diff --git a/advisories/unreviewed/2023/12/GHSA-w8hx-5jwc-x79j/GHSA-w8hx-5jwc-x79j.json b/advisories/unreviewed/2023/12/GHSA-w8hx-5jwc-x79j/GHSA-w8hx-5jwc-x79j.json index 8be71a370f8..bd0bd429e88 100644 --- a/advisories/unreviewed/2023/12/GHSA-w8hx-5jwc-x79j/GHSA-w8hx-5jwc-x79j.json +++ b/advisories/unreviewed/2023/12/GHSA-w8hx-5jwc-x79j/GHSA-w8hx-5jwc-x79j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w8hx-5jwc-x79j", - "modified": "2024-01-05T18:30:24Z", + "modified": "2024-07-10T21:30:37Z", "published": "2023-12-26T15:30:19Z", "aliases": [ "CVE-2023-51105" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://github.com/dongyuma/sox-defects/blob/main/mupdf-defects.md" + }, + { + "type": "WEB", + "url": "http://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=cee86dc519d5270a3b96476ad15809ceace64a26" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-428g-3m2x-46jh/GHSA-428g-3m2x-46jh.json b/advisories/unreviewed/2024/07/GHSA-428g-3m2x-46jh/GHSA-428g-3m2x-46jh.json index cbdede94a9f..829547ee4bf 100644 --- a/advisories/unreviewed/2024/07/GHSA-428g-3m2x-46jh/GHSA-428g-3m2x-46jh.json +++ b/advisories/unreviewed/2024/07/GHSA-428g-3m2x-46jh/GHSA-428g-3m2x-46jh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-428g-3m2x-46jh", - "modified": "2024-07-01T18:32:40Z", + "modified": "2024-07-10T21:30:37Z", "published": "2024-07-01T18:32:40Z", "aliases": [ "CVE-2024-20399" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-cmd-injection-xD9OhyOP" + }, + { + "type": "WEB", + "url": "https://www.sygnia.co/threat-reports-and-advisories/china-nexus-threat-group-velvet-ant-exploits-cisco-0-day" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-4h28-fcpw-hmpm/GHSA-4h28-fcpw-hmpm.json b/advisories/unreviewed/2024/07/GHSA-4h28-fcpw-hmpm/GHSA-4h28-fcpw-hmpm.json new file mode 100644 index 00000000000..1f8a9810959 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-4h28-fcpw-hmpm/GHSA-4h28-fcpw-hmpm.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4h28-fcpw-hmpm", + "modified": "2024-07-10T21:30:38Z", + "published": "2024-07-10T21:30:38Z", + "aliases": [ + "CVE-2024-6649" + ], + "details": "A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vulnerability is the function save_users of the file Users.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-271057 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6649" + }, + { + "type": "WEB", + "url": "https://github.com/Xu-Mingming/cve/blob/main/csrf1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.271057" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.271057" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.370663" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T19:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-56xm-5973-mjq5/GHSA-56xm-5973-mjq5.json b/advisories/unreviewed/2024/07/GHSA-56xm-5973-mjq5/GHSA-56xm-5973-mjq5.json new file mode 100644 index 00000000000..2525369a9c0 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-56xm-5973-mjq5/GHSA-56xm-5973-mjq5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-56xm-5973-mjq5", + "modified": "2024-07-10T21:30:39Z", + "published": "2024-07-10T21:30:39Z", + "aliases": [ + "CVE-2024-6148" + ], + "details": "Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6148" + }, + { + "type": "WEB", + "url": "https://support.citrix.com/article/CTX678037" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-79hg-h6r6-64mm/GHSA-79hg-h6r6-64mm.json b/advisories/unreviewed/2024/07/GHSA-79hg-h6r6-64mm/GHSA-79hg-h6r6-64mm.json index 95c23110b73..cc1cffecbc6 100644 --- a/advisories/unreviewed/2024/07/GHSA-79hg-h6r6-64mm/GHSA-79hg-h6r6-64mm.json +++ b/advisories/unreviewed/2024/07/GHSA-79hg-h6r6-64mm/GHSA-79hg-h6r6-64mm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-79hg-h6r6-64mm", - "modified": "2024-07-10T18:32:17Z", + "modified": "2024-07-10T21:30:37Z", "published": "2024-07-08T18:31:18Z", "aliases": [ "CVE-2024-6409" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6409" }, + { + "type": "WEB", + "url": "https://github.com/openela-main/openssh/commit/c00da7741d42029e49047dd89e266d91dcfbffa0" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-6409" diff --git a/advisories/unreviewed/2024/07/GHSA-9x49-p5gq-22q7/GHSA-9x49-p5gq-22q7.json b/advisories/unreviewed/2024/07/GHSA-9x49-p5gq-22q7/GHSA-9x49-p5gq-22q7.json new file mode 100644 index 00000000000..083b2b41d34 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-9x49-p5gq-22q7/GHSA-9x49-p5gq-22q7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9x49-p5gq-22q7", + "modified": "2024-07-10T21:30:38Z", + "published": "2024-07-10T21:30:38Z", + "aliases": [ + "CVE-2024-5913" + ], + "details": "An improper input validation vulnerability in Palo Alto Networks PAN-OS software enables an attacker with the ability to tamper with the physical file system to elevate privileges.