diff --git a/advisories/github-reviewed/2024/02/GHSA-v76w-3ph8-vm66/GHSA-v76w-3ph8-vm66.json b/advisories/github-reviewed/2024/02/GHSA-v76w-3ph8-vm66/GHSA-v76w-3ph8-vm66.json index cca98310706..26d4837c993 100644 --- a/advisories/github-reviewed/2024/02/GHSA-v76w-3ph8-vm66/GHSA-v76w-3ph8-vm66.json +++ b/advisories/github-reviewed/2024/02/GHSA-v76w-3ph8-vm66/GHSA-v76w-3ph8-vm66.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v76w-3ph8-vm66", - "modified": "2024-08-21T09:31:30Z", + "modified": "2024-11-22T12:39:07Z", "published": "2024-02-12T21:30:55Z", "aliases": [ "CVE-2024-1459" @@ -106,6 +106,10 @@ { "type": "WEB", "url": "https://issues.redhat.com/browse/UNDERTOW-2339" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241122-0008" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/03/GHSA-5mxf-42f5-j782/GHSA-5mxf-42f5-j782.json b/advisories/github-reviewed/2024/03/GHSA-5mxf-42f5-j782/GHSA-5mxf-42f5-j782.json index 797ebcac363..e01b5b92d7b 100644 --- a/advisories/github-reviewed/2024/03/GHSA-5mxf-42f5-j782/GHSA-5mxf-42f5-j782.json +++ b/advisories/github-reviewed/2024/03/GHSA-5mxf-42f5-j782/GHSA-5mxf-42f5-j782.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5mxf-42f5-j782", - "modified": "2024-07-08T20:32:56Z", + "modified": "2024-11-22T12:39:08Z", "published": "2024-03-07T18:30:28Z", "aliases": [ "CVE-2024-1442" @@ -127,13 +127,17 @@ { "type": "WEB", "url": "https://grafana.com/security/security-advisories/cve-2024-1442" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241122-0007" } ], "database_specific": { "cwe_ids": [ "CWE-269" ], - "severity": "MODERATE", + "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-03-07T19:11:52Z", "nvd_published_at": "2024-03-07T18:15:46Z" diff --git a/advisories/github-reviewed/2024/05/GHSA-7fcr-8qw6-92fr/GHSA-7fcr-8qw6-92fr.json b/advisories/github-reviewed/2024/05/GHSA-7fcr-8qw6-92fr/GHSA-7fcr-8qw6-92fr.json index f0c4564698e..5058e752542 100644 --- a/advisories/github-reviewed/2024/05/GHSA-7fcr-8qw6-92fr/GHSA-7fcr-8qw6-92fr.json +++ b/advisories/github-reviewed/2024/05/GHSA-7fcr-8qw6-92fr/GHSA-7fcr-8qw6-92fr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7fcr-8qw6-92fr", - "modified": "2024-07-30T21:26:08Z", + "modified": "2024-11-22T12:39:09Z", "published": "2024-05-14T20:30:57Z", "aliases": [ "CVE-2024-30045" @@ -568,6 +568,10 @@ { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30045" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241122-0001" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/09/GHSA-m9gf-397r-hwpg/GHSA-m9gf-397r-hwpg.json b/advisories/github-reviewed/2024/09/GHSA-m9gf-397r-hwpg/GHSA-m9gf-397r-hwpg.json index 78fc856dca5..80a89c93d72 100644 --- a/advisories/github-reviewed/2024/09/GHSA-m9gf-397r-hwpg/GHSA-m9gf-397r-hwpg.json +++ b/advisories/github-reviewed/2024/09/GHSA-m9gf-397r-hwpg/GHSA-m9gf-397r-hwpg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m9gf-397r-hwpg", - "modified": "2024-09-09T20:19:45Z", + "modified": "2024-11-22T12:39:08Z", "published": "2024-09-09T15:30:41Z", "aliases": [ "CVE-2024-8372" @@ -52,6 +52,10 @@ "type": "PACKAGE", "url": "https://github.com/angular/angular.js" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241122-0002" + }, { "type": "WEB", "url": "https://www.herodevs.com/vulnerability-directory/cve-2024-8372" diff --git a/advisories/github-reviewed/2024/09/GHSA-mqm9-c95h-x2p6/GHSA-mqm9-c95h-x2p6.json b/advisories/github-reviewed/2024/09/GHSA-mqm9-c95h-x2p6/GHSA-mqm9-c95h-x2p6.json