Publish Advisories

GHSA-3p7f-4r2q-wxmm
GHSA-6w42-c4vx-prcr
GHSA-7qpm-3qf3-fjgw
GHSA-925f-cxg2-4483
GHSA-ghhv-pj7q-4j6f
GHSA-jvrw-wp92-qhvc
GHSA-qrv4-68mg-fv43
GHSA-rhxj-255h-8jc4
GHSA-vcxr-8fw2-w2wp
GHSA-vjq8-qf9g-mxxr
GHSA-x3qm-cm3j-3qcm
This commit is contained in:
advisory-database[bot]
2024-03-26 00:33:14 +00:00
parent 730077d4a4
commit 2b48f7efd5
11 changed files with 399 additions and 1 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3p7f-4r2q-wxmm",
"modified": "2024-03-25T18:30:56Z",
"modified": "2024-03-26T00:31:59Z",
"published": "2024-02-19T12:30:37Z",
"aliases": [
"CVE-2024-1580"
@@ -37,6 +37,10 @@
"type": "WEB",
"url": "https://support.apple.com/kb/HT214093"
},
{
"type": "WEB",
"url": "https://support.apple.com/kb/HT214094"
},
{
"type": "WEB",
"url": "https://support.apple.com/kb/HT214095"
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6w42-c4vx-prcr",
"modified": "2024-03-26T00:32:02Z",
"published": "2024-03-26T00:32:02Z",
"aliases": [
"CVE-2024-2873"
],
"details": "A vulnerability was found in wolfSSH's server-side state machine before versions 1.4.17. A malicious client could create channels without first performing user authentication, resulting in unauthorized access.\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2873"
},
{
"type": "WEB",
"url": "https://github.com/wolfSSL/wolfssh/pull/670"
},
{
"type": "WEB",
"url": "https://github.com/wolfSSL/wolfssh/pull/671"
},
{
"type": "WEB",
"url": "https://www.wolfssl.com/docs/security-vulnerabilities"
}
],
"database_specific": {
"cwe_ids": [
"CWE-287"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T22:37:19Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7qpm-3qf3-fjgw",
"modified": "2024-03-26T00:32:02Z",
"published": "2024-03-26T00:32:02Z",
"aliases": [
"CVE-2024-29301"
],
"details": "SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-admin.php?admin_id=",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29301"
},
{
"type": "WEB",
"url": "https://packetstormsecurity.com/files/177737/Task-Management-System-1.0-SQL-Injection.html"
},
{
"type": "WEB",
"url": "https://www.strongboxit.com"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-26T00:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-925f-cxg2-4483",
"modified": "2024-03-26T00:32:01Z",
"published": "2024-03-26T00:32:01Z",
"aliases": [
"CVE-2024-21914"
],
"details": "\nA vulnerability exists in the affected product that allows a malicious user to restart the Rockwell Automation PanelView™ Plus 7 terminal remotely without security protections. If the vulnerability is exploited, it could lead to the loss of view or control of the PanelView™ product.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21914"
},
{
"type": "WEB",
"url": "https://www.rockwellautomation.com/en-us/support/advisory.SD1663.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T22:37:19Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ghhv-pj7q-4j6f",
"modified": "2024-03-26T00:32:02Z",
"published": "2024-03-26T00:32:02Z",
"aliases": [
"CVE-2024-29302"
],
"details": "SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-employee.php.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29302"
},
{
"type": "WEB",
"url": "https://packetstormsecurity.com/files/177737/Task-Management-System-1.0-SQL-Injection.html"
},
{
"type": "WEB",
"url": "https://www.strongboxit.com"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-26T00:15:08Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jvrw-wp92-qhvc",
"modified": "2024-03-26T00:32:01Z",
"published": "2024-03-26T00:32:01Z",
"aliases": [
"CVE-2024-29442"
],
"details": "An unauthorized access vulnerability has been discovered in ROS2 Humble Hawksbill versions where ROS_VERSION is 2 and ROS_PYTHON_VERSION is 3. This vulnerability could potentially allow a malicious user to gain unauthorized access to multiple ROS2 nodes remotely. Unauthorized access to these nodes could result in compromised system integrity, the execution of arbitrary commands, and disclosure of sensitive information.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29442"
},
{
"type": "WEB",
"url": "https://github.com/yashpatelphd/CVE-2024-29442"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T22:37:19Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qrv4-68mg-fv43",
"modified": "2024-03-26T00:32:02Z",
"published": "2024-03-26T00:32:02Z",
"aliases": [
"CVE-2024-0901"
],
"details": "Remotely executed SEGV and out of bounds read allows malicious packet sender to crash or cause an out of bounds read via sending a malformed packet with the correct length.\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0901"
},
{
"type": "WEB",
"url": "https://github.com/wolfSSL/wolfssl/issues/7089"
},
{
"type": "WEB",
"url": "https://github.com/wolfSSL/wolfssl/pull/7099"
}
],
"database_specific": {
"cwe_ids": [
"CWE-129"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T23:15:51Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rhxj-255h-8jc4",
"modified": "2024-03-26T00:32:02Z",
"published": "2024-03-26T00:32:02Z",
"aliases": [
"CVE-2024-28421"
],
"details": "SQL Injection vulnerability in Razor 0.8.0 allows a remote attacker to escalate privileges via the ChannelModel::updateapk method of the channelmodle.php",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28421"
},
{
"type": "WEB",
"url": "https://github.com/cobub/razor/issues/178"
},
{
"type": "WEB",
"url": "https://gist.github.com/LioTree/003202727a61c0fb3ec3c948ab5e38f9"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T23:15:51Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vcxr-8fw2-w2wp",
"modified": "2024-03-26T00:32:02Z",
"published": "2024-03-26T00:32:02Z",
"aliases": [
"CVE-2024-29303"
],
"details": "The delete admin users function of SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29303"
},
{
"type": "WEB",
"url": "https://packetstormsecurity.com/files/177737/Task-Management-System-1.0-SQL-Injection.html"
},
{
"type": "WEB",
"url": "https://www.strongboxit.com"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-26T00:15:08Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vjq8-qf9g-mxxr",
"modified": "2024-03-26T00:31:59Z",
"published": "2024-03-26T00:31:59Z",
"aliases": [
"CVE-2023-47430"
],
"details": "Stack-buffer-overflow vulnerability in ReadyMedia (MiniDLNA) v1.3.3 allows attackers to cause a denial of service via via the SendContainer() function at tivo_commands.c.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47430"
},
{
"type": "WEB",
"url": "https://sourceforge.net/p/minidlna/bugs/361"
},
{
"type": "WEB",
"url": "https://sourceforge.net/projects/minidlna"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T22:37:19Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x3qm-cm3j-3qcm",
"modified": "2024-03-26T00:31:59Z",
"published": "2024-03-26T00:31:59Z",
"aliases": [
"CVE-2024-1973"
],
"details": "By leveraging the vulnerability, lower-privileged users of Content Manager can manipulate Content Manager clients to elevate privileges and perform unauthorized operations. ",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1973"
},
{
"type": "WEB",
"url": "https://portal.microfocus.com/s/article/KM000027861"
}
],
"database_specific": {
"cwe_ids": [
"CWE-269"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T22:37:19Z"
}
}