diff --git a/advisories/unreviewed/2024/12/GHSA-545v-485r-7rr8/GHSA-545v-485r-7rr8.json b/advisories/unreviewed/2024/12/GHSA-545v-485r-7rr8/GHSA-545v-485r-7rr8.json new file mode 100644 index 00000000000..4f75f53c8d8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-545v-485r-7rr8/GHSA-545v-485r-7rr8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-545v-485r-7rr8", + "modified": "2024-12-18T00:31:23Z", + "published": "2024-12-18T00:31:23Z", + "aliases": [ + "CVE-2024-29224" + ], + "details": "An OS command injection vulnerability exists in the NAT parameter of GoCast 1.1.3. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29224" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1961" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1961" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-21T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6gq9-2wfh-4rj3/GHSA-6gq9-2wfh-4rj3.json b/advisories/unreviewed/2024/12/GHSA-6gq9-2wfh-4rj3/GHSA-6gq9-2wfh-4rj3.json new file mode 100644 index 00000000000..9c21caab48e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6gq9-2wfh-4rj3/GHSA-6gq9-2wfh-4rj3.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gq9-2wfh-4rj3", + "modified": "2024-12-18T00:31:23Z", + "published": "2024-12-18T00:31:23Z", + "aliases": [ + "CVE-2024-29646" + ], + "details": "Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the name, type, or group fields.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29646" + }, + { + "type": "WEB", + "url": "https://github.com/radareorg/radare2/pull/22562" + }, + { + "type": "WEB", + "url": "https://github.com/radareorg/radare2/pull/22567" + }, + { + "type": "WEB", + "url": "https://github.com/radareorg/radare2/pull/22572" + }, + { + "type": "WEB", + "url": "https://github.com/radareorg/radare2/pull/22578" + }, + { + "type": "WEB", + "url": "https://github.com/radareorg/radare2/pull/22599" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Crispy-fried-chicken/0be4a204e7226fa2cea761c09f027690" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T22:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6mpx-pmgp-ww49/GHSA-6mpx-pmgp-ww49.json b/advisories/unreviewed/2024/12/GHSA-6mpx-pmgp-ww49/GHSA-6mpx-pmgp-ww49.json new file mode 100644 index 00000000000..3c4ca3030b8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6mpx-pmgp-ww49/GHSA-6mpx-pmgp-ww49.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mpx-pmgp-ww49", + "modified": "2024-12-18T00:31:23Z", + "published": "2024-12-18T00:31:23Z", + "aliases": [ + "CVE-2024-10973" + ], + "details": "A vulnerability was found in Keycloak. The environment option `KC_CACHE_EMBEDDED_MTLS_ENABLED` does not work and the JGroups replication configuration is always used in plain text which can allow an attacker that has access to adjacent networks related to JGroups to read sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10973" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-10973" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2324361" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T23:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-93mv-5m6w-c964/GHSA-93mv-5m6w-c964.json b/advisories/unreviewed/2024/12/GHSA-93mv-5m6w-c964/GHSA-93mv-5m6w-c964.json new file mode 100644 index 00000000000..8f9008057a4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-93mv-5m6w-c964/GHSA-93mv-5m6w-c964.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93mv-5m6w-c964", + "modified": "2024-12-18T00:31:23Z", + "published": "2024-12-18T00:31:23Z", + "aliases": [ + "CVE-2024-51175" + ], + "details": "An issue in H3C switch h3c-S1526 allows a remote attacker to obtain sensitive information via the S1526.cfg component.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51175" + }, + { + "type": "WEB", + "url": "https://github.com/a1drewlong/h3c-S1526/blob/main/Vulnerability%20Cases.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T22:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9r59-cc3r-2gm6/GHSA-9r59-cc3r-2gm6.json b/advisories/unreviewed/2024/12/GHSA-9r59-cc3r-2gm6/GHSA-9r59-cc3r-2gm6.json index 2a2604859ce..bb2b299a129 100644 --- a/advisories/unreviewed/2024/12/GHSA-9r59-cc3r-2gm6/GHSA-9r59-cc3r-2gm6.json +++ b/advisories/unreviewed/2024/12/GHSA-9r59-cc3r-2gm6/GHSA-9r59-cc3r-2gm6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9r59-cc3r-2gm6", - "modified": "2024-12-17T21:30:34Z", + "modified": "2024-12-18T00:31:23Z", "published": "2024-12-17T21:30:34Z", "aliases": [ "CVE-2024-55056" ], "details": "A stored cross-site scripting (XSS) vulnerability was identified in Phpgurukul Online Birth Certificate System 1.0 in /user/certificate-form.php via the full name field.