3fr5-8rrj-9rf2", - "modified": "2024-07-18T00:31:19Z", + "modified": "2024-07-19T15:31:46Z", "published": "2024-04-13T15:34:57Z", "aliases": [ "CVE-2024-3735" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://mega.nz/file/3MUjTIiB#gMuogm3Vaqk-QLRXMtSS2dqlEJlnBhKal6CjeC-dIF8" }, + { + "type": "WEB", + "url": "https://mega.nz/file/7F0BSJhD#EvnXFRviBstJGHSafvLmVWosWH2JFPAouD6ER8wnGxk" + }, { "type": "WEB", "url": "https://mega.nz/file/jMEXzYQA#vrwPyvrHm80njR4N3UaZLonNizKec1nCXjtvXiqm9g0" diff --git a/advisories/unreviewed/2024/06/GHSA-23cc-8qjh-m5rg/GHSA-23cc-8qjh-m5rg.json b/advisories/unreviewed/2024/06/GHSA-23cc-8qjh-m5rg/GHSA-23cc-8qjh-m5rg.json index cb9dd33b430..e919473e1e7 100644 --- a/advisories/unreviewed/2024/06/GHSA-23cc-8qjh-m5rg/GHSA-23cc-8qjh-m5rg.json +++ b/advisories/unreviewed/2024/06/GHSA-23cc-8qjh-m5rg/GHSA-23cc-8qjh-m5rg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-23cc-8qjh-m5rg", - "modified": "2024-06-15T15:30:27Z", + "modified": "2024-07-19T15:31:46Z", "published": "2024-06-15T15:30:27Z", "aliases": [ "CVE-2024-6008" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-49m8-f75j-fw3p/GHSA-49m8-f75j-fw3p.json b/advisories/unreviewed/2024/06/GHSA-49m8-f75j-fw3p/GHSA-49m8-f75j-fw3p.json index 4d977aa2885..37018ad1c34 100644 --- a/advisories/unreviewed/2024/06/GHSA-49m8-f75j-fw3p/GHSA-49m8-f75j-fw3p.json +++ b/advisories/unreviewed/2024/06/GHSA-49m8-f75j-fw3p/GHSA-49m8-f75j-fw3p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-49m8-f75j-fw3p", - "modified": "2024-06-15T18:30:35Z", + "modified": "2024-07-19T15:31:46Z", "published": "2024-06-15T18:30:35Z", "aliases": [ "CVE-2024-6009" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-8vwj-6qr9-pvp7/GHSA-8vwj-6qr9-pvp7.json b/advisories/unreviewed/2024/06/GHSA-8vwj-6qr9-pvp7/GHSA-8vwj-6qr9-pvp7.json index b64ad175090..cbe3ffed167 100644 --- a/advisories/unreviewed/2024/06/GHSA-8vwj-6qr9-pvp7/GHSA-8vwj-6qr9-pvp7.json +++ b/advisories/unreviewed/2024/06/GHSA-8vwj-6qr9-pvp7/GHSA-8vwj-6qr9-pvp7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8vwj-6qr9-pvp7", - "modified": "2024-06-15T18:30:35Z", + "modified": "2024-07-19T15:31:46Z", "published": "2024-06-15T18:30:35Z", "aliases": [ "CVE-2024-6013" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-m5jq-qvgg-36pq/GHSA-m5jq-qvgg-36pq.json b/advisories/unreviewed/2024/06/GHSA-m5jq-qvgg-36pq/GHSA-m5jq-qvgg-36pq.json index 28302309ce9..32d962a5ddd 100644 --- a/advisories/unreviewed/2024/06/GHSA-m5jq-qvgg-36pq/GHSA-m5jq-qvgg-36pq.json +++ b/advisories/unreviewed/2024/06/GHSA-m5jq-qvgg-36pq/GHSA-m5jq-qvgg-36pq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m5jq-qvgg-36pq", - "modified": "2024-06-15T18:30:35Z", + "modified": "2024-07-19T15:31:46Z", "published": "2024-06-15T18:30:35Z", "aliases": [ "CVE-2024-6015" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-pwfh-2pj9-f3rc/GHSA-pwfh-2pj9-f3rc.json b/advisories/unreviewed/2024/06/GHSA-pwfh-2pj9-f3rc/GHSA-pwfh-2pj9-f3rc.json index 6c10c06283e..fb32066330b 100644 --- a/advisories/unreviewed/2024/06/GHSA-pwfh-2pj9-f3rc/GHSA-pwfh-2pj9-f3rc.json +++ b/advisories/unreviewed/2024/06/GHSA-pwfh-2pj9-f3rc/GHSA-pwfh-2pj9-f3rc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pwfh-2pj9-f3rc", - "modified": "2024-06-13T18:31:58Z", + "modified": "2024-07-19T15:31:46Z", "published": "2024-06-13T18:31:58Z", "aliases": [ "CVE-2024-35328" ], "details": "libyaml v0.2.5 is vulnerable to DDOS. Affected by this issue is the function yaml_parser_parse of the file /src/libyaml/src/parser.