diff --git a/advisories/github-reviewed/2024/08/GHSA-g8h2-j9pm-4xx2/GHSA-g8h2-j9pm-4xx2.json b/advisories/github-reviewed/2024/08/GHSA-g8h2-j9pm-4xx2/GHSA-g8h2-j9pm-4xx2.json index 7c51ec0e20b..9218e432c31 100644 --- a/advisories/github-reviewed/2024/08/GHSA-g8h2-j9pm-4xx2/GHSA-g8h2-j9pm-4xx2.json +++ b/advisories/github-reviewed/2024/08/GHSA-g8h2-j9pm-4xx2/GHSA-g8h2-j9pm-4xx2.json @@ -1,8 +1,9 @@ { "schema_version": "1.4.0", "id": "GHSA-g8h2-j9pm-4xx2", - "modified": "2024-08-23T22:52:12Z", + "modified": "2024-08-26T15:30:15Z", "published": "2024-08-23T21:30:42Z", + "withdrawn": "2024-08-26T15:30:15Z", "aliases": [ "CVE-2024-40111" ], diff --git a/advisories/unreviewed/2023/04/GHSA-99cc-3w6r-wwmv/GHSA-99cc-3w6r-wwmv.json b/advisories/unreviewed/2023/04/GHSA-99cc-3w6r-wwmv/GHSA-99cc-3w6r-wwmv.json index 8dde8344104..6a33215c16b 100644 --- a/advisories/unreviewed/2023/04/GHSA-99cc-3w6r-wwmv/GHSA-99cc-3w6r-wwmv.json +++ b/advisories/unreviewed/2023/04/GHSA-99cc-3w6r-wwmv/GHSA-99cc-3w6r-wwmv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-99cc-3w6r-wwmv", - "modified": "2023-11-09T15:30:26Z", + "modified": "2024-08-26T15:31:11Z", "published": "2023-04-11T21:31:02Z", "aliases": [ "CVE-2023-1989" diff --git a/advisories/unreviewed/2023/09/GHSA-2hg9-5m5v-wmhr/GHSA-2hg9-5m5v-wmhr.json b/advisories/unreviewed/2023/09/GHSA-2hg9-5m5v-wmhr/GHSA-2hg9-5m5v-wmhr.json index ef3666629e6..7f098072a01 100644 --- a/advisories/unreviewed/2023/09/GHSA-2hg9-5m5v-wmhr/GHSA-2hg9-5m5v-wmhr.json +++ b/advisories/unreviewed/2023/09/GHSA-2hg9-5m5v-wmhr/GHSA-2hg9-5m5v-wmhr.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-648" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-769q-xhv3-qgqv/GHSA-769q-xhv3-qgqv.json b/advisories/unreviewed/2023/11/GHSA-769q-xhv3-qgqv/GHSA-769q-xhv3-qgqv.json index 93158552c47..d6c7f4bfb25 100644 --- a/advisories/unreviewed/2023/11/GHSA-769q-xhv3-qgqv/GHSA-769q-xhv3-qgqv.json +++ b/advisories/unreviewed/2023/11/GHSA-769q-xhv3-qgqv/GHSA-769q-xhv3-qgqv.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-359" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-9h2f-7xpr-xgq4/GHSA-9h2f-7xpr-xgq4.json b/advisories/unreviewed/2023/11/GHSA-9h2f-7xpr-xgq4/GHSA-9h2f-7xpr-xgq4.json index 14eb33d6336..88dd4f2280f 100644 --- a/advisories/unreviewed/2023/11/GHSA-9h2f-7xpr-xgq4/GHSA-9h2f-7xpr-xgq4.json +++ b/advisories/unreviewed/2023/11/GHSA-9h2f-7xpr-xgq4/GHSA-9h2f-7xpr-xgq4.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-648" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-vx62-r535-jwqf/GHSA-vx62-r535-jwqf.json b/advisories/unreviewed/2023/11/GHSA-vx62-r535-jwqf/GHSA-vx62-r535-jwqf.json index 3fffb96a122..23c7d039d13 100644 --- a/advisories/unreviewed/2023/11/GHSA-vx62-r535-jwqf/GHSA-vx62-r535-jwqf.json +++ b/advisories/unreviewed/2023/11/GHSA-vx62-r535-jwqf/GHSA-vx62-r535-jwqf.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-648" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-jhxj-w2j8-p3gf/GHSA-jhxj-w2j8-p3gf.json b/advisories/unreviewed/2024/02/GHSA-jhxj-w2j8-p3gf/GHSA-jhxj-w2j8-p3gf.json index 2c65d0ca6a6..963c8c2b786 100644 --- a/advisories/unreviewed/2024/02/GHSA-jhxj-w2j8-p3gf/GHSA-jhxj-w2j8-p3gf.json +++ b/advisories/unreviewed/2024/02/GHSA-jhxj-w2j8-p3gf/GHSA-jhxj-w2j8-p3gf.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-648" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-p8w6-qgpq-8mqq/GHSA-p8w6-qgpq-8mqq.json b/advisories/unreviewed/2024/02/GHSA-p8w6-qgpq-8mqq/GHSA-p8w6-qgpq-8mqq.json index c7ef64d4262..2a0b4690319 100644 --- a/advisories/unreviewed/2024/02/GHSA-p8w6-qgpq-8mqq/GHSA-p8w6-qgpq-8mqq.json +++ b/advisories/unreviewed/2024/02/GHSA-p8w6-qgpq-8mqq/GHSA-p8w6-qgpq-8mqq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p8w6-qgpq-8mqq", - "modified": "2024-02-21T21:30:25Z", + "modified": "2024-08-26T15:31:13Z", "published": "2024-02-21T21:30:25Z", "aliases": [ "CVE-2024-25381" ], "details": "There is a Stored XSS Vulnerability in Emlog Pro 2.2.8 Article Publishing, due to non-filtering of quoted content.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T19:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-4965-8838-r53x/GHSA-4965-8838-r53x.json b/advisories/unreviewed/2024/04/GHSA-4965-8838-r53x/GHSA-4965-8838-r53x.json index 51991e5981d..e4e09bb02f3 100644 --- a/advisories/unreviewed/2024/04/GHSA-4965-8838-r53x/GHSA-4965-8838-r53x.json +++ b/advisories/unreviewed/2024/04/GHSA-4965-8838-r53x/GHSA-4965-8838-r53x.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-648" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-4vh4-c5mm-jqmw/GHSA-4vh4-c5mm-jqmw.json b/advisories/unreviewed/2024/04/GHSA-4vh4-c5mm-jqmw/GHSA-4vh4-c5mm-jqmw.json index 6ae3e5c6bec..cccfd199ca1 100644 --- a/advisories/unreviewed/2024/04/GHSA-4vh4-c5mm-jqmw/GHSA-4vh4-c5mm-jqmw.json +++ b/advisories/unreviewed/2024/04/GHSA-4vh4-c5mm-jqmw/GHSA-4vh4-c5mm-jqmw.json @@ -25,7 +25,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-248" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-cjjw-5q77-9xc9/GHSA-cjjw-5q77-9xc9.json b/advisories/unreviewed/2024/05/GHSA-cjjw-5q77-9xc9/GHSA-cjjw-5q77-9xc9.json index 673e99578e6..4fbe00fe363 100644 --- a/advisories/unreviewed/2024/05/GHSA-cjjw-5q77-9xc9/GHSA-cjjw-5q77-9xc9.json +++ b/advisories/unreviewed/2024/05/GHSA-cjjw-5q77-9xc9/GHSA-cjjw-5q77-9xc9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cjjw-5q77-9xc9", - "modified": "2024-05-21T21:30:27Z", + "modified": "2024-08-26T15:31:13Z", "published": "2024-05-21T21:30:27Z", "aliases": [ "CVE-2024-31756" ], "details": "An issue in MarvinTest Solutions Hardware Access Driver v.5.0.3.0 and before and fixed in v.5.0.4.0 allows a local attacker to escalate privileges via the Hw65.sys component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T20:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-rj2x-cq83-r6r3/GHSA-rj2x-cq83-r6r3.json b/advisories/unreviewed/2024/05/GHSA-rj2x-cq83-r6r3/GHSA-rj2x-cq83-r6r3.json index 2633c9d94af..c535977d1c6 100644 --- a/advisories/unreviewed/2024/05/GHSA-rj2x-cq83-r6r3/GHSA-rj2x-cq83-r6r3.json +++ b/advisories/unreviewed/2024/05/GHSA-rj2x-cq83-r6r3/GHSA-rj2x-cq83-r6r3.