From 3b2da86314bf7a9254f6cc09766977b0df650060 Mon Sep 17 00:00:00 2001
From: "advisory-database[bot]"
<45398580+advisory-database[bot]@users.noreply.github.com>
Date: Wed, 11 Dec 2024 18:31:58 +0000
Subject: [PATCH] Advisory Database Sync
---
.../GHSA-42j3-j7r2-vj2g.json | 4 +-
.../GHSA-65v5-9w4x-xh53.json | 4 +-
.../GHSA-x2cj-cp2c-fxvp.json | 2 +-
.../GHSA-9hx5-6xv8-6w7c.json | 11 +++--
.../GHSA-qfxp-cg32-f2jj.json | 11 +++--
.../GHSA-vvpf-53qx-cxhh.json | 2 +-
.../GHSA-3jh7-wc4v-w78v.json | 15 +++++--
.../GHSA-4jr3-hwqp-2vq3.json | 15 +++++--
.../GHSA-68m6-x9cq-fjwx.json | 15 +++++--
.../GHSA-85v9-53x3-q4xp.json | 15 +++++--
.../GHSA-9mhh-v2w9-x3xj.json | 15 +++++--
.../GHSA-h234-f9wp-jpmr.json | 15 +++++--
.../GHSA-hmvg-cx6j-hfj7.json | 15 +++++--
.../GHSA-mxqg-3qg8-9qfj.json | 15 +++++--
.../GHSA-rj62-x3fp-f44h.json | 15 +++++--
.../GHSA-w2hj-8f47-3gw5.json | 15 +++++--
.../GHSA-x52v-qr6m-xx85.json | 15 +++++--
.../GHSA-6fvx-97p6-hw44.json | 15 +++++--
.../GHSA-jv48-qx8c-4x4f.json | 15 +++++--
.../GHSA-r5mq-jg2w-g597.json | 11 +++--
.../GHSA-qcfq-rrwc-fg96.json | 4 +-
.../GHSA-639p-pgpg-5qr5.json | 11 +++--
.../GHSA-6q4v-9f44-vxxx.json | 1 +
.../GHSA-rhx4-7vf5-j6rw.json | 15 +++++--
.../GHSA-2fvj-55p5-9gp4.json | 36 +++++++++++++++++
.../GHSA-2hxh-f4xp-4wcj.json | 36 +++++++++++++++++
.../GHSA-33rw-2cg2-2mpc.json | 15 +++++--
.../GHSA-3743-c947-mrhr.json | 15 +++++--
.../GHSA-38h9-g2p9-689w.json | 3 +-
.../GHSA-3q42-g7wg-ggw3.json | 15 +++++--
.../GHSA-3q5q-j6r6-cgv8.json | 15 +++++--
.../GHSA-43mq-6xmg-29vm.json | 34 ++++++++++++++++
.../GHSA-4qf8-xmx7-vj5f.json | 15 +++++--
.../GHSA-4vf8-cqmh-j4f2.json | 19 +++++++--
.../GHSA-4wg6-j4jc-xh8j.json | 15 +++++--
.../GHSA-59r8-jcm7-vx66.json | 11 +++--
.../GHSA-5cj9-rv5c-h66j.json | 15 +++++--
.../GHSA-5cwm-fg2p-g6pp.json | 11 +++--
.../GHSA-5wwr-qqmw-x5rf.json | 15 +++++--
.../GHSA-5xh8-mfhp-x7wc.json | 15 +++++--
.../GHSA-623v-cr64-76w9.json | 11 +++--
.../GHSA-68q5-f84h-346q.json | 15 +++++--
.../GHSA-6gh4-647f-6rr5.json | 15 +++++--
.../GHSA-6hcg-vqw2-35jw.json | 15 +++++--
.../GHSA-6qhw-w3qj-8cf9.json | 15 +++++--
.../GHSA-79r7-f3jp-52j9.json | 15 +++++--
.../GHSA-7gvv-gph6-2hpj.json | 11 +++--
.../GHSA-7pg5-v792-9xv2.json | 31 ++++++++++++++
.../GHSA-7qwr-5g4p-5495.json | 15 +++++--
.../GHSA-7xjp-f5xm-j9vm.json | 15 +++++--
.../GHSA-84hg-pv4v-g5m7.json | 15 +++++--
.../GHSA-856r-5w5p-h874.json | 15 +++++--
.../GHSA-8jvw-w62h-38xj.json | 40 +++++++++++++++++++
.../GHSA-8m4x-x8j4-mx4j.json | 4 +-
.../GHSA-96jh-w5wq-573j.json | 15 +++++--
.../GHSA-9v3f-6pf4-r264.json | 15 +++++--
.../GHSA-c7v4-r383-g2wj.json | 11 +++--
.../GHSA-c8qh-4m7p-p922.json | 15 +++++--
.../GHSA-fvgc-3wm9-ph8c.json | 11 +++--
.../GHSA-g7g9-rh3x-m925.json | 11 +++--
.../GHSA-gm67-5x5w-8f7x.json | 15 +++++--
.../GHSA-hmv6-ggqr-j3vm.json | 15 +++++--
.../GHSA-jq63-f9q2-ph96.json | 35 ++++++++++++++++
.../GHSA-m48f-94xr-79qr.json | 15 +++++--
.../GHSA-m7cw-wqhh-5pr9.json | 15 +++++--
.../GHSA-m9wg-w5mf-5pw9.json | 15 +++++--
.../GHSA-mw8h-4567-xqvj.json | 15 +++++--
.../GHSA-p8jq-vpfm-hqfj.json | 36 +++++++++++++++++
.../GHSA-pc3w-52r9-h2g7.json | 11 +++--
.../GHSA-ph9m-4f8h-q2f7.json | 15 +++++--
.../GHSA-pqj8-xhcx-prxm.json | 15 +++++--
.../GHSA-qch9-x876-gmcw.json | 36 +++++++++++++++++
.../GHSA-qp3v-mjc4-jjf3.json | 15 +++++--
.../GHSA-r8vm-2j4g-7jq3.json | 11 +++--
.../GHSA-rhph-9qcj-jrgq.json | 15 +++++--
.../GHSA-rqmg-x323-7vjh.json | 36 +++++++++++++++++
.../GHSA-rvc2-xvxc-m9fw.json | 3 +-
.../GHSA-v24x-74gw-crvq.json | 15 +++++--
.../GHSA-vh4h-v74p-9778.json | 15 +++++--
.../GHSA-vq37-g99r-q77r.json | 15 +++++--
.../GHSA-vq87-xfrv-42wp.json | 15 +++++--
.../GHSA-w92r-fpr6-76rv.json | 15 +++++--
.../GHSA-wc68-rh2f-56m4.json | 4 +-
.../GHSA-wqvc-3mg4-x25w.json | 15 +++++--
.../GHSA-wxx9-pq23-vg6j.json | 15 +++++--
.../GHSA-x4ww-j464-7jpg.json | 15 +++++--
.../GHSA-x5rh-6m69-mwg4.json | 15 +++++--
.../GHSA-xfmg-7r6x-xpg8.json | 15 +++++--
.../GHSA-xqf3-q69c-jc7c.json | 15 +++++--
.../GHSA-xr7h-9g48-33qf.json | 15 +++++--
90 files changed, 1088 insertions(+), 280 deletions(-)
create mode 100644 advisories/unreviewed/2024/12/GHSA-2fvj-55p5-9gp4/GHSA-2fvj-55p5-9gp4.json
create mode 100644 advisories/unreviewed/2024/12/GHSA-2hxh-f4xp-4wcj/GHSA-2hxh-f4xp-4wcj.json
create mode 100644 advisories/unreviewed/2024/12/GHSA-43mq-6xmg-29vm/GHSA-43mq-6xmg-29vm.json
create mode 100644 advisories/unreviewed/2024/12/GHSA-7pg5-v792-9xv2/GHSA-7pg5-v792-9xv2.json
create mode 100644 advisories/unreviewed/2024/12/GHSA-8jvw-w62h-38xj/GHSA-8jvw-w62h-38xj.json
create mode 100644 advisories/unreviewed/2024/12/GHSA-jq63-f9q2-ph96/GHSA-jq63-f9q2-ph96.json
create mode 100644 advisories/unreviewed/2024/12/GHSA-p8jq-vpfm-hqfj/GHSA-p8jq-vpfm-hqfj.json
create mode 100644 advisories/unreviewed/2024/12/GHSA-qch9-x876-gmcw/GHSA-qch9-x876-gmcw.json
create mode 100644 advisories/unreviewed/2024/12/GHSA-rqmg-x323-7vjh/GHSA-rqmg-x323-7vjh.json
diff --git a/advisories/unreviewed/2023/06/GHSA-42j3-j7r2-vj2g/GHSA-42j3-j7r2-vj2g.json b/advisories/unreviewed/2023/06/GHSA-42j3-j7r2-vj2g/GHSA-42j3-j7r2-vj2g.json
index c64f09fe238..207a2aef1f3 100644
--- a/advisories/unreviewed/2023/06/GHSA-42j3-j7r2-vj2g/GHSA-42j3-j7r2-vj2g.json
+++ b/advisories/unreviewed/2023/06/GHSA-42j3-j7r2-vj2g/GHSA-42j3-j7r2-vj2g.json
@@ -33,7 +33,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-94"
+ ],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2023/06/GHSA-65v5-9w4x-xh53/GHSA-65v5-9w4x-xh53.json b/advisories/unreviewed/2023/06/GHSA-65v5-9w4x-xh53/GHSA-65v5-9w4x-xh53.json
index 351430b78d8..74f6b6e0ad9 100644
--- a/advisories/unreviewed/2023/06/GHSA-65v5-9w4x-xh53/GHSA-65v5-9w4x-xh53.json
+++ b/advisories/unreviewed/2023/06/GHSA-65v5-9w4x-xh53/GHSA-65v5-9w4x-xh53.json
@@ -45,7 +45,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-863"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2023/06/GHSA-x2cj-cp2c-fxvp/GHSA-x2cj-cp2c-fxvp.json b/advisories/unreviewed/2023/06/GHSA-x2cj-cp2c-fxvp/GHSA-x2cj-cp2c-fxvp.json
index 9b8ee368bd9..7bfe41cfc52 100644
--- a/advisories/unreviewed/2023/06/GHSA-x2cj-cp2c-fxvp/GHSA-x2cj-cp2c-fxvp.json
+++ b/advisories/unreviewed/2023/06/GHSA-x2cj-cp2c-fxvp/GHSA-x2cj-cp2c-fxvp.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x2cj-cp2c-fxvp",
- "modified": "2024-04-04T04:56:23Z",
+ "modified": "2024-12-11T18:30:35Z",
"published": "2023-06-19T12:30:21Z",
"aliases": [
"CVE-2023-29531"
diff --git a/advisories/unreviewed/2024/02/GHSA-9hx5-6xv8-6w7c/GHSA-9hx5-6xv8-6w7c.json b/advisories/unreviewed/2024/02/GHSA-9hx5-6xv8-6w7c/GHSA-9hx5-6xv8-6w7c.json
index 07e10bfe1f7..1698c6c55cc 100644
--- a/advisories/unreviewed/2024/02/GHSA-9hx5-6xv8-6w7c/GHSA-9hx5-6xv8-6w7c.json
+++ b/advisories/unreviewed/2024/02/GHSA-9hx5-6xv8-6w7c/GHSA-9hx5-6xv8-6w7c.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9hx5-6xv8-6w7c",
- "modified": "2024-02-28T09:30:36Z",
+ "modified": "2024-12-11T18:30:35Z",
"published": "2024-02-28T09:30:36Z",
"aliases": [
"CVE-2020-36787"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: aspeed: fix clock handling logic\n\nVideo engine uses eclk and vclk for its clock sources and its reset\ncontrol is coupled with eclk so the current clock enabling sequence works\nlike below.\n\n Enable eclk\n De-assert Video Engine reset\n 10ms delay\n Enable vclk\n\nIt introduces improper reset on the Video Engine hardware and eventually\nthe hardware generates unexpected DMA memory transfers that can corrupt\nmemory region in random and sporadic patterns. This issue is observed\nvery rarely on some specific AST2500 SoCs but it causes a critical\nkernel panic with making a various shape of signature so it's extremely\nhard to debug. Moreover, the issue is observed even when the video\nengine is not actively used because udevd turns on the video engine\nhardware for a short time to make a query in every boot.\n\nTo fix this issue, this commit changes the clock handling logic to make\nthe reset de-assertion triggered after enabling both eclk and vclk. Also,\nit adds clk_unprepare call for a case when probe fails.\n\nclk: ast2600: fix reset settings for eclk and vclk\nVideo engine reset setting should be coupled with eclk to match it\nwith the setting for previous Aspeed SoCs which is defined in\nclk-aspeed.c since all Aspeed SoCs are sharing a single video engine\ndriver. Also, reset bit 6 is defined as 'Video Engine' reset in\ndatasheet so it should be de-asserted when eclk is enabled. This\ncommit fixes the setting.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -37,7 +42,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-28T09:15:37Z"
diff --git a/advisories/unreviewed/2024/02/GHSA-qfxp-cg32-f2jj/GHSA-qfxp-cg32-f2jj.json b/advisories/unreviewed/2024/02/GHSA-qfxp-cg32-f2jj/GHSA-qfxp-cg32-f2jj.json
index 03fb46cacdb..114e3022c51 100644
--- a/advisories/unreviewed/2024/02/GHSA-qfxp-cg32-f2jj/GHSA-qfxp-cg32-f2jj.json
+++ b/advisories/unreviewed/2024/02/GHSA-qfxp-cg32-f2jj/GHSA-qfxp-cg32-f2jj.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qfxp-cg32-f2jj",
- "modified": "2024-02-27T21:31:27Z",
+ "modified": "2024-12-11T18:30:35Z",
"published": "2024-02-27T21:31:27Z",
"aliases": [
"CVE-2021-46963"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Fix crash in qla2xxx_mqueuecommand()\n\n RIP: 0010:kmem_cache_free+0xfa/0x1b0\n Call Trace:\n qla2xxx_mqueuecommand+0x2b5/0x2c0 [qla2xxx]\n scsi_queue_rq+0x5e2/0xa40\n __blk_mq_try_issue_directly+0x128/0x1d0\n blk_mq_request_issue_directly+0x4e/0xb0\n\nFix incorrect call to free srb in qla2xxx_mqueuecommand(), as srb is now\nallocated by upper layers. This fixes smatch warning of srb unintended\nfree.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -41,7 +46,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-27T19:04:07Z"
diff --git a/advisories/unreviewed/2024/02/GHSA-vvpf-53qx-cxhh/GHSA-vvpf-53qx-cxhh.json b/advisories/unreviewed/2024/02/GHSA-vvpf-53qx-cxhh/GHSA-vvpf-53qx-cxhh.json
index cbb877bd53c..66cdfa23a0e 100644
--- a/advisories/unreviewed/2024/02/GHSA-vvpf-53qx-cxhh/GHSA-vvpf-53qx-cxhh.json
+++ b/advisories/unreviewed/2024/02/GHSA-vvpf-53qx-cxhh/GHSA-vvpf-53qx-cxhh.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vvpf-53qx-cxhh",
- "modified": "2024-02-20T15:31:03Z",
+ "modified": "2024-12-11T18:30:35Z",
"published": "2024-02-20T15:31:03Z",
"aliases": [
"CVE-2024-25610"
diff --git a/advisories/unreviewed/2024/03/GHSA-3jh7-wc4v-w78v/GHSA-3jh7-wc4v-w78v.json b/advisories/unreviewed/2024/03/GHSA-3jh7-wc4v-w78v/GHSA-3jh7-wc4v-w78v.json
index a62722a034a..9df728998d4 100644
--- a/advisories/unreviewed/2024/03/GHSA-3jh7-wc4v-w78v/GHSA-3jh7-wc4v-w78v.json
+++ b/advisories/unreviewed/2024/03/GHSA-3jh7-wc4v-w78v/GHSA-3jh7-wc4v-w78v.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3jh7-wc4v-w78v",
- "modified": "2024-03-03T00:30:32Z",
+ "modified": "2024-12-11T18:30:36Z",
"published": "2024-03-03T00:30:32Z",
"aliases": [
"CVE-2023-52578"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bridge: use DEV_STATS_INC()\n\nsyzbot/KCSAN reported data-races in br_handle_frame_finish() [1]\nThis function can run from multiple cpus without mutual exclusion.\n\nAdopt SMP safe DEV_STATS_INC() to update dev->stats fields.\n\nHandles updates to dev->stats.tx_dropped while we are at it.\n\n[1]\nBUG: KCSAN: data-race in br_handle_frame_finish / br_handle_frame_finish\n\nread-write to 0xffff8881374b2178 of 8 bytes by interrupt on cpu 1:\nbr_handle_frame_finish+0xd4f/0xef0 net/bridge/br_input.c:189\nbr_nf_hook_thresh+0x1ed/0x220\nbr_nf_pre_routing_finish_ipv6+0x50f/0x540\nNF_HOOK include/linux/netfilter.h:304 [inline]\nbr_nf_pre_routing_ipv6+0x1e3/0x2a0 net/bridge/br_netfilter_ipv6.c:178\nbr_nf_pre_routing+0x526/0xba0 net/bridge/br_netfilter_hooks.c:508\nnf_hook_entry_hookfn include/linux/netfilter.h:144 [inline]\nnf_hook_bridge_pre net/bridge/br_input.c:272 [inline]\nbr_handle_frame+0x4c9/0x940 net/bridge/br_input.c:417\n__netif_receive_skb_core+0xa8a/0x21e0 net/core/dev.c:5417\n__netif_receive_skb_one_core net/core/dev.c:5521 [inline]\n__netif_receive_skb+0x57/0x1b0 net/core/dev.c:5637\nprocess_backlog+0x21f/0x380 net/core/dev.c:5965\n__napi_poll+0x60/0x3b0 net/core/dev.c:6527\nnapi_poll net/core/dev.c:6594 [inline]\nnet_rx_action+0x32b/0x750 net/core/dev.c:6727\n__do_softirq+0xc1/0x265 kernel/softirq.c:553\nrun_ksoftirqd+0x17/0x20 kernel/softirq.c:921\nsmpboot_thread_fn+0x30a/0x4a0 kernel/smpboot.c:164\nkthread+0x1d7/0x210 kernel/kthread.c:388\nret_from_fork+0x48/0x60 arch/x86/kernel/process.c:147\nret_from_fork_asm+0x11/0x20 arch/x86/entry/entry_64.S:304\n\nread-write to 0xffff8881374b2178 of 8 bytes by interrupt on cpu 0:\nbr_handle_frame_finish+0xd4f/0xef0 net/bridge/br_input.c:189\nbr_nf_hook_thresh+0x1ed/0x220\nbr_nf_pre_routing_finish_ipv6+0x50f/0x540\nNF_HOOK include/linux/netfilter.h:304 [inline]\nbr_nf_pre_routing_ipv6+0x1e3/0x2a0 net/bridge/br_netfilter_ipv6.c:178\nbr_nf_pre_routing+0x526/0xba0 net/bridge/br_netfilter_hooks.c:508\nnf_hook_entry_hookfn include/linux/netfilter.h:144 [inline]\nnf_hook_bridge_pre net/bridge/br_input.c:272 [inline]\nbr_handle_frame+0x4c9/0x940 net/bridge/br_input.c:417\n__netif_receive_skb_core+0xa8a/0x21e0 net/core/dev.c:5417\n__netif_receive_skb_one_core net/core/dev.c:5521 [inline]\n__netif_receive_skb+0x57/0x1b0 net/core/dev.c:5637\nprocess_backlog+0x21f/0x380 net/core/dev.c:5965\n__napi_poll+0x60/0x3b0 net/core/dev.c:6527\nnapi_poll net/core/dev.c:6594 [inline]\nnet_rx_action+0x32b/0x750 net/core/dev.c:6727\n__do_softirq+0xc1/0x265 kernel/softirq.c:553\ndo_softirq+0x5e/0x90 kernel/softirq.c:454\n__local_bh_enable_ip+0x64/0x70 kernel/softirq.c:381\n__raw_spin_unlock_bh include/linux/spinlock_api_smp.h:167 [inline]\n_raw_spin_unlock_bh+0x36/0x40 kernel/locking/spinlock.c:210\nspin_unlock_bh include/linux/spinlock.h:396 [inline]\nbatadv_tt_local_purge+0x1a8/0x1f0 net/batman-adv/translation-table.c:1356\nbatadv_tt_purge+0x2b/0x630 net/batman-adv/translation-table.c:3560\nprocess_one_work kernel/workqueue.c:2630 [inline]\nprocess_scheduled_works+0x5b8/0xa30 kernel/workqueue.c:2703\nworker_thread+0x525/0x730 kernel/workqueue.c:2784\nkthread+0x1d7/0x210 kernel/kthread.c:388\nret_from_fork+0x48/0x60 arch/x86/kernel/process.c:147\nret_from_fork_asm+0x11/0x20 arch/x86/entry/entry_64.S:304\n\nvalue changed: 0x00000000000d7190 -> 0x00000000000d7191\n\nReported by Kernel Concurrency Sanitizer on:\nCPU: 0 PID: 14848 Comm: kworker/u4:11 Not tainted 6.6.0-rc1-syzkaller-00236-gad8a69f361b9 #0",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -44,8 +49,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-362"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-02T22:15:49Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-4jr3-hwqp-2vq3/GHSA-4jr3-hwqp-2vq3.json b/advisories/unreviewed/2024/03/GHSA-4jr3-hwqp-2vq3/GHSA-4jr3-hwqp-2vq3.json
