From 28f5ed2d203179d8a39ccfab41a405d22bac6a28 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 27 Aug 2024 09:31:44 +0000 Subject: [PATCH] Publish Advisories GHSA-7qjm-443c-38h9 GHSA-4wch-q26f-448q GHSA-2fx8-5w8c-86ff GHSA-5hqj-p5mp-7xw9 GHSA-jhx9-8pp3-9q4m GHSA-p6m7-cwqx-m4h6 GHSA-p9fm-h38h-99qw GHSA-rjvg-jw68-99hj GHSA-w7wj-5p2p-g7p7 GHSA-x586-j2rp-5xgv --- .../GHSA-7qjm-443c-38h9.json | 2 +- .../GHSA-4wch-q26f-448q.json | 1 + .../GHSA-2fx8-5w8c-86ff.json | 38 +++++++++++++ .../GHSA-5hqj-p5mp-7xw9.json | 42 +++++++++++++++ .../GHSA-jhx9-8pp3-9q4m.json | 38 +++++++++++++ .../GHSA-p6m7-cwqx-m4h6.json | 50 +++++++++++++++++ .../GHSA-p9fm-h38h-99qw.json | 38 +++++++++++++ .../GHSA-rjvg-jw68-99hj.json | 38 +++++++++++++ .../GHSA-w7wj-5p2p-g7p7.json | 54 +++++++++++++++++++ .../GHSA-x586-j2rp-5xgv.json | 54 +++++++++++++++++++ 10 files changed, 354 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2024/08/GHSA-2fx8-5w8c-86ff/GHSA-2fx8-5w8c-86ff.json create mode 100644 advisories/unreviewed/2024/08/GHSA-5hqj-p5mp-7xw9/GHSA-5hqj-p5mp-7xw9.json create mode 100644 advisories/unreviewed/2024/08/GHSA-jhx9-8pp3-9q4m/GHSA-jhx9-8pp3-9q4m.json create mode 100644 advisories/unreviewed/2024/08/GHSA-p6m7-cwqx-m4h6/GHSA-p6m7-cwqx-m4h6.json create mode 100644 advisories/unreviewed/2024/08/GHSA-p9fm-h38h-99qw/GHSA-p9fm-h38h-99qw.json create mode 100644 advisories/unreviewed/2024/08/GHSA-rjvg-jw68-99hj/GHSA-rjvg-jw68-99hj.json create mode 100644 advisories/unreviewed/2024/08/GHSA-w7wj-5p2p-g7p7/GHSA-w7wj-5p2p-g7p7.json create mode 100644 advisories/unreviewed/2024/08/GHSA-x586-j2rp-5xgv/GHSA-x586-j2rp-5xgv.json diff --git a/advisories/unreviewed/2023/12/GHSA-7qjm-443c-38h9/GHSA-7qjm-443c-38h9.json b/advisories/unreviewed/2023/12/GHSA-7qjm-443c-38h9/GHSA-7qjm-443c-38h9.json index 2fc74eac997..ba834dfd6b1 100644 --- a/advisories/unreviewed/2023/12/GHSA-7qjm-443c-38h9/GHSA-7qjm-443c-38h9.json +++ b/advisories/unreviewed/2023/12/GHSA-7qjm-443c-38h9/GHSA-7qjm-443c-38h9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7qjm-443c-38h9", - "modified": "2024-01-04T06:30:32Z", + "modified": "2024-08-27T09:30:44Z", "published": "2023-12-27T15:30:22Z", "aliases": [ "CVE-2023-6190" diff --git a/advisories/unreviewed/2024/04/GHSA-4wch-q26f-448q/GHSA-4wch-q26f-448q.json b/advisories/unreviewed/2024/04/GHSA-4wch-q26f-448q/GHSA-4wch-q26f-448q.json index 391a636ae37..2eab6817832 100644 --- a/advisories/unreviewed/2024/04/GHSA-4wch-q26f-448q/GHSA-4wch-q26f-448q.json +++ b/advisories/unreviewed/2024/04/GHSA-4wch-q26f-448q/GHSA-4wch-q26f-448q.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-276", "CWE-732" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/08/GHSA-2fx8-5w8c-86ff/GHSA-2fx8-5w8c-86ff.json b/advisories/unreviewed/2024/08/GHSA-2fx8-5w8c-86ff/GHSA-2fx8-5w8c-86ff.json new file mode 100644 index 00000000000..c193cb0e93a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2fx8-5w8c-86ff/GHSA-2fx8-5w8c-86ff.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2fx8-5w8c-86ff", + "modified": "2024-08-27T09:30:44Z", + "published": "2024-08-27T09:30:44Z", + "aliases": [ + "CVE-2024-41176" + ], + "details": "The MPD package included in TwinCAT/BSD allows an authenticated, low-privileged local\nattacker to induce a Denial-of-Service (DoS) condition on the daemon and execute code in\nthe context of user “root” via a crafted HTTP request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41176" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-050" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T08:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5hqj-p5mp-7xw9/GHSA-5hqj-p5mp-7xw9.json b/advisories/unreviewed/2024/08/GHSA-5hqj-p5mp-7xw9/GHSA-5hqj-p5mp-7xw9.json new file mode 100644 index 00000000000..e1067888dd7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5hqj-p5mp-7xw9/GHSA-5hqj-p5mp-7xw9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hqj-p5mp-7xw9", + "modified": "2024-08-27T09:30:44Z", + "published": "2024-08-27T09:30:44Z", + "aliases": [ + "CVE-2024-41175" + ], + "details": "The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local denial-of-service attack by a low privileged attacker.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41175" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-049" + }, + { + "type": "WEB", + "url": "https://infosys.beckhoff.com/content/1033/twincat_bsd/11780818443.html?id=4222392218353411614" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T08:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jhx9-8pp3-9q4m/GHSA-jhx9-8pp3-9q4m.json b/advisories/unreviewed/2024/08/GHSA-jhx9-8pp3-9q4m/GHSA-jhx9-8pp3-9q4m.json new file mode 100644 index 00000000000..66f4bc782ff --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jhx9-8pp3-9q4m/GHSA-jhx9-8pp3-9q4m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhx9-8pp3-9q4m", + "modified": "2024-08-27T09:30:45Z", + "published": "2024-08-27T09:30:45Z", + "aliases": [ + "CVE-2024-7608" + ], + "details": "An authenticated user can download sensitive files from Trellix products NX, EX, FX, AX, IVX, and CMS using path traversal for the URL of network anomaly download_artifact.