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-256" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-355p-v6gf-92vj/GHSA-355p-v6gf-92vj.json b/advisories/unreviewed/2024/06/GHSA-355p-v6gf-92vj/GHSA-355p-v6gf-92vj.json index f37e43d35ce..d5491b5c99b 100644 --- a/advisories/unreviewed/2024/06/GHSA-355p-v6gf-92vj/GHSA-355p-v6gf-92vj.json +++ b/advisories/unreviewed/2024/06/GHSA-355p-v6gf-92vj/GHSA-355p-v6gf-92vj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-355p-v6gf-92vj", - "modified": "2024-06-19T15:30:52Z", + "modified": "2024-08-26T15:31:13Z", "published": "2024-06-19T15:30:52Z", "aliases": [ "CVE-2024-36979" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bridge: mst: fix vlan use-after-free\n\nsyzbot reported a suspicious rcu usage[1] in bridge's mst code. While\nfixing it I noticed that nothing prevents a vlan to be freed while\nwalking the list from the same path (br forward delay timer). Fix the rcu\nusage and also make sure we are not accessing freed memory by making\nbr_mst_vlan_set_state use rcu read lock.\n\n[1]\n WARNING: suspicious RCU usage\n 6.9.0-rc6-syzkaller #0 Not tainted\n -----------------------------\n net/bridge/br_private.h:1599 suspicious rcu_dereference_protected() usage!\n ...\n stack backtrace:\n CPU: 1 PID: 8017 Comm: syz-executor.1 Not tainted 6.9.0-rc6-syzkaller #0\n Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024\n Call Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:114\n lockdep_rcu_suspicious+0x221/0x340 kernel/locking/lockdep.c:6712\n nbp_vlan_group net/bridge/br_private.h:1599 [inline]\n br_mst_set_state+0x1ea/0x650 net/bridge/br_mst.c:105\n br_set_state+0x28a/0x7b0 net/bridge/br_stp.c:47\n br_forward_delay_timer_expired+0x176/0x440 net/bridge/br_stp_timer.c:88\n call_timer_fn+0x18e/0x650 kernel/time/timer.c:1793\n expire_timers kernel/time/timer.c:1844 [inline]\n __run_timers kernel/time/timer.c:2418 [inline]\n __run_timer_base+0x66a/0x8e0 kernel/time/timer.c:2429\n run_timer_base kernel/time/timer.c:2438 [inline]\n run_timer_softirq+0xb7/0x170 kernel/time/timer.c:2448\n __do_softirq+0x2c6/0x980 kernel/softirq.c:554\n invoke_softirq kernel/softirq.c:428 [inline]\n __irq_exit_rcu+0xf2/0x1c0 kernel/softirq.c:633\n irq_exit_rcu+0x9/0x30 kernel/softirq.c:645\n instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1043 [inline]\n sysvec_apic_timer_interrupt+0xa6/0xc0 arch/x86/kernel/apic/apic.c:1043\n \n \n asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:702\n RIP: 0010:lock_acquire+0x264/0x550 kernel/locking/lockdep.c:5758\n Code: 2b 00 74 08 4c 89 f7 e8 ba d1 84 00 f6 44 24 61 02 0f 85 85 01 00 00 41 f7 c7 00 02 00 00 74 01 fb 48 c7 44 24 40 0e 36 e0 45 <4b> c7 44 25 00 00 00 00 00 43 c7 44 25 09 00 00 00 00 43 c7 44 25\n RSP: 0018:ffffc90013657100 EFLAGS: 00000206\n RAX: 0000000000000001 RBX: 1ffff920026cae2c RCX: 0000000000000001\n RDX: dffffc0000000000 RSI: ffffffff8bcaca00 RDI: ffffffff8c1eaa60\n RBP: ffffc90013657260 R08: ffffffff92efe507 R09: 1ffffffff25dfca0\n R10: dffffc0000000000 R11: fffffbfff25dfca1 R12: 1ffff920026cae28\n R13: dffffc0000000000 R14: ffffc90013657160 R15: 0000000000000246", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:13Z" diff --git a/advisories/unreviewed/2024/06/GHSA-cjpf-prr4-vrfm/GHSA-cjpf-prr4-vrfm.json b/advisories/unreviewed/2024/06/GHSA-cjpf-prr4-vrfm/GHSA-cjpf-prr4-vrfm.json index 884d0b9ed92..727e0c98094 100644 --- a/advisories/unreviewed/2024/06/GHSA-cjpf-prr4-vrfm/GHSA-cjpf-prr4-vrfm.json +++ b/advisories/unreviewed/2024/06/GHSA-cjpf-prr4-vrfm/GHSA-cjpf-prr4-vrfm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cjpf-prr4-vrfm", - "modified": "2024-06-12T18:30:41Z", + "modified": "2024-08-26T15:31:13Z", "published": "2024-06-12T18:30:41Z", "aliases": [ "CVE-2024-24051" ], "details": "Improper input validation of printing files in Monoprice Select Mini V2 V37.115.32 allows attackers to instruct the device's movable parts to destinations that exceed the devices' maximum coordinates via the printing of a malicious .gcode file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-12T18:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-hw5c-f5h3-cr4p/GHSA-hw5c-f5h3-cr4p.json b/advisories/unreviewed/2024/06/GHSA-hw5c-f5h3-cr4p/GHSA-hw5c-f5h3-cr4p.json index 133220d96eb..34455264929 100644 --- a/advisories/unreviewed/2024/06/GHSA-hw5c-f5h3-cr4p/GHSA-hw5c-f5h3-cr4p.json +++ b/advisories/unreviewed/2024/06/GHSA-hw5c-f5h3-cr4p/GHSA-hw5c-f5h3-cr4p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hw5c-f5h3-cr4p", - "modified": "2024-06-17T21:31:10Z", + "modified": "2024-08-26T15:31:13Z", "published": "2024-06-17T21:31:10Z", "aliases": [ "CVE-2023-37058" ], "details": "Insecure Permissions vulnerability in JLINK Unionman Technology Co. Ltd Jlink AX1800 v.1.0 allows a remote attacker to escalate privileges via a crafted command.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-17T21:15:50Z" diff --git a/advisories/unreviewed/2024/06/GHSA-vmv4-cp43-whx4/GHSA-vmv4-cp43-whx4.json b/advisories/unreviewed/2024/06/GHSA-vmv4-cp43-whx4/GHSA-vmv4-cp43-whx4.json index 7298ce3529b..cf1ceb96f66 100644 --- a/advisories/unreviewed/2024/06/GHSA-vmv4-cp43-whx4/GHSA-vmv4-cp43-whx4.json +++ b/advisories/unreviewed/2024/06/GHSA-vmv4-cp43-whx4/GHSA-vmv4-cp43-whx4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vmv4-cp43-whx4", - "modified": "2024-06-19T15:30:52Z", + "modified": "2024-08-26T15:31:13Z", "published": "2024-06-19T15:30:52Z", "aliases": [ "CVE-2024-38539" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/cma: Fix kmemleak in rdma_core observed during blktests nvme/rdma use siw\n\nWhen running blktests nvme/rdma, the following kmemleak issue will appear.