Publish Advisories

GHSA-79hg-h6r6-64mm
GHSA-4jhq-mm86-8cmq
GHSA-54cg-4vp2-8f67
GHSA-5rx8-chp2-fvxf
GHSA-cmm9-h7p3-233m
GHSA-fjrj-vrrh-qjx6
GHSA-j3pw-x73p-86xf
GHSA-ww6r-jv53-52xq
This commit is contained in:
advisory-database[bot]
2024-08-07 06:32:58 +00:00
parent 6f63f2ffd3
commit 43ba815450
8 changed files with 311 additions and 47 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-79hg-h6r6-64mm",
"modified": "2024-08-02T18:31:10Z",
"modified": "2024-08-07T06:31:09Z",
"published": "2024-07-08T18:31:18Z",
"aliases": [
"CVE-2024-6409"
@@ -27,51 +27,7 @@
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:4457"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:4613"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:4716"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:4910"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-6409"
},
{
"type": "WEB",
"url": "https://almalinux.org/blog/2024-07-09-cve-2024-6409"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2295085"
},
{
"type": "WEB",
"url": "https://bugzilla.suse.com/show_bug.cgi?id=1227217"
},
{
"type": "WEB",
"url": "https://explore.alas.aws.amazon.com/CVE-2024-6409.html"
},
{
"type": "WEB",
"url": "https://security-tracker.debian.org/tracker/CVE-2024-6409"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240712-0003"
},
{
"type": "WEB",
"url": "https://sig-security.rocky.page/issues/CVE-2024-6409"
"url": "https://www.suse.com/security/cve/CVE-2024-6409.html"
},
{
"type": "WEB",
@@ -79,7 +35,55 @@
},
{
"type": "WEB",
"url": "https://www.suse.com/security/cve/CVE-2024-6409.html"
"url": "https://sig-security.rocky.page/issues/CVE-2024-6409"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240712-0003"
},
{
"type": "WEB",
"url": "https://security-tracker.debian.org/tracker/CVE-2024-6409"
},
{
"type": "WEB",
"url": "https://explore.alas.aws.amazon.com/CVE-2024-6409.html"
},
{
"type": "WEB",
"url": "https://bugzilla.suse.com/show_bug.cgi?id=1227217"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2295085"
},
{
"type": "WEB",
"url": "https://almalinux.org/blog/2024-07-09-cve-2024-6409"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-6409"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:4955"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:4910"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:4716"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:4613"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:4457"
},
{
"type": "WEB",
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4jhq-mm86-8cmq",
"modified": "2024-08-07T06:31:09Z",
"published": "2024-08-07T06:31:09Z",
"aliases": [
"CVE-2024-36131"
],
"details": "An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system of the appliance.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36131"
},
{
"type": "WEB",
"url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-for-Mobile-EPMM-July-2024"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-07T04:17:18Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-54cg-4vp2-8f67",
"modified": "2024-08-07T06:31:09Z",
"published": "2024-08-07T06:31:09Z",
"aliases": [
"CVE-2024-36132"
],
"details": "Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access sensitive resources.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36132"
},
{
"type": "WEB",
"url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-for-Mobile-EPMM-July-2024"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-07T04:17:18Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5rx8-chp2-fvxf",
"modified": "2024-08-07T06:31:10Z",
"published": "2024-08-07T06:31:10Z",
"aliases": [
"CVE-2024-37403"
],
"details": "Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to properly sanitize file names, resulting in a path traversal-affiliated vulnerability. This potentially enables other malicious apps on the device to read sensitive information stored in the app root.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37403"
},
{
"type": "WEB",
"url": "https://forums.ivanti.com/s/article/Security-Advisory-CVE-2024-37403-Dirty-Stream-for-Ivanti-Docs-Work-for-Android"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-07T04:17:18Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cmm9-h7p3-233m",
"modified": "2024-08-07T06:31:09Z",
"published": "2024-08-07T06:31:09Z",
"aliases": [
"CVE-2024-34788"
],
"details": "An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive information",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34788"
},
{
"type": "WEB",
"url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-for-Mobile-EPMM-July-2024"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-07T04:17:17Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fjrj-vrrh-qjx6",
"modified": "2024-08-07T06:31:10Z",
"published": "2024-08-07T06:31:10Z",
"aliases": [
"CVE-2024-6494"
],
"details": "The WordPress File Upload WordPress plugin before 4.24.8 does not properly sanitize and escape certain parameters, which could allow unauthenticated users to execute stored cross-site scripting (XSS) attacks.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6494"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/5b21a9be-b5fe-47ef-91c7-018dd42f763f"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-07T06:16:47Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j3pw-x73p-86xf",
"modified": "2024-08-07T06:31:10Z",
"published": "2024-08-07T06:31:10Z",
"aliases": [
"CVE-2024-3973"
],
"details": "The House Manager WordPress plugin through 1.0.8.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3973"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/8c6ce66e-091a-41da-a13d-5f80cadb499a"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-07T06:16:47Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ww6r-jv53-52xq",
"modified": "2024-08-07T06:31:09Z",
"published": "2024-08-07T06:31:09Z",
"aliases": [
"CVE-2024-36130"
],
"details": "An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36130"
},
{
"type": "WEB",
"url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-for-Mobile-EPMM-July-2024"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-07T04:17:17Z"
}
}