From 52b4f94c032589267fbf8678ba76aa56a8500150 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 11 Sep 2024 21:31:56 +0000 Subject: [PATCH] Publish Advisories GHSA-23p3-vcf6-94xq GHSA-3qmg-867g-8xrq GHSA-55jf-4cm3-v6wp GHSA-644w-28vg-vrrc GHSA-7pc9-4xmj-8wv3 GHSA-94rj-cjmj-fm26 GHSA-fj49-xvp9-p96q GHSA-gprh-65m4-pxq9 GHSA-hhqg-994q-93m3 GHSA-m6mv-6jvc-p4xv GHSA-wp84-35m6-8r5h GHSA-4429-9xv8-3xpm GHSA-6v8j-8q3j-35hh GHSA-94f8-mx94-9x98 GHSA-95vm-ph4x-xhv5 GHSA-cvgf-c753-74qx GHSA-hc3c-58pm-8f84 GHSA-jfgw-v3p5-42qh GHSA-mx92-jwq3-h28x GHSA-p9p3-pvmx-pxrh GHSA-qhw2-6888-mxmv GHSA-qrjx-rm44-85vw GHSA-vj8g-fr32-2wcg --- .../GHSA-23p3-vcf6-94xq.json | 2 +- .../GHSA-3qmg-867g-8xrq.json | 4 +- .../GHSA-55jf-4cm3-v6wp.json | 4 +- .../GHSA-644w-28vg-vrrc.json | 2 +- .../GHSA-7pc9-4xmj-8wv3.json | 2 +- .../GHSA-94rj-cjmj-fm26.json | 2 +- .../GHSA-fj49-xvp9-p96q.json | 1 + .../GHSA-gprh-65m4-pxq9.json | 2 +- .../GHSA-hhqg-994q-93m3.json | 4 +- .../GHSA-m6mv-6jvc-p4xv.json | 2 +- .../GHSA-wp84-35m6-8r5h.json | 4 +- .../GHSA-4429-9xv8-3xpm.json | 9 ++- .../GHSA-6v8j-8q3j-35hh.json | 39 +++++++++++++ .../GHSA-94f8-mx94-9x98.json | 11 ++-- .../GHSA-95vm-ph4x-xhv5.json | 54 +++++++++++++++++ .../GHSA-cvgf-c753-74qx.json | 39 +++++++++++++ .../GHSA-hc3c-58pm-8f84.json | 11 ++-- .../GHSA-jfgw-v3p5-42qh.json | 6 +- .../GHSA-mx92-jwq3-h28x.json | 58 +++++++++++++++++++ .../GHSA-p9p3-pvmx-pxrh.json | 11 ++-- .../GHSA-qhw2-6888-mxmv.json | 11 ++-- .../GHSA-qrjx-rm44-85vw.json | 54 +++++++++++++++++ .../GHSA-vj8g-fr32-2wcg.json | 11 ++-- 23 files changed, 305 insertions(+), 38 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-6v8j-8q3j-35hh/GHSA-6v8j-8q3j-35hh.json create mode 100644 advisories/unreviewed/2024/09/GHSA-95vm-ph4x-xhv5/GHSA-95vm-ph4x-xhv5.json create mode 100644 advisories/unreviewed/2024/09/GHSA-cvgf-c753-74qx/GHSA-cvgf-c753-74qx.json create mode 100644 advisories/unreviewed/2024/09/GHSA-mx92-jwq3-h28x/GHSA-mx92-jwq3-h28x.json create mode 100644 advisories/unreviewed/2024/09/GHSA-qrjx-rm44-85vw/GHSA-qrjx-rm44-85vw.json diff --git a/advisories/unreviewed/2023/10/GHSA-23p3-vcf6-94xq/GHSA-23p3-vcf6-94xq.json b/advisories/unreviewed/2023/10/GHSA-23p3-vcf6-94xq/GHSA-23p3-vcf6-94xq.json index 73fdff5befe..1097ae781b0 100644 --- a/advisories/unreviewed/2023/10/GHSA-23p3-vcf6-94xq/GHSA-23p3-vcf6-94xq.json +++ b/advisories/unreviewed/2023/10/GHSA-23p3-vcf6-94xq/GHSA-23p3-vcf6-94xq.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-3qmg-867g-8xrq/GHSA-3qmg-867g-8xrq.json b/advisories/unreviewed/2023/10/GHSA-3qmg-867g-8xrq/GHSA-3qmg-867g-8xrq.json index df8a3e91e55..bd72a17115a 100644 --- a/advisories/unreviewed/2023/10/GHSA-3qmg-867g-8xrq/GHSA-3qmg-867g-8xrq.json +++ b/advisories/unreviewed/2023/10/GHSA-3qmg-867g-8xrq/GHSA-3qmg-867g-8xrq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3qmg-867g-8xrq", - "modified": "2023-11-02T21:30:19Z", + "modified": "2024-09-11T21:30:36Z", "published": "2023-10-25T18:32:26Z", "aliases": [ "CVE-2023-5728" @@ -56,7 +56,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-55jf-4cm3-v6wp/GHSA-55jf-4cm3-v6wp.json b/advisories/unreviewed/2023/10/GHSA-55jf-4cm3-v6wp/GHSA-55jf-4cm3-v6wp.json index e62cc6e0bb1..884203e369b 100644 --- a/advisories/unreviewed/2023/10/GHSA-55jf-4cm3-v6wp/GHSA-55jf-4cm3-v6wp.json +++ b/advisories/unreviewed/2023/10/GHSA-55jf-4cm3-v6wp/GHSA-55jf-4cm3-v6wp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-55jf-4cm3-v6wp", - "modified": "2023-11-01T18:30:30Z", + "modified": "2024-09-11T21:30:35Z", "published": "2023-10-25T18:32:23Z", "aliases": [ "CVE-2023-43509" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-644w-28vg-vrrc/GHSA-644w-28vg-vrrc.json b/advisories/unreviewed/2023/10/GHSA-644w-28vg-vrrc/GHSA-644w-28vg-vrrc.json index 7a4b76c5416..e524287e267 100644 --- a/advisories/unreviewed/2023/10/GHSA-644w-28vg-vrrc/GHSA-644w-28vg-vrrc.json +++ b/advisories/unreviewed/2023/10/GHSA-644w-28vg-vrrc/GHSA-644w-28vg-vrrc.