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5913" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-5913" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T19:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-c2f9-vwv7-hm5f/GHSA-c2f9-vwv7-hm5f.json b/advisories/unreviewed/2024/07/GHSA-c2f9-vwv7-hm5f/GHSA-c2f9-vwv7-hm5f.json new file mode 100644 index 00000000000..e5859b93a7e --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-c2f9-vwv7-hm5f/GHSA-c2f9-vwv7-hm5f.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2f9-vwv7-hm5f", + "modified": "2024-07-10T21:30:39Z", + "published": "2024-07-10T21:30:39Z", + "aliases": [ + "CVE-2024-6664" + ], + "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6664" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-g3gr-qpxc-qc6c/GHSA-g3gr-qpxc-qc6c.json b/advisories/unreviewed/2024/07/GHSA-g3gr-qpxc-qc6c/GHSA-g3gr-qpxc-qc6c.json new file mode 100644 index 00000000000..7ee67fb5898 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-g3gr-qpxc-qc6c/GHSA-g3gr-qpxc-qc6c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3gr-qpxc-qc6c", + "modified": "2024-07-10T21:30:38Z", + "published": "2024-07-10T21:30:38Z", + "aliases": [ + "CVE-2024-6235" + ], + "details": "Sensitive information disclosure in NetScaler Console", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6235" + }, + { + "type": "WEB", + "url": "https://support.citrix.com/article/CTX677998" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T19:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-hg8f-ghpp-qpmq/GHSA-hg8f-ghpp-qpmq.json b/advisories/unreviewed/2024/07/GHSA-hg8f-ghpp-qpmq/GHSA-hg8f-ghpp-qpmq.json new file mode 100644 index 00000000000..3993b829f0f --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-hg8f-ghpp-qpmq/GHSA-hg8f-ghpp-qpmq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hg8f-ghpp-qpmq", + "modified": "2024-07-10T21:30:38Z", + "published": "2024-07-10T21:30:38Z", + "aliases": [ + "CVE-2024-25077" + ], + "details": "An issue was discovered on Renesas SmartBond DA14691, DA14695, DA14697, and DA14699 devices. The Nonce used for on-the-fly decryption of flash images is stored in an unsigned header, allowing its value to be modified without invalidating the signature used for secureboot image verification. Because the encryption engine for on-the-fly decryption uses AES in CTR mode without authentication, an attacker-modified Nonce can result in execution of arbitrary code.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25077" + }, + { + "type": "WEB", + "url": "https://github.com/atredispartners/advisories/blob/master/ATREDIS-2024-0001.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T20:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-hvhg-7wcv-cqpp/GHSA-hvhg-7wcv-cqpp.json b/advisories/unreviewed/2024/07/GHSA-hvhg-7wcv-cqpp/GHSA-hvhg-7wcv-cqpp.json new file mode 100644 index 00000000000..026bede2404 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-hvhg-7wcv-cqpp/GHSA-hvhg-7wcv-cqpp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvhg-7wcv-cqpp", + "modified": "2024-07-10T21:30:38Z", + "published": "2024-07-10T21:30:38Z", + "aliases": [ + "CVE-2024-25076" + ], + "details": "An issue was discovered on Renesas SmartBond DA14691, DA14695, DA14697, and DA14699 devices. The bootrom function responsible for validating the Flash Product Header directly uses a user-controllable size value (Length of Flash Config Section) to control a read from the QSPI device into a fixed sized buffer, resulting in a buffer overflow and execution of arbitrary code.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25076" + }, + { + "type": "WEB", + "url": "https://github.com/atredispartners/advisories/blob/master/ATREDIS-2024-0001.