diff --git a/advisories/github-reviewed/2021/02/GHSA-rhm9-p9w5-fwm7/GHSA-rhm9-p9w5-fwm7.json b/advisories/github-reviewed/2021/02/GHSA-rhm9-p9w5-fwm7/GHSA-rhm9-p9w5-fwm7.json index 0cb5e88c3a2..08ba9156bc0 100644 --- a/advisories/github-reviewed/2021/02/GHSA-rhm9-p9w5-fwm7/GHSA-rhm9-p9w5-fwm7.json +++ b/advisories/github-reviewed/2021/02/GHSA-rhm9-p9w5-fwm7/GHSA-rhm9-p9w5-fwm7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rhm9-p9w5-fwm7", - "modified": "2023-08-30T22:06:59Z", + "modified": "2024-09-13T18:33:13Z", "published": "2021-02-10T01:32:27Z", "aliases": [ "CVE-2020-36242" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N" } ], "affected": [ @@ -20,6 +24,11 @@ "ecosystem": "PyPI", "name": "cryptography" }, + "ecosystem_specific": { + "affected_functions": [ + "cryptography.hazmat.backends.openssl.ciphers._CipherContext" + ] + }, "ranges": [ { "type": "ECOSYSTEM", @@ -52,6 +61,10 @@ "type": "WEB", "url": "https://github.com/pyca/cryptography/commit/82b6ce28389f0a317bc55ba2091a74b346db7cae" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-rhm9-p9w5-fwm7" + }, { "type": "PACKAGE", "url": "https://github.com/pyca/cryptography" @@ -64,6 +77,14 @@ "type": "WEB", "url": "https://github.com/pyca/cryptography/compare/3.3.1...3.3.2" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2021-63.yaml" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L7RGQLK4J5ZQFRLKCHVVG6BKZTUQMG7E" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L7RGQLK4J5ZQFRLKCHVVG6BKZTUQMG7E" @@ -82,7 +103,7 @@ "CWE-190", "CWE-787" ], - "severity": "CRITICAL", + "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2021-02-10T01:31:02Z", "nvd_published_at": "2021-02-07T20:15:00Z" diff --git a/advisories/unreviewed/2022/05/GHSA-g6xf-xq8f-56f4/GHSA-g6xf-xq8f-56f4.json b/advisories/unreviewed/2022/05/GHSA-g6xf-xq8f-56f4/GHSA-g6xf-xq8f-56f4.json index 970cb2092c0..ee496509720 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6xf-xq8f-56f4/GHSA-g6xf-xq8f-56f4.json +++ b/advisories/unreviewed/2022/05/GHSA-g6xf-xq8f-56f4/GHSA-g6xf-xq8f-56f4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g6xf-xq8f-56f4", - "modified": "2024-09-12T18:31:37Z", + "modified": "2024-09-13T18:31:40Z", "published": "2022-05-02T03:26:42Z", "aliases": [ "CVE-2009-1605" ], "details": "Heap-based buffer overflow in the loadexponentialfunc function in mupdf/pdf_function.c in MuPDF in the mupdf-20090223-win32 package, as used in SumatraPDF 0.9.3 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF file. NOTE: some of these details are obtained from third party information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/07/GHSA-2g29-vvh2-xx4w/GHSA-2g29-vvh2-xx4w.json b/advisories/unreviewed/2023/07/GHSA-2g29-vvh2-xx4w/GHSA-2g29-vvh2-xx4w.json index 5d391ec794c..3c228aa01c9 100644 --- a/advisories/unreviewed/2023/07/GHSA-2g29-vvh2-xx4w/GHSA-2g29-vvh2-xx4w.json +++ b/advisories/unreviewed/2023/07/GHSA-2g29-vvh2-xx4w/GHSA-2g29-vvh2-xx4w.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-5q43-wwhh-v8wh/GHSA-5q43-wwhh-v8wh.json b/advisories/unreviewed/2023/07/GHSA-5q43-wwhh-v8wh/GHSA-5q43-wwhh-v8wh.json index 8a7c835d6fd..32a5e77b4a6 100644 --- a/advisories/unreviewed/2023/07/GHSA-5q43-wwhh-v8wh/GHSA-5q43-wwhh-v8wh.json +++ b/advisories/unreviewed/2023/07/GHSA-5q43-wwhh-v8wh/GHSA-5q43-wwhh-v8wh.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-5rj2-m4rq-8fmp/GHSA-5rj2-m4rq-8fmp.json b/advisories/unreviewed/2023/10/GHSA-5rj2-m4rq-8fmp/GHSA-5rj2-m4rq-8fmp.json index 34d4af5fc62..3a6326a52db 100644 --- a/advisories/unreviewed/2023/10/GHSA-5rj2-m4rq-8fmp/GHSA-5rj2-m4rq-8fmp.json +++ b/advisories/unreviewed/2023/10/GHSA-5rj2-m4rq-8fmp/GHSA-5rj2-m4rq-8fmp.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-cj23-4vc3-qpfc/GHSA-cj23-4vc3-qpfc.json b/advisories/unreviewed/2023/10/GHSA-cj23-4vc3-qpfc/GHSA-cj23-4vc3-qpfc.json index 269884ade4e..a4082efe87c 100644 --- a/advisories/unreviewed/2023/10/GHSA-cj23-4vc3-qpfc/GHSA-cj23-4vc3-qpfc.json +++ b/advisories/unreviewed/2023/10/GHSA-cj23-4vc3-qpfc/GHSA-cj23-4vc3-qpfc.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-mrh7-ghhj-6r6w/GHSA-mrh7-ghhj-6r6w.json b/advisories/unreviewed/2023/10/GHSA-mrh7-ghhj-6r6w/GHSA-mrh7-ghhj-6r6w.json index 52e6c1f03ff..7a07553c0bd 100644 --- a/advisories/unreviewed/2023/10/GHSA-mrh7-ghhj-6r6w/GHSA-mrh7-ghhj-6r6w.json +++ b/advisories/unreviewed/2023/10/GHSA-mrh7-ghhj-6r6w/GHSA-mrh7-ghhj-6r6w.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-vjwc-c2cc-76g5/GHSA-vjwc-c2cc-76g5.json b/advisories/unreviewed/2023/10/GHSA-vjwc-c2cc-76g5/GHSA-vjwc-c2cc-76g5.json index af2a1fc978d..7b4aed7f9e0 100644 --- a/advisories/unreviewed/2023/10/GHSA-vjwc-c2cc-76g5/GHSA-vjwc-c2cc-76g5.json +++ b/advisories/unreviewed/2023/10/GHSA-vjwc-c2cc-76g5/GHSA-vjwc-c2cc-76g5.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-wqw5-fg63-857m/GHSA-wqw5-fg63-857m.json b/advisories/unreviewed/2023/10/GHSA-wqw5-fg63-857m/GHSA-wqw5-fg63-857m.json index 103eceefbc4..def3c895949 100644 --- a/advisories/unreviewed/2023/10/GHSA-wqw5-fg63-857m/GHSA-wqw5-fg63-857m.json +++ b/advisories/unreviewed/2023/10/GHSA-wqw5-fg63-857m/GHSA-wqw5-fg63-857m.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-fhx8-5c23-x7x5/GHSA-fhx8-5c23-x7x5.json b/advisories/unreviewed/2024/03/GHSA-fhx8-5c23-x7x5/GHSA-fhx8-5c23-x7x5.json index 5c01f5c8e7b..f4e0cfd7e5b 100644 --- a/advisories/unreviewed/2024/03/GHSA-fhx8-5c23-x7x5/GHSA-fhx8-5c23-x7x5.json +++ b/advisories/unreviewed/2024/03/GHSA-fhx8-5c23-x7x5/GHSA-fhx8-5c23-x7x5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fhx8-5c23-x7x5", - "modified": "2024-08-21T18:31:25Z", + "modified": "2024-09-13T18:31:41Z", "published": "2024-03-01T15:31:37Z", "aliases": [ "CVE-2023-46950" @@ -25,6 +25,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46950" }, + { + "type": "WEB", + "url": "https://github.com/mhenrixon/sidekiq-unique-jobs/pull/829" + }, + { + "type": "WEB", + "url": "https://github.com/mhenrixon/sidekiq-unique-jobs/releases/tag/v8.0.7" + }, { "type": "WEB", "url": "https://link.org" @@ -32,6 +40,10 @@ { "type": "WEB", "url": "https://www.link.com" + }, + { + "type": "WEB", + "url": "https://www.mgm-sp.com/cve/sidekiq-unique-jobs-reflected-xss-cve-2023-46950-cve-2023-46951" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-xfrr-fwx4-vqh9/GHSA-xfrr-fwx4-vqh9.json b/advisories/unreviewed/2024/03/GHSA-xfrr-fwx4-vqh9/GHSA-xfrr-fwx4-vqh9.json index 917980d2376..715137fcaad 100644 --- a/advisories/unreviewed/2024/03/GHSA-xfrr-fwx4-vqh9/GHSA-xfrr-fwx4-vqh9.json +++ b/advisories/unreviewed/2024/03/GHSA-xfrr-fwx4-vqh9/GHSA-xfrr-fwx4-vqh9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xfrr-fwx4-vqh9", - "modified": "2024-08-01T15:31:29Z", + "modified": "2024-09-13T18:31:41Z", "published": "2024-03-01T15:31:37Z", "aliases": [ "CVE-2023-46951" @@ -25,6 +25,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46951" }, + { + "type": "WEB", + "url": "https://github.com/mhenrixon/sidekiq-unique-jobs/pull/829" + }, + { + "type": "WEB", + "url": "https://github.com/mhenrixon/sidekiq-unique-jobs/releases/tag/v8.0.7" + }, { "type": "WEB", "url": "https://link.org" @@ -32,6 +40,10 @@ { "type": "WEB", "url": "https://www.link.com" + }, + { + "type": "WEB", + "url": "https://www.mgm-sp.com/cve/sidekiq-unique-jobs-reflected-xss-cve-2023-46950-cve-2023-46951" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-382m-fgqc-gfhw/GHSA-382m-fgqc-gfhw.json b/advisories/unreviewed/2024/06/GHSA-382m-fgqc-gfhw/GHSA-382m-fgqc-gfhw.json index 5d06fa3751c..bca274c7de6 100644 --- a/advisories/unreviewed/2024/06/GHSA-382m-fgqc-gfhw/GHSA-382m-fgqc-gfhw.json +++ b/advisories/unreviewed/2024/06/GHSA-382m-fgqc-gfhw/GHSA-382m-fgqc-gfhw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-382m-fgqc-gfhw", - "modified": "2024-06-18T00:31:28Z", + "modified": "2024-09-13T18:31:41Z", "published": "2024-06-18T00:31:28Z", "aliases": [ "CVE-2024-6082" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-fg32-7hw7-w82p/GHSA-fg32-7hw7-w82p.json b/advisories/unreviewed/2024/06/GHSA-fg32-7hw7-w82p/GHSA-fg32-7hw7-w82p.json index b3ab2254457..e0c95c58546 100644 --- a/advisories/unreviewed/2024/06/GHSA-fg32-7hw7-w82p/GHSA-fg32-7hw7-w82p.json +++ b/advisories/unreviewed/2024/06/GHSA-fg32-7hw7-w82p/GHSA-fg32-7hw7-w82p.