From 2eca7fad0d014ca93c12e6dc83ab428bbf4c96bc Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 19 Apr 2024 12:32:24 +0000 Subject: [PATCH] Publish Advisories GHSA-xr62-xhf5-qw2c GHSA-6f82-r7wj-8fxf GHSA-8564-m639-jh8r GHSA-mhc2-rv3c-8qpj GHSA-mvc5-vcrh-v937 GHSA-p6gp-c388-p4cr GHSA-pc7c-2483-8558 GHSA-w74w-xq97-pg62 GHSA-xc66-q4x2-cwqx --- .../GHSA-xr62-xhf5-qw2c.json | 6 ++- .../GHSA-6f82-r7wj-8fxf.json | 6 ++- .../GHSA-8564-m639-jh8r.json | 6 ++- .../GHSA-mhc2-rv3c-8qpj.json | 38 +++++++++++++++++++ .../GHSA-mvc5-vcrh-v937.json | 6 ++- .../GHSA-p6gp-c388-p4cr.json | 6 ++- .../GHSA-pc7c-2483-8558.json | 6 ++- .../GHSA-w74w-xq97-pg62.json | 6 ++- .../GHSA-xc66-q4x2-cwqx.json | 6 ++- 9 files changed, 78 insertions(+), 8 deletions(-) create mode 100644 advisories/unreviewed/2024/04/GHSA-mhc2-rv3c-8qpj/GHSA-mhc2-rv3c-8qpj.json diff --git a/advisories/unreviewed/2024/03/GHSA-xr62-xhf5-qw2c/GHSA-xr62-xhf5-qw2c.json b/advisories/unreviewed/2024/03/GHSA-xr62-xhf5-qw2c/GHSA-xr62-xhf5-qw2c.json index cb37ada22a6..826bd18de75 100644 --- a/advisories/unreviewed/2024/03/GHSA-xr62-xhf5-qw2c/GHSA-xr62-xhf5-qw2c.json +++ b/advisories/unreviewed/2024/03/GHSA-xr62-xhf5-qw2c/GHSA-xr62-xhf5-qw2c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xr62-xhf5-qw2c", - "modified": "2024-04-16T18:31:34Z", + "modified": "2024-04-19T12:31:16Z", "published": "2024-03-19T12:30:41Z", "aliases": [ "CVE-2024-2609" @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1866100" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00012.html" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-12" diff --git a/advisories/unreviewed/2024/04/GHSA-6f82-r7wj-8fxf/GHSA-6f82-r7wj-8fxf.json b/advisories/unreviewed/2024/04/GHSA-6f82-r7wj-8fxf/GHSA-6f82-r7wj-8fxf.json index a7b135a9c9a..c8bf61f3b6e 100644 --- a/advisories/unreviewed/2024/04/GHSA-6f82-r7wj-8fxf/GHSA-6f82-r7wj-8fxf.json +++ b/advisories/unreviewed/2024/04/GHSA-6f82-r7wj-8fxf/GHSA-6f82-r7wj-8fxf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6f82-r7wj-8fxf", - "modified": "2024-04-16T18:31:35Z", + "modified": "2024-04-19T12:31:17Z", "published": "2024-04-16T18:31:35Z", "aliases": [ "CVE-2024-3859" @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1874489" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00012.html" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-18" diff --git a/advisories/unreviewed/2024/04/GHSA-8564-m639-jh8r/GHSA-8564-m639-jh8r.json b/advisories/unreviewed/2024/04/GHSA-8564-m639-jh8r/GHSA-8564-m639-jh8r.json index 0e5e21b32c7..1f6d383f98a 100644 --- a/advisories/unreviewed/2024/04/GHSA-8564-m639-jh8r/GHSA-8564-m639-jh8r.json +++ b/advisories/unreviewed/2024/04/GHSA-8564-m639-jh8r/GHSA-8564-m639-jh8r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8564-m639-jh8r", - "modified": "2024-04-16T18:31:34Z", + "modified": "2024-04-19T12:31:17Z", "published": "2024-04-16T18:31:34Z", "aliases": [ "CVE-2024-3857" @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1886683" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00012.html" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-18" diff --git a/advisories/unreviewed/2024/04/GHSA-mhc2-rv3c-8qpj/GHSA-mhc2-rv3c-8qpj.json b/advisories/unreviewed/2024/04/GHSA-mhc2-rv3c-8qpj/GHSA-mhc2-rv3c-8qpj.json new file mode 100644 index 00000000000..212201a8aae --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mhc2-rv3c-8qpj/GHSA-mhc2-rv3c-8qpj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhc2-rv3c-8qpj", + "modified": "2024-04-19T12:31:17Z", + "published": "2024-04-19T12:31:17Z", + "aliases": [ + "CVE-2024-32683" + ], + "details": "Authorization Bypass Through User-Controlled Key vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimate Review: from n/a through 2.2.