From 26e4a38979ec7ed4284a05180346fba49844a18b Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 19 Nov 2024 15:32:57 +0000 Subject: [PATCH] Publish Advisories GHSA-f47h-hr72-5959 GHSA-8gr4-jgmh-5g8w GHSA-9q6c-4f46-hgf2 GHSA-v5hx-2wwf-52wx GHSA-545f-546q-5w2v GHSA-5q4h-gp9j-4wfr GHSA-6hvr-5xqv-qc9j GHSA-7343-r6j5-pcf7 GHSA-939f-42q9-6v9h GHSA-crh9-vmx5-ggr8 GHSA-f75h-cwp9-8h5x GHSA-j3h2-4rr5-87p6 GHSA-jm4h-wwjv-4q5c GHSA-mqrm-h2pw-9j9r GHSA-rmm3-pvp6-hmx9 GHSA-vq94-gp7r-66mp --- .../GHSA-f47h-hr72-5959.json | 1 + .../GHSA-8gr4-jgmh-5g8w.json | 7 ++- .../GHSA-9q6c-4f46-hgf2.json | 10 +++- .../GHSA-v5hx-2wwf-52wx.json | 7 ++- .../GHSA-545f-546q-5w2v.json | 50 ++++++++++++++++ .../GHSA-5q4h-gp9j-4wfr.json | 38 ++++++++++++ .../GHSA-6hvr-5xqv-qc9j.json | 50 ++++++++++++++++ .../GHSA-7343-r6j5-pcf7.json | 11 ++-- .../GHSA-939f-42q9-6v9h.json | 54 +++++++++++++++++ .../GHSA-crh9-vmx5-ggr8.json | 35 +++++++++++ .../GHSA-f75h-cwp9-8h5x.json | 6 +- .../GHSA-j3h2-4rr5-87p6.json | 58 +++++++++++++++++++ .../GHSA-jm4h-wwjv-4q5c.json | 9 ++- .../GHSA-mqrm-h2pw-9j9r.json | 46 +++++++++++++++ .../GHSA-rmm3-pvp6-hmx9.json | 35 +++++++++++ .../GHSA-vq94-gp7r-66mp.json | 54 +++++++++++++++++ 16 files changed, 456 insertions(+), 15 deletions(-) create mode 100644 advisories/unreviewed/2024/11/GHSA-545f-546q-5w2v/GHSA-545f-546q-5w2v.json create mode 100644 advisories/unreviewed/2024/11/GHSA-5q4h-gp9j-4wfr/GHSA-5q4h-gp9j-4wfr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-6hvr-5xqv-qc9j/GHSA-6hvr-5xqv-qc9j.json create mode 100644 advisories/unreviewed/2024/11/GHSA-939f-42q9-6v9h/GHSA-939f-42q9-6v9h.json create mode 100644 advisories/unreviewed/2024/11/GHSA-crh9-vmx5-ggr8/GHSA-crh9-vmx5-ggr8.json create mode 100644 advisories/unreviewed/2024/11/GHSA-j3h2-4rr5-87p6/GHSA-j3h2-4rr5-87p6.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mqrm-h2pw-9j9r/GHSA-mqrm-h2pw-9j9r.json create mode 100644 advisories/unreviewed/2024/11/GHSA-rmm3-pvp6-hmx9/GHSA-rmm3-pvp6-hmx9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-vq94-gp7r-66mp/GHSA-vq94-gp7r-66mp.json diff --git a/advisories/unreviewed/2022/04/GHSA-f47h-hr72-5959/GHSA-f47h-hr72-5959.json b/advisories/unreviewed/2022/04/GHSA-f47h-hr72-5959/GHSA-f47h-hr72-5959.json index 9674670b315..03d2dde8d3c 100644 --- a/advisories/unreviewed/2022/04/GHSA-f47h-hr72-5959/GHSA-f47h-hr72-5959.json +++ b/advisories/unreviewed/2022/04/GHSA-f47h-hr72-5959/GHSA-f47h-hr72-5959.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-285", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/05/GHSA-8gr4-jgmh-5g8w/GHSA-8gr4-jgmh-5g8w.json b/advisories/unreviewed/2022/05/GHSA-8gr4-jgmh-5g8w/GHSA-8gr4-jgmh-5g8w.json index 77ad0040a91..762cec4d36b 100644 --- a/advisories/unreviewed/2022/05/GHSA-8gr4-jgmh-5g8w/GHSA-8gr4-jgmh-5g8w.json +++ b/advisories/unreviewed/2022/05/GHSA-8gr4-jgmh-5g8w/GHSA-8gr4-jgmh-5g8w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8gr4-jgmh-5g8w", - "modified": "2022-05-24T22:28:27Z", + "modified": "2024-11-19T15:31:50Z", "published": "2022-05-24T22:28:27Z", "aliases": [ "CVE-2021-25964" ], "details": "In “Calibre-web” application, v0.6.0 to v0.6.12, are vulnerable to Stored XSS in “Metadata”. An attacker that has access to edit the metadata information, can inject JavaScript payload in the description field. When a victim tries to open the file, XSS will be triggered.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-9q6c-4f46-hgf2/GHSA-9q6c-4f46-hgf2.json b/advisories/unreviewed/2022/05/GHSA-9q6c-4f46-hgf2/GHSA-9q6c-4f46-hgf2.json index f48db740017..fd4533669e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-9q6c-4f46-hgf2/GHSA-9q6c-4f46-hgf2.json +++ b/advisories/unreviewed/2022/05/GHSA-9q6c-4f46-hgf2/GHSA-9q6c-4f46-hgf2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9q6c-4f46-hgf2", - "modified": "2022-05-24T17:17:07Z", + "modified": "2024-11-19T15:31:50Z", "published": "2022-05-24T17:17:07Z", "aliases": [ "CVE-2020-12627" ], "details": "Calibre-Web 0.6.6 allows authentication bypass because of the 'A0Zr98j/3yX R~XHH!jmN]LWX/,?RT' hardcoded secret key.