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-798" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-jvrv-28g9-r22f/GHSA-jvrv-28g9-r22f.json b/advisories/unreviewed/2024/06/GHSA-jvrv-28g9-r22f/GHSA-jvrv-28g9-r22f.json index a216e5a1447..4ee5ee04131 100644 --- a/advisories/unreviewed/2024/06/GHSA-jvrv-28g9-r22f/GHSA-jvrv-28g9-r22f.json +++ b/advisories/unreviewed/2024/06/GHSA-jvrv-28g9-r22f/GHSA-jvrv-28g9-r22f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jvrv-28g9-r22f", - "modified": "2024-06-07T21:31:55Z", + "modified": "2024-09-13T18:31:41Z", "published": "2024-06-07T21:31:55Z", "aliases": [ "CVE-2023-49222" ], "details": "Precor touchscreen console P82 contains a private SSH key that corresponds to a default public key. A remote attacker could exploit this to gain root privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-07T20:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-m9vj-66ph-2pqf/GHSA-m9vj-66ph-2pqf.json b/advisories/unreviewed/2024/06/GHSA-m9vj-66ph-2pqf/GHSA-m9vj-66ph-2pqf.json index e51c173ee51..256da903ffa 100644 --- a/advisories/unreviewed/2024/06/GHSA-m9vj-66ph-2pqf/GHSA-m9vj-66ph-2pqf.json +++ b/advisories/unreviewed/2024/06/GHSA-m9vj-66ph-2pqf/GHSA-m9vj-66ph-2pqf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m9vj-66ph-2pqf", - "modified": "2024-06-07T21:31:55Z", + "modified": "2024-09-13T18:31:41Z", "published": "2024-06-07T21:31:55Z", "aliases": [ "CVE-2023-49223" ], "details": "Precor touchscreen console P62, P80, and P82 could allow a remote attacker to obtain sensitive information because the root password is stored in /etc/passwd. An attacker could exploit this to extract files and obtain sensitive information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-07T20:15:10Z" diff --git a/advisories/unreviewed/2024/08/GHSA-2qhq-448h-5333/GHSA-2qhq-448h-5333.json b/advisories/unreviewed/2024/08/GHSA-2qhq-448h-5333/GHSA-2qhq-448h-5333.json index e3fba6869cb..8913d11417f 100644 --- a/advisories/unreviewed/2024/08/GHSA-2qhq-448h-5333/GHSA-2qhq-448h-5333.json +++ b/advisories/unreviewed/2024/08/GHSA-2qhq-448h-5333/GHSA-2qhq-448h-5333.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-307", "CWE-667" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-4r4v-2j2q-ch33/GHSA-4r4v-2j2q-ch33.json b/advisories/unreviewed/2024/08/GHSA-4r4v-2j2q-ch33/GHSA-4r4v-2j2q-ch33.json index 645ca53c3b8..17362e29eaf 100644 --- a/advisories/unreviewed/2024/08/GHSA-4r4v-2j2q-ch33/GHSA-4r4v-2j2q-ch33.json +++ b/advisories/unreviewed/2024/08/GHSA-4r4v-2j2q-ch33/GHSA-4r4v-2j2q-ch33.json @@ -48,7 +48,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-xj8p-vpqc-xj39/GHSA-xj8p-vpqc-xj39.json b/advisories/unreviewed/2024/08/GHSA-xj8p-vpqc-xj39/GHSA-xj8p-vpqc-xj39.json index 00485038b70..ac2df865e47 100644 --- a/advisories/unreviewed/2024/08/GHSA-xj8p-vpqc-xj39/GHSA-xj8p-vpqc-xj39.json +++ b/advisories/unreviewed/2024/08/GHSA-xj8p-vpqc-xj39/GHSA-xj8p-vpqc-xj39.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xj8p-vpqc-xj39", - "modified": "2024-08-29T12:31:05Z", + "modified": "2024-09-13T18:31:41Z", "published": "2024-08-29T12:31:05Z", "aliases": [ "CVE-2024-7856" diff --git a/advisories/unreviewed/2024/09/GHSA-2h6h-vcrw-57ff/GHSA-2h6h-vcrw-57ff.json b/advisories/unreviewed/2024/09/GHSA-2h6h-vcrw-57ff/GHSA-2h6h-vcrw-57ff.json index 39fc59d94dc..0338236fdc8 100644 --- a/advisories/unreviewed/2024/09/GHSA-2h6h-vcrw-57ff/GHSA-2h6h-vcrw-57ff.json +++ b/advisories/unreviewed/2024/09/GHSA-2h6h-vcrw-57ff/GHSA-2h6h-vcrw-57ff.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2h6h-vcrw-57ff", - "modified": "2024-09-13T06:30:43Z", + "modified": "2024-09-13T18:31:46Z", "published": "2024-09-13T06:30:43Z", "aliases": [ "CVE-2024-46696" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: fix potential UAF in nfsd4_cb_getattr_release\n\nOnce we drop the delegation reference, the fields embedded in it are no\nlonger safe to access. Do that last.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-2hgx-34f4-hp3q/GHSA-2hgx-34f4-hp3q.json b/advisories/unreviewed/2024/09/GHSA-2hgx-34f4-hp3q/GHSA-2hgx-34f4-hp3q.json new file mode 100644 index 00000000000..23ec6da4ede --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-2hgx-34f4-hp3q/GHSA-2hgx-34f4-hp3q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2hgx-34f4-hp3q", + "modified": "2024-09-13T18:31:48Z", + "published": "2024-09-13T18:31:48Z", + "aliases": [ + "CVE-2024-8059" + ], + "details": "IPMI credentials may be captured in XCC audit log entries when the account username length is 16 characters.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8059" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-172051" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T18:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-2hm7-3qf5-g28w/GHSA-2hm7-3qf5-g28w.json b/advisories/unreviewed/2024/09/GHSA-2hm7-3qf5-g28w/GHSA-2hm7-3qf5-g28w.json index 3e17e2af978..176c6cc3a24 100644 --- a/advisories/unreviewed/2024/09/GHSA-2hm7-3qf5-g28w/GHSA-2hm7-3qf5-g28w.json +++ b/advisories/unreviewed/2024/09/GHSA-2hm7-3qf5-g28w/GHSA-2hm7-3qf5-g28w.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2hm7-3qf5-g28w", - "modified": "2024-09-12T18:31:42Z", + "modified": "2024-09-13T18:31:45Z", "published": "2024-09-12T18:31:42Z", "aliases": [ "CVE-2024-8696" ], "details": "A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker Desktop before 4.34.2.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-2qxv-pr9r-9797/GHSA-2qxv-pr9r-9797.json b/advisories/unreviewed/2024/09/GHSA-2qxv-pr9r-9797/GHSA-2qxv-pr9r-9797.json new file mode 100644 index 00000000000..bd875b4073b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-2qxv-pr9r-9797/GHSA-2qxv-pr9r-9797.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2qxv-pr9r-9797", + "modified": "2024-09-13T18:31:48Z", + "published": "2024-09-13T18:31:48Z", + "aliases": [ + "CVE-2024-8280" + ], + "details": "An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection or cause a recoverable denial of service using a specially crafted file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8280" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-172051" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-34r9-jr37-pmrf/GHSA-34r9-jr37-pmrf.json b/advisories/unreviewed/2024/09/GHSA-34r9-jr37-pmrf/GHSA-34r9-jr37-pmrf.json index 3fc6b0dbaf1..059a98184d0 100644 --- a/advisories/unreviewed/2024/09/GHSA-34r9-jr37-pmrf/GHSA-34r9-jr37-pmrf.json +++ b/advisories/unreviewed/2024/09/GHSA-34r9-jr37-pmrf/GHSA-34r9-jr37-pmrf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-34r9-jr37-pmrf", - "modified": "2024-09-13T06:30:43Z", + "modified": "2024-09-13T18:31:46Z", "published": "2024-09-13T06:30:43Z", "aliases": [ "CVE-2024-46700" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/mes: fix mes ring buffer overflow\n\nwait memory room until enough before writing mes packets\nto avoid ring buffer overflow.