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T20:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-j94j-pqhq-qr6h/GHSA-j94j-pqhq-qr6h.json b/advisories/unreviewed/2024/07/GHSA-j94j-pqhq-qr6h/GHSA-j94j-pqhq-qr6h.json new file mode 100644 index 00000000000..5d85d09baaf --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-j94j-pqhq-qr6h/GHSA-j94j-pqhq-qr6h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j94j-pqhq-qr6h", + "modified": "2024-07-10T21:30:39Z", + "published": "2024-07-10T21:30:39Z", + "aliases": [ + "CVE-2024-6150" + ], + "details": "A non-admin user can cause short-term disruption in Target VM availability in Citrix Provisioning", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6150" + }, + { + "type": "WEB", + "url": "https://support.citrix.com/article/CTX678025" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-jjrp-3hrg-cj26/GHSA-jjrp-3hrg-cj26.json b/advisories/unreviewed/2024/07/GHSA-jjrp-3hrg-cj26/GHSA-jjrp-3hrg-cj26.json new file mode 100644 index 00000000000..6b8303ca22b --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-jjrp-3hrg-cj26/GHSA-jjrp-3hrg-cj26.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjrp-3hrg-cj26", + "modified": "2024-07-10T21:30:39Z", + "published": "2024-07-10T21:30:39Z", + "aliases": [ + "CVE-2024-6236" + ], + "details": "Denial of Service in NetScaler Console (formerly NetScaler ADM), NetScaler Agent, and NetScaler SDX", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6236" + }, + { + "type": "WEB", + "url": "https://support.citrix.com/article/CTX677998" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-m2fx-wq5j-8657/GHSA-m2fx-wq5j-8657.json b/advisories/unreviewed/2024/07/GHSA-m2fx-wq5j-8657/GHSA-m2fx-wq5j-8657.json new file mode 100644 index 00000000000..7b2685f77de --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-m2fx-wq5j-8657/GHSA-m2fx-wq5j-8657.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m2fx-wq5j-8657", + "modified": "2024-07-10T21:30:39Z", + "published": "2024-07-10T21:30:39Z", + "aliases": [ + "CVE-2024-6149" + ], + "details": "Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6149" + }, + { + "type": "WEB", + "url": "https://support.citrix.com/article/CTX678037" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-m9gc-7c67-49qc/GHSA-m9gc-7c67-49qc.json b/advisories/unreviewed/2024/07/GHSA-m9gc-7c67-49qc/GHSA-m9gc-7c67-49qc.json new file mode 100644 index 00000000000..d7b92406e7b --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-m9gc-7c67-49qc/GHSA-m9gc-7c67-49qc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9gc-7c67-49qc", + "modified": "2024-07-10T21:30:38Z", + "published": "2024-07-10T21:30:38Z", + "aliases": [ + "CVE-2024-5911" + ], + "details": "An arbitrary file upload vulnerability in Palo Alto Networks Panorama software enables an authenticated read-write administrator with access to the web interface to disrupt system processes and crash the Panorama. Repeated attacks eventually cause the Panorama to enter maintenance mode, which requires manual intervention to bring the Panorama back online.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5911" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-5911" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T19:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-mf36-fw8h-4fjx/GHSA-mf36-fw8h-4fjx.json b/advisories/unreviewed/2024/07/GHSA-mf36-fw8h-4fjx/GHSA-mf36-fw8h-4fjx.json new file mode 100644 index 00000000000..b4842e3d21b --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-mf36-fw8h-4fjx/GHSA-mf36-fw8h-4fjx.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mf36-fw8h-4fjx", + "modified": "2024-07-10T21:30:39Z", + "published": "2024-07-10T21:30:39Z", + "aliases": [ + "CVE-2024-6663" + ], + "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6663" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-p959-c7xj-w3cr/GHSA-p959-c7xj-w3cr.json b/advisories/unreviewed/2024/07/GHSA-p959-c7xj-w3cr/GHSA-p959-c7xj-w3cr.json new file mode 100644 index 00000000000..a8358964ebc --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-p959-c7xj-w3cr/GHSA-p959-c7xj-w3cr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p959-c7xj-w3cr", + "modified": "2024-07-10T21:30:38Z", + "published": "2024-07-10T21:30:38Z", + "aliases": [ + "CVE-2024-5491" + ], + "details": "Denial of Service in NetScaler ADC and NetScaler Gateway in