mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-3p7f-4r2q-wxmm GHSA-6w42-c4vx-prcr GHSA-7qpm-3qf3-fjgw GHSA-925f-cxg2-4483 GHSA-ghhv-pj7q-4j6f GHSA-jvrw-wp92-qhvc GHSA-qrv4-68mg-fv43 GHSA-rhxj-255h-8jc4 GHSA-vcxr-8fw2-w2wp GHSA-vjq8-qf9g-mxxr GHSA-x3qm-cm3j-3qcm
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-3p7f-4r2q-wxmm",
|
||||
"modified": "2024-03-25T18:30:56Z",
|
||||
"modified": "2024-03-26T00:31:59Z",
|
||||
"published": "2024-02-19T12:30:37Z",
|
||||
"aliases": [
|
||||
"CVE-2024-1580"
|
||||
@@ -37,6 +37,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://support.apple.com/kb/HT214093"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://support.apple.com/kb/HT214094"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://support.apple.com/kb/HT214095"
|
||||
|
||||
@@ -0,0 +1,46 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-6w42-c4vx-prcr",
|
||||
"modified": "2024-03-26T00:32:02Z",
|
||||
"published": "2024-03-26T00:32:02Z",
|
||||
"aliases": [
|
||||
"CVE-2024-2873"
|
||||
],
|
||||
"details": "A vulnerability was found in wolfSSH's server-side state machine before versions 1.4.17. A malicious client could create channels without first performing user authentication, resulting in unauthorized access.\n",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2873"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/wolfSSL/wolfssh/pull/670"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/wolfSSL/wolfssh/pull/671"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.wolfssl.com/docs/security-vulnerabilities"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-287"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-03-25T22:37:19Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-7qpm-3qf3-fjgw",
|
||||
"modified": "2024-03-26T00:32:02Z",
|
||||
"published": "2024-03-26T00:32:02Z",
|
||||
"aliases": [
|
||||
"CVE-2024-29301"
|
||||
],
|
||||
"details": "SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-admin.php?admin_id=",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29301"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://packetstormsecurity.com/files/177737/Task-Management-System-1.0-SQL-Injection.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.strongboxit.com"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-03-26T00:15:08Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-925f-cxg2-4483",
|
||||
"modified": "2024-03-26T00:32:01Z",
|
||||
"published": "2024-03-26T00:32:01Z",
|
||||
"aliases": [
|
||||
"CVE-2024-21914"
|
||||
],
|
||||
"details": "\nA vulnerability exists in the affected product that allows a malicious user to restart the Rockwell Automation PanelView™ Plus 7 terminal remotely without security protections. If the vulnerability is exploited, it could lead to the loss of view or control of the PanelView™ product.\n\n",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21914"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.rockwellautomation.com/en-us/support/advisory.SD1663.html"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-03-25T22:37:19Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-ghhv-pj7q-4j6f",
|
||||
"modified": "2024-03-26T00:32:02Z",
|
||||
"published": "2024-03-26T00:32:02Z",
|
||||
"aliases": [
|
||||
"CVE-2024-29302"
|
||||
],
|
||||
"details": "SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-employee.php.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29302"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://packetstormsecurity.com/files/177737/Task-Management-System-1.0-SQL-Injection.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.strongboxit.com"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-03-26T00:15:08Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-jvrw-wp92-qhvc",
|
||||
"modified": "2024-03-26T00:32:01Z",
|
||||
"published": "2024-03-26T00:32:01Z",
|
||||
"aliases": [
|
||||
"CVE-2024-29442"
|
||||
],
|
||||
"details": "An unauthorized access vulnerability has been discovered in ROS2 Humble Hawksbill versions where ROS_VERSION is 2 and ROS_PYTHON_VERSION is 3. This vulnerability could potentially allow a malicious user to gain unauthorized access to multiple ROS2 nodes remotely. Unauthorized access to these nodes could result in compromised system integrity, the execution of arbitrary commands, and disclosure of sensitive information.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29442"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/yashpatelphd/CVE-2024-29442"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-03-25T22:37:19Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,42 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-qrv4-68mg-fv43",
|
||||
"modified": "2024-03-26T00:32:02Z",
|
||||
"published": "2024-03-26T00:32:02Z",
|
||||
"aliases": [
|
||||
"CVE-2024-0901"
|
||||
],
|
||||
"details": "Remotely executed SEGV and out of bounds read allows malicious packet sender to crash or cause an out of bounds read via sending a malformed packet with the correct length.\n",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0901"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/wolfSSL/wolfssl/issues/7089"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/wolfSSL/wolfssl/pull/7099"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-129"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-03-25T23:15:51Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-rhxj-255h-8jc4",
|
||||
"modified": "2024-03-26T00:32:02Z",
|
||||
"published": "2024-03-26T00:32:02Z",
|
||||
"aliases": [
|
||||
"CVE-2024-28421"
|
||||
],
|
||||
"details": "SQL Injection vulnerability in Razor 0.8.0 allows a remote attacker to escalate privileges via the ChannelModel::updateapk method of the channelmodle.php",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28421"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/cobub/razor/issues/178"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://gist.github.com/LioTree/003202727a61c0fb3ec3c948ab5e38f9"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-03-25T23:15:51Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-vcxr-8fw2-w2wp",
|
||||
"modified": "2024-03-26T00:32:02Z",
|
||||
"published": "2024-03-26T00:32:02Z",
|
||||
"aliases": [
|
||||
"CVE-2024-29303"
|
||||
],
|
||||
"details": "The delete admin users function of SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29303"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://packetstormsecurity.com/files/177737/Task-Management-System-1.0-SQL-Injection.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.strongboxit.com"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-03-26T00:15:08Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-vjq8-qf9g-mxxr",
|
||||
"modified": "2024-03-26T00:31:59Z",
|
||||
"published": "2024-03-26T00:31:59Z",
|
||||
"aliases": [
|
||||
"CVE-2023-47430"
|
||||
],
|
||||
"details": "Stack-buffer-overflow vulnerability in ReadyMedia (MiniDLNA) v1.3.3 allows attackers to cause a denial of service via via the SendContainer() function at tivo_commands.c.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47430"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://sourceforge.net/p/minidlna/bugs/361"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://sourceforge.net/projects/minidlna"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-03-25T22:37:19Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-x3qm-cm3j-3qcm",
|
||||
"modified": "2024-03-26T00:31:59Z",
|
||||
"published": "2024-03-26T00:31:59Z",
|
||||
"aliases": [
|
||||
"CVE-2024-1973"
|
||||
],
|
||||
"details": "By leveraging the vulnerability, lower-privileged users of Content Manager can manipulate Content Manager clients to elevate privileges and perform unauthorized operations. ",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1973"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://portal.microfocus.com/s/article/KM000027861"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-269"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-03-25T22:37:19Z"
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user