From 3b19c60f906c22d72f4fcdf28a2c635b87e1045a Mon Sep 17 00:00:00 2001
From: "advisory-database[bot]"
<45398580+advisory-database[bot]@users.noreply.github.com>
Date: Fri, 15 Nov 2024 20:50:58 +0000
Subject: [PATCH] Publish Advisories
GHSA-28p7-f6h6-3jh3
GHSA-3vjh-xrhf-v9xh
GHSA-4m5r-w2rq-q54q
GHSA-7663-37rg-c377
GHSA-888j-pjqh-fx58
GHSA-8fh4-942r-jf2g
GHSA-c86q-rj37-8f85
GHSA-gfwr-xqmj-j27v
GHSA-gv4m-f6fx-859x
GHSA-p66q-ppwr-q5j8
GHSA-qr8f-5qqg-j3wg
GHSA-rmr4-x6c9-jc68
GHSA-v7w9-63xh-6r3w
GHSA-xh4g-c9p6-5jxg
---
.../GHSA-28p7-f6h6-3jh3.json | 8 ++-
.../GHSA-3vjh-xrhf-v9xh.json | 31 +++++++--
.../GHSA-4m5r-w2rq-q54q.json | 8 ++-
.../GHSA-7663-37rg-c377.json | 8 ++-
.../GHSA-888j-pjqh-fx58.json | 8 ++-
.../GHSA-8fh4-942r-jf2g.json | 68 +++++++++++++++++++
.../GHSA-c86q-rj37-8f85.json | 8 ++-
.../GHSA-gfwr-xqmj-j27v.json | 8 ++-
.../GHSA-gv4m-f6fx-859x.json | 8 ++-
.../GHSA-p66q-ppwr-q5j8.json | 8 ++-
.../GHSA-qr8f-5qqg-j3wg.json | 8 ++-
.../GHSA-rmr4-x6c9-jc68.json | 8 ++-
.../GHSA-v7w9-63xh-6r3w.json | 8 ++-
.../GHSA-xh4g-c9p6-5jxg.json | 8 ++-
14 files changed, 167 insertions(+), 28 deletions(-)
rename advisories/{unreviewed => github-reviewed}/2024/11/GHSA-3vjh-xrhf-v9xh/GHSA-3vjh-xrhf-v9xh.json (66%)
create mode 100644 advisories/github-reviewed/2024/11/GHSA-8fh4-942r-jf2g/GHSA-8fh4-942r-jf2g.json
diff --git a/advisories/github-reviewed/2024/11/GHSA-28p7-f6h6-3jh3/GHSA-28p7-f6h6-3jh3.json b/advisories/github-reviewed/2024/11/GHSA-28p7-f6h6-3jh3/GHSA-28p7-f6h6-3jh3.json
index 5c00f1df58a..eca8ef5ceee 100644
--- a/advisories/github-reviewed/2024/11/GHSA-28p7-f6h6-3jh3/GHSA-28p7-f6h6-3jh3.json
+++ b/advisories/github-reviewed/2024/11/GHSA-28p7-f6h6-3jh3/GHSA-28p7-f6h6-3jh3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-28p7-f6h6-3jh3",
- "modified": "2024-11-15T15:45:31Z",
+ "modified": "2024-11-15T20:50:19Z",
"published": "2024-11-15T15:45:31Z",
"aliases": [
"CVE-2024-51496"
@@ -43,6 +43,10 @@
"type": "WEB",
"url": "https://github.com/librenms/librenms/security/advisories/GHSA-28p7-f6h6-3jh3"
},
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51496"
+ },
{
"type": "WEB",
"url": "https://github.com/librenms/librenms/commit/aef739a438ffb507e927a4ec87b359164a7a053a"
@@ -59,6 +63,6 @@
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-11-15T15:45:31Z",
- "nvd_published_at": null
+ "nvd_published_at": "2024-11-15T16:15:37Z"
}
}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-3vjh-xrhf-v9xh/GHSA-3vjh-xrhf-v9xh.json b/advisories/github-reviewed/2024/11/GHSA-3vjh-xrhf-v9xh/GHSA-3vjh-xrhf-v9xh.json
similarity index 66%
rename from advisories/unreviewed/2024/11/GHSA-3vjh-xrhf-v9xh/GHSA-3vjh-xrhf-v9xh.json
rename to advisories/github-reviewed/2024/11/GHSA-3vjh-xrhf-v9xh/GHSA-3vjh-xrhf-v9xh.json
index db0b3bf2999..83b5d210fb1 100644
--- a/advisories/unreviewed/2024/11/GHSA-3vjh-xrhf-v9xh/GHSA-3vjh-xrhf-v9xh.json
+++ b/advisories/github-reviewed/2024/11/GHSA-3vjh-xrhf-v9xh/GHSA-3vjh-xrhf-v9xh.json
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3vjh-xrhf-v9xh",
- "modified": "2024-11-15T12:31:44Z",
+ "modified": "2024-11-15T20:49:33Z",
"published": "2024-11-15T12:31:44Z",
"aliases": [
"CVE-2021-3902"
],
+ "summary": "Improper Restriction of XML External Entity Reference in dompdf/dompdf",
