From 36bf7f500de476844f04c089062d9a92987500d2 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 23 May 2024 09:31:58 +0000 Subject: [PATCH] Publish Advisories GHSA-7x4w-fjp3-6fmr GHSA-897p-94fw-f6m3 GHSA-9r4p-g7c7-2c4r GHSA-f835-w392-m6qf GHSA-hxp2-c3hq-rcq5 GHSA-mgrf-rx3w-m492 GHSA-mxpc-px8m-2fqc GHSA-qcr5-ffr5-4rgc GHSA-qm69-cr5h-7x64 GHSA-r6p6-7q5h-jc4x GHSA-rqhf-rjxm-7vcq GHSA-vw34-wv53-96pw GHSA-wx68-6699-cj45 GHSA-x8x2-935g-9qf2 --- .../GHSA-7x4w-fjp3-6fmr.json | 50 +++++++++++++++++++ .../GHSA-897p-94fw-f6m3.json | 43 ++++++++++++++++ .../GHSA-9r4p-g7c7-2c4r.json | 42 ++++++++++++++++ .../GHSA-f835-w392-m6qf.json | 35 +++++++++++++ .../GHSA-hxp2-c3hq-rcq5.json | 38 ++++++++++++++ .../GHSA-mgrf-rx3w-m492.json | 42 ++++++++++++++++ .../GHSA-mxpc-px8m-2fqc.json | 42 ++++++++++++++++ .../GHSA-qcr5-ffr5-4rgc.json | 46 +++++++++++++++++ .../GHSA-qm69-cr5h-7x64.json | 47 +++++++++++++++++ .../GHSA-r6p6-7q5h-jc4x.json | 42 ++++++++++++++++ .../GHSA-rqhf-rjxm-7vcq.json | 50 +++++++++++++++++++ .../GHSA-vw34-wv53-96pw.json | 38 ++++++++++++++ .../GHSA-wx68-6699-cj45.json | 50 +++++++++++++++++++ .../GHSA-x8x2-935g-9qf2.json | 38 ++++++++++++++ 14 files changed, 603 insertions(+) create mode 100644 advisories/unreviewed/2024/05/GHSA-7x4w-fjp3-6fmr/GHSA-7x4w-fjp3-6fmr.json create mode 100644 advisories/unreviewed/2024/05/GHSA-897p-94fw-f6m3/GHSA-897p-94fw-f6m3.json create mode 100644 advisories/unreviewed/2024/05/GHSA-9r4p-g7c7-2c4r/GHSA-9r4p-g7c7-2c4r.json create mode 100644 advisories/unreviewed/2024/05/GHSA-f835-w392-m6qf/GHSA-f835-w392-m6qf.json create mode 100644 advisories/unreviewed/2024/05/GHSA-hxp2-c3hq-rcq5/GHSA-hxp2-c3hq-rcq5.json create mode 100644 advisories/unreviewed/2024/05/GHSA-mgrf-rx3w-m492/GHSA-mgrf-rx3w-m492.json create mode 100644 advisories/unreviewed/2024/05/GHSA-mxpc-px8m-2fqc/GHSA-mxpc-px8m-2fqc.json create mode 100644 advisories/unreviewed/2024/05/GHSA-qcr5-ffr5-4rgc/GHSA-qcr5-ffr5-4rgc.json create mode 100644 advisories/unreviewed/2024/05/GHSA-qm69-cr5h-7x64/GHSA-qm69-cr5h-7x64.json create mode 100644 advisories/unreviewed/2024/05/GHSA-r6p6-7q5h-jc4x/GHSA-r6p6-7q5h-jc4x.json create mode 100644 advisories/unreviewed/2024/05/GHSA-rqhf-rjxm-7vcq/GHSA-rqhf-rjxm-7vcq.json create mode 100644 advisories/unreviewed/2024/05/GHSA-vw34-wv53-96pw/GHSA-vw34-wv53-96pw.json create mode 100644 advisories/unreviewed/2024/05/GHSA-wx68-6699-cj45/GHSA-wx68-6699-cj45.json create mode 100644 advisories/unreviewed/2024/05/GHSA-x8x2-935g-9qf2/GHSA-x8x2-935g-9qf2.json diff --git a/advisories/unreviewed/2024/05/GHSA-7x4w-fjp3-6fmr/GHSA-7x4w-fjp3-6fmr.json b/advisories/unreviewed/2024/05/GHSA-7x4w-fjp3-6fmr/GHSA-7x4w-fjp3-6fmr.json new file mode 100644 index 00000000000..071eae1fa61 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-7x4w-fjp3-6fmr/GHSA-7x4w-fjp3-6fmr.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7x4w-fjp3-6fmr", + "modified": "2024-05-23T09:30:28Z", + "published": "2024-05-23T09:30:28Z", + "aliases": [ + "CVE-2024-4043" + ], + "details": "The WP Ultimate Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpupg-text' shortcode in all versions up to, and including, 3.9.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4043" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-ultimate-post-grid/trunk/includes/public/shortcodes/general/class-wpupg-sc-text.php#L97" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3086319" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/wp-ultimate-post-grid/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/14e897f0-11e6-43b1-908c-be4ecdc7fd58?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-23T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-897p-94fw-f6m3/GHSA-897p-94fw-f6m3.json b/advisories/unreviewed/2024/05/GHSA-897p-94fw-f6m3/GHSA-897p-94fw-f6m3.json new file mode 100644 index 00000000000..0ad3ead45e2 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-897p-94fw-f6m3/GHSA-897p-94fw-f6m3.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-897p-94fw-f6m3", + "modified": "2024-05-23T09:30:28Z", + "published": "2024-05-23T09:30:28Z", + "aliases": [ + "CVE-2024-36011" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: HCI: Fix potential null-ptr-deref\n\nFix potential null-ptr-deref in hci_le_big_sync_established_evt().", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36011" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1f7ebb69c1d65732bcac2fda9d15421f76f01e81" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9f3be61f55d4eedc20eedc56c0f04a5ce2b4a55a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d2706004a1b8b526592e823d7e52551b518a7941" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-23T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-9r4p-g7c7-2c4r/GHSA-9r4p-g7c7-2c4r.json b/advisories/unreviewed/2024/05/GHSA-9r4p-g7c7-2c4r/GHSA-9r4p-g7c7-2c4r.json new file mode 100644 index 00000000000..e1555f0227a --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-9r4p-g7c7-2c4r/GHSA-9r4p-g7c7-2c4r.