Publish Advisories

GHSA-28p7-f6h6-3jh3
GHSA-3vjh-xrhf-v9xh
GHSA-4m5r-w2rq-q54q
GHSA-7663-37rg-c377
GHSA-888j-pjqh-fx58
GHSA-8fh4-942r-jf2g
GHSA-c86q-rj37-8f85
GHSA-gfwr-xqmj-j27v
GHSA-gv4m-f6fx-859x
GHSA-p66q-ppwr-q5j8
GHSA-qr8f-5qqg-j3wg
GHSA-rmr4-x6c9-jc68
GHSA-v7w9-63xh-6r3w
GHSA-xh4g-c9p6-5jxg
This commit is contained in:
advisory-database[bot]
2024-11-15 20:50:58 +00:00
parent 5db670254f
commit 3b19c60f90
14 changed files with 167 additions and 28 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-28p7-f6h6-3jh3",
"modified": "2024-11-15T15:45:31Z",
"modified": "2024-11-15T20:50:19Z",
"published": "2024-11-15T15:45:31Z",
"aliases": [
"CVE-2024-51496"
@@ -43,6 +43,10 @@
"type": "WEB",
"url": "https://github.com/librenms/librenms/security/advisories/GHSA-28p7-f6h6-3jh3"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51496"
},
{
"type": "WEB",
"url": "https://github.com/librenms/librenms/commit/aef739a438ffb507e927a4ec87b359164a7a053a"
@@ -59,6 +63,6 @@
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-11-15T15:45:31Z",
"nvd_published_at": null
"nvd_published_at": "2024-11-15T16:15:37Z"
}
}
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3vjh-xrhf-v9xh",
"modified": "2024-11-15T12:31:44Z",
"modified": "2024-11-15T20:49:33Z",
"published": "2024-11-15T12:31:44Z",
"aliases": [
"CVE-2021-3902"
],
"summary": "Improper Restriction of XML External Entity Reference in dompdf/dompdf",
"details": "An improper restriction of external entities (XXE) vulnerability in dompdf/dompdf's SVG parser allows for Server-Side Request Forgery (SSRF) and deserialization attacks. This issue affects all versions prior to 2.0.0. The vulnerability can be exploited even if the isRemoteEnabled option is set to false. It allows attackers to perform SSRF, disclose internal image files, and cause PHAR deserialization attacks.",
"severity": [
{
@@ -14,7 +15,25 @@
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "dompdf/dompdf"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "2.0.0"
}
]
}
]
}
],
"references": [
{
@@ -25,6 +44,10 @@
"type": "WEB",
"url": "https://github.com/dompdf/dompdf/commit/f56bc8e40be6c0ae0825e6c7396f4db80620b799"
},
{
"type": "PACKAGE",
"url": "https://github.com/dompdf/dompdf"
},
{
"type": "WEB",
"url": "https://huntr.com/bounties/a6071c07-806f-429a-8656-a4742e4191b1"
@@ -35,8 +58,8 @@
"CWE-611"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2024-11-15T20:49:33Z",
"nvd_published_at": "2024-11-15T11:15:06Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4m5r-w2rq-q54q",
"modified": "2024-11-15T15:41:38Z",
"modified": "2024-11-15T20:49:55Z",
"published": "2024-11-15T15:41:38Z",
"aliases": [
"CVE-2024-50355"
@@ -43,6 +43,10 @@
"type": "WEB",
"url": "https://github.com/librenms/librenms/security/advisories/GHSA-4m5r-w2rq-q54q"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50355"
},
{
"type": "WEB",
"url": "https://github.com/librenms/librenms/commit/bb4731419b592867bf974dde525e536606a52976"
@@ -59,6 +63,6 @@
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-11-15T15:41:38Z",
"nvd_published_at": null
"nvd_published_at": "2024-11-15T16:15:36Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7663-37rg-c377",
"modified": "2024-11-15T15:43:20Z",
"modified": "2024-11-15T20:50:16Z",
"published": "2024-11-15T15:43:20Z",
"aliases": [
"CVE-2024-51494"
@@ -43,6 +43,10 @@
"type": "WEB",
"url": "https://github.com/librenms/librenms/security/advisories/GHSA-7663-37rg-c377"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51494"
},
{
"type": "WEB",
"url": "https://github.com/librenms/librenms/commit/82a744bfe29017b8b58b5752ab9e1b335bedf0a0"
@@ -59,6 +63,6 @@
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-11-15T15:43:20Z",
"nvd_published_at": null
"nvd_published_at": "2024-11-15T16:15:37Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-888j-pjqh-fx58",
"modified": "2024-11-15T15:25:56Z",
"modified": "2024-11-15T20:49:47Z",
"published": "2024-11-15T15:25:56Z",
"aliases": [
"CVE-2024-49759"
@@ -43,6 +43,10 @@
"type": "WEB",
"url": "https://github.com/librenms/librenms/security/advisories/GHSA-888j-pjqh-fx58"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49759"
},
{
"type": "WEB",
"url": "https://github.com/librenms/librenms/commit/237f4d2e818170171dfad6efad36a275cd2ba8d0"
@@ -59,6 +63,6 @@
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-11-15T15:25:56Z",
"nvd_published_at": null
"nvd_published_at": "2024-11-15T16:15:35Z"
}
}
File diff suppressed because one or more lines are too long
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c86q-rj37-8f85",
"modified": "2024-11-15T15:17:33Z",
"modified": "2024-11-15T20:49:46Z",
"published": "2024-11-15T15:17:33Z",
"aliases": [
"CVE-2024-49758"
@@ -43,6 +43,10 @@
"type": "WEB",
"url": "https://github.com/librenms/librenms/security/advisories/GHSA-c86q-rj37-8f85"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49758"