index 3bf4cd28778..bd124523ce3 100644
--- a/advisories/unreviewed/2024/03/GHSA-4jr3-hwqp-2vq3/GHSA-4jr3-hwqp-2vq3.json
+++ b/advisories/unreviewed/2024/03/GHSA-4jr3-hwqp-2vq3/GHSA-4jr3-hwqp-2vq3.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4jr3-hwqp-2vq3",
- "modified": "2024-03-03T00:30:31Z",
+ "modified": "2024-12-11T18:30:36Z",
"published": "2024-03-03T00:30:31Z",
"aliases": [
"CVE-2023-52516"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndma-debug: don't call __dma_entry_alloc_check_leak() under free_entries_lock\n\n__dma_entry_alloc_check_leak() calls into printk -> serial console\noutput (qcom geni) and grabs port->lock under free_entries_lock\nspin lock, which is a reverse locking dependency chain as qcom_geni\nIRQ handler can call into dma-debug code and grab free_entries_lock\nunder port->lock.\n\nMove __dma_entry_alloc_check_leak() call out of free_entries_lock\nscope so that we don't acquire serial console's port->lock under it.\n\nTrimmed-down lockdep splat:\n\n The existing dependency chain (in reverse order) is:\n\n -> #2 (free_entries_lock){-.-.}-{2:2}:\n _raw_spin_lock_irqsave+0x60/0x80\n dma_entry_alloc+0x38/0x110\n debug_dma_map_page+0x60/0xf8\n dma_map_page_attrs+0x1e0/0x230\n dma_map_single_attrs.constprop.0+0x6c/0xc8\n geni_se_rx_dma_prep+0x40/0xcc\n qcom_geni_serial_isr+0x310/0x510\n __handle_irq_event_percpu+0x110/0x244\n handle_irq_event_percpu+0x20/0x54\n handle_irq_event+0x50/0x88\n handle_fasteoi_irq+0xa4/0xcc\n handle_irq_desc+0x28/0x40\n generic_handle_domain_irq+0x24/0x30\n gic_handle_irq+0xc4/0x148\n do_interrupt_handler+0xa4/0xb0\n el1_interrupt+0x34/0x64\n el1h_64_irq_handler+0x18/0x24\n el1h_64_irq+0x64/0x68\n arch_local_irq_enable+0x4/0x8\n ____do_softirq+0x18/0x24\n ...\n\n -> #1 (&port_lock_key){-.-.}-{2:2}:\n _raw_spin_lock_irqsave+0x60/0x80\n qcom_geni_serial_console_write+0x184/0x1dc\n console_flush_all+0x344/0x454\n console_unlock+0x94/0xf0\n vprintk_emit+0x238/0x24c\n vprintk_default+0x3c/0x48\n vprintk+0xb4/0xbc\n _printk+0x68/0x90\n register_console+0x230/0x38c\n uart_add_one_port+0x338/0x494\n qcom_geni_serial_probe+0x390/0x424\n platform_probe+0x70/0xc0\n really_probe+0x148/0x280\n __driver_probe_device+0xfc/0x114\n driver_probe_device+0x44/0x100\n __device_attach_driver+0x64/0xdc\n bus_for_each_drv+0xb0/0xd8\n __device_attach+0xe4/0x140\n device_initial_probe+0x1c/0x28\n bus_probe_device+0x44/0xb0\n device_add+0x538/0x668\n of_device_add+0x44/0x50\n of_platform_device_create_pdata+0x94/0xc8\n of_platform_bus_create+0x270/0x304\n of_platform_populate+0xac/0xc4\n devm_of_platform_populate+0x60/0xac\n geni_se_probe+0x154/0x160\n platform_probe+0x70/0xc0\n ...\n\n -> #0 (console_owner){-...}-{0:0}:\n __lock_acquire+0xdf8/0x109c\n lock_acquire+0x234/0x284\n console_flush_all+0x330/0x454\n console_unlock+0x94/0xf0\n vprintk_emit+0x238/0x24c\n vprintk_default+0x3c/0x48\n vprintk+0xb4/0xbc\n _printk+0x68/0x90\n dma_entry_alloc+0xb4/0x110\n debug_dma_map_sg+0xdc/0x2f8\n __dma_map_sg_attrs+0xac/0xe4\n dma_map_sgtable+0x30/0x4c\n get_pages+0x1d4/0x1e4 [msm]\n msm_gem_pin_pages_locked+0x38/0xac [msm]\n msm_gem_pin_vma_locked+0x58/0x88 [msm]\n msm_ioctl_gem_submit+0xde4/0x13ac [msm]\n drm_ioctl_kernel+0xe0/0x15c\n drm_ioctl+0x2e8/0x3f4\n vfs_ioctl+0x30/0x50\n ...\n\n Chain exists of:\n console_owner --> &port_lock_key --> free_entries_lock\n\n Possible unsafe locking scenario:\n\n CPU0 CPU1\n ---- ----\n lock(free_entries_lock);\n lock(&port_lock_key);\n lock(free_entries_lock);\n lock(console_owner);\n\n *** DEADLOCK ***\n\n Call trace:\n dump_backtrace+0xb4/0xf0\n show_stack+0x20/0x30\n dump_stack_lvl+0x60/0x84\n dump_stack+0x18/0x24\n print_circular_bug+0x1cc/0x234\n check_noncircular+0x78/0xac\n __lock_acquire+0xdf8/0x109c\n lock_acquire+0x234/0x284\n console_flush_all+0x330/0x454\n consol\n---truncated---",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-667"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-02T22:15:47Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-68m6-x9cq-fjwx/GHSA-68m6-x9cq-fjwx.json b/advisories/unreviewed/2024/03/GHSA-68m6-x9cq-fjwx/GHSA-68m6-x9cq-fjwx.json
index 5aa47202585..e8c2c5119eb 100644
--- a/advisories/unreviewed/2024/03/GHSA-68m6-x9cq-fjwx/GHSA-68m6-x9cq-fjwx.json
+++ b/advisories/unreviewed/2024/03/GHSA-68m6-x9cq-fjwx/GHSA-68m6-x9cq-fjwx.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-68m6-x9cq-fjwx",
- "modified": "2024-03-03T00:30:32Z",
+ "modified": "2024-12-11T18:30:36Z",
"published": "2024-03-03T00:30:32Z",
"aliases": [
"CVE-2023-52567"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nserial: 8250_port: Check IRQ data before use\n\nIn case the leaf driver wants to use IRQ polling (irq = 0) and\nIIR register shows that an interrupt happened in the 8250 hardware\nthe IRQ data can be NULL. In such a case we need to skip the wake\nevent as we came to this path from the timer interrupt and quite\nlikely system is already awake.\n\nWithout this fix we have got an Oops:\n\n serial8250: ttyS0 at I/O 0x3f8 (irq = 0, base_baud = 115200) is a 16550A\n ...\n BUG: kernel NULL pointer dereference, address: 0000000000000010\n RIP: 0010:serial8250_handle_irq+0x7c/0x240\n Call Trace:\n ? serial8250_handle_irq+0x7c/0x240\n ? __pfx_serial8250_timeout+0x10/0x10",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-02T22:15:49Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-85v9-53x3-q4xp/GHSA-85v9-53x3-q4xp.json b/advisories/unreviewed/2024/03/GHSA-85v9-53x3-q4xp/GHSA-85v9-53x3-q4xp.json
index 4ff13b04367..041042bd14d 100644
--- a/advisories/unreviewed/2024/03/GHSA-85v9-53x3-q4xp/GHSA-85v9-53x3-q4xp.json
+++ b/advisories/unreviewed/2024/03/GHSA-85v9-53x3-q4xp/GHSA-85v9-53x3-q4xp.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-85v9-53x3-q4xp",
- "modified": "2024-04-04T15:30:33Z",
+ "modified": "2024-12-11T18:30:36Z",
"published": "2024-03-03T00:30:32Z",
"aliases": [
"CVE-2023-52577"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndccp: fix dccp_v4_err()/dccp_v6_err() again\n\ndh->dccph_x is the 9th byte (offset 8) in \"struct dccp_hdr\",\nnot in the \"byte 7\" as Jann claimed.\n\nWe need to make sure the ICMP messages are big enough,\nusing more standard ways (no more assumptions).\n\nsyzbot reported:\nBUG: KMSAN: uninit-value in pskb_may_pull_reason include/linux/skbuff.h:2667 [inline]\nBUG: KMSAN: uninit-value in pskb_may_pull include/linux/skbuff.h:2681 [inline]\nBUG: KMSAN: uninit-value in dccp_v6_err+0x426/0x1aa0 net/dccp/ipv6.c:94\npskb_may_pull_reason include/linux/skbuff.h:2667 [inline]\npskb_may_pull include/linux/skbuff.h:2681 [inline]\ndccp_v6_err+0x426/0x1aa0 net/dccp/ipv6.c:94\nicmpv6_notify+0x4c7/0x880 net/ipv6/icmp.c:867\nicmpv6_rcv+0x19d5/0x30d0\nip6_protocol_deliver_rcu+0xda6/0x2a60 net/ipv6/ip6_input.c:438\nip6_input_finish net/ipv6/ip6_input.c:483 [inline]\nNF_HOOK include/linux/netfilter.h:304 [inline]\nip6_input+0x15d/0x430 net/ipv6/ip6_input.c:492\nip6_mc_input+0xa7e/0xc80 net/ipv6/ip6_input.c:586\ndst_input include/net/dst.h:468 [inline]\nip6_rcv_finish+0x5db/0x870 net/ipv6/ip6_input.c:79\nNF_HOOK include/linux/netfilter.h:304 [inline]\nipv6_rcv+0xda/0x390 net/ipv6/ip6_input.c:310\n__netif_receive_skb_one_core net/core/dev.c:5523 [inline]\n__netif_receive_skb+0x1a6/0x5a0 net/core/dev.c:5637\nnetif_receive_skb_internal net/core/dev.c:5723 [inline]\nnetif_receive_skb+0x58/0x660 net/core/dev.c:5782\ntun_rx_batched+0x83b/0x920\ntun_get_user+0x564c/0x6940 drivers/net/tun.c:2002\ntun_chr_write_iter+0x3af/0x5d0 drivers/net/tun.c:2048\ncall_write_iter include/linux/fs.h:1985 [inline]\nnew_sync_write fs/read_write.c:491 [inline]\nvfs_write+0x8ef/0x15c0 fs/read_write.c:584\nksys_write+0x20f/0x4c0 fs/read_write.c:637\n__do_sys_write fs/read_write.c:649 [inline]\n__se_sys_write fs/read_write.c:646 [inline]\n__x64_sys_write+0x93/0xd0 fs/read_write.c:646\ndo_syscall_x64 arch/x86/entry/common.c:50 [inline]\ndo_syscall_64+0x41/0xc0 arch/x86/entry/common.c:80\nentry_SYSCALL_64_after_hwframe+0x63/0xcd\n\nUninit was created at:\nslab_post_alloc_hook+0x12f/0xb70 mm/slab.h:767\nslab_alloc_node mm/slub.c:3478 [inline]\nkmem_cache_alloc_node+0x577/0xa80 mm/slub.c:3523\nkmalloc_reserve+0x13d/0x4a0 net/core/skbuff.c:559\n__alloc_skb+0x318/0x740 net/core/skbuff.c:650\nalloc_skb include/linux/skbuff.h:1286 [inline]\nalloc_skb_with_frags+0xc8/0xbd0 net/core/skbuff.c:6313\nsock_alloc_send_pskb+0xa80/0xbf0 net/core/sock.c:2795\ntun_alloc_skb drivers/net/tun.c:1531 [inline]\ntun_get_user+0x23cf/0x6940 drivers/net/tun.c:1846\ntun_chr_write_iter+0x3af/0x5d0 drivers/net/tun.c:2048\ncall_write_iter include/linux/fs.h:1985 [inline]\nnew_sync_write fs/read_write.c:491 [inline]\nvfs_write+0x8ef/0x15c0 fs/read_write.c:584\nksys_write+0x20f/0x4c0 fs/read_write.c:637\n__do_sys_write fs/read_write.c:649 [inline]\n__se_sys_write fs/read_write.c:646 [inline]\n__x64_sys_write+0x93/0xd0 fs/read_write.c:646\ndo_syscall_x64 arch/x86/entry/common.c:50 [inline]\ndo_syscall_64+0x41/0xc0 arch/x86/entry/common.c:80\nentry_SYSCALL_64_after_hwframe+0x63/0xcd\n\nCPU: 0 PID: 4995 Comm: syz-executor153 Not tainted 6.6.0-rc1-syzkaller-00014-ga747acc0b752 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/04/2023",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-908"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-02T22:15:49Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-9mhh-v2w9-x3xj/GHSA-9mhh-v2w9-x3xj.json b/advisories/unreviewed/2024/03/GHSA-9mhh-v2w9-x3xj/GHSA-9mhh-v2w9-x3xj.json
index e809009ca34..c4baa4687cf 100644
--- a/advisories/unreviewed/2024/03/GHSA-9mhh-v2w9-x3xj/GHSA-9mhh-v2w9-x3xj.json
+++ b/advisories/unreviewed/2024/03/GHSA-9mhh-v2w9-x3xj/GHSA-9mhh-v2w9-x3xj.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9mhh-v2w9-x3xj",
- "modified": "2024-03-03T00:30:31Z",
+ "modified": "2024-12-11T18:30:35Z",
"published": "2024-03-03T00:30:31Z",
"aliases": [
"CVE-2023-52515"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/srp: Do not call scsi_done() from srp_abort()\n\nAfter scmd_eh_abort_handler() has called the SCSI LLD eh_abort_handler\ncallback, it performs one of the following actions:\n* Call scsi_queue_insert().\n* Call scsi_finish_command().\n* Call scsi_eh_scmd_add().\nHence, SCSI abort handlers must not call scsi_done(). Otherwise all\nthe above actions would trigger a use-after-free. Hence remove the\nscsi_done() call from srp_abort(). Keep the srp_free_req() call\nbefore returning SUCCESS because we may not see the command again if\nSUCCESS is returned.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-02T22:15:47Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-h234-f9wp-jpmr/GHSA-h234-f9wp-jpmr.json b/advisories/unreviewed/2024/03/GHSA-h234-f9wp-jpmr/GHSA-h234-f9wp-jpmr.json
index 9f52fbe89a3..6ff3b06874b 100644
--- a/advisories/unreviewed/2024/03/GHSA-h234-f9wp-jpmr/GHSA-h234-f9wp-jpmr.json
+++ b/advisories/unreviewed/2024/03/GHSA-h234-f9wp-jpmr/GHSA-h234-f9wp-jpmr.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h234-f9wp-jpmr",
- "modified": "2024-03-03T00:30:32Z",
+ "modified": "2024-12-11T18:30:36Z",
"published": "2024-03-03T00:30:32Z",
"aliases": [
