Publish Advisories

GHSA-23p3-vcf6-94xq
GHSA-3qmg-867g-8xrq
GHSA-55jf-4cm3-v6wp
GHSA-644w-28vg-vrrc
GHSA-7pc9-4xmj-8wv3
GHSA-94rj-cjmj-fm26
GHSA-fj49-xvp9-p96q
GHSA-gprh-65m4-pxq9
GHSA-hhqg-994q-93m3
GHSA-m6mv-6jvc-p4xv
GHSA-wp84-35m6-8r5h
GHSA-4429-9xv8-3xpm
GHSA-6v8j-8q3j-35hh
GHSA-94f8-mx94-9x98
GHSA-95vm-ph4x-xhv5
GHSA-cvgf-c753-74qx
GHSA-hc3c-58pm-8f84
GHSA-jfgw-v3p5-42qh
GHSA-mx92-jwq3-h28x
GHSA-p9p3-pvmx-pxrh
GHSA-qhw2-6888-mxmv
GHSA-qrjx-rm44-85vw
GHSA-vj8g-fr32-2wcg
This commit is contained in:
advisory-database[bot]
2024-09-11 21:31:56 +00:00
parent a078808cdf
commit 52b4f94c03
23 changed files with 305 additions and 38 deletions
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3qmg-867g-8xrq",
"modified": "2023-11-02T21:30:19Z",
"modified": "2024-09-11T21:30:36Z",
"published": "2023-10-25T18:32:26Z",
"aliases": [
"CVE-2023-5728"
@@ -56,7 +56,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-416"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-55jf-4cm3-v6wp",
"modified": "2023-11-01T18:30:30Z",
"modified": "2024-09-11T21:30:35Z",
"published": "2023-10-25T18:32:23Z",
"aliases": [
"CVE-2023-43509"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-269"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-269"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -32,6 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-78",
"CWE-798"
],
"severity": "CRITICAL",
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-269"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hhqg-994q-93m3",
"modified": "2023-11-02T21:30:19Z",
"modified": "2024-09-11T21:30:36Z",
"published": "2023-10-25T18:32:26Z",
"aliases": [
"CVE-2023-5724"
@@ -56,7 +56,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-400"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-269"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wp84-35m6-8r5h",
"modified": "2023-11-01T18:30:30Z",
"modified": "2024-09-11T21:30:35Z",
"published": "2023-10-25T18:32:22Z",
"aliases": [
"CVE-2023-43506"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-269"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4429-9xv8-3xpm",
"modified": "2024-08-06T06:30:36Z",
"modified": "2024-09-11T21:30:36Z",
"published": "2024-08-06T06:30:36Z",
"aliases": [
"CVE-2024-39817"
],
"details": "Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user who can login to the product to view data that the user does not have access by conducting 'search' under certain conditions in Custom App.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-06T05:15:41Z"
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6v8j-8q3j-35hh",
"modified": "2024-09-11T21:30:36Z",
"published": "2024-09-11T21:30:36Z",
"aliases": [
"CVE-2024-44541"
],
"details": "evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the \"username\" parameter in \"/?action=processlogin.\"",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44541"
},
{
"type": "WEB",
"url": "https://github.com/evilnapsis/inventio-lite"
},
{
"type": "WEB",
"url": "https://github.com/pointedsec/CVE-2024-44541"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-11T19:15:15Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-94f8-mx94-9x98",
"modified": "2024-09-11T18:31:07Z",
"modified": "2024-09-11T21:30:36Z",
"published": "2024-09-11T18:31:07Z",
"aliases": [
"CVE-2024-5760"
],
"details": "The Samsung Universal Print Driver for Windows is potentially vulnerable to escalation of privilege allowing the creation of a reverse shell in the tool. This is only applicable for products in the application released or manufactured before 2018.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-269"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-11T16:15:08Z"
@@ -0,0 +1,54 @@
{
"schema_version": "1.4.0",
"id": "GHSA-95vm-ph4x-xhv5",
"modified": "2024-09-11T21:30:37Z",
"published": "2024-09-11T21:30:37Z",
"aliases": [
"CVE-2024-8692"
],
"details": "A vulnerability classified as critical was found in TDuckCloud TDuckPro up to 6.3. Affected by this vulnerability is an unknown functionality. The manipulation leads to weak password recovery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8692"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.277165"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.277165"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.401715"
},
{
"type": "WEB",
"url": "https://www.shawroot.cc/2794.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-640"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-11T19:15:15Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cvgf-c753-74qx",
"modified": "2024-09-11T21:30:36Z",
"published": "2024-09-11T21:30:36Z",
"aliases": [
"CVE-2024-42760"
],
"details": "SQL Injection vulnerability in Ellevo v.6.2.0.38160 allows a remote attacker to obtain sensitive information via the /api/mob/instrucao/conta/destinatarios component.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42760"
},
{
"type": "WEB",
"url": "https://csflabs.github.io/cve/2024/09/10/cve-2024-42760-sql-injection-in-ellevo-API.html"
},
{
"type": "WEB",
"url": "https://ellevo.com"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-11T19:15:14Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hc3c-58pm-8f84",
"modified": "2024-09-11T18:31:08Z",
"modified": "2024-09-11T21:30:36Z",
"published": "2024-09-11T18:31:08Z",
"aliases": [
"CVE-2024-44577"
],
"details": "RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the time_date function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-11T17:15:13Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jfgw-v3p5-42qh",
"modified": "2024-09-11T18:31:07Z",
"modified": "2024-09-11T21:30:36Z",
"published": "2024-09-11T18:31:07Z",
"aliases": [
"CVE-2024-7312"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7312"
},
{
"type": "WEB",
"url": "https://docs.payara.fish/enterprise/docs/5.67.0/Release%20Notes/Release%20Notes%205.67.0.html"
},
{
"type": "WEB",
"url": "https://docs.payara.fish/enterprise/docs/Release%20Notes/Release%20Notes%205.67.0.html"
@@ -0,0 +1,58 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mx92-jwq3-h28x",
"modified": "2024-09-11T21:30:37Z",
"published": "2024-09-11T21:30:37Z",
"aliases": [
"CVE-2024-8694"
],
"details": "A vulnerability, which was classified as problematic, was found in JFinalCMS up to 20240903. This affects the function update of the file /admin/template/update of the component com.cms.controller.admin.TemplateController. The manipulation of the argument fileName leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8694"
},
{
"type": "WEB",
"url": "https://gitee.com/heyewei/JFinalcms/issues/IAOKSQ"
},
{
"type": "WEB",
"url": "https://github.com/wave-to/SomeCms/blob/main/JFinalCMS.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.277167"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.277167"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.401858"
}
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-11T21:15:10Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p9p3-pvmx-pxrh",
"modified": "2024-09-11T18:31:04Z",
"modified": "2024-09-11T21:30:36Z",
"published": "2024-09-11T18:31:04Z",
"aliases": [
"CVE-2024-44466"
],
"details": "COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter iface.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-11T16:15:06Z"

Some files were not shown because too many files have changed in this diff Show More