From 3fa4f03cac6784171ccbfb50969d6a722665e02b Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 1 Oct 2024 12:31:56 +0000 Subject: [PATCH] Publish Advisories GHSA-9623-mqmm-5rcf GHSA-66jg-m4hw-q8f2 GHSA-f343-v9vj-986j GHSA-4xqh-59xq-qxj9 GHSA-564q-hf94-rx9q GHSA-9j74-wx54-mf4m GHSA-j2mx-xc3v-gw3q GHSA-qqj9-5c87-9cx7 --- .../GHSA-9623-mqmm-5rcf.json | 10 +++- .../GHSA-66jg-m4hw-q8f2.json | 10 +++- .../GHSA-f343-v9vj-986j.json | 10 +++- .../GHSA-4xqh-59xq-qxj9.json | 46 +++++++++++++++++ .../GHSA-564q-hf94-rx9q.json | 38 ++++++++++++++ .../GHSA-9j74-wx54-mf4m.json | 46 +++++++++++++++++ .../GHSA-j2mx-xc3v-gw3q.json | 50 +++++++++++++++++++ .../GHSA-qqj9-5c87-9cx7.json | 38 ++++++++++++++ 8 files changed, 245 insertions(+), 3 deletions(-) create mode 100644 advisories/unreviewed/2024/10/GHSA-4xqh-59xq-qxj9/GHSA-4xqh-59xq-qxj9.json create mode 100644 advisories/unreviewed/2024/10/GHSA-564q-hf94-rx9q/GHSA-564q-hf94-rx9q.json create mode 100644 advisories/unreviewed/2024/10/GHSA-9j74-wx54-mf4m/GHSA-9j74-wx54-mf4m.json create mode 100644 advisories/unreviewed/2024/10/GHSA-j2mx-xc3v-gw3q/GHSA-j2mx-xc3v-gw3q.json create mode 100644 advisories/unreviewed/2024/10/GHSA-qqj9-5c87-9cx7/GHSA-qqj9-5c87-9cx7.json diff --git a/advisories/github-reviewed/2024/08/GHSA-9623-mqmm-5rcf/GHSA-9623-mqmm-5rcf.json b/advisories/github-reviewed/2024/08/GHSA-9623-mqmm-5rcf/GHSA-9623-mqmm-5rcf.json index 9748cb1dd19..fc2e389b583 100644 --- a/advisories/github-reviewed/2024/08/GHSA-9623-mqmm-5rcf/GHSA-9623-mqmm-5rcf.json +++ b/advisories/github-reviewed/2024/08/GHSA-9623-mqmm-5rcf/GHSA-9623-mqmm-5rcf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9623-mqmm-5rcf", - "modified": "2024-09-19T21:33:29Z", + "modified": "2024-10-01T12:30:29Z", "published": "2024-08-21T15:30:54Z", "aliases": [ "CVE-2024-7885" @@ -52,6 +52,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:6883" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:7441" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:7442" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-7885" diff --git a/advisories/unreviewed/2023/10/GHSA-66jg-m4hw-q8f2/GHSA-66jg-m4hw-q8f2.json b/advisories/unreviewed/2023/10/GHSA-66jg-m4hw-q8f2/GHSA-66jg-m4hw-q8f2.json index 5936e22711f..a61de71794f 100644 --- a/advisories/unreviewed/2023/10/GHSA-66jg-m4hw-q8f2/GHSA-66jg-m4hw-q8f2.json +++ b/advisories/unreviewed/2023/10/GHSA-66jg-m4hw-q8f2/GHSA-66jg-m4hw-q8f2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-66jg-m4hw-q8f2", - "modified": "2024-04-04T08:11:18Z", + "modified": "2024-10-01T12:30:29Z", "published": "2023-10-03T18:30:22Z", "aliases": [ "CVE-2023-3196" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3196" }, + { + "type": "WEB", + "url": "https://git.canopsis.net/canopsis/canopsis-community/-/blob/develop/community/sources/webcore/src/canopsis-next/src/config.js?ref_type=heads#L38" + }, + { + "type": "WEB", + "url": "https://git.canopsis.net/canopsis/canopsis-community/-/blob/develop/community/sources/webcore/src/canopsis-next/src/helpers/html.js?ref_type=heads" + }, { "type": "WEB", "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-canopsis-capensis" diff --git a/advisories/unreviewed/2023/10/GHSA-f343-v9vj-986j/GHSA-f343-v9vj-986j.json b/advisories/unreviewed/2023/10/GHSA-f343-v9vj-986j/GHSA-f343-v9vj-986j.json index ac90b0349f5..91dac53b427 100644 --- a/advisories/unreviewed/2023/10/GHSA-f343-v9vj-986j/GHSA-f343-v9vj-986j.json +++ b/advisories/unreviewed/2023/10/GHSA-f343-v9vj-986j/GHSA-f343-v9vj-986j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f343-v9vj-986j", - "modified": "2024-04-04T08:11:22Z", + "modified": "2024-10-01T12:30:29Z", "published": "2023-10-03T18:30:22Z", "aliases": [ "CVE-2023-4564" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4564" }, + { + "type": "WEB", + "url": "https://git.canopsis.net/canopsis/canopsis-community/-/blob/develop/community/sources/webcore/src/canopsis-next/src/config.js?ref_type=heads#L38" + }, + { + "type": "WEB", + "url": "https://git.canopsis.net/canopsis/canopsis-community/-/blob/develop/community/sources/webcore/src/canopsis-next/src/helpers/html.js?ref_type=heads" + }, { "type": "WEB", "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-canopsis-capensis" diff --git a/advisories/unreviewed/2024/10/GHSA-4xqh-59xq-qxj9/GHSA-4xqh-59xq-qxj9.json b/advisories/unreviewed/2024/10/GHSA-4xqh-59xq-qxj9/GHSA-4xqh-59xq-qxj9.json new file mode 100644 index 00000000000..3b615fa790e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-4xqh-59xq-qxj9/GHSA-4xqh-59xq-qxj9.