Publish Advisories

GHSA-v76w-3ph8-vm66
GHSA-5mxf-42f5-j782
GHSA-7fcr-8qw6-92fr
GHSA-m9gf-397r-hwpg
GHSA-mqm9-c95h-x2p6
GHSA-jrv4-gggm-r53c
GHSA-hwxf-wjq7-j3hm
GHSA-ffpf-5h29-w36w
GHSA-ch4x-f5c4-36gv
GHSA-q793-mj5v-wh68
GHSA-5x53-pqpp-vfwr
GHSA-6w35-x982-hj9h
GHSA-g7gv-3436-vxj2
GHSA-g9p5-q86f-758v
GHSA-hjhx-mr4r-6j6j
GHSA-m7v8-cfx4-v2vg
GHSA-px2p-9r77-w9cq
This commit is contained in:
advisory-database[bot]
2024-11-22 12:40:43 +00:00
parent 7521af336b
commit 3a5b4001c5
17 changed files with 247 additions and 13 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v76w-3ph8-vm66",
"modified": "2024-08-21T09:31:30Z",
"modified": "2024-11-22T12:39:07Z",
"published": "2024-02-12T21:30:55Z",
"aliases": [
"CVE-2024-1459"
@@ -106,6 +106,10 @@
{
"type": "WEB",
"url": "https://issues.redhat.com/browse/UNDERTOW-2339"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20241122-0008"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5mxf-42f5-j782",
"modified": "2024-07-08T20:32:56Z",
"modified": "2024-11-22T12:39:08Z",
"published": "2024-03-07T18:30:28Z",
"aliases": [
"CVE-2024-1442"
@@ -127,13 +127,17 @@
{
"type": "WEB",
"url": "https://grafana.com/security/security-advisories/cve-2024-1442"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20241122-0007"
}
],
"database_specific": {
"cwe_ids": [
"CWE-269"
],
"severity": "MODERATE",
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-03-07T19:11:52Z",
"nvd_published_at": "2024-03-07T18:15:46Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7fcr-8qw6-92fr",
"modified": "2024-07-30T21:26:08Z",
"modified": "2024-11-22T12:39:09Z",
"published": "2024-05-14T20:30:57Z",
"aliases": [
"CVE-2024-30045"
@@ -568,6 +568,10 @@
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30045"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20241122-0001"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m9gf-397r-hwpg",
"modified": "2024-09-09T20:19:45Z",
"modified": "2024-11-22T12:39:08Z",
"published": "2024-09-09T15:30:41Z",
"aliases": [
"CVE-2024-8372"
@@ -52,6 +52,10 @@
"type": "PACKAGE",
"url": "https://github.com/angular/angular.js"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20241122-0002"
},
{
"type": "WEB",
"url": "https://www.herodevs.com/vulnerability-directory/cve-2024-8372"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mqm9-c95h-x2p6",
"modified": "2024-09-09T20:19:49Z",
"modified": "2024-11-22T12:39:08Z",
"published": "2024-09-09T15:30:41Z",
"aliases": [
"CVE-2024-8373"
@@ -52,6 +52,10 @@
"type": "PACKAGE",
"url": "https://github.com/angular/angular.js"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20241122-0003"
},
{
"type": "WEB",
"url": "https://www.herodevs.com/vulnerability-directory/cve-2024-8373"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jrv4-gggm-r53c",
"modified": "2022-04-22T00:00:46Z",
"modified": "2024-11-22T12:39:07Z",
"published": "2022-04-15T00:00:36Z",
"aliases": [
"CVE-2022-1304"
@@ -36,6 +36,14 @@
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2069726"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/10/msg00001.html"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20241122-0010"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hwxf-wjq7-j3hm",
"modified": "2024-05-22T18:30:38Z",
"modified": "2024-11-22T12:39:07Z",
"published": "2023-12-23T15:30:17Z",
"aliases": [
"CVE-2023-7008"
@@ -52,6 +52,10 @@
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QHNBXGKJWISJETTTDTZKTBFIBJUOSLKL"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20241122-0004"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ffpf-5h29-w36w",
"modified": "2024-05-17T00:30:59Z",
"modified": "2024-11-22T12:39:08Z",
"published": "2024-03-21T06:33:05Z",
"aliases": [
"CVE-2024-28835"
@@ -45,6 +45,10 @@
"type": "WEB",
"url": "https://lists.gnupg.org/pipermail/gnutls-help/2024-March/004845.html"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20241122-0009"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/03/22/1"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ch4x-f5c4-36gv",
"modified": "2024-07-19T15:31:46Z",
"modified": "2024-11-22T12:39:08Z",
"published": "2024-07-09T03:31:44Z",
"aliases": [