\n\nkmemleak: Kernel memory leak detector initialized (mempool available:36041)\nkmemleak: Automatic memory scanning thread started\nkmemleak: 2 new suspected memory leaks (see /sys/kernel/debug/kmemleak)\nkmemleak: 8 new suspected memory leaks (see /sys/kernel/debug/kmemleak)\nkmemleak: 17 new suspected memory leaks (see /sys/kernel/debug/kmemleak)\nkmemleak: 4 new suspected memory leaks (see /sys/kernel/debug/kmemleak)\n\nunreferenced object 0xffff88855da53400 (size 192):\n comm \"rdma\", pid 10630, jiffies 4296575922\n hex dump (first 32 bytes):\n 37 00 00 00 00 00 00 00 c0 ff ff ff 1f 00 00 00 7...............\n 10 34 a5 5d 85 88 ff ff 10 34 a5 5d 85 88 ff ff .4.].....4.]....\n backtrace (crc 47f66721):\n [] kmalloc_trace+0x30d/0x3b0\n [] alloc_gid_entry+0x47/0x380 [ib_core]\n [] add_modify_gid+0x166/0x930 [ib_core]\n [] ib_cache_update.part.0+0x6d8/0x910 [ib_core]\n [] ib_cache_setup_one+0x24a/0x350 [ib_core]\n [] ib_register_device+0x9e/0x3a0 [ib_core]\n [] 0xffffffffc2a3d389\n [] nldev_newlink+0x2b8/0x520 [ib_core]\n [] rdma_nl_rcv_msg+0x2c3/0x520 [ib_core]\n []\nrdma_nl_rcv_skb.constprop.0.isra.0+0x23c/0x3a0 [ib_core]\n [] netlink_unicast+0x445/0x710\n [] netlink_sendmsg+0x761/0xc40\n [] __sys_sendto+0x3a9/0x420\n [] __x64_sys_sendto+0xdc/0x1b0\n [] do_syscall_64+0x93/0x180\n [] entry_SYSCALL_64_after_hwframe+0x71/0x79\n\nThe root cause: rdma_put_gid_attr is not called when sgid_attr is set\nto ERR_PTR(-ENODEV).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:14Z" diff --git a/advisories/unreviewed/2024/07/GHSA-5pj2-3h8g-rxfg/GHSA-5pj2-3h8g-rxfg.json b/advisories/unreviewed/2024/07/GHSA-5pj2-3h8g-rxfg/GHSA-5pj2-3h8g-rxfg.json index df0c5527061..38523297bae 100644 --- a/advisories/unreviewed/2024/07/GHSA-5pj2-3h8g-rxfg/GHSA-5pj2-3h8g-rxfg.json +++ b/advisories/unreviewed/2024/07/GHSA-5pj2-3h8g-rxfg/GHSA-5pj2-3h8g-rxfg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5pj2-3h8g-rxfg", - "modified": "2024-07-29T15:30:44Z", + "modified": "2024-08-26T15:31:14Z", "published": "2024-07-29T15:30:44Z", "aliases": [ "CVE-2024-41064" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/eeh: avoid possible crash when edev->pdev changes\n\nIf a PCI device is removed during eeh_pe_report_edev(), edev->pdev\nwill change and can cause a crash, hold the PCI rescan/remove lock\nwhile taking a copy of edev->pdev->bus.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T15:15:14Z" diff --git a/advisories/unreviewed/2024/07/GHSA-83vm-wg7j-77hw/GHSA-83vm-wg7j-77hw.json b/advisories/unreviewed/2024/07/GHSA-83vm-wg7j-77hw/GHSA-83vm-wg7j-77hw.json index 7aac4061ed3..ca2d370b696 100644 --- a/advisories/unreviewed/2024/07/GHSA-83vm-wg7j-77hw/GHSA-83vm-wg7j-77hw.json +++ b/advisories/unreviewed/2024/07/GHSA-83vm-wg7j-77hw/GHSA-83vm-wg7j-77hw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-83vm-wg7j-77hw", - "modified": "2024-07-29T15:30:42Z", + "modified": "2024-08-26T15:31:14Z", "published": "2024-07-29T15:30:42Z", "aliases": [ "CVE-2024-41049" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfilelock: fix potential use-after-free in posix_lock_inode\n\nLight Hsieh reported a KASAN UAF warning in trace_posix_lock_inode().\nThe request pointer had been changed earlier to point to a lock entry\nthat was added to the inode's list. However, before the tracepoint could\nfire, another task raced in and freed that lock.\n\nFix this by moving the tracepoint inside the spinlock, which should\nensure that this doesn't happen.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T15:15:13Z" diff --git a/advisories/unreviewed/2024/07/GHSA-c3x3-cqcq-2r5x/GHSA-c3x3-cqcq-2r5x.json b/advisories/unreviewed/2024/07/GHSA-c3x3-cqcq-2r5x/GHSA-c3x3-cqcq-2r5x.json index 80785528008..39c718b5d24 100644 --- a/advisories/unreviewed/2024/07/GHSA-c3x3-cqcq-2r5x/GHSA-c3x3-cqcq-2r5x.json +++ b/advisories/unreviewed/2024/07/GHSA-c3x3-cqcq-2r5x/GHSA-c3x3-cqcq-2r5x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c3x3-cqcq-2r5x", - "modified": "2024-07-29T15:30:42Z", + "modified": "2024-08-26T15:31:14Z", "published": "2024-07-29T15:30:42Z", "aliases": [ "CVE-2024-41046" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ethernet: lantiq_etop: fix double free in detach\n\nThe number of the currently released descriptor is never incremented\nwhich results in the same skb being released multiple times.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-415" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T15:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-m487-w7jq-5grr/GHSA-m487-w7jq-5grr.json b/advisories/unreviewed/2024/07/GHSA-m487-w7jq-5grr/GHSA-m487-w7jq-5grr.json index b2182885c85..a81922a7ffd 100644 --- a/advisories/unreviewed/2024/07/GHSA-m487-w7jq-5grr/GHSA-m487-w7jq-5grr.json +++ b/advisories/unreviewed/2024/07/GHSA-m487-w7jq-5grr/GHSA-m487-w7jq-5grr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m487-w7jq-5grr", - "modified": "2024-07-29T15:30:46Z", + "modified": "2024-08-26T15:31:14Z", "published": "2024-07-29T15:30:46Z", "aliases": [ "CVE-2024-41071" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: Avoid address calculations via out of bounds array indexing\n\nreq->n_channels must be set before req->channels[] can be used.\n\nThis patch fixes one of the issues encountered in [1].\n\n[ 83.964255] UBSAN: array-index-out-of-bounds in net/mac80211/scan.c:364:4\n[ 83.964258] index 0 is out of range for type 'struct ieee80211_channel *[]'\n[...]\n[ 83.964264] Call Trace:\n[ 83.964267] \n[ 83.964269] dump_stack_lvl+0x3f/0xc0\n[ 83.964274] __ubsan_handle_out_of_bounds+0xec/0x110\n[ 83.964278] ieee80211_prep_hw_scan+0x2db/0x4b0\n[ 83.964281] __ieee80211_start_scan+0x601/0x990\n[ 83.964291] nl80211_trigger_scan+0x874/0x980\n[ 83.964295] genl_family_rcv_msg_doit+0xe8/0x160\n[ 83.964298] genl_rcv_msg+0x240/0x270\n[...]