"details": "An improper restriction of external entities (XXE) vulnerability in dompdf/dompdf's SVG parser allows for Server-Side Request Forgery (SSRF) and deserialization attacks. This issue affects all versions prior to 2.0.0. The vulnerability can be exploited even if the isRemoteEnabled option is set to false. It allows attackers to perform SSRF, disclose internal image files, and cause PHAR deserialization attacks.",
"severity": [
{
@@ -14,7 +15,25 @@
}
],
"affected": [
-
+ {
+ "package": {
+ "ecosystem": "Packagist",
+ "name": "dompdf/dompdf"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "0"
+ },
+ {
+ "fixed": "2.0.0"
+ }
+ ]
+ }
+ ]
+ }
],
"references": [
{
@@ -25,6 +44,10 @@
"type": "WEB",
"url": "https://github.com/dompdf/dompdf/commit/f56bc8e40be6c0ae0825e6c7396f4db80620b799"
},
+ {
+ "type": "PACKAGE",
+ "url": "https://github.com/dompdf/dompdf"
+ },
{
"type": "WEB",
"url": "https://huntr.com/bounties/a6071c07-806f-429a-8656-a4742e4191b1"
@@ -35,8 +58,8 @@
"CWE-611"
],
"severity": "CRITICAL",
- "github_reviewed": false,
- "github_reviewed_at": null,
+ "github_reviewed": true,
+ "github_reviewed_at": "2024-11-15T20:49:33Z",
"nvd_published_at": "2024-11-15T11:15:06Z"
}
}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/11/GHSA-4m5r-w2rq-q54q/GHSA-4m5r-w2rq-q54q.json b/advisories/github-reviewed/2024/11/GHSA-4m5r-w2rq-q54q/GHSA-4m5r-w2rq-q54q.json
index c696d3e3b96..a6e5bc8ded1 100644
--- a/advisories/github-reviewed/2024/11/GHSA-4m5r-w2rq-q54q/GHSA-4m5r-w2rq-q54q.json
+++ b/advisories/github-reviewed/2024/11/GHSA-4m5r-w2rq-q54q/GHSA-4m5r-w2rq-q54q.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4m5r-w2rq-q54q",
- "modified": "2024-11-15T15:41:38Z",
+ "modified": "2024-11-15T20:49:55Z",
"published": "2024-11-15T15:41:38Z",
"aliases": [
"CVE-2024-50355"
@@ -43,6 +43,10 @@
"type": "WEB",
"url": "https://github.com/librenms/librenms/security/advisories/GHSA-4m5r-w2rq-q54q"
},
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50355"
+ },
{
"type": "WEB",
"url": "https://github.com/librenms/librenms/commit/bb4731419b592867bf974dde525e536606a52976"
@@ -59,6 +63,6 @@
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-11-15T15:41:38Z",
- "nvd_published_at": null
+ "nvd_published_at": "2024-11-15T16:15:36Z"
}
}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/11/GHSA-7663-37rg-c377/GHSA-7663-37rg-c377.json b/advisories/github-reviewed/2024/11/GHSA-7663-37rg-c377/GHSA-7663-37rg-c377.json
index 1cf298e49a9..3fb2b1e73f5 100644
--- a/advisories/github-reviewed/2024/11/GHSA-7663-37rg-c377/GHSA-7663-37rg-c377.json
+++ b/advisories/github-reviewed/2024/11/GHSA-7663-37rg-c377/GHSA-7663-37rg-c377.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7663-37rg-c377",
- "modified": "2024-11-15T15:43:20Z",
+ "modified": "2024-11-15T20:50:16Z",
"published": "2024-11-15T15:43:20Z",
"aliases": [
"CVE-2024-51494"
@@ -43,6 +43,10 @@
"type": "WEB",
"url": "https://github.com/librenms/librenms/security/advisories/GHSA-7663-37rg-c377"
},
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51494"
+ },
{
"type": "WEB",
"url": "https://github.com/librenms/librenms/commit/82a744bfe29017b8b58b5752ab9e1b335bedf0a0"
@@ -59,6 +63,6 @@
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-11-15T15:43:20Z",
- "nvd_published_at": null
+ "nvd_published_at": "2024-11-15T16:15:37Z"
}
