From 27164db1d1bb43c1a0b8356687371620ec588442 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 21 Feb 2024 03:32:19 +0000 Subject: [PATCH] Publish Advisories GHSA-5g36-x562-44f9 GHSA-44jg-jgjx-3xg5 GHSA-468x-frcm-ghx6 GHSA-54pv-r62j-9qqc GHSA-6h6q-fm45-w3hv GHSA-73x3-8mrg-5r93 GHSA-745j-hgg9-cr25 GHSA-7998-f982-7c9x GHSA-cr36-3vqf-x5w5 GHSA-f6gc-85gg-m766 GHSA-hqp2-6j35-rqp5 GHSA-p28x-4r5h-ph6j GHSA-rwhv-hvj2-qrqm GHSA-rwxc-4cmw-7x75 GHSA-v2xq-m22w-jmpr GHSA-vrhp-w2wh-93c3 GHSA-xpjg-7hx7-wgcx --- .../GHSA-5g36-x562-44f9.json | 10 ++++- .../GHSA-44jg-jgjx-3xg5.json | 38 +++++++++++++++++ .../GHSA-468x-frcm-ghx6.json | 38 +++++++++++++++++ .../GHSA-54pv-r62j-9qqc.json | 38 +++++++++++++++++ .../GHSA-6h6q-fm45-w3hv.json | 6 ++- .../GHSA-73x3-8mrg-5r93.json | 38 +++++++++++++++++ .../GHSA-745j-hgg9-cr25.json | 31 ++++++++++++++ .../GHSA-7998-f982-7c9x.json | 6 ++- .../GHSA-cr36-3vqf-x5w5.json | 38 +++++++++++++++++ .../GHSA-f6gc-85gg-m766.json | 35 ++++++++++++++++ .../GHSA-hqp2-6j35-rqp5.json | 42 +++++++++++++++++++ .../GHSA-p28x-4r5h-ph6j.json | 38 +++++++++++++++++ .../GHSA-rwhv-hvj2-qrqm.json | 38 +++++++++++++++++ .../GHSA-rwxc-4cmw-7x75.json | 38 +++++++++++++++++ .../GHSA-v2xq-m22w-jmpr.json | 38 +++++++++++++++++ .../GHSA-vrhp-w2wh-93c3.json | 6 ++- .../GHSA-xpjg-7hx7-wgcx.json | 38 +++++++++++++++++ 17 files changed, 512 insertions(+), 4 deletions(-) create mode 100644 advisories/unreviewed/2024/02/GHSA-44jg-jgjx-3xg5/GHSA-44jg-jgjx-3xg5.json create mode 100644 advisories/unreviewed/2024/02/GHSA-468x-frcm-ghx6/GHSA-468x-frcm-ghx6.json create mode 100644 advisories/unreviewed/2024/02/GHSA-54pv-r62j-9qqc/GHSA-54pv-r62j-9qqc.json create mode 100644 advisories/unreviewed/2024/02/GHSA-73x3-8mrg-5r93/GHSA-73x3-8mrg-5r93.json create mode 100644 advisories/unreviewed/2024/02/GHSA-745j-hgg9-cr25/GHSA-745j-hgg9-cr25.json create mode 100644 advisories/unreviewed/2024/02/GHSA-cr36-3vqf-x5w5/GHSA-cr36-3vqf-x5w5.json create mode 100644 advisories/unreviewed/2024/02/GHSA-f6gc-85gg-m766/GHSA-f6gc-85gg-m766.json create mode 100644 advisories/unreviewed/2024/02/GHSA-hqp2-6j35-rqp5/GHSA-hqp2-6j35-rqp5.json create mode 100644 advisories/unreviewed/2024/02/GHSA-p28x-4r5h-ph6j/GHSA-p28x-4r5h-ph6j.json create mode 100644 advisories/unreviewed/2024/02/GHSA-rwhv-hvj2-qrqm/GHSA-rwhv-hvj2-qrqm.json create mode 100644 advisories/unreviewed/2024/02/GHSA-rwxc-4cmw-7x75/GHSA-rwxc-4cmw-7x75.json create mode 100644 advisories/unreviewed/2024/02/GHSA-v2xq-m22w-jmpr/GHSA-v2xq-m22w-jmpr.json create mode 100644 advisories/unreviewed/2024/02/GHSA-xpjg-7hx7-wgcx/GHSA-xpjg-7hx7-wgcx.json diff --git a/advisories/unreviewed/2024/01/GHSA-5g36-x562-44f9/GHSA-5g36-x562-44f9.json b/advisories/unreviewed/2024/01/GHSA-5g36-x562-44f9/GHSA-5g36-x562-44f9.json index c3245768ecb..f8545051769 100644 --- a/advisories/unreviewed/2024/01/GHSA-5g36-x562-44f9/GHSA-5g36-x562-44f9.json +++ b/advisories/unreviewed/2024/01/GHSA-5g36-x562-44f9/GHSA-5g36-x562-44f9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5g36-x562-44f9", - "modified": "2024-01-22T21:31:06Z", + "modified": "2024-02-21T03:30:36Z", "published": "2024-01-13T00:30:25Z", "aliases": [ "CVE-2024-23301" @@ -32,6 +32,14 @@ { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2024/02/msg00003.html" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7JIN57LUPBI2GDJOK3PYXNHJTZT3AQTZ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UHKMPXJNXEJJE6EVYE5HM7EKEJFQMBN7" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-44jg-jgjx-3xg5/GHSA-44jg-jgjx-3xg5.json b/advisories/unreviewed/2024/02/GHSA-44jg-jgjx-3xg5/GHSA-44jg-jgjx-3xg5.json new file mode 100644 index 00000000000..cf8353e8b51 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-44jg-jgjx-3xg5/GHSA-44jg-jgjx-3xg5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44jg-jgjx-3xg5", + "modified": "2024-02-21T03:30:38Z", + "published": "2024-02-21T03:30:38Z", + "aliases": [ + "CVE-2024-25603" + ], + "details": "Stored cross-site scripting (XSS) vulnerability in the Dynamic Data Mapping module's DDMForm in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via the instanceId parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25603" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-25603" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-468x-frcm-ghx6/GHSA-468x-frcm-ghx6.json