"CVE-2023-52528"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: smsc75xx: Fix uninit-value access in __smsc75xx_read_reg\n\nsyzbot reported the following uninit-value access issue:\n\n=====================================================\nBUG: KMSAN: uninit-value in smsc75xx_wait_ready drivers/net/usb/smsc75xx.c:975 [inline]\nBUG: KMSAN: uninit-value in smsc75xx_bind+0x5c9/0x11e0 drivers/net/usb/smsc75xx.c:1482\nCPU: 0 PID: 8696 Comm: kworker/0:3 Not tainted 5.8.0-rc5-syzkaller #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011\nWorkqueue: usb_hub_wq hub_event\nCall Trace:\n __dump_stack lib/dump_stack.c:77 [inline]\n dump_stack+0x21c/0x280 lib/dump_stack.c:118\n kmsan_report+0xf7/0x1e0 mm/kmsan/kmsan_report.c:121\n __msan_warning+0x58/0xa0 mm/kmsan/kmsan_instr.c:215\n smsc75xx_wait_ready drivers/net/usb/smsc75xx.c:975 [inline]\n smsc75xx_bind+0x5c9/0x11e0 drivers/net/usb/smsc75xx.c:1482\n usbnet_probe+0x1152/0x3f90 drivers/net/usb/usbnet.c:1737\n usb_probe_interface+0xece/0x1550 drivers/usb/core/driver.c:374\n really_probe+0xf20/0x20b0 drivers/base/dd.c:529\n driver_probe_device+0x293/0x390 drivers/base/dd.c:701\n __device_attach_driver+0x63f/0x830 drivers/base/dd.c:807\n bus_for_each_drv+0x2ca/0x3f0 drivers/base/bus.c:431\n __device_attach+0x4e2/0x7f0 drivers/base/dd.c:873\n device_initial_probe+0x4a/0x60 drivers/base/dd.c:920\n bus_probe_device+0x177/0x3d0 drivers/base/bus.c:491\n device_add+0x3b0e/0x40d0 drivers/base/core.c:2680\n usb_set_configuration+0x380f/0x3f10 drivers/usb/core/message.c:2032\n usb_generic_driver_probe+0x138/0x300 drivers/usb/core/generic.c:241\n usb_probe_device+0x311/0x490 drivers/usb/core/driver.c:272\n really_probe+0xf20/0x20b0 drivers/base/dd.c:529\n driver_probe_device+0x293/0x390 drivers/base/dd.c:701\n __device_attach_driver+0x63f/0x830 drivers/base/dd.c:807\n bus_for_each_drv+0x2ca/0x3f0 drivers/base/bus.c:431\n __device_attach+0x4e2/0x7f0 drivers/base/dd.c:873\n device_initial_probe+0x4a/0x60 drivers/base/dd.c:920\n bus_probe_device+0x177/0x3d0 drivers/base/bus.c:491\n device_add+0x3b0e/0x40d0 drivers/base/core.c:2680\n usb_new_device+0x1bd4/0x2a30 drivers/usb/core/hub.c:2554\n hub_port_connect drivers/usb/core/hub.c:5208 [inline]\n hub_port_connect_change drivers/usb/core/hub.c:5348 [inline]\n port_event drivers/usb/core/hub.c:5494 [inline]\n hub_event+0x5e7b/0x8a70 drivers/usb/core/hub.c:5576\n process_one_work+0x1688/0x2140 kernel/workqueue.c:2269\n worker_thread+0x10bc/0x2730 kernel/workqueue.c:2415\n kthread+0x551/0x590 kernel/kthread.c:292\n ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:293\n\nLocal variable ----buf.i87@smsc75xx_bind created at:\n __smsc75xx_read_reg drivers/net/usb/smsc75xx.c:83 [inline]\n smsc75xx_wait_ready drivers/net/usb/smsc75xx.c:968 [inline]\n smsc75xx_bind+0x485/0x11e0 drivers/net/usb/smsc75xx.c:1482\n __smsc75xx_read_reg drivers/net/usb/smsc75xx.c:83 [inline]\n smsc75xx_wait_ready drivers/net/usb/smsc75xx.c:968 [inline]\n smsc75xx_bind+0x485/0x11e0 drivers/net/usb/smsc75xx.c:1482\n\nThis issue is caused because usbnet_read_cmd() reads less bytes than requested\n(zero byte in the reproducer). In this case, 'buf' is not properly filled.\n\nThis patch fixes the issue by returning -ENODATA if usbnet_read_cmd() reads\nless bytes than requested.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-908"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-02T22:15:48Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-hmvg-cx6j-hfj7/GHSA-hmvg-cx6j-hfj7.json b/advisories/unreviewed/2024/03/GHSA-hmvg-cx6j-hfj7/GHSA-hmvg-cx6j-hfj7.json
index 5063f604768..1bda2b7aab0 100644
--- a/advisories/unreviewed/2024/03/GHSA-hmvg-cx6j-hfj7/GHSA-hmvg-cx6j-hfj7.json
+++ b/advisories/unreviewed/2024/03/GHSA-hmvg-cx6j-hfj7/GHSA-hmvg-cx6j-hfj7.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hmvg-cx6j-hfj7",
- "modified": "2024-06-26T00:31:35Z",
+ "modified": "2024-12-11T18:30:36Z",
"published": "2024-03-04T09:30:29Z",
"aliases": [
"CVE-2024-26622"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntomoyo: fix UAF write bug in tomoyo_write_control()\n\nSince tomoyo_write_control() updates head->write_buf when write()\nof long lines is requested, we need to fetch head->write_buf after\nhead->io_sem is held. Otherwise, concurrent write() requests can\ncause use-after-free-write and double-free problems.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -52,8 +57,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-04T07:15:11Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-mxqg-3qg8-9qfj/GHSA-mxqg-3qg8-9qfj.json b/advisories/unreviewed/2024/03/GHSA-mxqg-3qg8-9qfj/GHSA-mxqg-3qg8-9qfj.json
index b1366ee7633..86f0f7b98b7 100644
--- a/advisories/unreviewed/2024/03/GHSA-mxqg-3qg8-9qfj/GHSA-mxqg-3qg8-9qfj.json
+++ b/advisories/unreviewed/2024/03/GHSA-mxqg-3qg8-9qfj/GHSA-mxqg-3qg8-9qfj.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mxqg-3qg8-9qfj",
- "modified": "2024-03-03T00:30:32Z",
+ "modified": "2024-12-11T18:30:36Z",
"published": "2024-03-03T00:30:32Z",
"aliases": [
"CVE-2023-52568"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/sgx: Resolves SECS reclaim vs. page fault for EAUG race\n\nThe SGX EPC reclaimer (ksgxd) may reclaim the SECS EPC page for an\nenclave and set secs.epc_page to NULL. The SECS page is used for EAUG\nand ELDU in the SGX page fault handler. However, the NULL check for\nsecs.epc_page is only done for ELDU, not EAUG before being used.\n\nFix this by doing the same NULL check and reloading of the SECS page as\nneeded for both EAUG and ELDU.\n\nThe SECS page holds global enclave metadata. It can only be reclaimed\nwhen there are no other enclave pages remaining. At that point,\nvirtually nothing can be done with the enclave until the SECS page is\npaged back in.\n\nAn enclave can not run nor generate page faults without a resident SECS\npage. But it is still possible for a #PF for a non-SECS page to race\nwith paging out the SECS page: when the last resident non-SECS page A\ntriggers a #PF in a non-resident page B, and then page A and the SECS\nboth are paged out before the #PF on B is handled.\n\nHitting this bug requires that race triggered with a #PF for EAUG.\nFollowing is a trace when it happens.\n\nBUG: kernel NULL pointer dereference, address: 0000000000000000\nRIP: 0010:sgx_encl_eaug_page+0xc7/0x210\nCall Trace:\n ? __kmem_cache_alloc_node+0x16a/0x440\n ? xa_load+0x6e/0xa0\n sgx_vma_fault+0x119/0x230\n __do_fault+0x36/0x140\n do_fault+0x12f/0x400\n __handle_mm_fault+0x728/0x1110\n handle_mm_fault+0x105/0x310\n do_user_addr_fault+0x1ee/0x750\n ? __this_cpu_preempt_check+0x13/0x20\n exc_page_fault+0x76/0x180\n asm_exc_page_fault+0x27/0x30",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-02T22:15:49Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-rj62-x3fp-f44h/GHSA-rj62-x3fp-f44h.json b/advisories/unreviewed/2024/03/GHSA-rj62-x3fp-f44h/GHSA-rj62-x3fp-f44h.json
index cdca2f3ac59..82f94eaadd4 100644
--- a/advisories/unreviewed/2024/03/GHSA-rj62-x3fp-f44h/GHSA-rj62-x3fp-f44h.json
+++ b/advisories/unreviewed/2024/03/GHSA-rj62-x3fp-f44h/GHSA-rj62-x3fp-f44h.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rj62-x3fp-f44h",
- "modified": "2024-03-03T00:30:32Z",
+ "modified": "2024-12-11T18:30:36Z",
"published": "2024-03-03T00:30:32Z",
"aliases": [
"CVE-2023-52572"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: Fix UAF in cifs_demultiplex_thread()\n\nThere is a UAF when xfstests on cifs:\n\n BUG: KASAN: use-after-free in smb2_is_network_name_deleted+0x27/0x160\n Read of size 4 at addr ffff88810103fc08 by task cifsd/923\n\n CPU: 1 PID: 923 Comm: cifsd Not tainted 6.1.0-rc4+ #45\n ...\n Call Trace:\n \n dump_stack_lvl+0x34/0x44\n print_report+0x171/0x472\n kasan_report+0xad/0x130\n kasan_check_range+0x145/0x1a0\n smb2_is_network_name_deleted+0x27/0x160\n cifs_demultiplex_thread.cold+0x172/0x5a4\n kthread+0x165/0x1a0\n ret_from_fork+0x1f/0x30\n \n\n Allocated by task 923:\n kasan_save_stack+0x1e/0x40\n kasan_set_track+0x21/0x30\n __kasan_slab_alloc+0x54/0x60\n kmem_cache_alloc+0x147/0x320\n mempool_alloc+0xe1/0x260\n cifs_small_buf_get+0x24/0x60\n allocate_buffers+0xa1/0x1c0\n cifs_demultiplex_thread+0x199/0x10d0\n kthread+0x165/0x1a0\n ret_from_fork+0x1f/0x30\n\n Freed by task 921:\n kasan_save_stack+0x1e/0x40\n kasan_set_track+0x21/0x30\n kasan_save_free_info+0x2a/0x40\n ____kasan_slab_free+0x143/0x1b0\n kmem_cache_free+0xe3/0x4d0\n cifs_small_buf_release+0x29/0x90\n SMB2_negotiate+0x8b7/0x1c60\n smb2_negotiate+0x51/0x70\n cifs_negotiate_protocol+0xf0/0x160\n cifs_get_smb_ses+0x5fa/0x13c0\n mount_get_conns+0x7a/0x750\n cifs_mount+0x103/0xd00\n cifs_smb3_do_mount+0x1dd/0xcb0\n smb3_get_tree+0x1d5/0x300\n vfs_get_tree+0x41/0xf0\n path_mount+0x9b3/0xdd0\n __x64_sys_mount+0x190/0x1d0\n do_syscall_64+0x35/0x80\n entry_SYSCALL_64_after_hwframe+0x46/0xb0\n\nThe UAF is because:\n\n mount(pid: 921) | cifsd(pid: 923)\n-------------------------------|-------------------------------\n | cifs_demultiplex_thread\nSMB2_negotiate |\n cifs_send_recv |\n compound_send_recv |\n smb_send_rqst |\n wait_for_response |\n wait_event_state [1] |\n | standard_receive3\n | cifs_handle_standard\n | handle_mid\n | mid->resp_buf = buf; [2]\n | dequeue_mid [3]\n KILL the process [4] |\n resp_iov[i].iov_base = buf |\n free_rsp_buf [5] |\n | is_network_name_deleted [6]\n | callback\n\n1. After send request to server, wait the response until\n mid->mid_state != SUBMITTED;\n2. Receive response from server, and set it to mid;\n3. Set the mid state to RECEIVED;\n4. Kill the process, the mid state already RECEIVED, get 0;\n5. Handle and release the negotiate response;\n6. UAF.\n\nIt can be easily reproduce with add some delay in [3] - [6].\n\nOnly sync call has the problem since async call's callback is\nexecuted in cifsd process.\n\nAdd an extra state to mark the mid state to READY before wakeup the\nwaitter, then it can get the resp safely.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-02T22:15:49Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-w2hj-8f47-3gw5/GHSA-w2hj-8f47-3gw5.json b/advisories/unreviewed/2024/03/GHSA-w2hj-8f47-3gw5/GHSA-w2hj-8f47-3gw5.json
index 136a805bf3d..a6b4f80e585 100644
--- a/advisories/unreviewed/2024/03/GHSA-w2hj-8f47-3gw5/GHSA-w2hj-8f47-3gw5.json
+++ b/advisories/unreviewed/2024/03/GHSA-w2hj-8f47-3gw5/GHSA-w2hj-8f47-3gw5.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w2hj-8f47-3gw5",
- "modified": "2024-11-08T18:30:42Z",
+ "modified": "2024-12-11T18:30:36Z",
"published": "2024-03-03T00:30:32Z",
"aliases": [
"CVE-2023-52530"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix potential key use-after-free\n\nWhen ieee80211_key_link() is called by ieee80211_gtk_rekey_add()\nbut returns 0 due to KRACK protection (identical key reinstall),\nieee80211_gtk_rekey_add() will still return a pointer into the\nkey, in a potential use-after-free. This normally doesn't happen\nsince it's only called by iwlwifi in case of WoWLAN rekey offload\nwhich has its own KRACK protection, but still better to fix, do\nthat by returning an error code and converting that to success on\nthe cfg80211 boundary only, leaving the error for bad callers of\nieee80211_gtk_rekey_add().",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -40,8 +45,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-02T22:15:48Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-x52v-qr6m-xx85/GHSA-x52v-qr6m-xx85.json b/advisories/unreviewed/2024/05/GHSA-x52v-qr6m-xx85/GHSA-x52v-qr6m-xx85.json
index 66227a9271f..307a97af28f 100644
--- a/advisories/unreviewed/2024/05/GHSA-x52v-qr6m-xx85/GHSA-x52v-qr6m-xx85.json
+++ b/advisories/unreviewed/2024/05/GHSA-x52v-qr6m-xx85/GHSA-x52v-qr6m-xx85.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x52v-qr6m-xx85",
- "modified": "2024-05-21T15:31:38Z",
+ "modified": "2024-12-11T18:30:36Z",
"published": "2024-05-21T15:31:38Z",
"aliases": [
"CVE-2020-36788"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/nouveau: avoid a use-after-free when BO init fails\n\nnouveau_bo_init() is backed by ttm_bo_init() and ferries its return code\nback to the caller. On failures, ttm_bo_init() invokes the provided\ndestructor which should de-initialize and free the memory.\n\nThus, when nouveau_bo_init() returns an error the gem object has already\nbeen released and the memory freed by nouveau_bo_del_ttm().",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:11Z"
diff --git a/advisories/unreviewed/2024/07/GHSA-6fvx-97p6-hw44/GHSA-6fvx-97p6-hw44.json b/advisories/unreviewed/2024/07/GHSA-6fvx-97p6-hw44/GHSA-6fvx-97p6-hw44.json
index ca19e597ee4..9cb1cdf965d 100644
--- a/advisories/unreviewed/2024/07/GHSA-6fvx-97p6-hw44/GHSA-6fvx-97p6-hw44.json
+++ b/advisories/unreviewed/2024/07/GHSA-6fvx-97p6-hw44/GHSA-6fvx-97p6-hw44.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6fvx-97p6-hw44",
- "modified": "2024-07-30T09:32:01Z",
+ "modified": "2024-12-11T18:30:36Z",
"published": "2024-07-30T09:32:01Z",
"aliases": [
"CVE-2024-42132"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbluetooth/hci: disallow setting handle bigger than HCI_CONN_HANDLE_MAX\n\nSyzbot hit warning in hci_conn_del() caused by freeing handle that was\nnot allocated using ida allocator.\n\nThis is caused by handle bigger than HCI_CONN_HANDLE_MAX passed by\nhci_le_big_sync_established_evt(), which makes code think it's unset\nconnection.\n\nAdd same check for handle upper bound as in hci_conn_set_handle() to\nprevent warning.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-763"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-30T08:15:05Z"
diff --git a/advisories/unreviewed/2024/07/GHSA-jv48-qx8c-4x4f/GHSA-jv48-qx8c-4x4f.json b/advisories/unreviewed/2024/07/GHSA-jv48-qx8c-4x4f/GHSA-jv48-qx8c-4x4f.json
index ae3c1783c72..008fee18690 100644
--- a/advisories/unreviewed/2024/07/GHSA-jv48-qx8c-4x4f/GHSA-jv48-qx8c-4x4f.json
+++ b/advisories/unreviewed/2024/07/GHSA-jv48-qx8c-4x4f/GHSA-jv48-qx8c-4x4f.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jv48-qx8c-4x4f",
- "modified": "2024-07-30T09:32:02Z",
+ "modified": "2024-12-11T18:30:36Z",
"published": "2024-07-30T09:32:02Z",
"aliases": [
