From 26ef65ecd0bd4938a54631008d264558b8cd9ef9 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 12 Jun 2024 12:32:08 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-f67c-8m2w-79hm.json | 10 +- .../GHSA-95hw-v8fq-666q.json | 10 +- .../GHSA-mw7v-292c-8697.json | 6 +- .../GHSA-phhr-cqm7-gjv6.json | 10 +- .../GHSA-r8h5-fm59-g356.json | 10 +- .../GHSA-3h6x-952r-xr8p.json | 14 ++- .../GHSA-4287-v2hm-q9f2.json | 6 +- .../GHSA-73m5-j333-fcwc.json | 14 ++- .../GHSA-93px-8x98-j7p2.json | 114 ++++++++++-------- .../GHSA-98fx-x879-qp6f.json | 6 +- .../GHSA-v8xr-j3gp-fmxj.json | 6 +- .../GHSA-xw3g-x45j-xxhh.json | 6 +- .../GHSA-6cvp-282g-6jp8.json | 6 +- .../GHSA-jprr-pf4r-gvp5.json | 6 +- .../GHSA-c7hr-m654-77g5.json | 14 ++- .../GHSA-2x28-576q-2wr5.json | 38 ++++++ .../GHSA-3j8q-j2j7-x49c.json | 46 +++++++ .../GHSA-3rf3-8wmx-cm8q.json | 6 +- .../GHSA-457m-vq92-44f4.json | 38 ++++++ .../GHSA-7mqf-f8fg-5rvr.json | 38 ++++++ .../GHSA-7w3v-fgq3-jwhp.json | 6 +- .../GHSA-8qw7-56rp-hj8x.json | 38 ++++++ .../GHSA-8xmg-v9fm-xcgv.json | 42 +++++++ .../GHSA-8xpj-rxm7-wgf9.json | 42 +++++++ .../GHSA-9267-324r-qccw.json | 42 +++++++ .../GHSA-9qw6-wc53-f6x9.json | 42 +++++++ .../GHSA-fh66-vp6h-x77p.json | 38 ++++++ .../GHSA-fm6m-fmh2-f72v.json | 38 ++++++ .../GHSA-fp9r-pfv9-88w5.json | 38 ++++++ .../GHSA-jrv5-734x-jwfc.json | 38 ++++++ .../GHSA-m57w-mwxg-jc43.json | 38 ++++++ .../GHSA-m72x-qv6p-6hjg.json | 38 ++++++ .../GHSA-rm55-jfvw-6g3r.json | 38 ++++++ .../GHSA-rmff-fqq9-pc3q.json | 14 ++- .../GHSA-v5xq-m8f8-3cc2.json | 42 +++++++ .../GHSA-v8p9-qjc4-7jhh.json | 38 ++++++ .../GHSA-v9ph-8hf4-hgrx.json | 42 +++++++ .../GHSA-w9f6-jf9g-658h.json | 38 ++++++ 38 files changed, 988 insertions(+), 68 deletions(-) create mode 100644 advisories/unreviewed/2024/06/GHSA-2x28-576q-2wr5/GHSA-2x28-576q-2wr5.json create mode 100644 advisories/unreviewed/2024/06/GHSA-3j8q-j2j7-x49c/GHSA-3j8q-j2j7-x49c.json create mode 100644 advisories/unreviewed/2024/06/GHSA-457m-vq92-44f4/GHSA-457m-vq92-44f4.json create mode 100644 advisories/unreviewed/2024/06/GHSA-7mqf-f8fg-5rvr/GHSA-7mqf-f8fg-5rvr.json create mode 100644 advisories/unreviewed/2024/06/GHSA-8qw7-56rp-hj8x/GHSA-8qw7-56rp-hj8x.json create mode 100644 advisories/unreviewed/2024/06/GHSA-8xmg-v9fm-xcgv/GHSA-8xmg-v9fm-xcgv.json create mode 100644 advisories/unreviewed/2024/06/GHSA-8xpj-rxm7-wgf9/GHSA-8xpj-rxm7-wgf9.json create mode 100644 advisories/unreviewed/2024/06/GHSA-9267-324r-qccw/GHSA-9267-324r-qccw.json create mode 100644 advisories/unreviewed/2024/06/GHSA-9qw6-wc53-f6x9/GHSA-9qw6-wc53-f6x9.json create mode 100644 advisories/unreviewed/2024/06/GHSA-fh66-vp6h-x77p/GHSA-fh66-vp6h-x77p.json create mode 100644 advisories/unreviewed/2024/06/GHSA-fm6m-fmh2-f72v/GHSA-fm6m-fmh2-f72v.json create mode 100644 advisories/unreviewed/2024/06/GHSA-fp9r-pfv9-88w5/GHSA-fp9r-pfv9-88w5.json create mode 100644 advisories/unreviewed/2024/06/GHSA-jrv5-734x-jwfc/GHSA-jrv5-734x-jwfc.json create mode 100644 advisories/unreviewed/2024/06/GHSA-m57w-mwxg-jc43/GHSA-m57w-mwxg-jc43.json create mode 100644 advisories/unreviewed/2024/06/GHSA-m72x-qv6p-6hjg/GHSA-m72x-qv6p-6hjg.json create mode 100644 advisories/unreviewed/2024/06/GHSA-rm55-jfvw-6g3r/GHSA-rm55-jfvw-6g3r.json create mode 100644 advisories/unreviewed/2024/06/GHSA-v5xq-m8f8-3cc2/GHSA-v5xq-m8f8-3cc2.json create mode 100644 advisories/unreviewed/2024/06/GHSA-v8p9-qjc4-7jhh/GHSA-v8p9-qjc4-7jhh.json create mode 100644 advisories/unreviewed/2024/06/GHSA-v9ph-8hf4-hgrx/GHSA-v9ph-8hf4-hgrx.json create mode 100644 advisories/unreviewed/2024/06/GHSA-w9f6-jf9g-658h/GHSA-w9f6-jf9g-658h.json diff --git a/advisories/unreviewed/2023/11/GHSA-f67c-8m2w-79hm/GHSA-f67c-8m2w-79hm.json b/advisories/unreviewed/2023/11/GHSA-f67c-8m2w-79hm/GHSA-f67c-8m2w-79hm.json index 4f231e17dbd..b5cbead1c36 100644 --- a/advisories/unreviewed/2023/11/GHSA-f67c-8m2w-79hm/GHSA-f67c-8m2w-79hm.json +++ b/advisories/unreviewed/2023/11/GHSA-f67c-8m2w-79hm/GHSA-f67c-8m2w-79hm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f67c-8m2w-79hm", - "modified": "2023-11-06T12:30:24Z", + "modified": "2024-06-12T12:30:39Z", "published": "2023-11-06T12:30:24Z", "aliases": [ "CVE-2023-5090" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5090" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:3854" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:3855" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-5090" diff --git a/advisories/unreviewed/2023/12/GHSA-95hw-v8fq-666q/GHSA-95hw-v8fq-666q.json b/advisories/unreviewed/2023/12/GHSA-95hw-v8fq-666q/GHSA-95hw-v8fq-666q.json index ecd91ee32aa..3164b079fe8 100644 --- a/advisories/unreviewed/2023/12/GHSA-95hw-v8fq-666q/GHSA-95hw-v8fq-666q.json +++ b/advisories/unreviewed/2023/12/GHSA-95hw-v8fq-666q/GHSA-95hw-v8fq-666q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-95hw-v8fq-666q", - "modified": "2024-06-10T18:30:50Z", + "modified": "2024-06-12T12:30:39Z", "published": "2023-12-01T00:31:00Z", "aliases": [ "CVE-2023-42916" @@ -45,6 +45,14 @@ "type": "WEB", "url": "https://support.apple.com/en-us/HT214033" }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214033" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214034" + }, { "type": "WEB", "url": "https://support.apple.com/kb/HT214062" diff --git a/advisories/unreviewed/2023/12/GHSA-mw7v-292c-8697/GHSA-mw7v-292c-8697.json b/advisories/unreviewed/2023/12/GHSA-mw7v-292c-8697/GHSA-mw7v-292c-8697.json index 0c5df152caa..ab0055a2818 100644 --- a/advisories/unreviewed/2023/12/GHSA-mw7v-292c-8697/GHSA-mw7v-292c-8697.json +++ b/advisories/unreviewed/2023/12/GHSA-mw7v-292c-8697/GHSA-mw7v-292c-8697.