Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-02-13 15:32:28 +00:00
parent de385badbd
commit 2b29848a84
26 changed files with 576 additions and 27 deletions
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6cwm-wm82-hgrw",
"modified": "2022-05-24T17:47:06Z",
"modified": "2024-02-13T15:31:10Z",
"published": "2022-05-24T17:47:06Z",
"aliases": [
"CVE-2020-7924"
],
"details": "Usage of specific command line parameter in MongoDB Tools which was originally intended to just skip hostname checks, may result in MongoDB skipping all certificate validation. This may result in accepting invalid certificates.This issue affects: MongoDB Inc. MongoDB Database Tools 3.6 versions later than 3.6.5; 3.6 versions prior to 3.6.21; 4.0 versions prior to 4.0.21; 4.2 versions prior to 4.2.11; 100 versions prior to 100.2.0. MongoDB Inc. Mongomirror 0 versions later than 0.6.0.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-33hj-8g8g-96xr",
"modified": "2024-02-06T00:30:27Z",
"modified": "2024-02-13T15:31:11Z",
"published": "2024-02-06T00:30:27Z",
"aliases": [
"CVE-2024-0660"
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4f24-3c6c-gh99",
"modified": "2024-02-06T00:30:27Z",
"modified": "2024-02-13T15:31:11Z",
"published": "2024-02-06T00:30:27Z",
"aliases": [
"CVE-2024-0612"
@@ -23,7 +23,7 @@
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3024861/"
"url": "https://plugins.trac.wordpress.org/changeset/3024861"
},
{
"type": "WEB",
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -0,0 +1,31 @@
{
"schema_version": "1.4.0",
"id": "GHSA-53p9-pvv8-g92g",
"modified": "2024-02-13T15:31:12Z",
"published": "2024-02-13T15:31:12Z",
"aliases": [
"CVE-2024-0707"
],
"details": "Rejected reason: **REJECT** Not a valid vulnerability.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0707"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-13T14:15:46Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5vqw-jmgh-xgcx",
"modified": "2024-02-13T15:31:12Z",
"published": "2024-02-13T15:31:12Z",
"aliases": [
"CVE-2024-1140"
],
"details": "Twister Antivirus v8.17 is vulnerable to an Out-of-bounds Read vulnerability by triggering the 0x801120B8 IOCTL code of the filmfd.sys driver.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1140"
},
{
"type": "WEB",
"url": "https://fluidattacks.com/advisories/fitzgerald"
},
{
"type": "WEB",
"url": "http://www.filseclab.com/en-us/products/twister.htm"
}
],
"database_specific": {
"cwe_ids": [
"CWE-125"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-13T15:15:08Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6c2q-w54r-h6fv",
"modified": "2024-02-13T15:31:12Z",
"published": "2024-02-13T15:31:12Z",
"aliases": [
"CVE-2024-1309"
],
"details": "Uncontrolled Resource Consumption vulnerability in Honeywell Niagara Framework on Windows, Linux, QNX allows Content Spoofing.This issue affects Niagara Framework: before Niagara AX 3.8.1, before Niagara 4.1.\n\n",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1309"
},
{
"type": "WEB",
"url": "https://process.honeywell.com"
},
{
"type": "WEB",
"url": "https://www.honeywell.com/us/en/product-security"
}
],
"database_specific": {
"cwe_ids": [
"CWE-400"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-13T14:15:46Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-72xj-cfw6-3c4q",
"modified": "2024-02-06T00:30:26Z",
"modified": "2024-02-13T15:31:11Z",
"published": "2024-02-06T00:30:26Z",
"aliases": [
"CVE-2023-6989"
@@ -23,7 +23,7 @@
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3013699%40wp-simple-firewall&new=3013699%40wp-simple-firewall&sfp_email=&sfph_mail="
"url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3013699@wp-simple-firewall&new=3013699@wp-simple-firewall&sfp_email=&sfph_mail="
},
{
"type": "WEB",
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-78h2-jh6j-hhgf",
"modified": "2024-02-06T00:30:27Z",
"modified": "2024-02-13T15:31:11Z",
"published": "2024-02-06T00:30:27Z",
"aliases": [
"CVE-2024-0586"
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8h8w-85rq-cgp4",
"modified": "2024-02-13T15:31:12Z",
"published": "2024-02-13T15:31:12Z",
"aliases": [
"CVE-2024-1096"
],
"details": "Twister Antivirus v8.17 allows Elevation of Privileges on the computer where it's installed by triggering the 0x80112067, 0x801120CB and 0x801120CC IOCTL codes of the fildds.sys driver.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1096"
},
{
"type": "WEB",
"url": "https://fluidattacks.com/advisories/holiday"
},
{
"type": "WEB",
"url": "http://www.filseclab.com/en-us/products/twister.htm"
}
],
"database_specific": {
"cwe_ids": [
"CWE-20"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-13T15:15:08Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8m36-62rw-9mxw",
"modified": "2024-02-13T15:31:12Z",
"published": "2024-02-13T15:31:12Z",
"aliases": [
"CVE-2024-1163"
],
"details": "Path Traversal in GitHub repository mbloch/mapshaper prior to 0.6.44.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1163"
},
{
"type": "WEB",
"url": "https://github.com/mbloch/mapshaper/commit/7437d903c0a87802c3751fc529d2de7098094c72"
},
{
"type": "WEB",
"url": "https://huntr.com/bounties/c1cbc18b-e4ab-4332-ad13-0033f0f976f5"
}
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-13T15:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8mxm-4gjm-vrc7",
