Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-09-10 12:31:56 +00:00
parent 9c73f0eba4
commit 3b530f1f8f
47 changed files with 1356 additions and 20 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4vvg-656r-c25j",
"modified": "2024-07-09T12:30:54Z",
"modified": "2024-09-10T12:30:32Z",
"published": "2022-05-13T01:02:38Z",
"aliases": [
"CVE-2017-2680"
@@ -11,6 +11,10 @@
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gm9h-7xvc-jg2f",
"modified": "2023-01-10T12:30:27Z",
"modified": "2024-09-10T12:30:33Z",
"published": "2022-05-24T16:58:25Z",
"aliases": [
"CVE-2019-10923"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2019-10923"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/html/ssa-349422.html"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-349422.pdf"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j585-83xv-q5c7",
"modified": "2024-07-09T12:30:54Z",
"modified": "2024-09-10T12:30:32Z",
"published": "2022-05-13T01:02:35Z",
"aliases": [
"CVE-2017-2681"
@@ -11,6 +11,10 @@
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xv3q-r363-84pg",
"modified": "2023-12-12T12:30:41Z",
"modified": "2024-09-10T12:30:33Z",
"published": "2022-05-24T17:44:31Z",
"aliases": [
"CVE-2020-25236"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-25236"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/html/ssa-783481.html"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-783481.pdf"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j45q-g2vj-3f3r",
"modified": "2022-10-12T19:00:40Z",
"modified": "2024-09-10T12:30:33Z",
"published": "2022-10-11T12:00:45Z",
"aliases": [
"CVE-2022-36363"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36363"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/html/ssa-955858.html"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-955858.pdf"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jhfv-fgvm-hh32",
"modified": "2022-10-12T19:00:40Z",
"modified": "2024-09-10T12:30:33Z",
"published": "2022-10-11T12:00:45Z",
"aliases": [
"CVE-2022-36361"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36361"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/html/ssa-955858.html"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-955858.pdf"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mgxw-53vp-m2rh",
"modified": "2022-10-12T19:00:40Z",
"modified": "2024-09-10T12:30:33Z",
"published": "2022-10-11T12:00:45Z",
"aliases": [
"CVE-2022-36362"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36362"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/html/ssa-955858.html"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-955858.pdf"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-86gv-6g4q-x856",
"modified": "2024-08-13T09:30:52Z",
"modified": "2024-09-10T12:30:34Z",
"published": "2023-11-14T12:30:27Z",
"aliases": [
"CVE-2023-44373"
@@ -41,6 +41,10 @@
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/html/ssa-699386.html"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/html/ssa-721642.html"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-180704.pdf"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-395m-pvc6-8rvm",
"modified": "2024-08-13T09:30:51Z",
"modified": "2024-09-10T12:30:35Z",
"published": "2023-12-12T12:30:54Z",
"aliases": [
"CVE-2023-46283"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-84mm-xgw8-mv4q",
"modified": "2024-08-13T09:30:51Z",
"modified": "2024-09-10T12:30:35Z",
"published": "2023-12-12T12:30:54Z",
"aliases": [
"CVE-2023-46285"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9qvw-gvq6-g569",
"modified": "2024-08-13T09:30:51Z",
"modified": "2024-09-10T12:30:35Z",
"published": "2023-12-12T12:30:53Z",
"aliases": [
"CVE-2023-46281"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f2hj-x395-x532",
"modified": "2024-08-13T09:30:51Z",
"modified": "2024-09-10T12:30:35Z",
"published": "2023-12-12T12:30:54Z",
"aliases": [
"CVE-2023-46284"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fmr5-j3hh-jpg4",
"modified": "2024-08-13T09:30:51Z",
"modified": "2024-09-10T12:30:35Z",
"published": "2023-12-12T12:30:54Z",
"aliases": [
"CVE-2023-46282"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g38w-3g42-rgpg",
"modified": "2023-12-12T12:30:51Z",
"modified": "2024-09-10T12:30:35Z",
"published": "2023-12-12T12:30:51Z",
"aliases": [
"CVE-2022-42784"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42784"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/html/ssa-844582.html"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-844582.pdf"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cc9x-2646-xv35",
"modified": "2024-03-12T12:30:48Z",
"modified": "2024-09-10T12:30:35Z",
"published": "2024-03-12T12:30:48Z",
"aliases": [
"CVE-2024-21483"
@@ -11,6 +11,10 @@
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-23q7-9vq5-jc43",
"modified": "2024-09-10T12:30:38Z",
"published": "2024-09-10T12:30:38Z",
"aliases": [
"CVE-2024-40754"
],
