mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-v76w-3ph8-vm66 GHSA-5mxf-42f5-j782 GHSA-7fcr-8qw6-92fr GHSA-m9gf-397r-hwpg GHSA-mqm9-c95h-x2p6 GHSA-jrv4-gggm-r53c GHSA-hwxf-wjq7-j3hm GHSA-ffpf-5h29-w36w GHSA-ch4x-f5c4-36gv GHSA-q793-mj5v-wh68 GHSA-5x53-pqpp-vfwr GHSA-6w35-x982-hj9h GHSA-g7gv-3436-vxj2 GHSA-g9p5-q86f-758v GHSA-hjhx-mr4r-6j6j GHSA-m7v8-cfx4-v2vg GHSA-px2p-9r77-w9cq
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-v76w-3ph8-vm66",
|
||||
"modified": "2024-08-21T09:31:30Z",
|
||||
"modified": "2024-11-22T12:39:07Z",
|
||||
"published": "2024-02-12T21:30:55Z",
|
||||
"aliases": [
|
||||
"CVE-2024-1459"
|
||||
@@ -106,6 +106,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://issues.redhat.com/browse/UNDERTOW-2339"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20241122-0008"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-5mxf-42f5-j782",
|
||||
"modified": "2024-07-08T20:32:56Z",
|
||||
"modified": "2024-11-22T12:39:08Z",
|
||||
"published": "2024-03-07T18:30:28Z",
|
||||
"aliases": [
|
||||
"CVE-2024-1442"
|
||||
@@ -127,13 +127,17 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://grafana.com/security/security-advisories/cve-2024-1442"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20241122-0007"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-269"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2024-03-07T19:11:52Z",
|
||||
"nvd_published_at": "2024-03-07T18:15:46Z"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-7fcr-8qw6-92fr",
|
||||
"modified": "2024-07-30T21:26:08Z",
|
||||
"modified": "2024-11-22T12:39:09Z",
|
||||
"published": "2024-05-14T20:30:57Z",
|
||||
"aliases": [
|
||||
"CVE-2024-30045"
|
||||
@@ -568,6 +568,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30045"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20241122-0001"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-m9gf-397r-hwpg",
|
||||
"modified": "2024-09-09T20:19:45Z",
|
||||
"modified": "2024-11-22T12:39:08Z",
|
||||
"published": "2024-09-09T15:30:41Z",
|
||||
"aliases": [
|
||||
"CVE-2024-8372"
|
||||
@@ -52,6 +52,10 @@
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/angular/angular.js"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20241122-0002"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.herodevs.com/vulnerability-directory/cve-2024-8372"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-mqm9-c95h-x2p6",
|
||||
"modified": "2024-09-09T20:19:49Z",
|
||||
"modified": "2024-11-22T12:39:08Z",
|
||||
"published": "2024-09-09T15:30:41Z",
|
||||
"aliases": [
|
||||
"CVE-2024-8373"
|
||||
@@ -52,6 +52,10 @@
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/angular/angular.js"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20241122-0003"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.herodevs.com/vulnerability-directory/cve-2024-8373"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-jrv4-gggm-r53c",
|
||||
"modified": "2022-04-22T00:00:46Z",
|
||||
"modified": "2024-11-22T12:39:07Z",
|
||||
"published": "2022-04-15T00:00:36Z",
|
||||
"aliases": [
|
||||
"CVE-2022-1304"
|
||||
@@ -36,6 +36,14 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2069726"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.debian.org/debian-lts-announce/2024/10/msg00001.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20241122-0010"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-hwxf-wjq7-j3hm",
|
||||
"modified": "2024-05-22T18:30:38Z",
|
||||
"modified": "2024-11-22T12:39:07Z",
|
||||
"published": "2023-12-23T15:30:17Z",
|
||||
"aliases": [
|
||||
"CVE-2023-7008"
|
||||
@@ -52,6 +52,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QHNBXGKJWISJETTTDTZKTBFIBJUOSLKL"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20241122-0004"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-ffpf-5h29-w36w",
|
||||
"modified": "2024-05-17T00:30:59Z",
|
||||
"modified": "2024-11-22T12:39:08Z",
|
||||
"published": "2024-03-21T06:33:05Z",
|
||||
"aliases": [
|
||||
"CVE-2024-28835"
|
||||
@@ -45,6 +45,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://lists.gnupg.org/pipermail/gnutls-help/2024-March/004845.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20241122-0009"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://www.openwall.com/lists/oss-security/2024/03/22/1"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-ch4x-f5c4-36gv",
|
||||
"modified": "2024-07-19T15:31:46Z",
|
||||
"modified": "2024-11-22T12:39:08Z",
|
||||
"published": "2024-07-09T03:31:44Z",
|
||||
"aliases": [
|
||||
"CVE-2024-22020"
|
||||
