Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-08-29 18:32:57 +00:00
parent 6ff7bae70d
commit 3fea009de2
68 changed files with 1518 additions and 98 deletions
@@ -0,0 +1,92 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m6vm-37g8-gqvh",
"modified": "2024-08-29T18:32:05Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-22102"
],
"summary": "MySQL Connectors takeover vulnerability",
"details": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in MySQL Connectors, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of MySQL Connectors.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
}
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "com.mysql:mysql-connector-j"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "8.2.0"
}
]
}
]
},
{
"package": {
"ecosystem": "Maven",
"name": "com.mysql:mysql-connector-java"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "8.2.0"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22102"
},
{
"type": "PACKAGE",
"url": "https://github.com/mysql/mysql-connector-j"
},
{
"type": "WEB",
"url": "https://github.com/mysql/mysql-connector-j/compare/8.1.0...8.2.0"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231027-0007"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpuoct2023.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-08-29T18:32:05Z",
"nvd_published_at": "2023-10-17T22:15:15Z"
}
}
@@ -1,42 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m6vm-37g8-gqvh",
"modified": "2024-04-04T08:44:38Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-22102"
],
"details": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in MySQL Connectors, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22102"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231027-0007"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpuoct2023.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:15Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-37c3-qm4g-jf9g",
"modified": "2024-06-26T00:31:43Z",
"modified": "2024-08-29T18:31:32Z",
"published": "2024-05-19T09:34:47Z",
"aliases": [
"CVE-2024-35895"
@@ -26,6 +26,10 @@
"type": "WEB",
"url": "https://git.kernel.org/stable/c/6af057ccdd8e7619960aca1f0428339f213b31cd"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/913c30f827e17d8cda1da6eeb990f350d36cb69b"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/a44770fed86515eedb5a7c00b787f847ebb134a5"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-45rj-9f26-3gf5",
"modified": "2024-05-19T12:30:39Z",
"modified": "2024-08-29T18:31:34Z",
"published": "2024-05-19T12:30:39Z",
"aliases": [
"CVE-2024-35937"
@@ -29,6 +29,10 @@
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/9ad7974856926129f190ffbe3beea78460b3b7cc"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/9eb3bc0973d084423a6df21cf2c74692ff05647e"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wvq2-rqp6-pwmj",
"modified": "2024-08-19T06:30:52Z",
"modified": "2024-08-29T18:31:34Z",
"published": "2024-05-20T12:30:28Z",
"aliases": [
"CVE-2024-35966"
@@ -29,6 +29,10 @@
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/c3f787a3eafe519c93df9abbb0ca5145861c8d0f"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/eea40d33bf936a5c7fb03c190e61e0cfee00e872"
}
],
"database_specific": {
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-47ph-rf63-2m8f",
"modified": "2024-07-28T06:30:45Z",
"modified": "2024-08-29T18:31:34Z",
"published": "2024-07-28T06:30:45Z",
"aliases": [
"CVE-2024-42055"
],
"details": "Cervantes through 0.5-alpha allows stored XSS.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-28T04:15:01Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5r86-7p4c-pw27",
"modified": "2024-07-29T15:30:39Z",
"modified": "2024-08-29T18:31:34Z",
"published": "2024-07-29T15:30:39Z",
"aliases": [
"CVE-2024-41024"
@@ -18,6 +18,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41024"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/2eb973ee4770a26d9b5e292b58ad29822d321c7f"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/5e305b5986dc52122a9368a1461f0c13e1de3fd6"
@@ -29,6 +33,10 @@
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/c69fd8afacebfdf2f8a1ee1ea7e0723786529874"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/ea13bd807f1cef1af375d999980a9b9794c789b6"
}
],
"database_specific": {
@@ -32,7 +32,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-121"
"CWE-121",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-934p-m4fh-22q3",
"modified": "2024-08-19T06:30:52Z",
"modified": "2024-08-29T18:31:34Z",
"published": "2024-07-12T15:31:29Z",
"aliases": [
"CVE-2024-40972"
@@ -18,6 +18,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40972"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/0752e7fb549d90c33b4d4186f11cfd25a556d1dd"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/0a46ef234756dca04623b7591e8ebb3440622f0b"
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gjhv-rjxp-wwwg",
"modified": "2024-07-10T00:30:42Z",
"modified": "2024-08-29T18:31:34Z",
"published": "2024-07-10T00:30:42Z",
"aliases": [
"CVE-2024-39881"
],
"details": "Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a memory corruption condition. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r3jw-6ppm-jp54",
