From 3cb5df5e78225b6efb0c6d08abf00982aba816dd Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 25 Sep 2024 15:32:42 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-7f3x-fvqf-q6q5.json | 2 +- .../GHSA-5x5v-v8qh-gwrg.json | 2 +- .../GHSA-864g-m8f5-w226.json | 2 +- .../GHSA-g984-6p7h-qw9r.json | 2 +- .../GHSA-qq37-j4m8-2hhr.json | 2 +- .../GHSA-6r7v-r49r-49r5.json | 2 +- .../GHSA-jhc8-v2x5-jvj5.json | 3 +- .../GHSA-mr2m-75hp-m2f7.json | 3 +- .../GHSA-qjqc-63v2-7m34.json | 2 +- .../GHSA-x382-ggwj-j3wq.json | 3 +- .../GHSA-2m8v-gj6w-pvrw.json | 38 +++++++++++++ .../GHSA-2q3v-8m45-45jg.json | 9 ++-- .../GHSA-38h7-7925-fvwv.json | 11 ++-- .../GHSA-3hwv-fr9j-3wjq.json | 35 ++++++++++++ .../GHSA-3x94-47mg-35rf.json | 38 +++++++++++++ .../GHSA-4wh3-4hcw-ph3f.json | 38 +++++++++++++ .../GHSA-5mvr-wqp8-rqpq.json | 35 ++++++++++++ .../GHSA-6cm4-chj3-vwmx.json | 38 +++++++++++++ .../GHSA-6q8c-85p2-954c.json | 38 +++++++++++++ .../GHSA-6xmx-57h5-2fhv.json | 38 +++++++++++++ .../GHSA-73q2-8gvp-gh6w.json | 54 +++++++++++++++++++ .../GHSA-7gm9-jx2g-wpvm.json | 9 ++-- .../GHSA-7v3f-jf4x-gj99.json | 9 ++-- .../GHSA-8476-jpv4-xp4p.json | 11 ++-- .../GHSA-c4jq-v98x-5qm2.json | 3 +- .../GHSA-cxpf-r354-3v48.json | 38 +++++++++++++ .../GHSA-f5pf-wc6m-cx7j.json | 9 ++-- .../GHSA-fffw-jm62-gx8w.json | 38 +++++++++++++ .../GHSA-fvmx-5p62-pxm8.json | 9 ++-- .../GHSA-gm8f-9rvm-rrfq.json | 9 ++-- .../GHSA-gwm9-fmrx-q4pp.json | 9 ++-- .../GHSA-hqp9-2fgf-h6cx.json | 9 ++-- .../GHSA-hrw6-9556-27w2.json | 11 ++-- .../GHSA-jp9w-w77g-78h3.json | 38 +++++++++++++ .../GHSA-m6gq-8g82-wvgx.json | 9 ++-- .../GHSA-mj2f-7q85-79p2.json | 9 ++-- .../GHSA-mrp4-v2gf-6mxp.json | 9 ++-- .../GHSA-p477-mp4x-pw85.json | 2 +- .../GHSA-qqpc-7c83-686v.json | 9 ++-- .../GHSA-v6p4-r397-q442.json | 6 ++- .../GHSA-vx7x-qwmp-h33c.json | 35 ++++++++++++ .../GHSA-wg39-r923-gfr5.json | 9 ++-- .../GHSA-x829-m68r-85mm.json | 35 ++++++++++++ .../GHSA-xmf6-p99q-898v.json | 11 ++-- 44 files changed, 663 insertions(+), 68 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-2m8v-gj6w-pvrw/GHSA-2m8v-gj6w-pvrw.json create mode 100644 advisories/unreviewed/2024/09/GHSA-3hwv-fr9j-3wjq/GHSA-3hwv-fr9j-3wjq.json create mode 100644 advisories/unreviewed/2024/09/GHSA-3x94-47mg-35rf/GHSA-3x94-47mg-35rf.json create mode 100644 advisories/unreviewed/2024/09/GHSA-4wh3-4hcw-ph3f/GHSA-4wh3-4hcw-ph3f.json create mode 100644 advisories/unreviewed/2024/09/GHSA-5mvr-wqp8-rqpq/GHSA-5mvr-wqp8-rqpq.json create mode 100644 advisories/unreviewed/2024/09/GHSA-6cm4-chj3-vwmx/GHSA-6cm4-chj3-vwmx.json create mode 100644 advisories/unreviewed/2024/09/GHSA-6q8c-85p2-954c/GHSA-6q8c-85p2-954c.json create mode 100644 advisories/unreviewed/2024/09/GHSA-6xmx-57h5-2fhv/GHSA-6xmx-57h5-2fhv.json create mode 100644 advisories/unreviewed/2024/09/GHSA-73q2-8gvp-gh6w/GHSA-73q2-8gvp-gh6w.json create mode 100644 advisories/unreviewed/2024/09/GHSA-cxpf-r354-3v48/GHSA-cxpf-r354-3v48.json create mode 100644 advisories/unreviewed/2024/09/GHSA-fffw-jm62-gx8w/GHSA-fffw-jm62-gx8w.json create mode 100644 advisories/unreviewed/2024/09/GHSA-jp9w-w77g-78h3/GHSA-jp9w-w77g-78h3.json create mode 100644 advisories/unreviewed/2024/09/GHSA-vx7x-qwmp-h33c/GHSA-vx7x-qwmp-h33c.json create mode 100644 advisories/unreviewed/2024/09/GHSA-x829-m68r-85mm/GHSA-x829-m68r-85mm.json diff --git a/advisories/unreviewed/2022/04/GHSA-7f3x-fvqf-q6q5/GHSA-7f3x-fvqf-q6q5.json b/advisories/unreviewed/2022/04/GHSA-7f3x-fvqf-q6q5/GHSA-7f3x-fvqf-q6q5.json index be027c5ddc4..6858d9c70c7 100644 --- a/advisories/unreviewed/2022/04/GHSA-7f3x-fvqf-q6q5/GHSA-7f3x-fvqf-q6q5.json +++ b/advisories/unreviewed/2022/04/GHSA-7f3x-fvqf-q6q5/GHSA-7f3x-fvqf-q6q5.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-5x5v-v8qh-gwrg/GHSA-5x5v-v8qh-gwrg.json b/advisories/unreviewed/2022/05/GHSA-5x5v-v8qh-gwrg/GHSA-5x5v-v8qh-gwrg.json index d7189e79152..f36c937ec38 100644 --- a/advisories/unreviewed/2022/05/GHSA-5x5v-v8qh-gwrg/GHSA-5x5v-v8qh-gwrg.json +++ b/advisories/unreviewed/2022/05/GHSA-5x5v-v8qh-gwrg/GHSA-5x5v-v8qh-gwrg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5x5v-v8qh-gwrg", - "modified": "2022-05-17T04:16:35Z", + "modified": "2024-09-25T15:31:10Z", "published": "2022-05-17T04:16:35Z", "aliases": [ "CVE-2015-1383" diff --git a/advisories/unreviewed/2023/09/GHSA-864g-m8f5-w226/GHSA-864g-m8f5-w226.json b/advisories/unreviewed/2023/09/GHSA-864g-m8f5-w226/GHSA-864g-m8f5-w226.json index d1eaa00c8dc..88dafe60200 100644 --- a/advisories/unreviewed/2023/09/GHSA-864g-m8f5-w226/GHSA-864g-m8f5-w226.json +++ b/advisories/unreviewed/2023/09/GHSA-864g-m8f5-w226/GHSA-864g-m8f5-w226.