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9r4p-g7c7-2c4r", + "modified": "2024-05-23T09:30:28Z", + "published": "2024-05-23T09:30:28Z", + "aliases": [ + "CVE-2024-4835" + ], + "details": "A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this condition, an attacker can craft a malicious page to exfiltrate sensitive user information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4835" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2497024" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/461328" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-23T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-f835-w392-m6qf/GHSA-f835-w392-m6qf.json b/advisories/unreviewed/2024/05/GHSA-f835-w392-m6qf/GHSA-f835-w392-m6qf.json new file mode 100644 index 00000000000..609a33e9bdd --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-f835-w392-m6qf/GHSA-f835-w392-m6qf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f835-w392-m6qf", + "modified": "2024-05-23T09:30:28Z", + "published": "2024-05-23T09:30:28Z", + "aliases": [ + "CVE-2024-36013" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect()\n\nExtend a critical section to prevent chan from early freeing.\nAlso make the l2cap_connect() return type void. Nothing is using the\nreturned value but it is ugly to return a potentially freed pointer.\nMaking it void will help with backports because earlier kernels did use\nthe return value. Now the compile will break for kernels where this\npatch is not a complete fix.\n\nCall stack summary:\n\n[use]\nl2cap_bredr_sig_cmd\n l2cap_connect\n ┌ mutex_lock(&conn->chan_lock);\n │ chan = pchan->ops->new_connection(pchan); <- alloc chan\n │ __l2cap_chan_add(conn, chan);\n │ l2cap_chan_hold(chan);\n │ list_add(&chan->list, &conn->chan_l); ... (1)\n └ mutex_unlock(&conn->chan_lock);\n chan->conf_state ... (4) <- use after free\n\n[free]\nl2cap_conn_del\n┌ mutex_lock(&conn->chan_lock);\n│ foreach chan in conn->chan_l: ... (2)\n│ l2cap_chan_put(chan);\n│ l2cap_chan_destroy\n│ kfree(chan) ... (3) <- chan freed\n└ mutex_unlock(&conn->chan_lock);\n\n==================================================================\nBUG: KASAN: slab-use-after-free in instrument_atomic_read\ninclude/linux/instrumented.h:68 [inline]\nBUG: KASAN: slab-use-after-free in _test_bit\ninclude/asm-generic/bitops/instrumented-non-atomic.h:141 [inline]\nBUG: KASAN: slab-use-after-free in l2cap_connect+0xa67/0x11a0\nnet/bluetooth/l2cap_core.c:4260\nRead of size 8 at addr ffff88810bf040a0 by task kworker/u3:1/311", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36013" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4d7b41c0e43995b0e992b9f8903109275744b658" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-23T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-hxp2-c3hq-rcq5/GHSA-hxp2-c3hq-rcq5.json b/advisories/unreviewed/2024/05/GHSA-hxp2-c3hq-rcq5/GHSA-hxp2-c3hq-rcq5.json new file mode 100644 index 00000000000..ae8762582a2 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-hxp2-c3hq-rcq5/GHSA-hxp2-c3hq-rcq5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxp2-c3hq-rcq5", + "modified": "2024-05-23T09:30:29Z", + "published": "2024-05-23T09:30:29Z", + "aliases": [ + "CVE-2024-5264" + ], + "details": "Network Transfer with AES KHT in Thales Luna EFT 2.1 and above allows a user with administrative console access to access backups taken via offline analysis", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5264" + }, + { + "type": "WEB", + "url": "https://supportportal.thalesgroup.com/csm?id=kb_article_view&sys_kb_id=50da3cd9c302c218204e2a6ce00131b9&sysparm_article=KB0028531" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-338" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-23T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-mgrf-rx3w-m492/GHSA-mgrf-rx3w-m492.json b/advisories/unreviewed/2024/05/GHSA-mgrf-rx3w-m492/GHSA-mgrf-rx3w-m492.json new file mode 100644 index 00000000000..4e6ee302226 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-mgrf-rx3w-m492/GHSA-mgrf-rx3w-m492.