From 3837ee2e3de4ba03efd88e504e6b76c1cc9329eb Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 17 Oct 2024 06:31:36 +0000 Subject: [PATCH] Publish Advisories GHSA-3wg5-x88w-52fj GHSA-4hc6-gpqp-6hfp GHSA-53mg-f6w7-m2qc GHSA-9f2c-45xq-c486 GHSA-9pxc-g2q3-vqwv GHSA-mh59-w44g-9pjr GHSA-q285-mcqv-8j69 GHSA-q4c5-pfxq-m759 GHSA-qc3g-q2wx-9mq2 GHSA-r7wf-fpff-w68q GHSA-v4cx-r43j-pwh7 GHSA-w47r-whp2-pxw8 --- .../GHSA-3wg5-x88w-52fj.json | 6 ++- .../GHSA-4hc6-gpqp-6hfp.json | 50 +++++++++++++++++++ .../GHSA-53mg-f6w7-m2qc.json | 46 +++++++++++++++++ .../GHSA-9f2c-45xq-c486.json | 6 ++- .../GHSA-9pxc-g2q3-vqwv.json | 42 ++++++++++++++++ .../GHSA-mh59-w44g-9pjr.json | 46 +++++++++++++++++ .../GHSA-q285-mcqv-8j69.json | 47 +++++++++++++++++ .../GHSA-q4c5-pfxq-m759.json | 46 +++++++++++++++++ .../GHSA-qc3g-q2wx-9mq2.json | 46 +++++++++++++++++ .../GHSA-r7wf-fpff-w68q.json | 6 ++- .../GHSA-v4cx-r43j-pwh7.json | 35 +++++++++++++ .../GHSA-w47r-whp2-pxw8.json | 6 ++- 12 files changed, 378 insertions(+), 4 deletions(-) create mode 100644 advisories/unreviewed/2024/10/GHSA-4hc6-gpqp-6hfp/GHSA-4hc6-gpqp-6hfp.json create mode 100644 advisories/unreviewed/2024/10/GHSA-53mg-f6w7-m2qc/GHSA-53mg-f6w7-m2qc.json create mode 100644 advisories/unreviewed/2024/10/GHSA-9pxc-g2q3-vqwv/GHSA-9pxc-g2q3-vqwv.json create mode 100644 advisories/unreviewed/2024/10/GHSA-mh59-w44g-9pjr/GHSA-mh59-w44g-9pjr.json create mode 100644 advisories/unreviewed/2024/10/GHSA-q285-mcqv-8j69/GHSA-q285-mcqv-8j69.json create mode 100644 advisories/unreviewed/2024/10/GHSA-q4c5-pfxq-m759/GHSA-q4c5-pfxq-m759.json create mode 100644 advisories/unreviewed/2024/10/GHSA-qc3g-q2wx-9mq2/GHSA-qc3g-q2wx-9mq2.json create mode 100644 advisories/unreviewed/2024/10/GHSA-v4cx-r43j-pwh7/GHSA-v4cx-r43j-pwh7.json diff --git a/advisories/unreviewed/2024/10/GHSA-3wg5-x88w-52fj/GHSA-3wg5-x88w-52fj.json b/advisories/unreviewed/2024/10/GHSA-3wg5-x88w-52fj/GHSA-3wg5-x88w-52fj.json index 5bdd2c8b295..0b4952ad606 100644 --- a/advisories/unreviewed/2024/10/GHSA-3wg5-x88w-52fj/GHSA-3wg5-x88w-52fj.json +++ b/advisories/unreviewed/2024/10/GHSA-3wg5-x88w-52fj/GHSA-3wg5-x88w-52fj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3wg5-x88w-52fj", - "modified": "2024-10-15T15:30:45Z", + "modified": "2024-10-17T06:30:32Z", "published": "2024-10-09T18:31:43Z", "aliases": [ "CVE-2024-9466" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://security.paloaltonetworks.com/PAN-SA-2024-0010" + }, + { + "type": "WEB", + "url": "https://www.horizon3.ai/attack-research/palo-alto-expedition-from-n-day-to-full-compromise" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-4hc6-gpqp-6hfp/GHSA-4hc6-gpqp-6hfp.json b/advisories/unreviewed/2024/10/GHSA-4hc6-gpqp-6hfp/GHSA-4hc6-gpqp-6hfp.json new file mode 100644 index 00000000000..fccf7fc0323 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-4hc6-gpqp-6hfp/GHSA-4hc6-gpqp-6hfp.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hc6-gpqp-6hfp", + "modified": "2024-10-17T06:30:32Z", + "published": "2024-10-17T06:30:32Z", + "aliases": [ + "CVE-2024-9263" + ], + "details": "The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to Account Takeover/Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 1.0.25 via the save() due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to reset the emails and passwords of arbitrary user accounts, including administrators, which makes account takeover and privilege escalation possible.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9263" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/timetics/tags/1.0.25/core/customers/customer.php#L299" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3169771/timetics/trunk/core/customers/api-customer.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3169771/timetics/trunk/core/customers/customer.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/74bd595b-d2fa-4c62-82d2-dba2c2b128f0?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T04:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-53mg-f6w7-m2qc/GHSA-53mg-f6w7-m2qc.json b/advisories/unreviewed/2024/10/GHSA-53mg-f6w7-m2qc/GHSA-53mg-f6w7-m2qc.json new file mode 100644 index 00000000000..8509a129a7c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-53mg-f6w7-m2qc/GHSA-53mg-f6w7-m2qc.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53mg-f6w7-m2qc", + "modified": "2024-10-17T06:30:32Z", + "published": "2024-10-17T06:30:32Z", + "aliases": [ + "CVE-2024-9347" + ], + "details": "The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpext-export' parameter in all versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9347" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wpextended/tags/3.0.9/includes/libraries/wpext_export/wpext_export.php#L209" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3169963/wpextended/trunk/includes/libraries/wpext_export/wpext_export.