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7608" + }, + { + "type": "WEB", + "url": "https://thrive.trellix.com/s/article/000013844" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T08:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p6m7-cwqx-m4h6/GHSA-p6m7-cwqx-m4h6.json b/advisories/unreviewed/2024/08/GHSA-p6m7-cwqx-m4h6/GHSA-p6m7-cwqx-m4h6.json new file mode 100644 index 00000000000..a2dc68b4866 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-p6m7-cwqx-m4h6/GHSA-p6m7-cwqx-m4h6.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6m7-cwqx-m4h6", + "modified": "2024-08-27T09:30:44Z", + "published": "2024-08-27T09:30:44Z", + "aliases": [ + "CVE-2024-6804" + ], + "details": "The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6804" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/jeg-elementor-kit/tags/2.6.7/lib/jeg-framework/customizer/class-customizer.php#L595" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3139386" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/jeg-elementor-kit/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5491ff65-9060-4b0b-a31d-7b95ea581310?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T07:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p9fm-h38h-99qw/GHSA-p9fm-h38h-99qw.json b/advisories/unreviewed/2024/08/GHSA-p9fm-h38h-99qw/GHSA-p9fm-h38h-99qw.json new file mode 100644 index 00000000000..e6e26879b3d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-p9fm-h38h-99qw/GHSA-p9fm-h38h-99qw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9fm-h38h-99qw", + "modified": "2024-08-27T09:30:44Z", + "published": "2024-08-27T09:30:44Z", + "aliases": [ + "CVE-2024-41173" + ], + "details": "The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local authentication bypass by a low privileged attacker.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41173" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-045" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T08:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rjvg-jw68-99hj/GHSA-rjvg-jw68-99hj.json b/advisories/unreviewed/2024/08/GHSA-rjvg-jw68-99hj/GHSA-rjvg-jw68-99hj.json new file mode 100644 index 00000000000..6512e4cb02e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rjvg-jw68-99hj/GHSA-rjvg-jw68-99hj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rjvg-jw68-99hj", + "modified": "2024-08-27T09:30:44Z", + "published": "2024-08-27T09:30:44Z", + "aliases": [ + "CVE-2024-41174" + ], + "details": "The IPC-Diagnostics package in TwinCAT/BSD is susceptible to improper input neutralization by a low-privileged local attacker.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41174" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-048" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T08:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w7wj-5p2p-g7p7/GHSA-w7wj-5p2p-g7p7.json b/advisories/unreviewed/2024/08/GHSA-w7wj-5p2p-g7p7/GHSA-w7wj-5p2p-g7p7.json new file mode 100644 index 00000000000..8b8a9cb6708 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w7wj-5p2p-g7p7/GHSA-w7wj-5p2p-g7p7.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7wj-5p2p-g7p7", + "modified": "2024-08-27T09:30:44Z", + "published": "2024-08-27T09:30:44Z", + "aliases": [ + "CVE-2024-7304" + ], + "details": "The Ninja Tables – Easiest Data Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.0.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7304" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/ninja-tables/tags/5.0.12/app/Hooks/filters.php#L28" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3140370" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3140370/#file408" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/ninja-tables/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b1eb6896-2de3-4d4d-9b5f-253aaffd193b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T07:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-x586-j2rp-5xgv/GHSA-x586-j2rp-5xgv.json b/advisories/unreviewed/2024/08/GHSA-x586-j2rp-5xgv/GHSA-x586-j2rp-5xgv.json new file mode 100644 index 00000000000..fc775ec8199 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-x586-j2rp-5xgv/GHSA-x586-j2rp-5xgv.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x586-j2rp-5xgv", + "modified": "2024-08-27T09:30:45Z", + "published": "2024-08-27T09:30:45Z", + "aliases": [ + "CVE-2024-8046" + ], + "details": "The Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8046" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/logo-showcase-ultimate/tags/1.4.1/lcg_adl_main.php#L236" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3141393" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3141393/#file3" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/logo-showcase-ultimate/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/89525af0-105a-4d7d-93d1-af724a837e7a?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T08:15:06Z" + } +} \ No newline at end of file