"CVE-2024-42134"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio-pci: Check if is_avq is NULL\n\n[bug]\nIn the virtio_pci_common.c function vp_del_vqs, vp_dev->is_avq is involved\nto determine whether it is admin virtqueue, but this function vp_dev->is_avq\n may be empty. For installations, virtio_pci_legacy does not assign a value\n to vp_dev->is_avq.\n\n[fix]\nCheck whether it is vp_dev->is_avq before use.\n\n[test]\nTest with virsh Attach device\nBefore this patch, the following command would crash the guest system\n\nAfter applying the patch, everything seems to be working fine.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-30T08:15:05Z"
diff --git a/advisories/unreviewed/2024/07/GHSA-r5mq-jg2w-g597/GHSA-r5mq-jg2w-g597.json b/advisories/unreviewed/2024/07/GHSA-r5mq-jg2w-g597/GHSA-r5mq-jg2w-g597.json
index 64a2788ebc8..3c2b49a401f 100644
--- a/advisories/unreviewed/2024/07/GHSA-r5mq-jg2w-g597/GHSA-r5mq-jg2w-g597.json
+++ b/advisories/unreviewed/2024/07/GHSA-r5mq-jg2w-g597/GHSA-r5mq-jg2w-g597.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r5mq-jg2w-g597",
- "modified": "2024-07-30T09:32:01Z",
+ "modified": "2024-12-11T18:30:36Z",
"published": "2024-07-30T09:32:01Z",
"aliases": [
"CVE-2024-42133"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: Ignore too large handle values in BIG\n\nhci_le_big_sync_established_evt is necessary to filter out cases where the\nhandle value is belonging to ida id range, otherwise ida will be erroneously\nreleased in hci_conn_cleanup.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -29,7 +34,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-30T08:15:05Z"
diff --git a/advisories/unreviewed/2024/10/GHSA-qcfq-rrwc-fg96/GHSA-qcfq-rrwc-fg96.json b/advisories/unreviewed/2024/10/GHSA-qcfq-rrwc-fg96/GHSA-qcfq-rrwc-fg96.json
index 2619338da6b..b0f2fc11164 100644
--- a/advisories/unreviewed/2024/10/GHSA-qcfq-rrwc-fg96/GHSA-qcfq-rrwc-fg96.json
+++ b/advisories/unreviewed/2024/10/GHSA-qcfq-rrwc-fg96/GHSA-qcfq-rrwc-fg96.json
@@ -33,7 +33,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-787"
+ ],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/11/GHSA-639p-pgpg-5qr5/GHSA-639p-pgpg-5qr5.json b/advisories/unreviewed/2024/11/GHSA-639p-pgpg-5qr5/GHSA-639p-pgpg-5qr5.json
index 49fab5e76f4..90b01f63877 100644
--- a/advisories/unreviewed/2024/11/GHSA-639p-pgpg-5qr5/GHSA-639p-pgpg-5qr5.json
+++ b/advisories/unreviewed/2024/11/GHSA-639p-pgpg-5qr5/GHSA-639p-pgpg-5qr5.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-639p-pgpg-5qr5",
- "modified": "2024-11-08T06:30:49Z",
+ "modified": "2024-12-11T18:30:37Z",
"published": "2024-11-08T06:30:49Z",
"aliases": [
"CVE-2024-50191"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: don't set SB_RDONLY after filesystem errors\n\nWhen the filesystem is mounted with errors=remount-ro, we were setting\nSB_RDONLY flag to stop all filesystem modifications. We knew this misses\nproper locking (sb->s_umount) and does not go through proper filesystem\nremount procedure but it has been the way this worked since early ext2\ndays and it was good enough for catastrophic situation damage\nmitigation. Recently, syzbot has found a way (see link) to trigger\nwarnings in filesystem freezing because the code got confused by\nSB_RDONLY changing under its hands. Since these days we set\nEXT4_FLAGS_SHUTDOWN on the superblock which is enough to stop all\nfilesystem modifications, modifying SB_RDONLY shouldn't be needed. So\nstop doing that.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -37,7 +42,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-08T06:15:16Z"
diff --git a/advisories/unreviewed/2024/11/GHSA-6q4v-9f44-vxxx/GHSA-6q4v-9f44-vxxx.json b/advisories/unreviewed/2024/11/GHSA-6q4v-9f44-vxxx/GHSA-6q4v-9f44-vxxx.json
index 7ef9e43b988..cbeb0ee651c 100644
--- a/advisories/unreviewed/2024/11/GHSA-6q4v-9f44-vxxx/GHSA-6q4v-9f44-vxxx.json
+++ b/advisories/unreviewed/2024/11/GHSA-6q4v-9f44-vxxx/GHSA-6q4v-9f44-vxxx.json
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
+ "CWE-22",
"CWE-552"
],
"severity": "CRITICAL",
diff --git a/advisories/unreviewed/2024/11/GHSA-rhx4-7vf5-j6rw/GHSA-rhx4-7vf5-j6rw.json b/advisories/unreviewed/2024/11/GHSA-rhx4-7vf5-j6rw/GHSA-rhx4-7vf5-j6rw.json
index 7c714a9d0cb..ec7f2974ace 100644
--- a/advisories/unreviewed/2024/11/GHSA-rhx4-7vf5-j6rw/GHSA-rhx4-7vf5-j6rw.json
+++ b/advisories/unreviewed/2024/11/GHSA-rhx4-7vf5-j6rw/GHSA-rhx4-7vf5-j6rw.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rhx4-7vf5-j6rw",
- "modified": "2024-11-08T06:30:48Z",
+ "modified": "2024-12-11T18:30:37Z",
"published": "2024-11-08T06:30:48Z",
"aliases": [
"CVE-2024-50190"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nice: fix memleak in ice_init_tx_topology()\n\nFix leak of the FW blob (DDP pkg).\n\nMake ice_cfg_tx_topo() const-correct, so ice_init_tx_topology() can avoid\ncopying whole FW blob. Copy just the topology section, and only when\nneeded. Reuse the buffer allocated for the read of the current topology.\n\nThis was found by kmemleak, with the following trace for each PF:\n [] kmemdup_noprof+0x1d/0x50\n [] ice_init_ddp_config+0x100/0x220 [ice]\n [] ice_init_dev+0x6f/0x200 [ice]\n [] ice_init+0x29/0x560 [ice]\n [] ice_probe+0x21d/0x310 [ice]\n\nConstify ice_cfg_tx_topo() @buf parameter.\nThis cascades further down to few more functions.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-08T06:15:15Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-2fvj-55p5-9gp4/GHSA-2fvj-55p5-9gp4.json b/advisories/unreviewed/2024/12/GHSA-2fvj-55p5-9gp4/GHSA-2fvj-55p5-9gp4.json
new file mode 100644
index 00000000000..0f4873e852b
--- /dev/null
+++ b/advisories/unreviewed/2024/12/GHSA-2fvj-55p5-9gp4/GHSA-2fvj-55p5-9gp4.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2fvj-55p5-9gp4",
+ "modified": "2024-12-11T18:30:42Z",
+ "published": "2024-12-11T18:30:42Z",
+ "aliases": [
+ "CVE-2024-8496"
+ ],
+ "details": "Under specific circumstances, insecure permissions in Ivanti Workspace Control before version 10.18.40.0 allows a local authenticated attacker to achieve local privilege escalation.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8496"
+ },
+ {
+ "type": "WEB",
+ "url": "https://forums.ivanti.com/s/article/December-2024-Security-Advisory-Ivanti-Workspace-Control-IWC-CVE-2024-8496"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-276"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-12-11T17:15:21Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/12/GHSA-2hxh-f4xp-4wcj/GHSA-2hxh-f4xp-4wcj.json b/advisories/unreviewed/2024/12/GHSA-2hxh-f4xp-4wcj/GHSA-2hxh-f4xp-4wcj.json
new file mode 100644
index 00000000000..faae7f41f73
--- /dev/null
+++ b/advisories/unreviewed/2024/12/GHSA-2hxh-f4xp-4wcj/GHSA-2hxh-f4xp-4wcj.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2hxh-f4xp-4wcj",
+ "modified": "2024-12-11T18:30:42Z",
+ "published": "2024-12-11T18:30:42Z",
+ "aliases": [
+ "CVE-2024-11597"
+ ],
+ "details": "Under specific circumstances, insecure permissions in Ivanti Performance Manager before version 2024.3 HF1, 2024.1 HF1, or 2023.3 HF1 allows a local authenticated attacker to achieve local privilege escalation.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11597"
+ },
+ {
+ "type": "WEB",
+ "url": "https://forums.ivanti.com/s/article/December-2024-Security-Advisory-Ivanti-Performance-Manager-CVE-2024-11597"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-276"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-12-11T17:15:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/12/GHSA-33rw-2cg2-2mpc/GHSA-33rw-2cg2-2mpc.json b/advisories/unreviewed/2024/12/GHSA-33rw-2cg2-2mpc/GHSA-33rw-2cg2-2mpc.json
index f4bb4ac7e6d..6863d462c0e 100644
--- a/advisories/unreviewed/2024/12/GHSA-33rw-2cg2-2mpc/GHSA-33rw-2cg2-2mpc.json
+++ b/advisories/unreviewed/2024/12/GHSA-33rw-2cg2-2mpc/GHSA-33rw-2cg2-2mpc.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-33rw-2cg2-2mpc",
- "modified": "2024-12-05T12:31:28Z",
+ "modified": "2024-12-11T18:30:39Z",
"published": "2024-12-04T15:31:52Z",
"aliases": [
"CVE-2024-53136"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: revert \"mm: shmem: fix data-race in shmem_getattr()\"\n\nRevert d949d1d14fa2 (\"mm: shmem: fix data-race in shmem_getattr()\") as\nsuggested by Chuck [1]. It is causing deadlocks when accessing tmpfs over\nNFS.\n\nAs Hugh commented, \"added just to silence a syzbot sanitizer splat: added\nwhere there has never been any practical problem\".",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-362"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-04T15:15:13Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-3743-c947-mrhr/GHSA-3743-c947-mrhr.json b/advisories/unreviewed/2024/12/GHSA-3743-c947-mrhr/GHSA-3743-c947-mrhr.json
index 14bd98a0f46..da40d8117b0 100644
--- a/advisories/unreviewed/2024/12/GHSA-3743-c947-mrhr/GHSA-3743-c947-mrhr.json
+++ b/advisories/unreviewed/2024/12/GHSA-3743-c947-mrhr/GHSA-3743-c947-mrhr.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3743-c947-mrhr",
- "modified": "2024-12-10T03:31:45Z",
+ "modified": "2024-12-11T18:30:42Z",
"published": "2024-12-10T03:31:45Z",
"aliases": [
"CVE-2024-53552"
],
"details": "CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-640"
+ ],
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-10T02:15:17Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-38h9-g2p9-689w/GHSA-38h9-g2p9-689w.json b/advisories/unreviewed/2024/12/GHSA-38h9-g2p9-689w/GHSA-38h9-g2p9-689w.json
index 25bb1ed12db..7558cc4a9ec 100644
--- a/advisories/unreviewed/2024/12/GHSA-38h9-g2p9-689w/GHSA-38h9-g2p9-689w.json
+++ b/advisories/unreviewed/2024/12/GHSA-38h9-g2p9-689w/GHSA-38h9-g2p9-689w.json
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-74"
+ "CWE-74",
+ "CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/12/GHSA-3q42-g7wg-ggw3/GHSA-3q42-g7wg-ggw3.json b/advisories/unreviewed/2024/12/GHSA-3q42-g7wg-ggw3/GHSA-3q42-g7wg-ggw3.json
index e6d32ce960d..f0ee142bc4e 100644
--- a/advisories/unreviewed/2024/12/GHSA-3q42-g7wg-ggw3/GHSA-3q42-g7wg-ggw3.json
+++ b/advisories/unreviewed/2024/12/GHSA-3q42-g7wg-ggw3/GHSA-3q42-g7wg-ggw3.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3q42-g7wg-ggw3",
- "modified": "2024-12-09T21:31:02Z",
+ "modified": "2024-12-11T18:30:41Z",
"published": "2024-12-09T21:31:02Z",
"aliases": [
"CVE-2024-54923"
],
"details": "A SQL Injection vulnerability was found in /admin/edit_teacher.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the department parameter.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-09T19:15:16Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-3q5q-j6r6-cgv8/GHSA-3q5q-j6r6-cgv8.json b/advisories/unreviewed/2024/12/GHSA-3q5q-j6r6-cgv8/GHSA-3q5q-j6r6-cgv8.json
index 88b0af36485..dd382697764 100644
--- a/advisories/unreviewed/2024/12/GHSA-3q5q-j6r6-cgv8/GHSA-3q5q-j6r6-cgv8.json
+++ b/advisories/unreviewed/2024/12/GHSA-3q5q-j6r6-cgv8/GHSA-3q5q-j6r6-cgv8.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3q5q-j6r6-cgv8",
- "modified": "2024-12-04T15:31:52Z",
+ "modified": "2024-12-11T18:30:39Z",
"published": "2024-12-04T15:31:52Z",
"aliases": [
"CVE-2024-53133"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Handle dml allocation failure to avoid crash\n\n[Why]\nIn the case where a dml allocation fails for any reason, the\ncurrent state's dml contexts would no longer be valid. Then\nsubsequent calls dc_state_copy_internal would shallow copy\ninvalid memory and if the new state was released, a double\nfree would occur.\n\n[How]\nReset dml pointers in new_state to NULL and avoid invalid\npointer\n\n(cherry picked from commit bcafdc61529a48f6f06355d78eb41b3aeda5296c)",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-415"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-04T15:15:13Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-43mq-6xmg-29vm/GHSA-43mq-6xmg-29vm.json b/advisories/unreviewed/2024/12/GHSA-43mq-6xmg-29vm/GHSA-43mq-6xmg-29vm.json
new file mode 100644
index 00000000000..f6017e26bb7
--- /dev/null
+++ b/advisories/unreviewed/2024/12/GHSA-43mq-6xmg-29vm/GHSA-43mq-6xmg-29vm.json
@@ -0,0 +1,34 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-43mq-6xmg-29vm",
+ "modified": "2024-12-11T18:30:42Z",
+ "published": "2024-12-11T18:30:42Z",
+ "aliases": [
+ "CVE-2024-53677"
+ ],
+ "details": "File upload logic is flawed vulnerability in Apache Struts.\n\nThis issue affects Apache Struts: from 2.0.0 before 6.4.0.\n\nUsers are recommended to upgrade to version 6.4.0, which fixes the issue.\n\nYou can find more details in https://cwiki.apache.org/confluence/display/WW/S2-067",
+ "severity": [
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:A/V:C/RE:L/U:Red"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53677"
+ },
+ {
+ "type": "WEB",
+ "url": "https://cwiki.apache.org/confluence/display/WW/S2-067"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": "CRITICAL",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-12-11T16:15:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/12/GHSA-4qf8-xmx7-vj5f/GHSA-4qf8-xmx7-vj5f.json b/advisories/unreviewed/2024/12/GHSA-4qf8-xmx7-vj5f/GHSA-4qf8-xmx7-vj5f.json
index 94185366305..a2f721393db 100644
--- a/advisories/unreviewed/2024/12/GHSA-4qf8-xmx7-vj5f/GHSA-4qf8-xmx7-vj5f.json
+++ b/advisories/unreviewed/2024/12/GHSA-4qf8-xmx7-vj5f/GHSA-4qf8-xmx7-vj5f.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4qf8-xmx7-vj5f",
- "modified": "2024-12-06T00:31:47Z",
+ "modified": "2024-12-11T18:30:41Z",