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-7pc9-4xmj-8wv3/GHSA-7pc9-4xmj-8wv3.json b/advisories/unreviewed/2023/10/GHSA-7pc9-4xmj-8wv3/GHSA-7pc9-4xmj-8wv3.json index 36c71d44742..a64a86cb8ec 100644 --- a/advisories/unreviewed/2023/10/GHSA-7pc9-4xmj-8wv3/GHSA-7pc9-4xmj-8wv3.json +++ b/advisories/unreviewed/2023/10/GHSA-7pc9-4xmj-8wv3/GHSA-7pc9-4xmj-8wv3.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-94rj-cjmj-fm26/GHSA-94rj-cjmj-fm26.json b/advisories/unreviewed/2023/10/GHSA-94rj-cjmj-fm26/GHSA-94rj-cjmj-fm26.json index 4155e62937e..f07baf72813 100644 --- a/advisories/unreviewed/2023/10/GHSA-94rj-cjmj-fm26/GHSA-94rj-cjmj-fm26.json +++ b/advisories/unreviewed/2023/10/GHSA-94rj-cjmj-fm26/GHSA-94rj-cjmj-fm26.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-fj49-xvp9-p96q/GHSA-fj49-xvp9-p96q.json b/advisories/unreviewed/2023/10/GHSA-fj49-xvp9-p96q/GHSA-fj49-xvp9-p96q.json index 278fef04153..1d3fd5aca03 100644 --- a/advisories/unreviewed/2023/10/GHSA-fj49-xvp9-p96q/GHSA-fj49-xvp9-p96q.json +++ b/advisories/unreviewed/2023/10/GHSA-fj49-xvp9-p96q/GHSA-fj49-xvp9-p96q.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-78", "CWE-798" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/10/GHSA-gprh-65m4-pxq9/GHSA-gprh-65m4-pxq9.json b/advisories/unreviewed/2023/10/GHSA-gprh-65m4-pxq9/GHSA-gprh-65m4-pxq9.json index 5aff617794e..e8c39ba45cf 100644 --- a/advisories/unreviewed/2023/10/GHSA-gprh-65m4-pxq9/GHSA-gprh-65m4-pxq9.json +++ b/advisories/unreviewed/2023/10/GHSA-gprh-65m4-pxq9/GHSA-gprh-65m4-pxq9.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-hhqg-994q-93m3/GHSA-hhqg-994q-93m3.json b/advisories/unreviewed/2023/10/GHSA-hhqg-994q-93m3/GHSA-hhqg-994q-93m3.json index 692767ad0d8..1f6b6473822 100644 --- a/advisories/unreviewed/2023/10/GHSA-hhqg-994q-93m3/GHSA-hhqg-994q-93m3.json +++ b/advisories/unreviewed/2023/10/GHSA-hhqg-994q-93m3/GHSA-hhqg-994q-93m3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hhqg-994q-93m3", - "modified": "2023-11-02T21:30:19Z", + "modified": "2024-09-11T21:30:36Z", "published": "2023-10-25T18:32:26Z", "aliases": [ "CVE-2023-5724" @@ -56,7 +56,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-m6mv-6jvc-p4xv/GHSA-m6mv-6jvc-p4xv.json b/advisories/unreviewed/2023/10/GHSA-m6mv-6jvc-p4xv/GHSA-m6mv-6jvc-p4xv.json index e61b8b64942..da1d865cdb0 100644 --- a/advisories/unreviewed/2023/10/GHSA-m6mv-6jvc-p4xv/GHSA-m6mv-6jvc-p4xv.json +++ b/advisories/unreviewed/2023/10/GHSA-m6mv-6jvc-p4xv/GHSA-m6mv-6jvc-p4xv.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-wp84-35m6-8r5h/GHSA-wp84-35m6-8r5h.json b/advisories/unreviewed/2023/10/GHSA-wp84-35m6-8r5h/GHSA-wp84-35m6-8r5h.json index 73938241eec..234b3a1cbda 100644 --- a/advisories/unreviewed/2023/10/GHSA-wp84-35m6-8r5h/GHSA-wp84-35m6-8r5h.json +++ b/advisories/unreviewed/2023/10/GHSA-wp84-35m6-8r5h/GHSA-wp84-35m6-8r5h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wp84-35m6-8r5h", - "modified": "2023-11-01T18:30:30Z", + "modified": "2024-09-11T21:30:35Z", "published": "2023-10-25T18:32:22Z", "aliases": [ "CVE-2023-43506" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-4429-9xv8-3xpm/GHSA-4429-9xv8-3xpm.json b/advisories/unreviewed/2024/08/GHSA-4429-9xv8-3xpm/GHSA-4429-9xv8-3xpm.json index