index 8600f5549f3..2cdfb197570 100644 --- a/advisories/github-reviewed/2024/09/GHSA-mqm9-c95h-x2p6/GHSA-mqm9-c95h-x2p6.json +++ b/advisories/github-reviewed/2024/09/GHSA-mqm9-c95h-x2p6/GHSA-mqm9-c95h-x2p6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mqm9-c95h-x2p6", - "modified": "2024-09-09T20:19:49Z", + "modified": "2024-11-22T12:39:08Z", "published": "2024-09-09T15:30:41Z", "aliases": [ "CVE-2024-8373" @@ -52,6 +52,10 @@ "type": "PACKAGE", "url": "https://github.com/angular/angular.js" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241122-0003" + }, { "type": "WEB", "url": "https://www.herodevs.com/vulnerability-directory/cve-2024-8373" diff --git a/advisories/unreviewed/2022/04/GHSA-jrv4-gggm-r53c/GHSA-jrv4-gggm-r53c.json b/advisories/unreviewed/2022/04/GHSA-jrv4-gggm-r53c/GHSA-jrv4-gggm-r53c.json index 6b09b3f0386..944772a4f93 100644 --- a/advisories/unreviewed/2022/04/GHSA-jrv4-gggm-r53c/GHSA-jrv4-gggm-r53c.json +++ b/advisories/unreviewed/2022/04/GHSA-jrv4-gggm-r53c/GHSA-jrv4-gggm-r53c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jrv4-gggm-r53c", - "modified": "2022-04-22T00:00:46Z", + "modified": "2024-11-22T12:39:07Z", "published": "2022-04-15T00:00:36Z", "aliases": [ "CVE-2022-1304" @@ -36,6 +36,14 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2069726" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/10/msg00001.html" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241122-0010" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/12/GHSA-hwxf-wjq7-j3hm/GHSA-hwxf-wjq7-j3hm.json b/advisories/unreviewed/2023/12/GHSA-hwxf-wjq7-j3hm/GHSA-hwxf-wjq7-j3hm.json index 49a7ac36477..b748475e29f 100644 --- a/advisories/unreviewed/2023/12/GHSA-hwxf-wjq7-j3hm/GHSA-hwxf-wjq7-j3hm.json +++ b/advisories/unreviewed/2023/12/GHSA-hwxf-wjq7-j3hm/GHSA-hwxf-wjq7-j3hm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hwxf-wjq7-j3hm", - "modified": "2024-05-22T18:30:38Z", + "modified": "2024-11-22T12:39:07Z", "published": "2023-12-23T15:30:17Z", "aliases": [ "CVE-2023-7008" @@ -52,6 +52,10 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QHNBXGKJWISJETTTDTZKTBFIBJUOSLKL" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241122-0004" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-ffpf-5h29-w36w/GHSA-ffpf-5h29-w36w.json b/advisories/unreviewed/2024/03/GHSA-ffpf-5h29-w36w/GHSA-ffpf-5h29-w36w.json index 2a21219df93..69cc16f2225 100644 --- a/advisories/unreviewed/2024/03/GHSA-ffpf-5h29-w36w/GHSA-ffpf-5h29-w36w.json +++ b/advisories/unreviewed/2024/03/GHSA-ffpf-5h29-w36w/GHSA-ffpf-5h29-w36w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ffpf-5h29-w36w", - "modified": "2024-05-17T00:30:59Z", + "modified": "2024-11-22T12:39:08Z", "published": "2024-03-21T06:33:05Z", "aliases": [ "CVE-2024-28835" @@ -45,6 +45,10 @@ "type": "WEB", "url": "https://lists.gnupg.org/pipermail/gnutls-help/2024-March/004845.html" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241122-0009" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/03/22/1" diff --git a/advisories/unreviewed/2024/07/GHSA-ch4x-f5c4-36gv/GHSA-ch4x-f5c4-36gv.json b/advisories/unreviewed/2024/07/GHSA-ch4x-f5c4-36gv/GHSA-ch4x-f5c4-36gv.json index f01ce1d42ae..7851c1e20ea 100644 --- a/advisories/unreviewed/2024/07/GHSA-ch4x-f5c4-36gv/GHSA-ch4x-f5c4-36gv.json +++ b/advisories/unreviewed/2024/07/GHSA-ch4x-f5c4-36gv/GHSA-ch4x-f5c4-36gv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ch4x-f5c4-36gv", - "modified": "2024-07-19T15:31:46Z", + "modified": "2024-11-22T12:39:08Z", "published": "2024-07-09T03:31:44Z", "aliases": [ "CVE-2024-22020" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://hackerone.com/reports/2092749" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241122-0006" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/07/11/6" diff --git a/advisories/unreviewed/2024/09/GHSA-q793-mj5v-wh68/GHSA-q793-mj5v-wh68.json b/advisories/unreviewed/2024/09/GHSA-q793-mj5v-wh68/GHSA-q793-mj5v-wh68.json index 30c14e89b2e..6c1872cba02 100644 --- a/advisories/unreviewed/2024/09/GHSA-q793-mj5v-wh68/GHSA-q793-mj5v-wh68.json +++ b/advisories/unreviewed/2024/09/GHSA-q793-mj5v-wh68/GHSA-q793-mj5v-wh68.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q793-mj5v-wh68", - "modified": "2024-09-07T18:30:23Z", + "modified": "2024-11-22T12:39:08Z", "published": "2024-09-07T18:30:23Z", "aliases": [ "CVE-2024-36137" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://nodejs.org/en/blog/vulnerability/july-2024-security-releases" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241122-0005" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/11/GHSA-5x53-pqpp-vfwr/GHSA-5x53-pqpp-vfwr.json b/advisories/unreviewed/2024/11/GHSA-5x53-pqpp-vfwr/GHSA-5x53-pqpp-vfwr.json new file mode 100644 index 00000000000..b4051880732 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5x53-pqpp-vfwr/GHSA-5x53-pqpp-vfwr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5x53-pqpp-vfwr", + "modified": "2024-11-22T12:39:08Z", + "published": "2024-11-22T12:39:08Z", + "aliases": [ + "CVE-2017-9711" + ], + "details": "Certain unprivileged processes are able to perform IOCTL calls.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-9711" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2018-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T10:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6w35-x982-hj9h/GHSA-6w35-x982-hj9h.json b/advisories/unreviewed/2024/11/GHSA-6w35-x982-hj9h/GHSA-6w35-x982-hj9h.json index ae1b30b9919..cd36440406b 100644 --- a/advisories/unreviewed/2024/11/GHSA-6w35-x982-hj9h/GHSA-6w35-x982-hj9h.json +++ b/advisories/unreviewed/2024/11/GHSA-6w35-x982-hj9h/GHSA-6w35-x982-hj9h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6w35-x982-hj9h", - "modified": "2024-11-08T15:31:12Z", + "modified": "2024-11-22T12:39:08Z", "published": "2024-11-04T15:31:56Z", "aliases": [ "CVE-2024-51556" diff --git a/advisories/unreviewed/2024/11/GHSA-g7gv-3436-vxj2/GHSA-g7gv-3436-vxj2.json b/advisories/unreviewed/2024/11/GHSA-g7gv-3436-vxj2/GHSA-g7gv-3436-vxj2.json new file mode 100644 index 00000000000..4f07a2265d6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g7gv-3436-vxj2/GHSA-g7gv-3436-vxj2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7gv-3436-vxj2", + "modified": "2024-11-22T12:39:08Z", + "published": "2024-11-22T12:39:08Z", + "aliases": [ + "CVE-2024-41781" + ], + "details": "IBM PowerVM Platform KeyStore (IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1030.00 through FW1030.60, FW1050.00 through FW1050.20, and FW1060.00 through FW1060.10 functionality can be compromised if an attacker gains service access to the HMC. An attacker that gains service access to the HMC can locate and through a series of service procedures decrypt data contained in the Platform KeyStore.