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mw7v-292c-8697", - "modified": "2023-12-13T18:31:03Z", + "modified": "2024-06-12T12:30:39Z", "published": "2023-12-12T03:31:43Z", "aliases": [ "CVE-2023-42890" @@ -45,6 +45,10 @@ "type": "WEB", "url": "https://support.apple.com/en-us/HT214041" }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214039" + }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2023/Dec/12" diff --git a/advisories/unreviewed/2023/12/GHSA-phhr-cqm7-gjv6/GHSA-phhr-cqm7-gjv6.json b/advisories/unreviewed/2023/12/GHSA-phhr-cqm7-gjv6/GHSA-phhr-cqm7-gjv6.json index e24a300e9f9..c615a51ac38 100644 --- a/advisories/unreviewed/2023/12/GHSA-phhr-cqm7-gjv6/GHSA-phhr-cqm7-gjv6.json +++ b/advisories/unreviewed/2023/12/GHSA-phhr-cqm7-gjv6/GHSA-phhr-cqm7-gjv6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-phhr-cqm7-gjv6", - "modified": "2024-06-10T18:30:51Z", + "modified": "2024-06-12T12:30:39Z", "published": "2023-12-01T00:31:00Z", "aliases": [ "CVE-2023-42917" @@ -45,6 +45,14 @@ "type": "WEB", "url": "https://support.apple.com/en-us/HT214033" }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214033" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214034" + }, { "type": "WEB", "url": "https://support.apple.com/kb/HT214062" diff --git a/advisories/unreviewed/2023/12/GHSA-r8h5-fm59-g356/GHSA-r8h5-fm59-g356.json b/advisories/unreviewed/2023/12/GHSA-r8h5-fm59-g356/GHSA-r8h5-fm59-g356.json index f52ece92215..cb907c5b925 100644 --- a/advisories/unreviewed/2023/12/GHSA-r8h5-fm59-g356/GHSA-r8h5-fm59-g356.json +++ b/advisories/unreviewed/2023/12/GHSA-r8h5-fm59-g356/GHSA-r8h5-fm59-g356.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r8h5-fm59-g356", - "modified": "2023-12-13T18:31:03Z", + "modified": "2024-06-12T12:30:39Z", "published": "2023-12-12T03:31:43Z", "aliases": [ "CVE-2023-42883" @@ -45,6 +45,14 @@ "type": "WEB", "url": "https://support.apple.com/en-us/HT214041" }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214034" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214039" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5580" diff --git a/advisories/unreviewed/2024/01/GHSA-3h6x-952r-xr8p/GHSA-3h6x-952r-xr8p.json b/advisories/unreviewed/2024/01/GHSA-3h6x-952r-xr8p/GHSA-3h6x-952r-xr8p.json index e56cf385584..522ab096652 100644 --- a/advisories/unreviewed/2024/01/GHSA-3h6x-952r-xr8p/GHSA-3h6x-952r-xr8p.json +++ b/advisories/unreviewed/2024/01/GHSA-3h6x-952r-xr8p/GHSA-3h6x-952r-xr8p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3h6x-952r-xr8p", - "modified": "2024-06-10T18:30:51Z", + "modified": "2024-06-12T12:30:39Z", "published": "2024-01-23T03:31:08Z", "aliases": [ "CVE-2024-23213" @@ -53,6 +53,18 @@ "type": "WEB", "url": "https://support.apple.com/en-us/HT214063" }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214055" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214056" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214059" + }, { "type": "WEB", "url": "https://support.apple.com/kb/HT214060" diff --git a/advisories/unreviewed/2024/01/GHSA-4287-v2hm-q9f2/GHSA-4287-v2hm-q9f2.json b/advisories/unreviewed/2024/01/GHSA-4287-v2hm-q9f2/GHSA-4287-v2hm-q9f2.json index e055695df6a..3f08b5f0b27 100644 --- a/advisories/unreviewed/2024/01/GHSA-4287-v2hm-q9f2/GHSA-4287-v2hm-q9f2.json +++ b/advisories/unreviewed/2024/01/GHSA-4287-v2hm-q9f2/GHSA-4287-v2hm-q9f2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4287-v2hm-q9f2", - "modified": "2024-06-10T18:30:51Z", + "modified": "2024-06-12T12:30:39Z", "published": "2024-01-23T03:31:08Z", "aliases": [ "CVE-2024-23214" @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://support.apple.com/en-us/HT214063" }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214059" + }, { "type": "WEB", "url": "https://support.apple.com/kb/HT214061" diff --git a/advisories/unreviewed/2024/01/GHSA-73m5-j333-fcwc/GHSA-73m5-j333-fcwc.json b/advisories/unreviewed/2024/01/GHSA-73m5-j333-fcwc/GHSA-73m5-j333-fcwc.json index ba5036e841d..e917f0b5bf4 100644 --- a/advisories/unreviewed/2024/01/GHSA-73m5-j333-fcwc/GHSA-73m5-j333-fcwc.json +++ b/advisories/unreviewed/2024/01/GHSA-73m5-j333-fcwc/GHSA-73m5-j333-fcwc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-73m5-j333-fcwc", - "modified": "2024-06-10T18:30:51Z", + "modified": "2024-06-12T12:30:39Z", "published": "2024-01-23T03:31:08Z", "aliases": [ "CVE-2024-23206" @@ -53,6 +53,18 @@ "type": "WEB", "url": "https://support.apple.com/en-us/HT214063" }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214055" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214056" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214059" + }, { "type": "WEB", "url": "https://support.apple.com/kb/HT214060" diff --git a/advisories/unreviewed/2024/01/GHSA-93px-8x98-j7p2/GHSA-93px-8x98-j7p2.json b/advisories/unreviewed/2024/01/GHSA-93px-8x98-j7p2/GHSA-93px-8x98-j7p2.json index fdcacdbaf5a..d2fb17e0d0b 100644 --- a/advisories/unreviewed/2024/01/GHSA-93px-8x98-j7p2/GHSA-93px-8x98-j7p2.json +++ b/advisories/unreviewed/2024/01/GHSA-93px-8x98-j7p2/GHSA-93px-8x98-j7p2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-93px-8x98-j7p2", - "modified": "2024-06-10T18:30:52Z", + "modified": "2024-06-12T12:30:39Z", "published": "2024-01-23T03:31:08Z", "aliases": [ "CVE-2024-23222" @@ -23,55 +23,7 @@ }, { "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/US43EQFC2IS66EA2CPAZFH2RQ6WD7PKF" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X2VJMEDT4GL42AQVHSYOT6DIVJDZWIV4" - }, - { - "type": "WEB", - "url": "https://support.apple.com/en-us/HT214055" - }, - { - "type": "WEB", - "url": "https://support.apple.com/en-us/HT214056" - }, - { - "type": "WEB", - "url": "https://support.apple.com/en-us/HT214057" - }, - { - "type": "WEB", - "url": "https://support.apple.com/en-us/HT214058" - }, - { - "type": "WEB", - "url": "https://support.apple.com/en-us/HT214059" - }, - { - "type": "WEB", - "url": "https://support.apple.com/en-us/HT214061" - }, - { - "type": "WEB", - "url": "https://support.apple.com/en-us/HT214063" - }, - { - "type": "WEB", - "url": "https://support.apple.com/en-us/HT214070" - }, - { - "type": "WEB", - "url": "https://support.apple.com/kb/HT214057" - }, - { - "type": "WEB", - "url": "https://support.apple.com/kb/HT214058" - }, - { - "type": "WEB", - "url": "https://support.apple.com/kb/HT214061" + "url": "https://support.apple.com/kb/HT214070" }, { "type": "WEB", @@ -79,7 +31,67 @@ }, { "type": "WEB", - "url": "https://support.apple.com/kb/HT214070" + "url": "https://support.apple.com/kb/HT214061" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214059" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214058" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214057" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214056" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214055" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214070" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214063" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214061" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214059" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214058" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214057" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214056" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214055" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X2VJMEDT4GL42AQVHSYOT6DIVJDZWIV4" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/US43EQFC2IS66EA2CPAZFH2RQ6WD7PKF" }, { "type": "WEB", diff --git a/advisories/unreviewed/2024/02/GHSA-98fx-x879-qp6f/GHSA-98fx-x879-qp6f.json b/advisories/unreviewed/2024/02/GHSA-98fx-x879-qp6f/GHSA-98fx-x879-qp6f.json index 6ea19d66855..3b9c4dc8a57 100644 --- a/advisories/unreviewed/2024/02/GHSA-98fx-x879-qp6f/GHSA-98fx-x879-qp6f.json +++ b/advisories/unreviewed/2024/02/GHSA-98fx-x879-qp6f/GHSA-98fx-x879-qp6f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-98fx-x879-qp6f", - "modified": "2024-04-25T18:30:38Z", + "modified": "2024-06-12T12:30:39Z", "published": "2024-02-07T21:30:27Z", "aliases": [ "CVE-2023-6356" @@ -45,6 +45,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:1248" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:3810" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-6356" diff --git a/advisories/unreviewed/2024/02/GHSA-v8xr-j3gp-fmxj/GHSA-v8xr-j3gp-fmxj.json b/advisories/unreviewed/2024/02/GHSA-v8xr-j3gp-fmxj/GHSA-v8xr-j3gp-fmxj.json index 616425e04ca..daa437a21f1 100644 --- a/advisories/unreviewed/2024/02/GHSA-v8xr-j3gp-fmxj/GHSA-v8xr-j3gp-fmxj.json +++ b/advisories/unreviewed/2024/02/GHSA-v8xr-j3gp-fmxj/GHSA-v8xr-j3gp-fmxj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v8xr-j3gp-fmxj", - "modified": "2024-04-25T18:30:38Z", + "modified": "2024-06-12T12:30:39Z", "published": "2024-02-07T21:30:27Z", "aliases": [ "CVE-2023-6535" @@ -45,6 +45,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:1248" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:3810" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-6535" diff --git a/advisories/unreviewed/2024/02/GHSA-xw3g-x45j-xxhh/GHSA-xw3g-x45j-xxhh.json b/advisories/unreviewed/2024/02/GHSA-xw3g-x45j-xxhh/GHSA-xw3g-x45j-xxhh.json index 5d79a8c8b88..2d1d128f872 100644 --- a/advisories/unreviewed/2024/02/GHSA-xw3g-x45j-xxhh/GHSA-xw3g-x45j-xxhh.json +++ b/advisories/unreviewed/2024/02/GHSA-xw3g-x45j-xxhh/GHSA-xw3g-x45j-xxhh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xw3g-x45j-xxhh", - "modified": "2024-04-15T15:30:50Z", + "modified": "2024-06-12T12:30:40Z", "published": "2024-02-07T21:30:27Z", "aliases": [ "CVE-2023-6536" @@ -45,6 +45,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:1248" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:3810" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-6536" diff --git a/advisories/unreviewed/2024/03/GHSA-6cvp-282g-6jp8/GHSA-6cvp-282g-6jp8.json b/advisories/unreviewed/2024/03/GHSA-6cvp-282g-6jp8/GHSA-6cvp-282g-6jp8.json index 7d33b8d0010..dff4f336551 100644 --- a/advisories/unreviewed/2024/03/GHSA-6cvp-282g-6jp8/GHSA-6cvp-282g-6jp8.json +++ b/advisories/unreviewed/2024/03/GHSA-6cvp-282g-6jp8/GHSA-6cvp-282g-6jp8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6cvp-282g-6jp8", - "modified": "2024-05-07T06:30:36Z", + "modified": "2024-06-12T12:30:40Z", "published": "2024-03-28T18:30:47Z", "aliases": [ "CVE-2023-42950" @@ -45,6 +45,10 @@ "type": "WEB", "url": "https://support.apple.com/en-us/HT214041" }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214039" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/03/26/1" diff --git a/advisories/unreviewed/2024/03/GHSA-jprr-pf4r-gvp5/GHSA-jprr-pf4r-gvp5.json b/advisories/unreviewed/2024/03/GHSA-jprr-pf4r-gvp5/GHSA-jprr-pf4r-gvp5.json index e3e877be8bb..998482709b0 100644 --- a/advisories/unreviewed/2024/03/GHSA-jprr-pf4r-gvp5/GHSA-jprr-pf4r-gvp5.json +++ b/advisories/unreviewed/2024/03/GHSA-jprr-pf4r-gvp5/GHSA-jprr-pf4r-gvp5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jprr-pf4r-gvp5", - "modified": "2024-05-07T06:30:36Z", + "modified": "2024-06-12T12:30:40Z", "published": "2024-03-28T18:30:47Z", "aliases": [ "CVE-2023-42956" @@ -37,6 +37,10 @@ "type": "WEB", "url": "https://support.apple.com/en-us/HT214039" }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214039" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/03/26/1" diff --git a/advisories/unreviewed/2024/04/GHSA-c7hr-m654-77g5/GHSA-c7hr-m654-77g5.json b/advisories/unreviewed/2024/04/GHSA-c7hr-m654-77g5/GHSA-c7hr-m654-77g5.json index 479278d5cd4..41befe037a4 100644 --- a/advisories/unreviewed/2024/04/GHSA-c7hr-m654-77g5/GHSA-c7hr-m654-77g5.json +++ b/advisories/unreviewed/2024/04/GHSA-c7hr-m654-77g5/GHSA-c7hr-m654-77g5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c7hr-m654-77g5", - "modified": "2024-06-10T18:30:56Z", + "modified": "2024-06-12T12:30:40Z", "published": "2024-04-24T18:30:33Z", "aliases": [ "CVE-2024-23271" @@ -38,6 +38,18 @@ "type": "WEB", "url": "https://support.apple.com/en-us/HT214061" }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214055" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214056" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214059" + }, { "type": "WEB", "url": "https://support.apple.com/kb/HT214060" diff --git a/advisories/unreviewed/2024/06/GHSA-2x28-576q-2wr5/GHSA-2x28-576q-2wr5.json b/advisories/unreviewed/2024/06/GHSA-2x28-576q-2wr5/GHSA-2x28-576q-2wr5.json new file mode 100644 index 00000000000..f1f48b67328 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-2x28-576q-2wr5/GHSA-2x28-576q-2wr5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2x28-576q-2wr5", + "modified": "2024-06-12T12:30:40Z", + "published": "2024-06-12T12:30:40Z", + "aliases": [ + "CVE-2023-38395" + ], + "details": "Missing Authorization vulnerability in Afzal Multani WP Clone Menu.This issue affects WP Clone Menu: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38395" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/clone-menu/wordpress-wp-clone-menu-plugin-1-0-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T10:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-3j8q-j2j7-x49c/GHSA-3j8q-j2j7-x49c.json b/advisories/unreviewed/2024/06/GHSA-3j8q-j2j7-x49c/GHSA-3j8q-j2j7-x49c.json new file mode 100644 index 00000000000..4e800f79c85 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-3j8q-j2j7-x49c/GHSA-3j8q-j2j7-x49c.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3j8q-j2j7-x49c", + "modified": "2024-06-12T12:30:41Z", + "published": "2024-06-12T12:30:41Z", + "aliases": [ + "CVE-2024-2092" + ], + "details": "The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Twitter Widget in all versions up to, and including, 1.13.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2092" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/addon-elements-for-elementor-page-builder/tags/1.13/modules/twitter/widgets/twitter.php#L712" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3077362%40addon-elements-for-elementor-page-builder%2Ftrunk&old=3058768%40addon-elements-for-elementor-page-builder%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/67790c0b-c078-4955-a175-977a695392fc?