From 4d51af89df8e546d49993381b074ec938cd49987 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 27 Jun 2024 03:32:23 +0000 Subject: [PATCH] Publish Advisories GHSA-356g-7x36-7m34 GHSA-p5cg-6rfr-6mx8 GHSA-r82w-3phg-qvr4 GHSA-x29x-qwvx-fxr2 GHSA-44qp-5pm8-6j8p GHSA-7whj-w45h-ccjg GHSA-8g25-xmmm-86qm GHSA-9f8f-453p-rg87 GHSA-jhc8-v2x5-jvj5 GHSA-m848-8f5r-6j4g GHSA-r5mh-qgc2-26p2 GHSA-rpvg-h6p6-42qj GHSA-vfgq-wwf7-2j79 --- .../GHSA-356g-7x36-7m34.json | 10 +++- .../GHSA-p5cg-6rfr-6mx8.json | 10 +++- .../GHSA-r82w-3phg-qvr4.json | 10 +++- .../GHSA-x29x-qwvx-fxr2.json | 10 +++- .../GHSA-44qp-5pm8-6j8p.json | 17 +++++-- .../GHSA-7whj-w45h-ccjg.json | 42 +++++++++++++++++ .../GHSA-8g25-xmmm-86qm.json | 6 ++- .../GHSA-9f8f-453p-rg87.json | 10 +++- .../GHSA-jhc8-v2x5-jvj5.json | 6 ++- .../GHSA-m848-8f5r-6j4g.json | 10 +++- .../GHSA-r5mh-qgc2-26p2.json | 10 +++- .../GHSA-rpvg-h6p6-42qj.json | 10 +++- .../GHSA-vfgq-wwf7-2j79.json | 46 +++++++++++++++++++ 13 files changed, 184 insertions(+), 13 deletions(-) create mode 100644 advisories/unreviewed/2024/06/GHSA-7whj-w45h-ccjg/GHSA-7whj-w45h-ccjg.json create mode 100644 advisories/unreviewed/2024/06/GHSA-vfgq-wwf7-2j79/GHSA-vfgq-wwf7-2j79.json diff --git a/advisories/github-reviewed/2024/06/GHSA-356g-7x36-7m34/GHSA-356g-7x36-7m34.json b/advisories/github-reviewed/2024/06/GHSA-356g-7x36-7m34/GHSA-356g-7x36-7m34.json index dc914fc7473..04167cad3ed 100644 --- a/advisories/github-reviewed/2024/06/GHSA-356g-7x36-7m34/GHSA-356g-7x36-7m34.json +++ b/advisories/github-reviewed/2024/06/GHSA-356g-7x36-7m34/GHSA-356g-7x36-7m34.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-356g-7x36-7m34", - "modified": "2024-06-18T22:45:39Z", + "modified": "2024-06-27T03:30:55Z", "published": "2024-06-18T21:30:36Z", "aliases": [ "CVE-2024-38276" @@ -165,6 +165,14 @@ "type": "WEB", "url": "https://github.com/moodle/moodle/commit/093aedf79889114d004495f05969168b646b0285" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F7AZYR7EXV6E5SQE2GYTNQE3NOENJCQ6" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GHTIX55J4Q4LEOMLNEA4OZSWVEENQX7E" + }, { "type": "WEB", "url": "https://moodle.org/mod/forum/discuss.php?d=459501" diff --git a/advisories/github-reviewed/2024/06/GHSA-p5cg-6rfr-6mx8/GHSA-p5cg-6rfr-6mx8.json b/advisories/github-reviewed/2024/06/GHSA-p5cg-6rfr-6mx8/GHSA-p5cg-6rfr-6mx8.json index c5ca5b751f7..9ca606b2a77 100644 --- a/advisories/github-reviewed/2024/06/GHSA-p5cg-6rfr-6mx8/GHSA-p5cg-6rfr-6mx8.json +++ b/advisories/github-reviewed/2024/06/GHSA-p5cg-6rfr-6mx8/GHSA-p5cg-6rfr-6mx8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p5cg-6rfr-6mx8", - "modified": "2024-06-18T22:45:19Z", + "modified": "2024-06-27T03:30:55Z", "published": "2024-06-18T21:30:36Z", "aliases": [ "CVE-2024-38274" @@ -105,6 +105,14 @@ "type": "PACKAGE", "url": "https://github.com/moodle/moodle" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F7AZYR7EXV6E5SQE2GYTNQE3NOENJCQ6" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GHTIX55J4Q4LEOMLNEA4OZSWVEENQX7E" + }, { "type": "WEB", "url": "https://moodle.org/mod/forum/discuss.php?d=459499" diff --git a/advisories/github-reviewed/2024/06/GHSA-r82w-3phg-qvr4/GHSA-r82w-3phg-qvr4.json b/advisories/github-reviewed/2024/06/GHSA-r82w-3phg-qvr4/GHSA-r82w-3phg-qvr4.json index 0799bd27607..b6ae7dffb64 100644 --- a/advisories/github-reviewed/2024/06/GHSA-r82w-3phg-qvr4/GHSA-r82w-3phg-qvr4.json +++ b/advisories/github-reviewed/2024/06/GHSA-r82w-3phg-qvr4/GHSA-r82w-3phg-qvr4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r82w-3phg-qvr4", - "modified": "2024-06-18T22:45:45Z", + "modified": "2024-06-27T03:30:55Z", "published": "2024-06-18T21:30:36Z", "aliases": [ "CVE-2024-38277" @@ -121,6 +121,14 @@ "type": "PACKAGE", "url": "https://github.com/moodle/moodle" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F7AZYR7EXV6E5SQE2GYTNQE3NOENJCQ6" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GHTIX55J4Q4LEOMLNEA4OZSWVEENQX7E" + }, { "type": "WEB", "url": "https://moodle.org/mod/forum/discuss.php?d=459502" diff --git a/advisories/github-reviewed/2024/06/GHSA-x29x-qwvx-fxr2/GHSA-x29x-qwvx-fxr2.json b/advisories/github-reviewed/2024/06/GHSA-x29x-qwvx-fxr2/GHSA-x29x-qwvx-fxr2.json index fea15452503..97b54b20889 100644 --- a/advisories/github-reviewed/2024/06/GHSA-x29x-qwvx-fxr2/GHSA-x29x-qwvx-fxr2.json +++ b/advisories/github-reviewed/2024/06/GHSA-x29x-qwvx-fxr2/GHSA-x29x-qwvx-fxr2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x29x-qwvx-fxr2", - "modified": "2024-06-18T22:02:50Z", + "modified": "2024-06-27T03:30:55Z", "published": "2024-06-18T21:30:36Z", "aliases": [ "CVE-2024-38273" @@ -117,6 +117,14 @@ "type": "PACKAGE", "url": "https://github.com/moodle/moodle" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F7AZYR7EXV6E5SQE2GYTNQE3NOENJCQ6" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GHTIX55J4Q4LEOMLNEA4OZSWVEENQX7E" + }, { "type": "WEB", "url": "https://moodle.org/mod/forum/discuss.php?d=459498" diff --git a/advisories/unreviewed/2022/05/GHSA-44qp-5pm8-6j8p/GHSA-44qp-5pm8-6j8p.json b/advisories/unreviewed/2022/05/GHSA-44qp-5pm8-6j8p/GHSA-44qp-5pm8-6j8p.json index 412dcc777f9..2c1343aaf0b 100644 --- a/advisories/unreviewed/2022/05/GHSA-44qp-5pm8-6j8p/GHSA-44qp-5pm8-6j8p.json +++ b/advisories/unreviewed/2022/05/GHSA-44qp-5pm8-6j8p/GHSA-44qp-5pm8-6j8p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-44qp-5pm8-6j8p", - "modified": "2022-05-24T17:19:37Z", + "modified": "2024-06-27T03:30:55Z", "published": "2022-05-24T17:19:37Z", "aliases": [ "CVE-2020-13965" ], "details": "An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -38,6 +41,14 @@ "type": "WEB", "url": "https://github.com/roundcube/roundcubemail/releases/tag/1.4.5" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DLESQ4LPJGMSWHQ4TBRTVQRDG7IXAZCW" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ODPJXBHZ32QSP4MYT2OBCALYXSUJ47SK" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DLESQ4LPJGMSWHQ4TBRTVQRDG7IXAZCW" @@ -57,7 +68,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-7whj-w45h-ccjg/GHSA-7whj-w45h-ccjg.json b/advisories/unreviewed/2024/06/GHSA-7whj-w45h-ccjg/GHSA-7whj-w45h-ccjg.json new file mode 100644 index 00000000000..2a7bcc54a4b --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-7whj-w45h-ccjg/GHSA-7whj-w45h-ccjg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7whj-w45h-ccjg", + "modified": "2024-06-27T03:30:56Z", + "published": "2024-06-27T03:30:56Z", + "aliases": [ + "CVE-2024-6054" + ], + "details": "The Auto Featured Image plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'create_post_attachment_from_url' function in all versions up to, and including, 1.2. This makes it possible for authenticated attackers, with contributor-level and above permissions, to upload arbitrary files on the affected site's server which may make remote code execution possible.