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-g984-6p7h-qw9r/GHSA-g984-6p7h-qw9r.json b/advisories/unreviewed/2023/09/GHSA-g984-6p7h-qw9r/GHSA-g984-6p7h-qw9r.json index f8de15346c3..82f898d64e7 100644 --- a/advisories/unreviewed/2023/09/GHSA-g984-6p7h-qw9r/GHSA-g984-6p7h-qw9r.json +++ b/advisories/unreviewed/2023/09/GHSA-g984-6p7h-qw9r/GHSA-g984-6p7h-qw9r.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-qq37-j4m8-2hhr/GHSA-qq37-j4m8-2hhr.json b/advisories/unreviewed/2023/09/GHSA-qq37-j4m8-2hhr/GHSA-qq37-j4m8-2hhr.json index b5d6f38d8e4..ccff28b6fb6 100644 --- a/advisories/unreviewed/2023/09/GHSA-qq37-j4m8-2hhr/GHSA-qq37-j4m8-2hhr.json +++ b/advisories/unreviewed/2023/09/GHSA-qq37-j4m8-2hhr/GHSA-qq37-j4m8-2hhr.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-6r7v-r49r-49r5/GHSA-6r7v-r49r-49r5.json b/advisories/unreviewed/2024/06/GHSA-6r7v-r49r-49r5/GHSA-6r7v-r49r-49r5.json index ce30275cd84..1034d59ce6d 100644 --- a/advisories/unreviewed/2024/06/GHSA-6r7v-r49r-49r5/GHSA-6r7v-r49r-49r5.json +++ b/advisories/unreviewed/2024/06/GHSA-6r7v-r49r-49r5/GHSA-6r7v-r49r-49r5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6r7v-r49r-49r5", - "modified": "2024-06-10T09:31:05Z", + "modified": "2024-09-25T15:31:10Z", "published": "2024-06-10T09:31:05Z", "aliases": [ "CVE-2024-35717" diff --git a/advisories/unreviewed/2024/06/GHSA-jhc8-v2x5-jvj5/GHSA-jhc8-v2x5-jvj5.json b/advisories/unreviewed/2024/06/GHSA-jhc8-v2x5-jvj5/GHSA-jhc8-v2x5-jvj5.json index 95ffa7cc694..b31cf43f807 100644 --- a/advisories/unreviewed/2024/06/GHSA-jhc8-v2x5-jvj5/GHSA-jhc8-v2x5-jvj5.json +++ b/advisories/unreviewed/2024/06/GHSA-jhc8-v2x5-jvj5/GHSA-jhc8-v2x5-jvj5.json @@ -56,7 +56,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-863" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-mr2m-75hp-m2f7/GHSA-mr2m-75hp-m2f7.json b/advisories/unreviewed/2024/06/GHSA-mr2m-75hp-m2f7/GHSA-mr2m-75hp-m2f7.json index 4f04604db98..019ba62ff2a 100644 --- a/advisories/unreviewed/2024/06/GHSA-mr2m-75hp-m2f7/GHSA-mr2m-75hp-m2f7.json +++ b/advisories/unreviewed/2024/06/GHSA-mr2m-75hp-m2f7/GHSA-mr2m-75hp-m2f7.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-qjqc-63v2-7m34/GHSA-qjqc-63v2-7m34.json b/advisories/unreviewed/2024/06/GHSA-qjqc-63v2-7m34/GHSA-qjqc-63v2-7m34.json index da0decf244f..972fdb8c7b6 100644 --- a/advisories/unreviewed/2024/06/GHSA-qjqc-63v2-7m34/GHSA-qjqc-63v2-7m34.json +++ b/advisories/unreviewed/2024/06/GHSA-qjqc-63v2-7m34/GHSA-qjqc-63v2-7m34.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qjqc-63v2-7m34", - "modified": "2024-06-10T09:31:05Z", + "modified": "2024-09-25T15:31:10Z", "published": "2024-06-10T09:31:05Z", "aliases": [ "CVE-2024-35720" diff --git a/advisories/unreviewed/2024/06/GHSA-x382-ggwj-j3wq/GHSA-x382-ggwj-j3wq.json b/advisories/unreviewed/2024/06/GHSA-x382-ggwj-j3wq/GHSA-x382-ggwj-j3wq.json index d8d5feac100..842bb1f1899 100644 --- a/advisories/unreviewed/2024/06/GHSA-x382-ggwj-j3wq/GHSA-x382-ggwj-j3wq.json +++ b/advisories/unreviewed/2024/06/GHSA-x382-ggwj-j3wq/GHSA-x382-ggwj-j3wq.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-2m8v-gj6w-pvrw/GHSA-2m8v-gj6w-pvrw.json b/advisories/unreviewed/2024/09/GHSA-2m8v-gj6w-pvrw/GHSA-2m8v-gj6w-pvrw.json new file mode 100644 index 00000000000..582c9f1e13b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-2m8v-gj6w-pvrw/GHSA-2m8v-gj6w-pvrw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2m8v-gj6w-pvrw", + "modified": "2024-09-25T15:31:13Z", + "published": "2024-09-25T15:31:13Z", + "aliases": [ + "CVE-2024-43990" + ], + "details": "Insertion of Sensitive Information into Log File vulnerability in StylemixThemes Masterstudy LMS Starter.This issue affects Masterstudy LMS Starter: from n/a through 1.1.