\n\n[1] https://bugzilla.kernel.org/show_bug.cgi?id=218810", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-129" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T15:15:14Z" diff --git a/advisories/unreviewed/2024/07/GHSA-mhpr-v3hf-gcxg/GHSA-mhpr-v3hf-gcxg.json b/advisories/unreviewed/2024/07/GHSA-mhpr-v3hf-gcxg/GHSA-mhpr-v3hf-gcxg.json index 50bcdbfc417..a99b5a6ce8b 100644 --- a/advisories/unreviewed/2024/07/GHSA-mhpr-v3hf-gcxg/GHSA-mhpr-v3hf-gcxg.json +++ b/advisories/unreviewed/2024/07/GHSA-mhpr-v3hf-gcxg/GHSA-mhpr-v3hf-gcxg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mhpr-v3hf-gcxg", - "modified": "2024-07-29T18:30:40Z", + "modified": "2024-08-26T15:31:14Z", "published": "2024-07-29T18:30:40Z", "aliases": [ "CVE-2024-42085" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: dwc3: core: remove lock of otg mode during gadget suspend/resume to avoid deadlock\n\nWhen config CONFIG_USB_DWC3_DUAL_ROLE is selected, and trigger system\nto enter suspend status with below command:\necho mem > /sys/power/state\nThere will be a deadlock issue occurring. Detailed invoking path as\nbelow:\ndwc3_suspend_common()\n spin_lock_irqsave(&dwc->lock, flags); <-- 1st\n dwc3_gadget_suspend(dwc);\n dwc3_gadget_soft_disconnect(dwc);\n spin_lock_irqsave(&dwc->lock, flags); <-- 2nd\nThis issue is exposed by commit c7ebd8149ee5 (\"usb: dwc3: gadget: Fix\nNULL pointer dereference in dwc3_gadget_suspend\") that removes the code\nof checking whether dwc->gadget_driver is NULL or not. It causes the\nfollowing code is executed and deadlock occurs when trying to get the\nspinlock. In fact, the root cause is the commit 5265397f9442(\"usb: dwc3:\nRemove DWC3 locking during gadget suspend/resume\") that forgot to remove\nthe lock of otg mode. So, remove the redundant lock of otg mode during\ngadget suspend/resume.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T17:15:11Z" diff --git a/advisories/unreviewed/2024/07/GHSA-pr22-x636-xp32/GHSA-pr22-x636-xp32.json b/advisories/unreviewed/2024/07/GHSA-pr22-x636-xp32/GHSA-pr22-x636-xp32.json index 22574c05ac6..4602b08e206 100644 --- a/advisories/unreviewed/2024/07/GHSA-pr22-x636-xp32/GHSA-pr22-x636-xp32.json +++ b/advisories/unreviewed/2024/07/GHSA-pr22-x636-xp32/GHSA-pr22-x636-xp32.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pr22-x636-xp32", - "modified": "2024-07-29T18:30:42Z", + "modified": "2024-08-26T15:31:14Z", "published": "2024-07-29T18:30:42Z", "aliases": [ "CVE-2024-42090" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npinctrl: fix deadlock in create_pinctrl() when handling -EPROBE_DEFER\n\nIn create_pinctrl(), pinctrl_maps_mutex is acquired before calling\nadd_setting(). If add_setting() returns -EPROBE_DEFER, create_pinctrl()\ncalls pinctrl_free(). However, pinctrl_free() attempts to acquire\npinctrl_maps_mutex, which is already held by create_pinctrl(), leading to\na potential deadlock.\n\nThis patch resolves the issue by releasing pinctrl_maps_mutex before\ncalling pinctrl_free(), preventing the deadlock.\n\nThis bug was discovered and resolved using Coverity Static Analysis\nSecurity Testing (SAST) by Synopsys, Inc.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T17:15:11Z" diff --git a/advisories/unreviewed/2024/07/GHSA-v9r3-3hjw-wxm2/GHSA-v9r3-3hjw-wxm2.json b/advisories/unreviewed/2024/07/GHSA-v9r3-3hjw-wxm2/GHSA-v9r3-3hjw-wxm2.json index a770302d503..e468dbb4335 100644 --- a/advisories/unreviewed/2024/07/GHSA-v9r3-3hjw-wxm2/GHSA-v9r3-3hjw-wxm2.json +++ b/advisories/unreviewed/2024/07/GHSA-v9r3-3hjw-wxm2/GHSA-v9r3-3hjw-wxm2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v9r3-3hjw-wxm2", - "modified": "2024-07-29T18:30:43Z", + "modified": "2024-08-26T15:31:14Z", "published": "2024-07-29T18:30:43Z", "aliases": [ "CVE-2024-42093" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/dpaa2: Avoid explicit cpumask var allocation on stack\n\nFor CONFIG_CPUMASK_OFFSTACK=y kernel, explicit allocation of cpumask\nvariable on stack is not recommended since it can cause potential stack\noverflow.\n\nInstead, kernel code should always use *cpumask_var API(s) to allocate\ncpumask var in config-neutral way, leaving allocation strategy to\nCONFIG_CPUMASK_OFFSTACK.\n\nUse *cpumask_var API(s) to address it.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T18:15:11Z" diff --git a/advisories/unreviewed/2024/07/GHSA-xj6g-c6gv-vmjp/GHSA-xj6g-c6gv-vmjp.json b/advisories/unreviewed/2024/07/GHSA-xj6g-c6gv-vmjp/GHSA-xj6g-c6gv-vmjp.json index d44a72161d0..2780031b1d8 100644 --- a/advisories/unreviewed/2024/07/GHSA-xj6g-c6gv-vmjp/GHSA-xj6g-c6gv-vmjp.json +++ b/advisories/unreviewed/2024/07/GHSA-xj6g-c6gv-vmjp/GHSA-xj6g-c6gv-vmjp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xj6g-c6gv-vmjp", - "modified": "2024-07-29T18:30:38Z", + "modified": "2024-08-26T15:31:14Z", "published": "2024-07-29T18:30:38Z", "aliases": [ "CVE-2024-41083" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix netfs_page_mkwrite() to check folio->mapping is valid\n\nFix netfs_page_mkwrite() to check that folio->mapping is valid once it has\ntaken the folio lock (as filemap_page_mkwrite() does). Without this,\ngeneric/247 occasionally oopses with something like the following:\n\n BUG: kernel NULL pointer dereference, address: 0000000000000000\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n\n RIP: 0010:trace_event_raw_event_netfs_folio+0x61/0xc0\n ...\n Call Trace:\n \n ? __die_body+0x1a/0x60\n ? page_fault_oops+0x6e/0xa0\n ? exc_page_fault+0xc2/0xe0\n ? asm_exc_page_fault+0x22/0x30\n ? trace_event_raw_event_netfs_folio+0x61/0xc0\n trace_netfs_folio+0x39/0x40\n netfs_page_mkwrite+0x14c/0x1d0\n do_page_mkwrite+0x50/0x90\n do_pte_missing+0x184/0x200\n __handle_mm_fault+0x42d/0x500\n handle_mm_fault+0x121/0x1f0\n do_user_addr_fault+0x23e/0x3c0\n exc_page_fault+0xc2/0xe0\n asm_exc_page_fault+0x22/0x30\n\nThis is due to the invalidate_inode_pages2_range() issued at the end of the\nDIO write interfering with the mmap'd writes.