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-798" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-v5hx-2wwf-52wx/GHSA-v5hx-2wwf-52wx.json b/advisories/unreviewed/2022/05/GHSA-v5hx-2wwf-52wx/GHSA-v5hx-2wwf-52wx.json index 9a2434a50a1..141ed24b6d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5hx-2wwf-52wx/GHSA-v5hx-2wwf-52wx.json +++ b/advisories/unreviewed/2022/05/GHSA-v5hx-2wwf-52wx/GHSA-v5hx-2wwf-52wx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v5hx-2wwf-52wx", - "modified": "2022-05-24T19:20:49Z", + "modified": "2024-11-19T15:31:51Z", "published": "2022-05-24T19:20:49Z", "aliases": [ "CVE-2021-25965" ], "details": "In Calibre-web, versions 0.6.0 to 0.6.13 are vulnerable to Cross-Site Request Forgery (CSRF). By luring an authenticated user to click on a link, an attacker can create a new user role with admin privileges and attacker-controlled credentials, allowing them to take over the application.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2024/11/GHSA-545f-546q-5w2v/GHSA-545f-546q-5w2v.json b/advisories/unreviewed/2024/11/GHSA-545f-546q-5w2v/GHSA-545f-546q-5w2v.json new file mode 100644 index 00000000000..2f83ff25cfe --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-545f-546q-5w2v/GHSA-545f-546q-5w2v.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-545f-546q-5w2v", + "modified": "2024-11-19T15:31:53Z", + "published": "2024-11-19T15:31:53Z", + "aliases": [ + "CVE-2024-11198" + ], + "details": "The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘extra_class’ parameter in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11198" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/gd-rating-system/tags/3.6.1/d4plib/plugin/d4p.shortcodes.php#L63" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3189622" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/gd-rating-system/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/66cad18d-a433-47f1-9cb6-c619c8717a0d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T13:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5q4h-gp9j-4wfr/GHSA-5q4h-gp9j-4wfr.json b/advisories/unreviewed/2024/11/GHSA-5q4h-gp9j-4wfr/GHSA-5q4h-gp9j-4wfr.json new file mode 100644 index 00000000000..94a50ec0d61 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5q4h-gp9j-4wfr/GHSA-5q4h-gp9j-4wfr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5q4h-gp9j-4wfr", + "modified": "2024-11-19T15:31:54Z", + "published": "2024-11-19T15:31:54Z", + "aliases": [ + "CVE-2024-10204" + ], + "details": "Heap-based Buffer Overflow and Uninitialized Variable vulnerabilities exist in the X_B and SAT file reading procedure in eDrawings from Release SOLIDWORKS 2024 through Release SOLIDWORKS 2025. These vulnerabilities could allow an attacker to execute arbitrary code while opening a specially crafted X_B or SAT file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10204" + }, + { + "type": "WEB", + "url": "https://www.3ds.com/vulnerability/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6hvr-5xqv-qc9j/GHSA-6hvr-5xqv-qc9j.json b/advisories/unreviewed/2024/11/GHSA-6hvr-5xqv-qc9j/GHSA-6hvr-5xqv-qc9j.json new file mode 100644 index 00000000000..88da56aacfc --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6hvr-5xqv-qc9j/GHSA-6hvr-5xqv-qc9j.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6hvr-5xqv-qc9j", + "modified": "2024-11-19T15:31:53Z", + "published": "2024-11-19T15:31:53Z", + "aliases": [ + "CVE-2024-11224" + ], + "details": "The Parallax Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘position’ parameter in all versions up to, and including, 1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11224" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/parallax-image/tags/1.9/assets/shortcode.php#L156" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3189649" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/parallax-image/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/56e5f7c9-ad22-43b3-9bfe-0eea1f8040d3?