diff --git a/advisories/github-reviewed/2024/04/GHSA-3rq5-2g8h-59hc/GHSA-3rq5-2g8h-59hc.json b/advisories/github-reviewed/2024/04/GHSA-3rq5-2g8h-59hc/GHSA-3rq5-2g8h-59hc.json index 643144002ad..36fec63ea43 100644 --- a/advisories/github-reviewed/2024/04/GHSA-3rq5-2g8h-59hc/GHSA-3rq5-2g8h-59hc.json +++ b/advisories/github-reviewed/2024/04/GHSA-3rq5-2g8h-59hc/GHSA-3rq5-2g8h-59hc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3rq5-2g8h-59hc", - "modified": "2024-06-10T18:30:54Z", + "modified": "2024-06-26T03:31:48Z", "published": "2024-04-11T15:30:48Z", "aliases": [ "CVE-2023-29483" @@ -95,6 +95,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOHJOO3OM65UIUUUVDEXMCTXNM6LXZEH" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3BNSIK5NFYSAP53Y45GOCMOQHHDLGIF" + }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20240510-0001" diff --git a/advisories/unreviewed/2024/06/GHSA-57qf-5gg6-9g3g/GHSA-57qf-5gg6-9g3g.json b/advisories/unreviewed/2024/06/GHSA-57qf-5gg6-9g3g/GHSA-57qf-5gg6-9g3g.json new file mode 100644 index 00000000000..da10f7cffbe --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-57qf-5gg6-9g3g/GHSA-57qf-5gg6-9g3g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57qf-5gg6-9g3g", + "modified": "2024-06-26T03:31:50Z", + "published": "2024-06-26T03:31:50Z", + "aliases": [ + "CVE-2024-29174" + ], + "details": "Dell Data Domain, versions prior to 7.13.0.0, LTS 7.7.5.30, LTS 7.10.1.20 contain an SQL Injection vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing unauthorized access to application data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29174" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000226148/dsa-2024-219-dell-technologies-powerprotect-dd-security-update-for-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T03:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-8xc2-8m55-8q36/GHSA-8xc2-8m55-8q36.json b/advisories/unreviewed/2024/06/GHSA-8xc2-8m55-8q36/GHSA-8xc2-8m55-8q36.json new file mode 100644 index 00000000000..26d02405b64 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-8xc2-8m55-8q36/GHSA-8xc2-8m55-8q36.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xc2-8m55-8q36", + "modified": "2024-06-26T03:31:51Z", + "published": "2024-06-26T03:31:50Z", + "aliases": [ + "CVE-2024-5181" + ], + "details": "A command injection vulnerability exists in the mudler/localai version 2.14.0. The vulnerability arises from the application's handling of the backend parameter in the configuration file, which is used in the name of the initialized process. An attacker can exploit this vulnerability by manipulating the path of the vulnerable binary file specified in the backend parameter, allowing the execution of arbitrary code on the system. This issue is due to improper neutralization of special elements used in an OS command, leading to potential full control over the affected system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5181" + }, + { + "type": "WEB", + "url": "https://github.com/mudler/localai/commit/1a3dedece06cab1acc3332055d285ac540a47f0e" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/c6e3cb58-6fa4-4207-bb92-ae7644174661" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T03:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-982x-mjmg-rfmg/GHSA-982x-mjmg-rfmg.json b/advisories/unreviewed/2024/06/GHSA-982x-mjmg-rfmg/GHSA-982x-mjmg-rfmg.json new file mode 100644 index 00000000000..3fda7516988 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-982x-mjmg-rfmg/GHSA-982x-mjmg-rfmg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-982x-mjmg-rfmg", + "modified": "2024-06-26T03:31:50Z", + "published": "2024-06-26T03:31:50Z", + "aliases": [ + "CVE-2024-5173" + ], + "details": "The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Video player widget settings in all versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5173" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/ht-mega-for-elementor/tags/2.5.3/includes/widgets/htmega_videoplayer.php#L549" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/aac9569e-d33d-45b3-bd03-2e7f48536ae5?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T02:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-g4vq-69fj-97qw/GHSA-g4vq-69fj-97qw.json b/advisories/unreviewed/2024/06/GHSA-g4vq-69fj-97qw/GHSA-g4vq-69fj-97qw.json new file mode 100644 index 00000000000..f61a951d27e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-g4vq-69fj-97qw/GHSA-g4vq-69fj-97qw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4vq-69fj-97qw", + "modified": "2024-06-26T03:31:50Z", + "published": "2024-06-26T03:31:50Z", + "aliases": [ + "CVE-2024-29177" + ], + "details": "Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a disclosure of temporary sensitive information vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to the reuse of disclosed information to gain unauthorized access to the application report.