\n\nv2: squash in sched_hw_submission fix\n\n(cherry picked from commit 34e087e8920e635c62e2ed6a758b0cd27f836d13)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-35qc-5x66-f277/GHSA-35qc-5x66-f277.json b/advisories/unreviewed/2024/09/GHSA-35qc-5x66-f277/GHSA-35qc-5x66-f277.json index 8121496d2d0..45de616d3f9 100644 --- a/advisories/unreviewed/2024/09/GHSA-35qc-5x66-f277/GHSA-35qc-5x66-f277.json +++ b/advisories/unreviewed/2024/09/GHSA-35qc-5x66-f277/GHSA-35qc-5x66-f277.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-35qc-5x66-f277", - "modified": "2024-09-11T18:31:06Z", + "modified": "2024-09-13T18:31:42Z", "published": "2024-09-11T18:31:06Z", "aliases": [ "CVE-2024-45019" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Take state lock during tx timeout reporter\n\nmlx5e_safe_reopen_channels() requires the state lock taken. The\nreferenced changed in the Fixes tag removed the lock to fix another\nissue. This patch adds it back but at a later point (when calling\nmlx5e_safe_reopen_channels()) to avoid the deadlock referenced in the\nFixes tag.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T16:15:06Z" diff --git a/advisories/unreviewed/2024/09/GHSA-375r-hmjc-j5gg/GHSA-375r-hmjc-j5gg.json b/advisories/unreviewed/2024/09/GHSA-375r-hmjc-j5gg/GHSA-375r-hmjc-j5gg.json index 20356b894f1..824d5d87ff3 100644 --- a/advisories/unreviewed/2024/09/GHSA-375r-hmjc-j5gg/GHSA-375r-hmjc-j5gg.json +++ b/advisories/unreviewed/2024/09/GHSA-375r-hmjc-j5gg/GHSA-375r-hmjc-j5gg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-375r-hmjc-j5gg", - "modified": "2024-09-11T18:31:05Z", + "modified": "2024-09-13T18:31:41Z", "published": "2024-09-11T18:31:05Z", "aliases": [ "CVE-2024-45015" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/dpu: move dpu_encoder's connector assignment to atomic_enable()\n\nFor cases where the crtc's connectors_changed was set without enable/active\ngetting toggled , there is an atomic_enable() call followed by an\natomic_disable() but without an atomic_mode_set().\n\nThis results in a NULL ptr access for the dpu_encoder_get_drm_fmt() call in\nthe atomic_enable() as the dpu_encoder's connector was cleared in the\natomic_disable() but not re-assigned as there was no atomic_mode_set() call.\n\nFix the NULL ptr access by moving the assignment for atomic_enable() and also\nuse drm_atomic_get_new_connector_for_encoder() to get the connector from\nthe atomic_state.\n\nPatchwork: https://patchwork.freedesktop.org/patch/606729/", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T16:15:06Z" diff --git a/advisories/unreviewed/2024/09/GHSA-3rvq-3fc5-4w68/GHSA-3rvq-3fc5-4w68.json b/advisories/unreviewed/2024/09/GHSA-3rvq-3fc5-4w68/GHSA-3rvq-3fc5-4w68.json index 5365be833cf..c5e357aa41a 100644 --- a/advisories/unreviewed/2024/09/GHSA-3rvq-3fc5-4w68/GHSA-3rvq-3fc5-4w68.json +++ b/advisories/unreviewed/2024/09/GHSA-3rvq-3fc5-4w68/GHSA-3rvq-3fc5-4w68.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3rvq-3fc5-4w68", - "modified": "2024-09-13T06:30:43Z", + "modified": "2024-09-13T18:31:47Z", "published": "2024-09-13T06:30:43Z", "aliases": [ "CVE-2024-7864" ], "details": "The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not have CSRF and path validation in the output_sub_admin_page_0() function, allowing attackers to make logged in admins delete arbitrary files on the server", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:15Z" diff --git a/advisories/unreviewed/2024/09/GHSA-3w3r-r6g6-w8x5/GHSA-3w3r-r6g6-w8x5.json b/advisories/unreviewed/2024/09/GHSA-3w3r-r6g6-w8x5/GHSA-3w3r-r6g6-w8x5.json index 676910a59bf..6e63bacfc41 100644 --- a/advisories/unreviewed/2024/09/GHSA-3w3r-r6g6-w8x5/GHSA-3w3r-r6g6-w8x5.json +++ b/advisories/unreviewed/2024/09/GHSA-3w3r-r6g6-w8x5/GHSA-3w3r-r6g6-w8x5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3w3r-r6g6-w8x5", - "modified": "2024-09-12T09:31:21Z", + "modified": "2024-09-13T18:31:44Z", "published": "2024-09-12T09:31:21Z", "aliases": [ "CVE-2024-8522" diff --git a/advisories/unreviewed/2024/09/GHSA-3xv2-v2hj-2crv/GHSA-3xv2-v2hj-2crv.json b/advisories/unreviewed/2024/09/GHSA-3xv2-v2hj-2crv/GHSA-3xv2-v2hj-2crv.json index 788c21eed50..b092ce34108 100644 --- a/advisories/unreviewed/2024/09/GHSA-3xv2-v2hj-2crv/GHSA-3xv2-v2hj-2crv.json +++ b/advisories/unreviewed/2024/09/GHSA-3xv2-v2hj-2crv/GHSA-3xv2-v2hj-2crv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3xv2-v2hj-2crv", - "modified": "2024-09-13T06:30:43Z", + "modified": "2024-09-13T18:31:47Z", "published": "2024-09-13T06:30:43Z", "aliases": [ "CVE-2024-6617" ], "details": "The NinjaTeam Header Footer Custom Code WordPress plugin before 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:15Z" diff --git a/advisories/unreviewed/2024/09/GHSA-4gw2-r6x4-xxxg/GHSA-4gw2-r6x4-xxxg.json b/advisories/unreviewed/2024/09/GHSA-4gw2-r6x4-xxxg/GHSA-4gw2-r6x4-xxxg.json index e4d2e63376a..3044e340b0e 100644 --- a/advisories/unreviewed/2024/09/GHSA-4gw2-r6x4-xxxg/GHSA-4gw2-r6x4-xxxg.json +++ b/advisories/unreviewed/2024/09/GHSA-4gw2-r6x4-xxxg/GHSA-4gw2-r6x4-xxxg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4gw2-r6x4-xxxg", - "modified": "2024-09-11T18:31:07Z", + "modified": "2024-09-13T18:31:42Z", "published": "2024-09-11T18:31:06Z", "aliases": [ "CVE-2024-45028" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: mmc_test: Fix NULL dereference on allocation failure\n\nIf the \"test->highmem = alloc_pages()\" allocation fails then calling\n__free_pages(test->highmem) will result in a NULL dereference. Also\nchange the error code to -ENOMEM instead of returning success.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T16:15:07Z" diff --git a/advisories/unreviewed/2024/09/GHSA-4j5q-jrmv-h6pp/GHSA-4j5q-jrmv-h6pp.json b/advisories/unreviewed/2024/09/GHSA-4j5q-jrmv-h6pp/GHSA-4j5q-jrmv-h6pp.json index 2451bc15dbe..f90e2fe41ba 100644 --- a/advisories/unreviewed/2024/09/GHSA-4j5q-jrmv-h6pp/GHSA-4j5q-jrmv-h6pp.json +++ b/advisories/unreviewed/2024/09/GHSA-4j5q-jrmv-h6pp/GHSA-4j5q-jrmv-h6pp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4j5q-jrmv-h6pp", - "modified": "2024-09-11T18:31:05Z", + "modified": "2024-09-13T18:31:41Z", "published": "2024-09-11T18:31:05Z", "aliases": [ "CVE-2024-45013" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvme: move stopping keep-alive into nvme_uninit_ctrl()\n\nCommit 4733b65d82bd (\"nvme: start keep-alive after admin queue setup\")\nmoves starting keep-alive from nvme_start_ctrl() into\nnvme_init_ctrl_finish(), but don't move stopping keep-alive into\nnvme_uninit_ctrl(), so keep-alive work can be started and keep pending\nafter failing to start controller, finally use-after-free is triggered if\nnvme host driver is unloaded.\n\nThis patch fixes kernel panic when running nvme/004 in case that connection\nfailure is triggered, by moving stopping keep-alive into nvme_uninit_ctrl().\n\nThis way is reasonable because keep-alive is now started in\nnvme_init_ctrl_finish().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T16:15:06Z" diff --git a/advisories/unreviewed/2024/09/GHSA-4qc3-9vcj-2gh8/GHSA-4qc3-9vcj-2gh8.json b/advisories/unreviewed/2024/09/GHSA-4qc3-9vcj-2gh8/GHSA-4qc3-9vcj-2gh8.json index 4ea66ea6b9e..98e11efaa30 100644 --- a/advisories/unreviewed/2024/09/GHSA-4qc3-9vcj-2gh8/GHSA-4qc3-9vcj-2gh8.json +++ b/advisories/unreviewed/2024/09/GHSA-4qc3-9vcj-2gh8/GHSA-4qc3-9vcj-2gh8.