From 45e81ed5db5877066620410c7cfd659e3a008f77 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 31 Jul 2024 18:34:22 +0000 Subject: [PATCH] Publish Advisories GHSA-24g8-xhgr-ch6g GHSA-2fvc-q825-c4gm GHSA-5v8f-xx9m-wj44 GHSA-84cr-4mp4-8888 GHSA-cxjq-fmfx-pgf3 GHSA-q22c-j54j-x955 GHSA-q77q-33v2-m8hr GHSA-vc5j-jhxm-jh4w --- .../GHSA-24g8-xhgr-ch6g.json | 38 ++++++++++++++ .../GHSA-2fvc-q825-c4gm.json | 50 +++++++++++++++++++ .../GHSA-5v8f-xx9m-wj44.json | 38 ++++++++++++++ .../GHSA-84cr-4mp4-8888.json | 38 ++++++++++++++ .../GHSA-cxjq-fmfx-pgf3.json | 38 ++++++++++++++ .../GHSA-q22c-j54j-x955.json | 38 ++++++++++++++ .../GHSA-q77q-33v2-m8hr.json | 38 ++++++++++++++ .../GHSA-vc5j-jhxm-jh4w.json | 11 ++-- 8 files changed, 285 insertions(+), 4 deletions(-) create mode 100644 advisories/unreviewed/2024/07/GHSA-24g8-xhgr-ch6g/GHSA-24g8-xhgr-ch6g.json create mode 100644 advisories/unreviewed/2024/07/GHSA-2fvc-q825-c4gm/GHSA-2fvc-q825-c4gm.json create mode 100644 advisories/unreviewed/2024/07/GHSA-5v8f-xx9m-wj44/GHSA-5v8f-xx9m-wj44.json create mode 100644 advisories/unreviewed/2024/07/GHSA-84cr-4mp4-8888/GHSA-84cr-4mp4-8888.json create mode 100644 advisories/unreviewed/2024/07/GHSA-cxjq-fmfx-pgf3/GHSA-cxjq-fmfx-pgf3.json create mode 100644 advisories/unreviewed/2024/07/GHSA-q22c-j54j-x955/GHSA-q22c-j54j-x955.json create mode 100644 advisories/unreviewed/2024/07/GHSA-q77q-33v2-m8hr/GHSA-q77q-33v2-m8hr.json diff --git a/advisories/unreviewed/2024/07/GHSA-24g8-xhgr-ch6g/GHSA-24g8-xhgr-ch6g.json b/advisories/unreviewed/2024/07/GHSA-24g8-xhgr-ch6g/GHSA-24g8-xhgr-ch6g.json new file mode 100644 index 00000000000..28cec7535dd --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-24g8-xhgr-ch6g/GHSA-24g8-xhgr-ch6g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24g8-xhgr-ch6g", + "modified": "2024-07-31T18:32:01Z", + "published": "2024-07-31T18:32:01Z", + "aliases": [ + "CVE-2024-6974" + ], + "details": "Untrusted Search Path, Incorrect Default Permissions vulnerability in Cato Networks SDP Client on Windows allows Privilege Escalation.This issue affects SDP Client: before 5.10.34.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6974" + }, + { + "type": "WEB", + "url": "https://support.catonetworks.com/hc/en-us/articles/19762641007133-CVE-2024-6974-Windows-SDP-Client-Local-Privilege-Escalation-via-self-upgrade" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-31T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-2fvc-q825-c4gm/GHSA-2fvc-q825-c4gm.json b/advisories/unreviewed/2024/07/GHSA-2fvc-q825-c4gm/GHSA-2fvc-q825-c4gm.json new file mode 100644 index 00000000000..0f60ca3ded4 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-2fvc-q825-c4gm/GHSA-2fvc-q825-c4gm.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2fvc-q825-c4gm", + "modified": "2024-07-31T18:32:01Z", + "published": "2024-07-31T18:32:01Z", + "aliases": [ + "CVE-2024-7324" + ], + "details": "A vulnerability was found in IObit iTop Data Recovery Pro 4.4.0.687. It has been declared as critical. Affected by this vulnerability is an unknown functionality in the library madbasic_.bpl of the component BPL Handler. The manipulation leads to uncontrolled search path. Local access is required to approach this attack. The associated identifier of this vulnerability is VDB-273247. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7324" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273247" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273247" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.378138" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-31T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-5v8f-xx9m-wj44/GHSA-5v8f-xx9m-wj44.json b/advisories/unreviewed/2024/07/GHSA-5v8f-xx9m-wj44/GHSA-5v8f-xx9m-wj44.json new file mode 100644 index 00000000000..da094ee7e11 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-5v8f-xx9m-wj44/GHSA-5v8f-xx9m-wj44.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5v8f-xx9m-wj44", + "modified": "2024-07-31T18:32:01Z", + "published": "2024-07-31T18:32:01Z", + "aliases": [ + "CVE-2024-23444" + ], + "details": "It was discovered by Elastic engineering that when elasticsearch-certutil CLI tool is used with the csr option in order to create a new Certificate Signing Requests, the associated private key that is generated is stored on disk unencrypted even if the --pass parameter is passed in the command invocation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23444" + }, + { + "type": "WEB", + "url": "https://discuss.elastic.co/t/elasticsearch-8-13-0-7-17-23-security-update-esa-2024-12/364157" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-311" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-31T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-84cr-4mp4-8888/GHSA-84cr-4mp4-8888.json b/advisories/unreviewed/2024/07/GHSA-84cr-4mp4-8888/GHSA-84cr-4mp4-8888.json new file mode 100644 index 00000000000..52b31796363 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-84cr-4mp4-8888/GHSA-84cr-4mp4-8888.