Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-11-22 04:26:23 +00:00
parent 10b01e7032
commit 51fb2f611c
26 changed files with 614 additions and 38 deletions
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q833-5r3h-2vq9",
"modified": "2024-02-15T00:30:32Z",
"modified": "2024-11-22T04:25:00Z",
"published": "2024-02-15T00:30:32Z",
"aliases": [
"CVE-2023-6138"
],
"details": "A potential security vulnerability has been identified in the system BIOS for certain HP Workstation PCs, which might allow escalation of privilege, arbitrary code execution, or denial of service. HP is releasing mitigation for the potential vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-14T23:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4m4w-x26h-2qjx",
"modified": "2024-08-16T00:32:05Z",
"modified": "2024-11-22T04:25:01Z",
"published": "2024-08-16T00:32:05Z",
"aliases": [
"CVE-2024-34742"
],
"details": "In shouldWrite of OwnersData.java, there is a possible edge case that prevents MDM policies from being persisted due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-15T22:15:06Z"
@@ -32,7 +32,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-284"
"CWE-284",
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rvh8-75gg-f2cc",
"modified": "2024-08-12T15:30:49Z",
"modified": "2024-11-22T04:25:01Z",
"published": "2024-08-12T15:30:49Z",
"aliases": [
"CVE-2024-36518"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-26fv-px38-wm73",
"modified": "2024-11-22T04:25:02Z",
"published": "2024-11-22T04:25:02Z",
"aliases": [
"CVE-2024-5029"
],
"details": "The CM Table Of Contents WordPress plugin before 1.2.4 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5029"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/f0f4a33c-9dd2-45ee-82e7-4b8bc2c20094"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-21T11:15:35Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2jp2-4gcw-39mv",
"modified": "2024-11-22T04:25:02Z",
"published": "2024-11-22T04:25:02Z",
"aliases": [
"CVE-2024-52052"
],
"details": "Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom application property and poison a stream target for high-privilege remote code execution.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52052"
},
{
"type": "WEB",
"url": "https://www.rapid7.com/blog/post/2024/11/20/multiple-vulnerabilities-in-wowza-streaming-engine-fixed"
},
{
"type": "WEB",
"url": "https://www.wowza.com/docs/wowza-streaming-engine-4-9-1-release-notes"
}
],
"database_specific": {
"cwe_ids": [
"CWE-646"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-21T23:15:04Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-37v9-jh5m-f5pg",
"modified": "2024-11-14T15:32:16Z",
"modified": "2024-11-22T04:25:02Z",
"published": "2024-11-14T15:32:15Z",
"aliases": [
"CVE-2024-10978"
@@ -21,6 +21,14 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10978"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/11/msg00018.html"
},
{
"type": "WEB",
"url": "https://www.postgresql.org/message-id/173171334532.1547978.1518068370217143844%40wrigleys.postgresql.org"
},
{
"type": "WEB",
"url": "https://www.postgresql.org/support/security/CVE-2024-10978"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3wr4-4m2q-j8pw",
"modified": "2024-11-13T21:30:38Z",
"modified": "2024-11-22T04:25:01Z",
"published": "2024-11-13T21:30:38Z",
"aliases": [
"CVE-2024-45878"
],
"details": "The \"Stammdaten\" menu of baltic-it TOPqw Webportal v1.35.283.2 (fixed in version 1.35.291), in /Apps/TOPqw/qwStammdaten.aspx, is vulnerable to persistent Cross-Site Scripting (XSS).",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-13T21:15:29Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4gvm-v69v-r798",
"modified": "2024-11-18T15:33:20Z",
"modified": "2024-11-22T04:25:02Z",
"published": "2024-11-18T15:33:20Z",
"aliases": [
"CVE-2024-11304"
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://cyberdanube.com/en/en-st-polten-uas-stored-cross-site-scripting-in-seh-utnserver-pro/index.html"
},
{
"type": "WEB",
"url": "http://seclists.org/fulldisclosure/2024/Nov/7"
}
],
"database_specific": {
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4jvj-8r9f-f6pm",
"modified": "2024-11-22T04:25:02Z",
"published": "2024-11-22T04:25:02Z",
"aliases": [
"CVE-2024-10482"
],
"details": "The Media File Rename, Find Unused File, Add Alt text, Caption, Desc For Image SEO WordPress plugin before 1.5.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10482"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/46cbd4bb-b6f3-49e8-8d79-8c378c617e7c"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-21T11:15:16Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4qgx-w4q7-p46p",
"modified": "2024-11-13T21:30:38Z",
"modified": "2024-11-22T04:25:01Z",
"published": "2024-11-13T21:30:38Z",
"aliases": [
"CVE-2024-45875"
],
"details": "The create user function in baltic-it TOPqw Webportal 1.35.287.1 (fixed in version1.35.291), in /Apps/TOPqw/BenutzerManagement.aspx/SaveNewUser, is vulnerable to SQL injection. The JSON object username allows the manipulation of SQL queries.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-13T21:15:28Z"
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6245-p6w7-hf5m",
"modified": "2024-11-22T04:25:03Z",
"published": "2024-11-22T04:25:03Z",
"aliases": [
"CVE-2024-47142"
],
"details": "AIPHONE IXG SYSTEM IXG-2C7 firmware Ver.2.03 and earlier and IXG-2C7-L firmware Ver.2.03 and earlier contain an issue with insufficiently protected credentials, which may allow a network-adjacent authenticated attacker to perform unintended operations.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47142"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/jp/JVN41397971"
