From 39966360141f077630389a293c4e6cb4556629b1 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 8 Jul 2024 12:32:38 +0000 Subject: [PATCH] Publish Advisories GHSA-pqjh-mmh7-2g8c GHSA-54v8-3w5h-ggf6 GHSA-63q4-8wcf-wg8f GHSA-8v44-2x42-qwmw GHSA-f6v5-hjxr-p24j GHSA-mfqw-44wg-mrpf --- .../GHSA-pqjh-mmh7-2g8c.json | 11 ++++- .../GHSA-54v8-3w5h-ggf6.json | 2 +- .../GHSA-63q4-8wcf-wg8f.json | 43 +++++++++++++++++++ .../GHSA-8v44-2x42-qwmw.json | 42 ++++++++++++++++++ .../GHSA-f6v5-hjxr-p24j.json | 43 +++++++++++++++++++ .../GHSA-mfqw-44wg-mrpf.json | 43 +++++++++++++++++++ 6 files changed, 181 insertions(+), 3 deletions(-) create mode 100644 advisories/unreviewed/2024/07/GHSA-63q4-8wcf-wg8f/GHSA-63q4-8wcf-wg8f.json create mode 100644 advisories/unreviewed/2024/07/GHSA-8v44-2x42-qwmw/GHSA-8v44-2x42-qwmw.json create mode 100644 advisories/unreviewed/2024/07/GHSA-f6v5-hjxr-p24j/GHSA-f6v5-hjxr-p24j.json create mode 100644 advisories/unreviewed/2024/07/GHSA-mfqw-44wg-mrpf/GHSA-mfqw-44wg-mrpf.json diff --git a/advisories/unreviewed/2022/05/GHSA-pqjh-mmh7-2g8c/GHSA-pqjh-mmh7-2g8c.json b/advisories/unreviewed/2022/05/GHSA-pqjh-mmh7-2g8c/GHSA-pqjh-mmh7-2g8c.json index c202f6371ac..83d1aa265a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqjh-mmh7-2g8c/GHSA-pqjh-mmh7-2g8c.json +++ b/advisories/unreviewed/2022/05/GHSA-pqjh-mmh7-2g8c/GHSA-pqjh-mmh7-2g8c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pqjh-mmh7-2g8c", - "modified": "2022-05-24T17:32:22Z", + "modified": "2024-07-08T12:31:04Z", "published": "2022-05-24T17:32:22Z", "aliases": [ "CVE-2019-8761" ], "details": "This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, macOS Catalina 10.15. Parsing a maliciously crafted text file may lead to disclosure of user information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,6 +28,10 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT210722" + }, + { + "type": "WEB", + "url": "https://www.paulosyibelo.com/2021/04/this-man-thought-opening-txt-file-is.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/11/GHSA-54v8-3w5h-ggf6/GHSA-54v8-3w5h-ggf6.json b/advisories/unreviewed/2023/11/GHSA-54v8-3w5h-ggf6/GHSA-54v8-3w5h-ggf6.json index 2785c430e41..add1d0207fa 100644 --- a/advisories/unreviewed/2023/11/GHSA-54v8-3w5h-ggf6/GHSA-54v8-3w5h-ggf6.json +++ b/advisories/unreviewed/2023/11/GHSA-54v8-3w5h-ggf6/GHSA-54v8-3w5h-ggf6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-54v8-3w5h-ggf6", - "modified": "2023-11-16T18:30:30Z", + "modified": "2024-07-08T12:31:04Z", "published": "2023-11-13T00:30:17Z", "aliases": [ "CVE-2023-28696" diff --git a/advisories/unreviewed/2024/07/GHSA-63q4-8wcf-wg8f/GHSA-63q4-8wcf-wg8f.json b/advisories/unreviewed/2024/07/GHSA-63q4-8wcf-wg8f/GHSA-63q4-8wcf-wg8f.json new file mode 100644 index 00000000000..aae66677a79 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-63q4-8wcf-wg8f/GHSA-63q4-8wcf-wg8f.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63q4-8wcf-wg8f", + "modified": "2024-07-08T12:31:05Z", + "published": "2024-07-08T12:31:05Z", + "aliases": [ + "CVE-2024-27903" + ], + "details": "OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27903" + }, + { + "type": "WEB", + "url": "https://community.openvpn.net/openvpn/wiki/CVE-2024-27903" + }, + { + "type": "WEB", + "url": "https://openvpn.net/security-advisory/ovpnx-vulnerability-cve-2024-27903-cve-2024-27459-cve-2024-24974" + }, + { + "type": "WEB", + "url": "https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07534.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-283" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-08T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-8v44-2x42-qwmw/GHSA-8v44-2x42-qwmw.json b/advisories/unreviewed/2024/07/GHSA-8v44-2x42-qwmw/GHSA-8v44-2x42-qwmw.json new file mode 100644 index 00000000000..7fa75d1f7e7 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-8v44-2x42-qwmw/GHSA-8v44-2x42-qwmw.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8v44-2x42-qwmw", + "modified": "2024-07-08T12:31:06Z", + "published": "2024-07-08T12:31:06Z", + "aliases": [ + "CVE-2024-37999" + ], + "details": "A vulnerability has been identified in Medicalis Workflow Orchestrator (All versions). The affected application executes as a trusted account with high privileges and network access. This could allow an authenticated local attacker to escalate privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37999" + }, + { + "type": "WEB", + "url": "https://www.siemens-healthineers.com/en-us/support-documentation/cybersecurity/shsa-501799" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-282" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-08T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-f6v5-hjxr-p24j/GHSA-f6v5-hjxr-p24j.json b/advisories/unreviewed/2024/07/GHSA-f6v5-hjxr-p24j/GHSA-f6v5-hjxr-p24j.json new file mode 100644 index 00000000000..652bbe74101 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-f6v5-hjxr-p24j/GHSA-f6v5-hjxr-p24j.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6v5-hjxr-p24j", + "modified": "2024-07-08T12:31:05Z", + "published": "2024-07-08T12:31:05Z", + "aliases": [ + "CVE-2024-27459" + ], + "details": "The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27459" + }, + { + "type": "WEB", + "url": "https://community.openvpn.net/openvpn/wiki/CVE-2024-27459" + }, + { + "type": "WEB", + "url": "https://openvpn.net/security-advisory/ovpnx-vulnerability-cve-2024-27903-cve-2024-27459-cve-2024-24974" + }, + { + "type": "WEB", + "url": "https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07534.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-08T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-mfqw-44wg-mrpf/GHSA-mfqw-44wg-mrpf.json b/advisories/unreviewed/2024/07/GHSA-mfqw-44wg-mrpf/GHSA-mfqw-44wg-mrpf.json new file mode 100644 index 00000000000..f14de3329b2 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-mfqw-44wg-mrpf/GHSA-mfqw-44wg-mrpf.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mfqw-44wg-mrpf", + "modified": "2024-07-08T12:31:05Z", + "published": "2024-07-08T12:31:05Z", + "aliases": [ + "CVE-2024-24974" + ], + "details": "The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with the privileged OpenVPN interactive service.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24974" + }, + { + "type": "WEB", + "url": "https://community.openvpn.net/openvpn/wiki/CVE-2024-24974" + }, + { + "type": "WEB", + "url": "https://openvpn.net/security-advisory/ovpnx-vulnerability-cve-2024-27903-cve-2024-27459-cve-2024-24974" + }, + { + "type": "WEB", + "url": "https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07534.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-923" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-08T11:15:10Z" + } +} \ No newline at end of file