"details": "Heap-based Buffer Overflow vulnerability in Samsung Open Source Escargot JavaScript engine allows Overflow Buffers.This issue affects Escargot: 4.0.0.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40754"
},
{
"type": "WEB",
"url": "https://github.com/Samsung/escargot/pull/1369"
}
],
"database_specific": {
"cwe_ids": [
"CWE-122"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-10T11:15:10Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-36gf-ghcv-f3qq",
"modified": "2024-09-10T12:30:37Z",
"published": "2024-09-10T12:30:37Z",
"aliases": [
"CVE-2023-49069"
],
"details": "A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.14.0 only if the basic authentication mechanism is used by the application), Mendix Runtime V10.12 (All versions < V10.12.2 only if the basic authentication mechanism is used by the application), Mendix Runtime V10.6 (All versions < V10.6.12 only if the basic authentication mechanism is used by the application), Mendix Runtime V8 (All versions only if the basic authentication mechanism is used by the application), Mendix Runtime V9 (All versions < V9.24.26 only if the basic authentication mechanism is used by the application). The authentication mechanism of affected applications contains an observable response discrepancy vulnerability when validating usernames. This could allow unauthenticated remote attackers to distinguish between valid and invalid usernames.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49069"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/html/ssa-097435.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-204"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-10T10:15:08Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-39wj-cf86-6v9w",
"modified": "2024-09-10T12:30:37Z",
"published": "2024-09-10T12:30:37Z",
"aliases": [
"CVE-2023-2919"
],
"details": "The Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.4. This is due to missing or incorrect nonce validation on the 'addon_enable_disable' function. This makes it possible for unauthenticated attackers to enable or disable addons via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2919"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/tutor/trunk/classes/Ajax.php?rev=3128650#L506"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3148621/tutor/tags/2.7.5/classes/Ajax.php"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/992abd72-2a8e-4bda-94c2-4a7f88487906?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-10T10:15:05Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-44w9-25wr-fjwf",
"modified": "2024-09-10T12:30:37Z",
"published": "2024-09-10T12:30:37Z",
"aliases": [
"CVE-2023-30755"
],
"details": "A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-7 LTE (All versions < V3.5.20), SIMATIC CP 1243-8 IRC (6GK7243-8RX30-0XE0) (All versions < V3.5.20), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions), SIMATIC IPC DiagBase (All versions), SIMATIC IPC DiagMonitor (All versions), SIMATIC WinCC Runtime Advanced (All versions), SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0) (All versions < V2.4.8), TIM 1531 IRC (6GK7543-1MX00-0XE0) (All versions < V2.4.8). The web server of the affected devices do not properly handle the shutdown or reboot request, which could lead to the clean up of certain resources. \n\nThis could allow a remote attacker with elevated privileges to cause a denial of service condition in the system.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30755"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/html/ssa-423808.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-476"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-10T10:15:05Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4p43-gfmp-qjmm",
"modified": "2024-09-10T12:30:37Z",
"published": "2024-09-10T12:30:37Z",
"aliases": [
"CVE-2023-30756"
],
"details": "A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-7 LTE (All versions < V3.5.20), SIMATIC CP 1243-8 IRC (6GK7243-8RX30-0XE0) (All versions < V3.5.20), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions), SIMATIC IPC DiagBase (All versions), SIMATIC IPC DiagMonitor (All versions), SIMATIC WinCC Runtime Advanced (All versions), SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0) (All versions < V2.4.8), TIM 1531 IRC (6GK7543-1MX00-0XE0) (All versions < V2.4.8). The web server of the affected devices do not properly handle certain errors when using the Expect HTTP request header, resulting in NULL dereference.\n\nThis could allow a remote attacker with no privileges to cause a denial of service condition in the system.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30756"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/html/ssa-423808.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-476"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-10T10:15:06Z"
}
}

Some files were not shown because too many files have changed in this diff Show More