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43990" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ms-lms-starter-theme/wordpress-masterstudy-lms-starter-theme-1-1-8-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-2q3v-8m45-45jg/GHSA-2q3v-8m45-45jg.json b/advisories/unreviewed/2024/09/GHSA-2q3v-8m45-45jg/GHSA-2q3v-8m45-45jg.json index 05cf0c60aad..5a0553224aa 100644 --- a/advisories/unreviewed/2024/09/GHSA-2q3v-8m45-45jg/GHSA-2q3v-8m45-45jg.json +++ b/advisories/unreviewed/2024/09/GHSA-2q3v-8m45-45jg/GHSA-2q3v-8m45-45jg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2q3v-8m45-45jg", - "modified": "2024-09-25T06:30:42Z", + "modified": "2024-09-25T15:31:12Z", "published": "2024-09-25T06:30:42Z", "aliases": [ "CVE-2024-6845" ], "details": "The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, allowing unauthenticated users to retrieve the encoded key and then decode it, thereby leaking the OpenAI API key", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-25T06:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-38h7-7925-fvwv/GHSA-38h7-7925-fvwv.json b/advisories/unreviewed/2024/09/GHSA-38h7-7925-fvwv/GHSA-38h7-7925-fvwv.json index f60059e103c..0edf12eaf39 100644 --- a/advisories/unreviewed/2024/09/GHSA-38h7-7925-fvwv/GHSA-38h7-7925-fvwv.json +++ b/advisories/unreviewed/2024/09/GHSA-38h7-7925-fvwv/GHSA-38h7-7925-fvwv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-38h7-7925-fvwv", - "modified": "2024-09-25T12:30:40Z", + "modified": "2024-09-25T15:31:12Z", "published": "2024-09-25T12:30:40Z", "aliases": [ "CVE-2024-31145" ], "details": "Certain PCI devices in a system might be assigned Reserved Memory\nRegions (specified via Reserved Memory Region Reporting, \"RMRR\") for\nIntel VT-d or Unity Mapping ranges for AMD-Vi. These are typically used\nfor platform tasks such as legacy USB emulation.\n\nSince the precise purpose of these regions is unknown, once a device\nassociated with such a region is active, the mappings of these regions\nneed to remain continuouly accessible by the device. In the logic\nestablishing these mappings, error handling was flawed, resulting in\nsuch mappings to potentially remain in place when they should have been\nremoved again. Respective guests would then gain access to memory\nregions which they aren't supposed to have access to.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-25T11:15:12Z" diff --git a/advisories/unreviewed/2024/09/GHSA-3hwv-fr9j-3wjq/GHSA-3hwv-fr9j-3wjq.json b/advisories/unreviewed/2024/09/GHSA-3hwv-fr9j-3wjq/GHSA-3hwv-fr9j-3wjq.json new file mode 100644 index 00000000000..b027b985dc0 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3hwv-fr9j-3wjq/GHSA-3hwv-fr9j-3wjq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hwv-fr9j-3wjq", + "modified": "2024-09-25T15:31:13Z", + "published": "2024-09-25T15:31:13Z", + "aliases": [ + "CVE-2024-46461" + ], + "details": "VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms stream (heap based overflow). If successful, a malicious third party could trigger either a crash of VLC or an arbitrary code execution with the target user's privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46461" + }, + { + "type": "WEB", + "url": "https://www.videolan.org/security/sb-vlc3021.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3x94-47mg-35rf/GHSA-3x94-47mg-35rf.json b/advisories/unreviewed/2024/09/GHSA-3x94-47mg-35rf/GHSA-3x94-47mg-35rf.json new file mode 100644 index 00000000000..d553d21be80 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3x94-47mg-35rf/GHSA-3x94-47mg-35rf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3x94-47mg-35rf", + "modified": "2024-09-25T15:31:12Z", + "published": "2024-09-25T15:31:12Z", + "aliases": [ + "CVE-2024-7576" + ], + "details": "In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7576" + }, + { + "type": "WEB", + "url": "https://docs.telerik.com/devtools/wpf/knowledge-base/unsafe-deserialization-cve-2024-7576" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T14:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-4wh3-4hcw-ph3f/GHSA-4wh3-4hcw-ph3f.json b/advisories/unreviewed/2024/09/GHSA-4wh3-4hcw-ph3f/GHSA-4wh3-4hcw-ph3f.json new file mode 100644 index 00000000000..2c4676ca4a6 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-4wh3-4hcw-ph3f/GHSA-4wh3-4hcw-ph3f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wh3-4hcw-ph3f", + "modified": "2024-09-25T15:31:13Z", + "published": "2024-09-25T15:31:13Z", + "aliases": [ + "CVE-2024-7679" + ], + "details": "In Progress Telerik UI for WinForms versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7679" + }, + { + "type": "WEB", + "url": "https://docs.telerik.com/devtools/winforms/knowledge-base/command-injection-cve-2024-7679" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-5mvr-wqp8-rqpq/GHSA-5mvr-wqp8-rqpq.json b/advisories/unreviewed/2024/09/GHSA-5mvr-wqp8-rqpq/GHSA-5mvr-wqp8-rqpq.json new file mode 100644 index 00000000000..ddbbfbf4383 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5mvr-wqp8-rqpq/GHSA-5mvr-wqp8-rqpq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mvr-wqp8-rqpq", + "modified": "2024-09-25T15:31:13Z", + "published": "2024-09-25T15:31:13Z", + "aliases": [ + "CVE-2024-22893" + ], + "details": "OpenSlides 4.0.15 verifies passwords by comparing password hashes using a function with content-dependent runtime. This can allow attackers to obtain information about the password hash using a timing attack.