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xqh-59xq-qxj9", + "modified": "2024-10-01T12:30:30Z", + "published": "2024-10-01T12:30:30Z", + "aliases": [ + "CVE-2024-9118" + ], + "details": "The QS Dark Mode Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9118" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3159458" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/qs-dark-mode/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/61fce18a-44ec-442f-879e-f4ceab93d972?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T10:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-564q-hf94-rx9q/GHSA-564q-hf94-rx9q.json b/advisories/unreviewed/2024/10/GHSA-564q-hf94-rx9q/GHSA-564q-hf94-rx9q.json new file mode 100644 index 00000000000..2d07e53ff42 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-564q-hf94-rx9q/GHSA-564q-hf94-rx9q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-564q-hf94-rx9q", + "modified": "2024-10-01T12:30:30Z", + "published": "2024-10-01T12:30:30Z", + "aliases": [ + "CVE-2024-9405" + ], + "details": "An incorrect limitation of a path to a restricted directory (path traversal) has been detected in Pluck CMS, affecting version 4.7.18. An unauthenticated attacker could extract sensitive information from the server via the absolute path of a file located in the same directory or subdirectory as the module, but not from recursive directories.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9405" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/incorrect-limitation-path-restricted-directory-pluck-cms" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T12:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9j74-wx54-mf4m/GHSA-9j74-wx54-mf4m.json b/advisories/unreviewed/2024/10/GHSA-9j74-wx54-mf4m/GHSA-9j74-wx54-mf4m.json new file mode 100644 index 00000000000..1f81ba7b621 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9j74-wx54-mf4m/GHSA-9j74-wx54-mf4m.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9j74-wx54-mf4m", + "modified": "2024-10-01T12:30:30Z", + "published": "2024-10-01T12:30:30Z", + "aliases": [ + "CVE-2024-9060" + ], + "details": "The AVIF & SVG Uploader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in version 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9060" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3159481" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/avif-support/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a09113d3-8be0-45fa-b1d7-4eb6ebb1780e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T10:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-j2mx-xc3v-gw3q/GHSA-j2mx-xc3v-gw3q.json b/advisories/unreviewed/2024/10/GHSA-j2mx-xc3v-gw3q/GHSA-j2mx-xc3v-gw3q.json new file mode 100644 index 00000000000..b465c3f4176 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-j2mx-xc3v-gw3q/GHSA-j2mx-xc3v-gw3q.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2mx-xc3v-gw3q", + "modified": "2024-10-01T12:30:30Z", + "published": "2024-10-01T12:30:30Z", + "aliases": [ + "CVE-2023-3441" + ], + "details": "An issue has been discovered in GitLab EE/CE affecting all versions starting from 8.0 before 16.4. The product did not sufficiently warn about security implications of granting merge rights to protected branches.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3441" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2033561" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2041385" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/416482" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/417284" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-213" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T10:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qqj9-5c87-9cx7/GHSA-qqj9-5c87-9cx7.json b/advisories/unreviewed/2024/10/GHSA-qqj9-5c87-9cx7/GHSA-qqj9-5c87-9cx7.json new file mode 100644 index 00000000000..2cf2e569848 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qqj9-5c87-9cx7/GHSA-qqj9-5c87-9cx7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qqj9-5c87-9cx7", + "modified": "2024-10-01T12:30:30Z", + "published": "2024-10-01T12:30:30Z", + "aliases": [ + "CVE-2024-30132" + ], + "details": "HCL Nomad server on Domino did not configure certain HTTP Security headers by default which could allow an attacker to obtain sensitive information via unspecified vectors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30132" + }, + { + "type": "WEB", + "url": "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0116298" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T12:15:03Z" + } +} \ No newline at end of file