Publish Advisories

GHSA-2g9g-66pp-8rq7
GHSA-3g7m-8wg3-6ggh
GHSA-62rm-mh7j-gv7j
GHSA-8jrf-cjx8-q3g8
GHSA-8p3v-87jv-mp95
GHSA-f35w-r35c-hc8m
GHSA-f83j-8cc9-3p7f
GHSA-fmpq-mw2c-9cvr
GHSA-fpw7-j2hg-69v5
GHSA-gcvf-qqcq-825h
GHSA-gvq9-2m65-mcj6
GHSA-h6f8-82jm-w268
GHSA-jqqv-px8m-v953
GHSA-mq99-924g-fq3x
GHSA-r3qr-6c5q-pr77
GHSA-rhmf-g96x-3g22
GHSA-v3cc-gxvr-wp29
GHSA-v7v6-3chw-vv8j
GHSA-wm9w-g37p-3f8p
GHSA-x2m4-5rqp-rhvq
This commit is contained in:
advisory-database[bot]
2024-04-11 06:31:34 +00:00
parent a960f6ae48
commit 4349e88339
20 changed files with 648 additions and 3 deletions
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2g9g-66pp-8rq7",
"modified": "2024-04-11T06:30:35Z",
"published": "2024-04-11T06:30:35Z",
"aliases": [
"CVE-2024-30915"
],
"details": "An issue was discovered in OpenDDS commit b1c534032bb62ad4ae32609778de6b8d6c823a66, allows a local attacker to cause a denial of service and obtain sensitive information via the max_samples parameter within the DataReaderQoS component.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30915"
},
{
"type": "WEB",
"url": "https://github.com/OpenDDS/OpenDDS/issues/4527"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T06:15:06Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3g7m-8wg3-6ggh",
"modified": "2024-04-11T06:30:35Z",
"published": "2024-04-11T06:30:35Z",
"aliases": [
"CVE-2024-29449"
],
"details": "An issue was discovered in ROS2 Humble Hawksbill in ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to obtain sensitive information via man-in-the-middle attacks due to cleartext transmission of data across the ROS2 nodes' communication channels.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29449"
},
{
"type": "WEB",
"url": "https://github.com/yashpatelphd/CVE-2024-29449"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T04:15:08Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-62rm-mh7j-gv7j",
"modified": "2024-04-11T06:30:35Z",
"published": "2024-04-11T06:30:35Z",
"aliases": [
"CVE-2024-30916"
],
"details": "An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a denial of service (DoS) and obtain sensitive information via a crafted max_samples parameter in DurabilityService QoS component.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30916"
},
{
"type": "WEB",
"url": "https://github.com/eProsima/Fast-DDS/issues/4609"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T06:15:07Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8jrf-cjx8-q3g8",
"modified": "2024-04-11T06:30:35Z",
"published": "2024-04-11T06:30:35Z",
"aliases": [
"CVE-2024-30880"
],
"details": "Reflected Cross Site Scripting (XSS) vulnerability in RageFrame2 v2.6.43, allows remote attackers to execute arbitrary web scripts or HTML and obtain sensitive information via a crafted payload injected into the multiple parameter in the image cropping function.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30880"
},
{
"type": "WEB",
"url": "https://github.com/jianyan74/rageframe2/issues/114"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T05:15:47Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8p3v-87jv-mp95",
"modified": "2024-04-11T06:30:35Z",
"published": "2024-04-11T06:30:35Z",
"aliases": [
"CVE-2024-30917"
],
"details": "An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a denial of service (DoS) and obtain sensitive information via a crafted history_depth parameter in DurabilityService QoS component.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30917"
},
{
"type": "WEB",
"url": "https://github.com/eProsima/Fast-DDS/issues/4609"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T06:15:07Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f35w-r35c-hc8m",
"modified": "2024-04-11T06:30:35Z",
"published": "2024-04-11T06:30:35Z",
"aliases": [
"CVE-2023-6257"
],
"details": "The Inline Related Posts WordPress plugin before 3.6.0 does not ensure that post content displayed via an AJAX action are accessible to the user, allowing any authenticated user, such as subscriber to retrieve the content of password protected posts",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6257"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/19a86448-8d7c-4f02-9290-d9f93810e6e1"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T05:15:47Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f83j-8cc9-3p7f",
"modified": "2024-04-11T06:30:35Z",
"published": "2024-04-11T06:30:35Z",
"aliases": [
"CVE-2024-30884"
],