"published": "2024-12-06T00:31:47Z",
"aliases": [
"CVE-2024-30961"
],
"details": "Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the error-thrown mechanism in nav2_bt_navigator.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-94"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-05T23:15:05Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-4vf8-cqmh-j4f2/GHSA-4vf8-cqmh-j4f2.json b/advisories/unreviewed/2024/12/GHSA-4vf8-cqmh-j4f2/GHSA-4vf8-cqmh-j4f2.json
index 2f7e524b96b..8bc50d15ffb 100644
--- a/advisories/unreviewed/2024/12/GHSA-4vf8-cqmh-j4f2/GHSA-4vf8-cqmh-j4f2.json
+++ b/advisories/unreviewed/2024/12/GHSA-4vf8-cqmh-j4f2/GHSA-4vf8-cqmh-j4f2.json
@@ -1,27 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4vf8-cqmh-j4f2",
- "modified": "2024-12-10T21:30:52Z",
+ "modified": "2024-12-11T18:30:42Z",
"published": "2024-12-10T21:30:52Z",
"aliases": [
"CVE-2024-50699"
],
"details": "TP-Link TL-WR845N(UN)_V4_201214, TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 were discovered to contain weak default credentials for the Administrator account.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50699"
},
+ {
+ "type": "WEB",
+ "url": "https://security.iiita.ac.in/iot/base64-authorization.docx"
+ },
{
"type": "WEB",
"url": "https://security.iiita.ac.in/iot/password-reset-missing-tplink.pdf"
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-522"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-10T19:15:30Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-4wg6-j4jc-xh8j/GHSA-4wg6-j4jc-xh8j.json b/advisories/unreviewed/2024/12/GHSA-4wg6-j4jc-xh8j/GHSA-4wg6-j4jc-xh8j.json
index a6d266cdd37..3a3c40b6bb7 100644
--- a/advisories/unreviewed/2024/12/GHSA-4wg6-j4jc-xh8j/GHSA-4wg6-j4jc-xh8j.json
+++ b/advisories/unreviewed/2024/12/GHSA-4wg6-j4jc-xh8j/GHSA-4wg6-j4jc-xh8j.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4wg6-j4jc-xh8j",
- "modified": "2024-12-09T18:31:19Z",
+ "modified": "2024-12-11T18:30:41Z",
"published": "2024-12-09T18:31:19Z",
"aliases": [
"CVE-2024-54933"
],
"details": "Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_content.php.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-09T18:15:24Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-59r8-jcm7-vx66/GHSA-59r8-jcm7-vx66.json b/advisories/unreviewed/2024/12/GHSA-59r8-jcm7-vx66/GHSA-59r8-jcm7-vx66.json
index ff48849a236..50be8c662c5 100644
--- a/advisories/unreviewed/2024/12/GHSA-59r8-jcm7-vx66/GHSA-59r8-jcm7-vx66.json
+++ b/advisories/unreviewed/2024/12/GHSA-59r8-jcm7-vx66/GHSA-59r8-jcm7-vx66.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-59r8-jcm7-vx66",
- "modified": "2024-12-04T15:31:52Z",
+ "modified": "2024-12-11T18:30:39Z",
"published": "2024-12-04T15:31:52Z",
"aliases": [
"CVE-2024-53137"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nARM: fix cacheflush with PAN\n\nIt seems that the cacheflush syscall got broken when PAN for LPAE was\nimplemented. User access was not enabled around the cache maintenance\ninstructions, causing them to fault.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -25,7 +30,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-04T15:15:13Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-5cj9-rv5c-h66j/GHSA-5cj9-rv5c-h66j.json b/advisories/unreviewed/2024/12/GHSA-5cj9-rv5c-h66j/GHSA-5cj9-rv5c-h66j.json
index d3359f0fff4..0a5a8063de7 100644
--- a/advisories/unreviewed/2024/12/GHSA-5cj9-rv5c-h66j/GHSA-5cj9-rv5c-h66j.json
+++ b/advisories/unreviewed/2024/12/GHSA-5cj9-rv5c-h66j/GHSA-5cj9-rv5c-h66j.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5cj9-rv5c-h66j",
- "modified": "2024-12-09T21:31:02Z",
+ "modified": "2024-12-11T18:30:41Z",
"published": "2024-12-09T21:31:02Z",
"aliases": [
"CVE-2024-54928"
],
"details": "kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_teacher.php,",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-09T19:15:16Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-5cwm-fg2p-g6pp/GHSA-5cwm-fg2p-g6pp.json b/advisories/unreviewed/2024/12/GHSA-5cwm-fg2p-g6pp/GHSA-5cwm-fg2p-g6pp.json
index 7ab8ebafad5..e8cec143e19 100644
--- a/advisories/unreviewed/2024/12/GHSA-5cwm-fg2p-g6pp/GHSA-5cwm-fg2p-g6pp.json
+++ b/advisories/unreviewed/2024/12/GHSA-5cwm-fg2p-g6pp/GHSA-5cwm-fg2p-g6pp.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5cwm-fg2p-g6pp",
- "modified": "2024-12-05T12:31:28Z",
+ "modified": "2024-12-11T18:30:38Z",
"published": "2024-12-04T15:31:52Z",
"aliases": [
"CVE-2024-53127"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRevert \"mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K\"\n\nThe commit 8396c793ffdf (\"mmc: dw_mmc: Fix IDMAC operation with pages\nbigger than 4K\") increased the max_req_size, even for 4K pages, causing\nvarious issues:\n- Panic booting the kernel/rootfs from an SD card on Rockchip RK3566\n- Panic booting the kernel/rootfs from an SD card on StarFive JH7100\n- \"swiotlb buffer is full\" and data corruption on StarFive JH7110\n\nAt this stage no fix have been found, so it's probably better to just\nrevert the change.\n\nThis reverts commit 8396c793ffdf28bb8aee7cfe0891080f8cab7890.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -37,7 +42,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-04T15:15:12Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-5wwr-qqmw-x5rf/GHSA-5wwr-qqmw-x5rf.json b/advisories/unreviewed/2024/12/GHSA-5wwr-qqmw-x5rf/GHSA-5wwr-qqmw-x5rf.json
index 882ae456223..f4ab2574618 100644
--- a/advisories/unreviewed/2024/12/GHSA-5wwr-qqmw-x5rf/GHSA-5wwr-qqmw-x5rf.json
+++ b/advisories/unreviewed/2024/12/GHSA-5wwr-qqmw-x5rf/GHSA-5wwr-qqmw-x5rf.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5wwr-qqmw-x5rf",
- "modified": "2024-12-09T18:31:19Z",
+ "modified": "2024-12-11T18:30:41Z",
"published": "2024-12-09T18:31:19Z",
"aliases": [
"CVE-2022-38946"
],
"details": "Arbitrary File Upload vulnerability in Doctor-Appointment version 1.0 in /Frontend/signup_com.php, allows attackers to execute arbitrary code.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-94"
+ ],
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-09T17:15:05Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-5xh8-mfhp-x7wc/GHSA-5xh8-mfhp-x7wc.json b/advisories/unreviewed/2024/12/GHSA-5xh8-mfhp-x7wc/GHSA-5xh8-mfhp-x7wc.json
index a9d0531176a..d07ee2b7dd0 100644
--- a/advisories/unreviewed/2024/12/GHSA-5xh8-mfhp-x7wc/GHSA-5xh8-mfhp-x7wc.json
+++ b/advisories/unreviewed/2024/12/GHSA-5xh8-mfhp-x7wc/GHSA-5xh8-mfhp-x7wc.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5xh8-mfhp-x7wc",
- "modified": "2024-12-10T18:31:07Z",
+ "modified": "2024-12-11T18:30:42Z",
"published": "2024-12-10T18:31:07Z",
"aliases": [
"CVE-2024-45493"
],
"details": "An issue was discovered in MSA Safety FieldServer Gateways and Embedded Modules with build revisions before 7.0.0. The FieldServer Gateway has internal users, whose access is supposed to be restricted to login locally on the device. However, an attacker can bypass the check for this, which might allow them to authenticate with an internal user account from the network (if they know their password).",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-10T17:15:10Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-623v-cr64-76w9/GHSA-623v-cr64-76w9.json b/advisories/unreviewed/2024/12/GHSA-623v-cr64-76w9/GHSA-623v-cr64-76w9.json
index 950874e6790..b5789f0c2dd 100644
--- a/advisories/unreviewed/2024/12/GHSA-623v-cr64-76w9/GHSA-623v-cr64-76w9.json
+++ b/advisories/unreviewed/2024/12/GHSA-623v-cr64-76w9/GHSA-623v-cr64-76w9.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-623v-cr64-76w9",
- "modified": "2024-12-04T15:31:52Z",
+ "modified": "2024-12-11T18:30:38Z",
"published": "2024-12-04T15:31:52Z",
"aliases": [
"CVE-2024-53126"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvdpa: solidrun: Fix UB bug with devres\n\nIn psnet_open_pf_bar() and snet_open_vf_bar() a string later passed to\npcim_iomap_regions() is placed on the stack. Neither\npcim_iomap_regions() nor the functions it calls copy that string.\n\nShould the string later ever be used, this, consequently, causes\nundefined behavior since the stack frame will by then have disappeared.\n\nFix the bug by allocating the strings on the heap through\ndevm_kasprintf().",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -29,7 +34,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-04T15:15:12Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-68q5-f84h-346q/GHSA-68q5-f84h-346q.json b/advisories/unreviewed/2024/12/GHSA-68q5-f84h-346q/GHSA-68q5-f84h-346q.json
index 27d551406e2..942700f355b 100644
--- a/advisories/unreviewed/2024/12/GHSA-68q5-f84h-346q/GHSA-68q5-f84h-346q.json
+++ b/advisories/unreviewed/2024/12/GHSA-68q5-f84h-346q/GHSA-68q5-f84h-346q.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-68q5-f84h-346q",
- "modified": "2024-12-09T21:31:02Z",
+ "modified": "2024-12-11T18:30:41Z",
"published": "2024-12-09T21:31:02Z",
"aliases": [
"CVE-2024-54921"
],
"details": "A SQL Injection was found in /student_signup.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username, firstname, lastname, and class_id parameters.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-09T19:15:15Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-6gh4-647f-6rr5/GHSA-6gh4-647f-6rr5.json b/advisories/unreviewed/2024/12/GHSA-6gh4-647f-6rr5/GHSA-6gh4-647f-6rr5.json
index 046e2230b17..42115ccc56a 100644
--- a/advisories/unreviewed/2024/12/GHSA-6gh4-647f-6rr5/GHSA-6gh4-647f-6rr5.json
+++ b/advisories/unreviewed/2024/12/GHSA-6gh4-647f-6rr5/GHSA-6gh4-647f-6rr5.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6gh4-647f-6rr5",
- "modified": "2024-12-05T18:31:03Z",
+ "modified": "2024-12-11T18:30:40Z",
"published": "2024-12-05T18:31:03Z",
"aliases": [
"CVE-2024-53472"
],
"details": "WeGIA v3.2.0 was discovered to contain a Cross-Site Request Forgery (CSRF).",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-05T16:15:25Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-6hcg-vqw2-35jw/GHSA-6hcg-vqw2-35jw.json b/advisories/unreviewed/2024/12/GHSA-6hcg-vqw2-35jw/GHSA-6hcg-vqw2-35jw.json
index bb53070456b..0b13b0d18eb 100644
--- a/advisories/unreviewed/2024/12/GHSA-6hcg-vqw2-35jw/GHSA-6hcg-vqw2-35jw.json
+++ b/advisories/unreviewed/2024/12/GHSA-6hcg-vqw2-35jw/GHSA-6hcg-vqw2-35jw.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6hcg-vqw2-35jw",
- "modified": "2024-12-05T21:31:52Z",
+ "modified": "2024-12-11T18:30:40Z",
"published": "2024-12-05T21:31:52Z",
"aliases": [
"CVE-2024-53589"
],
"details": "GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-120"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-05T20:15:22Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-6qhw-w3qj-8cf9/GHSA-6qhw-w3qj-8cf9.json b/advisories/unreviewed/2024/12/GHSA-6qhw-w3qj-8cf9/GHSA-6qhw-w3qj-8cf9.json
index f84289f1818..1872f82e1b1 100644
--- a/advisories/unreviewed/2024/12/GHSA-6qhw-w3qj-8cf9/GHSA-6qhw-w3qj-8cf9.json
+++ b/advisories/unreviewed/2024/12/GHSA-6qhw-w3qj-8cf9/GHSA-6qhw-w3qj-8cf9.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6qhw-w3qj-8cf9",
- "modified": "2024-12-09T18:31:19Z",
+ "modified": "2024-12-11T18:30:41Z",
"published": "2024-12-09T18:31:19Z",
"aliases": [
"CVE-2024-54930"
],
"details": "Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_student.php.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-09T18:15:24Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-79r7-f3jp-52j9/GHSA-79r7-f3jp-52j9.json b/advisories/unreviewed/2024/12/GHSA-79r7-f3jp-52j9/GHSA-79r7-f3jp-52j9.json
index e3a7efbb24d..c3bc6080777 100644
--- a/advisories/unreviewed/2024/12/GHSA-79r7-f3jp-52j9/GHSA-79r7-f3jp-52j9.json
+++ b/advisories/unreviewed/2024/12/GHSA-79r7-f3jp-52j9/GHSA-79r7-f3jp-52j9.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-79r7-f3jp-52j9",
- "modified": "2024-12-05T21:31:52Z",
+ "modified": "2024-12-11T18:30:40Z",
"published": "2024-12-05T21:31:52Z",
"aliases": [
"CVE-2023-50913"
],
"details": "Oxide control plane software before 5 allows SSRF.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-918"
+ ],
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-05T20:15:20Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-7gvv-gph6-2hpj/GHSA-7gvv-gph6-2hpj.json b/advisories/unreviewed/2024/12/GHSA-7gvv-gph6-2hpj/GHSA-7gvv-gph6-2hpj.json
index fbacad5de59..7760cc53b85 100644
--- a/advisories/unreviewed/2024/12/GHSA-7gvv-gph6-2hpj/GHSA-7gvv-gph6-2hpj.json
+++ b/advisories/unreviewed/2024/12/GHSA-7gvv-gph6-2hpj/GHSA-7gvv-gph6-2hpj.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7gvv-gph6-2hpj",
- "modified": "2024-12-04T15:31:52Z",
+ "modified": "2024-12-11T18:30:39Z",
"published": "2024-12-04T15:31:52Z",
"aliases": [