b/advisories/unreviewed/2024/02/GHSA-468x-frcm-ghx6/GHSA-468x-frcm-ghx6.json new file mode 100644 index 00000000000..6caf2adcb57 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-468x-frcm-ghx6/GHSA-468x-frcm-ghx6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-468x-frcm-ghx6", + "modified": "2024-02-21T03:30:37Z", + "published": "2024-02-21T03:30:37Z", + "aliases": [ + "CVE-2023-40191" + ], + "details": "Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Portal 7.4.3.44 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 44 through 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the “Blocked Email Domains” text field", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40191" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-40191" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T03:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-54pv-r62j-9qqc/GHSA-54pv-r62j-9qqc.json b/advisories/unreviewed/2024/02/GHSA-54pv-r62j-9qqc/GHSA-54pv-r62j-9qqc.json new file mode 100644 index 00000000000..5b4d6d83f61 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-54pv-r62j-9qqc/GHSA-54pv-r62j-9qqc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54pv-r62j-9qqc", + "modified": "2024-02-21T03:30:37Z", + "published": "2024-02-21T03:30:37Z", + "aliases": [ + "CVE-2023-42496" + ], + "details": "Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Portal 7.3.3 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, 7.4 GA through update 92, and 7.3 before update 34 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_roles_admin_web_portlet_RolesAdminPortlet_tabs2 parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42496" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-42496" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-6h6q-fm45-w3hv/GHSA-6h6q-fm45-w3hv.json b/advisories/unreviewed/2024/02/GHSA-6h6q-fm45-w3hv/GHSA-6h6q-fm45-w3hv.json index 549cb590a4a..b582e3b3190 100644 --- a/advisories/unreviewed/2024/02/GHSA-6h6q-fm45-w3hv/GHSA-6h6q-fm45-w3hv.json +++ b/advisories/unreviewed/2024/02/GHSA-6h6q-fm45-w3hv/GHSA-6h6q-fm45-w3hv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6h6q-fm45-w3hv", - "modified": "2024-02-20T03:30:56Z", + "modified": "2024-02-21T03:30:37Z", "published": "2024-02-05T18:31:37Z", "aliases": [ "CVE-2024-24259" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://github.com/yinluming13579/mupdf_defects/blob/main/mupdf_detect_2.md" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6IBAWX3HMMZVAWJZ3U6VOAYYOYJCN3IS" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T43DAHPIWMGN54E4I6ABLHNYHZSTX7H5" diff --git a/advisories/unreviewed/2024/02/GHSA-73x3-8mrg-5r93/GHSA-73x3-8mrg-5r93.json b/advisories/unreviewed/2024/02/GHSA-73x3-8mrg-5r93/GHSA-73x3-8mrg-5r93.json new file mode 100644 index 00000000000..e4cacb31dd9 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-73x3-8mrg-5r93/GHSA-73x3-8mrg-5r93.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73x3-8mrg-5r93", + "modified": "2024-02-21T03:30:37Z", + "published": "2024-02-21T03:30:37Z", + "aliases": [ + "CVE-2023-42498" + ], + "details": "Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal 7.4.3.8 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 4 through 92 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_portal_language_override_web_internal_portlet_PLOPortlet_key parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42498" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-42498" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-745j-hgg9-cr25/GHSA-745j-hgg9-cr25.json b/advisories/unreviewed/2024/02/GHSA-745j-hgg9-cr25/GHSA-745j-hgg9-cr25.json new file mode 100644 index 00000000000..97b9b3bfe65 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-745j-hgg9-cr25/GHSA-745j-hgg9-cr25.