},
{
"type": "WEB",
"url": "https://www.aiphone.net/important/20241016_2"
},
{
"type": "WEB",
"url": "https://www.aiphone.net/support/software-documents/ixg"
}
],
"database_specific": {
"cwe_ids": [
"CWE-522"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-22T02:15:21Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6cpp-mpjx-cx8v",
"modified": "2024-11-20T00:32:15Z",
"modified": "2024-11-22T04:25:02Z",
"published": "2024-11-20T00:32:15Z",
"aliases": [
"CVE-2024-44309"
],
"details": "A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, macOS Sequoia 15.1.1, iOS 18.1.1 and iPadOS 18.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to a cross site scripting attack. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
}
],
"affected": [
@@ -41,9 +44,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-20T00:15:17Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-78cp-pmx4-6cr5",
"modified": "2024-11-14T00:31:11Z",
"modified": "2024-11-22T04:25:02Z",
"published": "2024-11-14T00:31:11Z",
"aliases": [
"CVE-2024-50955"
],
"details": "An issue in how XINJE XD5E-24R and XL5E-16T v3.5.3b handles TCP protocol messages allows attackers to cause a Denial of Service (DoS) via a crafted TCP message.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-13T22:15:15Z"
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-84j6-9f5r-c6v4",
"modified": "2024-11-22T04:25:02Z",
"published": "2024-11-22T04:25:02Z",
"aliases": [
"CVE-2024-52056"
],
"details": "Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to delete any directory on the file system if the target directory contains an XML definition file.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52056"
},
{
"type": "WEB",
"url": "https://www.rapid7.com/blog/post/2024/11/20/multiple-vulnerabilities-in-wowza-streaming-engine-fixed"
},
{
"type": "WEB",
"url": "https://www.wowza.com/docs/wowza-streaming-engine-4-9-1-release-notes"
}
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-21T23:15:06Z"
}
}
@@ -0,0 +1,54 @@
{
"schema_version": "1.4.0",
"id": "GHSA-865x-83mq-3qpq",
"modified": "2024-11-22T04:25:02Z",
"published": "2024-11-22T04:25:02Z",
"aliases": [
"CVE-2024-31408"
],
"details": "OS command injection vulnerability exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent authenticated attacker may execute an arbitrary OS command with root privileges by sending a specially crafted request.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31408"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/jp/JVN41397971"
},
{
"type": "WEB",
"url": "https://www.aiphone.net/important/20241016_1"
},
{
"type": "WEB",
"url": "https://www.aiphone.net/important/20241016_2"
},
{
"type": "WEB",
"url": "https://www.aiphone.net/support/software-documents/ix"
},
{
"type": "WEB",
"url": "https://www.aiphone.net/support/software-documents/ixg"
}
],
"database_specific": {
"cwe_ids": [
"CWE-78"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-22T02:15:19Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8rrm-crhv-qpmv",
"modified": "2024-11-13T21:30:38Z",
"modified": "2024-11-22T04:25:02Z",
"published": "2024-11-13T21:30:38Z",
"aliases": [
"CVE-2024-45879"
],
"details": "The file upload function in the \"QWKalkulation\" tool of baltic-it TOPqw Webportal v1.35.287.1 (fixed in version 1.35.291), in /Apps/TOPqw/QWKalkulation/QWKalkulation.aspx, is vulnerable to Cross-Site Scripting (XSS). To exploit the persistent XSS vulnerability, an attacker has to be authenticated to the application that uses the \"TOPqw Webportal\" as a software. When authenticated, the attacker can persistently place the malicious JavaScript code in the \"QWKalkulation\" menu.'",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-13T21:15:29Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cxr4-643w-mfv3",
"modified": "2024-11-15T18:30:50Z",
"modified": "2024-11-22T04:25:02Z",
"published": "2024-11-15T18:30:50Z",
"aliases": [
"CVE-2024-50651"
],
"details": "java_shop 1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-639"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-15T16:15:36Z"
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f2q5-6frm-qr93",
"modified": "2024-11-22T04:25:02Z",
"published": "2024-11-22T04:25:02Z",
"aliases": [
"CVE-2024-52053"
],
"details": "Stored Cross-Site Scripting in the Manager component of Wowza Streaming Engine below 4.9.1 allows an unauthenticated attacker to inject client-side JavaScript into the web dashboard to automatically hijack admin accounts.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52053"
},
{
"type": "WEB",
"url": "https://www.rapid7.com/blog/post/2024/11/20/multiple-vulnerabilities-in-wowza-streaming-engine-fixed"
},
{
"type": "WEB",
"url": "https://www.wowza.com/docs/wowza-streaming-engine-4-9-1-release-notes"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-21T23:15:05Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h32x-x27w-622g",
"modified": "2024-11-22T04:25:03Z",
"published": "2024-11-22T04:25:03Z",
"aliases": [
"CVE-2024-38296"
],
"details": "Dell Edge Gateway 5200 (Coffee Lake S), versions prior to 12.0.94.2380, contains an Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38296"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000250949/dsa-2024-345-security-update-for-dell-networking-edge-gateway-5200-vulnerability"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-22T03:15:04Z"
}
}

Some files were not shown because too many files have changed in this diff Show More