}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/11/GHSA-888j-pjqh-fx58/GHSA-888j-pjqh-fx58.json b/advisories/github-reviewed/2024/11/GHSA-888j-pjqh-fx58/GHSA-888j-pjqh-fx58.json
index db681e6c417..8a52b51642e 100644
--- a/advisories/github-reviewed/2024/11/GHSA-888j-pjqh-fx58/GHSA-888j-pjqh-fx58.json
+++ b/advisories/github-reviewed/2024/11/GHSA-888j-pjqh-fx58/GHSA-888j-pjqh-fx58.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-888j-pjqh-fx58",
- "modified": "2024-11-15T15:25:56Z",
+ "modified": "2024-11-15T20:49:47Z",
"published": "2024-11-15T15:25:56Z",
"aliases": [
"CVE-2024-49759"
@@ -43,6 +43,10 @@
"type": "WEB",
"url": "https://github.com/librenms/librenms/security/advisories/GHSA-888j-pjqh-fx58"
},
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49759"
+ },
{
"type": "WEB",
"url": "https://github.com/librenms/librenms/commit/237f4d2e818170171dfad6efad36a275cd2ba8d0"
@@ -59,6 +63,6 @@
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-11-15T15:25:56Z",
- "nvd_published_at": null
+ "nvd_published_at": "2024-11-15T16:15:35Z"
}
}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/11/GHSA-8fh4-942r-jf2g/GHSA-8fh4-942r-jf2g.json b/advisories/github-reviewed/2024/11/GHSA-8fh4-942r-jf2g/GHSA-8fh4-942r-jf2g.json
new file mode 100644
index 00000000000..437ed84b0b8
--- /dev/null
+++ b/advisories/github-reviewed/2024/11/GHSA-8fh4-942r-jf2g/GHSA-8fh4-942r-jf2g.json
@@ -0,0 +1,68 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8fh4-942r-jf2g",
+ "modified": "2024-11-15T20:48:45Z",
+ "published": "2024-11-15T20:48:45Z",
+ "aliases": [
+ "CVE-2024-52526"
+ ],
+ "summary": "LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/device/services.inc.php",
+ "details": "### Summary\nA Stored Cross-Site Scripting (XSS) vulnerability in the \"Services\" tab of the Device page allows authenticated users to inject arbitrary JavaScript through the \"descr\" parameter when adding a service to a device. This vulnerability could result in the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and enabling unauthorized actions.\n\n### Details\nWhen creating a device through the \"edit device -> services\" workflow (example path: \"/device/15/edit/section=services\"), the attacker can inject an XSS payload in the \"descr\" parameter. This payload is reflected in the \"Services\" tab of the device (URL: \"/device/15/services\"). It is important to note that the vulnerability does not exist when creating devices through the normal \"Add Service\" interface (created through the ajax_form.php request with the \"type=create-service\").\n\nThe payload used to exploit this vulnerability is:\n```Descr'\">```\n\nNote: The payload uses the \"15.rs\" domain to bypass some of the length restrictions found during research by pointing to a malicious remote file. The file contains a POC XSS payload, and can contain any arbitrary JS code.\n\nThe root cause is the application's failure to sanitize the \"descr\" parameter before outputting it in the HTML. The sink is as follows:\nhttps://github.com/librenms/librenms/blob/7f2ae971c4a565b0d7345fa78b4211409f96800a/includes/html/pages/device/services.inc.php#L87\n\n### PoC\n1. Create a service for a device using the following payload in the \"descr\" parameter:\n```Descr'\">```\n2. Save the service.\n3. Navigate to the \"Services\" tab of the device.\n4. Observe that the injected script executes in the \"Services\" tab.