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-835" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T16:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-v575-95ph-534m/GHSA-v575-95ph-534m.json b/advisories/unreviewed/2024/06/GHSA-v575-95ph-534m/GHSA-v575-95ph-534m.json index 6023e7fe820..87a1b0c0525 100644 --- a/advisories/unreviewed/2024/06/GHSA-v575-95ph-534m/GHSA-v575-95ph-534m.json +++ b/advisories/unreviewed/2024/06/GHSA-v575-95ph-534m/GHSA-v575-95ph-534m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v575-95ph-534m", - "modified": "2024-06-15T18:30:35Z", + "modified": "2024-07-19T15:31:46Z", "published": "2024-06-15T18:30:35Z", "aliases": [ "CVE-2024-6014" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-xrrx-xr48-h4jv/GHSA-xrrx-xr48-h4jv.json b/advisories/unreviewed/2024/06/GHSA-xrrx-xr48-h4jv/GHSA-xrrx-xr48-h4jv.json index d44f3da933a..dc56d5a7ff4 100644 --- a/advisories/unreviewed/2024/06/GHSA-xrrx-xr48-h4jv/GHSA-xrrx-xr48-h4jv.json +++ b/advisories/unreviewed/2024/06/GHSA-xrrx-xr48-h4jv/GHSA-xrrx-xr48-h4jv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xrrx-xr48-h4jv", - "modified": "2024-06-15T21:30:33Z", + "modified": "2024-07-19T15:31:46Z", "published": "2024-06-15T21:30:33Z", "aliases": [ "CVE-2024-6016" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/07/GHSA-2m5h-vv32-6gjr/GHSA-2m5h-vv32-6gjr.json b/advisories/unreviewed/2024/07/GHSA-2m5h-vv32-6gjr/GHSA-2m5h-vv32-6gjr.json new file mode 100644 index 00000000000..031c0dc94ec --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-2m5h-vv32-6gjr/GHSA-2m5h-vv32-6gjr.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2m5h-vv32-6gjr", + "modified": "2024-07-19T15:31:47Z", + "published": "2024-07-19T15:31:47Z", + "aliases": [ + "CVE-2024-0006" + ], + "details": "Information exposure in the logging system in Yugabyte Platform allows local attackers with access to application logs to obtain database user credentials in log files, potentially leading to unauthorized database access.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0006" + }, + { + "type": "WEB", + "url": "https://github.com/yugabyte/yugabyte-db/commit/439c6286f1971f9ac6bff2c7215b454c2025c593" + }, + { + "type": "WEB", + "url": "https://github.com/yugabyte/yugabyte-db/commit/5cc7f4e15d6ccccbf97c57946fd0aa630f88c9e2" + }, + { + "type": "WEB", + "url": "https://github.com/yugabyte/yugabyte-db/commit/d96e6b629f34d065b47204daeeb44064e484c579" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-19T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-4mqw-v4pq-hg97/GHSA-4mqw-v4pq-hg97.json b/advisories/unreviewed/2024/07/GHSA-4mqw-v4pq-hg97/GHSA-4mqw-v4pq-hg97.json index 07dcaaf75fb..23ff38bfa83 100644 --- a/advisories/unreviewed/2024/07/GHSA-4mqw-v4pq-hg97/GHSA-4mqw-v4pq-hg97.json +++ b/advisories/unreviewed/2024/07/GHSA-4mqw-v4pq-hg97/GHSA-4mqw-v4pq-hg97.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4mqw-v4pq-hg97", - "modified": "2024-07-17T00:32:55Z", + "modified": "2024-07-19T15:31:46Z", "published": "2024-07-17T00:32:55Z", "aliases": [ "CVE-2024-21145" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21145" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240719-0008" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujul2024.html" diff --git a/advisories/unreviewed/2024/07/GHSA-4rqr-f9qq-h7w3/GHSA-4rqr-f9qq-h7w3.json b/advisories/unreviewed/2024/07/GHSA-4rqr-f9qq-h7w3/GHSA-4rqr-f9qq-h7w3.json index d16d4663bb6..41598bd288d 100644 --- a/advisories/unreviewed/2024/07/GHSA-4rqr-f9qq-h7w3/GHSA-4rqr-f9qq-h7w3.json +++ b/advisories/unreviewed/2024/07/GHSA-4rqr-f9qq-h7w3/GHSA-4rqr-f9qq-h7w3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4rqr-f9qq-h7w3", - "modified": "2024-07-17T00:32:54Z", + "modified": "2024-07-19T15:31:46Z", "published": "2024-07-17T00:32:54Z", "aliases": [ "CVE-2024-21138" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21138" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240719-0008" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujul2024.html" diff --git a/advisories/unreviewed/2024/07/GHSA-5qwh-g35c-5mmm/GHSA-5qwh-g35c-5mmm.json b/advisories/unreviewed/2024/07/GHSA-5qwh-g35c-5mmm/GHSA-5qwh-g35c-5mmm.json index b3cc2725c7b..a15f848f197 100644 --- a/advisories/unreviewed/2024/07/GHSA-5qwh-g35c-5mmm/GHSA-5qwh-g35c-5mmm.json +++ b/advisories/unreviewed/2024/07/GHSA-5qwh-g35c-5mmm/GHSA-5qwh-g35c-5mmm.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-427" + "CWE-427", + "CWE-434" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-7prq-r42m-wfcx/GHSA-7prq-r42m-wfcx.json b/advisories/unreviewed/2024/07/GHSA-7prq-r42m-wfcx/GHSA-7prq-r42m-wfcx.json index 4058b48d463..634ca27302c 100644 --- a/advisories/unreviewed/2024/07/GHSA-7prq-r42m-wfcx/GHSA-7prq-r42m-wfcx.json +++ b/advisories/unreviewed/2024/07/GHSA-7prq-r42m-wfcx/GHSA-7prq-r42m-wfcx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7prq-r42m-wfcx", - "modified": "2024-07-17T00:32:54Z", + "modified": "2024-07-19T15:31:46Z", "published": "2024-07-17T00:32:54Z", "aliases": [ "CVE-2024-21140" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21140" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240719-0008" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujul2024.html" diff --git a/advisories/unreviewed/2024/07/GHSA-7rc8-rqg8-27m3/GHSA-7rc8-rqg8-27m3.json b/advisories/unreviewed/2024/07/GHSA-7rc8-rqg8-27m3/GHSA-7rc8-rqg8-27m3.json index 30aaa856947..c3160051687 100644 --- a/advisories/unreviewed/2024/07/GHSA-7rc8-rqg8-27m3/GHSA-7rc8-rqg8-27m3.json +++ b/advisories/unreviewed/2024/07/GHSA-7rc8-rqg8-27m3/GHSA-7rc8-rqg8-27m3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7rc8-rqg8-27m3", - "modified": "2024-07-18T12:30:52Z", + "modified": "2024-07-19T15:31:47Z", "published": "2024-07-17T09:30:47Z", "aliases": [ "CVE-2024-41010" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix too early release of tcx_entry\n\nPedro Pinto and later independently also Hyunwoo Kim and Wongi Lee reported\nan issue that the tcx_entry can be released too early leading to a use\nafter free (UAF) when an active old-style ingress or clsact qdisc with a\nshared tc block is later replaced by another ingress or clsact instance.\n\nEssentially, the sequence to trigger the UAF (one example) can be as follows:\n\n 1. A network namespace is created\n 2. An ingress qdisc is created. This allocates a tcx_entry, and\n &tcx_entry->miniq is stored in the qdisc's miniqp->p_miniq. At the\n same time, a tcf block with index 1 is created.\n 3. chain0 is attached to the tcf block. chain0 must be connected to\n the block linked to the ingress qdisc to later reach the function\n tcf_chain0_head_change_cb_del() which triggers the UAF.\n 4. Create and graft a clsact qdisc. This causes the ingress qdisc\n created in step 1 to be removed, thus freeing the previously linked\n tcx_entry:\n\n rtnetlink_rcv_msg()\n => tc_modify_qdisc()\n => qdisc_create()\n => clsact_init() [a]\n => qdisc_graft()\n => qdisc_destroy()\n => __qdisc_destroy()\n => ingress_destroy() [b]\n => tcx_entry_free()\n => kfree_rcu() // tcx_entry freed\n\n 5. Finally, the network namespace is closed. This registers the\n cleanup_net worker, and during the process of releasing the\n remaining clsact qdisc, it accesses the tcx_entry that was\n already freed in step 4, causing the UAF to occur:\n\n cleanup_net()\n => ops_exit_list()\n => default_device_exit_batch()\n => unregister_netdevice_many()\n => unregister_netdevice_many_notify()\n => dev_shutdown()\n => qdisc_put()\n => clsact_destroy() [c]\n => tcf_block_put_ext()\n => tcf_chain0_head_change_cb_del()\n => tcf_chain_head_change_item()\n => clsact_chain_head_change()\n => mini_qdisc_pair_swap() // UAF\n\nThere are also other variants, the gist is to add an ingress (or clsact)\nqdisc with a specific shared block, then to replace that qdisc, waiting\nfor the tcx_entry kfree_rcu() to be executed and subsequently accessing\nthe current active qdisc's miniq one way or another.