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T13:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7343-r6j5-pcf7/GHSA-7343-r6j5-pcf7.json b/advisories/unreviewed/2024/11/GHSA-7343-r6j5-pcf7/GHSA-7343-r6j5-pcf7.json index fc5b43cb981..6054502a4d4 100644 --- a/advisories/unreviewed/2024/11/GHSA-7343-r6j5-pcf7/GHSA-7343-r6j5-pcf7.json +++ b/advisories/unreviewed/2024/11/GHSA-7343-r6j5-pcf7/GHSA-7343-r6j5-pcf7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7343-r6j5-pcf7", - "modified": "2024-11-13T18:32:04Z", + "modified": "2024-11-19T15:31:53Z", "published": "2024-11-13T18:32:04Z", "aliases": [ "CVE-2024-23715" ], "details": "In PMRWritePMPageList of pmr.c, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-13T18:15:20Z" diff --git a/advisories/unreviewed/2024/11/GHSA-939f-42q9-6v9h/GHSA-939f-42q9-6v9h.json b/advisories/unreviewed/2024/11/GHSA-939f-42q9-6v9h/GHSA-939f-42q9-6v9h.json new file mode 100644 index 00000000000..a211413c3a7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-939f-42q9-6v9h/GHSA-939f-42q9-6v9h.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-939f-42q9-6v9h", + "modified": "2024-11-19T15:31:54Z", + "published": "2024-11-19T15:31:54Z", + "aliases": [ + "CVE-2024-9830" + ], + "details": "The Bard theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.216. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9830" + }, + { + "type": "WEB", + "url": "https://themes.trac.wordpress.org/browser/bard/2.216/functions.php#L109" + }, + { + "type": "WEB", + "url": "https://themes.trac.wordpress.org/browser/bard/2.216/functions.php#L98" + }, + { + "type": "WEB", + "url": "https://themes.trac.wordpress.org/changeset/248854" + }, + { + "type": "WEB", + "url": "https://wordpress.org/themes/bard" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9aff1e5b-2f16-43d0-b75a-c07e59a9c15f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T13:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-crh9-vmx5-ggr8/GHSA-crh9-vmx5-ggr8.json b/advisories/unreviewed/2024/11/GHSA-crh9-vmx5-ggr8/GHSA-crh9-vmx5-ggr8.json new file mode 100644 index 00000000000..37bff0f0f10 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-crh9-vmx5-ggr8/GHSA-crh9-vmx5-ggr8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crh9-vmx5-ggr8", + "modified": "2024-11-19T15:31:53Z", + "published": "2024-11-19T15:31:53Z", + "aliases": [ + "CVE-2024-52675" + ], + "details": "SourceCodester Sentiment Based Movie Rating System 1.0 is vulnerable to SQL Injection in /msrps/movies.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52675" + }, + { + "type": "WEB", + "url": "https://github.com/xubeining/Cve_report/blob/main/Sourcecodester-SQLi-Sentiment-Based-Moive-Rating.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T13:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f75h-cwp9-8h5x/GHSA-f75h-cwp9-8h5x.json b/advisories/unreviewed/2024/11/GHSA-f75h-cwp9-8h5x/GHSA-f75h-cwp9-8h5x.json index 28605ed0796..e262af7f688 100644 --- a/advisories/unreviewed/2024/11/GHSA-f75h-cwp9-8h5x/GHSA-f75h-cwp9-8h5x.json +++ b/advisories/unreviewed/2024/11/GHSA-f75h-cwp9-8h5x/GHSA-f75h-cwp9-8h5x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f75h-cwp9-8h5x", - "modified": "2024-11-15T06:30:32Z", + "modified": "2024-11-19T15:31:53Z", "published": "2024-11-15T06:30:32Z", "aliases": [ "CVE-2024-10924" @@ -37,6 +37,10 @@ "type": "WEB", "url": "https://plugins.trac.wordpress.org/changeset/3188431/really-simple-ssl" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/blog/2024/11/really-simple-security-vulnerability" + }, { "type": "WEB", "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7d5d05ad-1a7a-43d2-bbbf-597e975446be?source=cve" diff --git a/advisories/unreviewed/2024/11/GHSA-j3h2-4rr5-87p6/GHSA-j3h2-4rr5-87p6.json b/advisories/unreviewed/2024/11/GHSA-j3h2-4rr5-87p6/GHSA-j3h2-4rr5-87p6.json new file mode 100644 index 00000000000..0382d0986d7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-j3h2-4rr5-87p6/GHSA-j3h2-4rr5-87p6.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3h2-4rr5-87p6", + "modified": "2024-11-19T15:31:54Z", + "published": "2024-11-19T15:31:54Z", + "aliases": [ + "CVE-2024-11075" + ], + "details": "A vulnerability in the Incoming Goods Suite allows a user with unprivileged access to the underlying system (e.g. local or via SSH) a privilege escalation to the administrative level due to the usage of component vendor Docker images running with root permissions. Exploiting this misconfiguration leads to the fact that an attacker can gain administrative control. over the whole system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11075" + }, + { + "type": "WEB", + "url": "https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF" + }, + { + "type": "WEB", + "url": "https://sick.com/psirt" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" + }, + { + "type": "WEB", + "url": "https://www.first.org/cvss/calculator/3.1" + }, + { + "type": "WEB", + "url": "https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0005.json" + }, + { + "type": "WEB", + "url": "https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0005.