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22893" + }, + { + "type": "WEB", + "url": "https://gist.github.com/mdickopp/10e4a4ba3d7ded8315a1613ee7f2541e" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6cm4-chj3-vwmx/GHSA-6cm4-chj3-vwmx.json b/advisories/unreviewed/2024/09/GHSA-6cm4-chj3-vwmx/GHSA-6cm4-chj3-vwmx.json new file mode 100644 index 00000000000..7df33d7d2a1 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6cm4-chj3-vwmx/GHSA-6cm4-chj3-vwmx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cm4-chj3-vwmx", + "modified": "2024-09-25T15:31:13Z", + "published": "2024-09-25T15:31:13Z", + "aliases": [ + "CVE-2024-30128" + ], + "details": "HCL Nomad server on Domino is affected by an open proxy vulnerability in which an unauthenticated attacker can mask their original source IP address. This may enable an attacker to trick the user into exposing sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30128" + }, + { + "type": "WEB", + "url": "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0115504" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6q8c-85p2-954c/GHSA-6q8c-85p2-954c.json b/advisories/unreviewed/2024/09/GHSA-6q8c-85p2-954c/GHSA-6q8c-85p2-954c.json new file mode 100644 index 00000000000..960c3407482 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6q8c-85p2-954c/GHSA-6q8c-85p2-954c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6q8c-85p2-954c", + "modified": "2024-09-25T15:31:13Z", + "published": "2024-09-25T15:31:12Z", + "aliases": [ + "CVE-2024-8316" + ], + "details": "In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8316" + }, + { + "type": "WEB", + "url": "https://docs.telerik.com/devtools/wpf/knowledge-base/unsafe-deserialization-cve-2024-8316" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6xmx-57h5-2fhv/GHSA-6xmx-57h5-2fhv.json b/advisories/unreviewed/2024/09/GHSA-6xmx-57h5-2fhv/GHSA-6xmx-57h5-2fhv.json new file mode 100644 index 00000000000..eeaee27a86c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6xmx-57h5-2fhv/GHSA-6xmx-57h5-2fhv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xmx-57h5-2fhv", + "modified": "2024-09-25T15:31:13Z", + "published": "2024-09-25T15:31:13Z", + "aliases": [ + "CVE-2024-43237" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in TaxoPress WordPress Tag Cloud Plugin – Tag Groups.This issue affects WordPress Tag Cloud Plugin – Tag Groups: from n/a through 2.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43237" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/tag-groups/wordpress-tag-groups-plugin-2-0-3-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-73q2-8gvp-gh6w/GHSA-73q2-8gvp-gh6w.json b/advisories/unreviewed/2024/09/GHSA-73q2-8gvp-gh6w/GHSA-73q2-8gvp-gh6w.json new file mode 100644 index 00000000000..ca9244eeba7 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-73q2-8gvp-gh6w/GHSA-73q2-8gvp-gh6w.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73q2-8gvp-gh6w", + "modified": "2024-09-25T15:31:12Z", + "published": "2024-09-25T15:31:12Z", + "aliases": [ + "CVE-2024-8546" + ], + "details": "The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video widget in all versions up to, and including, 3.2.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8546" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/elementskit-lite/trunk/widgets/video/parts/video-button.php#L10" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3155880" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3155880/elementskit-lite/trunk/widgets/video/video.php" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/elementskit-lite/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d21aeeb6-2e7d-426e-82c5-ff65e33bc5cb?