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:03Z" diff --git a/advisories/unreviewed/2024/08/GHSA-25gm-jxwr-cv79/GHSA-25gm-jxwr-cv79.json b/advisories/unreviewed/2024/08/GHSA-25gm-jxwr-cv79/GHSA-25gm-jxwr-cv79.json new file mode 100644 index 00000000000..27ec0e518a0 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-25gm-jxwr-cv79/GHSA-25gm-jxwr-cv79.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25gm-jxwr-cv79", + "modified": "2024-08-26T15:31:15Z", + "published": "2024-08-26T15:31:15Z", + "aliases": [ + "CVE-2024-43966" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stark Digital WP Testimonial Widget.This issue affects WP Testimonial Widget: from n/a through 3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43966" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-testimonial-widget/wordpress-wp-testimonial-widget-plugin-3-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-553w-hm5g-6ccq/GHSA-553w-hm5g-6ccq.json b/advisories/unreviewed/2024/08/GHSA-553w-hm5g-6ccq/GHSA-553w-hm5g-6ccq.json index 972366abd93..34c151cef5e 100644 --- a/advisories/unreviewed/2024/08/GHSA-553w-hm5g-6ccq/GHSA-553w-hm5g-6ccq.json +++ b/advisories/unreviewed/2024/08/GHSA-553w-hm5g-6ccq/GHSA-553w-hm5g-6ccq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-553w-hm5g-6ccq", - "modified": "2024-08-23T15:30:34Z", + "modified": "2024-08-26T15:31:14Z", "published": "2024-08-23T15:30:34Z", "aliases": [ "CVE-2024-42766" ], "details": "Kashipara Bus Ticket Reservation System v1.0 0 is vulnerable to Incorrect Access Control via /deleteTicket.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-23T15:15:16Z" diff --git a/advisories/unreviewed/2024/08/GHSA-5554-3cr8-7rwc/GHSA-5554-3cr8-7rwc.json b/advisories/unreviewed/2024/08/GHSA-5554-3cr8-7rwc/GHSA-5554-3cr8-7rwc.json new file mode 100644 index 00000000000..94e4a400000 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5554-3cr8-7rwc/GHSA-5554-3cr8-7rwc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5554-3cr8-7rwc", + "modified": "2024-08-26T15:31:15Z", + "published": "2024-08-26T15:31:15Z", + "aliases": [ + "CVE-2024-38859" + ], + "details": "XSS in the view page with the SLA column configured in Checkmk versions prior to 2.3.0p14, 2.2.0p33, 2.1.0p47 and 2.0.0 (EOL) allowed malicious users to execute arbitrary scripts by injecting HTML elements into the SLA column title. These scripts could be executed when the view page was cloned by other users.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38859" + }, + { + "type": "WEB", + "url": "https://checkmk.com/werk/17026" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-57cq-jgq2-x7vg/GHSA-57cq-jgq2-x7vg.json b/advisories/unreviewed/2024/08/GHSA-57cq-jgq2-x7vg/GHSA-57cq-jgq2-x7vg.json index 2ad7c673f6b..9ea504ac584 100644 --- a/advisories/unreviewed/2024/08/GHSA-57cq-jgq2-x7vg/GHSA-57cq-jgq2-x7vg.json +++ b/advisories/unreviewed/2024/08/GHSA-57cq-jgq2-x7vg/GHSA-57cq-jgq2-x7vg.json @@ -33,6 +33,7 @@ "database_specific": { "cwe_ids": [ "CWE-122", + "CWE-787", "CWE-79" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-598h-v73f-rx7f/GHSA-598h-v73f-rx7f.json b/advisories/unreviewed/2024/08/GHSA-598h-v73f-rx7f/GHSA-598h-v73f-rx7f.json index 94d1d7bcba1..52c629a0352 100644 --- a/advisories/unreviewed/2024/08/GHSA-598h-v73f-rx7f/GHSA-598h-v73f-rx7f.json +++ b/advisories/unreviewed/2024/08/GHSA-598h-v73f-rx7f/GHSA-598h-v73f-rx7f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-598h-v73f-rx7f", - "modified": "2024-08-26T06:30:46Z", + "modified": "2024-08-26T15:31:14Z", "published": "2024-08-20T06:31:37Z", "aliases": [ "CVE-2024-43688" ], "details": "cron/entry.c in vixie cron before 9cc8ab1, as used in OpenBSD 7.4 and 7.5, allows a heap-based buffer underflow and memory corruption. NOTE: this issue was introduced during a May 2023 refactoring.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-20T06:15:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-6qwg-m6gj-jwc9/GHSA-6qwg-m6gj-jwc9.json b/advisories/unreviewed/2024/08/GHSA-6qwg-m6gj-jwc9/GHSA-6qwg-m6gj-jwc9.json new file mode 100644 index 00000000000..5a3a1ba3994 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6qwg-m6gj-jwc9/GHSA-6qwg-m6gj-jwc9.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6qwg-m6gj-jwc9", + "modified": "2024-08-26T15:31:15Z", + "published": "2024-08-26T15:31:15Z", + "aliases": [ + "CVE-2024-8164" + ], + "details": "A vulnerability, which was classified as critical, has been found in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5. Affected by this issue is the function rename of the file /Admin/Http/Controllers/FileManagerController.php. The manipulation of the argument new_name leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8164" + }, + { + "type": "WEB", + "url": "https://github.com/DeepMountains/zzz/blob/main/CVE4-2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.275762" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.275762" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.393375" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-736q-w2cq-gpwv/GHSA-736q-w2cq-gpwv.json b/advisories/unreviewed/2024/08/GHSA-736q-w2cq-gpwv/GHSA-736q-w2cq-gpwv.json new file mode 100644 index 00000000000..df5f0c124f7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-736q-w2cq-gpwv/GHSA-736q-w2cq-gpwv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-736q-w2cq-gpwv", + "modified": "2024-08-26T15:31:15Z", + "published": "2024-08-26T15:31:15Z", + "aliases": [ + "CVE-2024-42787" + ], + "details": "A Stored Cross Site Scripting (XSS) vulnerability was found in \"/music/ajax.php?action=save_playlist\" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via \"title\" & \"description\" parameter fields.