From 2b48f7efd55b27efdcfdd2d589e402fce1bc3cf2 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 26 Mar 2024 00:33:14 +0000 Subject: [PATCH] Publish Advisories GHSA-3p7f-4r2q-wxmm GHSA-6w42-c4vx-prcr GHSA-7qpm-3qf3-fjgw GHSA-925f-cxg2-4483 GHSA-ghhv-pj7q-4j6f GHSA-jvrw-wp92-qhvc GHSA-qrv4-68mg-fv43 GHSA-rhxj-255h-8jc4 GHSA-vcxr-8fw2-w2wp GHSA-vjq8-qf9g-mxxr GHSA-x3qm-cm3j-3qcm --- .../GHSA-3p7f-4r2q-wxmm.json | 6 ++- .../GHSA-6w42-c4vx-prcr.json | 46 +++++++++++++++++++ .../GHSA-7qpm-3qf3-fjgw.json | 39 ++++++++++++++++ .../GHSA-925f-cxg2-4483.json | 38 +++++++++++++++ .../GHSA-ghhv-pj7q-4j6f.json | 39 ++++++++++++++++ .../GHSA-jvrw-wp92-qhvc.json | 35 ++++++++++++++ .../GHSA-qrv4-68mg-fv43.json | 42 +++++++++++++++++ .../GHSA-rhxj-255h-8jc4.json | 39 ++++++++++++++++ .../GHSA-vcxr-8fw2-w2wp.json | 39 ++++++++++++++++ .../GHSA-vjq8-qf9g-mxxr.json | 39 ++++++++++++++++ .../GHSA-x3qm-cm3j-3qcm.json | 38 +++++++++++++++ 11 files changed, 399 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2024/03/GHSA-6w42-c4vx-prcr/GHSA-6w42-c4vx-prcr.json create mode 100644 advisories/unreviewed/2024/03/GHSA-7qpm-3qf3-fjgw/GHSA-7qpm-3qf3-fjgw.json create mode 100644 advisories/unreviewed/2024/03/GHSA-925f-cxg2-4483/GHSA-925f-cxg2-4483.json create mode 100644 advisories/unreviewed/2024/03/GHSA-ghhv-pj7q-4j6f/GHSA-ghhv-pj7q-4j6f.json create mode 100644 advisories/unreviewed/2024/03/GHSA-jvrw-wp92-qhvc/GHSA-jvrw-wp92-qhvc.json create mode 100644 advisories/unreviewed/2024/03/GHSA-qrv4-68mg-fv43/GHSA-qrv4-68mg-fv43.json create mode 100644 advisories/unreviewed/2024/03/GHSA-rhxj-255h-8jc4/GHSA-rhxj-255h-8jc4.json create mode 100644 advisories/unreviewed/2024/03/GHSA-vcxr-8fw2-w2wp/GHSA-vcxr-8fw2-w2wp.json create mode 100644 advisories/unreviewed/2024/03/GHSA-vjq8-qf9g-mxxr/GHSA-vjq8-qf9g-mxxr.json create mode 100644 advisories/unreviewed/2024/03/GHSA-x3qm-cm3j-3qcm/GHSA-x3qm-cm3j-3qcm.json diff --git a/advisories/unreviewed/2024/02/GHSA-3p7f-4r2q-wxmm/GHSA-3p7f-4r2q-wxmm.json b/advisories/unreviewed/2024/02/GHSA-3p7f-4r2q-wxmm/GHSA-3p7f-4r2q-wxmm.json index 6387672aaa2..a136f9770c9 100644 --- a/advisories/unreviewed/2024/02/GHSA-3p7f-4r2q-wxmm/GHSA-3p7f-4r2q-wxmm.json +++ b/advisories/unreviewed/2024/02/GHSA-3p7f-4r2q-wxmm/GHSA-3p7f-4r2q-wxmm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3p7f-4r2q-wxmm", - "modified": "2024-03-25T18:30:56Z", + "modified": "2024-03-26T00:31:59Z", "published": "2024-02-19T12:30:37Z", "aliases": [ "CVE-2024-1580" @@ -37,6 +37,10 @@ "type": "WEB", "url": "https://support.apple.com/kb/HT214093" }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214094" + }, { "type": "WEB", "url": "https://support.apple.com/kb/HT214095" diff --git a/advisories/unreviewed/2024/03/GHSA-6w42-c4vx-prcr/GHSA-6w42-c4vx-prcr.json b/advisories/unreviewed/2024/03/GHSA-6w42-c4vx-prcr/GHSA-6w42-c4vx-prcr.json new file mode 100644 index 00000000000..6078b757abb --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-6w42-c4vx-prcr/GHSA-6w42-c4vx-prcr.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6w42-c4vx-prcr", + "modified": "2024-03-26T00:32:02Z", + "published": "2024-03-26T00:32:02Z", + "aliases": [ + "CVE-2024-2873" + ], + "details": "A vulnerability was found in wolfSSH's server-side state machine before versions 1.4.17. A malicious client could create channels without first performing user authentication, resulting in unauthorized access.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2873" + }, + { + "type": "WEB", + "url": "https://github.com/wolfSSL/wolfssh/pull/670" + }, + { + "type": "WEB", + "url": "https://github.com/wolfSSL/wolfssh/pull/671" + }, + { + "type": "WEB", + "url": "https://www.wolfssl.com/docs/security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-25T22:37:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-7qpm-3qf3-fjgw/GHSA-7qpm-3qf3-fjgw.json b/advisories/unreviewed/2024/03/GHSA-7qpm-3qf3-fjgw/GHSA-7qpm-3qf3-fjgw.json new file mode 100644 index 00000000000..ed55757464b --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-7qpm-3qf3-fjgw/GHSA-7qpm-3qf3-fjgw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qpm-3qf3-fjgw", + "modified": "2024-03-26T00:32:02Z", + "published": "2024-03-26T00:32:02Z", + "aliases": [ + "CVE-2024-29301" + ], + "details": "SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-admin.php?admin_id=", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29301" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/177737/Task-Management-System-1.0-SQL-Injection.html" + }, + { + "type": "WEB", + "url": "https://www.strongboxit.