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41781" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7172698" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T12:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-g9p5-q86f-758v/GHSA-g9p5-q86f-758v.json b/advisories/unreviewed/2024/11/GHSA-g9p5-q86f-758v/GHSA-g9p5-q86f-758v.json new file mode 100644 index 00000000000..bd23f6a5d31 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g9p5-q86f-758v/GHSA-g9p5-q86f-758v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9p5-q86f-758v", + "modified": "2024-11-22T12:39:08Z", + "published": "2024-11-22T12:39:08Z", + "aliases": [ + "CVE-2021-30299" + ], + "details": "Possible out of bound access in audio module due to lack of validation of user provided input.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-30299" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/march-2022-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T10:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hjhx-mr4r-6j6j/GHSA-hjhx-mr4r-6j6j.json b/advisories/unreviewed/2024/11/GHSA-hjhx-mr4r-6j6j/GHSA-hjhx-mr4r-6j6j.json index 3a5947d2cbc..d4f2834df80 100644 --- a/advisories/unreviewed/2024/11/GHSA-hjhx-mr4r-6j6j/GHSA-hjhx-mr4r-6j6j.json +++ b/advisories/unreviewed/2024/11/GHSA-hjhx-mr4r-6j6j/GHSA-hjhx-mr4r-6j6j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hjhx-mr4r-6j6j", - "modified": "2024-11-08T15:31:12Z", + "modified": "2024-11-22T12:39:08Z", "published": "2024-11-04T15:31:57Z", "aliases": [ "CVE-2024-51559" diff --git a/advisories/unreviewed/2024/11/GHSA-m7v8-cfx4-v2vg/GHSA-m7v8-cfx4-v2vg.json b/advisories/unreviewed/2024/11/GHSA-m7v8-cfx4-v2vg/GHSA-m7v8-cfx4-v2vg.json new file mode 100644 index 00000000000..d8722500a67 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-m7v8-cfx4-v2vg/GHSA-m7v8-cfx4-v2vg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m7v8-cfx4-v2vg", + "modified": "2024-11-22T12:39:08Z", + "published": "2024-11-22T12:39:08Z", + "aliases": [ + "CVE-2024-41779" + ], + "details": "IBM Engineering Systems Design Rhapsody - Model Manager 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending a specially crafted request, an attacker could exploit this vulnerability to remotely execute code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41779" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7172535" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T12:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-px2p-9r77-w9cq/GHSA-px2p-9r77-w9cq.json b/advisories/unreviewed/2024/11/GHSA-px2p-9r77-w9cq/GHSA-px2p-9r77-w9cq.json new file mode 100644 index 00000000000..80eb3409024 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-px2p-9r77-w9cq/GHSA-px2p-9r77-w9cq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-px2p-9r77-w9cq", + "modified": "2024-11-22T12:39:09Z", + "published": "2024-11-22T12:39:09Z", + "aliases": [ + "CVE-2024-51766" + ], + "details": "A potential security vulnerability has been identified in the HPE NonStop DISK UTIL (T9208) product. This vulnerability could be exploited to cause a denial of service (DoS) to NonStop server. It exists in all prior DISK UTIL product versions of L-series and J-series.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51766" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbns04759en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-755" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T12:15:19Z" + } +} \ No newline at end of file