\n\nExample Request:\n```http\nPOST /device/15/edit/section=services HTTP/1.1\nHost: \nContent-Type: application/x-www-form-urlencoded\nCookie: \n\n_token=&name=Name'\">&addsrv=yes&device=15&type=pollen&descr=Descr'\">&ip=IP'\">¶ms=Params'\">&Submit=\n```\n\n### Impact\n\nThis vulnerability allows authenticated users to inject and execute arbitrary JavaScript in the context of other users' sessions when they visit the \"Services\" tab of the device. This could result in the compromise of user accounts and unauthorized actions performed on their behalf.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L"
+ }
+ ],
+ "affected": [
+ {
+ "package": {
+ "ecosystem": "Packagist",
+ "name": "librenms/librenms"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "0"
+ },
+ {
+ "fixed": "24.10.0"
+ }
+ ]
+ }
+ ],
+ "database_specific": {
+ "last_known_affected_version_range": "<= 24.9.1"
+ }
+ }
+ ],
+ "references": [
+ {
+ "type": "WEB",
+ "url": "https://github.com/librenms/librenms/security/advisories/GHSA-8fh4-942r-jf2g"
+ },
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52526"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/librenms/librenms/commit/30e522c29bbb1f9b72951025e7049a26c7e1d76e"
+ },
+ {
+ "type": "PACKAGE",
+ "url": "https://github.com/librenms/librenms"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": true,
+ "github_reviewed_at": "2024-11-15T20:48:45Z",
+ "nvd_published_at": "2024-11-15T16:15:38Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/11/GHSA-c86q-rj37-8f85/GHSA-c86q-rj37-8f85.json b/advisories/github-reviewed/2024/11/GHSA-c86q-rj37-8f85/GHSA-c86q-rj37-8f85.json
index f693ae3c7b5..a5949e99975 100644
--- a/advisories/github-reviewed/2024/11/GHSA-c86q-rj37-8f85/GHSA-c86q-rj37-8f85.json
+++ b/advisories/github-reviewed/2024/11/GHSA-c86q-rj37-8f85/GHSA-c86q-rj37-8f85.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c86q-rj37-8f85",
- "modified": "2024-11-15T15:17:33Z",
+ "modified": "2024-11-15T20:49:46Z",
"published": "2024-11-15T15:17:33Z",
"aliases": [
"CVE-2024-49758"
@@ -43,6 +43,10 @@
"type": "WEB",
"url": "https://github.com/librenms/librenms/security/advisories/GHSA-c86q-rj37-8f85"
},
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49758"
+ },
{
"type": "WEB",
"url": "https://github.com/librenms/librenms/commit/24b142d753898e273ec20b542a27dd6eb530c7d8"
@@ -59,6 +63,6 @@
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-11-15T15:17:33Z",
- "nvd_published_at": null
+ "nvd_published_at": "2024-11-15T16:15:34Z"
}
}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/11/GHSA-gfwr-xqmj-j27v/GHSA-gfwr-xqmj-j27v.json b/advisories/github-reviewed/2024/11/GHSA-gfwr-xqmj-j27v/GHSA-gfwr-xqmj-j27v.json
index 3040eaccf74..b83e044c890 100644
--- a/advisories/github-reviewed/2024/11/GHSA-gfwr-xqmj-j27v/GHSA-gfwr-xqmj-j27v.json
+++ b/advisories/github-reviewed/2024/11/GHSA-gfwr-xqmj-j27v/GHSA-gfwr-xqmj-j27v.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gfwr-xqmj-j27v",
- "modified": "2024-11-15T15:11:45Z",
+ "modified": "2024-11-15T20:49:44Z",
"published": "2024-11-15T15:11:45Z",
"aliases": [
"CVE-2024-49754"
@@ -43,6 +43,10 @@
"type": "WEB",
"url": "https://github.com/librenms/librenms/security/advisories/GHSA-gfwr-xqmj-j27v"
},
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49754"
+ },
{
"type": "WEB",