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-17T21:15:08Z" diff --git a/advisories/unreviewed/2024/12/GHSA-jhh6-6fhp-q2xp/GHSA-jhh6-6fhp-q2xp.json b/advisories/unreviewed/2024/12/GHSA-jhh6-6fhp-q2xp/GHSA-jhh6-6fhp-q2xp.json new file mode 100644 index 00000000000..cb24dc32700 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jhh6-6fhp-q2xp/GHSA-jhh6-6fhp-q2xp.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhh6-6fhp-q2xp", + "modified": "2024-12-18T00:31:23Z", + "published": "2024-12-18T00:31:23Z", + "aliases": [ + "CVE-2024-9779" + ], + "details": "A flaw was found in Open Cluster Management (OCM) when a user has access to the worker nodes which contain the cluster-manager or klusterlet deployments. The cluster-manager deployment uses a service account with the same name \"cluster-manager\" which is bound to a ClusterRole also named \"cluster-manager\", which includes the permission to create Pod resources. If this deployment runs a pod on an attacker-controlled node, the attacker can obtain the cluster-manager's token and steal any service account token by creating and mounting the target service account to control the whole cluster.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9779" + }, + { + "type": "WEB", + "url": "https://github.com/open-cluster-management-io/registration-operator/issues/361" + }, + { + "type": "WEB", + "url": "https://github.com/open-cluster-management-io/ocm/pull/325" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-9779" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2317916" + }, + { + "type": "WEB", + "url": "https://github.com/open-cluster-management-io/ocm/releases/tag/v0.13.0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-501" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T23:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-px38-239g-x5mg/GHSA-px38-239g-x5mg.json b/advisories/unreviewed/2024/12/GHSA-px38-239g-x5mg/GHSA-px38-239g-x5mg.json new file mode 100644 index 00000000000..c948f796f7c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-px38-239g-x5mg/GHSA-px38-239g-x5mg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-px38-239g-x5mg", + "modified": "2024-12-18T00:31:23Z", + "published": "2024-12-18T00:31:23Z", + "aliases": [ + "CVE-2023-37940" + ], + "details": "Cross-site scripting (XSS) vulnerability in the edit Service Access Policy page in Liferay Portal 7.0.0 through 7.4.3.87, and Liferay DXP 7.4 GA through update 87, 7.3 GA through update 29, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a service access policy's `Service Class` text field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37940" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2023-37940" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T22:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w87m-4q2m-g66w/GHSA-w87m-4q2m-g66w.json b/advisories/unreviewed/2024/12/GHSA-w87m-4q2m-g66w/GHSA-w87m-4q2m-g66w.json new file mode 100644 index 00000000000..5763efc685b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w87m-4q2m-g66w/GHSA-w87m-4q2m-g66w.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w87m-4q2m-g66w", + "modified": "2024-12-18T00:31:23Z", + "published": "2024-12-18T00:31:23Z", + "aliases": [ + "CVE-2024-31668" + ], + "details": "rizin before v0.6.3 is vulnerable to Improper Neutralization of Special Elements via meta_set function in librz/analysis/meta.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31668" + }, + { + "type": "WEB", + "url": "https://github.com/rizinorg/rizin/commit/c025dcee40c8eac2ab559f2caa3798a2dbf019e4" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Crispy-fried-chicken/cb0b3a653a43a2fe2361641eddd8330d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T22:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wv62-mc54-722c/GHSA-wv62-mc54-722c.json b/advisories/unreviewed/2024/12/GHSA-wv62-mc54-722c/GHSA-wv62-mc54-722c.json index 618ba26b6b6..adf11855d5a 100644 --- a/advisories/unreviewed/2024/12/GHSA-wv62-mc54-722c/GHSA-wv62-mc54-722c.json +++ b/advisories/unreviewed/2024/12/GHSA-wv62-mc54-722c/GHSA-wv62-mc54-722c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wv62-mc54-722c", - "modified": "2024-12-17T21:30:34Z", + "modified": "2024-12-18T00:31:23Z", "published": "2024-12-17T21:30:34Z", "aliases": [ "CVE-2024-55057" ], "details": "Phpgurukul Online Birth Certificate System 1.0 suffers from insufficient password requirements which can lead to unauthorized access to user accounts.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-916" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-17T21:15:08Z"