From 4c67bccbf7aba374efa64f1a6806e42f8dc10359 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 6 Sep 2024 00:33:01 +0000 Subject: [PATCH] Publish Advisories GHSA-5fx6-86fq-8xxf GHSA-j2rf-gr77-35c7 GHSA-8vq8-vjqp-8v4r GHSA-c2mc-q4gg-xgm7 GHSA-q8p7-cg4r-8f76 GHSA-cjpg-8x68-w7r7 GHSA-gfjq-fhhf-pp45 GHSA-rrr4-rqcr-8jmq GHSA-v7v5-mxj3-9qmp GHSA-4m5c-7v8f-8p2q GHSA-rpw7-c5cp-v8vp GHSA-vgqv-q7r5-8p24 GHSA-9r7p-fqpx-jpcq GHSA-fhf2-m449-jpqg GHSA-xpqq-5557-v5jm --- .../GHSA-5fx6-86fq-8xxf.json | 3 +- .../GHSA-j2rf-gr77-35c7.json | 3 +- .../GHSA-8vq8-vjqp-8v4r.json | 3 +- .../GHSA-c2mc-q4gg-xgm7.json | 2 +- .../GHSA-q8p7-cg4r-8f76.json | 2 +- .../GHSA-cjpg-8x68-w7r7.json | 2 +- .../GHSA-gfjq-fhhf-pp45.json | 5 ++- .../GHSA-rrr4-rqcr-8jmq.json | 5 ++- .../GHSA-v7v5-mxj3-9qmp.json | 3 +- .../GHSA-4m5c-7v8f-8p2q.json | 3 +- .../GHSA-rpw7-c5cp-v8vp.json | 3 +- .../GHSA-vgqv-q7r5-8p24.json | 3 +- .../GHSA-9r7p-fqpx-jpcq.json | 3 +- .../GHSA-fhf2-m449-jpqg.json | 42 +++++++++++++++++++ .../GHSA-xpqq-5557-v5jm.json | 42 +++++++++++++++++++ 15 files changed, 109 insertions(+), 15 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-fhf2-m449-jpqg/GHSA-fhf2-m449-jpqg.json create mode 100644 advisories/unreviewed/2024/09/GHSA-xpqq-5557-v5jm/GHSA-xpqq-5557-v5jm.json diff --git a/advisories/unreviewed/2023/07/GHSA-5fx6-86fq-8xxf/GHSA-5fx6-86fq-8xxf.json b/advisories/unreviewed/2023/07/GHSA-5fx6-86fq-8xxf/GHSA-5fx6-86fq-8xxf.json index fb2cec5b13c..ab9434472cc 100644 --- a/advisories/unreviewed/2023/07/GHSA-5fx6-86fq-8xxf/GHSA-5fx6-86fq-8xxf.json +++ b/advisories/unreviewed/2023/07/GHSA-5fx6-86fq-8xxf/GHSA-5fx6-86fq-8xxf.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-j2rf-gr77-35c7/GHSA-j2rf-gr77-35c7.json b/advisories/unreviewed/2023/07/GHSA-j2rf-gr77-35c7/GHSA-j2rf-gr77-35c7.json index 987153ef686..94e31d969b9 100644 --- a/advisories/unreviewed/2023/07/GHSA-j2rf-gr77-35c7/GHSA-j2rf-gr77-35c7.json +++ b/advisories/unreviewed/2023/07/GHSA-j2rf-gr77-35c7/GHSA-j2rf-gr77-35c7.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-8vq8-vjqp-8v4r/GHSA-8vq8-vjqp-8v4r.json b/advisories/unreviewed/2023/08/GHSA-8vq8-vjqp-8v4r/GHSA-8vq8-vjqp-8v4r.json index 69bd7076931..193d7762108 100644 --- a/advisories/unreviewed/2023/08/GHSA-8vq8-vjqp-8v4r/GHSA-8vq8-vjqp-8v4r.json +++ b/advisories/unreviewed/2023/08/GHSA-8vq8-vjqp-8v4r/GHSA-8vq8-vjqp-8v4r.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-330" + "CWE-330", + "CWE-331" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-c2mc-q4gg-xgm7/GHSA-c2mc-q4gg-xgm7.json b/advisories/unreviewed/2023/08/GHSA-c2mc-q4gg-xgm7/GHSA-c2mc-q4gg-xgm7.json index 45841c40632..b97ba383830 100644 --- a/advisories/unreviewed/2023/08/GHSA-c2mc-q4gg-xgm7/GHSA-c2mc-q4gg-xgm7.json +++ b/advisories/unreviewed/2023/08/GHSA-c2mc-q4gg-xgm7/GHSA-c2mc-q4gg-xgm7.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-321" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-q8p7-cg4r-8f76/GHSA-q8p7-cg4r-8f76.json b/advisories/unreviewed/2023/08/GHSA-q8p7-cg4r-8f76/GHSA-q8p7-cg4r-8f76.json index dd876dc8b9c..b3834e95a09 100644 --- a/advisories/unreviewed/2023/08/GHSA-q8p7-cg4r-8f76/GHSA-q8p7-cg4r-8f76.json +++ b/advisories/unreviewed/2023/08/GHSA-q8p7-cg4r-8f76/GHSA-q8p7-cg4r-8f76.