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32683" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-ultimate-review/wordpress-wp-ultimate-review-plugin-2-2-5-insecure-direct-object-references-idor-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T12:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mvc5-vcrh-v937/GHSA-mvc5-vcrh-v937.json b/advisories/unreviewed/2024/04/GHSA-mvc5-vcrh-v937/GHSA-mvc5-vcrh-v937.json index c336556c3dc..a891b2cd72c 100644 --- a/advisories/unreviewed/2024/04/GHSA-mvc5-vcrh-v937/GHSA-mvc5-vcrh-v937.json +++ b/advisories/unreviewed/2024/04/GHSA-mvc5-vcrh-v937/GHSA-mvc5-vcrh-v937.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mvc5-vcrh-v937", - "modified": "2024-04-16T18:31:36Z", + "modified": "2024-04-19T12:31:17Z", "published": "2024-04-16T18:31:36Z", "aliases": [ "CVE-2024-3861" @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1883158" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00012.html" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-18" diff --git a/advisories/unreviewed/2024/04/GHSA-p6gp-c388-p4cr/GHSA-p6gp-c388-p4cr.json b/advisories/unreviewed/2024/04/GHSA-p6gp-c388-p4cr/GHSA-p6gp-c388-p4cr.json index ba3f4a9f1fd..a325b0362a7 100644 --- a/advisories/unreviewed/2024/04/GHSA-p6gp-c388-p4cr/GHSA-p6gp-c388-p4cr.json +++ b/advisories/unreviewed/2024/04/GHSA-p6gp-c388-p4cr/GHSA-p6gp-c388-p4cr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p6gp-c388-p4cr", - "modified": "2024-04-16T18:31:34Z", + "modified": "2024-04-19T12:31:17Z", "published": "2024-04-16T18:31:34Z", "aliases": [ "CVE-2024-3302" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://kb.cert.org/vuls/id/421644" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00012.html" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-18" diff --git a/advisories/unreviewed/2024/04/GHSA-pc7c-2483-8558/GHSA-pc7c-2483-8558.json b/advisories/unreviewed/2024/04/GHSA-pc7c-2483-8558/GHSA-pc7c-2483-8558.json index 847c5eeb341..524fdc3d5c0 100644 --- a/advisories/unreviewed/2024/04/GHSA-pc7c-2483-8558/GHSA-pc7c-2483-8558.json +++ b/advisories/unreviewed/2024/04/GHSA-pc7c-2483-8558/GHSA-pc7c-2483-8558.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pc7c-2483-8558", - "modified": "2024-04-16T18:31:34Z", + "modified": "2024-04-19T12:31:17Z", "published": "2024-04-16T18:31:34Z", "aliases": [ "CVE-2024-3852" @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1883542" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00012.html" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-18" diff --git a/advisories/unreviewed/2024/04/GHSA-w74w-xq97-pg62/GHSA-w74w-xq97-pg62.json b/advisories/unreviewed/2024/04/GHSA-w74w-xq97-pg62/GHSA-w74w-xq97-pg62.json index 75c5c7f25fa..1ebba46bdfc 100644 --- a/advisories/unreviewed/2024/04/GHSA-w74w-xq97-pg62/GHSA-w74w-xq97-pg62.json +++ b/advisories/unreviewed/2024/04/GHSA-w74w-xq97-pg62/GHSA-w74w-xq97-pg62.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w74w-xq97-pg62", - "modified": "2024-04-16T18:31:36Z", + "modified": "2024-04-19T12:31:17Z", "published": "2024-04-16T18:31:36Z", "aliases": [ "CVE-2024-3864" @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1888333" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00012.html" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-18" diff --git a/advisories/unreviewed/2024/04/GHSA-xc66-q4x2-cwqx/GHSA-xc66-q4x2-cwqx.json b/advisories/unreviewed/2024/04/GHSA-xc66-q4x2-cwqx/GHSA-xc66-q4x2-cwqx.json index 9c73f968b63..b60c6c0ce03 100644 --- a/advisories/unreviewed/2024/04/GHSA-xc66-q4x2-cwqx/GHSA-xc66-q4x2-cwqx.json +++ b/advisories/unreviewed/2024/04/GHSA-xc66-q4x2-cwqx/GHSA-xc66-q4x2-cwqx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xc66-q4x2-cwqx", - "modified": "2024-04-16T18:31:34Z", + "modified": "2024-04-19T12:31:17Z", "published": "2024-04-16T18:31:34Z", "aliases": [ "CVE-2024-3854" @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1884552" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00012.html" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-18"