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T00:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-925f-cxg2-4483/GHSA-925f-cxg2-4483.json b/advisories/unreviewed/2024/03/GHSA-925f-cxg2-4483/GHSA-925f-cxg2-4483.json new file mode 100644 index 00000000000..c9d6e5a4d41 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-925f-cxg2-4483/GHSA-925f-cxg2-4483.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-925f-cxg2-4483", + "modified": "2024-03-26T00:32:01Z", + "published": "2024-03-26T00:32:01Z", + "aliases": [ + "CVE-2024-21914" + ], + "details": "\nA vulnerability exists in the affected product that allows a malicious user to restart the Rockwell Automation PanelView™ Plus 7 terminal remotely without security protections. If the vulnerability is exploited, it could lead to the loss of view or control of the PanelView™ product.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21914" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/support/advisory.SD1663.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-25T22:37:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-ghhv-pj7q-4j6f/GHSA-ghhv-pj7q-4j6f.json b/advisories/unreviewed/2024/03/GHSA-ghhv-pj7q-4j6f/GHSA-ghhv-pj7q-4j6f.json new file mode 100644 index 00000000000..71bd2a6f480 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-ghhv-pj7q-4j6f/GHSA-ghhv-pj7q-4j6f.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghhv-pj7q-4j6f", + "modified": "2024-03-26T00:32:02Z", + "published": "2024-03-26T00:32:02Z", + "aliases": [ + "CVE-2024-29302" + ], + "details": "SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-employee.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29302" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/177737/Task-Management-System-1.0-SQL-Injection.html" + }, + { + "type": "WEB", + "url": "https://www.strongboxit.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T00:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-jvrw-wp92-qhvc/GHSA-jvrw-wp92-qhvc.json b/advisories/unreviewed/2024/03/GHSA-jvrw-wp92-qhvc/GHSA-jvrw-wp92-qhvc.json new file mode 100644 index 00000000000..301e5fbaaa4 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-jvrw-wp92-qhvc/GHSA-jvrw-wp92-qhvc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvrw-wp92-qhvc", + "modified": "2024-03-26T00:32:01Z", + "published": "2024-03-26T00:32:01Z", + "aliases": [ + "CVE-2024-29442" + ], + "details": "An unauthorized access vulnerability has been discovered in ROS2 Humble Hawksbill versions where ROS_VERSION is 2 and ROS_PYTHON_VERSION is 3. This vulnerability could potentially allow a malicious user to gain unauthorized access to multiple ROS2 nodes remotely. Unauthorized access to these nodes could result in compromised system integrity, the execution of arbitrary commands, and disclosure of sensitive information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29442" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-29442" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-25T22:37:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-qrv4-68mg-fv43/GHSA-qrv4-68mg-fv43.json b/advisories/unreviewed/2024/03/GHSA-qrv4-68mg-fv43/GHSA-qrv4-68mg-fv43.json new file mode 100644 index 00000000000..ebf8589dce4 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-qrv4-68mg-fv43/GHSA-qrv4-68mg-fv43.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrv4-68mg-fv43", + "modified": "2024-03-26T00:32:02Z", + "published": "2024-03-26T00:32:02Z", + "aliases": [ + "CVE-2024-0901" + ], + "details": "Remotely executed SEGV and out of bounds read allows malicious packet sender to crash or cause an out of bounds read via sending a malformed packet with the correct length.