@@ -25,6 +25,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://hackerone.com/reports/2092749"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20241122-0006"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://www.openwall.com/lists/oss-security/2024/07/11/6"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-q793-mj5v-wh68",
|
||||
"modified": "2024-09-07T18:30:23Z",
|
||||
"modified": "2024-11-22T12:39:08Z",
|
||||
"published": "2024-09-07T18:30:23Z",
|
||||
"aliases": [
|
||||
"CVE-2024-36137"
|
||||
@@ -24,6 +24,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://nodejs.org/en/blog/vulnerability/july-2024-security-releases"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20241122-0005"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-5x53-pqpp-vfwr",
|
||||
"modified": "2024-11-22T12:39:08Z",
|
||||
"published": "2024-11-22T12:39:08Z",
|
||||
"aliases": [
|
||||
"CVE-2017-9711"
|
||||
],
|
||||
"details": "Certain unprivileged processes are able to perform IOCTL calls.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2017-9711"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2018-bulletin.html"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-11-22T10:15:03Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-6w35-x982-hj9h",
|
||||
"modified": "2024-11-08T15:31:12Z",
|
||||
"modified": "2024-11-22T12:39:08Z",
|
||||
"published": "2024-11-04T15:31:56Z",
|
||||
"aliases": [
|
||||
"CVE-2024-51556"
|
||||
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-g7gv-3436-vxj2",
|
||||
"modified": "2024-11-22T12:39:08Z",
|
||||
"published": "2024-11-22T12:39:08Z",
|
||||
"aliases": [
|
||||
"CVE-2024-41781"
|
||||
],
|
||||
"details": "IBM PowerVM Platform KeyStore (IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1030.00 through FW1030.60, FW1050.00 through FW1050.20, and FW1060.00 through FW1060.10 functionality can be compromised if an attacker gains service access to the HMC. An attacker that gains service access to the HMC can locate and through a series of service procedures decrypt data contained in the Platform KeyStore.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41781"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.ibm.com/support/pages/node/7172698"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-497"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-11-22T12:15:19Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-g9p5-q86f-758v",
|
||||
"modified": "2024-11-22T12:39:08Z",
|
||||
"published": "2024-11-22T12:39:08Z",
|
||||
"aliases": [
|
||||
"CVE-2021-30299"
|
||||
],
|
||||
"details": "Possible out of bound access in audio module due to lack of validation of user provided input.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-30299"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/march-2022-bulletin.html"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-20"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-11-22T10:15:04Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-hjhx-mr4r-6j6j",
|
||||
"modified": "2024-11-08T15:31:12Z",
|
||||
"modified": "2024-11-22T12:39:08Z",
|
||||
"published": "2024-11-04T15:31:57Z",
|
||||
"aliases": [
|
||||
"CVE-2024-51559"
|
||||
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-m7v8-cfx4-v2vg",
|
||||
"modified": "2024-11-22T12:39:08Z",
|
||||
"published": "2024-11-22T12:39:08Z",
|
||||
"aliases": [
|
||||
"CVE-2024-41779"
|
||||
],
|
||||
"details": "IBM Engineering Systems Design Rhapsody - Model Manager 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending a specially crafted request, an attacker could exploit this vulnerability to remotely execute code.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41779"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.ibm.com/support/pages/node/7172535"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-367"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-11-22T12:15:18Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-px2p-9r77-w9cq",
|
||||
"modified": "2024-11-22T12:39:09Z",
|
||||
"published": "2024-11-22T12:39:09Z",
|
||||
"aliases": [
|
||||
"CVE-2024-51766"
|
||||
],
|
||||
"details": "A potential security vulnerability has been identified in the HPE NonStop DISK UTIL (T9208) product. This vulnerability could be exploited to cause a denial of service (DoS) to NonStop server. It exists in all prior DISK UTIL product versions of L-series and J-series.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51766"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbns04759en_us&docLocale=en_US"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-755"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-11-22T12:15:19Z"
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user