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-5293-cf37-fxqw/GHSA-5293-cf37-fxqw.json b/advisories/unreviewed/2024/09/GHSA-5293-cf37-fxqw/GHSA-5293-cf37-fxqw.json index a9389d72e66..74cae30eb97 100644 --- a/advisories/unreviewed/2024/09/GHSA-5293-cf37-fxqw/GHSA-5293-cf37-fxqw.json +++ b/advisories/unreviewed/2024/09/GHSA-5293-cf37-fxqw/GHSA-5293-cf37-fxqw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5293-cf37-fxqw", - "modified": "2024-09-13T06:30:43Z", + "modified": "2024-09-13T18:31:46Z", "published": "2024-09-13T06:30:43Z", "aliases": [ "CVE-2024-46692" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: qcom: scm: Mark get_wq_ctx() as atomic call\n\nCurrently get_wq_ctx() is wrongly configured as a standard call. When two\nSMC calls are in sleep and one SMC wakes up, it calls get_wq_ctx() to\nresume the corresponding sleeping thread. But if get_wq_ctx() is\ninterrupted, goes to sleep and another SMC call is waiting to be allocated\na waitq context, it leads to a deadlock.\n\nTo avoid this get_wq_ctx() must be an atomic call and can't be a standard\nSMC call. Hence mark get_wq_ctx() as a fast call.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-5397-7533-4p4r/GHSA-5397-7533-4p4r.json b/advisories/unreviewed/2024/09/GHSA-5397-7533-4p4r/GHSA-5397-7533-4p4r.json new file mode 100644 index 00000000000..eaf0c5a10e6 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5397-7533-4p4r/GHSA-5397-7533-4p4r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5397-7533-4p4r", + "modified": "2024-09-13T18:31:48Z", + "published": "2024-09-13T18:31:48Z", + "aliases": [ + "CVE-2024-4550" + ], + "details": "A potential buffer overflow vulnerability was reported in some Lenovo ThinkSystem and ThinkStation products that could allow a local attacker with elevated privileges to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4550" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-165524" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-56j2-rfmx-x6p8/GHSA-56j2-rfmx-x6p8.json b/advisories/unreviewed/2024/09/GHSA-56j2-rfmx-x6p8/GHSA-56j2-rfmx-x6p8.json index 4e5061b37ba..4ec72dc23f1 100644 --- a/advisories/unreviewed/2024/09/GHSA-56j2-rfmx-x6p8/GHSA-56j2-rfmx-x6p8.json +++ b/advisories/unreviewed/2024/09/GHSA-56j2-rfmx-x6p8/GHSA-56j2-rfmx-x6p8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-56j2-rfmx-x6p8", - "modified": "2024-09-11T18:31:07Z", + "modified": "2024-09-13T18:31:42Z", "published": "2024-09-11T18:31:07Z", "aliases": [ "CVE-2024-46672" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: cfg80211: Handle SSID based pmksa deletion\n\nwpa_supplicant 2.11 sends since 1efdba5fdc2c (\"Handle PMKSA flush in the\ndriver for SAE/OWE offload cases\") SSID based PMKSA del commands.\nbrcmfmac is not prepared and tries to dereference the NULL bssid and\npmkid pointers in cfg80211_pmksa. PMKID_V3 operations support SSID based\nupdates so copy the SSID.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T16:15:07Z" diff --git a/advisories/unreviewed/2024/09/GHSA-573v-9j9r-xm6w/GHSA-573v-9j9r-xm6w.json b/advisories/unreviewed/2024/09/GHSA-573v-9j9r-xm6w/GHSA-573v-9j9r-xm6w.json new file mode 100644 index 00000000000..9bba96db561 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-573v-9j9r-xm6w/GHSA-573v-9j9r-xm6w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-573v-9j9r-xm6w", + "modified": "2024-09-13T18:31:47Z", + "published": "2024-09-13T18:31:47Z", + "aliases": [ + "CVE-2024-31415" + ], + "details": "The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, user management, etc. The software uses encryption to store these configurations securely on the host machine. However, the keys used for this encryption were insecurely stored, which could be abused to possibly change or remove the server configuration.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31415" + }, + { + "type": "WEB", + "url": "https://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/etn-va-2024-1008.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-5785-6rg8-vqjc/GHSA-5785-6rg8-vqjc.json b/advisories/unreviewed/2024/09/GHSA-5785-6rg8-vqjc/GHSA-5785-6rg8-vqjc.json index 0f974f79edd..022975b6067 100644 --- a/advisories/unreviewed/2024/09/GHSA-5785-6rg8-vqjc/GHSA-5785-6rg8-vqjc.json +++ b/advisories/unreviewed/2024/09/GHSA-5785-6rg8-vqjc/GHSA-5785-6rg8-vqjc.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-5m73-3pch-86m2/GHSA-5m73-3pch-86m2.json b/advisories/unreviewed/2024/09/GHSA-5m73-3pch-86m2/GHSA-5m73-3pch-86m2.json index 46136d28c21..3e86a11602f 100644 --- a/advisories/unreviewed/2024/09/GHSA-5m73-3pch-86m2/GHSA-5m73-3pch-86m2.json +++ b/advisories/unreviewed/2024/09/GHSA-5m73-3pch-86m2/GHSA-5m73-3pch-86m2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5m73-3pch-86m2", - "modified": "2024-09-11T18:31:06Z", + "modified": "2024-09-13T18:31:42Z", "published": "2024-09-11T18:31:06Z", "aliases": [ "CVE-2024-45021" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmemcg_write_event_control(): fix a user-triggerable oops\n\nwe are *not* guaranteed that anything past the terminating NUL\nis mapped (let alone initialized with anything sane).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T16:15:07Z" diff --git a/advisories/unreviewed/2024/09/GHSA-5pqc-wgxh-g2rx/GHSA-5pqc-wgxh-g2rx.json b/advisories/unreviewed/2024/09/GHSA-5pqc-wgxh-g2rx/GHSA-5pqc-wgxh-g2rx.json new file mode 100644 index 00000000000..4ef767bd1a0 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5pqc-wgxh-g2rx/GHSA-5pqc-wgxh-g2rx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5pqc-wgxh-g2rx", + "modified": "2024-09-13T18:31:47Z", + "published": "2024-09-13T18:31:47Z", + "aliases": [ + "CVE-2024-31414" + ], + "details": "The Eaton Foreseer software provides users the capability to customize the dashboard in WebView pages. However, the input fields for this feature in the Eaton Foreseer software lacked proper input sanitization on the server-side, which could lead to injection and execution of malicious scripts when abused by bad actors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31414" + }, + { + "type": "WEB", + "url": "https://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/etn-va-2024-1008.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-5qvx-cmvh-v55m/GHSA-5qvx-cmvh-v55m.json b/advisories/unreviewed/2024/09/GHSA-5qvx-cmvh-v55m/GHSA-5qvx-cmvh-v55m.json index f1813663280..ae0e082f8d1 100644 --- a/advisories/unreviewed/2024/09/GHSA-5qvx-cmvh-v55m/GHSA-5qvx-cmvh-v55m.json +++ b/advisories/unreviewed/2024/09/GHSA-5qvx-cmvh-v55m/GHSA-5qvx-cmvh-v55m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5qvx-cmvh-v55m", - "modified": "2024-09-13T06:30:43Z", + "modified": "2024-09-13T18:31:46Z", "published": "2024-09-13T06:30:43Z", "aliases": [ "CVE-2024-46693" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: qcom: pmic_glink: Fix race during initialization\n\nAs pointed out by Stephen Boyd it is possible that during initialization\nof the pmic_glink child drivers, the protection-domain notifiers fires,\nand the associated work is scheduled, before the client registration\nreturns and as a result the local \"client\" pointer has been initialized.\n\nThe outcome of this is a NULL pointer dereference as the \"client\"\npointer is blindly dereferenced.\n\nTimeline provided by Stephen:\n CPU0 CPU1\n ---- ----\n ucsi->client = NULL;\n devm_pmic_glink_register_client()\n client->pdr_notify(client->priv, pg->client_state)\n pmic_glink_ucsi_pdr_notify()\n schedule_work(&ucsi->register_work)\n \n pmic_glink_ucsi_register()\n ucsi_register()\n pmic_glink_ucsi_read_version()\n pmic_glink_ucsi_read()\n pmic_glink_ucsi_read()\n pmic_glink_send(ucsi->client)\n \n ucsi->client = client // Too late!