},
{
"type": "WEB",
"url": "https://github.com/librenms/librenms/commit/24b142d753898e273ec20b542a27dd6eb530c7d8"
@@ -59,6 +63,6 @@
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-11-15T15:17:33Z",
"nvd_published_at": null
"nvd_published_at": "2024-11-15T16:15:34Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gfwr-xqmj-j27v",
"modified": "2024-11-15T15:11:45Z",
"modified": "2024-11-15T20:49:44Z",
"published": "2024-11-15T15:11:45Z",
"aliases": [
"CVE-2024-49754"
@@ -43,6 +43,10 @@
"type": "WEB",
"url": "https://github.com/librenms/librenms/security/advisories/GHSA-gfwr-xqmj-j27v"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49754"
},
{
"type": "WEB",
"url": "https://github.com/librenms/librenms/commit/25988a937cbaebd2ba4c0517510206c404dfb359"
@@ -59,6 +63,6 @@
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-11-15T15:11:45Z",
"nvd_published_at": null
"nvd_published_at": "2024-11-15T16:15:34Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gv4m-f6fx-859x",
"modified": "2024-11-15T15:46:33Z",
"modified": "2024-11-15T20:50:21Z",
"published": "2024-11-15T15:46:32Z",
"aliases": [
"CVE-2024-51497"
@@ -43,6 +43,10 @@
"type": "WEB",
"url": "https://github.com/librenms/librenms/security/advisories/GHSA-gv4m-f6fx-859x"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51497"
},
{
"type": "WEB",
"url": "https://github.com/librenms/librenms/commit/42b156e42a3811c23758772ce8c63d4d3eaba59b"
@@ -59,6 +63,6 @@
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-11-15T15:46:32Z",
"nvd_published_at": null
"nvd_published_at": "2024-11-15T16:15:37Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p66q-ppwr-q5j8",
"modified": "2024-11-15T15:44:27Z",
"modified": "2024-11-15T20:50:17Z",
"published": "2024-11-15T15:44:27Z",
"aliases": [
"CVE-2024-51495"
@@ -43,6 +43,10 @@
"type": "WEB",
"url": "https://github.com/librenms/librenms/security/advisories/GHSA-p66q-ppwr-q5j8"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51495"
},
{
"type": "WEB",
"url": "https://github.com/librenms/librenms/commit/4568188ce9097a2e3a3b563311077f2bb82455c0"
@@ -59,6 +63,6 @@
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-11-15T15:44:27Z",
"nvd_published_at": null
"nvd_published_at": "2024-11-15T16:15:37Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qr8f-5qqg-j3wg",
"modified": "2024-11-15T15:39:52Z",
"modified": "2024-11-15T20:49:54Z",
"published": "2024-11-15T15:39:52Z",
"aliases": [
"CVE-2024-50352"
@@ -43,6 +43,10 @@
"type": "WEB",
"url": "https://github.com/librenms/librenms/security/advisories/GHSA-qr8f-5qqg-j3wg"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50352"
},
{
"type": "WEB",
"url": "https://github.com/librenms/librenms/commit/b4af778ca42c5839801f16ece53505bb7fa1e7bc"
@@ -59,6 +63,6 @@
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-11-15T15:39:52Z",
"nvd_published_at": null
"nvd_published_at": "2024-11-15T16:15:35Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rmr4-x6c9-jc68",
"modified": "2024-11-15T15:28:25Z",
"modified": "2024-11-15T20:49:49Z",
"published": "2024-11-15T15:27:42Z",
"aliases": [
"CVE-2024-49764"
@@ -43,6 +43,10 @@
"type": "WEB",
"url": "https://github.com/librenms/librenms/security/advisories/GHSA-rmr4-x6c9-jc68"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49764"
},
{
"type": "WEB",
"url": "https://github.com/librenms/librenms/commit/af15eabbb1752985d36f337cecf137a947e170f6"
@@ -59,6 +63,6 @@
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-11-15T15:27:42Z",
"nvd_published_at": null
"nvd_published_at": "2024-11-15T16:15:35Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v7w9-63xh-6r3w",
"modified": "2024-11-15T15:34:37Z",
"modified": "2024-11-15T20:49:52Z",
"published": "2024-11-15T15:34:36Z",
"aliases": [
"CVE-2024-50351"
@@ -43,6 +43,10 @@
"type": "WEB",
"url": "https://github.com/librenms/librenms/security/advisories/GHSA-v7w9-63xh-6r3w"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50351"
},
{
"type": "WEB",
"url": "https://github.com/librenms/librenms/commit/6a14a9bd767c6e452e4df77a24126c3eeb93dcbf"
@@ -59,6 +63,6 @@
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-11-15T15:34:36Z",
"nvd_published_at": null
"nvd_published_at": "2024-11-15T16:15:35Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xh4g-c9p6-5jxg",
"modified": "2024-11-15T15:30:05Z",
"modified": "2024-11-15T20:49:50Z",
"published": "2024-11-15T15:30:05Z",
"aliases": [
"CVE-2024-50350"
@@ -43,6 +43,10 @@
"type": "WEB",
"url": "https://github.com/librenms/librenms/security/advisories/GHSA-xh4g-c9p6-5jxg"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50350"
},
{
"type": "WEB",
"url": "https://github.com/librenms/librenms/commit/82a744bfe29017b8b58b5752ab9e1b335bedf0a0"
@@ -59,6 +63,6 @@
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-11-15T15:30:05Z",
"nvd_published_at": null
"nvd_published_at": "2024-11-15T16:15:35Z"
}
}