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42787" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Music%20Management%20System%20v1.0/Stored%20XSS%20-%20Add%20Playlist.pdf" + }, + { + "type": "WEB", + "url": "https://www.kashipara.com/project/php/12978/music-management-system-in-php-php-project-source-code" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-84wj-vj6c-5mrf/GHSA-84wj-vj6c-5mrf.json b/advisories/unreviewed/2024/08/GHSA-84wj-vj6c-5mrf/GHSA-84wj-vj6c-5mrf.json new file mode 100644 index 00000000000..fbacf364e9f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-84wj-vj6c-5mrf/GHSA-84wj-vj6c-5mrf.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-84wj-vj6c-5mrf", + "modified": "2024-08-26T15:31:16Z", + "published": "2024-08-26T15:31:15Z", + "aliases": [ + "CVE-2024-8167" + ], + "details": "A vulnerability was found in code-projects Job Portal 1.0. It has been classified as critical. Affected is an unknown function of the file /forget.php. The manipulation of the argument email/mobile leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8167" + }, + { + "type": "WEB", + "url": "https://github.com/t4rrega/cve/issues/1" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.275766" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.275766" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.397714" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-896v-mq35-7wx7/GHSA-896v-mq35-7wx7.json b/advisories/unreviewed/2024/08/GHSA-896v-mq35-7wx7/GHSA-896v-mq35-7wx7.json new file mode 100644 index 00000000000..4943ceee609 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-896v-mq35-7wx7/GHSA-896v-mq35-7wx7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-896v-mq35-7wx7", + "modified": "2024-08-26T15:31:15Z", + "published": "2024-08-26T15:31:15Z", + "aliases": [ + "CVE-2024-39097" + ], + "details": "There is an Open Redirect vulnerability in Gnuboard v6.0.4 and below via the `url` parameter in login path.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39097" + }, + { + "type": "WEB", + "url": "https://github.com/gnuboard/g6/issues/582" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Letm3through/1c7a422aa93b587fe63254e06b7f2977" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-8p7p-r9xv-w8g4/GHSA-8p7p-r9xv-w8g4.json b/advisories/unreviewed/2024/08/GHSA-8p7p-r9xv-w8g4/GHSA-8p7p-r9xv-w8g4.json index e458dc4a3cf..41e72702cf1 100644 --- a/advisories/unreviewed/2024/08/GHSA-8p7p-r9xv-w8g4/GHSA-8p7p-r9xv-w8g4.json +++ b/advisories/unreviewed/2024/08/GHSA-8p7p-r9xv-w8g4/GHSA-8p7p-r9xv-w8g4.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-345" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-9gr6-q98c-q2r4/GHSA-9gr6-q98c-q2r4.json b/advisories/unreviewed/2024/08/GHSA-9gr6-q98c-q2r4/GHSA-9gr6-q98c-q2r4.json index 9d60eeb5181..546c3235cbb 100644 --- a/advisories/unreviewed/2024/08/GHSA-9gr6-q98c-q2r4/GHSA-9gr6-q98c-q2r4.json +++ b/advisories/unreviewed/2024/08/GHSA-9gr6-q98c-q2r4/GHSA-9gr6-q98c-q2r4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9gr6-q98c-q2r4", - "modified": "2024-08-26T12:31:20Z", + "modified": "2024-08-26T15:31:15Z", "published": "2024-08-26T12:31:20Z", "aliases": [ "CVE-2024-44563" ], "details": "Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function setIptvInfo.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T12:15:05Z" diff --git a/advisories/unreviewed/2024/08/GHSA-c7r9-cmp3-5xg9/GHSA-c7r9-cmp3-5xg9.json b/advisories/unreviewed/2024/08/GHSA-c7r9-cmp3-5xg9/GHSA-c7r9-cmp3-5xg9.json new file mode 100644 index 00000000000..a6cdb93e3c8 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c7r9-cmp3-5xg9/GHSA-c7r9-cmp3-5xg9.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7r9-cmp3-5xg9", + "modified": "2024-08-26T15:31:15Z", + "published": "2024-08-26T15:31:15Z", + "aliases": [ + "CVE-2024-8165" + ], + "details": "A vulnerability, which was classified as problematic, was found in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5. This affects the function exportZip of the file /admin/file_manager/export. The manipulation of the argument path leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8165" + }, + { + "type": "WEB", + "url": "https://github.com/DeepMountains/Mirage/blob/main/CVE18-1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.275763" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.275763" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.393376" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f3c7-2m22-wr7x/GHSA-f3c7-2m22-wr7x.json b/advisories/unreviewed/2024/08/GHSA-f3c7-2m22-wr7x/GHSA-f3c7-2m22-wr7x.json index 88f19d09874..1d8302329ca 100644 --- a/advisories/unreviewed/2024/08/GHSA-f3c7-2m22-wr7x/GHSA-f3c7-2m22-wr7x.json +++ b/advisories/unreviewed/2024/08/GHSA-f3c7-2m22-wr7x/GHSA-f3c7-2m22-wr7x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f3c7-2m22-wr7x", - "modified": "2024-08-22T03:31:33Z", + "modified": "2024-08-26T15:31:14Z", "published": "2024-08-22T03:31:32Z", "aliases": [ "CVE-2024-42056" ], "details": "Retool (self-hosted enterprise) through 3.40.0 inserts resource authentication credentials into sent data. Credentials for users with \"Use\" permissions can be discovered (by an authenticated attacker) via the /api/resources endpoint. The earliest affected version is 3.18.1.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-532" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-22T01:15:03Z" diff --git a/advisories/unreviewed/2024/08/GHSA-fmc4-v39v-phr8/GHSA-fmc4-v39v-phr8.json b/advisories/unreviewed/2024/08/GHSA-fmc4-v39v-phr8/GHSA-fmc4-v39v-phr8.json new file mode 100644 index 00000000000..526ba3ea311 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fmc4-v39v-phr8/GHSA-fmc4-v39v-phr8.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmc4-v39v-phr8", + "modified": "2024-08-26T15:31:15Z", + "published": "2024-08-26T15:31:15Z", + "aliases": [ + "CVE-2024-8162" + ], + "details": "A vulnerability classified as critical has been found in TOTOLINK T10 AC1200 4.1.8cu.5207. Affected is an unknown function of the file /squashfs-root/web_cste/cgi-bin/product.ini of the component Telnet Service. The manipulation leads to hard-coded credentials. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8162" + }, + { + "type": "WEB", + "url": "https://github.com/rohitburke/TOTOLINK" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.275760" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.275760" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.392015" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fw5q-5jr8-g3vh/GHSA-fw5q-5jr8-g3vh.json b/advisories/unreviewed/2024/08/GHSA-fw5q-5jr8-g3vh/GHSA-fw5q-5jr8-g3vh.json index 6425eee0d73..b82b0615867 100644 --- a/advisories/unreviewed/2024/08/GHSA-fw5q-5jr8-g3vh/GHSA-fw5q-5jr8-g3vh.json +++ b/advisories/unreviewed/2024/08/GHSA-fw5q-5jr8-g3vh/GHSA-fw5q-5jr8-g3vh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fw5q-5jr8-g3vh", - "modified": "2024-08-26T09:30:44Z", + "modified": "2024-08-26T15:31:15Z", "published": "2024-08-26T09:30:44Z", "aliases": [ "CVE-2024-45256" ], "details": "An arbitrary file write issue in the exfiltration endpoint in BYOB (Build Your Own Botnet) 2.0 allows attackers to overwrite SQLite databases and bypass authentication via an unauthenticated HTTP request with a crafted parameter. This occurs in file_add in api/files/routes.py.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T07:15:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-grmc-8w5p-47x7/GHSA-grmc-8w5p-47x7.json b/advisories/unreviewed/2024/08/GHSA-grmc-8w5p-47x7/GHSA-grmc-8w5p-47x7.json new file mode 100644 index 00000000000..e13deb04bcf --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-grmc-8w5p-47x7/GHSA-grmc-8w5p-47x7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grmc-8w5p-47x7", + "modified": "2024-08-26T15:31:15Z", + "published": "2024-08-26T15:31:15Z", + "aliases": [ + "CVE-2024-44558" + ], + "details": "Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function setIptvInfo.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44558" + }, + { + "type": "WEB", + "url": "https://detailed-stetson-767.notion.site/Tenda-AX1806-Buffer-Overflow-in-setIptvInfo-5aee8fa8b7754d319ee35027d3628f2e?pvs=4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T13:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hqgg-5wv8-wwxg/GHSA-hqgg-5wv8-wwxg.json b/advisories/unreviewed/2024/08/GHSA-hqgg-5wv8-wwxg/GHSA-hqgg-5wv8-wwxg.json new file mode 100644 index 00000000000..6e55c78814a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hqgg-5wv8-wwxg/GHSA-hqgg-5wv8-wwxg.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqgg-5wv8-wwxg", + "modified": "2024-08-26T15:31:15Z", + "published": "2024-08-26T15:31:15Z", + "aliases": [ + "CVE-2024-42789" + ], + "details": "A Reflected Cross Site Scripting (XSS) vulnerability was found in \"/music/controller.php?page=test\" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via the \"page\" parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42789" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Music%20Management%20System%20v1.0/Reflected%20XSS%20-%20Controller.pdf" + }, + { + "type": "WEB", + "url": "https://www.kashipara.com/project/php/12978/music-management-system-in-php-php-project-source-code" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j26h-qjc9-68hh/GHSA-j26h-qjc9-68hh.json b/advisories/unreviewed/2024/08/GHSA-j26h-qjc9-68hh/GHSA-j26h-qjc9-68hh.json new file mode 100644 index 00000000000..a7842de4ae7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j26h-qjc9-68hh/GHSA-j26h-qjc9-68hh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j26h-qjc9-68hh", + "modified": "2024-08-26T15:31:15Z", + "published": "2024-08-26T15:31:15Z", + "aliases": [ + "CVE-2023-49582" + ], + "details": "Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, potentially revealing sensitive application data. \n\nThis issue does not affect non-Unix platforms, or builds with APR_USE_SHMEM_SHMGET=1 (apr.h)\n\nUsers are recommended to upgrade to APR version 1.7.5, which fixes this issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49582" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/sntjc04t1rvjhdzz2tzmtz2zdnmv7dc4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j2gf-fhx6-5xrq/GHSA-j2gf-fhx6-5xrq.json b/advisories/unreviewed/2024/08/GHSA-j2gf-fhx6-5xrq/GHSA-j2gf-fhx6-5xrq.json index 8bd0d47b016..67941182793 100644 --- a/advisories/unreviewed/2024/08/GHSA-j2gf-fhx6-5xrq/GHSA-j2gf-fhx6-5xrq.json +++ b/advisories/unreviewed/2024/08/GHSA-j2gf-fhx6-5xrq/GHSA-j2gf-fhx6-5xrq.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-j685-8895-62hc/GHSA-j685-8895-62hc.json b/advisories/unreviewed/2024/08/GHSA-j685-8895-62hc/GHSA-j685-8895-62hc.json new file mode 100644 index 00000000000..dd01b6b2c61 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j685-8895-62hc/GHSA-j685-8895-62hc.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j685-8895-62hc", + "modified": "2024-08-26T15:31:15Z", + "published": "2024-08-26T15:31:15Z", + "aliases": [ + "CVE-2024-8163" + ], + "details": "A vulnerability classified as critical was found in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5. Affected by this vulnerability is the function destroyFiles of the file /admin/file_manager/files. The manipulation of the argument files leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8163" + }, + { + "type": "WEB", + "url": "https://github.com/DeepMountains/zzz/blob/main/CVE4-1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.275761" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.275761" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.393374" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mcpp-jhwq-85qq/GHSA-mcpp-jhwq-85qq.json b/advisories/unreviewed/2024/08/GHSA-mcpp-jhwq-85qq/GHSA-mcpp-jhwq-85qq.json new file mode 100644 index 00000000000..c297cbce384 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mcpp-jhwq-85qq/GHSA-mcpp-jhwq-85qq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcpp-jhwq-85qq", + "modified": "2024-08-26T15:31:15Z", + "published": "2024-08-26T15:31:15Z", + "aliases": [ + "CVE-2024-7987" + ], + "details": "A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™\nthat allows a threat actor to execute arbitrary code with System privileges. To exploit this vulnerability and a threat actor must abuse the ThinServer™ service by creating a junction and use it to upload arbitrary files.