\n\nThis code is identical across the altmode, battery manager and usci\nchild drivers.\n\nResolve this by splitting the allocation of the \"client\" object and the\nregistration thereof into two operations.\n\nThis only happens if the protection domain registry is populated at the\ntime of registration, which by the introduction of commit '1ebcde047c54\n(\"soc: qcom: add pd-mapper implementation\")' became much more likely.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-5w55-q3rh-9cgc/GHSA-5w55-q3rh-9cgc.json b/advisories/unreviewed/2024/09/GHSA-5w55-q3rh-9cgc/GHSA-5w55-q3rh-9cgc.json index 5238b587791..a0af7b81f13 100644 --- a/advisories/unreviewed/2024/09/GHSA-5w55-q3rh-9cgc/GHSA-5w55-q3rh-9cgc.json +++ b/advisories/unreviewed/2024/09/GHSA-5w55-q3rh-9cgc/GHSA-5w55-q3rh-9cgc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5w55-q3rh-9cgc", - "modified": "2024-09-13T06:30:43Z", + "modified": "2024-09-13T18:31:46Z", "published": "2024-09-13T06:30:43Z", "aliases": [ "CVE-2024-46691" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: Move unregister out of atomic section\n\nCommit '9329933699b3 (\"soc: qcom: pmic_glink: Make client-lock\nnon-sleeping\")' moved the pmic_glink client list under a spinlock, as it\nis accessed by the rpmsg/glink callback, which in turn is invoked from\nIRQ context.\n\nThis means that ucsi_unregister() is now called from atomic context,\nwhich isn't feasible as it's expecting a sleepable context. An effort is\nunder way to get GLINK to invoke its callbacks in a sleepable context,\nbut until then lets schedule the unregistration.\n\nA side effect of this is that ucsi_unregister() can now happen\nafter the remote processor, and thereby the communication link with it, is\ngone. pmic_glink_send() is amended with a check to avoid the resulting NULL\npointer dereference.\nThis does however result in the user being informed about this error by\nthe following entry in the kernel log:\n\n ucsi_glink.pmic_glink_ucsi pmic_glink.ucsi.0: failed to send UCSI write request: -5", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-62hc-56xq-xr7v/GHSA-62hc-56xq-xr7v.json b/advisories/unreviewed/2024/09/GHSA-62hc-56xq-xr7v/GHSA-62hc-56xq-xr7v.json new file mode 100644 index 00000000000..9110ae81213 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-62hc-56xq-xr7v/GHSA-62hc-56xq-xr7v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62hc-56xq-xr7v", + "modified": "2024-09-13T18:31:47Z", + "published": "2024-09-13T18:31:47Z", + "aliases": [ + "CVE-2024-42025" + ], + "details": "A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.3.32 and earlier) allows a malicious actor with unifi user shell access to escalate privileges to root on the host device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42025" + }, + { + "type": "WEB", + "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-042-042/c4f68b56-cdc4-4128-b2cb-5870209d1704" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T16:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-64qj-9hxc-x9rc/GHSA-64qj-9hxc-x9rc.json b/advisories/unreviewed/2024/09/GHSA-64qj-9hxc-x9rc/GHSA-64qj-9hxc-x9rc.json index d5a767a341f..fd73f242fda 100644 --- a/advisories/unreviewed/2024/09/GHSA-64qj-9hxc-x9rc/GHSA-64qj-9hxc-x9rc.json +++ b/advisories/unreviewed/2024/09/GHSA-64qj-9hxc-x9rc/GHSA-64qj-9hxc-x9rc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-64qj-9hxc-x9rc", - "modified": "2024-09-13T06:30:42Z", + "modified": "2024-09-13T18:31:46Z", "published": "2024-09-13T06:30:42Z", "aliases": [ "CVE-2024-46677" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngtp: fix a potential NULL pointer dereference\n\nWhen sockfd_lookup() fails, gtp_encap_enable_socket() returns a\nNULL pointer, but its callers only check for error pointers thus miss\nthe NULL pointer case.\n\nFix it by returning an error pointer with the error code carried from\nsockfd_lookup().\n\n(I found this bug during code inspection.)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:12Z" diff --git a/advisories/unreviewed/2024/09/GHSA-66cw-5j4x-3r2w/GHSA-66cw-5j4x-3r2w.json b/advisories/unreviewed/2024/09/GHSA-66cw-5j4x-3r2w/GHSA-66cw-5j4x-3r2w.json index e2816d6bfa3..3e8d5b61bd5 100644 --- a/advisories/unreviewed/2024/09/GHSA-66cw-5j4x-3r2w/GHSA-66cw-5j4x-3r2w.json +++ b/advisories/unreviewed/2024/09/GHSA-66cw-5j4x-3r2w/GHSA-66cw-5j4x-3r2w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-66cw-5j4x-3r2w", - "modified": "2024-09-11T18:31:07Z", + "modified": "2024-09-13T18:31:42Z", "published": "2024-09-11T18:31:06Z", "aliases": [ "CVE-2024-45026" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/dasd: fix error recovery leading to data corruption on ESE devices\n\nExtent Space Efficient (ESE) or thin provisioned volumes need to be\nformatted on demand during usual IO processing.\n\nThe dasd_ese_needs_format function checks for error codes that signal\nthe non existence of a proper track format.\n\nThe check for incorrect length is to imprecise since other error cases\nleading to transport of insufficient data also have this flag set.\nThis might lead to data corruption in certain error cases for example\nduring a storage server warmstart.\n\nFix by removing the check for incorrect length and replacing by\nexplicitly checking for invalid track format in transport mode.\n\nAlso remove the check for file protected since this is not a valid\nESE handling case.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T16:15:07Z" diff --git a/advisories/unreviewed/2024/09/GHSA-6p2q-8qfq-wq7x/GHSA-6p2q-8qfq-wq7x.json b/advisories/unreviewed/2024/09/GHSA-6p2q-8qfq-wq7x/GHSA-6p2q-8qfq-wq7x.json new file mode 100644 index 00000000000..45e29cfb467 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6p2q-8qfq-wq7x/GHSA-6p2q-8qfq-wq7x.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6p2q-8qfq-wq7x", + "modified": "2024-09-13T18:31:48Z", + "published": "2024-09-13T18:31:48Z", + "aliases": [ + "CVE-2024-6087" + ], + "details": "An improper access control vulnerability exists in lunary-ai/lunary at the latest commit (a761d83) on the main branch. The vulnerability allows an attacker to use the auth tokens issued by the 'invite user' functionality to obtain valid JWT tokens. These tokens can be used to compromise target users upon registration for their own arbitrary organizations. The attacker can invite a target email, obtain a one-time use token, retract the invite, and later use the token to reset the password of the target user, leading to full account takeover.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6087" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/844e8855c7a713dc7371766dba4125de4007b1cf" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/bd9f2301-11c7-4cbd-8d77-3e9225bd67e8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6x3x-mhgp-4j2c/GHSA-6x3x-mhgp-4j2c.json b/advisories/unreviewed/2024/09/GHSA-6x3x-mhgp-4j2c/GHSA-6x3x-mhgp-4j2c.json index a03579b95b7..8b516dac2ac 100644 --- a/advisories/unreviewed/2024/09/GHSA-6x3x-mhgp-4j2c/GHSA-6x3x-mhgp-4j2c.json +++ b/advisories/unreviewed/2024/09/GHSA-6x3x-mhgp-4j2c/GHSA-6x3x-mhgp-4j2c.