Publish Advisories

GHSA-356g-7x36-7m34
GHSA-p5cg-6rfr-6mx8
GHSA-r82w-3phg-qvr4
GHSA-x29x-qwvx-fxr2
GHSA-44qp-5pm8-6j8p
GHSA-7whj-w45h-ccjg
GHSA-8g25-xmmm-86qm
GHSA-9f8f-453p-rg87
GHSA-jhc8-v2x5-jvj5
GHSA-m848-8f5r-6j4g
GHSA-r5mh-qgc2-26p2
GHSA-rpvg-h6p6-42qj
GHSA-vfgq-wwf7-2j79
This commit is contained in:
advisory-database[bot]
2024-06-27 03:32:23 +00:00
parent 0a17e8fb22
commit 4d51af89df
13 changed files with 184 additions and 13 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-356g-7x36-7m34",
"modified": "2024-06-18T22:45:39Z",
"modified": "2024-06-27T03:30:55Z",
"published": "2024-06-18T21:30:36Z",
"aliases": [
"CVE-2024-38276"
@@ -165,6 +165,14 @@
"type": "WEB",
"url": "https://github.com/moodle/moodle/commit/093aedf79889114d004495f05969168b646b0285"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F7AZYR7EXV6E5SQE2GYTNQE3NOENJCQ6"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GHTIX55J4Q4LEOMLNEA4OZSWVEENQX7E"
},
{
"type": "WEB",
"url": "https://moodle.org/mod/forum/discuss.php?d=459501"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p5cg-6rfr-6mx8",
"modified": "2024-06-18T22:45:19Z",
"modified": "2024-06-27T03:30:55Z",
"published": "2024-06-18T21:30:36Z",
"aliases": [
"CVE-2024-38274"
@@ -105,6 +105,14 @@
"type": "PACKAGE",
"url": "https://github.com/moodle/moodle"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F7AZYR7EXV6E5SQE2GYTNQE3NOENJCQ6"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GHTIX55J4Q4LEOMLNEA4OZSWVEENQX7E"
},
{
"type": "WEB",
"url": "https://moodle.org/mod/forum/discuss.php?d=459499"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r82w-3phg-qvr4",
"modified": "2024-06-18T22:45:45Z",
"modified": "2024-06-27T03:30:55Z",
"published": "2024-06-18T21:30:36Z",
"aliases": [
"CVE-2024-38277"
@@ -121,6 +121,14 @@
"type": "PACKAGE",
"url": "https://github.com/moodle/moodle"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F7AZYR7EXV6E5SQE2GYTNQE3NOENJCQ6"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GHTIX55J4Q4LEOMLNEA4OZSWVEENQX7E"
},
{
"type": "WEB",
"url": "https://moodle.org/mod/forum/discuss.php?d=459502"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x29x-qwvx-fxr2",
"modified": "2024-06-18T22:02:50Z",
"modified": "2024-06-27T03:30:55Z",
"published": "2024-06-18T21:30:36Z",
"aliases": [
"CVE-2024-38273"
@@ -117,6 +117,14 @@
"type": "PACKAGE",
"url": "https://github.com/moodle/moodle"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F7AZYR7EXV6E5SQE2GYTNQE3NOENJCQ6"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GHTIX55J4Q4LEOMLNEA4OZSWVEENQX7E"
},
{
"type": "WEB",
"url": "https://moodle.org/mod/forum/discuss.php?d=459498"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-44qp-5pm8-6j8p",
"modified": "2022-05-24T17:19:37Z",
"modified": "2024-06-27T03:30:55Z",
"published": "2022-05-24T17:19:37Z",
"aliases": [
"CVE-2020-13965"
],
"details": "An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -38,6 +41,14 @@
"type": "WEB",
"url": "https://github.com/roundcube/roundcubemail/releases/tag/1.4.5"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DLESQ4LPJGMSWHQ4TBRTVQRDG7IXAZCW"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ODPJXBHZ32QSP4MYT2OBCALYXSUJ47SK"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DLESQ4LPJGMSWHQ4TBRTVQRDG7IXAZCW"
@@ -57,7 +68,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7whj-w45h-ccjg",
"modified": "2024-06-27T03:30:56Z",
"published": "2024-06-27T03:30:56Z",
"aliases": [
"CVE-2024-6054"
],
"details": "The Auto Featured Image plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'create_post_attachment_from_url' function in all versions up to, and including, 1.2. This makes it possible for authenticated attackers, with contributor-level and above permissions, to upload arbitrary files on the affected site's server which may make remote code execution possible.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6054"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/auto-featured-image/tags/1.2/auto-featured-image.php#L167"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4d1512c2-75c1-405b-8bb4-f42ec69159a7?source=cve"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-27T03:15:50Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8g25-xmmm-86qm",