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-745j-hgg9-cr25", + "modified": "2024-02-21T03:30:37Z", + "published": "2024-02-21T03:30:37Z", + "aliases": [ + "CVE-2024-24475" + ], + "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24475" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T01:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-7998-f982-7c9x/GHSA-7998-f982-7c9x.json b/advisories/unreviewed/2024/02/GHSA-7998-f982-7c9x/GHSA-7998-f982-7c9x.json index 8ab65637634..0dc3620fbbe 100644 --- a/advisories/unreviewed/2024/02/GHSA-7998-f982-7c9x/GHSA-7998-f982-7c9x.json +++ b/advisories/unreviewed/2024/02/GHSA-7998-f982-7c9x/GHSA-7998-f982-7c9x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7998-f982-7c9x", - "modified": "2024-02-20T18:30:34Z", + "modified": "2024-02-21T03:30:37Z", "published": "2024-02-20T18:30:34Z", "aliases": [ "CVE-2024-0794" @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://support.hp.com/us-en/document/ish_10174031-10174074-16" + }, + { + "type": "WEB", + "url": "https://support.hp.com/us-en/document/ish_10174031-10198670-16" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-cr36-3vqf-x5w5/GHSA-cr36-3vqf-x5w5.json b/advisories/unreviewed/2024/02/GHSA-cr36-3vqf-x5w5/GHSA-cr36-3vqf-x5w5.json new file mode 100644 index 00000000000..b0175646ce0 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-cr36-3vqf-x5w5/GHSA-cr36-3vqf-x5w5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cr36-3vqf-x5w5", + "modified": "2024-02-21T03:30:37Z", + "published": "2024-02-21T03:30:37Z", + "aliases": [ + "CVE-2024-25601" + ], + "details": "Stored cross-site scripting (XSS) vulnerability in Expando module's geolocation custom fields in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into the name text field of a geolocation custom field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25601" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-25601" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T02:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-f6gc-85gg-m766/GHSA-f6gc-85gg-m766.json b/advisories/unreviewed/2024/02/GHSA-f6gc-85gg-m766/GHSA-f6gc-85gg-m766.json new file mode 100644 index 00000000000..155f7b6dfd2 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-f6gc-85gg-m766/GHSA-f6gc-85gg-m766.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6gc-85gg-m766", + "modified": "2024-02-21T03:30:37Z", + "published": "2024-02-21T03:30:37Z", + "aliases": [ + "CVE-2024-0407" + ], + "details": "Certain HP Enterprise LaserJet, and HP LaserJet Managed Printers are potentially vulnerable to information disclosure, when connections made by the device back to services enabled by some solutions may have been trusted without the appropriate CA certificate in the device's certificate store.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0407" + }, + { + "type": "WEB", + "url": "https://support.hp.com/us-en/document/ish_10174094-10174120-16" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T01:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-hqp2-6j35-rqp5/GHSA-hqp2-6j35-rqp5.json b/advisories/unreviewed/2024/02/GHSA-hqp2-6j35-rqp5/GHSA-hqp2-6j35-rqp5.json new file mode 100644 index 00000000000..46b0adbc79d --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-hqp2-6j35-rqp5/GHSA-hqp2-6j35-rqp5.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqp2-6j35-rqp5", + "modified": "2024-02-21T03:30:37Z", + "published": "2024-02-21T03:30:37Z", + "aliases": [ + "CVE-2024-1108" + ], + "details": "The Plugin Groups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_init() function in all versions up to, and including, 2.0.6. This makes it possible for unauthenticated attackers to change the settings of the plugin, which can also cause a denial of service due to a misconfiguration.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1108" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3036754/plugin-groups/trunk/classes/class-plugin-groups.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8298f1fb-3165-40e3-9192-805a07c14cae?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-p28x-4r5h-ph6j/GHSA-p28x-4r5h-ph6j.json b/advisories/unreviewed/2024/02/GHSA-p28x-4r5h-ph6j/GHSA-p28x-4r5h-ph6j.json new file mode 100644 index 00000000000..438f2daa7c3 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-p28x-4r5h-ph6j/GHSA-p28x-4r5h-ph6j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p28x-4r5h-ph6j", + "modified": "2024-02-21T03:30:37Z", + "published": "2024-02-21T03:30:37Z", + "aliases": [ + "CVE-2024-25152" + ], + "details": "Stored cross-site scripting (XSS) vulnerability in Message Board widget in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via the filename of an attachment.