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/822c0a33-e57e-48c7-b8df-fddf3bb2e552?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T04:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9f2c-45xq-c486/GHSA-9f2c-45xq-c486.json b/advisories/unreviewed/2024/10/GHSA-9f2c-45xq-c486/GHSA-9f2c-45xq-c486.json index df21666195d..b626b09d5ed 100644 --- a/advisories/unreviewed/2024/10/GHSA-9f2c-45xq-c486/GHSA-9f2c-45xq-c486.json +++ b/advisories/unreviewed/2024/10/GHSA-9f2c-45xq-c486/GHSA-9f2c-45xq-c486.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9f2c-45xq-c486", - "modified": "2024-10-15T15:30:45Z", + "modified": "2024-10-17T06:30:32Z", "published": "2024-10-09T18:31:43Z", "aliases": [ "CVE-2024-9465" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://security.paloaltonetworks.com/PAN-SA-2024-0010" + }, + { + "type": "WEB", + "url": "https://www.horizon3.ai/attack-research/palo-alto-expedition-from-n-day-to-full-compromise" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-9pxc-g2q3-vqwv/GHSA-9pxc-g2q3-vqwv.json b/advisories/unreviewed/2024/10/GHSA-9pxc-g2q3-vqwv/GHSA-9pxc-g2q3-vqwv.json new file mode 100644 index 00000000000..64cef6640c9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9pxc-g2q3-vqwv/GHSA-9pxc-g2q3-vqwv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9pxc-g2q3-vqwv", + "modified": "2024-10-17T06:30:32Z", + "published": "2024-10-17T06:30:32Z", + "aliases": [ + "CVE-2024-8719" + ], + "details": "The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters like 'MaxBeds' and 'MinBeds' in all versions up to, and including, 3.14.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8719" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3169439%40flexmls-idx&new=3169439%40flexmls-idx&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/aac3fb8e-9b92-4ed1-ac9f-50870d4c5c9f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T04:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mh59-w44g-9pjr/GHSA-mh59-w44g-9pjr.json b/advisories/unreviewed/2024/10/GHSA-mh59-w44g-9pjr/GHSA-mh59-w44g-9pjr.json new file mode 100644 index 00000000000..19d43d91d78 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mh59-w44g-9pjr/GHSA-mh59-w44g-9pjr.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mh59-w44g-9pjr", + "modified": "2024-10-17T06:30:32Z", + "published": "2024-10-17T06:30:32Z", + "aliases": [ + "CVE-2024-7417" + ], + "details": "The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.3.986 via the data_fetch. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract data from password protected posts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7417" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/royal-elementor-addons/tags/1.3.985/classes/modules/wpr-ajax-search.php#L21" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3162784/royal-elementor-addons/tags/1.3.987/classes/modules/wpr-ajax-search.php?old=3141814&old_path=royal-elementor-addons%2Ftags%2F1.3.985%2Fclasses%2Fmodules%2Fwpr-ajax-search.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c3dfb0b7-5d9f-492b-9a1a-d4445d39c00c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T04:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-q285-mcqv-8j69/GHSA-q285-mcqv-8j69.json b/advisories/unreviewed/2024/10/GHSA-q285-mcqv-8j69/GHSA-q285-mcqv-8j69.json new file mode 100644 index 00000000000..2e8b223bdfd --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-q285-mcqv-8j69/GHSA-q285-mcqv-8j69.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q285-mcqv-8j69", + "modified": "2024-10-17T06:30:32Z", + "published": "2024-10-17T06:30:32Z", + "aliases": [ + "CVE-2024-49593" + ], + "details": "In Advanced Custom Fields (ACF) before 6.3.9 and Secure Custom Fields before 6.3.6.3 (plugins for WordPress), using the Field Group editor to edit one of the plugin's fields can result in execution of a stored XSS payload. NOTE: if you wish to use the WP Engine alternative update mechanism for the free version of ACF, then you can follow the process shown at the advancedcustomfields.com blog URL within the References section below.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49593" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/advanced-custom-fields/#developers" + }, + { + "type": "WEB", + "url": "https://www.advancedcustomfields.com/blog/installing-and-upgrading-to-the-latest-version-of-acf" + }, + { + "type": "WEB", + "url": "https://www.advancedcustomfields.com/changelog" + }, + { + "type": "WEB", + "url": "https://x.com/wp_acf/status/1845190372764401908" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T04:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-q4c5-pfxq-m759/GHSA-q4c5-pfxq-m759.json b/advisories/unreviewed/2024/10/GHSA-q4c5-pfxq-m759/GHSA-q4c5-pfxq-m759.json new file mode 100644 index 00000000000..9acae83228b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-q4c5-pfxq-m759/GHSA-q4c5-pfxq-m759.