"modified": "2024-07-10T00:30:42Z",
"modified": "2024-08-29T18:31:34Z",
"published": "2024-07-10T00:30:42Z",
"aliases": [
"CVE-2024-39883"
],
"details": "Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
@@ -28,7 +32,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-122"
"CWE-122",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r595-x79c-68p4",
"modified": "2024-07-16T18:31:42Z",
"modified": "2024-08-29T18:31:34Z",
"published": "2024-07-09T15:30:54Z",
"aliases": [
"CVE-2024-6610"
],
"details": "Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen mode. This vulnerability affects Firefox < 128.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
}
],
"affected": [
@@ -35,7 +38,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-09T15:15:12Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r8m6-4m9c-fg6x",
"modified": "2024-07-28T06:30:45Z",
"modified": "2024-08-29T18:31:34Z",
"published": "2024-07-28T06:30:45Z",
"aliases": [
"CVE-2024-42054"
],
"details": "Cervantes through 0.5-alpha accepts insecure file uploads.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-434"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-28T04:15:01Z"
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wmrf-m77q-pc98",
"modified": "2024-07-10T00:30:42Z",
"modified": "2024-08-29T18:31:34Z",
"published": "2024-07-10T00:30:42Z",
"aliases": [
"CVE-2024-39882"
],
"details": "Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-27qw-rmpj-379q",
"modified": "2024-08-26T12:31:20Z",
"modified": "2024-08-29T18:31:35Z",
"published": "2024-08-26T12:31:20Z",
"aliases": [
"CVE-2024-44939"
@@ -18,6 +18,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44939"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/53023ab11836ac56fd75f7a71ec1356e50920fa9"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/6ea10dbb1e6c58384136e9adfd75f81951e423f6"
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2c63-x392-hx7w",
"modified": "2024-08-29T18:31:35Z",
"published": "2024-08-29T18:31:35Z",
"aliases": [
"CVE-2024-35118"
],
"details": "IBM MaaS360 for Android 6.31 through 8.60 is using hard coded credentials that can be obtained by a user with physical access to the device.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35118"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/290341"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7166750"
}
],
"database_specific": {
"cwe_ids": [
"CWE-798"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-29T16:15:08Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2p5q-hvc3-c85p",
"modified": "2024-08-07T09:31:08Z",
"modified": "2024-08-29T18:31:34Z",
"published": "2024-08-07T09:31:08Z",
"aliases": [
"CVE-2024-42222"
],
"details": "In Apache CloudStack 4.19.1.0, a regression in the network listing API allows unauthorised list access of network details for domain admin and normal user accounts. This vulnerability compromises tenant isolation, potentially leading to unauthorised access to network details, configurations and data.\n\nAffected users are advised to upgrade to version 4.19.1.1 to address this issue. Users on older versions of CloudStack considering to upgrade, can skip 4.19.1.0 and upgrade directly to 4.19.1.1.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
@@ -39,7 +42,7 @@
"cwe_ids": [
"CWE-200"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-07T08:16:12Z"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-328c-8rw4-p536",
"modified": "2024-08-29T18:31:35Z",
"published": "2024-08-29T18:31:35Z",
"aliases": [
"CVE-2024-43952"
],
"details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Esotera allows Stored XSS.This issue affects Esotera: from n/a through 1.2.5.1.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43952"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/esotera/wordpress-esotera-theme-1-2-5-1-cross-site-scripting-xss-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-29T18:15:12Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-32r9-2j7h-3vqq",
"modified": "2024-08-29T18:31:36Z",
"published": "2024-08-29T18:31:36Z",
"aliases": [
"CVE-2024-44778"
],
"details": "A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44778"
},
{
"type": "WEB",
"url": "https://packetstormsecurity.com/files/180462/vTiger-CRM-7.4.0-Cross-Site-Scripting.html"
},
{
"type": "WEB",
"url": "http://vtiger.com"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-29T18:15:14Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-38g8-fv8m-xfpr",
"modified": "2024-08-29T18:31:35Z",
"published": "2024-08-29T18:31:35Z",
"aliases": [
"CVE-2024-43926"
],
"details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Beaver Builder Team Beaver Builder allows Reflected XSS.This issue affects Beaver Builder: from n/a through 2.8.3.2.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43926"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/beaver-builder-lite-version/wordpress-beaver-builder-plugin-2-8-3-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-29T18:15:09Z"
}
}

Some files were not shown because too many files have changed in this diff Show More