"url": "https://github.com/librenms/librenms/commit/25988a937cbaebd2ba4c0517510206c404dfb359"
@@ -59,6 +63,6 @@
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-11-15T15:11:45Z",
- "nvd_published_at": null
+ "nvd_published_at": "2024-11-15T16:15:34Z"
}
}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/11/GHSA-gv4m-f6fx-859x/GHSA-gv4m-f6fx-859x.json b/advisories/github-reviewed/2024/11/GHSA-gv4m-f6fx-859x/GHSA-gv4m-f6fx-859x.json
index b76a4660756..7721d76b1fa 100644
--- a/advisories/github-reviewed/2024/11/GHSA-gv4m-f6fx-859x/GHSA-gv4m-f6fx-859x.json
+++ b/advisories/github-reviewed/2024/11/GHSA-gv4m-f6fx-859x/GHSA-gv4m-f6fx-859x.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gv4m-f6fx-859x",
- "modified": "2024-11-15T15:46:33Z",
+ "modified": "2024-11-15T20:50:21Z",
"published": "2024-11-15T15:46:32Z",
"aliases": [
"CVE-2024-51497"
@@ -43,6 +43,10 @@
"type": "WEB",
"url": "https://github.com/librenms/librenms/security/advisories/GHSA-gv4m-f6fx-859x"
},
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51497"
+ },
{
"type": "WEB",
"url": "https://github.com/librenms/librenms/commit/42b156e42a3811c23758772ce8c63d4d3eaba59b"
@@ -59,6 +63,6 @@
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-11-15T15:46:32Z",
- "nvd_published_at": null
+ "nvd_published_at": "2024-11-15T16:15:37Z"
}
}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/11/GHSA-p66q-ppwr-q5j8/GHSA-p66q-ppwr-q5j8.json b/advisories/github-reviewed/2024/11/GHSA-p66q-ppwr-q5j8/GHSA-p66q-ppwr-q5j8.json
index 828fe9ee704..154ba81317d 100644
--- a/advisories/github-reviewed/2024/11/GHSA-p66q-ppwr-q5j8/GHSA-p66q-ppwr-q5j8.json
+++ b/advisories/github-reviewed/2024/11/GHSA-p66q-ppwr-q5j8/GHSA-p66q-ppwr-q5j8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p66q-ppwr-q5j8",
- "modified": "2024-11-15T15:44:27Z",
+ "modified": "2024-11-15T20:50:17Z",
"published": "2024-11-15T15:44:27Z",
"aliases": [
"CVE-2024-51495"
@@ -43,6 +43,10 @@
"type": "WEB",
"url": "https://github.com/librenms/librenms/security/advisories/GHSA-p66q-ppwr-q5j8"
},
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51495"
+ },
{
"type": "WEB",
"url": "https://github.com/librenms/librenms/commit/4568188ce9097a2e3a3b563311077f2bb82455c0"
@@ -59,6 +63,6 @@
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-11-15T15:44:27Z",
- "nvd_published_at": null
+ "nvd_published_at": "2024-11-15T16:15:37Z"
}
}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/11/GHSA-qr8f-5qqg-j3wg/GHSA-qr8f-5qqg-j3wg.json b/advisories/github-reviewed/2024/11/GHSA-qr8f-5qqg-j3wg/GHSA-qr8f-5qqg-j3wg.json
index 593497a9012..270df60ed00 100644
--- a/advisories/github-reviewed/2024/11/GHSA-qr8f-5qqg-j3wg/GHSA-qr8f-5qqg-j3wg.json
+++ b/advisories/github-reviewed/2024/11/GHSA-qr8f-5qqg-j3wg/GHSA-qr8f-5qqg-j3wg.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qr8f-5qqg-j3wg",
- "modified": "2024-11-15T15:39:52Z",
+ "modified": "2024-11-15T20:49:54Z",
"published": "2024-11-15T15:39:52Z",
"aliases": [
"CVE-2024-50352"
@@ -43,6 +43,10 @@
"type": "WEB",
"url": "https://github.com/librenms/librenms/security/advisories/GHSA-qr8f-5qqg-j3wg"
},
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50352"
+ },
{
"type": "WEB",
"url": "https://github.com/librenms/librenms/commit/b4af778ca42c5839801f16ece53505bb7fa1e7bc"
@@ -59,6 +63,6 @@
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-11-15T15:39:52Z",