be5876c1f18..89e09b580b3 100644 --- a/advisories/unreviewed/2024/08/GHSA-4429-9xv8-3xpm/GHSA-4429-9xv8-3xpm.json +++ b/advisories/unreviewed/2024/08/GHSA-4429-9xv8-3xpm/GHSA-4429-9xv8-3xpm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4429-9xv8-3xpm", - "modified": "2024-08-06T06:30:36Z", + "modified": "2024-09-11T21:30:36Z", "published": "2024-08-06T06:30:36Z", "aliases": [ "CVE-2024-39817" ], "details": "Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user who can login to the product to view data that the user does not have access by conducting 'search' under certain conditions in Custom App.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T05:15:41Z" diff --git a/advisories/unreviewed/2024/09/GHSA-6v8j-8q3j-35hh/GHSA-6v8j-8q3j-35hh.json b/advisories/unreviewed/2024/09/GHSA-6v8j-8q3j-35hh/GHSA-6v8j-8q3j-35hh.json new file mode 100644 index 00000000000..c62e79cb884 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6v8j-8q3j-35hh/GHSA-6v8j-8q3j-35hh.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v8j-8q3j-35hh", + "modified": "2024-09-11T21:30:36Z", + "published": "2024-09-11T21:30:36Z", + "aliases": [ + "CVE-2024-44541" + ], + "details": "evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the \"username\" parameter in \"/?action=processlogin.\"", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44541" + }, + { + "type": "WEB", + "url": "https://github.com/evilnapsis/inventio-lite" + }, + { + "type": "WEB", + "url": "https://github.com/pointedsec/CVE-2024-44541" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-11T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-94f8-mx94-9x98/GHSA-94f8-mx94-9x98.json b/advisories/unreviewed/2024/09/GHSA-94f8-mx94-9x98/GHSA-94f8-mx94-9x98.json index 9574b0b18db..d8264c182c5 100644 --- a/advisories/unreviewed/2024/09/GHSA-94f8-mx94-9x98/GHSA-94f8-mx94-9x98.json +++ b/advisories/unreviewed/2024/09/GHSA-94f8-mx94-9x98/GHSA-94f8-mx94-9x98.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-94f8-mx94-9x98", - "modified": "2024-09-11T18:31:07Z", + "modified": "2024-09-11T21:30:36Z", "published": "2024-09-11T18:31:07Z", "aliases": [ "CVE-2024-5760" ], "details": "The Samsung Universal Print Driver for Windows is potentially vulnerable to escalation of privilege allowing the creation of a reverse shell in the tool. This is only applicable for products in the application released or manufactured before 2018.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T16:15:08Z" diff --git a/advisories/unreviewed/2024/09/GHSA-95vm-ph4x-xhv5/GHSA-95vm-ph4x-xhv5.json b/advisories/unreviewed/2024/09/GHSA-95vm-ph4x-xhv5/GHSA-95vm-ph4x-xhv5.json new file mode 100644 index 00000000000..5b248c510fe --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-95vm-ph4x-xhv5/GHSA-95vm-ph4x-xhv5.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95vm-ph4x-xhv5", + "modified": "2024-09-11T21:30:37Z", + "published": "2024-09-11T21:30:37Z", + "aliases": [ + "CVE-2024-8692" + ], + "details": "A vulnerability classified as critical was found in TDuckCloud TDuckPro up to 6.3. Affected by this vulnerability is an unknown functionality. The manipulation leads to weak password recovery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8692" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.277165" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.277165" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.401715" + }, + { + "type": "WEB", + "url": "https://www.shawroot.cc/2794.