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29177" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000226148/dsa-2024-219-dell-technologies-powerprotect-dd-security-update-for-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T03:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-j72h-72jr-j8pr/GHSA-j72h-72jr-j8pr.json b/advisories/unreviewed/2024/06/GHSA-j72h-72jr-j8pr/GHSA-j72h-72jr-j8pr.json new file mode 100644 index 00000000000..ac111035d71 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-j72h-72jr-j8pr/GHSA-j72h-72jr-j8pr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j72h-72jr-j8pr", + "modified": "2024-06-26T03:31:50Z", + "published": "2024-06-26T03:31:50Z", + "aliases": [ + "CVE-2024-29175" + ], + "details": "Dell PowerProtect Data Domain, versions prior to 7.13.0.0, LTS 7.7.5.40, LTS 7.10.1.30 contain an weak cryptographic algorithm vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to man-in-the-middle attack that exposes sensitive session information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29175" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000226148/dsa-2024-219-dell-technologies-powerprotect-dd-security-update-for-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-327" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T03:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-m882-mjcv-h646/GHSA-m882-mjcv-h646.json b/advisories/unreviewed/2024/06/GHSA-m882-mjcv-h646/GHSA-m882-mjcv-h646.json new file mode 100644 index 00000000000..77351b49d2e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-m882-mjcv-h646/GHSA-m882-mjcv-h646.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m882-mjcv-h646", + "modified": "2024-06-26T03:31:50Z", + "published": "2024-06-26T03:31:50Z", + "aliases": [ + "CVE-2024-29173" + ], + "details": "Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a Server-Side Request Forgery (SSRF) vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to disclosure of information on the application or remote client.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29173" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000226148/dsa-2024-219-dell-technologies-powerprotect-dd-security-update-for-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-rjv4-w97f-h7vm/GHSA-rjv4-w97f-h7vm.json b/advisories/unreviewed/2024/06/GHSA-rjv4-w97f-h7vm/GHSA-rjv4-w97f-h7vm.json new file mode 100644 index 00000000000..8f5aa59a6fc --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-rjv4-w97f-h7vm/GHSA-rjv4-w97f-h7vm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rjv4-w97f-h7vm", + "modified": "2024-06-26T03:31:50Z", + "published": "2024-06-26T03:31:50Z", + "aliases": [ + "CVE-2024-28973" + ], + "details": "Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a Stored Cross-Site Scripting Vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes in a trusted application data store. When a high privileged victim user accesses the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application. Exploitation may lead to information disclosure, session theft, or client-side request forgery", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28973" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000226148/dsa-2024-219-dell-technologies-powerprotect-dd-security-update-for-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-vx2h-xx2h-2744/GHSA-vx2h-xx2h-2744.json b/advisories/unreviewed/2024/06/GHSA-vx2h-xx2h-2744/GHSA-vx2h-xx2h-2744.json new file mode 100644 index 00000000000..09bfbe1d41c --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-vx2h-xx2h-2744/GHSA-vx2h-xx2h-2744.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vx2h-xx2h-2744", + "modified": "2024-06-26T03:31:50Z", + "published": "2024-06-26T03:31:50Z", + "aliases": [ + "CVE-2024-29176" + ], + "details": "Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a buffer overflow vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to an application crash or execution of arbitrary code on the vulnerable application's underlying operating system with privileges of the vulnerable application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29176" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000226148/dsa-2024-219-dell-technologies-powerprotect-dd-security-update-for-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-788" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T03:15:10Z" + } +} \ No newline at end of file