- "nvd_published_at": null
+ "nvd_published_at": "2024-11-15T16:15:35Z"
}
}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/11/GHSA-rmr4-x6c9-jc68/GHSA-rmr4-x6c9-jc68.json b/advisories/github-reviewed/2024/11/GHSA-rmr4-x6c9-jc68/GHSA-rmr4-x6c9-jc68.json
index abadf015377..fc9e690f2cb 100644
--- a/advisories/github-reviewed/2024/11/GHSA-rmr4-x6c9-jc68/GHSA-rmr4-x6c9-jc68.json
+++ b/advisories/github-reviewed/2024/11/GHSA-rmr4-x6c9-jc68/GHSA-rmr4-x6c9-jc68.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rmr4-x6c9-jc68",
- "modified": "2024-11-15T15:28:25Z",
+ "modified": "2024-11-15T20:49:49Z",
"published": "2024-11-15T15:27:42Z",
"aliases": [
"CVE-2024-49764"
@@ -43,6 +43,10 @@
"type": "WEB",
"url": "https://github.com/librenms/librenms/security/advisories/GHSA-rmr4-x6c9-jc68"
},
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49764"
+ },
{
"type": "WEB",
"url": "https://github.com/librenms/librenms/commit/af15eabbb1752985d36f337cecf137a947e170f6"
@@ -59,6 +63,6 @@
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-11-15T15:27:42Z",
- "nvd_published_at": null
+ "nvd_published_at": "2024-11-15T16:15:35Z"
}
}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/11/GHSA-v7w9-63xh-6r3w/GHSA-v7w9-63xh-6r3w.json b/advisories/github-reviewed/2024/11/GHSA-v7w9-63xh-6r3w/GHSA-v7w9-63xh-6r3w.json
index 7105584edb5..164a880c663 100644
--- a/advisories/github-reviewed/2024/11/GHSA-v7w9-63xh-6r3w/GHSA-v7w9-63xh-6r3w.json
+++ b/advisories/github-reviewed/2024/11/GHSA-v7w9-63xh-6r3w/GHSA-v7w9-63xh-6r3w.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v7w9-63xh-6r3w",
- "modified": "2024-11-15T15:34:37Z",
+ "modified": "2024-11-15T20:49:52Z",
"published": "2024-11-15T15:34:36Z",
"aliases": [
"CVE-2024-50351"
@@ -43,6 +43,10 @@
"type": "WEB",
"url": "https://github.com/librenms/librenms/security/advisories/GHSA-v7w9-63xh-6r3w"
},
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50351"
+ },
{
"type": "WEB",
"url": "https://github.com/librenms/librenms/commit/6a14a9bd767c6e452e4df77a24126c3eeb93dcbf"
@@ -59,6 +63,6 @@
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-11-15T15:34:36Z",
- "nvd_published_at": null
+ "nvd_published_at": "2024-11-15T16:15:35Z"
}
}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/11/GHSA-xh4g-c9p6-5jxg/GHSA-xh4g-c9p6-5jxg.json b/advisories/github-reviewed/2024/11/GHSA-xh4g-c9p6-5jxg/GHSA-xh4g-c9p6-5jxg.json
index f742f19142b..560e790b127 100644
--- a/advisories/github-reviewed/2024/11/GHSA-xh4g-c9p6-5jxg/GHSA-xh4g-c9p6-5jxg.json
+++ b/advisories/github-reviewed/2024/11/GHSA-xh4g-c9p6-5jxg/GHSA-xh4g-c9p6-5jxg.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xh4g-c9p6-5jxg",
- "modified": "2024-11-15T15:30:05Z",
+ "modified": "2024-11-15T20:49:50Z",
"published": "2024-11-15T15:30:05Z",
"aliases": [
"CVE-2024-50350"
@@ -43,6 +43,10 @@
"type": "WEB",
"url": "https://github.com/librenms/librenms/security/advisories/GHSA-xh4g-c9p6-5jxg"
},
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50350"
+ },
{
"type": "WEB",
"url": "https://github.com/librenms/librenms/commit/82a744bfe29017b8b58b5752ab9e1b335bedf0a0"
@@ -59,6 +63,6 @@
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-11-15T15:30:05Z",
- "nvd_published_at": null
+ "nvd_published_at": "2024-11-15T16:15:35Z"
}
}
\ No newline at end of file