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T10:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-3rf3-8wmx-cm8q/GHSA-3rf3-8wmx-cm8q.json b/advisories/unreviewed/2024/06/GHSA-3rf3-8wmx-cm8q/GHSA-3rf3-8wmx-cm8q.json index dd002ad947e..21edc783abe 100644 --- a/advisories/unreviewed/2024/06/GHSA-3rf3-8wmx-cm8q/GHSA-3rf3-8wmx-cm8q.json +++ b/advisories/unreviewed/2024/06/GHSA-3rf3-8wmx-cm8q/GHSA-3rf3-8wmx-cm8q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3rf3-8wmx-cm8q", - "modified": "2024-06-10T09:31:06Z", + "modified": "2024-06-12T12:30:40Z", "published": "2024-06-10T09:31:06Z", "aliases": [ "CVE-2024-36971" @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/92f1655aa2b2294d0b49925f3b875a634bd3b59e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b8af8e6118a6605f0e495a58d591ca94a85a50fc" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-457m-vq92-44f4/GHSA-457m-vq92-44f4.json b/advisories/unreviewed/2024/06/GHSA-457m-vq92-44f4/GHSA-457m-vq92-44f4.json new file mode 100644 index 00000000000..412dd6b5ab7 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-457m-vq92-44f4/GHSA-457m-vq92-44f4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-457m-vq92-44f4", + "modified": "2024-06-12T12:30:40Z", + "published": "2024-06-12T12:30:40Z", + "aliases": [ + "CVE-2023-25030" + ], + "details": "Missing Authorization vulnerability in Buy Me a Coffee.This issue affects Buy Me a Coffee: from n/a through 3.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25030" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/buymeacoffee/wordpress-buy-me-a-coffee-plugin-3-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T10:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-7mqf-f8fg-5rvr/GHSA-7mqf-f8fg-5rvr.json b/advisories/unreviewed/2024/06/GHSA-7mqf-f8fg-5rvr/GHSA-7mqf-f8fg-5rvr.json new file mode 100644 index 00000000000..7bca60637e8 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-7mqf-f8fg-5rvr/GHSA-7mqf-f8fg-5rvr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7mqf-f8fg-5rvr", + "modified": "2024-06-12T12:30:41Z", + "published": "2024-06-12T12:30:41Z", + "aliases": [ + "CVE-2023-51413" + ], + "details": "Missing Authorization vulnerability in Piotnet Forms.This issue affects Piotnet Forms: from n/a through 1.0.29.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51413" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/piotnetforms/wordpress-piotnet-forms-plugin-1-0-25-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T10:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-7w3v-fgq3-jwhp/GHSA-7w3v-fgq3-jwhp.json b/advisories/unreviewed/2024/06/GHSA-7w3v-fgq3-jwhp/GHSA-7w3v-fgq3-jwhp.json index 45cd162a151..451b5ad6014 100644 --- a/advisories/unreviewed/2024/06/GHSA-7w3v-fgq3-jwhp/GHSA-7w3v-fgq3-jwhp.json +++ b/advisories/unreviewed/2024/06/GHSA-7w3v-fgq3-jwhp/GHSA-7w3v-fgq3-jwhp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7w3v-fgq3-jwhp", - "modified": "2024-06-08T15:31:18Z", + "modified": "2024-06-12T12:30:40Z", "published": "2024-06-08T15:31:18Z", "aliases": [ "CVE-2024-36968" @@ -18,6 +18,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36968" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4d3dbaa252257d20611c3647290e6171f1bbd6c8" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/a5b862c6a221459d54e494e88965b48dcfa6cc44" diff --git a/advisories/unreviewed/2024/06/GHSA-8qw7-56rp-hj8x/GHSA-8qw7-56rp-hj8x.json b/advisories/unreviewed/2024/06/GHSA-8qw7-56rp-hj8x/GHSA-8qw7-56rp-hj8x.json new file mode 100644 index 00000000000..fb714f36838 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-8qw7-56rp-hj8x/GHSA-8qw7-56rp-hj8x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qw7-56rp-hj8x", + "modified": "2024-06-12T12:30:40Z", + "published": "2024-06-12T12:30:40Z", + "aliases": [ + "CVE-2023-40672" + ], + "details": "Missing Authorization vulnerability in Hardik Chavada Sticky Social Media Icons.This issue affects Sticky Social Media Icons: from n/a through 2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40672" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/sticky-social-media-icons/wordpress-sticky-social-media-icons-plugin-1-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T10:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-8xmg-v9fm-xcgv/GHSA-8xmg-v9fm-xcgv.json b/advisories/unreviewed/2024/06/GHSA-8xmg-v9fm-xcgv/GHSA-8xmg-v9fm-xcgv.json new file mode 100644 index 00000000000..d7e9bcbf4fb --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-8xmg-v9fm-xcgv/GHSA-8xmg-v9fm-xcgv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xmg-v9fm-xcgv", + "modified": "2024-06-12T12:30:41Z", + "published": "2024-06-12T12:30:41Z", + "aliases": [ + "CVE-2024-5674" + ], + "details": "The Newsletter - API v1 and v2 addon plugin for WordPress is vulnerable to unauthorized subscribers management due to PHP type juggling issue on the check_api_key function in all versions up to, and including, 2.4.5. This makes it possible for unauthenticated attackers to list, create or delete newsletter subscribers. This issue affects only sites running the PHP version below 