"modified": "2024-06-12T09:30:48Z",
"modified": "2024-06-27T03:30:55Z",
"published": "2024-06-12T09:30:48Z",
"aliases": [
"CVE-2024-3183"
@@ -65,6 +65,10 @@
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2270685"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WT3JL7JQDIAFKKEFARWYES7GZNWGQNCI"
},
{
"type": "WEB",
"url": "https://www.freeipa.org/release-notes/4-12-1.html"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9f8f-453p-rg87",
"modified": "2024-06-25T00:34:46Z",
"modified": "2024-06-27T03:30:56Z",
"published": "2024-06-25T00:34:46Z",
"aliases": [
"CVE-2024-6293"
@@ -25,6 +25,14 @@
{
"type": "WEB",
"url": "https://issues.chromium.org/issues/345993680"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T6OJ65HWXYSYMH55VDO6N36EOZFUNL4O"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WHV5WTU27YOIBIM2CON42SHWY6J2HPRS"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jhc8-v2x5-jvj5",
"modified": "2024-06-12T09:30:47Z",
"modified": "2024-06-27T03:30:55Z",
"published": "2024-06-12T09:30:47Z",
"aliases": [
"CVE-2024-2698"
@@ -45,6 +45,10 @@
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2270353"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WT3JL7JQDIAFKKEFARWYES7GZNWGQNCI"
},
{
"type": "WEB",
"url": "https://www.freeipa.org/release-notes/4-12-1.html"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m848-8f5r-6j4g",
"modified": "2024-06-25T00:34:46Z",
"modified": "2024-06-27T03:30:56Z",
"published": "2024-06-25T00:34:46Z",
"aliases": [
"CVE-2024-6292"
@@ -25,6 +25,14 @@
{
"type": "WEB",
"url": "https://issues.chromium.org/issues/342545100"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T6OJ65HWXYSYMH55VDO6N36EOZFUNL4O"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WHV5WTU27YOIBIM2CON42SHWY6J2HPRS"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r5mh-qgc2-26p2",
"modified": "2024-06-25T00:34:46Z",
"modified": "2024-06-27T03:30:56Z",
"published": "2024-06-25T00:34:46Z",
"aliases": [
"CVE-2024-6290"
@@ -25,6 +25,14 @@
{
"type": "WEB",
"url": "https://issues.chromium.org/issues/342428008"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T6OJ65HWXYSYMH55VDO6N36EOZFUNL4O"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WHV5WTU27YOIBIM2CON42SHWY6J2HPRS"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rpvg-h6p6-42qj",
"modified": "2024-06-25T00:34:46Z",
"modified": "2024-06-27T03:30:56Z",
"published": "2024-06-25T00:34:46Z",
"aliases": [
"CVE-2024-6291"
@@ -25,6 +25,14 @@
{
"type": "WEB",
"url": "https://issues.chromium.org/issues/40942995"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T6OJ65HWXYSYMH55VDO6N36EOZFUNL4O"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WHV5WTU27YOIBIM2CON42SHWY6J2HPRS"
}
],
"database_specific": {
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vfgq-wwf7-2j79",
"modified": "2024-06-27T03:30:56Z",
"published": "2024-06-27T03:30:56Z",
"aliases": [
"CVE-2024-5289"
],
"details": "The Gutenberg Blocks with AI by Kadence WP Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps widget parameters in all versions up to, and including, 3.2.42 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5289"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.2.38/includes/blocks/class-kadence-blocks-googlemaps-block.php#L226"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.2.42/includes/blocks/class-kadence-blocks-googlemaps-block.php#L237"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f9c0ad1e-380e-4b67-b07e-70bf44e4e614?source=cve"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-27T03:15:50Z"
}
}