From 418d3c83d69d44be9d3dcda728a88a6fc14c2eb3 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 1 Mar 2024 09:32:36 +0000 Subject: [PATCH] Publish Advisories GHSA-26x3-cx3r-433v GHSA-3fj5-f9x9-2hvx GHSA-4r48-c38p-vgcv GHSA-5mf6-7wvp-g69h GHSA-79pv-8q24-469w GHSA-fffg-cwc9-xvj7 GHSA-j8jw-w4g4-q965 GHSA-q567-8x9h-6cgw GHSA-qw8c-vmfp-c4cj --- .../GHSA-26x3-cx3r-433v.json | 42 +++++++++++++++++++ .../GHSA-3fj5-f9x9-2hvx.json | 42 +++++++++++++++++++ .../GHSA-4r48-c38p-vgcv.json | 31 ++++++++++++++ .../GHSA-5mf6-7wvp-g69h.json | 38 +++++++++++++++++ .../GHSA-79pv-8q24-469w.json | 38 +++++++++++++++++ .../GHSA-fffg-cwc9-xvj7.json | 35 ++++++++++++++++ .../GHSA-j8jw-w4g4-q965.json | 38 +++++++++++++++++ .../GHSA-q567-8x9h-6cgw.json | 31 ++++++++++++++ .../GHSA-qw8c-vmfp-c4cj.json | 39 +++++++++++++++++ 9 files changed, 334 insertions(+) create mode 100644 advisories/unreviewed/2024/03/GHSA-26x3-cx3r-433v/GHSA-26x3-cx3r-433v.json create mode 100644 advisories/unreviewed/2024/03/GHSA-3fj5-f9x9-2hvx/GHSA-3fj5-f9x9-2hvx.json create mode 100644 advisories/unreviewed/2024/03/GHSA-4r48-c38p-vgcv/GHSA-4r48-c38p-vgcv.json create mode 100644 advisories/unreviewed/2024/03/GHSA-5mf6-7wvp-g69h/GHSA-5mf6-7wvp-g69h.json create mode 100644 advisories/unreviewed/2024/03/GHSA-79pv-8q24-469w/GHSA-79pv-8q24-469w.json create mode 100644 advisories/unreviewed/2024/03/GHSA-fffg-cwc9-xvj7/GHSA-fffg-cwc9-xvj7.json create mode 100644 advisories/unreviewed/2024/03/GHSA-j8jw-w4g4-q965/GHSA-j8jw-w4g4-q965.json create mode 100644 advisories/unreviewed/2024/03/GHSA-q567-8x9h-6cgw/GHSA-q567-8x9h-6cgw.json create mode 100644 advisories/unreviewed/2024/03/GHSA-qw8c-vmfp-c4cj/GHSA-qw8c-vmfp-c4cj.json diff --git a/advisories/unreviewed/2024/03/GHSA-26x3-cx3r-433v/GHSA-26x3-cx3r-433v.json b/advisories/unreviewed/2024/03/GHSA-26x3-cx3r-433v/GHSA-26x3-cx3r-433v.json new file mode 100644 index 00000000000..e042fd55de2 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-26x3-cx3r-433v/GHSA-26x3-cx3r-433v.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-26x3-cx3r-433v", + "modified": "2024-03-01T09:31:06Z", + "published": "2024-03-01T09:31:06Z", + "aliases": [ + "CVE-2024-1859" + ], + "details": "The Slider Responsive Slideshow – Image slider, Gallery slideshow plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.8 via deserialization of untrusted input to the awl_slider_responsive_shortcode function. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1859" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3041884%40slider-responsive-slideshow&new=3041884%40slider-responsive-slideshow&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d35266cd-41e6-4358-afaa-bc008962f2e1?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-01T07:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-3fj5-f9x9-2hvx/GHSA-3fj5-f9x9-2hvx.json b/advisories/unreviewed/2024/03/GHSA-3fj5-f9x9-2hvx/GHSA-3fj5-f9x9-2hvx.json new file mode 100644 index 00000000000..64c90e80c81 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-3fj5-f9x9-2hvx/GHSA-3fj5-f9x9-2hvx.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3fj5-f9x9-2hvx", + "modified": "2024-03-01T09:31:07Z", + "published": "2024-03-01T09:31:07Z", + "aliases": [ + "CVE-2024-0692" + ], + "details": "The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse SolarWinds’ service, resulting in remote code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0692" + }, + { + "type": "WEB", + "url": "https://documentation.solarwinds.com/en/success_center/sem/content/release_notes/sem_2023-4-1_release_notes.htm" + }, + { + "type": "WEB", + "url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-0692" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-01T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-4r48-c38p-vgcv/GHSA-4r48-c38p-vgcv.json b/advisories/unreviewed/2024/03/GHSA-4r48-c38p-vgcv/GHSA-4r48-c38p-vgcv.json new file mode 100644 index 00000000000..628120c407a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-4r48-c38p-vgcv/GHSA-4r48-c38p-vgcv.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4r48-c38p-vgcv", + "modified": "2024-03-01T09:31:06Z", + "published": "2024-03-01T09:31:06Z", + "aliases": [ + "CVE-2024-25553" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25553" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-01T08:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-5mf6-7wvp-g69h/GHSA-5mf6-7wvp-g69h.json b/advisories/unreviewed/2024/03/GHSA-5mf6-7wvp-g69h/GHSA-5mf6-7wvp-g69h.json new file mode 100644 index 00000000000..54e9ce2d723 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-5mf6-7wvp-g69h/GHSA-5mf6-7wvp-g69h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mf6-7wvp-g69h", + "modified": "2024-03-01T09:31:06Z", + "published": "2024-03-01T09:31:06Z", + "aliases": [ + "CVE-2024-25552" + ], + "details": "A local attacker can gain administrative privileges by inserting an executable file in the path of the affected product.