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T13:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-7gm9-jx2g-wpvm/GHSA-7gm9-jx2g-wpvm.json b/advisories/unreviewed/2024/09/GHSA-7gm9-jx2g-wpvm/GHSA-7gm9-jx2g-wpvm.json index 0d350145838..cd04fd9d26a 100644 --- a/advisories/unreviewed/2024/09/GHSA-7gm9-jx2g-wpvm/GHSA-7gm9-jx2g-wpvm.json +++ b/advisories/unreviewed/2024/09/GHSA-7gm9-jx2g-wpvm/GHSA-7gm9-jx2g-wpvm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7gm9-jx2g-wpvm", - "modified": "2024-09-17T00:31:04Z", + "modified": "2024-09-25T15:31:11Z", "published": "2024-09-17T00:31:04Z", "aliases": [ "CVE-2024-40856" ], "details": "An integrity issue was addressed with Beacon Protection. This issue is fixed in iOS 18 and iPadOS 18, tvOS 18, macOS Sequoia 15. An attacker may be able to force a device to disconnect from a secure network.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:49Z" diff --git a/advisories/unreviewed/2024/09/GHSA-7v3f-jf4x-gj99/GHSA-7v3f-jf4x-gj99.json b/advisories/unreviewed/2024/09/GHSA-7v3f-jf4x-gj99/GHSA-7v3f-jf4x-gj99.json index 5473500403f..a81e985db10 100644 --- a/advisories/unreviewed/2024/09/GHSA-7v3f-jf4x-gj99/GHSA-7v3f-jf4x-gj99.json +++ b/advisories/unreviewed/2024/09/GHSA-7v3f-jf4x-gj99/GHSA-7v3f-jf4x-gj99.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7v3f-jf4x-gj99", - "modified": "2024-09-17T00:31:04Z", + "modified": "2024-09-25T15:31:11Z", "published": "2024-09-17T00:31:04Z", "aliases": [ "CVE-2024-40863" ], "details": "This issue was addressed with improved data protection. This issue is fixed in iOS 18 and iPadOS 18. An app may be able to leak sensitive user information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:49Z" diff --git a/advisories/unreviewed/2024/09/GHSA-8476-jpv4-xp4p/GHSA-8476-jpv4-xp4p.json b/advisories/unreviewed/2024/09/GHSA-8476-jpv4-xp4p/GHSA-8476-jpv4-xp4p.json index f17d4422c02..3bdbfac857e 100644 --- a/advisories/unreviewed/2024/09/GHSA-8476-jpv4-xp4p/GHSA-8476-jpv4-xp4p.json +++ b/advisories/unreviewed/2024/09/GHSA-8476-jpv4-xp4p/GHSA-8476-jpv4-xp4p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8476-jpv4-xp4p", - "modified": "2024-09-17T00:31:04Z", + "modified": "2024-09-25T15:31:11Z", "published": "2024-09-17T00:31:04Z", "aliases": [ "CVE-2024-40857" ], "details": "This issue was addressed through improved state management. This issue is fixed in Safari 18, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iPadOS 18, tvOS 18. Processing maliciously crafted web content may lead to universal cross site scripting.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:49Z" diff --git a/advisories/unreviewed/2024/09/GHSA-c4jq-v98x-5qm2/GHSA-c4jq-v98x-5qm2.json b/advisories/unreviewed/2024/09/GHSA-c4jq-v98x-5qm2/GHSA-c4jq-v98x-5qm2.json index e36665098b9..99317f7fddd 100644 --- a/advisories/unreviewed/2024/09/GHSA-c4jq-v98x-5qm2/GHSA-c4jq-v98x-5qm2.json +++ b/advisories/unreviewed/2024/09/GHSA-c4jq-v98x-5qm2/GHSA-c4jq-v98x-5qm2.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-cxpf-r354-3v48/GHSA-cxpf-r354-3v48.json b/advisories/unreviewed/2024/09/GHSA-cxpf-r354-3v48/GHSA-cxpf-r354-3v48.json new file mode 100644 index 00000000000..b063204ce22 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-cxpf-r354-3v48/GHSA-cxpf-r354-3v48.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxpf-r354-3v48", + "modified": "2024-09-25T15:31:12Z", + "published": "2024-09-25T15:31:12Z", + "aliases": [ + "CVE-2024-4657" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Software BAP Automation allows Stored XSS.This issue affects BAP Automation: before 30840.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4657" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1536" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T13:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-f5pf-wc6m-cx7j/GHSA-f5pf-wc6m-cx7j.json b/advisories/unreviewed/2024/09/GHSA-f5pf-wc6m-cx7j/GHSA-f5pf-wc6m-cx7j.json index 6f6b7a6937b..1e22fb69172 100644 --- a/advisories/unreviewed/2024/09/GHSA-f5pf-wc6m-cx7j/GHSA-f5pf-wc6m-cx7j.json +++ b/advisories/unreviewed/2024/09/GHSA-f5pf-wc6m-cx7j/GHSA-f5pf-wc6m-cx7j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f5pf-wc6m-cx7j", - "modified": "2024-09-17T00:31:05Z", + "modified": "2024-09-25T15:31:11Z", "published": "2024-09-17T00:31:05Z", "aliases": [ "CVE-2024-44129" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7, macOS Sequoia 15. An app may be able to leak sensitive user information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:50Z" diff --git a/advisories/unreviewed/2024/09/GHSA-fffw-jm62-gx8w/GHSA-fffw-jm62-gx8w.json b/advisories/unreviewed/2024/09/GHSA-fffw-jm62-gx8w/GHSA-fffw-jm62-gx8w.json new file mode 100644 index 00000000000..f9d2091d1cb --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-fffw-jm62-gx8w/GHSA-fffw-jm62-gx8w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fffw-jm62-gx8w", + "modified": "2024-09-25T15:31:13Z", + "published": "2024-09-25T15:31:13Z", + "aliases": [ + "CVE-2024-43959" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themepoints Testimonials allows Reflected XSS.This issue affects Testimonials: from n/a through 3.