"CVE-2024-22020"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://hackerone.com/reports/2092749"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20241122-0006"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/07/11/6"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q793-mj5v-wh68",
"modified": "2024-09-07T18:30:23Z",
"modified": "2024-11-22T12:39:08Z",
"published": "2024-09-07T18:30:23Z",
"aliases": [
"CVE-2024-36137"
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://nodejs.org/en/blog/vulnerability/july-2024-security-releases"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20241122-0005"
}
],
"database_specific": {
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5x53-pqpp-vfwr",
"modified": "2024-11-22T12:39:08Z",
"published": "2024-11-22T12:39:08Z",
"aliases": [
"CVE-2017-9711"
],
"details": "Certain unprivileged processes are able to perform IOCTL calls.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2017-9711"
},
{
"type": "WEB",
"url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2018-bulletin.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-22T10:15:03Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6w35-x982-hj9h",
"modified": "2024-11-08T15:31:12Z",
"modified": "2024-11-22T12:39:08Z",
"published": "2024-11-04T15:31:56Z",
"aliases": [
"CVE-2024-51556"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g7gv-3436-vxj2",
"modified": "2024-11-22T12:39:08Z",
"published": "2024-11-22T12:39:08Z",
"aliases": [
"CVE-2024-41781"
],
"details": "IBM PowerVM Platform KeyStore (IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1030.00 through FW1030.60, FW1050.00 through FW1050.20, and FW1060.00 through FW1060.10 functionality can be compromised if an attacker gains service access to the HMC. An attacker that gains service access to the HMC can locate and through a series of service procedures decrypt data contained in the Platform KeyStore.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41781"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7172698"
}
],
"database_specific": {
"cwe_ids": [
"CWE-497"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-22T12:15:19Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g9p5-q86f-758v",
"modified": "2024-11-22T12:39:08Z",
"published": "2024-11-22T12:39:08Z",
"aliases": [
"CVE-2021-30299"
],
"details": "Possible out of bound access in audio module due to lack of validation of user provided input.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-30299"
},
{
"type": "WEB",
"url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/march-2022-bulletin.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-20"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-22T10:15:04Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hjhx-mr4r-6j6j",
"modified": "2024-11-08T15:31:12Z",
"modified": "2024-11-22T12:39:08Z",
"published": "2024-11-04T15:31:57Z",
"aliases": [
"CVE-2024-51559"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m7v8-cfx4-v2vg",
"modified": "2024-11-22T12:39:08Z",
"published": "2024-11-22T12:39:08Z",
"aliases": [
"CVE-2024-41779"
],
"details": "IBM Engineering Systems Design Rhapsody - Model Manager 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending a specially crafted request, an attacker could exploit this vulnerability to remotely execute code.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41779"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7172535"
}
],
"database_specific": {
"cwe_ids": [
"CWE-367"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-22T12:15:18Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-px2p-9r77-w9cq",
"modified": "2024-11-22T12:39:09Z",
"published": "2024-11-22T12:39:09Z",
"aliases": [
"CVE-2024-51766"
],
"details": "A potential security vulnerability has been identified in the HPE NonStop DISK UTIL (T9208) product. This vulnerability could be exploited to cause a denial of service (DoS) to NonStop server. It exists in all prior DISK UTIL product versions of L-series and J-series.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51766"
},
{
"type": "WEB",
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbns04759en_us&docLocale=en_US"
}
],
"database_specific": {
"cwe_ids": [
"CWE-755"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-22T12:15:19Z"
}
}