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgrf-rx3w-m492", + "modified": "2024-05-23T09:30:28Z", + "published": "2024-05-23T09:30:28Z", + "aliases": [ + "CVE-2024-4706" + ], + "details": "The WordPress + Microsoft Office 365 / Azure AD | LOGIN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pintra' shortcode in all versions up to, and including, 27.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4706" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3090428/wpo365-login" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/602a8030-087b-459f-b649-b4116404cf3e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-23T08:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-mxpc-px8m-2fqc/GHSA-mxpc-px8m-2fqc.json b/advisories/unreviewed/2024/05/GHSA-mxpc-px8m-2fqc/GHSA-mxpc-px8m-2fqc.json new file mode 100644 index 00000000000..a39bff78491 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-mxpc-px8m-2fqc/GHSA-mxpc-px8m-2fqc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxpc-px8m-2fqc", + "modified": "2024-05-23T09:30:28Z", + "published": "2024-05-23T09:30:28Z", + "aliases": [ + "CVE-2024-3648" + ], + "details": "The ShareThis Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sharethis-inline-button' shortcode in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3648" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3089529/sharethis-share-buttons" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/03b37c90-4bb5-4003-a440-3fb57a5c1cae?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-23T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-qcr5-ffr5-4rgc/GHSA-qcr5-ffr5-4rgc.json b/advisories/unreviewed/2024/05/GHSA-qcr5-ffr5-4rgc/GHSA-qcr5-ffr5-4rgc.json new file mode 100644 index 00000000000..a420e987b55 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-qcr5-ffr5-4rgc/GHSA-qcr5-ffr5-4rgc.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcr5-ffr5-4rgc", + "modified": "2024-05-23T09:30:28Z", + "published": "2024-05-23T09:30:28Z", + "aliases": [ + "CVE-2024-2038" + ], + "details": "The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.22.6. This is due to the use of hardcoded credentials to authenticate all the incoming API requests. This makes it possible for unauthenticated attackers to modify plugin settings, delete posts, modify post titles, and upload images.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2038" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/atarim-visual-collaboration/tags/3.18/inc/wpf_api.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?old=3076514&old_path=atarim-visual-collaboration%2Ftrunk%2Fatarim-visual-collaboration.php&new=3090249&new_path=atarim-visual-collaboration%2Ftrunk%2Fatarim-visual-collaboration.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/29532f4d-e830-4c99-ad77-076eebbbe98d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-23T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-qm69-cr5h-7x64/GHSA-qm69-cr5h-7x64.json b/advisories/unreviewed/2024/05/GHSA-qm69-cr5h-7x64/GHSA-qm69-cr5h-7x64.json new file mode 100644 index 00000000000..6f22a30d8a3 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-qm69-cr5h-7x64/GHSA-qm69-cr5h-7x64.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qm69-cr5h-7x64", + "modified": "2024-05-23T09:30:28Z", + "published": "2024-05-23T09:30:28Z", + "aliases": [ + "CVE-2024-36012" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: msft: fix slab-use-after-free in msft_do_close()\n\nTying the msft->data lifetime to hdev by freeing it in\nhci_release_dev() to fix the following case:\n\n[use]\nmsft_do_close()\n msft = hdev->msft_data;\n if (!msft) ...(1) <- passed.\n return;\n mutex_lock(&msft->filter_lock); ...(4) <- used after freed.\n\n[free]\nmsft_unregister()\n msft = hdev->msft_data;\n hdev->msft_data = NULL; ...(2)\n kfree(msft); ...(3) <- msft is freed.\n\n==================================================================\nBUG: KASAN: slab-use-after-free in __mutex_lock_common\nkernel/locking/mutex.c:587 [inline]\nBUG: KASAN: slab-use-after-free in __mutex_lock+0x8f/0xc30\nkernel/locking/mutex.c:752\nRead of size 8 at addr ffff888106cbbca8 by task kworker/u5:2/309", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36012" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/10f9f426ac6e752c8d87bf4346930ba347aaabac" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4f1de02de07748da80a8178879bc7a1df37fdf56" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a85a60e62355e3bf4802dead7938966824b23940" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e3880b531b68f98d3941d83f2f6dd11cf4fd6b76" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-23T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-r6p6-7q5h-jc4x/GHSA-r6p6-7q5h-jc4x.json b/advisories/unreviewed/2024/05/GHSA-r6p6-7q5h-jc4x/GHSA-r6p6-7q5h-jc4x.json new file mode 100644 index 00000000000..3920ab32e9e --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-r6p6-7q5h-jc4x/GHSA-r6p6-7q5h-jc4x.