"CVE-2024-53135"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: VMX: Bury Intel PT virtualization (guest/host mode) behind CONFIG_BROKEN\n\nHide KVM's pt_mode module param behind CONFIG_BROKEN, i.e. disable support\nfor virtualizing Intel PT via guest/host mode unless BROKEN=y. There are\nmyriad bugs in the implementation, some of which are fatal to the guest,\nand others which put the stability and health of the host at risk.\n\nFor guest fatalities, the most glaring issue is that KVM fails to ensure\ntracing is disabled, and *stays* disabled prior to VM-Enter, which is\nnecessary as hardware disallows loading (the guest's) RTIT_CTL if tracing\nis enabled (enforced via a VMX consistency check). Per the SDM:\n\n If the logical processor is operating with Intel PT enabled (if\n IA32_RTIT_CTL.TraceEn = 1) at the time of VM entry, the \"load\n IA32_RTIT_CTL\" VM-entry control must be 0.\n\nOn the host side, KVM doesn't validate the guest CPUID configuration\nprovided by userspace, and even worse, uses the guest configuration to\ndecide what MSRs to save/load at VM-Enter and VM-Exit. E.g. configuring\nguest CPUID to enumerate more address ranges than are supported in hardware\nwill result in KVM trying to passthrough, save, and load non-existent MSRs,\nwhich generates a variety of WARNs, ToPA ERRORs in the host, a potential\ndeadlock, etc.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -33,7 +38,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-04T15:15:13Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-7pg5-v792-9xv2/GHSA-7pg5-v792-9xv2.json b/advisories/unreviewed/2024/12/GHSA-7pg5-v792-9xv2/GHSA-7pg5-v792-9xv2.json
new file mode 100644
index 00000000000..84233b85614
--- /dev/null
+++ b/advisories/unreviewed/2024/12/GHSA-7pg5-v792-9xv2/GHSA-7pg5-v792-9xv2.json
@@ -0,0 +1,31 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7pg5-v792-9xv2",
+ "modified": "2024-12-11T18:30:42Z",
+ "published": "2024-12-11T18:30:42Z",
+ "aliases": [
+ "CVE-2024-28139"
+ ],
+ "details": "The www-data user can elevate its privileges because sudo is configured to allow the execution of the mount command as root without a password. Therefore, the privileges can be escalated to the root user. The risk has been accepted by the vendor and won't be fixed in the near future.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28139"
+ },
+ {
+ "type": "WEB",
+ "url": "https://r.sec-consult.com/imageaccess"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-250"
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-12-11T16:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/12/GHSA-7qwr-5g4p-5495/GHSA-7qwr-5g4p-5495.json b/advisories/unreviewed/2024/12/GHSA-7qwr-5g4p-5495/GHSA-7qwr-5g4p-5495.json
index 05c3f7b5735..573460afdd7 100644
--- a/advisories/unreviewed/2024/12/GHSA-7qwr-5g4p-5495/GHSA-7qwr-5g4p-5495.json
+++ b/advisories/unreviewed/2024/12/GHSA-7qwr-5g4p-5495/GHSA-7qwr-5g4p-5495.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7qwr-5g4p-5495",
- "modified": "2024-12-05T21:31:52Z",
+ "modified": "2024-12-11T18:30:40Z",
"published": "2024-12-05T21:31:52Z",
"aliases": [
"CVE-2024-53523"
],
"details": "JSFinder commit d70ab9bc5221e016c08cffaf0d9ac79646c90645 is vulnerable to Directory Traversal in the find_by_file function.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-22"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-05T21:15:08Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-7xjp-f5xm-j9vm/GHSA-7xjp-f5xm-j9vm.json b/advisories/unreviewed/2024/12/GHSA-7xjp-f5xm-j9vm/GHSA-7xjp-f5xm-j9vm.json
index 58c32c41259..93b71f9f218 100644
--- a/advisories/unreviewed/2024/12/GHSA-7xjp-f5xm-j9vm/GHSA-7xjp-f5xm-j9vm.json
+++ b/advisories/unreviewed/2024/12/GHSA-7xjp-f5xm-j9vm/GHSA-7xjp-f5xm-j9vm.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7xjp-f5xm-j9vm",
- "modified": "2024-12-04T18:32:35Z",
+ "modified": "2024-12-11T18:30:40Z",
"published": "2024-12-04T18:32:35Z",
"aliases": [
"CVE-2024-37575"
],
"details": "The Mister org.mistergroup.shouldianswer application 1.4.264 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the org.mistergroup.shouldianswer.ui.default_dialer.DefaultDialerActivity component.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-281"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-04T16:15:24Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-84hg-pv4v-g5m7/GHSA-84hg-pv4v-g5m7.json b/advisories/unreviewed/2024/12/GHSA-84hg-pv4v-g5m7/GHSA-84hg-pv4v-g5m7.json
index 8b60ea3e642..72e809cd2e1 100644
--- a/advisories/unreviewed/2024/12/GHSA-84hg-pv4v-g5m7/GHSA-84hg-pv4v-g5m7.json
+++ b/advisories/unreviewed/2024/12/GHSA-84hg-pv4v-g5m7/GHSA-84hg-pv4v-g5m7.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-84hg-pv4v-g5m7",
- "modified": "2024-12-05T21:31:52Z",
+ "modified": "2024-12-11T18:30:40Z",
"published": "2024-12-05T21:31:52Z",
"aliases": [
"CVE-2023-48010"
],
"details": "STMicroelectronics SPC58 is vulnerable to Missing Protection Mechanism for Alternate Hardware Interface. Code running as Supervisor on the SPC58 PowerPC microcontrollers may disable the System Memory Protection Unit and gain unabridged read/write access to protected assets.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-522"
+ ],
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-05T20:15:20Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-856r-5w5p-h874/GHSA-856r-5w5p-h874.json b/advisories/unreviewed/2024/12/GHSA-856r-5w5p-h874/GHSA-856r-5w5p-h874.json
index 68f28afe399..e8a7d7f7e1d 100644
--- a/advisories/unreviewed/2024/12/GHSA-856r-5w5p-h874/GHSA-856r-5w5p-h874.json
+++ b/advisories/unreviewed/2024/12/GHSA-856r-5w5p-h874/GHSA-856r-5w5p-h874.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-856r-5w5p-h874",
- "modified": "2024-12-09T21:31:02Z",
+ "modified": "2024-12-11T18:30:41Z",
"published": "2024-12-09T21:31:02Z",
"aliases": [
"CVE-2024-54931"
],
"details": "A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-09T19:15:16Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-8jvw-w62h-38xj/GHSA-8jvw-w62h-38xj.json b/advisories/unreviewed/2024/12/GHSA-8jvw-w62h-38xj/GHSA-8jvw-w62h-38xj.json
new file mode 100644
index 00000000000..0274c382804
--- /dev/null
+++ b/advisories/unreviewed/2024/12/GHSA-8jvw-w62h-38xj/GHSA-8jvw-w62h-38xj.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8jvw-w62h-38xj",
+ "modified": "2024-12-11T18:30:42Z",
+ "published": "2024-12-11T18:30:42Z",
+ "aliases": [
+ "CVE-2024-28141"
+ ],
+ "details": "The web application is not protected against cross-site request forgery attacks. Therefore, an attacker can trick users into performing actions on the application when they visit an attacker-controlled website or click on a malicious link. E.g. an attacker can forge malicious links to reset the admin password or create new users.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28141"
+ },
+ {
+ "type": "WEB",
+ "url": "https://r.sec-consult.com/imageaccess"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.imageaccess.de/?page=SupportPortal&lang=en"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-12-11T16:15:10Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/12/GHSA-8m4x-x8j4-mx4j/GHSA-8m4x-x8j4-mx4j.json b/advisories/unreviewed/2024/12/GHSA-8m4x-x8j4-mx4j/GHSA-8m4x-x8j4-mx4j.json
index 078fa505bb6..4cb51e00516 100644
--- a/advisories/unreviewed/2024/12/GHSA-8m4x-x8j4-mx4j/GHSA-8m4x-x8j4-mx4j.json
+++ b/advisories/unreviewed/2024/12/GHSA-8m4x-x8j4-mx4j/GHSA-8m4x-x8j4-mx4j.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-312"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/12/GHSA-96jh-w5wq-573j/GHSA-96jh-w5wq-573j.json b/advisories/unreviewed/2024/12/GHSA-96jh-w5wq-573j/GHSA-96jh-w5wq-573j.json
index f959c10cdf2..d0d03a7f41c 100644
--- a/advisories/unreviewed/2024/12/GHSA-96jh-w5wq-573j/GHSA-96jh-w5wq-573j.json
+++ b/advisories/unreviewed/2024/12/GHSA-96jh-w5wq-573j/GHSA-96jh-w5wq-573j.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-96jh-w5wq-573j",
- "modified": "2024-12-09T21:31:02Z",
+ "modified": "2024-12-11T18:30:41Z",
"published": "2024-12-09T21:31:02Z",
"aliases": [
"CVE-2024-54927"
],
"details": "Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_users.php.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-09T19:15:16Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-9v3f-6pf4-r264/GHSA-9v3f-6pf4-r264.json b/advisories/unreviewed/2024/12/GHSA-9v3f-6pf4-r264/GHSA-9v3f-6pf4-r264.json
index 1ca860a7967..c10a8b1f03a 100644
--- a/advisories/unreviewed/2024/12/GHSA-9v3f-6pf4-r264/GHSA-9v3f-6pf4-r264.json
+++ b/advisories/unreviewed/2024/12/GHSA-9v3f-6pf4-r264/GHSA-9v3f-6pf4-r264.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9v3f-6pf4-r264",
- "modified": "2024-12-10T21:30:52Z",
+ "modified": "2024-12-11T18:30:42Z",
"published": "2024-12-10T21:30:52Z",
"aliases": [
"CVE-2024-50929"
],
"details": "Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to arbitrarily change the device type in the controller's memory, leading to a Denial of Service (DoS).",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-281"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-10T19:15:30Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-c7v4-r383-g2wj/GHSA-c7v4-r383-g2wj.json b/advisories/unreviewed/2024/12/GHSA-c7v4-r383-g2wj/GHSA-c7v4-r383-g2wj.json
index e20f570fcdd..06fdf04d241 100644
--- a/advisories/unreviewed/2024/12/GHSA-c7v4-r383-g2wj/GHSA-c7v4-r383-g2wj.json
+++ b/advisories/unreviewed/2024/12/GHSA-c7v4-r383-g2wj/GHSA-c7v4-r383-g2wj.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c7v4-r383-g2wj",
- "modified": "2024-12-04T15:31:52Z",
+ "modified": "2024-12-11T18:30:39Z",
"published": "2024-12-04T15:31:52Z",
"aliases": [
"CVE-2024-53132"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/oa: Fix \"Missing outer runtime PM protection\" warning\n\nFix the following drm_WARN:\n\n[953.586396] xe 0000:00:02.0: [drm] Missing outer runtime PM protection\n...\n<4> [953.587090] ? xe_pm_runtime_get_noresume+0x8d/0xa0 [xe]\n<4> [953.587208] guc_exec_queue_add_msg+0x28/0x130 [xe]\n<4> [953.587319] guc_exec_queue_fini+0x3a/0x40 [xe]\n<4> [953.587425] xe_exec_queue_destroy+0xb3/0xf0 [xe]\n<4> [953.587515] xe_oa_release+0x9c/0xc0 [xe]\n\n(cherry picked from commit b107c63d2953907908fd0cafb0e543b3c3167b75)",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -25,7 +30,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-04T15:15:13Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-c8qh-4m7p-p922/GHSA-c8qh-4m7p-p922.json b/advisories/unreviewed/2024/12/GHSA-c8qh-4m7p-p922/GHSA-c8qh-4m7p-p922.json
index b31df41f0a3..9ea0f56a606 100644
--- a/advisories/unreviewed/2024/12/GHSA-c8qh-4m7p-p922/GHSA-c8qh-4m7p-p922.json
+++ b/advisories/unreviewed/2024/12/GHSA-c8qh-4m7p-p922/GHSA-c8qh-4m7p-p922.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c8qh-4m7p-p922",
- "modified": "2024-12-09T18:31:19Z",
+ "modified": "2024-12-11T18:30:41Z",
"published": "2024-12-09T18:31:19Z",
"aliases": [
"CVE-2024-53450"
],
"details": "RAGFlow 0.13.0 suffers from improper access control in document-hooks.ts, allowing unauthorized access to user documents.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-125"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-09T17:15:09Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-fvgc-3wm9-ph8c/GHSA-fvgc-3wm9-ph8c.json b/advisories/unreviewed/2024/12/GHSA-fvgc-3wm9-ph8c/GHSA-fvgc-3wm9-ph8c.json
index 47b14633d4b..fbe83de7c01 100644
--- a/advisories/unreviewed/2024/12/GHSA-fvgc-3wm9-ph8c/GHSA-fvgc-3wm9-ph8c.json
+++ b/advisories/unreviewed/2024/12/GHSA-fvgc-3wm9-ph8c/GHSA-fvgc-3wm9-ph8c.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fvgc-3wm9-ph8c",
- "modified": "2024-12-10T09:31:18Z",
+ "modified": "2024-12-11T18:30:42Z",
"published": "2024-12-10T09:31:18Z",
"aliases": [
"CVE-2024-28138"
],
"details": "An unauthenticated attacker with network access to the affected device's web interface can execute any system command via the \"msg_events.php\" script as the www-data user. The HTTP GET parameter \"data\" is not properly sanitized.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
+ }
+ ],
"affected": [],
"references": [
{
@@ -27,7 +32,7 @@
"cwe_ids": [
"CWE-78"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-10T08:15:18Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-g7g9-rh3x-m925/GHSA-g7g9-rh3x-m925.json b/advisories/unreviewed/2024/12/GHSA-g7g9-rh3x-m925/GHSA-g7g9-rh3x-m925.json
index a0fa7955238..b82114f52ef 100644
--- a/advisories/unreviewed/2024/12/GHSA-g7g9-rh3x-m925/GHSA-g7g9-rh3x-m925.json
+++ b/advisories/unreviewed/2024/12/GHSA-g7g9-rh3x-m925/GHSA-g7g9-rh3x-m925.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g7g9-rh3x-m925",
- "modified": "2024-12-04T21:30:52Z",
+ "modified": "2024-12-11T18:30:40Z",
"published": "2024-12-04T21:30:52Z",
"aliases": [
"CVE-2024-39219"
],
"details": "An issue in Aginode GigaSwitch V5 before version 7.06G allows authenticated attackers with Administrator privileges to upload an earlier firmware version, exposing the device to previously patched vulnerabilities.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -25,7 +30,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-04T21:15:24Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-gm67-5x5w-8f7x/GHSA-gm67-5x5w-8f7x.json b/advisories/unreviewed/2024/12/GHSA-gm67-5x5w-8f7x/GHSA-gm67-5x5w-8f7x.json
index 4c8307379f9..96714b2a65c 100644
--- a/advisories/unreviewed/2024/12/GHSA-gm67-5x5w-8f7x/GHSA-gm67-5x5w-8f7x.json
+++ b/advisories/unreviewed/2024/12/GHSA-gm67-5x5w-8f7x/GHSA-gm67-5x5w-8f7x.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gm67-5x5w-8f7x",
- "modified": "2024-12-04T15:31:52Z",
+ "modified": "2024-12-11T18:30:39Z",
"published": "2024-12-04T15:31:52Z",
"aliases": [