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4c5-pfxq-m759", + "modified": "2024-10-17T06:30:32Z", + "published": "2024-10-17T06:30:32Z", + "aliases": [ + "CVE-2024-9352" + ], + "details": "The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.35.1. This is due to missing or incorrect nonce validation on the custom form 'create_module' function. This makes it possible for unauthenticated attackers to create draft forms via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9352" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/forminator/tags/1.35.0/library/modules/custom-forms/admin/admin-loader.php#L418" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3169243" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/81e6e266-078a-4f4f-a335-c9d388f41ef2?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T06:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qc3g-q2wx-9mq2/GHSA-qc3g-q2wx-9mq2.json b/advisories/unreviewed/2024/10/GHSA-qc3g-q2wx-9mq2/GHSA-qc3g-q2wx-9mq2.json new file mode 100644 index 00000000000..9be478d3784 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qc3g-q2wx-9mq2/GHSA-qc3g-q2wx-9mq2.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qc3g-q2wx-9mq2", + "modified": "2024-10-17T06:30:32Z", + "published": "2024-10-17T06:30:32Z", + "aliases": [ + "CVE-2024-9351" + ], + "details": "The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.35.1. This is due to missing or incorrect nonce validation on the quiz 'create_module' function. This makes it possible for unauthenticated attackers to create draft quizzes via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9351" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/forminator/tags/1.35.0/library/modules/quizzes/admin/admin-loader.php#L719" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3169243" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8d89e3b7-d980-42bb-ab0c-d86ab174a69c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T06:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-r7wf-fpff-w68q/GHSA-r7wf-fpff-w68q.json b/advisories/unreviewed/2024/10/GHSA-r7wf-fpff-w68q/GHSA-r7wf-fpff-w68q.json index 1b46f1df21b..8e1dffeca8b 100644 --- a/advisories/unreviewed/2024/10/GHSA-r7wf-fpff-w68q/GHSA-r7wf-fpff-w68q.json +++ b/advisories/unreviewed/2024/10/GHSA-r7wf-fpff-w68q/GHSA-r7wf-fpff-w68q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r7wf-fpff-w68q", - "modified": "2024-10-15T15:30:45Z", + "modified": "2024-10-17T06:30:32Z", "published": "2024-10-09T18:31:43Z", "aliases": [ "CVE-2024-9464" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://security.paloaltonetworks.com/PAN-SA-2024-0010" + }, + { + "type": "WEB", + "url": "https://www.horizon3.ai/attack-research/palo-alto-expedition-from-n-day-to-full-compromise" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-v4cx-r43j-pwh7/GHSA-v4cx-r43j-pwh7.json b/advisories/unreviewed/2024/10/GHSA-v4cx-r43j-pwh7/GHSA-v4cx-r43j-pwh7.json new file mode 100644 index 00000000000..8b1ae4cb71e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-v4cx-r43j-pwh7/GHSA-v4cx-r43j-pwh7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4cx-r43j-pwh7", + "modified": "2024-10-17T06:30:32Z", + "published": "2024-10-17T06:30:32Z", + "aliases": [ + "CVE-2024-5429" + ], + "details": "The Logo Slider WordPress plugin before 4.1.0 does not validate and escape some of its Slider Settings before outputting them back in attributes, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5429" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/ddb76c88-aeca-42df-830e-abffd29f1141" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T06:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w47r-whp2-pxw8/GHSA-w47r-whp2-pxw8.json b/advisories/unreviewed/2024/10/GHSA-w47r-whp2-pxw8/GHSA-w47r-whp2-pxw8.json index 42e7f7b23e7..f05539fc745 100644 --- a/advisories/unreviewed/2024/10/GHSA-w47r-whp2-pxw8/GHSA-w47r-whp2-pxw8.json +++ b/advisories/unreviewed/2024/10/GHSA-w47r-whp2-pxw8/GHSA-w47r-whp2-pxw8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w47r-whp2-pxw8", - "modified": "2024-10-15T21:30:36Z", + "modified": "2024-10-17T06:30:32Z", "published": "2024-10-09T18:31:44Z", "aliases": [ "CVE-2024-9473" @@ -25,6 +25,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9473" }, + { + "type": "WEB", + "url": "https://sec-consult.com/vulnerability-lab/advisory/local-privilege-escalation-via-msi-installer-in-palo-alto-networks-globalprotect" + }, { "type": "WEB", "url": "https://security.paloaltonetworks.com/CVE-2024-9473"