Publish Advisories

GHSA-35qh-7f6c-rjf7
GHSA-39qc-p384-v64h
GHSA-47ww-93v9-3cq9
GHSA-557j-83gh-rpqh
GHSA-7w6m-v2g8-529p
GHSA-jw3q-qghm-x757
GHSA-rwc7-c97h-vxjm
GHSA-v73j-w4mq-xcv7
GHSA-vj54-gx3v-3434
This commit is contained in:
advisory-database[bot]
2024-04-11 12:32:16 +00:00
parent 8c3df41a4a
commit 3f65ae929e
9 changed files with 325 additions and 1 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-35qh-7f6c-rjf7",
"modified": "2024-02-15T06:31:36Z",
"modified": "2024-04-11T12:30:27Z",
"published": "2024-02-15T06:31:35Z",
"aliases": [
"CVE-2024-1488"
@@ -21,6 +21,18 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1488"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1750"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1751"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1780"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-1488"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-39qc-p384-v64h",
"modified": "2024-04-11T12:30:28Z",
"published": "2024-04-11T12:30:28Z",
"aliases": [
"CVE-2024-20797"
],
"details": "Animate versions 23.0.4, 24.0.1 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20797"
},
{
"type": "WEB",
"url": "https://helpx.adobe.com/security/products/animate/apsb24-26.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-125"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T11:15:48Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-47ww-93v9-3cq9",
"modified": "2024-04-11T12:30:28Z",
"published": "2024-04-11T12:30:28Z",
"aliases": [
"CVE-2024-20794"
],
"details": "Animate versions 23.0.4, 24.0.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service. An attacker could leverage this vulnerability to cause a system crash, resulting in a denial of service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20794"
},
{
"type": "WEB",
"url": "https://helpx.adobe.com/security/products/animate/apsb24-26.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-476"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T11:15:47Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-557j-83gh-rpqh",
"modified": "2024-04-11T12:30:28Z",
"published": "2024-04-11T12:30:28Z",
"aliases": [
"CVE-2023-32295"
],
"details": "Missing Authorization vulnerability in Alex Tselegidis Easy!Appointments.This issue affects Easy!Appointments: from n/a through 1.3.2.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32295"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/easyappointments/wordpress-easy-appointments-plugin-1-3-1-arbitrary-file-deletion-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T12:15:07Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7w6m-v2g8-529p",
"modified": "2024-04-11T12:30:28Z",
"published": "2024-04-11T12:30:28Z",
"aliases": [
"CVE-2024-32112"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in Leadinfo leadinfo. The patch was released under the same version which was reported as vulnerable. We consider the current version as vulnerable.This issue affects Leadinfo: from n/a through 1.0.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32112"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/leadinfo/wordpress-leadinfo-plugin-1-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T12:15:08Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jw3q-qghm-x757",
"modified": "2024-04-11T12:30:28Z",
"published": "2024-04-11T12:30:28Z",
"aliases": [
"CVE-2024-3344"
],
"details": "The Otter Blocks Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3344"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3068495/otter-blocks"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/db836f4b-d31f-4442-89a5-1a400525c598?source=cve"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T11:15:48Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rwc7-c97h-vxjm",
"modified": "2024-04-11T12:30:28Z",
"published": "2024-04-11T12:30:28Z",
"aliases": [
"CVE-2024-3343"
],
"details": "The Otter Blocks Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block attributes in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3343"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3068495/otter-blocks"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/67981160-6c91-48a4-ba1c-68204d538ed6?source=cve"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T11:15:48Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v73j-w4mq-xcv7",
"modified": "2024-04-11T12:30:28Z",
"published": "2024-04-11T12:30:28Z",
"aliases": [
"CVE-2024-20795"
],
"details": "Animate versions 23.0.4, 24.0.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20795"
},
{
"type": "WEB",
"url": "https://helpx.adobe.com/security/products/animate/apsb24-26.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-190"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T11:15:47Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vj54-gx3v-3434",
"modified": "2024-04-11T12:30:28Z",
"published": "2024-04-11T12:30:28Z",
"aliases": [
"CVE-2024-20796"
],
"details": "Animate versions 23.0.4, 24.0.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20796"
},
{
"type": "WEB",
"url": "https://helpx.adobe.com/security/products/animate/apsb24-26.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-125"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T11:15:47Z"
}
}