"CVE-2024-53134"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\npmdomain: imx93-blk-ctrl: correct remove path\n\nThe check condition should be 'i < bc->onecell_data.num_domains', not\n'bc->onecell_data.num_domains' which will make the look never finish\nand cause kernel panic.\n\nAlso disable runtime to address\n\"imx93-blk-ctrl 4ac10000.system-controller: Unbalanced pm_runtime_enable!\"",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-670"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-04T15:15:13Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-hmv6-ggqr-j3vm/GHSA-hmv6-ggqr-j3vm.json b/advisories/unreviewed/2024/12/GHSA-hmv6-ggqr-j3vm/GHSA-hmv6-ggqr-j3vm.json
index 3d128682fbf..9cd7823a242 100644
--- a/advisories/unreviewed/2024/12/GHSA-hmv6-ggqr-j3vm/GHSA-hmv6-ggqr-j3vm.json
+++ b/advisories/unreviewed/2024/12/GHSA-hmv6-ggqr-j3vm/GHSA-hmv6-ggqr-j3vm.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hmv6-ggqr-j3vm",
- "modified": "2024-12-09T18:31:19Z",
+ "modified": "2024-12-11T18:30:41Z",
"published": "2024-12-09T18:31:19Z",
"aliases": [
"CVE-2022-38947"
],
"details": "SQL Injection vulnerability in Flipkart-Clone-PHP version 1.0 in entry.php in product_title parameter, allows attackers to execute arbitrary code.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-09T16:15:18Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-jq63-f9q2-ph96/GHSA-jq63-f9q2-ph96.json b/advisories/unreviewed/2024/12/GHSA-jq63-f9q2-ph96/GHSA-jq63-f9q2-ph96.json
new file mode 100644
index 00000000000..8e6ca0a1ac8
--- /dev/null
+++ b/advisories/unreviewed/2024/12/GHSA-jq63-f9q2-ph96/GHSA-jq63-f9q2-ph96.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jq63-f9q2-ph96",
+ "modified": "2024-12-11T18:30:42Z",
+ "published": "2024-12-11T18:30:42Z",
+ "aliases": [
+ "CVE-2024-28140"
+ ],
+ "details": "The scanner device boots into a kiosk mode by default and opens the Scan2Net interface in a browser window. This browser is run with the permissions of the root user. There are also several other applications running as root user. This can be confirmed by running \"ps aux\" as the root user and observing the output.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28140"
+ },
+ {
+ "type": "WEB",
+ "url": "https://r.sec-consult.com/imageaccess"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.imageaccess.de/?page=SupportPortal&lang=en"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-250"
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-12-11T16:15:10Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/12/GHSA-m48f-94xr-79qr/GHSA-m48f-94xr-79qr.json b/advisories/unreviewed/2024/12/GHSA-m48f-94xr-79qr/GHSA-m48f-94xr-79qr.json
index ca5db3aa799..0df8435c67c 100644
--- a/advisories/unreviewed/2024/12/GHSA-m48f-94xr-79qr/GHSA-m48f-94xr-79qr.json
+++ b/advisories/unreviewed/2024/12/GHSA-m48f-94xr-79qr/GHSA-m48f-94xr-79qr.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m48f-94xr-79qr",
- "modified": "2024-12-09T18:31:19Z",
+ "modified": "2024-12-11T18:30:41Z",
"published": "2024-12-09T18:31:19Z",
"aliases": [
"CVE-2024-40583"
],
"details": "Pentaminds CuroVMS v2.0.1 was discovered to contain exposed credentials.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-522"
+ ],
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-09T16:15:22Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-m7cw-wqhh-5pr9/GHSA-m7cw-wqhh-5pr9.json b/advisories/unreviewed/2024/12/GHSA-m7cw-wqhh-5pr9/GHSA-m7cw-wqhh-5pr9.json
index f57b046e7a2..f1da9976e05 100644
--- a/advisories/unreviewed/2024/12/GHSA-m7cw-wqhh-5pr9/GHSA-m7cw-wqhh-5pr9.json
+++ b/advisories/unreviewed/2024/12/GHSA-m7cw-wqhh-5pr9/GHSA-m7cw-wqhh-5pr9.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m7cw-wqhh-5pr9",
- "modified": "2024-12-10T15:32:31Z",
+ "modified": "2024-12-11T18:30:42Z",
"published": "2024-12-10T15:32:31Z",
"aliases": [
"CVE-2024-54751"
],
"details": "COMFAST CF-WR630AX v2.7.0.2 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-276"
+ ],
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-10T15:15:08Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-m9wg-w5mf-5pw9/GHSA-m9wg-w5mf-5pw9.json b/advisories/unreviewed/2024/12/GHSA-m9wg-w5mf-5pw9/GHSA-m9wg-w5mf-5pw9.json
index d779fdcb003..aa8615b4d40 100644
--- a/advisories/unreviewed/2024/12/GHSA-m9wg-w5mf-5pw9/GHSA-m9wg-w5mf-5pw9.json
+++ b/advisories/unreviewed/2024/12/GHSA-m9wg-w5mf-5pw9/GHSA-m9wg-w5mf-5pw9.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m9wg-w5mf-5pw9",
- "modified": "2024-12-09T18:31:19Z",
+ "modified": "2024-12-11T18:30:41Z",
"published": "2024-12-09T18:31:19Z",
"aliases": [
"CVE-2024-40582"
],
"details": "Pentaminds CuroVMS v2.0.1 was discovered to contain exposed sensitive information.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-312"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-09T16:15:22Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-mw8h-4567-xqvj/GHSA-mw8h-4567-xqvj.json b/advisories/unreviewed/2024/12/GHSA-mw8h-4567-xqvj/GHSA-mw8h-4567-xqvj.json
index 63ba167b94e..663cb578b8e 100644
--- a/advisories/unreviewed/2024/12/GHSA-mw8h-4567-xqvj/GHSA-mw8h-4567-xqvj.json
+++ b/advisories/unreviewed/2024/12/GHSA-mw8h-4567-xqvj/GHSA-mw8h-4567-xqvj.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mw8h-4567-xqvj",
- "modified": "2024-12-10T18:31:07Z",
+ "modified": "2024-12-11T18:30:42Z",
"published": "2024-12-10T18:31:07Z",
"aliases": [
"CVE-2024-46657"
],
"details": "Artifex Software mupdf v1.24.9 was discovered to contain a segmentation fault via the component /tools/pdfextract.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-120"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-10T17:15:10Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-p8jq-vpfm-hqfj/GHSA-p8jq-vpfm-hqfj.json b/advisories/unreviewed/2024/12/GHSA-p8jq-vpfm-hqfj/GHSA-p8jq-vpfm-hqfj.json
new file mode 100644
index 00000000000..a61d3d61074
--- /dev/null
+++ b/advisories/unreviewed/2024/12/GHSA-p8jq-vpfm-hqfj/GHSA-p8jq-vpfm-hqfj.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-p8jq-vpfm-hqfj",
+ "modified": "2024-12-11T18:30:42Z",
+ "published": "2024-12-11T18:30:42Z",
+ "aliases": [
+ "CVE-2024-9845"
+ ],
+ "details": "Under specific circumstances, insecure permissions in Ivanti Automation before version 2024.4.0.1 allows a local authenticated attacker to achieve local privilege escalation.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9845"
+ },
+ {
+ "type": "WEB",
+ "url": "https://forums.ivanti.com/s/article/December-2024-Security-Advisory-Ivanti-Automation-CVE-2024-9845"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-276"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-12-11T17:15:21Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/12/GHSA-pc3w-52r9-h2g7/GHSA-pc3w-52r9-h2g7.json b/advisories/unreviewed/2024/12/GHSA-pc3w-52r9-h2g7/GHSA-pc3w-52r9-h2g7.json
index c0d9a3867b3..7ec6c90488e 100644
--- a/advisories/unreviewed/2024/12/GHSA-pc3w-52r9-h2g7/GHSA-pc3w-52r9-h2g7.json
+++ b/advisories/unreviewed/2024/12/GHSA-pc3w-52r9-h2g7/GHSA-pc3w-52r9-h2g7.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pc3w-52r9-h2g7",
- "modified": "2024-12-05T12:31:28Z",
+ "modified": "2024-12-11T18:30:40Z",
"published": "2024-12-04T15:31:52Z",
"aliases": [
"CVE-2024-53140"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetlink: terminate outstanding dump on socket close\n\nNetlink supports iterative dumping of data. It provides the families\nthe following ops:\n - start - (optional) kicks off the dumping process\n - dump - actual dump helper, keeps getting called until it returns 0\n - done - (optional) pairs with .start, can be used for cleanup\nThe whole process is asynchronous and the repeated calls to .dump\ndon't actually happen in a tight loop, but rather are triggered\nin response to recvmsg() on the socket.\n\nThis gives the user full control over the dump, but also means that\nthe user can close the socket without getting to the end of the dump.\nTo make sure .start is always paired with .done we check if there\nis an ongoing dump before freeing the socket, and if so call .done.\n\nThe complication is that sockets can get freed from BH and .done\nis allowed to sleep. So we use a workqueue to defer the call, when\nneeded.\n\nUnfortunately this does not work correctly. What we defer is not\nthe cleanup but rather releasing a reference on the socket.\nWe have no guarantee that we own the last reference, if someone\nelse holds the socket they may release it in BH and we're back\nto square one.\n\nThe whole dance, however, appears to be unnecessary. Only the user\ncan interact with dumps, so we can clean up when socket is closed.\nAnd close always happens in process context. Some async code may\nstill access the socket after close, queue notification skbs to it etc.\nbut no dumps can start, end or otherwise make progress.\n\nDelete the workqueue and flush the dump state directly from the release\nhandler. Note that further cleanup is possible in -next, for instance\nwe now always call .done before releasing the main module reference,\nso dump doesn't have to take a reference of its own.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -37,7 +42,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-04T15:15:16Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-ph9m-4f8h-q2f7/GHSA-ph9m-4f8h-q2f7.json b/advisories/unreviewed/2024/12/GHSA-ph9m-4f8h-q2f7/GHSA-ph9m-4f8h-q2f7.json
index a46d08da768..e4262920249 100644
--- a/advisories/unreviewed/2024/12/GHSA-ph9m-4f8h-q2f7/GHSA-ph9m-4f8h-q2f7.json
+++ b/advisories/unreviewed/2024/12/GHSA-ph9m-4f8h-q2f7/GHSA-ph9m-4f8h-q2f7.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ph9m-4f8h-q2f7",
- "modified": "2024-12-05T21:31:52Z",
+ "modified": "2024-12-11T18:30:40Z",
"published": "2024-12-05T21:31:52Z",
"aliases": [
"CVE-2024-53442"
],
"details": "whapa v1.59 is vulnerable to Command Injection via a crafted filename to the HTML reports component.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-05T20:15:22Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-pqj8-xhcx-prxm/GHSA-pqj8-xhcx-prxm.json b/advisories/unreviewed/2024/12/GHSA-pqj8-xhcx-prxm/GHSA-pqj8-xhcx-prxm.json
index b512066861f..4c3ee4c3d14 100644
--- a/advisories/unreviewed/2024/12/GHSA-pqj8-xhcx-prxm/GHSA-pqj8-xhcx-prxm.json
+++ b/advisories/unreviewed/2024/12/GHSA-pqj8-xhcx-prxm/GHSA-pqj8-xhcx-prxm.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pqj8-xhcx-prxm",
- "modified": "2024-12-04T18:32:36Z",
+ "modified": "2024-12-11T18:30:40Z",
"published": "2024-12-04T18:32:36Z",
"aliases": [
"CVE-2024-39163"
],
"details": "binux pyspider up to v0.3.10 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Flask endpoints.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-04T17:15:13Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-qch9-x876-gmcw/GHSA-qch9-x876-gmcw.json b/advisories/unreviewed/2024/12/GHSA-qch9-x876-gmcw/GHSA-qch9-x876-gmcw.json
new file mode 100644
index 00000000000..7c76b1ad9c8
--- /dev/null
+++ b/advisories/unreviewed/2024/12/GHSA-qch9-x876-gmcw/GHSA-qch9-x876-gmcw.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qch9-x876-gmcw",
+ "modified": "2024-12-11T18:30:42Z",
+ "published": "2024-12-11T18:30:42Z",
+ "aliases": [
+ "CVE-2024-11598"
+ ],
+ "details": "Under specific circumstances, insecure permissions in Ivanti Application Control before version 2024.3 HF1, 2024.1 HF2, or 2023.3 HF3 allows a local authenticated attacker to achieve local privilege escalation.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11598"
+ },
+ {
+ "type": "WEB",
+ "url": "https://forums.ivanti.com/s/article/December-2024-Security-Advisory-Ivanti-Application-Control-CVE-2024-11598"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-276"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-12-11T17:15:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/12/GHSA-qp3v-mjc4-jjf3/GHSA-qp3v-mjc4-jjf3.json b/advisories/unreviewed/2024/12/GHSA-qp3v-mjc4-jjf3/GHSA-qp3v-mjc4-jjf3.json
index c798c3dfc61..270603cf411 100644
--- a/advisories/unreviewed/2024/12/GHSA-qp3v-mjc4-jjf3/GHSA-qp3v-mjc4-jjf3.json
+++ b/advisories/unreviewed/2024/12/GHSA-qp3v-mjc4-jjf3/GHSA-qp3v-mjc4-jjf3.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qp3v-mjc4-jjf3",
- "modified": "2024-12-05T18:31:03Z",
+ "modified": "2024-12-11T18:30:40Z",
"published": "2024-12-05T18:31:03Z",
"aliases": [
"CVE-2024-53490"
],
"details": "Favorites-web 1.3.0 favorites-web has a directory traversal vulnerability in SecurityFilter.java.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-22"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-05T17:15:14Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-r8vm-2j4g-7jq3/GHSA-r8vm-2j4g-7jq3.json b/advisories/unreviewed/2024/12/GHSA-r8vm-2j4g-7jq3/GHSA-r8vm-2j4g-7jq3.json
index 84aba228410..7b8e6a8a746 100644
--- a/advisories/unreviewed/2024/12/GHSA-r8vm-2j4g-7jq3/GHSA-r8vm-2j4g-7jq3.json
+++ b/advisories/unreviewed/2024/12/GHSA-r8vm-2j4g-7jq3/GHSA-r8vm-2j4g-7jq3.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r8vm-2j4g-7jq3",
- "modified": "2024-12-04T15:31:53Z",
+ "modified": "2024-12-11T18:30:39Z",
"published": "2024-12-04T15:31:53Z",
"aliases": [