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-327" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-cjpg-8x68-w7r7/GHSA-cjpg-8x68-w7r7.json b/advisories/unreviewed/2024/01/GHSA-cjpg-8x68-w7r7/GHSA-cjpg-8x68-w7r7.json index 9f77f07f475..d2d79c59f8e 100644 --- a/advisories/unreviewed/2024/01/GHSA-cjpg-8x68-w7r7/GHSA-cjpg-8x68-w7r7.json +++ b/advisories/unreviewed/2024/01/GHSA-cjpg-8x68-w7r7/GHSA-cjpg-8x68-w7r7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cjpg-8x68-w7r7", - "modified": "2024-01-10T21:31:06Z", + "modified": "2024-09-06T00:31:19Z", "published": "2024-01-03T21:30:31Z", "aliases": [ "CVE-2023-5881" diff --git a/advisories/unreviewed/2024/01/GHSA-gfjq-fhhf-pp45/GHSA-gfjq-fhhf-pp45.json b/advisories/unreviewed/2024/01/GHSA-gfjq-fhhf-pp45/GHSA-gfjq-fhhf-pp45.json index 16f67bca29a..3016db15d85 100644 --- a/advisories/unreviewed/2024/01/GHSA-gfjq-fhhf-pp45/GHSA-gfjq-fhhf-pp45.json +++ b/advisories/unreviewed/2024/01/GHSA-gfjq-fhhf-pp45/GHSA-gfjq-fhhf-pp45.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gfjq-fhhf-pp45", - "modified": "2024-01-22T21:31:07Z", + "modified": "2024-09-06T00:31:19Z", "published": "2024-01-22T21:31:07Z", "aliases": [ "CVE-2024-0430" @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-476" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-rrr4-rqcr-8jmq/GHSA-rrr4-rqcr-8jmq.json b/advisories/unreviewed/2024/01/GHSA-rrr4-rqcr-8jmq/GHSA-rrr4-rqcr-8jmq.json index b5c3a63e321..2379aec7cb4 100644 --- a/advisories/unreviewed/2024/01/GHSA-rrr4-rqcr-8jmq/GHSA-rrr4-rqcr-8jmq.json +++ b/advisories/unreviewed/2024/01/GHSA-rrr4-rqcr-8jmq/GHSA-rrr4-rqcr-8jmq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rrr4-rqcr-8jmq", - "modified": "2024-01-29T18:31:53Z", + "modified": "2024-09-06T00:31:19Z", "published": "2024-01-29T18:31:53Z", "aliases": [ "CVE-2024-0788" @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-96" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-v7v5-mxj3-9qmp/GHSA-v7v5-mxj3-9qmp.json b/advisories/unreviewed/2024/01/GHSA-v7v5-mxj3-9qmp/GHSA-v7v5-mxj3-9qmp.json index 4cd6c84aac3..54c9c8df361 100644 --- a/advisories/unreviewed/2024/01/GHSA-v7v5-mxj3-9qmp/GHSA-v7v5-mxj3-9qmp.json +++ b/advisories/unreviewed/2024/01/GHSA-v7v5-mxj3-9qmp/GHSA-v7v5-mxj3-9qmp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v7v5-mxj3-9qmp", - "modified": "2024-01-29T18:31:49Z", + "modified": "2024-09-06T00:31:19Z", "published": "2024-01-29T18:31:49Z", "aliases": [ "CVE-2024-23441" @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-400", "CWE-476" ], diff --git a/advisories/unreviewed/2024/02/GHSA-4m5c-7v8f-8p2q/GHSA-4m5c-7v8f-8p2q.json b/advisories/unreviewed/2024/02/GHSA-4m5c-7v8f-8p2q/GHSA-4m5c-7v8f-8p2q.json index 78a1c062152..ad42af0ab93 100644 --- a/advisories/unreviewed/2024/02/GHSA-4m5c-7v8f-8p2q/GHSA-4m5c-7v8f-8p2q.json +++ b/advisories/unreviewed/2024/02/GHSA-4m5c-7v8f-8p2q/GHSA-4m5c-7v8f-8p2q.