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-640" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-11T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-cvgf-c753-74qx/GHSA-cvgf-c753-74qx.json b/advisories/unreviewed/2024/09/GHSA-cvgf-c753-74qx/GHSA-cvgf-c753-74qx.json new file mode 100644 index 00000000000..29f0d08da8a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-cvgf-c753-74qx/GHSA-cvgf-c753-74qx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvgf-c753-74qx", + "modified": "2024-09-11T21:30:36Z", + "published": "2024-09-11T21:30:36Z", + "aliases": [ + "CVE-2024-42760" + ], + "details": "SQL Injection vulnerability in Ellevo v.6.2.0.38160 allows a remote attacker to obtain sensitive information via the /api/mob/instrucao/conta/destinatarios component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42760" + }, + { + "type": "WEB", + "url": "https://csflabs.github.io/cve/2024/09/10/cve-2024-42760-sql-injection-in-ellevo-API.html" + }, + { + "type": "WEB", + "url": "https://ellevo.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-11T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-hc3c-58pm-8f84/GHSA-hc3c-58pm-8f84.json b/advisories/unreviewed/2024/09/GHSA-hc3c-58pm-8f84/GHSA-hc3c-58pm-8f84.json index f0a24a4b4a0..d0a455d3240 100644 --- a/advisories/unreviewed/2024/09/GHSA-hc3c-58pm-8f84/GHSA-hc3c-58pm-8f84.json +++ b/advisories/unreviewed/2024/09/GHSA-hc3c-58pm-8f84/GHSA-hc3c-58pm-8f84.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hc3c-58pm-8f84", - "modified": "2024-09-11T18:31:08Z", + "modified": "2024-09-11T21:30:36Z", "published": "2024-09-11T18:31:08Z", "aliases": [ "CVE-2024-44577" ], "details": "RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the time_date function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T17:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-jfgw-v3p5-42qh/GHSA-jfgw-v3p5-42qh.json b/advisories/unreviewed/2024/09/GHSA-jfgw-v3p5-42qh/GHSA-jfgw-v3p5-42qh.json index 1daaf854592..db639ac0253 100644 --- a/advisories/unreviewed/2024/09/GHSA-jfgw-v3p5-42qh/GHSA-jfgw-v3p5-42qh.json +++ b/advisories/unreviewed/2024/09/GHSA-jfgw-v3p5-42qh/GHSA-jfgw-v3p5-42qh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jfgw-v3p5-42qh", - "modified": "2024-09-11T18:31:07Z", + "modified": "2024-09-11T21:30:36Z", "published": "2024-09-11T18:31:07Z", "aliases": [ "CVE-2024-7312" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7312" }, + { + "type": "WEB", + "url": "https://docs.payara.fish/enterprise/docs/5.67.0/Release%20Notes/Release%20Notes%205.67.0.html" + }, { "type": "WEB", "url": "https://docs.payara.fish/enterprise/docs/Release%20Notes/Release%20Notes%205.67.0.html" diff --git a/advisories/unreviewed/2024/09/GHSA-mx92-jwq3-h28x/GHSA-mx92-jwq3-h28x.json b/advisories/unreviewed/2024/09/GHSA-mx92-jwq3-h28x/GHSA-mx92-jwq3-h28x.json new file mode 100644 index 00000000000..10e77926d17 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mx92-jwq3-h28x/GHSA-mx92-jwq3-h28x.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mx92-jwq3-h28x", + "modified": "2024-09-11T21:30:37Z", + "published": "2024-09-11T21:30:37Z", + "aliases": [ + "CVE-2024-8694" + ], + "details": "A vulnerability, which was classified as problematic, was found in JFinalCMS up to 20240903. This affects the function update of the file /admin/template/update of the component com.cms.controller.admin.TemplateController. The manipulation of the argument fileName leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8694" + }, + { + "type": "WEB", + "url": "https://gitee.com/heyewei/JFinalcms/issues/IAOKSQ" + }, + { + "type": "WEB", + "url": "https://github.com/wave-to/SomeCms/blob/main/JFinalCMS.