"CVE-2024-53138"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: kTLS, Fix incorrect page refcounting\n\nThe kTLS tx handling code is using a mix of get_page() and\npage_ref_inc() APIs to increment the page reference. But on the release\npath (mlx5e_ktls_tx_handle_resync_dump_comp()), only put_page() is used.\n\nThis is an issue when using pages from large folios: the get_page()\nreferences are stored on the folio page while the page_ref_inc()\nreferences are stored directly in the given page. On release the folio\npage will be dereferenced too many times.\n\nThis was found while doing kTLS testing with sendfile() + ZC when the\nserved file was read from NFS on a kernel with NFS large folios support\n(commit 49b29a573da8 (\"nfs: add support for large folios\")).",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -33,7 +38,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-04T15:15:13Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-rhph-9qcj-jrgq/GHSA-rhph-9qcj-jrgq.json b/advisories/unreviewed/2024/12/GHSA-rhph-9qcj-jrgq/GHSA-rhph-9qcj-jrgq.json
index a0dbbd18c96..1ce8e25c3c5 100644
--- a/advisories/unreviewed/2024/12/GHSA-rhph-9qcj-jrgq/GHSA-rhph-9qcj-jrgq.json
+++ b/advisories/unreviewed/2024/12/GHSA-rhph-9qcj-jrgq/GHSA-rhph-9qcj-jrgq.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rhph-9qcj-jrgq",
- "modified": "2024-12-06T18:30:45Z",
+ "modified": "2024-12-11T18:30:40Z",
"published": "2024-12-06T18:30:45Z",
"aliases": [
"CVE-2024-54745"
],
"details": "WAVLINK WN701AE M01AE_V240305 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-276"
+ ],
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-06T16:15:22Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-rqmg-x323-7vjh/GHSA-rqmg-x323-7vjh.json b/advisories/unreviewed/2024/12/GHSA-rqmg-x323-7vjh/GHSA-rqmg-x323-7vjh.json
new file mode 100644
index 00000000000..fb3bee51a83
--- /dev/null
+++ b/advisories/unreviewed/2024/12/GHSA-rqmg-x323-7vjh/GHSA-rqmg-x323-7vjh.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-rqmg-x323-7vjh",
+ "modified": "2024-12-11T18:30:42Z",
+ "published": "2024-12-11T18:30:42Z",
+ "aliases": [
+ "CVE-2024-10251"
+ ],
+ "details": "Under specific circumstances, insecure permissions in Ivanti Security Controls before version 2024.4.1 allows a local authenticated attacker to achieve local privilege escalation.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10251"
+ },
+ {
+ "type": "WEB",
+ "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Security-Controls-iSec-CVE-2024-10251"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-276"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-12-11T17:15:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/12/GHSA-rvc2-xvxc-m9fw/GHSA-rvc2-xvxc-m9fw.json b/advisories/unreviewed/2024/12/GHSA-rvc2-xvxc-m9fw/GHSA-rvc2-xvxc-m9fw.json
index df9493e29c6..90514c1dbc3 100644
--- a/advisories/unreviewed/2024/12/GHSA-rvc2-xvxc-m9fw/GHSA-rvc2-xvxc-m9fw.json
+++ b/advisories/unreviewed/2024/12/GHSA-rvc2-xvxc-m9fw/GHSA-rvc2-xvxc-m9fw.json
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-74"
+ "CWE-74",
+ "CWE-94"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/12/GHSA-v24x-74gw-crvq/GHSA-v24x-74gw-crvq.json b/advisories/unreviewed/2024/12/GHSA-v24x-74gw-crvq/GHSA-v24x-74gw-crvq.json
index 757ca4a58c1..67db3f28c27 100644
--- a/advisories/unreviewed/2024/12/GHSA-v24x-74gw-crvq/GHSA-v24x-74gw-crvq.json
+++ b/advisories/unreviewed/2024/12/GHSA-v24x-74gw-crvq/GHSA-v24x-74gw-crvq.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v24x-74gw-crvq",
- "modified": "2024-12-10T21:30:52Z",
+ "modified": "2024-12-11T18:30:42Z",
"published": "2024-12-10T21:30:52Z",
"aliases": [
"CVE-2024-50920"
],
"details": "Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to create a fake node via supplying crafted packets.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-281"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-10T19:15:30Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-vh4h-v74p-9778/GHSA-vh4h-v74p-9778.json b/advisories/unreviewed/2024/12/GHSA-vh4h-v74p-9778/GHSA-vh4h-v74p-9778.json
index 8c7d0c4e968..4df723aa2b1 100644
--- a/advisories/unreviewed/2024/12/GHSA-vh4h-v74p-9778/GHSA-vh4h-v74p-9778.json
+++ b/advisories/unreviewed/2024/12/GHSA-vh4h-v74p-9778/GHSA-vh4h-v74p-9778.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vh4h-v74p-9778",
- "modified": "2024-12-09T18:31:19Z",
+ "modified": "2024-12-11T18:30:41Z",
"published": "2024-12-09T18:31:19Z",
"aliases": [
"CVE-2024-54926"
],
"details": "A SQL Injection vulnerability was found in /search_class.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the school_year parameter.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-09T17:15:09Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-vq37-g99r-q77r/GHSA-vq37-g99r-q77r.json b/advisories/unreviewed/2024/12/GHSA-vq37-g99r-q77r/GHSA-vq37-g99r-q77r.json
index 48d0bcdb08c..dc0cb4a47fc 100644
--- a/advisories/unreviewed/2024/12/GHSA-vq37-g99r-q77r/GHSA-vq37-g99r-q77r.json
+++ b/advisories/unreviewed/2024/12/GHSA-vq37-g99r-q77r/GHSA-vq37-g99r-q77r.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vq37-g99r-q77r",
- "modified": "2024-12-09T18:31:19Z",
+ "modified": "2024-12-11T18:30:41Z",
"published": "2024-12-09T18:31:19Z",
"aliases": [
"CVE-2024-54922"
],
"details": "A SQL Injection was found in /lms/admin/edit_user.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the firstname, lastname, and username parameters.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-09T18:15:24Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-vq87-xfrv-42wp/GHSA-vq87-xfrv-42wp.json b/advisories/unreviewed/2024/12/GHSA-vq87-xfrv-42wp/GHSA-vq87-xfrv-42wp.json
index a9694d0e7c9..054d18a1fdb 100644
--- a/advisories/unreviewed/2024/12/GHSA-vq87-xfrv-42wp/GHSA-vq87-xfrv-42wp.json
+++ b/advisories/unreviewed/2024/12/GHSA-vq87-xfrv-42wp/GHSA-vq87-xfrv-42wp.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vq87-xfrv-42wp",
- "modified": "2024-12-10T00:31:26Z",
+ "modified": "2024-12-11T18:30:41Z",
"published": "2024-12-10T00:31:26Z",
"aliases": [
"CVE-2024-50627"
],
"details": "An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Privilege Escalation vulnerability exists in the file upload feature. It allows an attacker on the local area network (with specific permissions) to upload and execute malicious files, potentially leading to unauthorized system access.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-552"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-09T22:15:22Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-w92r-fpr6-76rv/GHSA-w92r-fpr6-76rv.json b/advisories/unreviewed/2024/12/GHSA-w92r-fpr6-76rv/GHSA-w92r-fpr6-76rv.json
index 16bf9689b42..0907304cebd 100644
--- a/advisories/unreviewed/2024/12/GHSA-w92r-fpr6-76rv/GHSA-w92r-fpr6-76rv.json
+++ b/advisories/unreviewed/2024/12/GHSA-w92r-fpr6-76rv/GHSA-w92r-fpr6-76rv.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w92r-fpr6-76rv",
- "modified": "2024-12-09T21:31:01Z",
+ "modified": "2024-12-11T18:30:41Z",
"published": "2024-12-09T21:31:01Z",
"aliases": [
"CVE-2024-48956"
],
"details": "Serviceware Processes 6.0 through 7.3 allows attackers without valid authentication to send a specially crafted HTTP request to a service endpoint resulting in remote code execution.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-120"
+ ],
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-09T19:15:13Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-wc68-rh2f-56m4/GHSA-wc68-rh2f-56m4.json b/advisories/unreviewed/2024/12/GHSA-wc68-rh2f-56m4/GHSA-wc68-rh2f-56m4.json
index 1a2dfe79fbf..35fe70760e0 100644
--- a/advisories/unreviewed/2024/12/GHSA-wc68-rh2f-56m4/GHSA-wc68-rh2f-56m4.json
+++ b/advisories/unreviewed/2024/12/GHSA-wc68-rh2f-56m4/GHSA-wc68-rh2f-56m4.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-125"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/12/GHSA-wqvc-3mg4-x25w/GHSA-wqvc-3mg4-x25w.json b/advisories/unreviewed/2024/12/GHSA-wqvc-3mg4-x25w/GHSA-wqvc-3mg4-x25w.json
index bc9a98925ef..10b9b9ec7c7 100644
--- a/advisories/unreviewed/2024/12/GHSA-wqvc-3mg4-x25w/GHSA-wqvc-3mg4-x25w.json
+++ b/advisories/unreviewed/2024/12/GHSA-wqvc-3mg4-x25w/GHSA-wqvc-3mg4-x25w.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wqvc-3mg4-x25w",
- "modified": "2024-12-05T21:31:52Z",
+ "modified": "2024-12-11T18:30:40Z",
"published": "2024-12-05T21:31:52Z",
"aliases": [
"CVE-2024-41579"
],
"details": "DTStack Taier 1.4.0 allows remote attackers to specify the jobName parameter in the console listNames function to cause a SQL injection vulnerability",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-05T20:15:22Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-wxx9-pq23-vg6j/GHSA-wxx9-pq23-vg6j.json b/advisories/unreviewed/2024/12/GHSA-wxx9-pq23-vg6j/GHSA-wxx9-pq23-vg6j.json
index 4045ad3488c..ef6ee8370e3 100644
--- a/advisories/unreviewed/2024/12/GHSA-wxx9-pq23-vg6j/GHSA-wxx9-pq23-vg6j.json
+++ b/advisories/unreviewed/2024/12/GHSA-wxx9-pq23-vg6j/GHSA-wxx9-pq23-vg6j.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wxx9-pq23-vg6j",
- "modified": "2024-12-09T21:31:02Z",
+ "modified": "2024-12-11T18:30:41Z",
"published": "2024-12-09T21:31:02Z",
"aliases": [
"CVE-2024-54938"
],
"details": "A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/uploads.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-125"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-09T19:15:17Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-x4ww-j464-7jpg/GHSA-x4ww-j464-7jpg.json b/advisories/unreviewed/2024/12/GHSA-x4ww-j464-7jpg/GHSA-x4ww-j464-7jpg.json
index d2a6c101f7b..a1fb6c6b347 100644
--- a/advisories/unreviewed/2024/12/GHSA-x4ww-j464-7jpg/GHSA-x4ww-j464-7jpg.json
+++ b/advisories/unreviewed/2024/12/GHSA-x4ww-j464-7jpg/GHSA-x4ww-j464-7jpg.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x4ww-j464-7jpg",
- "modified": "2024-12-10T00:31:26Z",
+ "modified": "2024-12-11T18:30:41Z",
"published": "2024-12-10T00:31:26Z",
"aliases": [
"CVE-2024-50628"
],
"details": "An issue was discovered in the web services of Digi ConnectPort LTS before 1.4.12. It allows an attacker on the local area network to achieve unauthorized manipulation of resources, which may lead to remote code execution when combined with other issues.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-09T22:15:22Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-x5rh-6m69-mwg4/GHSA-x5rh-6m69-mwg4.json b/advisories/unreviewed/2024/12/GHSA-x5rh-6m69-mwg4/GHSA-x5rh-6m69-mwg4.json
index d83ab86934d..42490876c72 100644
--- a/advisories/unreviewed/2024/12/GHSA-x5rh-6m69-mwg4/GHSA-x5rh-6m69-mwg4.json
+++ b/advisories/unreviewed/2024/12/GHSA-x5rh-6m69-mwg4/GHSA-x5rh-6m69-mwg4.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x5rh-6m69-mwg4",
- "modified": "2024-12-02T21:31:20Z",
+ "modified": "2024-12-11T18:30:38Z",
"published": "2024-12-02T21:31:20Z",
"aliases": [
"CVE-2024-53477"
],
"details": "JFinal CMS 5.1.0 is vulnerable to Command Execution via unauthorized execution of deserialization in the file ApiForm.java",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-502"
+ ],
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-02T21:15:11Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-xfmg-7r6x-xpg8/GHSA-xfmg-7r6x-xpg8.json b/advisories/unreviewed/2024/12/GHSA-xfmg-7r6x-xpg8/GHSA-xfmg-7r6x-xpg8.json
index 059b583fffc..edf521966ec 100644
--- a/advisories/unreviewed/2024/12/GHSA-xfmg-7r6x-xpg8/GHSA-xfmg-7r6x-xpg8.json
+++ b/advisories/unreviewed/2024/12/GHSA-xfmg-7r6x-xpg8/GHSA-xfmg-7r6x-xpg8.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xfmg-7r6x-xpg8",
- "modified": "2024-12-09T21:31:02Z",
+ "modified": "2024-12-11T18:30:41Z",
"published": "2024-12-09T21:31:02Z",
"aliases": [
"CVE-2024-54924"
],
"details": "A SQL Injection was found in /admin/edit_content.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the title and content parameters.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-09T19:15:16Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-xqf3-q69c-jc7c/GHSA-xqf3-q69c-jc7c.json b/advisories/unreviewed/2024/12/GHSA-xqf3-q69c-jc7c/GHSA-xqf3-q69c-jc7c.json
index cf7b768108c..2f1dd2f2728 100644
--- a/advisories/unreviewed/2024/12/GHSA-xqf3-q69c-jc7c/GHSA-xqf3-q69c-jc7c.json
+++ b/advisories/unreviewed/2024/12/GHSA-xqf3-q69c-jc7c/GHSA-xqf3-q69c-jc7c.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xqf3-q69c-jc7c",
- "modified": "2024-12-10T21:30:52Z",
+ "modified": "2024-12-11T18:30:42Z",
"published": "2024-12-10T21:30:52Z",
"aliases": [
"CVE-2024-50931"
],
"details": "Silicon Labs Z-Wave Series 500 v6.84.0 was discovered to contain insecure permissions.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-281"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-10T19:15:30Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-xr7h-9g48-33qf/GHSA-xr7h-9g48-33qf.json b/advisories/unreviewed/2024/12/GHSA-xr7h-9g48-33qf/GHSA-xr7h-9g48-33qf.json
index 3afe5fb1e9a..1bf761baed5 100644
--- a/advisories/unreviewed/2024/12/GHSA-xr7h-9g48-33qf/GHSA-xr7h-9g48-33qf.json
+++ b/advisories/unreviewed/2024/12/GHSA-xr7h-9g48-33qf/GHSA-xr7h-9g48-33qf.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xr7h-9g48-33qf",
- "modified": "2024-12-09T21:31:01Z",
+ "modified": "2024-12-11T18:30:41Z",
"published": "2024-12-09T21:31:01Z",
"aliases": [
"CVE-2024-46547"
],
"details": "A vulnerability was found in Romain Bourdon Wampserver all versions (discovered in v3.2.3 and v3.2.6) where unauthorized users could access sensitive information due to improper access control validation via PHP Info Page. This issue can lead to data leaks.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-116"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-09T19:15:13Z"