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25552" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-018" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-428" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-01T08:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-79pv-8q24-469w/GHSA-79pv-8q24-469w.json b/advisories/unreviewed/2024/03/GHSA-79pv-8q24-469w/GHSA-79pv-8q24-469w.json new file mode 100644 index 00000000000..ca7cc5923a5 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-79pv-8q24-469w/GHSA-79pv-8q24-469w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79pv-8q24-469w", + "modified": "2024-03-01T09:31:07Z", + "published": "2024-03-01T09:31:07Z", + "aliases": [ + "CVE-2024-27950" + ], + "details": "Missing Authorization vulnerability in sirv.Com Image Optimizer, Resizer and CDN – Sirv.This issue affects Image Optimizer, Resizer and CDN – Sirv: from n/a through 7.2.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27950" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/sirv/wordpress-sirv-plugin-7-2-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-01T08:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-fffg-cwc9-xvj7/GHSA-fffg-cwc9-xvj7.json b/advisories/unreviewed/2024/03/GHSA-fffg-cwc9-xvj7/GHSA-fffg-cwc9-xvj7.json new file mode 100644 index 00000000000..9c5e374611d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-fffg-cwc9-xvj7/GHSA-fffg-cwc9-xvj7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fffg-cwc9-xvj7", + "modified": "2024-03-01T09:31:06Z", + "published": "2024-03-01T09:31:06Z", + "aliases": [ + "CVE-2023-52555" + ], + "details": "In mongo-express 1.0.2, /admin allows CSRF, as demonstrated by deletion of a Collection.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52555" + }, + { + "type": "WEB", + "url": "https://github.com/mongo-express/mongo-express/issues/1338" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-01T08:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-j8jw-w4g4-q965/GHSA-j8jw-w4g4-q965.json b/advisories/unreviewed/2024/03/GHSA-j8jw-w4g4-q965/GHSA-j8jw-w4g4-q965.json new file mode 100644 index 00000000000..331e0a32afa --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-j8jw-w4g4-q965/GHSA-j8jw-w4g4-q965.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8jw-w4g4-q965", + "modified": "2024-03-01T09:31:07Z", + "published": "2024-03-01T09:31:07Z", + "aliases": [ + "CVE-2024-27949" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in sirv.Com Image Optimizer, Resizer and CDN – Sirv.This issue affects Image Optimizer, Resizer and CDN – Sirv: from n/a through 7.2.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27949" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/sirv/wordpress-sirv-plugin-7-2-0-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-01T08:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-q567-8x9h-6cgw/GHSA-q567-8x9h-6cgw.json b/advisories/unreviewed/2024/03/GHSA-q567-8x9h-6cgw/GHSA-q567-8x9h-6cgw.json new file mode 100644 index 00000000000..158a38c553f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-q567-8x9h-6cgw/GHSA-q567-8x9h-6cgw.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q567-8x9h-6cgw", + "modified": "2024-03-01T09:31:06Z", + "published": "2024-03-01T09:31:06Z", + "aliases": [ + "CVE-2024-25554" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25554" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-01T08:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-qw8c-vmfp-c4cj/GHSA-qw8c-vmfp-c4cj.json b/advisories/unreviewed/2024/03/GHSA-qw8c-vmfp-c4cj/GHSA-qw8c-vmfp-c4cj.json new file mode 100644 index 00000000000..82ca55cc19a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-qw8c-vmfp-c4cj/GHSA-qw8c-vmfp-c4cj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qw8c-vmfp-c4cj", + "modified": "2024-03-01T09:31:07Z", + "published": "2024-03-01T09:31:07Z", + "aliases": [ + "CVE-2024-25091" + ], + "details": "Protection mechanism failure issue exists in RevoWorks SCVX prior to scvimage4.10.21_1013 (when using 'VirusChecker' or 'ThreatChecker' feature) and RevoWorks Browser prior to 2.2.95 (when using 'VirusChecker' or 'ThreatChecker' feature). If data containing malware is saved in a specific file format (eml, dmg, vhd, iso, msi), malware may be taken outside the sandboxed environment.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25091" + }, + { + "type": "WEB", + "url": "https://jscom.jp/news-20240229" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN35928117" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-01T09:15:09Z" + } +} \ No newline at end of file