8.0", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5674" + }, + { + "type": "WEB", + "url": "https://www.thenewsletterplugin.com/documentation/developers/newsletter-api-2" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ecd9800e-ce0f-45f3-bb66-3690c51d885b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T11:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-8xpj-rxm7-wgf9/GHSA-8xpj-rxm7-wgf9.json b/advisories/unreviewed/2024/06/GHSA-8xpj-rxm7-wgf9/GHSA-8xpj-rxm7-wgf9.json new file mode 100644 index 00000000000..e0f44ecdaec --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-8xpj-rxm7-wgf9/GHSA-8xpj-rxm7-wgf9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xpj-rxm7-wgf9", + "modified": "2024-06-12T12:30:41Z", + "published": "2024-06-12T12:30:41Z", + "aliases": [ + "CVE-2024-4845" + ], + "details": "The Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘options[list_id]’ parameter in all versions up to, and including, 5.7.22 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4845" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3098321/email-subscribers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/21be2215-8ce0-438e-94e0-6a350b8cc952?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T10:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-9267-324r-qccw/GHSA-9267-324r-qccw.json b/advisories/unreviewed/2024/06/GHSA-9267-324r-qccw/GHSA-9267-324r-qccw.json new file mode 100644 index 00000000000..de683f6c2a3 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-9267-324r-qccw/GHSA-9267-324r-qccw.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9267-324r-qccw", + "modified": "2024-06-12T12:30:41Z", + "published": "2024-06-12T12:30:41Z", + "aliases": [ + "CVE-2024-3492" + ], + "details": "The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'event', 'location', and 'event_category' shortcodes in all versions up to, and including, 6.4.7.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3492" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3101326/events-manager" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a767f65e-bc7d-4576-af78-b77bd23dc089?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T11:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-9qw6-wc53-f6x9/GHSA-9qw6-wc53-f6x9.json b/advisories/unreviewed/2024/06/GHSA-9qw6-wc53-f6x9/GHSA-9qw6-wc53-f6x9.json new file mode 100644 index 00000000000..335c05df2c1 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-9qw6-wc53-f6x9/GHSA-9qw6-wc53-f6x9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qw6-wc53-f6x9", + "modified": "2024-06-12T12:30:41Z", + "published": "2024-06-12T12:30:41Z", + "aliases": [ + "CVE-2024-4898" + ], + "details": "The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due to a missing authorization checks on the REST API calls in all versions up to, and including, 0.1.0.38. This makes it possible for unauthenticated attackers to connect the site to InstaWP API, edit arbitrary site options and create administrator accounts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4898" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/instawp-connect/tags/0.1.0.38/includes/class-instawp-rest-api.php#L926" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/92a00fb4-7b50-43fd-ac04-5d6e29336e9c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T11:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-fh66-vp6h-x77p/GHSA-fh66-vp6h-x77p.json b/advisories/unreviewed/2024/06/GHSA-fh66-vp6h-x77p/GHSA-fh66-vp6h-x77p.json new file mode 100644 index 00000000000..c8e5420571d --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-fh66-vp6h-x77p/GHSA-fh66-vp6h-x77p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fh66-vp6h-x77p", + "modified": "2024-06-12T12:30:40Z", + "published": "2024-06-12T12:30:40Z", + "aliases": [ + "CVE-2023-40209" + ], + "details": "Missing Authorization vulnerability in Himalaya Saxena Highcompress Image Compressor.This issue affects Highcompress Image Compressor: from n/a through 6.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40209" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/high-compress/wordpress-highcompress-image-compressor-plugin-4-0-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T10:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-fm6m-fmh2-f72v/GHSA-fm6m-fmh2-f72v.json b/advisories/unreviewed/2024/06/GHSA-fm6m-fmh2-f72v/GHSA-fm6m-fmh2-f72v.json new file mode 100644 index 00000000000..65634595ce5 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-fm6m-fmh2-f72v/GHSA-fm6m-fmh2-f72v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fm6m-fmh2-f72v", + "modified": "2024-06-12T12:30:41Z", + "published": "2024-06-12T12:30:41Z", + "aliases": [ + "CVE-2024-5056" + ], + "details": "CWE-552: Files or Directories Accessible to External Parties vulnerability exists which may\nprevent user to update the device firmware and prevent proper behavior of the webserver when\nspecific files or directories are removed from the filesystem.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5056" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-163-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-163-01.