\n\nThe correct fix is to turn the miniq_active boolean into a counter. What\ncan be observed, at step 2 above, the counter transitions from 0->1, at\nstep [a] from 1->2 (in order for the miniq object to remain active during\nthe replacement), then in [b] from 2->1 and finally [c] 1->0 with the\neventual release. The reference counter in general ranges from [0,2] and\nit does not need to be atomic since all access to the counter is protected\nby the rtnl mutex. With this in place, there is no longer a UAF happening\nand the tcx_entry is freed at the correct time.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-17T07:15:02Z" diff --git a/advisories/unreviewed/2024/07/GHSA-8f25-gjr3-mjjg/GHSA-8f25-gjr3-mjjg.json b/advisories/unreviewed/2024/07/GHSA-8f25-gjr3-mjjg/GHSA-8f25-gjr3-mjjg.json index cb2d01b871d..6d3206031ad 100644 --- a/advisories/unreviewed/2024/07/GHSA-8f25-gjr3-mjjg/GHSA-8f25-gjr3-mjjg.json +++ b/advisories/unreviewed/2024/07/GHSA-8f25-gjr3-mjjg/GHSA-8f25-gjr3-mjjg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8f25-gjr3-mjjg", - "modified": "2024-07-17T00:32:56Z", + "modified": "2024-07-19T15:31:47Z", "published": "2024-07-17T00:32:55Z", "aliases": [ "CVE-2024-3169" ], "details": "Use after free in V8 in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-16T23:15:23Z" diff --git a/advisories/unreviewed/2024/07/GHSA-9v6p-294w-vpfg/GHSA-9v6p-294w-vpfg.json b/advisories/unreviewed/2024/07/GHSA-9v6p-294w-vpfg/GHSA-9v6p-294w-vpfg.json index 1ffa1110cb2..a277f694782 100644 --- a/advisories/unreviewed/2024/07/GHSA-9v6p-294w-vpfg/GHSA-9v6p-294w-vpfg.json +++ b/advisories/unreviewed/2024/07/GHSA-9v6p-294w-vpfg/GHSA-9v6p-294w-vpfg.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-9xvm-xmw3-2hm2/GHSA-9xvm-xmw3-2hm2.json b/advisories/unreviewed/2024/07/GHSA-9xvm-xmw3-2hm2/GHSA-9xvm-xmw3-2hm2.json index 4df1e1eb22f..fc03258cd4a 100644 --- a/advisories/unreviewed/2024/07/GHSA-9xvm-xmw3-2hm2/GHSA-9xvm-xmw3-2hm2.json +++ b/advisories/unreviewed/2024/07/GHSA-9xvm-xmw3-2hm2/GHSA-9xvm-xmw3-2hm2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9xvm-xmw3-2hm2", - "modified": "2024-07-11T21:31:12Z", + "modified": "2024-07-19T15:31:46Z", "published": "2024-07-10T03:30:35Z", "aliases": [ "CVE-2024-22018" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/07/11/6" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/19/3" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-ch4x-f5c4-36gv/GHSA-ch4x-f5c4-36gv.json b/advisories/unreviewed/2024/07/GHSA-ch4x-f5c4-36gv/GHSA-ch4x-f5c4-36gv.json index 637d75d7504..f01ce1d42ae 100644 --- a/advisories/unreviewed/2024/07/GHSA-ch4x-f5c4-36gv/GHSA-ch4x-f5c4-36gv.json +++ b/advisories/unreviewed/2024/07/GHSA-ch4x-f5c4-36gv/GHSA-ch4x-f5c4-36gv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ch4x-f5c4-36gv", - "modified": "2024-07-11T21:31:12Z", + "modified": "2024-07-19T15:31:46Z", "published": "2024-07-09T03:31:44Z", "aliases": [ "CVE-2024-22020" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/07/11/6" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/19/3" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-cmpj-4482-wc34/GHSA-cmpj-4482-wc34.json b/advisories/unreviewed/2024/07/GHSA-cmpj-4482-wc34/GHSA-cmpj-4482-wc34.json index dd564a27225..94c6290e64d 100644 --- a/advisories/unreviewed/2024/07/GHSA-cmpj-4482-wc34/GHSA-cmpj-4482-wc34.json +++ b/advisories/unreviewed/2024/07/GHSA-cmpj-4482-wc34/GHSA-cmpj-4482-wc34.