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43959" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/super-testimonial/wordpress-super-testimonials-plugin-3-0-8-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-fvmx-5p62-pxm8/GHSA-fvmx-5p62-pxm8.json b/advisories/unreviewed/2024/09/GHSA-fvmx-5p62-pxm8/GHSA-fvmx-5p62-pxm8.json index 9c9c0a3fc9a..93cafa0ea22 100644 --- a/advisories/unreviewed/2024/09/GHSA-fvmx-5p62-pxm8/GHSA-fvmx-5p62-pxm8.json +++ b/advisories/unreviewed/2024/09/GHSA-fvmx-5p62-pxm8/GHSA-fvmx-5p62-pxm8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fvmx-5p62-pxm8", - "modified": "2024-09-17T00:31:06Z", + "modified": "2024-09-25T15:31:11Z", "published": "2024-09-17T00:31:06Z", "aliases": [ "CVE-2024-44176" ], "details": "An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.7, iOS 17.7 and iPadOS 17.7, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iPadOS 18, macOS Sonoma 14.7, tvOS 18. Processing an image may lead to a denial-of-service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:51Z" diff --git a/advisories/unreviewed/2024/09/GHSA-gm8f-9rvm-rrfq/GHSA-gm8f-9rvm-rrfq.json b/advisories/unreviewed/2024/09/GHSA-gm8f-9rvm-rrfq/GHSA-gm8f-9rvm-rrfq.json index 59e0448412c..0582b6a4e24 100644 --- a/advisories/unreviewed/2024/09/GHSA-gm8f-9rvm-rrfq/GHSA-gm8f-9rvm-rrfq.json +++ b/advisories/unreviewed/2024/09/GHSA-gm8f-9rvm-rrfq/GHSA-gm8f-9rvm-rrfq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gm8f-9rvm-rrfq", - "modified": "2024-09-17T00:31:05Z", + "modified": "2024-09-25T15:31:11Z", "published": "2024-09-17T00:31:05Z", "aliases": [ "CVE-2024-44125" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.7, macOS Sequoia 15. A malicious application may be able to leak sensitive user information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:49Z" diff --git a/advisories/unreviewed/2024/09/GHSA-gwm9-fmrx-q4pp/GHSA-gwm9-fmrx-q4pp.json b/advisories/unreviewed/2024/09/GHSA-gwm9-fmrx-q4pp/GHSA-gwm9-fmrx-q4pp.json index 6791749ed5d..e1647253579 100644 --- a/advisories/unreviewed/2024/09/GHSA-gwm9-fmrx-q4pp/GHSA-gwm9-fmrx-q4pp.json +++ b/advisories/unreviewed/2024/09/GHSA-gwm9-fmrx-q4pp/GHSA-gwm9-fmrx-q4pp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gwm9-fmrx-q4pp", - "modified": "2024-09-25T06:30:42Z", + "modified": "2024-09-25T15:31:12Z", "published": "2024-09-25T06:30:42Z", "aliases": [ "CVE-2024-7892" ], "details": "The adstxt Plugin WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-25T06:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-hqp9-2fgf-h6cx/GHSA-hqp9-2fgf-h6cx.json b/advisories/unreviewed/2024/09/GHSA-hqp9-2fgf-h6cx/GHSA-hqp9-2fgf-h6cx.json index 9a4739aff9d..7aab61283a1 100644 --- a/advisories/unreviewed/2024/09/GHSA-hqp9-2fgf-h6cx/GHSA-hqp9-2fgf-h6cx.json +++ b/advisories/unreviewed/2024/09/GHSA-hqp9-2fgf-h6cx/GHSA-hqp9-2fgf-h6cx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hqp9-2fgf-h6cx", - "modified": "2024-09-17T00:31:05Z", + "modified": "2024-09-25T15:31:11Z", "published": "2024-09-17T00:31:05Z", "aliases": [ "CVE-2024-44135" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to access protected files within an App Sandbox container.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:50Z" diff --git a/advisories/unreviewed/2024/09/GHSA-hrw6-9556-27w2/GHSA-hrw6-9556-27w2.json b/advisories/unreviewed/2024/09/GHSA-hrw6-9556-27w2/GHSA-hrw6-9556-27w2.json index ce665b035cb..5960e83f360 100644 --- a/advisories/unreviewed/2024/09/GHSA-hrw6-9556-27w2/GHSA-hrw6-9556-27w2.json +++ b/advisories/unreviewed/2024/09/GHSA-hrw6-9556-27w2/GHSA-hrw6-9556-27w2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hrw6-9556-27w2", - "modified": "2024-09-25T12:30:40Z", + "modified": "2024-09-25T15:31:12Z", "published": "2024-09-25T12:30:40Z", "aliases": [ "CVE-2024-31146" ], "details": "When multiple devices share resources and one of them is to be passed\nthrough to a guest, security of the entire system and of respective\nguests individually cannot really be guaranteed without knowing\ninternals of any of the involved guests. Therefore such a configuration\ncannot really be security-supported, yet making that explicit was so far\nmissing.