NetScaler", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5491" + }, + { + "type": "WEB", + "url": "https://support.citrix.com/article/CTX677944/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20245491-and-cve20245492" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T19:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-px3f-fc5j-2fqv/GHSA-px3f-fc5j-2fqv.json b/advisories/unreviewed/2024/07/GHSA-px3f-fc5j-2fqv/GHSA-px3f-fc5j-2fqv.json new file mode 100644 index 00000000000..f967190033a --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-px3f-fc5j-2fqv/GHSA-px3f-fc5j-2fqv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-px3f-fc5j-2fqv", + "modified": "2024-07-10T21:30:38Z", + "published": "2024-07-10T21:30:38Z", + "aliases": [ + "CVE-2024-5910" + ], + "details": "Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition.\n\nNote: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data imported into Expedition is at risk due to this issue.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:D/RE:M/U:Red" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5910" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-5910" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T19:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-qcjc-4pgc-2w7h/GHSA-qcjc-4pgc-2w7h.json b/advisories/unreviewed/2024/07/GHSA-qcjc-4pgc-2w7h/GHSA-qcjc-4pgc-2w7h.json new file mode 100644 index 00000000000..bb3d626e206 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-qcjc-4pgc-2w7h/GHSA-qcjc-4pgc-2w7h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcjc-4pgc-2w7h", + "modified": "2024-07-10T21:30:39Z", + "published": "2024-07-10T21:30:39Z", + "aliases": [ + "CVE-2024-6151" + ], + "details": "Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Virtual Delivery Agent for Windows used by Citrix Virtual Apps and Desktops and Citrix DaaS", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6151" + }, + { + "type": "WEB", + "url": "https://support.citrix.com/article/CTX678035" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-qgrq-6c5w-399w/GHSA-qgrq-6c5w-399w.json b/advisories/unreviewed/2024/07/GHSA-qgrq-6c5w-399w/GHSA-qgrq-6c5w-399w.json new file mode 100644 index 00000000000..2bc4e0911d2 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-qgrq-6c5w-399w/GHSA-qgrq-6c5w-399w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgrq-6c5w-399w", + "modified": "2024-07-10T21:30:39Z", + "published": "2024-07-10T21:30:39Z", + "aliases": [ + "CVE-2024-6286" + ], + "details": "Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6286" + }, + { + "type": "WEB", + "url": "https://support.citrix.com/article/CTX678036" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-wj5r-m28j-95q9/GHSA-wj5r-m28j-95q9.json b/advisories/unreviewed/2024/07/GHSA-wj5r-m28j-95q9/GHSA-wj5r-m28j-95q9.json new file mode 100644 index 00000000000..531d4d141a0 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-wj5r-m28j-95q9/GHSA-wj5r-m28j-95q9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wj5r-m28j-95q9", + "modified": "2024-07-10T21:30:38Z", + "published": "2024-07-10T21:30:38Z", + "aliases": [ + "CVE-2024-5492" + ], + "details": "Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5492" + }, + { + "type": "WEB", + "url": "https://support.citrix.com/article/CTX677944/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20245491-and-cve20245492" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T19:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-wjvm-2xmx-5vhg/GHSA-wjvm-2xmx-5vhg.json b/advisories/unreviewed/2024/07/GHSA-wjvm-2xmx-5vhg/GHSA-wjvm-2xmx-5vhg.json new file mode 100644 index 00000000000..31f1a987a51 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-wjvm-2xmx-5vhg/GHSA-wjvm-2xmx-5vhg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjvm-2xmx-5vhg", + "modified": "2024-07-10T21:30:38Z", + "published": "2024-07-10T21:30:38Z", + "aliases": [ + "CVE-2024-5912" + ], + "details": "An improper file signature check in Palo Alto Networks Cortex XDR agent may allow an attacker to bypass the Cortex XDR agent's executable blocking capabilities and run untrusted executables on the device. This issue can be leveraged to execute untrusted software without being detected or blocked.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5912" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-5912" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-347" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T19:15:11Z" + } +} \ No newline at end of file