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.277167" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.277167" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.401858" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-11T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-p9p3-pvmx-pxrh/GHSA-p9p3-pvmx-pxrh.json b/advisories/unreviewed/2024/09/GHSA-p9p3-pvmx-pxrh/GHSA-p9p3-pvmx-pxrh.json index b24fc8fb404..c5dca3ff8f9 100644 --- a/advisories/unreviewed/2024/09/GHSA-p9p3-pvmx-pxrh/GHSA-p9p3-pvmx-pxrh.json +++ b/advisories/unreviewed/2024/09/GHSA-p9p3-pvmx-pxrh/GHSA-p9p3-pvmx-pxrh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p9p3-pvmx-pxrh", - "modified": "2024-09-11T18:31:04Z", + "modified": "2024-09-11T21:30:36Z", "published": "2024-09-11T18:31:04Z", "aliases": [ "CVE-2024-44466" ], "details": "COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter iface.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T16:15:06Z" diff --git a/advisories/unreviewed/2024/09/GHSA-qhw2-6888-mxmv/GHSA-qhw2-6888-mxmv.json b/advisories/unreviewed/2024/09/GHSA-qhw2-6888-mxmv/GHSA-qhw2-6888-mxmv.json index 818d310f0de..4c369d73b8a 100644 --- a/advisories/unreviewed/2024/09/GHSA-qhw2-6888-mxmv/GHSA-qhw2-6888-mxmv.json +++ b/advisories/unreviewed/2024/09/GHSA-qhw2-6888-mxmv/GHSA-qhw2-6888-mxmv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qhw2-6888-mxmv", - "modified": "2024-09-11T18:31:08Z", + "modified": "2024-09-11T21:30:36Z", "published": "2024-09-11T18:31:08Z", "aliases": [ "CVE-2024-44574" ], "details": "RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_conf function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T17:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-qrjx-rm44-85vw/GHSA-qrjx-rm44-85vw.json b/advisories/unreviewed/2024/09/GHSA-qrjx-rm44-85vw/GHSA-qrjx-rm44-85vw.json new file mode 100644 index 00000000000..00a4e5d0fb7 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-qrjx-rm44-85vw/GHSA-qrjx-rm44-85vw.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrjx-rm44-85vw", + "modified": "2024-09-11T21:30:37Z", + "published": "2024-09-11T21:30:37Z", + "aliases": [ + "CVE-2024-8693" + ], + "details": "A vulnerability, which was classified as problematic, has been found in Kaon CG3000 1.01.43. Affected by this issue is some unknown functionality of the component dhcpcd Command Handler. The manipulation of the argument -h with the input leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8693" + }, + { + "type": "WEB", + "url": "https://github.com/peritocibernetico/ClaroDHCPXSS" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.277166" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.277166" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.402043" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-11T20:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vj8g-fr32-2wcg/GHSA-vj8g-fr32-2wcg.json b/advisories/unreviewed/2024/09/GHSA-vj8g-fr32-2wcg/GHSA-vj8g-fr32-2wcg.json index 2062535fc2d..b383e9ee7b4 100644 --- a/advisories/unreviewed/2024/09/GHSA-vj8g-fr32-2wcg/GHSA-vj8g-fr32-2wcg.json +++ b/advisories/unreviewed/2024/09/GHSA-vj8g-fr32-2wcg/GHSA-vj8g-fr32-2wcg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vj8g-fr32-2wcg", - "modified": "2024-09-11T18:31:04Z", + "modified": "2024-09-11T21:30:36Z", "published": "2024-09-11T18:31:04Z", "aliases": [ "CVE-2024-44851" ], "details": "A stored cross-site scripting (XSS) vulnerability in the Discussion section of Perfex CRM v1.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Content parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T16:15:06Z"