Publish Advisories

GHSA-7qjm-443c-38h9
GHSA-4wch-q26f-448q
GHSA-2fx8-5w8c-86ff
GHSA-5hqj-p5mp-7xw9
GHSA-jhx9-8pp3-9q4m
GHSA-p6m7-cwqx-m4h6
GHSA-p9fm-h38h-99qw
GHSA-rjvg-jw68-99hj
GHSA-w7wj-5p2p-g7p7
GHSA-x586-j2rp-5xgv
This commit is contained in:
advisory-database[bot]
2024-08-27 09:31:44 +00:00
parent 836ad34eee
commit 28f5ed2d20
10 changed files with 354 additions and 1 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7qjm-443c-38h9",
"modified": "2024-01-04T06:30:32Z",
"modified": "2024-08-27T09:30:44Z",
"published": "2023-12-27T15:30:22Z",
"aliases": [
"CVE-2023-6190"
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-276",
"CWE-732"
],
"severity": "CRITICAL",
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2fx8-5w8c-86ff",
"modified": "2024-08-27T09:30:44Z",
"published": "2024-08-27T09:30:44Z",
"aliases": [
"CVE-2024-41176"
],
"details": "The MPD package included in TwinCAT/BSD allows an authenticated, low-privileged local\nattacker to induce a Denial-of-Service (DoS) condition on the daemon and execute code in\nthe context of user “root” via a crafted HTTP request.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41176"
},
{
"type": "WEB",
"url": "https://cert.vde.com/en/advisories/VDE-2024-050"
}
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-27T08:15:05Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5hqj-p5mp-7xw9",
"modified": "2024-08-27T09:30:44Z",
"published": "2024-08-27T09:30:44Z",
"aliases": [
"CVE-2024-41175"
],
"details": "The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local denial-of-service attack by a low privileged attacker.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41175"
},
{
"type": "WEB",
"url": "https://cert.vde.com/en/advisories/VDE-2024-049"
},
{
"type": "WEB",
"url": "https://infosys.beckhoff.com/content/1033/twincat_bsd/11780818443.html?id=4222392218353411614"
}
],
"database_specific": {
"cwe_ids": [
"CWE-770"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-27T08:15:05Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jhx9-8pp3-9q4m",
"modified": "2024-08-27T09:30:45Z",
"published": "2024-08-27T09:30:45Z",
"aliases": [
"CVE-2024-7608"
],
"details": "An authenticated user can download sensitive files from Trellix products NX, EX, FX, AX, IVX, and CMS using path traversal for the URL of network anomaly download_artifact.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7608"
},
{
"type": "WEB",
"url": "https://thrive.trellix.com/s/article/000013844"
}
],
"database_specific": {
"cwe_ids": [
"CWE-35"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-27T08:15:05Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p6m7-cwqx-m4h6",
"modified": "2024-08-27T09:30:44Z",
"published": "2024-08-27T09:30:44Z",
"aliases": [
"CVE-2024-6804"
],
"details": "The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6804"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/jeg-elementor-kit/tags/2.6.7/lib/jeg-framework/customizer/class-customizer.php#L595"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3139386"
},
{
"type": "WEB",
"url": "https://wordpress.org/plugins/jeg-elementor-kit/#developers"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5491ff65-9060-4b0b-a31d-7b95ea581310?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-27T07:15:03Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p9fm-h38h-99qw",
"modified": "2024-08-27T09:30:44Z",
"published": "2024-08-27T09:30:44Z",
"aliases": [
"CVE-2024-41173"
],
"details": "The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local authentication bypass by a low privileged attacker.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41173"
},
{
"type": "WEB",
"url": "https://cert.vde.com/en/advisories/VDE-2024-045"
}
],
"database_specific": {
"cwe_ids": [
"CWE-288"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-27T08:15:04Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rjvg-jw68-99hj",
"modified": "2024-08-27T09:30:44Z",
"published": "2024-08-27T09:30:44Z",
"aliases": [
"CVE-2024-41174"
],
"details": "The IPC-Diagnostics package in TwinCAT/BSD is susceptible to improper input neutralization by a low-privileged local attacker.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41174"
},
{
"type": "WEB",
"url": "https://cert.vde.com/en/advisories/VDE-2024-048"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-27T08:15:04Z"
}
}
@@ -0,0 +1,54 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w7wj-5p2p-g7p7",
"modified": "2024-08-27T09:30:44Z",
"published": "2024-08-27T09:30:44Z",
"aliases": [
"CVE-2024-7304"
],
"details": "The Ninja Tables Easiest Data Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.0.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7304"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/ninja-tables/tags/5.0.12/app/Hooks/filters.php#L28"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3140370"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3140370/#file408"
},
{
"type": "WEB",
"url": "https://wordpress.org/plugins/ninja-tables/#developers"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b1eb6896-2de3-4d4d-9b5f-253aaffd193b?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-27T07:15:04Z"
}
}
@@ -0,0 +1,54 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x586-j2rp-5xgv",
"modified": "2024-08-27T09:30:45Z",
"published": "2024-08-27T09:30:45Z",
"aliases": [
"CVE-2024-8046"
],
"details": "The Logo Showcase Ultimate Logo Carousel, Logo Slider & Logo Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8046"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/logo-showcase-ultimate/tags/1.4.1/lcg_adl_main.php#L236"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3141393"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3141393/#file3"
},
{
"type": "WEB",
"url": "https://wordpress.org/plugins/logo-showcase-ultimate/#developers"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/89525af0-105a-4d7d-93d1-af724a837e7a?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-27T08:15:06Z"
}
}