\n\nResources the sharing of which is known to be problematic include, but\nare not limited to\n- - PCI Base Address Registers (BARs) of multiple devices mapping to the\n same page (4k on x86),\n- - INTx lines.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-25T11:15:12Z" diff --git a/advisories/unreviewed/2024/09/GHSA-jp9w-w77g-78h3/GHSA-jp9w-w77g-78h3.json b/advisories/unreviewed/2024/09/GHSA-jp9w-w77g-78h3/GHSA-jp9w-w77g-78h3.json new file mode 100644 index 00000000000..152856d1a23 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-jp9w-w77g-78h3/GHSA-jp9w-w77g-78h3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jp9w-w77g-78h3", + "modified": "2024-09-25T15:31:12Z", + "published": "2024-09-25T15:31:12Z", + "aliases": [ + "CVE-2024-7575" + ], + "details": "In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7575" + }, + { + "type": "WEB", + "url": "https://docs.telerik.com/devtools/wpf/knowledge-base/command-injection-cve-2024-7575" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T14:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-m6gq-8g82-wvgx/GHSA-m6gq-8g82-wvgx.json b/advisories/unreviewed/2024/09/GHSA-m6gq-8g82-wvgx/GHSA-m6gq-8g82-wvgx.json index ce1e1857554..f608d9d592e 100644 --- a/advisories/unreviewed/2024/09/GHSA-m6gq-8g82-wvgx/GHSA-m6gq-8g82-wvgx.json +++ b/advisories/unreviewed/2024/09/GHSA-m6gq-8g82-wvgx/GHSA-m6gq-8g82-wvgx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m6gq-8g82-wvgx", - "modified": "2024-09-17T00:31:06Z", + "modified": "2024-09-25T15:31:11Z", "published": "2024-09-17T00:31:06Z", "aliases": [ "CVE-2024-44191" ], "details": "This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, Xcode 16, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iPadOS 18, tvOS 18. An app may gain unauthorized access to Bluetooth.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:52Z" diff --git a/advisories/unreviewed/2024/09/GHSA-mj2f-7q85-79p2/GHSA-mj2f-7q85-79p2.json b/advisories/unreviewed/2024/09/GHSA-mj2f-7q85-79p2/GHSA-mj2f-7q85-79p2.json index a3bbc5ba634..af6f4f670bc 100644 --- a/advisories/unreviewed/2024/09/GHSA-mj2f-7q85-79p2/GHSA-mj2f-7q85-79p2.json +++ b/advisories/unreviewed/2024/09/GHSA-mj2f-7q85-79p2/GHSA-mj2f-7q85-79p2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mj2f-7q85-79p2", - "modified": "2024-09-25T06:30:42Z", + "modified": "2024-09-25T15:31:12Z", "published": "2024-09-25T06:30:42Z", "aliases": [ "CVE-2024-7878" ], "details": "The WP ULike WordPress plugin before 4.7.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-25T06:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-mrp4-v2gf-6mxp/GHSA-mrp4-v2gf-6mxp.json b/advisories/unreviewed/2024/09/GHSA-mrp4-v2gf-6mxp/GHSA-mrp4-v2gf-6mxp.json index 0859d11b837..88bd047a03c 100644 --- a/advisories/unreviewed/2024/09/GHSA-mrp4-v2gf-6mxp/GHSA-mrp4-v2gf-6mxp.json +++ b/advisories/unreviewed/2024/09/GHSA-mrp4-v2gf-6mxp/GHSA-mrp4-v2gf-6mxp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mrp4-v2gf-6mxp", - "modified": "2024-09-17T00:31:05Z", + "modified": "2024-09-25T15:31:11Z", "published": "2024-09-17T00:31:05Z", "aliases": [ "CVE-2024-44128" ], "details": "This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. An Automator Quick Action workflow may be able to bypass Gatekeeper.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:50Z" diff --git a/advisories/unreviewed/2024/09/GHSA-p477-mp4x-pw85/GHSA-p477-mp4x-pw85.json b/advisories/unreviewed/2024/09/GHSA-p477-mp4x-pw85/GHSA-p477-mp4x-pw85.json index 3e08bfc5333..f7208b67b0d 100644 --- a/advisories/unreviewed/2024/09/GHSA-p477-mp4x-pw85/GHSA-p477-mp4x-pw85.json +++ b/advisories/unreviewed/2024/09/GHSA-p477-mp4x-pw85/GHSA-p477-mp4x-pw85.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p477-mp4x-pw85", - "modified": "2024-09-18T00:31:12Z", + "modified": "2024-09-25T15:31:12Z", "published": "2024-09-18T00:31:12Z", "aliases": [ "CVE-2024-44005" diff --git a/advisories/unreviewed/2024/09/GHSA-qqpc-7c83-686v/GHSA-qqpc-7c83-686v.json b/advisories/unreviewed/2024/09/GHSA-qqpc-7c83-686v/GHSA-qqpc-7c83-686v.json index f37115482af..9ccac1ca2ef 100644 --- a/advisories/unreviewed/2024/09/GHSA-qqpc-7c83-686v/GHSA-qqpc-7c83-686v.json +++ b/advisories/unreviewed/2024/09/GHSA-qqpc-7c83-686v/GHSA-qqpc-7c83-686v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qqpc-7c83-686v", - "modified": "2024-09-17T00:31:04Z", + "modified": "2024-09-25T15:31:11Z", "published": "2024-09-17T00:31:04Z", "aliases": [ "CVE-2024-44124" ], "details": "This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. A malicious Bluetooth input device may bypass pairing.