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-7977-m9r5-5r9p/GHSA-7977-m9r5-5r9p.json b/advisories/unreviewed/2024/09/GHSA-7977-m9r5-5r9p/GHSA-7977-m9r5-5r9p.json index 1ebad70faec..f7a8e948dec 100644 --- a/advisories/unreviewed/2024/09/GHSA-7977-m9r5-5r9p/GHSA-7977-m9r5-5r9p.json +++ b/advisories/unreviewed/2024/09/GHSA-7977-m9r5-5r9p/GHSA-7977-m9r5-5r9p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7977-m9r5-5r9p", - "modified": "2024-09-11T18:31:07Z", + "modified": "2024-09-13T18:31:42Z", "published": "2024-09-11T18:31:07Z", "aliases": [ "CVE-2024-45025" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfix bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE\n\ncopy_fd_bitmaps(new, old, count) is expected to copy the first\ncount/BITS_PER_LONG bits from old->full_fds_bits[] and fill\nthe rest with zeroes. What it does is copying enough words\n(BITS_TO_LONGS(count/BITS_PER_LONG)), then memsets the rest.\nThat works fine, *if* all bits past the cutoff point are\nclear. Otherwise we are risking garbage from the last word\nwe'd copied.\n\nFor most of the callers that is true - expand_fdtable() has\ncount equal to old->max_fds, so there's no open descriptors\npast count, let alone fully occupied words in ->open_fds[],\nwhich is what bits in ->full_fds_bits[] correspond to.\n\nThe other caller (dup_fd()) passes sane_fdtable_size(old_fdt, max_fds),\nwhich is the smallest multiple of BITS_PER_LONG that covers all\nopened descriptors below max_fds. In the common case (copying on\nfork()) max_fds is ~0U, so all opened descriptors will be below\nit and we are fine, by the same reasons why the call in expand_fdtable()\nis safe.\n\nUnfortunately, there is a case where max_fds is less than that\nand where we might, indeed, end up with junk in ->full_fds_bits[] -\nclose_range(from, to, CLOSE_RANGE_UNSHARE) with\n\t* descriptor table being currently shared\n\t* 'to' being above the current capacity of descriptor table\n\t* 'from' being just under some chunk of opened descriptors.\nIn that case we end up with observably wrong behaviour - e.g. spawn\na child with CLONE_FILES, get all descriptors in range 0..127 open,\nthen close_range(64, ~0U, CLOSE_RANGE_UNSHARE) and watch dup(0) ending\nup with descriptor #128, despite #64 being observably not open.\n\nThe minimally invasive fix would be to deal with that in dup_fd().\nIf this proves to add measurable overhead, we can go that way, but\nlet's try to fix copy_fd_bitmaps() first.\n\n* new helper: bitmap_copy_and_expand(to, from, bits_to_copy, size).\n* make copy_fd_bitmaps() take the bitmap size in words, rather than\nbits; it's 'count' argument is always a multiple of BITS_PER_LONG,\nso we are not losing any information, and that way we can use the\nsame helper for all three bitmaps - compiler will see that count\nis a multiple of BITS_PER_LONG for the large ones, so it'll generate\nplain memcpy()+memset().\n\nReproducer added to tools/testing/selftests/core/close_range_test.c", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T16:15:07Z" diff --git a/advisories/unreviewed/2024/09/GHSA-7f48-pc7q-83qh/GHSA-7f48-pc7q-83qh.json b/advisories/unreviewed/2024/09/GHSA-7f48-pc7q-83qh/GHSA-7f48-pc7q-83qh.json index f0bcef967c4..7094fdc74cf 100644 --- a/advisories/unreviewed/2024/09/GHSA-7f48-pc7q-83qh/GHSA-7f48-pc7q-83qh.json +++ b/advisories/unreviewed/2024/09/GHSA-7f48-pc7q-83qh/GHSA-7f48-pc7q-83qh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7f48-pc7q-83qh", - "modified": "2024-09-13T06:30:43Z", + "modified": "2024-09-13T18:31:46Z", "published": "2024-09-13T06:30:43Z", "aliases": [ "CVE-2024-46698" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvideo/aperture: optionally match the device in sysfb_disable()\n\nIn aperture_remove_conflicting_pci_devices(), we currently only\ncall sysfb_disable() on vga class devices. This leads to the\nfollowing problem when the pimary device is not VGA compatible:\n\n1. A PCI device with a non-VGA class is the boot display\n2. That device is probed first and it is not a VGA device so\n sysfb_disable() is not called, but the device resources\n are freed by aperture_detach_platform_device()\n3. Non-primary GPU has a VGA class and it ends up calling sysfb_disable()\n4. NULL pointer dereference via sysfb_disable() since the resources\n have already been freed by aperture_detach_platform_device() when\n it was called by the other device.\n\nFix this by passing a device pointer to sysfb_disable() and checking\nthe device to determine if we should execute it or not.\n\nv2: Fix build when CONFIG_SCREEN_INFO is not set\nv3: Move device check into the mutex\n Drop primary variable in aperture_remove_conflicting_pci_devices()\n Drop __init on pci sysfb_pci_dev_is_enabled()", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-7fv4-rmp7-g4qh/GHSA-7fv4-rmp7-g4qh.json b/advisories/unreviewed/2024/09/GHSA-7fv4-rmp7-g4qh/GHSA-7fv4-rmp7-g4qh.json index a181eb97187..a06b1db65b5 100644 --- a/advisories/unreviewed/2024/09/GHSA-7fv4-rmp7-g4qh/GHSA-7fv4-rmp7-g4qh.json +++ b/advisories/unreviewed/2024/09/GHSA-7fv4-rmp7-g4qh/GHSA-7fv4-rmp7-g4qh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7fv4-rmp7-g4qh", - "modified": "2024-09-11T18:31:06Z", + "modified": "2024-09-13T18:31:42Z", "published": "2024-09-11T18:31:06Z", "aliases": [ "CVE-2024-45022" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/vmalloc: fix page mapping if vm_area_alloc_pages() with high order fallback to order 0\n\nThe __vmap_pages_range_noflush() assumes its argument pages** contains\npages with the same page shift. However, since commit e9c3cda4d86e (\"mm,\nvmalloc: fix high order __GFP_NOFAIL allocations\"), if gfp_flags includes\n__GFP_NOFAIL with high order in vm_area_alloc_pages() and page allocation\nfailed for high order, the pages** may contain two different page shifts\n(high order and order-0). This could lead __vmap_pages_range_noflush() to\nperform incorrect mappings, potentially resulting in memory corruption.\n\nUsers might encounter this as follows (vmap_allow_huge = true, 2M is for\nPMD_SIZE):\n\nkvmalloc(2M, __GFP_NOFAIL|GFP_X)\n __vmalloc_node_range_noprof(vm_flags=VM_ALLOW_HUGE_VMAP)\n vm_area_alloc_pages(order=9) ---> order-9 allocation failed and fallback to order-0\n vmap_pages_range()\n vmap_pages_range_noflush()\n __vmap_pages_range_noflush(page_shift = 21) ----> wrong mapping happens\n\nWe can remove the fallback code because if a high-order allocation fails,\n__vmalloc_node_range_noprof() will retry with order-0. Therefore, it is\nunnecessary to fallback to order-0 here. Therefore, fix this by removing\nthe fallback code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T16:15:07Z" diff --git a/advisories/unreviewed/2024/09/GHSA-7g34-wcpj-vf55/GHSA-7g34-wcpj-vf55.json b/advisories/unreviewed/2024/09/GHSA-7g34-wcpj-vf55/GHSA-7g34-wcpj-vf55.json index 838f615f5aa..95350c06531 100644 --- a/advisories/unreviewed/2024/09/GHSA-7g34-wcpj-vf55/GHSA-7g34-wcpj-vf55.json +++ b/advisories/unreviewed/2024/09/GHSA-7g34-wcpj-vf55/GHSA-7g34-wcpj-vf55.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7g34-wcpj-vf55", - "modified": "2024-09-11T18:31:05Z", + "modified": "2024-09-13T18:31:43Z", "published": "2024-09-11T18:31:05Z", "aliases": [ "CVE-2024-45012" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnouveau/firmware: use dma non-coherent allocator\n\nCurrently, enabling SG_DEBUG in the kernel will cause nouveau to hit a\nBUG() on startup, when the iommu is enabled:\n\nkernel BUG at include/linux/scatterlist.h:187!