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25152" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-25152" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T02:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-rwhv-hvj2-qrqm/GHSA-rwhv-hvj2-qrqm.json b/advisories/unreviewed/2024/02/GHSA-rwhv-hvj2-qrqm/GHSA-rwhv-hvj2-qrqm.json new file mode 100644 index 00000000000..3535d1cf3c4 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-rwhv-hvj2-qrqm/GHSA-rwhv-hvj2-qrqm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwhv-hvj2-qrqm", + "modified": "2024-02-21T03:30:38Z", + "published": "2024-02-21T03:30:38Z", + "aliases": [ + "CVE-2024-26269" + ], + "details": "Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37, and Liferay DXP 7.4 before update 38, 7.3 before update 11, 7.2 before fix pack 20, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via the anchor (hash) part of a URL.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26269" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-26269" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-rwxc-4cmw-7x75/GHSA-rwxc-4cmw-7x75.json b/advisories/unreviewed/2024/02/GHSA-rwxc-4cmw-7x75/GHSA-rwxc-4cmw-7x75.json new file mode 100644 index 00000000000..ecbbc7616b9 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-rwxc-4cmw-7x75/GHSA-rwxc-4cmw-7x75.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwxc-4cmw-7x75", + "modified": "2024-02-21T03:30:38Z", + "published": "2024-02-21T03:30:38Z", + "aliases": [ + "CVE-2024-26266" + ], + "details": "Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.2.0 through 7.4.3.13, and older unsupported versions, and Liferay DXP 7.4 before update 10, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allow remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into the first/middle/last name text field of the user who creates an entry in the (1) Announcement widget, or (2) Alerts widget.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26266" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-26266" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-v2xq-m22w-jmpr/GHSA-v2xq-m22w-jmpr.json b/advisories/unreviewed/2024/02/GHSA-v2xq-m22w-jmpr/GHSA-v2xq-m22w-jmpr.json new file mode 100644 index 00000000000..188af34d91e --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-v2xq-m22w-jmpr/GHSA-v2xq-m22w-jmpr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2xq-m22w-jmpr", + "modified": "2024-02-21T03:30:37Z", + "published": "2024-02-21T03:30:37Z", + "aliases": [ + "CVE-2024-25602" + ], + "details": "Stored cross-site scripting (XSS) vulnerability in Users Admin module's edit user page in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into an organization’s “Name” text field", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25602" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-25602" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T02:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-vrhp-w2wh-93c3/GHSA-vrhp-w2wh-93c3.json b/advisories/unreviewed/2024/02/GHSA-vrhp-w2wh-93c3/GHSA-vrhp-w2wh-93c3.json index 6f9c7238025..6198b614ffd 100644 --- a/advisories/unreviewed/2024/02/GHSA-vrhp-w2wh-93c3/GHSA-vrhp-w2wh-93c3.json +++ b/advisories/unreviewed/2024/02/GHSA-vrhp-w2wh-93c3/GHSA-vrhp-w2wh-93c3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vrhp-w2wh-93c3", - "modified": "2024-02-20T03:30:56Z", + "modified": "2024-02-21T03:30:37Z", "published": "2024-02-05T18:31:37Z", "aliases": [ "CVE-2024-24258" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://github.com/yinluming13579/mupdf_defects/blob/main/mupdf_detect_1.md" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6IBAWX3HMMZVAWJZ3U6VOAYYOYJCN3IS" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T43DAHPIWMGN54E4I6ABLHNYHZSTX7H5" diff --git a/advisories/unreviewed/2024/02/GHSA-xpjg-7hx7-wgcx/GHSA-xpjg-7hx7-wgcx.json b/advisories/unreviewed/2024/02/GHSA-xpjg-7hx7-wgcx/GHSA-xpjg-7hx7-wgcx.json new file mode 100644 index 00000000000..41afc0b0cb7 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-xpjg-7hx7-wgcx/GHSA-xpjg-7hx7-wgcx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpjg-7hx7-wgcx", + "modified": "2024-02-21T03:30:37Z", + "published": "2024-02-21T03:30:37Z", + "aliases": [ + "CVE-2024-25147" + ], + "details": "Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via crafted javascript: style links.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25147" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-25147" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T02:15:29Z" + } +} \ No newline at end of file