diff --git a/advisories/unreviewed/2023/12/GHSA-v727-f437-6cxx/GHSA-v727-f437-6cxx.json b/advisories/unreviewed/2023/12/GHSA-v727-f437-6cxx/GHSA-v727-f437-6cxx.json index be06e1f5be2..abb09504faa 100644 --- a/advisories/unreviewed/2023/12/GHSA-v727-f437-6cxx/GHSA-v727-f437-6cxx.json +++ b/advisories/unreviewed/2023/12/GHSA-v727-f437-6cxx/GHSA-v727-f437-6cxx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v727-f437-6cxx", - "modified": "2023-12-21T21:30:31Z", + "modified": "2024-02-21T06:30:32Z", "published": "2023-12-21T21:30:31Z", "aliases": [ "CVE-2023-6546" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://github.com/torvalds/linux/commit/3c4f8333b582487a2d1e02171f1465531cde53e3" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0930" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-6546" diff --git a/advisories/unreviewed/2024/02/GHSA-29vg-wcmp-5fp9/GHSA-29vg-wcmp-5fp9.json b/advisories/unreviewed/2024/02/GHSA-29vg-wcmp-5fp9/GHSA-29vg-wcmp-5fp9.json new file mode 100644 index 00000000000..5673ed4a885 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-29vg-wcmp-5fp9/GHSA-29vg-wcmp-5fp9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29vg-wcmp-5fp9", + "modified": "2024-02-21T06:30:32Z", + "published": "2024-02-21T06:30:32Z", + "aliases": [ + "CVE-2024-1674" + ], + "details": "Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1674" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/02/stable-channel-update-for-desktop_20.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/40095183" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T04:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-2j24-h5g8-5q33/GHSA-2j24-h5g8-5q33.json b/advisories/unreviewed/2024/02/GHSA-2j24-h5g8-5q33/GHSA-2j24-h5g8-5q33.json new file mode 100644 index 00000000000..e18da7b1845 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-2j24-h5g8-5q33/GHSA-2j24-h5g8-5q33.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2j24-h5g8-5q33", + "modified": "2024-02-21T06:30:32Z", + "published": "2024-02-21T06:30:32Z", + "aliases": [ + "CVE-2024-1501" + ], + "details": "The Database Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.22. This is due to missing or incorrect nonce validation on the install_wpr() function. This makes it possible for unauthenticated attackers to install the WP Reset Plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1501" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wordpress-database-reset/trunk/class-db-reset-admin.php#L127" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3037742%40wordpress-database-reset&new=3037742%40wordpress-database-reset&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a2e493cf-d022-404d-a501-a6671e6116f4?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T04:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-36mr-3fcp-m422/GHSA-36mr-3fcp-m422.json b/advisories/unreviewed/2024/02/GHSA-36mr-3fcp-m422/GHSA-36mr-3fcp-m422.json new file mode 100644 index 00000000000..2c620d9f77b --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-36mr-3fcp-m422/GHSA-36mr-3fcp-m422.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36mr-3fcp-m422", + "modified": "2024-02-21T06:30:32Z", + "published": "2024-02-21T06:30:32Z", + "aliases": [ + "CVE-2024-22235" + ], + "details": "VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22235" + }, + { + "type": "WEB", + "url": "https://www.vmware.com/security/advisories/VMSA-2024-0004.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T05:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-672f-vpw8-x67x/GHSA-672f-vpw8-x67x.json b/advisories/unreviewed/2024/02/GHSA-672f-vpw8-x67x/GHSA-672f-vpw8-x67x.json new file mode 100644 index 00000000000..7bd27a3f2d9 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-672f-vpw8-x67x/GHSA-672f-vpw8-x67x.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-672f-vpw8-x67x", + "modified": "2024-02-21T06:30:32Z", + "published": "2024-02-21T06:30:32Z", + "aliases": [ + "CVE-2024-1673" + ], + "details": "Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1673" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/02/stable-channel-update-for-desktop_20.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/41490491" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T04:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-78w9-qxr3-hqhc/GHSA-78w9-qxr3-hqhc.json b/advisories/unreviewed/2024/02/GHSA-78w9-qxr3-hqhc/GHSA-78w9-qxr3-hqhc.json new file mode 100644 index 00000000000..b7346e25798 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-78w9-qxr3-hqhc/GHSA-78w9-qxr3-hqhc.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78w9-qxr3-hqhc", + "modified": "2024-02-21T06:30:32Z", + "published": "2024-02-21T06:30:32Z", + "aliases": [ + "CVE-2024-1675" + ], + "details": "Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1675" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/02/stable-channel-update-for-desktop_20.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/41486208" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T04:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-f8gg-fh4p-4795/GHSA-f8gg-fh4p-4795.json b/advisories/unreviewed/2024/02/GHSA-f8gg-fh4p-4795/GHSA-f8gg-fh4p-4795.json new file mode 100644 index 00000000000..de5412ede75 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-f8gg-fh4p-4795/GHSA-f8gg-fh4p-4795.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8gg-fh4p-4795", + "modified": "2024-02-21T06:30:32Z", + "published": "2024-02-21T06:30:32Z", + "aliases": [ + "CVE-2024-1669" + ], + "details": "Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1669" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/02/stable-channel-update-for-desktop_20.