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6p6-7q5h-jc4x", + "modified": "2024-05-23T09:30:28Z", + "published": "2024-05-23T09:30:28Z", + "aliases": [ + "CVE-2024-2874" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions before 16.10.6, version 16.11 before 16.11.3, and 17.0 before 17.0.1. A runner registered with a crafted description has the potential to disrupt the loading of targeted GitLab web resources.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2874" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2426166" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/451911" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-23T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-rqhf-rjxm-7vcq/GHSA-rqhf-rjxm-7vcq.json b/advisories/unreviewed/2024/05/GHSA-rqhf-rjxm-7vcq/GHSA-rqhf-rjxm-7vcq.json new file mode 100644 index 00000000000..db75ac61715 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-rqhf-rjxm-7vcq/GHSA-rqhf-rjxm-7vcq.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqhf-rjxm-7vcq", + "modified": "2024-05-23T09:30:28Z", + "published": "2024-05-23T09:30:28Z", + "aliases": [ + "CVE-2024-5240" + ], + "details": "A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /view/unread_msg.php. The manipulation of the argument my_index leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-265991.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5240" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20sql/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2030.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.265991" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.265991" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.339816" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-23T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-vw34-wv53-96pw/GHSA-vw34-wv53-96pw.json b/advisories/unreviewed/2024/05/GHSA-vw34-wv53-96pw/GHSA-vw34-wv53-96pw.json new file mode 100644 index 00000000000..27d298ea6f7 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-vw34-wv53-96pw/GHSA-vw34-wv53-96pw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vw34-wv53-96pw", + "modified": "2024-05-23T09:30:28Z", + "published": "2024-05-23T09:30:28Z", + "aliases": [ + "CVE-2024-30279" + ], + "details": "Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30279" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-23T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-wx68-6699-cj45/GHSA-wx68-6699-cj45.json b/advisories/unreviewed/2024/05/GHSA-wx68-6699-cj45/GHSA-wx68-6699-cj45.json new file mode 100644 index 00000000000..77504e0945c --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-wx68-6699-cj45/GHSA-wx68-6699-cj45.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wx68-6699-cj45", + "modified": "2024-05-23T09:30:28Z", + "published": "2024-05-23T09:30:28Z", + "aliases": [ + "CVE-2024-5241" + ], + "details": "A vulnerability was found in Huashi Private Cloud CDN Live Streaming Acceleration Server up to 20240520. It has been classified as critical. Affected is an unknown function of the file /manager/ipconfig_new.php. The manipulation of the argument dev leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-265992.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5241" + }, + { + "type": "WEB", + "url": "https://github.com/h0e4a0r1t/h0e4a0r1t.github.io/blob/master/2024/8I~%2CbRx%5E4%26%3Fu%7D2tS/Huashi_Private_Cloud_CDN_Live_Streaming_Acceleration_Server_RCE_Vulnerability-ipconfig_new.php.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.265992" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.265992" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.339491" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-23T07:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-x8x2-935g-9qf2/GHSA-x8x2-935g-9qf2.json b/advisories/unreviewed/2024/05/GHSA-x8x2-935g-9qf2/GHSA-x8x2-935g-9qf2.json new file mode 100644 index 00000000000..df9d5da2cbe --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-x8x2-935g-9qf2/GHSA-x8x2-935g-9qf2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x8x2-935g-9qf2", + "modified": "2024-05-23T09:30:28Z", + "published": "2024-05-23T09:30:28Z", + "aliases": [ + "CVE-2024-30280" + ], + "details": "Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30280" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-23T09:15:09Z" + } +} \ No newline at end of file