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:49Z" diff --git a/advisories/unreviewed/2024/09/GHSA-v6p4-r397-q442/GHSA-v6p4-r397-q442.json b/advisories/unreviewed/2024/09/GHSA-v6p4-r397-q442/GHSA-v6p4-r397-q442.json index 84801283439..f940f002ac7 100644 --- a/advisories/unreviewed/2024/09/GHSA-v6p4-r397-q442/GHSA-v6p4-r397-q442.json +++ b/advisories/unreviewed/2024/09/GHSA-v6p4-r397-q442/GHSA-v6p4-r397-q442.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v6p4-r397-q442", - "modified": "2024-09-25T09:30:46Z", + "modified": "2024-09-25T15:31:12Z", "published": "2024-09-25T09:30:46Z", "aliases": [ "CVE-2024-8175" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://cert.vde.com/en/advisories/VDE-2024-057" + }, + { + "type": "WEB", + "url": "https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=18604&token=d5e1e2820ee63077b875b3bb41014b1f102e88a3&download=" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/09/GHSA-vx7x-qwmp-h33c/GHSA-vx7x-qwmp-h33c.json b/advisories/unreviewed/2024/09/GHSA-vx7x-qwmp-h33c/GHSA-vx7x-qwmp-h33c.json new file mode 100644 index 00000000000..6915aed275b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vx7x-qwmp-h33c/GHSA-vx7x-qwmp-h33c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vx7x-qwmp-h33c", + "modified": "2024-09-25T15:31:12Z", + "published": "2024-09-25T15:31:12Z", + "aliases": [ + "CVE-2024-6512" + ], + "details": "Authorization bypass in the PAM access request approval mechanism in Devolutions Server 2024.2.10 and earlier allows authenticated users with permissions to approve their own requests, bypassing intended security restrictions, via the PAM access request approval mechanism.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6512" + }, + { + "type": "WEB", + "url": "https://devolutions.net/security/advisories/DEVO-2024-0013" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T14:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-wg39-r923-gfr5/GHSA-wg39-r923-gfr5.json b/advisories/unreviewed/2024/09/GHSA-wg39-r923-gfr5/GHSA-wg39-r923-gfr5.json index c6f1d74fbeb..1f2bec32eaa 100644 --- a/advisories/unreviewed/2024/09/GHSA-wg39-r923-gfr5/GHSA-wg39-r923-gfr5.json +++ b/advisories/unreviewed/2024/09/GHSA-wg39-r923-gfr5/GHSA-wg39-r923-gfr5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wg39-r923-gfr5", - "modified": "2024-09-17T00:31:04Z", + "modified": "2024-09-25T15:31:11Z", "published": "2024-09-17T00:31:04Z", "aliases": [ "CVE-2024-40860" ], "details": "A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to modify protected parts of the file system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:49Z" diff --git a/advisories/unreviewed/2024/09/GHSA-x829-m68r-85mm/GHSA-x829-m68r-85mm.json b/advisories/unreviewed/2024/09/GHSA-x829-m68r-85mm/GHSA-x829-m68r-85mm.json new file mode 100644 index 00000000000..6a27a26face --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-x829-m68r-85mm/GHSA-x829-m68r-85mm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x829-m68r-85mm", + "modified": "2024-09-25T15:31:13Z", + "published": "2024-09-25T15:31:12Z", + "aliases": [ + "CVE-2024-22892" + ], + "details": "OpenSlides 4.0.15 was discovered to be using a weak hashing algorithm to store passwords.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22892" + }, + { + "type": "WEB", + "url": "https://gist.github.com/mdickopp/0cab0d7f91b1f4ea0d326dd976db70e5" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xmf6-p99q-898v/GHSA-xmf6-p99q-898v.json b/advisories/unreviewed/2024/09/GHSA-xmf6-p99q-898v/GHSA-xmf6-p99q-898v.json index f41fbf3f14d..ad8ca54face 100644 --- a/advisories/unreviewed/2024/09/GHSA-xmf6-p99q-898v/GHSA-xmf6-p99q-898v.json +++ b/advisories/unreviewed/2024/09/GHSA-xmf6-p99q-898v/GHSA-xmf6-p99q-898v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xmf6-p99q-898v", - "modified": "2024-09-17T00:31:06Z", + "modified": "2024-09-25T15:31:11Z", "published": "2024-09-17T00:31:06Z", "aliases": [ "CVE-2024-44187" ], "details": "A cross-origin issue existed with \"iframe\" elements. This was addressed with improved tracking of security origins. This issue is fixed in Safari 18, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iPadOS 18, tvOS 18. A malicious website may exfiltrate data cross-origin.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-346" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:52Z"