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cmpj-4482-wc34", - "modified": "2024-07-17T00:32:56Z", + "modified": "2024-07-19T15:31:47Z", "published": "2024-07-17T00:32:55Z", "aliases": [ "CVE-2024-3168" ], "details": "Use after free in DevTools in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-16T23:15:23Z" diff --git a/advisories/unreviewed/2024/07/GHSA-gmm6-5xx7-57r6/GHSA-gmm6-5xx7-57r6.json b/advisories/unreviewed/2024/07/GHSA-gmm6-5xx7-57r6/GHSA-gmm6-5xx7-57r6.json index 41aea6c2a9b..66538166f5a 100644 --- a/advisories/unreviewed/2024/07/GHSA-gmm6-5xx7-57r6/GHSA-gmm6-5xx7-57r6.json +++ b/advisories/unreviewed/2024/07/GHSA-gmm6-5xx7-57r6/GHSA-gmm6-5xx7-57r6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gmm6-5xx7-57r6", - "modified": "2024-07-19T12:31:28Z", + "modified": "2024-07-19T15:31:47Z", "published": "2024-07-19T12:31:28Z", "aliases": [ "CVE-2024-41107" @@ -33,6 +33,14 @@ { "type": "WEB", "url": "https://www.shapeblue.com/shapeblue-security-advisory-apache-cloudstack-cve-2024-41107" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/19/1" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/19/2" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-h9cv-6mcv-ffr4/GHSA-h9cv-6mcv-ffr4.json b/advisories/unreviewed/2024/07/GHSA-h9cv-6mcv-ffr4/GHSA-h9cv-6mcv-ffr4.json new file mode 100644 index 00000000000..a39c9924a53 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-h9cv-6mcv-ffr4/GHSA-h9cv-6mcv-ffr4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9cv-6mcv-ffr4", + "modified": "2024-07-19T15:31:47Z", + "published": "2024-07-19T15:31:47Z", + "aliases": [ + "CVE-2024-6895" + ], + "details": "Insufficient authentication in user account management in Yugabyte Platform allows local network attackers with a compromised user session to change critical security information without re-authentication. An attacker with user session and access to application can modify settings such as password and email without being prompted for the current password, enabling account takeover.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:P/VC:H/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6895" + }, + { + "type": "WEB", + "url": "https://github.com/yugabyte/yugabyte-db/commit/9687371d8777f876285b737a9d01995bc46bafa5" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-19T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-hw83-24q6-v392/GHSA-hw83-24q6-v392.json b/advisories/unreviewed/2024/07/GHSA-hw83-24q6-v392/GHSA-hw83-24q6-v392.json index 8736abe9334..c78ab1afe46 100644 --- a/advisories/unreviewed/2024/07/GHSA-hw83-24q6-v392/GHSA-hw83-24q6-v392.json +++ b/advisories/unreviewed/2024/07/GHSA-hw83-24q6-v392/GHSA-hw83-24q6-v392.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hw83-24q6-v392", - "modified": "2024-07-17T00:32:55Z", + "modified": "2024-07-19T15:31:47Z", "published": "2024-07-17T00:32:55Z", "aliases": [ "CVE-2024-21147" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21147" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240719-0008" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujul2024.html" diff --git a/advisories/unreviewed/2024/07/GHSA-j9gw-h8vh-cc5r/GHSA-j9gw-h8vh-cc5r.json b/advisories/unreviewed/2024/07/GHSA-j9gw-h8vh-cc5r/GHSA-j9gw-h8vh-cc5r.json new file mode 100644 index 00000000000..1c1e92586cf --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-j9gw-h8vh-cc5r/GHSA-j9gw-h8vh-cc5r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9gw-h8vh-cc5r", + "modified": "2024-07-19T15:31:47Z", + "published": "2024-07-19T15:31:47Z", + "aliases": [ + "CVE-2024-39963" + ], + "details": "AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX9 V22.03.01.46 and AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX12 V1.0 V22.03.01.46 were discovered to contain an authenticated remote command execution (RCE) vulnerability via the macFilterType parameter at /goform/setMacFilterCfg.