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-250" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jm4h-wwjv-4q5c/GHSA-jm4h-wwjv-4q5c.json b/advisories/unreviewed/2024/11/GHSA-jm4h-wwjv-4q5c/GHSA-jm4h-wwjv-4q5c.json index a91b7093664..41f20c8b88a 100644 --- a/advisories/unreviewed/2024/11/GHSA-jm4h-wwjv-4q5c/GHSA-jm4h-wwjv-4q5c.json +++ b/advisories/unreviewed/2024/11/GHSA-jm4h-wwjv-4q5c/GHSA-jm4h-wwjv-4q5c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jm4h-wwjv-4q5c", - "modified": "2024-11-13T15:31:37Z", + "modified": "2024-11-19T15:31:53Z", "published": "2024-11-13T15:31:37Z", "aliases": [ "CVE-2024-11159" ], "details": "Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird < 128.4.3 and Thunderbird < 132.0.1.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-13T14:15:15Z" diff --git a/advisories/unreviewed/2024/11/GHSA-mqrm-h2pw-9j9r/GHSA-mqrm-h2pw-9j9r.json b/advisories/unreviewed/2024/11/GHSA-mqrm-h2pw-9j9r/GHSA-mqrm-h2pw-9j9r.json new file mode 100644 index 00000000000..0a5a618ccc7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mqrm-h2pw-9j9r/GHSA-mqrm-h2pw-9j9r.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqrm-h2pw-9j9r", + "modified": "2024-11-19T15:31:54Z", + "published": "2024-11-19T15:31:54Z", + "aliases": [ + "CVE-2024-10524" + ], + "details": "Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10524" + }, + { + "type": "WEB", + "url": "https://git.savannah.gnu.org/cgit/wget.git/commit/?id=c419542d956a2607bbce5df64b9d378a8588d778" + }, + { + "type": "WEB", + "url": "https://jfrog.com/blog/cve-2024-10524-wget-zero-day-vulnerability" + }, + { + "type": "WEB", + "url": "https://seclists.org/oss-sec/2024/q4/107" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T15:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rmm3-pvp6-hmx9/GHSA-rmm3-pvp6-hmx9.json b/advisories/unreviewed/2024/11/GHSA-rmm3-pvp6-hmx9/GHSA-rmm3-pvp6-hmx9.json new file mode 100644 index 00000000000..9e5e1d05383 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rmm3-pvp6-hmx9/GHSA-rmm3-pvp6-hmx9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmm3-pvp6-hmx9", + "modified": "2024-11-19T15:31:54Z", + "published": "2024-11-19T15:31:54Z", + "aliases": [ + "CVE-2024-52711" + ], + "details": "DI-8100 v16.07.26A1 is vulnerable to Buffer Overflow In the ip_position_asp function via the ip parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52711" + }, + { + "type": "WEB", + "url": "https://github.com/CLan-nad/CVE/blob/main/D-Link/ip_position_asp/1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T14:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vq94-gp7r-66mp/GHSA-vq94-gp7r-66mp.json b/advisories/unreviewed/2024/11/GHSA-vq94-gp7r-66mp/GHSA-vq94-gp7r-66mp.json new file mode 100644 index 00000000000..9b00083f3bf --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vq94-gp7r-66mp/GHSA-vq94-gp7r-66mp.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vq94-gp7r-66mp", + "modified": "2024-11-19T15:31:54Z", + "published": "2024-11-19T15:31:54Z", + "aliases": [ + "CVE-2024-9777" + ], + "details": "The Ashe theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.243. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9777" + }, + { + "type": "WEB", + "url": "https://themes.trac.wordpress.org/browser/ashe/2.242/functions.php#L101" + }, + { + "type": "WEB", + "url": "https://themes.trac.wordpress.org/browser/ashe/2.242/functions.php#L112" + }, + { + "type": "WEB", + "url": "https://themes.trac.wordpress.org/changeset/248853" + }, + { + "type": "WEB", + "url": "https://wordpress.org/themes/ashe" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ce6c2f36-9eed-482f-9201-8d26e8c5c369?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T13:15:04Z" + } +} \ No newline at end of file