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-770" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-rpw7-c5cp-v8vp/GHSA-rpw7-c5cp-v8vp.json b/advisories/unreviewed/2024/02/GHSA-rpw7-c5cp-v8vp/GHSA-rpw7-c5cp-v8vp.json index f7e9bc6aee1..09e46612bf3 100644 --- a/advisories/unreviewed/2024/02/GHSA-rpw7-c5cp-v8vp/GHSA-rpw7-c5cp-v8vp.json +++ b/advisories/unreviewed/2024/02/GHSA-rpw7-c5cp-v8vp/GHSA-rpw7-c5cp-v8vp.json @@ -33,7 +33,8 @@ "database_specific": { "cwe_ids": [ "CWE-20", - "CWE-22" + "CWE-22", + "CWE-73" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-vgqv-q7r5-8p24/GHSA-vgqv-q7r5-8p24.json b/advisories/unreviewed/2024/03/GHSA-vgqv-q7r5-8p24/GHSA-vgqv-q7r5-8p24.json index ed65a9369ab..5d0da8bccf0 100644 --- a/advisories/unreviewed/2024/03/GHSA-vgqv-q7r5-8p24/GHSA-vgqv-q7r5-8p24.json +++ b/advisories/unreviewed/2024/03/GHSA-vgqv-q7r5-8p24/GHSA-vgqv-q7r5-8p24.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-404" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-9r7p-fqpx-jpcq/GHSA-9r7p-fqpx-jpcq.json b/advisories/unreviewed/2024/04/GHSA-9r7p-fqpx-jpcq/GHSA-9r7p-fqpx-jpcq.json index 2d52543ad79..e036911f0e5 100644 --- a/advisories/unreviewed/2024/04/GHSA-9r7p-fqpx-jpcq/GHSA-9r7p-fqpx-jpcq.json +++ b/advisories/unreviewed/2024/04/GHSA-9r7p-fqpx-jpcq/GHSA-9r7p-fqpx-jpcq.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-404" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-fhf2-m449-jpqg/GHSA-fhf2-m449-jpqg.json b/advisories/unreviewed/2024/09/GHSA-fhf2-m449-jpqg/GHSA-fhf2-m449-jpqg.json new file mode 100644 index 00000000000..436fc5c6f7e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-fhf2-m449-jpqg/GHSA-fhf2-m449-jpqg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhf2-m449-jpqg", + "modified": "2024-09-06T00:31:21Z", + "published": "2024-09-06T00:31:21Z", + "aliases": [ + "CVE-2024-39278" + ], + "details": "Credentials to access device configuration information stored unencrypted in flash memory. These credentials would allow read-only access to network configuration information and terminal configuration data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39278" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-249-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T23:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xpqq-5557-v5jm/GHSA-xpqq-5557-v5jm.json b/advisories/unreviewed/2024/09/GHSA-xpqq-5557-v5jm/GHSA-xpqq-5557-v5jm.json new file mode 100644 index 00000000000..b69d5b2c039 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xpqq-5557-v5jm/GHSA-xpqq-5557-v5jm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpqq-5557-v5jm", + "modified": "2024-09-06T00:31:21Z", + "published": "2024-09-06T00:31:21Z", + "aliases": [ + "CVE-2024-42495" + ], + "details": "Credentials to access device configuration were transmitted using an unencrypted protocol. These credentials would allow read-only access to network configuration information and terminal configuration data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42495" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-249-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-311" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T23:15:12Z" + } +} \ No newline at end of file