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-552" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T12:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-fp9r-pfv9-88w5/GHSA-fp9r-pfv9-88w5.json b/advisories/unreviewed/2024/06/GHSA-fp9r-pfv9-88w5/GHSA-fp9r-pfv9-88w5.json new file mode 100644 index 00000000000..35f4d0045d8 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-fp9r-pfv9-88w5/GHSA-fp9r-pfv9-88w5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fp9r-pfv9-88w5", + "modified": "2024-06-12T12:30:41Z", + "published": "2024-06-12T12:30:41Z", + "aliases": [ + "CVE-2023-48280" + ], + "details": "Missing Authorization vulnerability in Consensu.IO Consensu.Io.This issue affects Consensu.Io: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48280" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/consensu-io/wordpress-consensu-io-plugin-1-0-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T10:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-jrv5-734x-jwfc/GHSA-jrv5-734x-jwfc.json b/advisories/unreviewed/2024/06/GHSA-jrv5-734x-jwfc/GHSA-jrv5-734x-jwfc.json new file mode 100644 index 00000000000..c85417c027f --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-jrv5-734x-jwfc/GHSA-jrv5-734x-jwfc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrv5-734x-jwfc", + "modified": "2024-06-12T12:30:41Z", + "published": "2024-06-12T12:30:41Z", + "aliases": [ + "CVE-2023-41240" + ], + "details": "Missing Authorization vulnerability in Vark Pricing Deals for WooCommerce.This issue affects Pricing Deals for WooCommerce: from n/a through 2.0.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41240" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/pricing-deals-for-woocommerce/wordpress-pricing-deals-for-woocommercepricing-deals-for-woocommerce-plugin-2-0-3-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T10:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-m57w-mwxg-jc43/GHSA-m57w-mwxg-jc43.json b/advisories/unreviewed/2024/06/GHSA-m57w-mwxg-jc43/GHSA-m57w-mwxg-jc43.json new file mode 100644 index 00000000000..babe5ceb85e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-m57w-mwxg-jc43/GHSA-m57w-mwxg-jc43.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m57w-mwxg-jc43", + "modified": "2024-06-12T12:30:40Z", + "published": "2024-06-12T12:30:40Z", + "aliases": [ + "CVE-2023-40603" + ], + "details": "Missing Authorization vulnerability in Gangesh Matta Simple Org Chart.This issue affects Simple Org Chart: from n/a through 2.3.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40603" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/simple-org-chart/wordpress-simple-org-chart-plugin-2-3-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T10:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-m72x-qv6p-6hjg/GHSA-m72x-qv6p-6hjg.json b/advisories/unreviewed/2024/06/GHSA-m72x-qv6p-6hjg/GHSA-m72x-qv6p-6hjg.json new file mode 100644 index 00000000000..e8d14ab4753 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-m72x-qv6p-6hjg/GHSA-m72x-qv6p-6hjg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m72x-qv6p-6hjg", + "modified": "2024-06-12T12:30:41Z", + "published": "2024-06-12T12:30:40Z", + "aliases": [ + "CVE-2023-47828" + ], + "details": "Missing Authorization vulnerability in Mandrill wpMandrill.This issue affects wpMandrill: from n/a through 1.33.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47828" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wpmandrill/wordpress-wpmandrill-plugin-1-33-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T10:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-rm55-jfvw-6g3r/GHSA-rm55-jfvw-6g3r.json b/advisories/unreviewed/2024/06/GHSA-rm55-jfvw-6g3r/GHSA-rm55-jfvw-6g3r.json new file mode 100644 index 00000000000..c365dd51519 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-rm55-jfvw-6g3r/GHSA-rm55-jfvw-6g3r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rm55-jfvw-6g3r", + "modified": "2024-06-12T12:30:41Z", + "published": "2024-06-12T12:30:41Z", + "aliases": [ + "CVE-2023-47845" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Lim Kai Yang Grab & Save.This issue affects Grab & Save: from n/a through 1.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47845" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/save-grab/wordpress-grab-save-plugin-1-0-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T10:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-rmff-fqq9-pc3q/GHSA-rmff-fqq9-pc3q.json b/advisories/unreviewed/2024/06/GHSA-rmff-fqq9-pc3q/GHSA-rmff-fqq9-pc3q.json index 3c252b60a50..5792efa7d0f 100644 --- a/advisories/unreviewed/2024/06/GHSA-rmff-fqq9-pc3q/GHSA-rmff-fqq9-pc3q.json +++ b/advisories/unreviewed/2024/06/GHSA-rmff-fqq9-pc3q/GHSA-rmff-fqq9-pc3q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rmff-fqq9-pc3q", - "modified": "2024-06-10T15:31:02Z", + "modified": "2024-06-12T12:30:40Z", "published": "2024-06-10T15:31:02Z", "aliases": [ "CVE-2024-36972" @@ -18,9 +18,21 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36972" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4708f49add84a57ce0ccc7bf9a6269845c631cc3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4bf6964451c3cb411fbaa1ae8b214b3d97a59bf1" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/9841991a446c87f90f66f4b9fee6fe934c1336a2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d59ae9314b97e01c76a4171472441e55721ba636" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-v5xq-m8f8-3cc2/GHSA-v5xq-m8f8-3cc2.json b/advisories/unreviewed/2024/06/GHSA-v5xq-m8f8-3cc2/GHSA-v5xq-m8f8-3cc2.json new file mode 100644 index 00000000000..5891ed8adbc --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-v5xq-m8f8-3cc2/GHSA-v5xq-m8f8-3cc2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5xq-m8f8-3cc2", + "modified": "2024-06-12T12:30:41Z", + "published": "2024-06-12T12:30:41Z", + "aliases": [ + "CVE-2024-1766" + ], + "details": "The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.2.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability requires social engineering to successfully exploit, and the impact would be very limited due to the attacker requiring a user to login as the user with the injected payload for execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1766" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/download-manager/trunk/src/User/views/dashboard/edit-profile.php#L16" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9774c999-acb6-4c5f-ad6c-10979660b164?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T11:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-v8p9-qjc4-7jhh/GHSA-v8p9-qjc4-7jhh.json b/advisories/unreviewed/2024/06/GHSA-v8p9-qjc4-7jhh/GHSA-v8p9-qjc4-7jhh.json new file mode 100644 index 00000000000..0b9401fd746 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-v8p9-qjc4-7jhh/GHSA-v8p9-qjc4-7jhh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8p9-qjc4-7jhh", + "modified": "2024-06-12T12:30:41Z", + "published": "2024-06-12T12:30:41Z", + "aliases": [ + "CVE-2023-51524" + ], + "details": "Missing Authorization vulnerability in weForms.This issue affects weForms: from n/a through 1.6.18.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51524" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/weforms/wordpress-weforms-plugin-1-6-18-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T10:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-v9ph-8hf4-hgrx/GHSA-v9ph-8hf4-hgrx.json b/advisories/unreviewed/2024/06/GHSA-v9ph-8hf4-hgrx/GHSA-v9ph-8hf4-hgrx.json new file mode 100644 index 00000000000..e424efe796f --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-v9ph-8hf4-hgrx/GHSA-v9ph-8hf4-hgrx.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9ph-8hf4-hgrx", + "modified": "2024-06-12T12:30:41Z", + "published": "2024-06-12T12:30:41Z", + "aliases": [ + "CVE-2024-5211" + ], + "details": "A path traversal vulnerability in mintplex-labs/anything-llm allowed a manager to bypass the `normalizePath()` function, intended to defend against path traversal attacks. This vulnerability enables the manager to read, delete, or overwrite the 'anythingllm.db' database file and other files stored in the 'storage' directory, such as internal communication keys and .env secrets. Exploitation of this vulnerability could lead to application compromise, denial of service (DoS) attacks, and unauthorized admin account takeover. The issue stems from improper validation of user-supplied input in the process of setting a custom logo for the app, which can be manipulated to achieve arbitrary file read, deletion, or overwrite, and to execute a DoS attack by deleting critical files required for the application's operation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5211" + }, + { + "type": "WEB", + "url": "https://github.com/mintplex-labs/anything-llm/commit/e208074ef4c240fe03e4147ab097ec3b52b97619" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/38f282cb-7226-435e-9832-2d4a102dad4b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-29" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T12:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-w9f6-jf9g-658h/GHSA-w9f6-jf9g-658h.json b/advisories/unreviewed/2024/06/GHSA-w9f6-jf9g-658h/GHSA-w9f6-jf9g-658h.json new file mode 100644 index 00000000000..2e8d24ac699 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-w9f6-jf9g-658h/GHSA-w9f6-jf9g-658h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9f6-jf9g-658h", + "modified": "2024-06-12T12:30:41Z", + "published": "2024-06-12T12:30:40Z", + "aliases": [ + "CVE-2023-44234" + ], + "details": "Missing Authorization vulnerability in Bastianon Massimo WP GPX Map.This issue affects WP GPX Map: from n/a through 1.7.08.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44234" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-gpx-maps/wordpress-wp-gpx-maps-plugin-1-7-05-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T10:15:27Z" + } +} \ No newline at end of file