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7987" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1692.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p997-wfmc-cvcj/GHSA-p997-wfmc-cvcj.json b/advisories/unreviewed/2024/08/GHSA-p997-wfmc-cvcj/GHSA-p997-wfmc-cvcj.json new file mode 100644 index 00000000000..bd3a7edc5fa --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-p997-wfmc-cvcj/GHSA-p997-wfmc-cvcj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p997-wfmc-cvcj", + "modified": "2024-08-26T15:31:15Z", + "published": "2024-08-26T15:31:15Z", + "aliases": [ + "CVE-2024-7988" + ], + "details": "A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. This vulnerability exists due to the lack of proper data input validation, which allows files to be overwritten.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7988" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1692.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pg2r-prx2-mw84/GHSA-pg2r-prx2-mw84.json b/advisories/unreviewed/2024/08/GHSA-pg2r-prx2-mw84/GHSA-pg2r-prx2-mw84.json new file mode 100644 index 00000000000..d5604abd618 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-pg2r-prx2-mw84/GHSA-pg2r-prx2-mw84.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pg2r-prx2-mw84", + "modified": "2024-08-26T15:31:15Z", + "published": "2024-08-26T15:31:15Z", + "aliases": [ + "CVE-2024-44556" + ], + "details": "Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function setIptvInfo.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44556" + }, + { + "type": "WEB", + "url": "https://detailed-stetson-767.notion.site/Tenda-AX1806-Buffer-Overflow-in-setIptvInfo-5aee8fa8b7754d319ee35027d3628f2e?pvs=4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T13:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rpx6-6266-hrf9/GHSA-rpx6-6266-hrf9.json b/advisories/unreviewed/2024/08/GHSA-rpx6-6266-hrf9/GHSA-rpx6-6266-hrf9.json new file mode 100644 index 00000000000..82cfea96a9c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rpx6-6266-hrf9/GHSA-rpx6-6266-hrf9.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpx6-6266-hrf9", + "modified": "2024-08-26T15:31:15Z", + "published": "2024-08-26T15:31:15Z", + "aliases": [ + "CVE-2024-8166" + ], + "details": "A vulnerability has been found in Ruijie EG2000K 11.1(6)B2 and classified as critical. This vulnerability affects unknown code of the file /tool/index.php?c=download&a=save. The manipulation of the argument content leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8166" + }, + { + "type": "WEB", + "url": "https://github.com/qiuhuihk/cve/blob/main/ruijie.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.275764" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.275764" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.393750" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w5rf-88wr-4cq3/GHSA-w5rf-88wr-4cq3.json b/advisories/unreviewed/2024/08/GHSA-w5rf-88wr-4cq3/GHSA-w5rf-88wr-4cq3.json new file mode 100644 index 00000000000..fc1f020ab0b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w5rf-88wr-4cq3/GHSA-w5rf-88wr-4cq3.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w5rf-88wr-4cq3", + "modified": "2024-08-26T15:31:16Z", + "published": "2024-08-26T15:31:15Z", + "aliases": [ + "CVE-2024-8168" + ], + "details": "A vulnerability was found in code-projects Online Bus Reservation Site 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file login.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8168" + }, + { + "type": "WEB", + "url": "https://github.com/t4rrega/cve/issues/2" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.275767" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.275767" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.397715" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wmgr-v54x-r8jg/GHSA-wmgr-v54x-r8jg.json b/advisories/unreviewed/2024/08/GHSA-wmgr-v54x-r8jg/GHSA-wmgr-v54x-r8jg.json new file mode 100644 index 00000000000..01632d22194 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-wmgr-v54x-r8jg/GHSA-wmgr-v54x-r8jg.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmgr-v54x-r8jg", + "modified": "2024-08-26T15:31:16Z", + "published": "2024-08-26T15:31:16Z", + "aliases": [ + "CVE-2024-8169" + ], + "details": "A vulnerability was found in code-projects Online Quiz Site 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file signupuser.php. The manipulation of the argument lid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8169" + }, + { + "type": "WEB", + "url": "https://github.com/t4rrega/cve/issues/5" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.275768" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.275768" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.397718" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-x38q-hvmx-rwhg/GHSA-x38q-hvmx-rwhg.json b/advisories/unreviewed/2024/08/GHSA-x38q-hvmx-rwhg/GHSA-x38q-hvmx-rwhg.json index 09fd75aa2dd..c2781cdcd27 100644 --- a/advisories/unreviewed/2024/08/GHSA-x38q-hvmx-rwhg/GHSA-x38q-hvmx-rwhg.json +++ b/advisories/unreviewed/2024/08/GHSA-x38q-hvmx-rwhg/GHSA-x38q-hvmx-rwhg.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-358" + "CWE-358", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false,