From 3f65ae929ec0b2e34581c125d2ef1d006c4f026e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 11 Apr 2024 12:32:16 +0000 Subject: [PATCH] Publish Advisories GHSA-35qh-7f6c-rjf7 GHSA-39qc-p384-v64h GHSA-47ww-93v9-3cq9 GHSA-557j-83gh-rpqh GHSA-7w6m-v2g8-529p GHSA-jw3q-qghm-x757 GHSA-rwc7-c97h-vxjm GHSA-v73j-w4mq-xcv7 GHSA-vj54-gx3v-3434 --- .../GHSA-35qh-7f6c-rjf7.json | 14 ++++++- .../GHSA-39qc-p384-v64h.json | 38 +++++++++++++++++ .../GHSA-47ww-93v9-3cq9.json | 38 +++++++++++++++++ .../GHSA-557j-83gh-rpqh.json | 38 +++++++++++++++++ .../GHSA-7w6m-v2g8-529p.json | 38 +++++++++++++++++ .../GHSA-jw3q-qghm-x757.json | 42 +++++++++++++++++++ .../GHSA-rwc7-c97h-vxjm.json | 42 +++++++++++++++++++ .../GHSA-v73j-w4mq-xcv7.json | 38 +++++++++++++++++ .../GHSA-vj54-gx3v-3434.json | 38 +++++++++++++++++ 9 files changed, 325 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2024/04/GHSA-39qc-p384-v64h/GHSA-39qc-p384-v64h.json create mode 100644 advisories/unreviewed/2024/04/GHSA-47ww-93v9-3cq9/GHSA-47ww-93v9-3cq9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-557j-83gh-rpqh/GHSA-557j-83gh-rpqh.json create mode 100644 advisories/unreviewed/2024/04/GHSA-7w6m-v2g8-529p/GHSA-7w6m-v2g8-529p.json create mode 100644 advisories/unreviewed/2024/04/GHSA-jw3q-qghm-x757/GHSA-jw3q-qghm-x757.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rwc7-c97h-vxjm/GHSA-rwc7-c97h-vxjm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-v73j-w4mq-xcv7/GHSA-v73j-w4mq-xcv7.json create mode 100644 advisories/unreviewed/2024/04/GHSA-vj54-gx3v-3434/GHSA-vj54-gx3v-3434.json diff --git a/advisories/unreviewed/2024/02/GHSA-35qh-7f6c-rjf7/GHSA-35qh-7f6c-rjf7.json b/advisories/unreviewed/2024/02/GHSA-35qh-7f6c-rjf7/GHSA-35qh-7f6c-rjf7.json index ea1aa4ebf2e..b269a0b90c1 100644 --- a/advisories/unreviewed/2024/02/GHSA-35qh-7f6c-rjf7/GHSA-35qh-7f6c-rjf7.json +++ b/advisories/unreviewed/2024/02/GHSA-35qh-7f6c-rjf7/GHSA-35qh-7f6c-rjf7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-35qh-7f6c-rjf7", - "modified": "2024-02-15T06:31:36Z", + "modified": "2024-04-11T12:30:27Z", "published": "2024-02-15T06:31:35Z", "aliases": [ "CVE-2024-1488" @@ -21,6 +21,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1488" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1750" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1751" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1780" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-1488" diff --git a/advisories/unreviewed/2024/04/GHSA-39qc-p384-v64h/GHSA-39qc-p384-v64h.json b/advisories/unreviewed/2024/04/GHSA-39qc-p384-v64h/GHSA-39qc-p384-v64h.json new file mode 100644 index 00000000000..82b420301b1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-39qc-p384-v64h/GHSA-39qc-p384-v64h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39qc-p384-v64h", + "modified": "2024-04-11T12:30:28Z", + "published": "2024-04-11T12:30:28Z", + "aliases": [ + "CVE-2024-20797" + ], + "details": "Animate versions 23.0.4, 24.0.1 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20797" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/animate/apsb24-26.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-11T11:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-47ww-93v9-3cq9/GHSA-47ww-93v9-3cq9.json b/advisories/unreviewed/2024/04/GHSA-47ww-93v9-3cq9/GHSA-47ww-93v9-3cq9.json new file mode 100644 index 00000000000..94e9e39b9ec --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-47ww-93v9-3cq9/GHSA-47ww-93v9-3cq9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47ww-93v9-3cq9", + "modified": "2024-04-11T12:30:28Z", + "published": "2024-04-11T12:30:28Z", + "aliases": [ + "CVE-2024-20794" + ], + "details": "Animate versions 23.0.4, 24.0.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service. An attacker could leverage this vulnerability to cause a system crash, resulting in a denial of service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20794" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/animate/apsb24-26.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-11T11:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-557j-83gh-rpqh/GHSA-557j-83gh-rpqh.json b/advisories/unreviewed/2024/04/GHSA-557j-83gh-rpqh/GHSA-557j-83gh-rpqh.json new file mode 100644 index 00000000000..aef488aa02f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-557j-83gh-rpqh/GHSA-557j-83gh-rpqh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-557j-83gh-rpqh", + "modified": "2024-04-11T12:30:28Z", + "published": "2024-04-11T12:30:28Z", + "aliases": [ + "CVE-2023-32295" + ], + "details": "Missing Authorization vulnerability in Alex Tselegidis Easy!Appointments.This issue affects Easy!Appointments: from n/a through 1.3.