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6054" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/auto-featured-image/tags/1.2/auto-featured-image.php#L167" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4d1512c2-75c1-405b-8bb4-f42ec69159a7?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-27T03:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-8g25-xmmm-86qm/GHSA-8g25-xmmm-86qm.json b/advisories/unreviewed/2024/06/GHSA-8g25-xmmm-86qm/GHSA-8g25-xmmm-86qm.json index bd3d812d56a..1fbdd630911 100644 --- a/advisories/unreviewed/2024/06/GHSA-8g25-xmmm-86qm/GHSA-8g25-xmmm-86qm.json +++ b/advisories/unreviewed/2024/06/GHSA-8g25-xmmm-86qm/GHSA-8g25-xmmm-86qm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8g25-xmmm-86qm", - "modified": "2024-06-12T09:30:48Z", + "modified": "2024-06-27T03:30:55Z", "published": "2024-06-12T09:30:48Z", "aliases": [ "CVE-2024-3183" @@ -65,6 +65,10 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2270685" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WT3JL7JQDIAFKKEFARWYES7GZNWGQNCI" + }, { "type": "WEB", "url": "https://www.freeipa.org/release-notes/4-12-1.html" diff --git a/advisories/unreviewed/2024/06/GHSA-9f8f-453p-rg87/GHSA-9f8f-453p-rg87.json b/advisories/unreviewed/2024/06/GHSA-9f8f-453p-rg87/GHSA-9f8f-453p-rg87.json index dcfd3983e21..7e42dac8d38 100644 --- a/advisories/unreviewed/2024/06/GHSA-9f8f-453p-rg87/GHSA-9f8f-453p-rg87.json +++ b/advisories/unreviewed/2024/06/GHSA-9f8f-453p-rg87/GHSA-9f8f-453p-rg87.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9f8f-453p-rg87", - "modified": "2024-06-25T00:34:46Z", + "modified": "2024-06-27T03:30:56Z", "published": "2024-06-25T00:34:46Z", "aliases": [ "CVE-2024-6293" @@ -25,6 +25,14 @@ { "type": "WEB", "url": "https://issues.chromium.org/issues/345993680" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T6OJ65HWXYSYMH55VDO6N36EOZFUNL4O" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WHV5WTU27YOIBIM2CON42SHWY6J2HPRS" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-jhc8-v2x5-jvj5/GHSA-jhc8-v2x5-jvj5.json b/advisories/unreviewed/2024/06/GHSA-jhc8-v2x5-jvj5/GHSA-jhc8-v2x5-jvj5.json index 520b0430902..95ffa7cc694 100644 --- a/advisories/unreviewed/2024/06/GHSA-jhc8-v2x5-jvj5/GHSA-jhc8-v2x5-jvj5.json +++ b/advisories/unreviewed/2024/06/GHSA-jhc8-v2x5-jvj5/GHSA-jhc8-v2x5-jvj5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jhc8-v2x5-jvj5", - "modified": "2024-06-12T09:30:47Z", + "modified": "2024-06-27T03:30:55Z", "published": "2024-06-12T09:30:47Z", "aliases": [ "CVE-2024-2698" @@ -45,6 +45,10 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2270353" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WT3JL7JQDIAFKKEFARWYES7GZNWGQNCI" + }, { "type": "WEB", "url": "https://www.freeipa.org/release-notes/4-12-1.html" diff --git a/advisories/unreviewed/2024/06/GHSA-m848-8f5r-6j4g/GHSA-m848-8f5r-6j4g.json b/advisories/unreviewed/2024/06/GHSA-m848-8f5r-6j4g/GHSA-m848-8f5r-6j4g.json index f6f9021d9e0..e481f9b0095 100644 --- a/advisories/unreviewed/2024/06/GHSA-m848-8f5r-6j4g/GHSA-m848-8f5r-6j4g.json +++ b/advisories/unreviewed/2024/06/GHSA-m848-8f5r-6j4g/GHSA-m848-8f5r-6j4g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m848-8f5r-6j4g", - "modified": "2024-06-25T00:34:46Z", + "modified": "2024-06-27T03:30:56Z", "published": "2024-06-25T00:34:46Z", "aliases": [ "CVE-2024-6292" @@ -25,6 +25,14 @@ { "type": "WEB", "url": "https://issues.chromium.org/issues/342545100" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T6OJ65HWXYSYMH55VDO6N36EOZFUNL4O" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WHV5WTU27YOIBIM2CON42SHWY6J2HPRS" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-r5mh-qgc2-26p2/GHSA-r5mh-qgc2-26p2.json b/advisories/unreviewed/2024/06/GHSA-r5mh-qgc2-26p2/GHSA-r5mh-qgc2-26p2.json index 179b61fccee..9e74be2d91a 100644 --- a/advisories/unreviewed/2024/06/GHSA-r5mh-qgc2-26p2/GHSA-r5mh-qgc2-26p2.json +++ b/advisories/unreviewed/2024/06/GHSA-r5mh-qgc2-26p2/GHSA-r5mh-qgc2-26p2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r5mh-qgc2-26p2", - "modified": "2024-06-25T00:34:46Z", + "modified": "2024-06-27T03:30:56Z", "published": "2024-06-25T00:34:46Z", "aliases": [ "CVE-2024-6290" @@ -25,6 +25,14 @@ { "type": "WEB", "url": "https://issues.chromium.org/issues/342428008" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T6OJ65HWXYSYMH55VDO6N36EOZFUNL4O" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WHV5WTU27YOIBIM2CON42SHWY6J2HPRS" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-rpvg-h6p6-42qj/GHSA-rpvg-h6p6-42qj.json b/advisories/unreviewed/2024/06/GHSA-rpvg-h6p6-42qj/GHSA-rpvg-h6p6-42qj.json index 12ece05eff4..f7ef2abf2e7 100644 --- a/advisories/unreviewed/2024/06/GHSA-rpvg-h6p6-42qj/GHSA-rpvg-h6p6-42qj.json +++ b/advisories/unreviewed/2024/06/GHSA-rpvg-h6p6-42qj/GHSA-rpvg-h6p6-42qj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rpvg-h6p6-42qj", - "modified": "2024-06-25T00:34:46Z", + "modified": "2024-06-27T03:30:56Z", "published": "2024-06-25T00:34:46Z", "aliases": [ "CVE-2024-6291" @@ -25,6 +25,14 @@ { "type": "WEB", "url": "https://issues.chromium.org/issues/40942995" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T6OJ65HWXYSYMH55VDO6N36EOZFUNL4O" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WHV5WTU27YOIBIM2CON42SHWY6J2HPRS" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-vfgq-wwf7-2j79/GHSA-vfgq-wwf7-2j79.json b/advisories/unreviewed/2024/06/GHSA-vfgq-wwf7-2j79/GHSA-vfgq-wwf7-2j79.json new file mode 100644 index 00000000000..92c23a301c3 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-vfgq-wwf7-2j79/GHSA-vfgq-wwf7-2j79.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfgq-wwf7-2j79", + "modified": "2024-06-27T03:30:56Z", + "published": "2024-06-27T03:30:56Z", + "aliases": [ + "CVE-2024-5289" + ], + "details": "The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps widget parameters in all versions up to, and including, 3.2.42 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5289" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.2.38/includes/blocks/class-kadence-blocks-googlemaps-block.php#L226" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.2.42/includes/blocks/class-kadence-blocks-googlemaps-block.php#L237" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f9c0ad1e-380e-4b67-b07e-70bf44e4e614?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-27T03:15:50Z" + } +} \ No newline at end of file