"details": "Reflected Cross-Site Scripting (XSS) vulnerability in Discuz! version X3.4 20220811, allows remote attackers to execute arbitrary code and obtain sensitive information via crafted payload to the primarybegin parameter in the misc.php component.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30884"
},
{
"type": "WEB",
"url": "https://github.com/Hebing123/cve/issues/28"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T05:15:47Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fmpq-mw2c-9cvr",
"modified": "2024-04-11T06:30:35Z",
"published": "2024-04-11T06:30:35Z",
"aliases": [
"CVE-2024-29450"
],
"details": "An issue has been discovered in the permission and access control components within ROS2 Humble Hawksbill, in ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain sensitive information via the authentication system, including protocols, processes, and checks designed to verify the identities of users or devices attempting to access the ROS2 system.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29450"
},
{
"type": "WEB",
"url": "https://github.com/yashpatelphd/CVE-2024-29450"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T04:15:08Z"
}
}
@@ -0,0 +1,58 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fpw7-j2hg-69v5",
"modified": "2024-04-11T06:30:35Z",
"published": "2024-04-11T06:30:35Z",
"aliases": [
"CVE-2024-21508"
],
"details": "Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the readCodeFor function due to improper validation of the supportBigNumbers and bigNumberStrings values.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21508"
},
{
"type": "WEB",
"url": "https://github.com/sidorares/node-mysql2/pull/2572"
},
{
"type": "WEB",
"url": "https://github.com/sidorares/node-mysql2/commit/74abf9ef94d76114d9a09415e28b496522a94805"
},
{
"type": "WEB",
"url": "https://blog.slonser.info/posts/mysql2-attacker-configuration"
},
{
"type": "WEB",
"url": "https://github.com/sidorares/node-mysql2/blob/1609b5393516d72a4ae47196837317fbe75e0c13/lib/parsers/text_parser.js%23L14C10-L14C21"
},
{
"type": "WEB",
"url": "https://github.com/sidorares/node-mysql2/releases/tag/v3.9.4"
},
{
"type": "WEB",
"url": "https://security.snyk.io/vuln/SNYK-JS-MYSQL2-6591085"
}
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T05:15:47Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gcvf-qqcq-825h",
"modified": "2024-04-09T00:30:41Z",
"modified": "2024-04-11T06:30:34Z",
"published": "2024-04-09T00:30:41Z",
"aliases": [
"CVE-2024-27632"
@@ -18,6 +18,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27632"
},
{
"type": "WEB",
"url": "https://github.com/ally-petitt/CVE-2024-27632"
},
{
"type": "WEB",
"url": "https://medium.com/%40allypetitt/how-i-found-3-cves-in-2-days-8a135eb924d3"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gvq9-2m65-mcj6",
"modified": "2024-04-11T06:30:35Z",
"published": "2024-04-11T06:30:35Z",
"aliases": [
"CVE-2024-30883"
],
"details": "Reflected Cross Site Scripting (XSS) vulnerability in RageFrame2 v2.6.43, allows remote attackers to execute arbitrary web scripts or HTML and obtain sensitive information via a crafted payload injected into the aspectRatio parameter in the image cropping function.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30883"
},
{
"type": "WEB",
"url": "https://github.com/jianyan74/rageframe2/issues/114"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T05:15:47Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h6f8-82jm-w268",
"modified": "2024-04-11T06:30:35Z",
"published": "2024-04-11T06:30:35Z",
"aliases": [
"CVE-2024-29455"
],
"details": "An arbitrary file upload vulnerability has been discovered in ROS2 Humble Hawksbill in ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code, cause a denial of service (DoS), and obtain sensitive information via crafted payload to the file upload mechanism of the ROS2 system, including the servers functionality for handling file uploads and the associated validation processes.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29455"
},
{
"type": "WEB",
"url": "https://github.com/yashpatelphd/CVE-2024-29455"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T05:15:47Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jqqv-px8m-v953",
"modified": "2024-04-11T06:30:35Z",
"published": "2024-04-11T06:30:35Z",
"aliases": [
"CVE-2024-3621"
],
"details": "A vulnerability was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. It has been classified as critical. This affects an unknown part of the file /control/register_case.php. The manipulation of the argument title/case_no/client_name/court/case_type/case_stage/legel_acts/description/filling_date/hearing_date/opposite_lawyer/total_fees/unpaid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260277 was assigned to this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3621"