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39963" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Swind1er/c8e4369c7fdfd750c8ad01a276105c57" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-19T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-jx8h-rc52-2jx8/GHSA-jx8h-rc52-2jx8.json b/advisories/unreviewed/2024/07/GHSA-jx8h-rc52-2jx8/GHSA-jx8h-rc52-2jx8.json index 0e866ec8c66..157bc128157 100644 --- a/advisories/unreviewed/2024/07/GHSA-jx8h-rc52-2jx8/GHSA-jx8h-rc52-2jx8.json +++ b/advisories/unreviewed/2024/07/GHSA-jx8h-rc52-2jx8/GHSA-jx8h-rc52-2jx8.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-m5m5-h3mf-ph9j/GHSA-m5m5-h3mf-ph9j.json b/advisories/unreviewed/2024/07/GHSA-m5m5-h3mf-ph9j/GHSA-m5m5-h3mf-ph9j.json index 428df256f95..528c4ad1567 100644 --- a/advisories/unreviewed/2024/07/GHSA-m5m5-h3mf-ph9j/GHSA-m5m5-h3mf-ph9j.json +++ b/advisories/unreviewed/2024/07/GHSA-m5m5-h3mf-ph9j/GHSA-m5m5-h3mf-ph9j.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-p5jm-j9rm-7m7m/GHSA-p5jm-j9rm-7m7m.json b/advisories/unreviewed/2024/07/GHSA-p5jm-j9rm-7m7m/GHSA-p5jm-j9rm-7m7m.json new file mode 100644 index 00000000000..1660d9fa9e3 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-p5jm-j9rm-7m7m/GHSA-p5jm-j9rm-7m7m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5jm-j9rm-7m7m", + "modified": "2024-07-19T15:31:47Z", + "published": "2024-07-19T15:31:47Z", + "aliases": [ + "CVE-2024-39962" + ], + "details": "D-Link DIR-823X AX3000 Dual-Band Gigabit Wireless Router v21_D240126 was discovered to contain a remote code execution (RCE) vulnerability in the ntp_zone_val parameter at /goform/set_ntp. This vulnerability is exploited via a crafted HTTP request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39962" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Swind1er/40c33f1b1549028677cb4e2e5ef69109" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-19T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-qvfw-rqcg-jh9g/GHSA-qvfw-rqcg-jh9g.json b/advisories/unreviewed/2024/07/GHSA-qvfw-rqcg-jh9g/GHSA-qvfw-rqcg-jh9g.json index dfb499b069c..db83e8c8205 100644 --- a/advisories/unreviewed/2024/07/GHSA-qvfw-rqcg-jh9g/GHSA-qvfw-rqcg-jh9g.json +++ b/advisories/unreviewed/2024/07/GHSA-qvfw-rqcg-jh9g/GHSA-qvfw-rqcg-jh9g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qvfw-rqcg-jh9g", - "modified": "2024-07-17T09:30:47Z", + "modified": "2024-07-19T15:31:47Z", "published": "2024-07-17T09:30:47Z", "aliases": [ "CVE-2024-41009" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix overrunning reservations in ringbuf\n\nThe BPF ring buffer internally is implemented as a power-of-2 sized circular\nbuffer, with two logical and ever-increasing counters: consumer_pos is the\nconsumer counter to show which logical position the consumer consumed the\ndata, and producer_pos which is the producer counter denoting the amount of\ndata reserved by all producers.\n\nEach time a record is reserved, the producer that \"owns\" the record will\nsuccessfully advance producer counter. In user space each time a record is\nread, the consumer of the data advanced the consumer counter once it finished\nprocessing. Both counters are stored in separate pages so that from user\nspace, the producer counter is read-only and the consumer counter is read-write.