"modified": "2024-02-13T15:31:12Z",
"published": "2024-02-13T15:31:12Z",
"aliases": [
"CVE-2023-6516"
],
"details": "To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts to clean up the database. It uses several methods, including some that are asynchronous: a small chunk of memory pointing to the cache element that can be cleaned up is first allocated and then queued for later processing. It was discovered that if the resolver is continuously processing query patterns triggering this type of cache-database maintenance, `named` may not be able to handle the cleanup events in a timely manner. This in turn enables the list of queued cleanup events to grow infinitely large over time, allowing the configured `max-cache-size` limit to be significantly exceeded.\nThis issue affects BIND 9 versions 9.16.0 through 9.16.45 and 9.16.8-S1 through 9.16.45-S1.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6516"
},
{
"type": "WEB",
"url": "https://kb.isc.org/docs/cve-2023-6516"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-13T14:15:46Z"
}
}
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-611"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fc5m-43m8-862c",
"modified": "2024-02-06T00:30:26Z",
"modified": "2024-02-13T15:31:11Z",
"published": "2024-02-06T00:30:26Z",
"aliases": [
"CVE-2023-6982"
@@ -23,7 +23,7 @@
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3021133%40shortcode-to-display-post-and-user-data&new=3021133%40shortcode-to-display-post-and-user-data&sfp_email=&sfph_mail="
"url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3021133@shortcode-to-display-post-and-user-data&new=3021133@shortcode-to-display-post-and-user-data&sfp_email=&sfph_mail="
},
{
"type": "WEB",
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ff78-2q7q-3gpw",
"modified": "2024-02-06T00:30:25Z",
"modified": "2024-02-13T15:31:10Z",
"published": "2024-02-06T00:30:25Z",
"aliases": [
"CVE-2023-22817"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fxcj-mv3v-84c5",
"modified": "2024-02-06T00:30:27Z",
"modified": "2024-02-13T15:31:11Z",
"published": "2024-02-06T00:30:27Z",
"aliases": [
"CVE-2024-1208"
@@ -27,7 +27,7 @@
},
{
"type": "WEB",
"url": "https://www.learndash.com/release-notes/"
"url": "https://www.learndash.com/release-notes"
},
{
"type": "WEB",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g56c-cwv7-vvrx",
"modified": "2024-02-06T00:30:27Z",
"modified": "2024-02-13T15:31:11Z",
"published": "2024-02-06T00:30:27Z",
"aliases": [
"CVE-2024-1177"
@@ -23,7 +23,7 @@
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3030843%40wp-club-manager&new=3030843%40wp-club-manager&sfp_email=&sfph_mail="
"url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3030843@wp-club-manager&new=3030843@wp-club-manager&sfp_email=&sfph_mail="
},
{
"type": "WEB",
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h29x-7wp6-7rpx",
"modified": "2024-02-13T15:31:12Z",
"published": "2024-02-13T15:31:12Z",
"aliases": [
"CVE-2024-24782"
],
"details": "An unauthenticated attacker can send a ping request from one network to another through an error in the origin verification even though the ports are separated by VLAN.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24782"
},
{
"type": "WEB",
"url": "https://cert.vde.com/en/advisories/VDE-2024-013"
}
],
"database_specific": {
"cwe_ids": [
"CWE-346"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-13T14:15:47Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jr25-xhw2-xwv9",
"modified": "2024-02-13T15:31:12Z",
"published": "2024-02-13T15:31:12Z",
"aliases": [
"CVE-2024-23440"
],
"details": "Vba32 Antivirus v3.36.0 is vulnerable to an Arbitrary Memory Read vulnerability. The 0x22200B IOCTL code of the Vba32m64.sys driver allows to read up to 0x802 of memory from ar arbitrary user-supplied pointer.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23440"
},
{
"type": "WEB",
"url": "https://fluidattacks.com/advisories/adderley"
},
{
"type": "WEB",
"url": "https://www.anti-virus.by/vba32"
}
],
"database_specific": {
"cwe_ids": [
"CWE-125"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-13T15:15:09Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m868-f948-vvjc",
"modified": "2024-02-13T15:31:12Z",
"published": "2024-02-13T15:31:12Z",
"aliases": [
"CVE-2023-5680"
],
"details": "If a resolver cache has a very large number of ECS records stored for the same name, the process of cleaning the cache database node for this name can significantly impair query performance. \nThis issue affects BIND 9 versions 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5680"
},
{
"type": "WEB",
"url": "https://kb.isc.org/docs/cve-2023-5680"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-13T14:15:45Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pgjx-2qxc-c47q",
"modified": "2024-02-06T00:30:27Z",
"modified": "2024-02-13T15:31:11Z",
"published": "2024-02-06T00:30:27Z",
"aliases": [
"CVE-2024-0597"
@@ -23,7 +23,7 @@
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3023398/"
"url": "https://plugins.trac.wordpress.org/changeset/3023398"
},
{
"type": "WEB",
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,

Some files were not shown because too many files have changed in this diff Show More