\ninvalid opcode: 0000 [#1] PREEMPT SMP NOPTI\nCPU: 7 PID: 930 Comm: (udev-worker) Not tainted 6.9.0-rc3Lyude-Test+ #30\nHardware name: MSI MS-7A39/A320M GAMING PRO (MS-7A39), BIOS 1.I0 01/22/2019\nRIP: 0010:sg_init_one+0x85/0xa0\nCode: 69 88 32 01 83 e1 03 f6 c3 03 75 20 a8 01 75 1e 48 09 cb 41 89 54\n24 08 49 89 1c 24 41 89 6c 24 0c 5b 5d 41 5c e9 7b b9 88 00 <0f> 0b 0f 0b\n0f 0b 48 8b 05 5e 46 9a 01 eb b2 66 66 2e 0f 1f 84 00\nRSP: 0018:ffffa776017bf6a0 EFLAGS: 00010246\nRAX: 0000000000000000 RBX: ffffa77600d87000 RCX: 000000000000002b\nRDX: 0000000000000001 RSI: 0000000000000000 RDI: ffffa77680d87000\nRBP: 000000000000e000 R08: 0000000000000000 R09: 0000000000000000\nR10: ffff98f4c46aa508 R11: 0000000000000000 R12: ffff98f4c46aa508\nR13: ffff98f4c46aa008 R14: ffffa77600d4a000 R15: ffffa77600d4a018\nFS: 00007feeb5aae980(0000) GS:ffff98f5c4dc0000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f22cb9a4520 CR3: 00000001043ba000 CR4: 00000000003506f0\nCall Trace:\n \n ? die+0x36/0x90\n ? do_trap+0xdd/0x100\n ? sg_init_one+0x85/0xa0\n ? do_error_trap+0x65/0x80\n ? sg_init_one+0x85/0xa0\n ? exc_invalid_op+0x50/0x70\n ? sg_init_one+0x85/0xa0\n ? asm_exc_invalid_op+0x1a/0x20\n ? sg_init_one+0x85/0xa0\n nvkm_firmware_ctor+0x14a/0x250 [nouveau]\n nvkm_falcon_fw_ctor+0x42/0x70 [nouveau]\n ga102_gsp_booter_ctor+0xb4/0x1a0 [nouveau]\n r535_gsp_oneinit+0xb3/0x15f0 [nouveau]\n ? srso_return_thunk+0x5/0x5f\n ? srso_return_thunk+0x5/0x5f\n ? nvkm_udevice_new+0x95/0x140 [nouveau]\n ? srso_return_thunk+0x5/0x5f\n ? srso_return_thunk+0x5/0x5f\n ? ktime_get+0x47/0xb0\n\nFix this by using the non-coherent allocator instead, I think there\nmight be a better answer to this, but it involve ripping up some of\nAPIs using sg lists.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T16:15:06Z" diff --git a/advisories/unreviewed/2024/09/GHSA-8grv-f28f-g844/GHSA-8grv-f28f-g844.json b/advisories/unreviewed/2024/09/GHSA-8grv-f28f-g844/GHSA-8grv-f28f-g844.json index 2b16a760119..83aadccf2d5 100644 --- a/advisories/unreviewed/2024/09/GHSA-8grv-f28f-g844/GHSA-8grv-f28f-g844.json +++ b/advisories/unreviewed/2024/09/GHSA-8grv-f28f-g844/GHSA-8grv-f28f-g844.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8grv-f28f-g844", - "modified": "2024-09-11T18:31:06Z", + "modified": "2024-09-13T18:31:42Z", "published": "2024-09-11T18:31:06Z", "aliases": [ "CVE-2024-45024" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/hugetlb: fix hugetlb vs. core-mm PT locking\n\nWe recently made GUP's common page table walking code to also walk hugetlb\nVMAs without most hugetlb special-casing, preparing for the future of\nhaving less hugetlb-specific page table walking code in the codebase. \nTurns out that we missed one page table locking detail: page table locking\nfor hugetlb folios that are not mapped using a single PMD/PUD.\n\nAssume we have hugetlb folio that spans multiple PTEs (e.g., 64 KiB\nhugetlb folios on arm64 with 4 KiB base page size). GUP, as it walks the\npage tables, will perform a pte_offset_map_lock() to grab the PTE table\nlock.\n\nHowever, hugetlb that concurrently modifies these page tables would\nactually grab the mm->page_table_lock: with USE_SPLIT_PTE_PTLOCKS, the\nlocks would differ. Something similar can happen right now with hugetlb\nfolios that span multiple PMDs when USE_SPLIT_PMD_PTLOCKS.\n\nThis issue can be reproduced [1], for example triggering:\n\n[ 3105.936100] ------------[ cut here ]------------\n[ 3105.939323] WARNING: CPU: 31 PID: 2732 at mm/gup.c:142 try_grab_folio+0x11c/0x188\n[ 3105.944634] Modules linked in: [...]\n[ 3105.974841] CPU: 31 PID: 2732 Comm: reproducer Not tainted 6.10.0-64.eln141.aarch64 #1\n[ 3105.980406] Hardware name: QEMU KVM Virtual Machine, BIOS edk2-20240524-4.fc40 05/24/2024\n[ 3105.986185] pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ 3105.991108] pc : try_grab_folio+0x11c/0x188\n[ 3105.994013] lr : follow_page_pte+0xd8/0x430\n[ 3105.996986] sp : ffff80008eafb8f0\n[ 3105.999346] x29: ffff80008eafb900 x28: ffffffe8d481f380 x27: 00f80001207cff43\n[ 3106.004414] x26: 0000000000000001 x25: 0000000000000000 x24: ffff80008eafba48\n[ 3106.009520] x23: 0000ffff9372f000 x22: ffff7a54459e2000 x21: ffff7a546c1aa978\n[ 3106.014529] x20: ffffffe8d481f3c0 x19: 0000000000610041 x18: 0000000000000001\n[ 3106.019506] x17: 0000000000000001 x16: ffffffffffffffff x15: 0000000000000000\n[ 3106.024494] x14: ffffb85477fdfe08 x13: 0000ffff9372ffff x12: 0000000000000000\n[ 3106.029469] x11: 1fffef4a88a96be1 x10: ffff7a54454b5f0c x9 : ffffb854771b12f0\n[ 3106.034324] x8 : 0008000000000000 x7 : ffff7a546c1aa980 x6 : 0008000000000080\n[ 3106.038902] x5 : 00000000001207cf x4 : 0000ffff9372f000 x3 : ffffffe8d481f000\n[ 3106.043420] x2 : 0000000000610041 x1 : 0000000000000001 x0 : 0000000000000000\n[ 3106.047957] Call trace:\n[ 3106.049522] try_grab_folio+0x11c/0x188\n[ 3106.051996] follow_pmd_mask.constprop.0.isra.0+0x150/0x2e0\n[ 3106.055527] follow_page_mask+0x1a0/0x2b8\n[ 3106.058118] __get_user_pages+0xf0/0x348\n[ 3106.060647] faultin_page_range+0xb0/0x360\n[ 3106.063651] do_madvise+0x340/0x598\n\nLet's make huge_pte_lockptr() effectively use the same PT locks as any\ncore-mm page table walker would. Add ptep_lockptr() to obtain the PTE\npage table lock using a pte pointer -- unfortunately we cannot convert\npte_lockptr() because virt_to_page() doesn't work with kmap'ed page tables\nwe can have with CONFIG_HIGHPTE.\n\nHandle CONFIG_PGTABLE_LEVELS correctly by checking in reverse order, such\nthat when e.g., CONFIG_PGTABLE_LEVELS==2 with\nPGDIR_SIZE==P4D_SIZE==PUD_SIZE==PMD_SIZE will work as expected. Document\nwhy that works.\n\nThere is one ugly case: powerpc 8xx, whereby we have an 8 MiB hugetlb\nfolio being mapped using two PTE page tables. While hugetlb wants to take\nthe PMD table lock, core-mm would grab the PTE table lock of one of both\nPTE page tables. In such corner cases, we have to make sure that both\nlocks match, which is (fortunately!) currently guaranteed for 8xx as it\ndoes not support SMP and consequently doesn't use split PT locks.\n\n[1] https://lore.kernel.org/all/1bbfcc7f-f222-45a5-ac44-c5a1381c596d@redhat.com/", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T16:15:07Z" diff --git a/advisories/unreviewed/2024/09/GHSA-8v66-q974-wq26/GHSA-8v66-q974-wq26.json b/advisories/unreviewed/2024/09/GHSA-8v66-q974-wq26/GHSA-8v66-q974-wq26.json index 4fced89175c..3eeee5831a2 100644 --- a/advisories/unreviewed/2024/09/GHSA-8v66-q974-wq26/GHSA-8v66-q974-wq26.json +++ b/advisories/unreviewed/2024/09/GHSA-8v66-q974-wq26/GHSA-8v66-q974-wq26.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8v66-q974-wq26", - "modified": "2024-09-11T18:31:05Z", + "modified": "2024-09-13T18:31:41Z", "published": "2024-09-11T18:31:05Z", "aliases": [ "CVE-2024-45014" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/boot: Avoid possible physmem_info segment corruption\n\nWhen physical memory for the kernel image is allocated it does not\nconsider extra memory required for offsetting the image start to\nmatch it with the lower 20 bits of KASLR virtual base address. That\nmight lead to kernel access beyond its memory range.