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0901" + }, + { + "type": "WEB", + "url": "https://github.com/wolfSSL/wolfssl/issues/7089" + }, + { + "type": "WEB", + "url": "https://github.com/wolfSSL/wolfssl/pull/7099" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-129" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-25T23:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-rhxj-255h-8jc4/GHSA-rhxj-255h-8jc4.json b/advisories/unreviewed/2024/03/GHSA-rhxj-255h-8jc4/GHSA-rhxj-255h-8jc4.json new file mode 100644 index 00000000000..eb21c911fba --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-rhxj-255h-8jc4/GHSA-rhxj-255h-8jc4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhxj-255h-8jc4", + "modified": "2024-03-26T00:32:02Z", + "published": "2024-03-26T00:32:02Z", + "aliases": [ + "CVE-2024-28421" + ], + "details": "SQL Injection vulnerability in Razor 0.8.0 allows a remote attacker to escalate privileges via the ChannelModel::updateapk method of the channelmodle.php", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28421" + }, + { + "type": "WEB", + "url": "https://github.com/cobub/razor/issues/178" + }, + { + "type": "WEB", + "url": "https://gist.github.com/LioTree/003202727a61c0fb3ec3c948ab5e38f9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-25T23:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-vcxr-8fw2-w2wp/GHSA-vcxr-8fw2-w2wp.json b/advisories/unreviewed/2024/03/GHSA-vcxr-8fw2-w2wp/GHSA-vcxr-8fw2-w2wp.json new file mode 100644 index 00000000000..869235f25b5 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-vcxr-8fw2-w2wp/GHSA-vcxr-8fw2-w2wp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcxr-8fw2-w2wp", + "modified": "2024-03-26T00:32:02Z", + "published": "2024-03-26T00:32:02Z", + "aliases": [ + "CVE-2024-29303" + ], + "details": "The delete admin users function of SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29303" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/177737/Task-Management-System-1.0-SQL-Injection.html" + }, + { + "type": "WEB", + "url": "https://www.strongboxit.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T00:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-vjq8-qf9g-mxxr/GHSA-vjq8-qf9g-mxxr.json b/advisories/unreviewed/2024/03/GHSA-vjq8-qf9g-mxxr/GHSA-vjq8-qf9g-mxxr.json new file mode 100644 index 00000000000..f5cd2ee9a71 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-vjq8-qf9g-mxxr/GHSA-vjq8-qf9g-mxxr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjq8-qf9g-mxxr", + "modified": "2024-03-26T00:31:59Z", + "published": "2024-03-26T00:31:59Z", + "aliases": [ + "CVE-2023-47430" + ], + "details": "Stack-buffer-overflow vulnerability in ReadyMedia (MiniDLNA) v1.3.3 allows attackers to cause a denial of service via via the SendContainer() function at tivo_commands.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47430" + }, + { + "type": "WEB", + "url": "https://sourceforge.net/p/minidlna/bugs/361" + }, + { + "type": "WEB", + "url": "https://sourceforge.net/projects/minidlna" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-25T22:37:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-x3qm-cm3j-3qcm/GHSA-x3qm-cm3j-3qcm.json b/advisories/unreviewed/2024/03/GHSA-x3qm-cm3j-3qcm/GHSA-x3qm-cm3j-3qcm.json new file mode 100644 index 00000000000..57b8409e45e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-x3qm-cm3j-3qcm/GHSA-x3qm-cm3j-3qcm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3qm-cm3j-3qcm", + "modified": "2024-03-26T00:31:59Z", + "published": "2024-03-26T00:31:59Z", + "aliases": [ + "CVE-2024-1973" + ], + "details": "By leveraging the vulnerability, lower-privileged users of Content Manager can manipulate Content Manager clients to elevate privileges and perform unauthorized operations. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1973" + }, + { + "type": "WEB", + "url": "https://portal.microfocus.com/s/article/KM000027861" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-25T22:37:19Z" + } +} \ No newline at end of file