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-84cr-4mp4-8888", + "modified": "2024-07-31T18:32:01Z", + "published": "2024-07-31T18:32:01Z", + "aliases": [ + "CVE-2024-6973" + ], + "details": "Improper Input Validation vulnerability in Cato Networks SDP Client on Windows allows OS Command Injection.This issue affects Windows SDP Client: before 5.10.34.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6973" + }, + { + "type": "WEB", + "url": "https://support.catonetworks.com/hc/en-us/articles/19756987454237-CVE-2024-6973-Windows-SDP-Client-Remote-Code-Execution-via-crafted-URLs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-31T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-cxjq-fmfx-pgf3/GHSA-cxjq-fmfx-pgf3.json b/advisories/unreviewed/2024/07/GHSA-cxjq-fmfx-pgf3/GHSA-cxjq-fmfx-pgf3.json new file mode 100644 index 00000000000..a2ec6d18852 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-cxjq-fmfx-pgf3/GHSA-cxjq-fmfx-pgf3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxjq-fmfx-pgf3", + "modified": "2024-07-31T18:32:01Z", + "published": "2024-07-31T18:32:01Z", + "aliases": [ + "CVE-2024-6975" + ], + "details": "Untrusted Search Path vulnerability in Cato Networks SDP Client on Windows allows Privilege Escalation.This issue affects SDP Client: before 5.10.34.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6975" + }, + { + "type": "WEB", + "url": "https://support.catonetworks.com/hc/en-us/articles/19758025406621-CVE-2024-6975-Windows-SDP-Client-Local-Privilege-Escalation-via-openssl-configuration-file" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-426" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-31T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-q22c-j54j-x955/GHSA-q22c-j54j-x955.json b/advisories/unreviewed/2024/07/GHSA-q22c-j54j-x955/GHSA-q22c-j54j-x955.json new file mode 100644 index 00000000000..b9e1314f280 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-q22c-j54j-x955/GHSA-q22c-j54j-x955.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q22c-j54j-x955", + "modified": "2024-07-31T18:32:01Z", + "published": "2024-07-31T18:32:01Z", + "aliases": [ + "CVE-2024-6978" + ], + "details": "Improper Input Validation vulnerability in Cato Networks SDP Client on Windows allows Command Injection.This issue affects SDP Client: before 5.10.28.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6978" + }, + { + "type": "WEB", + "url": "https://support.catonetworks.com/hc/en-us/articles/19767051500957-CVE-2024-6978-Windows-SDP-Client-Local-root-certificates-can-be-installed-with-low-privileged-users" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-31T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-q77q-33v2-m8hr/GHSA-q77q-33v2-m8hr.json b/advisories/unreviewed/2024/07/GHSA-q77q-33v2-m8hr/GHSA-q77q-33v2-m8hr.json new file mode 100644 index 00000000000..9d3dbbb3aaf --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-q77q-33v2-m8hr/GHSA-q77q-33v2-m8hr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q77q-33v2-m8hr", + "modified": "2024-07-31T18:32:01Z", + "published": "2024-07-31T18:32:01Z", + "aliases": [ + "CVE-2024-6977" + ], + "details": "A vulnerability in Cato Networks SDP Client on Windows allows the insertion of sensitive information into the log file, which can lead to an account takeover. However, the attack requires bypassing protections on modifying the tunnel token on a the attacker's system.This issue affects SDP Client: before 5.10.34.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6977" + }, + { + "type": "WEB", + "url": "https://support.catonetworks.com/hc/en-us/articles/19766795729437-CVE-2024-6977-Windows-SDP-Client-Sensitive-data-in-trace-logs-can-lead-to-account-takeover" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-31T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-vc5j-jhxm-jh4w/GHSA-vc5j-jhxm-jh4w.json b/advisories/unreviewed/2024/07/GHSA-vc5j-jhxm-jh4w/GHSA-vc5j-jhxm-jh4w.json index 480322d0a36..41587b00b08 100644 --- a/advisories/unreviewed/2024/07/GHSA-vc5j-jhxm-jh4w/GHSA-vc5j-jhxm-jh4w.json +++ b/advisories/unreviewed/2024/07/GHSA-vc5j-jhxm-jh4w/GHSA-vc5j-jhxm-jh4w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vc5j-jhxm-jh4w", - "modified": "2024-07-10T09:30:41Z", + "modified": "2024-07-31T18:32:00Z", "published": "2024-07-10T09:30:41Z", "aliases": [ "CVE-2024-39493" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qat - Fix ADF_DEV_RESET_SYNC memory leak\n\nUsing completion_done to determine whether the caller has gone\naway only works after a complete call. Furthermore it's still\npossible that the caller has not yet called wait_for_completion,\nresulting in another potential UAF.\n\nFix this by making the caller use cancel_work_sync and then freeing\nthe memory safely.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-10T08:15:11Z"