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32295" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/easyappointments/wordpress-easy-appointments-plugin-1-3-1-arbitrary-file-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-11T12:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7w6m-v2g8-529p/GHSA-7w6m-v2g8-529p.json b/advisories/unreviewed/2024/04/GHSA-7w6m-v2g8-529p/GHSA-7w6m-v2g8-529p.json new file mode 100644 index 00000000000..111b6f03570 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7w6m-v2g8-529p/GHSA-7w6m-v2g8-529p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7w6m-v2g8-529p", + "modified": "2024-04-11T12:30:28Z", + "published": "2024-04-11T12:30:28Z", + "aliases": [ + "CVE-2024-32112" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Leadinfo leadinfo. The patch was released under the same version which was reported as vulnerable. We consider the current version as vulnerable.This issue affects Leadinfo: from n/a through 1.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32112" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/leadinfo/wordpress-leadinfo-plugin-1-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-11T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jw3q-qghm-x757/GHSA-jw3q-qghm-x757.json b/advisories/unreviewed/2024/04/GHSA-jw3q-qghm-x757/GHSA-jw3q-qghm-x757.json new file mode 100644 index 00000000000..34fdfd7982c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jw3q-qghm-x757/GHSA-jw3q-qghm-x757.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jw3q-qghm-x757", + "modified": "2024-04-11T12:30:28Z", + "published": "2024-04-11T12:30:28Z", + "aliases": [ + "CVE-2024-3344" + ], + "details": "The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3344" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3068495/otter-blocks" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/db836f4b-d31f-4442-89a5-1a400525c598?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-11T11:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rwc7-c97h-vxjm/GHSA-rwc7-c97h-vxjm.json b/advisories/unreviewed/2024/04/GHSA-rwc7-c97h-vxjm/GHSA-rwc7-c97h-vxjm.json new file mode 100644 index 00000000000..27e7e1f0685 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rwc7-c97h-vxjm/GHSA-rwc7-c97h-vxjm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwc7-c97h-vxjm", + "modified": "2024-04-11T12:30:28Z", + "published": "2024-04-11T12:30:28Z", + "aliases": [ + "CVE-2024-3343" + ], + "details": "The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block attributes in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3343" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3068495/otter-blocks" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/67981160-6c91-48a4-ba1c-68204d538ed6?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-11T11:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-v73j-w4mq-xcv7/GHSA-v73j-w4mq-xcv7.json b/advisories/unreviewed/2024/04/GHSA-v73j-w4mq-xcv7/GHSA-v73j-w4mq-xcv7.json new file mode 100644 index 00000000000..662c1262203 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-v73j-w4mq-xcv7/GHSA-v73j-w4mq-xcv7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v73j-w4mq-xcv7", + "modified": "2024-04-11T12:30:28Z", + "published": "2024-04-11T12:30:28Z", + "aliases": [ + "CVE-2024-20795" + ], + "details": "Animate versions 23.0.4, 24.0.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20795" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/animate/apsb24-26.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-11T11:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-vj54-gx3v-3434/GHSA-vj54-gx3v-3434.json b/advisories/unreviewed/2024/04/GHSA-vj54-gx3v-3434/GHSA-vj54-gx3v-3434.json new file mode 100644 index 00000000000..f2ad63c9d90 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vj54-gx3v-3434/GHSA-vj54-gx3v-3434.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vj54-gx3v-3434", + "modified": "2024-04-11T12:30:28Z", + "published": "2024-04-11T12:30:28Z", + "aliases": [ + "CVE-2024-20796" + ], + "details": "Animate versions 23.0.4, 24.0.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20796" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/animate/apsb24-26.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-11T11:15:47Z" + } +} \ No newline at end of file