},
{
"type": "WEB",
"url": "https://github.com/zyairelai/CVE-submissions/blob/main/kortex-register_case-sqli.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.260277"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.260277"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.312832"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T04:15:08Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mq99-924g-fq3x",
"modified": "2024-04-11T06:30:35Z",
"published": "2024-04-11T06:30:35Z",
"aliases": [
"CVE-2024-30878"
],
"details": "A cross-site scripting (XSS) vulnerability in RageFrame2 v2.6.43, allows remote attackers to execute arbitrary web scripts or HTML and obtain sensitive information via a crafted payload injected into the upload_drive parameter.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30878"
},
{
"type": "WEB",
"url": "https://github.com/jianyan74/rageframe2/issues/111"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T05:15:47Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r3qr-6c5q-pr77",
"modified": "2024-04-11T06:30:35Z",
"published": "2024-04-11T06:30:35Z",
"aliases": [
"CVE-2024-30885"
],
"details": "Reflected Cross-Site Scripting (XSS) vulnerability in HadSky v7.6.3, allows remote attackers to execute arbitrary code and obtain sensitive information via the chklogin.php component .",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30885"
},
{
"type": "WEB",
"url": "https://github.com/Hebing123/cve/issues/29"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T05:15:47Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rhmf-g96x-3g22",
"modified": "2024-04-11T06:30:35Z",
"published": "2024-04-11T06:30:35Z",
"aliases": [
"CVE-2024-29399"
],
"details": "An issue was discovered in GNU Savane v.3.13 and before, allows a remote attacker to execute arbitrary code and escalate privileges via a crafted file to the upload.php component.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29399"
},
{
"type": "WEB",
"url": "https://github.com/ally-petitt/CVE-2024-29399"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T06:15:06Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v3cc-gxvr-wp29",
"modified": "2024-04-08T21:31:16Z",
"modified": "2024-04-11T06:30:34Z",
"published": "2024-04-08T21:31:16Z",
"aliases": [
"CVE-2024-27631"
@@ -22,6 +22,10 @@
"type": "WEB",
"url": "https://git.savannah.nongnu.org/cgit/administration/savane.git/commit/?h=i18n&id=d3962d3feb75467489b869204db98e2dffaaaf09"
},
{
"type": "WEB",
"url": "https://github.com/ally-petitt/CVE-2024-27631"
},
{
"type": "WEB",
"url": "https://medium.com/%40allypetitt/how-i-found-3-cves-in-2-days-8a135eb924d3"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v7v6-3chw-vv8j",
"modified": "2024-04-11T06:30:35Z",
"published": "2024-04-11T06:30:35Z",
"aliases": [
"CVE-2024-30879"
],
"details": "Reflected Cross Site Scripting (XSS) vulnerability in RageFrame2 v2.6.43, allows remote attackers to execute arbitrary web scripts or HTML and obtain sensitive information via a crafted payload injected into the boxId parameter in the image cropping function.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30879"
},
{
"type": "WEB",
"url": "https://github.com/jianyan74/rageframe2/issues/114"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T05:15:47Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wm9w-g37p-3f8p",
"modified": "2024-04-11T06:30:34Z",
"published": "2024-04-11T06:30:34Z",
"aliases": [
"CVE-2024-29448"
],
"details": "A buffer overflow vulnerability has been discovered in the C++ components of ROS2 Humble Hawksbill in ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code or cause a denial of service (DoS) via improper handling of arrays or strings.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29448"
},
{
"type": "WEB",
"url": "https://github.com/yashpatelphd/CVE-2024-29448"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T04:15:08Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x2m4-5rqp-rhvq",
"modified": "2024-04-08T21:31:16Z",
"modified": "2024-04-11T06:30:34Z",
"published": "2024-04-08T21:31:16Z",
"aliases": [
"CVE-2024-27630"
@@ -18,6 +18,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27630"
},
{
"type": "WEB",
"url": "https://github.com/ally-petitt/CVE-2024-27630"
},
{
"type": "WEB",
"url": "https://medium.com/%40allypetitt/how-i-found-3-cves-in-2-days-8a135eb924d3"