\n\nOne aspect that simplifies and thus speeds up the implementation of both\nproducers and consumers is how the data area is mapped twice contiguously\nback-to-back in the virtual memory, allowing to not take any special measures\nfor samples that have to wrap around at the end of the circular buffer data\narea, because the next page after the last data page would be first data page\nagain, and thus the sample will still appear completely contiguous in virtual\nmemory.\n\nEach record has a struct bpf_ringbuf_hdr { u32 len; u32 pg_off; } header for\nbook-keeping the length and offset, and is inaccessible to the BPF program.\nHelpers like bpf_ringbuf_reserve() return `(void *)hdr + BPF_RINGBUF_HDR_SZ`\nfor the BPF program to use. Bing-Jhong and Muhammad reported that it is however\npossible to make a second allocated memory chunk overlapping with the first\nchunk and as a result, the BPF program is now able to edit first chunk's\nheader.\n\nFor example, consider the creation of a BPF_MAP_TYPE_RINGBUF map with size\nof 0x4000. Next, the consumer_pos is modified to 0x3000 /before/ a call to\nbpf_ringbuf_reserve() is made. This will allocate a chunk A, which is in\n[0x0,0x3008], and the BPF program is able to edit [0x8,0x3008]. Now, lets\nallocate a chunk B with size 0x3000. This will succeed because consumer_pos\nwas edited ahead of time to pass the `new_prod_pos - cons_pos > rb->mask`\ncheck. Chunk B will be in range [0x3008,0x6010], and the BPF program is able\nto edit [0x3010,0x6010]. Due to the ring buffer memory layout mentioned\nearlier, the ranges [0x0,0x4000] and [0x4000,0x8000] point to the same data\npages. This means that chunk B at [0x4000,0x4008] is chunk A's header.\nbpf_ringbuf_submit() / bpf_ringbuf_discard() use the header's pg_off to then\nlocate the bpf_ringbuf itself via bpf_ringbuf_restore_from_rec(). Once chunk\nB modified chunk A's header, then bpf_ringbuf_commit() refers to the wrong\npage and could cause a crash.\n\nFix it by calculating the oldest pending_pos and check whether the range\nfrom the oldest outstanding record to the newest would span beyond the ring\nbuffer size. If that is the case, then reject the request. We've tested with\nthe ring buffer benchmark in BPF selftests (./benchs/run_bench_ringbufs.sh)\nbefore/after the fix and while it seems a bit slower on some benchmarks, it\nis still not significantly enough to matter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-17T07:15:01Z" diff --git a/advisories/unreviewed/2024/07/GHSA-rxm2-9pqc-4vv2/GHSA-rxm2-9pqc-4vv2.json b/advisories/unreviewed/2024/07/GHSA-rxm2-9pqc-4vv2/GHSA-rxm2-9pqc-4vv2.json index cbd43853cdb..76415d14c3b 100644 --- a/advisories/unreviewed/2024/07/GHSA-rxm2-9pqc-4vv2/GHSA-rxm2-9pqc-4vv2.json +++ b/advisories/unreviewed/2024/07/GHSA-rxm2-9pqc-4vv2/GHSA-rxm2-9pqc-4vv2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rxm2-9pqc-4vv2", - "modified": "2024-07-17T00:32:55Z", + "modified": "2024-07-19T15:31:47Z", "published": "2024-07-17T00:32:55Z", "aliases": [ "CVE-2024-2884" ], "details": "Out of bounds read in V8 in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-16T23:15:23Z" diff --git a/advisories/unreviewed/2024/07/GHSA-v5pp-g8vf-3fxg/GHSA-v5pp-g8vf-3fxg.json b/advisories/unreviewed/2024/07/GHSA-v5pp-g8vf-3fxg/GHSA-v5pp-g8vf-3fxg.json index 5a24226ef97..9664f34206b 100644 --- a/advisories/unreviewed/2024/07/GHSA-v5pp-g8vf-3fxg/GHSA-v5pp-g8vf-3fxg.json +++ b/advisories/unreviewed/2024/07/GHSA-v5pp-g8vf-3fxg/GHSA-v5pp-g8vf-3fxg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v5pp-g8vf-3fxg", - "modified": "2024-07-17T00:32:54Z", + "modified": "2024-07-19T15:31:46Z", "published": "2024-07-17T00:32:54Z", "aliases": [ "CVE-2024-21131" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21131" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240719-0008" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujul2024.html" diff --git a/advisories/unreviewed/2024/07/GHSA-vwc8-7rg6-jffc/GHSA-vwc8-7rg6-jffc.json b/advisories/unreviewed/2024/07/GHSA-vwc8-7rg6-jffc/GHSA-vwc8-7rg6-jffc.json new file mode 100644 index 00000000000..e1751a6f8d8 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-vwc8-7rg6-jffc/GHSA-vwc8-7rg6-jffc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vwc8-7rg6-jffc", + "modified": "2024-07-19T15:31:47Z", + "published": "2024-07-19T15:31:47Z", + "aliases": [ + "CVE-2024-6908" + ], + "details": "Improper privilege management in Yugabyte Platform allows authenticated admin users to escalate privileges to SuperAdmin via a crafted PUT HTTP request, potentially leading to unauthorized access to sensitive system functions and data.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:P/VC:L/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6908" + }, + { + "type": "WEB", + "url": "https://github.com/yugabyte/yugabyte-db/commit/03b193de40b79329439bb9968a7d27a1cc57d662" + }, + { + "type": "WEB", + "url": "https://github.com/yugabyte/yugabyte-db/commit/68f01680c565be2a370cfb7734a1b3721d6778bb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-19T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-w3x2-w5xp-gm6x/GHSA-w3x2-w5xp-gm6x.json b/advisories/unreviewed/2024/07/GHSA-w3x2-w5xp-gm6x/GHSA-w3x2-w5xp-gm6x.json new file mode 100644 index 00000000000..0a577ccaf1c --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-w3x2-w5xp-gm6x/GHSA-w3x2-w5xp-gm6x.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3x2-w5xp-gm6x", + "modified": "2024-07-19T15:31:47Z", + "published": "2024-07-19T15:31:47Z", + "aliases": [ + "CVE-2024-27489" + ], + "details": "An issue in the DelFile() function of WMCMS v4.4 allows attackers to delete arbitrary files via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27489" + }, + { + "type": "WEB", + "url": "https://gist.github.com/yyyyy7777777/a36541cb60d9e55628f78f2a68968212" + }, + { + "type": "WEB", + "url": "https://gitee.com/y1336247431/poc-public/issues/I920OW" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-19T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-w7m5-fr55-qch7/GHSA-w7m5-fr55-qch7.json b/advisories/unreviewed/2024/07/GHSA-w7m5-fr55-qch7/GHSA-w7m5-fr55-qch7.json index 7528c67dd41..18827e8d011 100644 --- a/advisories/unreviewed/2024/07/GHSA-w7m5-fr55-qch7/GHSA-w7m5-fr55-qch7.json +++ b/advisories/unreviewed/2024/07/GHSA-w7m5-fr55-qch7/GHSA-w7m5-fr55-qch7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w7m5-fr55-qch7", - "modified": "2024-07-17T00:32:54Z", + "modified": "2024-07-19T15:31:47Z", "published": "2024-07-17T00:32:54Z", "aliases": [ "CVE-2024-21144" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21144" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240719-0007" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujul2024.html" diff --git a/advisories/unreviewed/2024/07/GHSA-x9px-jpvw-739v/GHSA-x9px-jpvw-739v.json b/advisories/unreviewed/2024/07/GHSA-x9px-jpvw-739v/GHSA-x9px-jpvw-739v.json index 7a82f57e3ed..3cd67db8cb8 100644 --- a/advisories/unreviewed/2024/07/GHSA-x9px-jpvw-739v/GHSA-x9px-jpvw-739v.json +++ b/advisories/unreviewed/2024/07/GHSA-x9px-jpvw-739v/GHSA-x9px-jpvw-739v.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false,