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/41495060" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T04:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-frg3-hm7v-3rpf/GHSA-frg3-hm7v-3rpf.json b/advisories/unreviewed/2024/02/GHSA-frg3-hm7v-3rpf/GHSA-frg3-hm7v-3rpf.json new file mode 100644 index 00000000000..b8b50ea4f99 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-frg3-hm7v-3rpf/GHSA-frg3-hm7v-3rpf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frg3-hm7v-3rpf", + "modified": "2024-02-21T06:30:32Z", + "published": "2024-02-21T06:30:32Z", + "aliases": [ + "CVE-2024-1671" + ], + "details": "Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1671" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/02/stable-channel-update-for-desktop_20.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/41487933" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T04:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-hgr6-6hhw-883f/GHSA-hgr6-6hhw-883f.json b/advisories/unreviewed/2024/02/GHSA-hgr6-6hhw-883f/GHSA-hgr6-6hhw-883f.json new file mode 100644 index 00000000000..06a147dd478 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-hgr6-6hhw-883f/GHSA-hgr6-6hhw-883f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgr6-6hhw-883f", + "modified": "2024-02-21T06:30:32Z", + "published": "2024-02-21T06:30:32Z", + "aliases": [ + "CVE-2024-25151" + ], + "details": "The Calendar module in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions does not escape user supplied data in the default notification email template, which allows remote authenticated users to inject arbitrary web script or HTML via the title of a calendar event or the user's name. This may lead to a content spoofing or cross-site scripting (XSS) attacks depending on the capability of the receiver's mail client.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25151" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-25151" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T04:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-q8f8-rhx9-2qm4/GHSA-q8f8-rhx9-2qm4.json b/advisories/unreviewed/2024/02/GHSA-q8f8-rhx9-2qm4/GHSA-q8f8-rhx9-2qm4.json new file mode 100644 index 00000000000..fbf7bd66857 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-q8f8-rhx9-2qm4/GHSA-q8f8-rhx9-2qm4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8f8-rhx9-2qm4", + "modified": "2024-02-21T06:30:32Z", + "published": "2024-02-21T06:30:32Z", + "aliases": [ + "CVE-2024-1672" + ], + "details": "Inappropriate implementation in Content Security Policy in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1672" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/02/stable-channel-update-for-desktop_20.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/41485789" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T04:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-r5qg-76hh-gr9p/GHSA-r5qg-76hh-gr9p.json b/advisories/unreviewed/2024/02/GHSA-r5qg-76hh-gr9p/GHSA-r5qg-76hh-gr9p.json new file mode 100644 index 00000000000..35c4e398f02 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-r5qg-76hh-gr9p/GHSA-r5qg-76hh-gr9p.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5qg-76hh-gr9p", + "modified": "2024-02-21T06:30:32Z", + "published": "2024-02-21T06:30:32Z", + "aliases": [ + "CVE-2024-1676" + ], + "details": "Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1676" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/02/stable-channel-update-for-desktop_20.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/40944847" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T04:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-wjv4-j3hc-gxvv/GHSA-wjv4-j3hc-gxvv.json b/advisories/unreviewed/2024/02/GHSA-wjv4-j3hc-gxvv/GHSA-wjv4-j3hc-gxvv.json new file mode 100644 index 00000000000..006febc6cd0 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-wjv4-j3hc-gxvv/GHSA-wjv4-j3hc-gxvv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjv4-j3hc-gxvv", + "modified": "2024-02-21T06:30:32Z", + "published": "2024-02-21T06:30:32Z", + "aliases": [ + "CVE-2024-1670" + ], + "details": "Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1670" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/02/stable-channel-update-for-desktop_20.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/41481374" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T04:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-wqjf-rx4g-qxmr/GHSA-wqjf-rx4g-qxmr.json b/advisories/unreviewed/2024/02/GHSA-wqjf-rx4g-qxmr/GHSA-wqjf-rx4g-qxmr.json new file mode 100644 index 00000000000..c696e34bfec --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-wqjf-rx4g-qxmr/GHSA-wqjf-rx4g-qxmr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqjf-rx4g-qxmr", + "modified": "2024-02-21T06:30:32Z", + "published": "2024-02-21T06:30:32Z", + "aliases": [ + "CVE-2024-1562" + ], + "details": "The WooCommerce Google Sheet Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the execute_post_data function in all versions up to, and including, 1.3.11. This makes it possible for unauthenticated attackers to update plugin settings.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1562" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3038517%40wc-gsheetconnector&new=3038517%40wc-gsheetconnector&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e36df7b7-fcbc-4e5d-812c-861bfe8abb55?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T04:15:07Z" + } +} \ No newline at end of file