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T16:15:06Z" diff --git a/advisories/unreviewed/2024/09/GHSA-956h-wvh5-7cgp/GHSA-956h-wvh5-7cgp.json b/advisories/unreviewed/2024/09/GHSA-956h-wvh5-7cgp/GHSA-956h-wvh5-7cgp.json index ba149a39ee2..ba460c4961c 100644 --- a/advisories/unreviewed/2024/09/GHSA-956h-wvh5-7cgp/GHSA-956h-wvh5-7cgp.json +++ b/advisories/unreviewed/2024/09/GHSA-956h-wvh5-7cgp/GHSA-956h-wvh5-7cgp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-956h-wvh5-7cgp", - "modified": "2024-09-13T15:31:35Z", + "modified": "2024-09-13T18:31:47Z", "published": "2024-09-13T15:31:35Z", "aliases": [ "CVE-2024-46048" ], "details": "Tenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function i", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T14:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-9672-786w-jwpr/GHSA-9672-786w-jwpr.json b/advisories/unreviewed/2024/09/GHSA-9672-786w-jwpr/GHSA-9672-786w-jwpr.json index 557337fcb23..98b146c071b 100644 --- a/advisories/unreviewed/2024/09/GHSA-9672-786w-jwpr/GHSA-9672-786w-jwpr.json +++ b/advisories/unreviewed/2024/09/GHSA-9672-786w-jwpr/GHSA-9672-786w-jwpr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9672-786w-jwpr", - "modified": "2024-09-13T15:31:34Z", + "modified": "2024-09-13T18:31:47Z", "published": "2024-09-13T15:31:34Z", "aliases": [ "CVE-2024-46046" ], "details": "Tenda FH451 v1.0.0.9 has a stack overflow vulnerability located in the RouteStatic function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T14:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-974p-hhmc-6h46/GHSA-974p-hhmc-6h46.json b/advisories/unreviewed/2024/09/GHSA-974p-hhmc-6h46/GHSA-974p-hhmc-6h46.json new file mode 100644 index 00000000000..57fd4ea76c3 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-974p-hhmc-6h46/GHSA-974p-hhmc-6h46.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-974p-hhmc-6h46", + "modified": "2024-09-13T18:31:48Z", + "published": "2024-09-13T18:31:48Z", + "aliases": [ + "CVE-2024-39924" + ], + "details": "An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified in the authentication and authorization process of the endpoint responsible for altering the metadata of an emergency access. It permits an attacker with granted emergency access to escalate their privileges by changing the access level and modifying the wait time. Consequently, the attacker can gain full control over the vault (when only intended to have read access) while bypassing the necessary wait period.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39924" + }, + { + "type": "WEB", + "url": "https://github.com/dani-garcia/vaultwarden/blob/1.30.3/src/api/core/emergency_access.rs#L115-L148" + }, + { + "type": "WEB", + "url": "https://github.com/dani-garcia/vaultwarden/releases/tag/1.32.0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T18:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-98wp-w76v-f75p/GHSA-98wp-w76v-f75p.json b/advisories/unreviewed/2024/09/GHSA-98wp-w76v-f75p/GHSA-98wp-w76v-f75p.json index 0c61da1dfd4..138aa317f41 100644 --- a/advisories/unreviewed/2024/09/GHSA-98wp-w76v-f75p/GHSA-98wp-w76v-f75p.json +++ b/advisories/unreviewed/2024/09/GHSA-98wp-w76v-f75p/GHSA-98wp-w76v-f75p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-98wp-w76v-f75p", - "modified": "2024-09-12T09:31:21Z", + "modified": "2024-09-13T18:31:44Z", "published": "2024-09-12T09:31:21Z", "aliases": [ "CVE-2024-8529" diff --git a/advisories/unreviewed/2024/09/GHSA-9jmp-j63g-8x6m/GHSA-9jmp-j63g-8x6m.json b/advisories/unreviewed/2024/09/GHSA-9jmp-j63g-8x6m/GHSA-9jmp-j63g-8x6m.json new file mode 100644 index 00000000000..bb54b660fe5 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-9jmp-j63g-8x6m/GHSA-9jmp-j63g-8x6m.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9jmp-j63g-8x6m", + "modified": "2024-09-13T18:31:48Z", + "published": "2024-09-13T18:31:48Z", + "aliases": [ + "CVE-2024-6867" + ], + "details": "An information disclosure vulnerability exists in the lunary-ai/lunary, specifically in the `runs/{run_id}/related` endpoint. This endpoint does not verify that the user has the necessary access rights to the run(s) they are accessing. As a result, it returns not only the specified run but also all runs that have the `run_id` listed as their parent run. This issue affects the main branch, commit a761d833. The vulnerability allows unauthorized users to obtain information about non-public runs and their related runs, given the `run_id` of a public or non-public run.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6867" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/35afd4439464571eb016318cd7b6f85a162225ca" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/460df515-164c-4435-954b-0233a181545f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1220" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-9mqh-56r5-64mq/GHSA-9mqh-56r5-64mq.json b/advisories/unreviewed/2024/09/GHSA-9mqh-56r5-64mq/GHSA-9mqh-56r5-64mq.json new file mode 100644 index 00000000000..5f64092f325 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-9mqh-56r5-64mq/GHSA-9mqh-56r5-64mq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mqh-56r5-64mq", + "modified": "2024-09-13T18:31:47Z", + "published": "2024-09-13T18:31:47Z", + "aliases": [ + "CVE-2024-31416" + ], + "details": "The Eaton Foreseer software provides multiple customizable input fields for the users to configure parameters in the tool like alarms, reports, etc. Some of these input fields were not checking the length and bounds of the entered value. The exploit of this security flaw by a bad actor may result in excessive memory consumption or integer overflow.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31416" + }, + { + "type": "WEB", + "url": "https://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/etn-va-2024-1008.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-9rrr-65q4-qrrq/GHSA-9rrr-65q4-qrrq.json b/advisories/unreviewed/2024/09/GHSA-9rrr-65q4-qrrq/GHSA-9rrr-65q4-qrrq.json new file mode 100644 index 00000000000..69a56b6d54d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-9rrr-65q4-qrrq/GHSA-9rrr-65q4-qrrq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rrr-65q4-qrrq", + "modified": "2024-09-13T18:31:48Z", + "published": "2024-09-13T18:31:48Z", + "aliases": [ + "CVE-2024-45101" + ], + "details": "A privilege escalation vulnerability was discovered when Single Sign On (SSO) is enabled that could allow an attacker to intercept a valid, authenticated LXCA user’s XCC session if they can convince the user to click on a specially crafted URL.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45101" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-154748" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-f2v6-mw6x-qmwc/GHSA-f2v6-mw6x-qmwc.json b/advisories/unreviewed/2024/09/GHSA-f2v6-mw6x-qmwc/GHSA-f2v6-mw6x-qmwc.json index 7534c520d1d..08b76a705f4 100644 --- a/advisories/unreviewed/2024/09/GHSA-f2v6-mw6x-qmwc/GHSA-f2v6-mw6x-qmwc.json +++ b/advisories/unreviewed/2024/09/GHSA-f2v6-mw6x-qmwc/GHSA-f2v6-mw6x-qmwc.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-457" + "CWE-457", + "CWE-908" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-fr4x-3m2g-jm28/GHSA-fr4x-3m2g-jm28.json b/advisories/unreviewed/2024/09/GHSA-fr4x-3m2g-jm28/GHSA-fr4x-3m2g-jm28.json index cd0882175df..d9b309e1b3e 100644 --- a/advisories/unreviewed/2024/09/GHSA-fr4x-3m2g-jm28/GHSA-fr4x-3m2g-jm28.json +++ b/advisories/unreviewed/2024/09/GHSA-fr4x-3m2g-jm28/GHSA-fr4x-3m2g-jm28.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fr4x-3m2g-jm28", - "modified": "2024-09-13T06:30:43Z", + "modified": "2024-09-13T18:31:47Z", "published": "2024-09-13T06:30:43Z", "aliases": [ "CVE-2024-7863" ], "details": "The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not validate files to be uploaded and does not have CSRF checks, which could allow attackers to make logged in admin upload arbitrary files such as PHP on the server", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:15Z" diff --git a/advisories/unreviewed/2024/09/GHSA-fwj7-298v-7488/GHSA-fwj7-298v-7488.json b/advisories/unreviewed/2024/09/GHSA-fwj7-298v-7488/GHSA-fwj7-298v-7488.json new file mode 100644 index 00000000000..33742836654 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-fwj7-298v-7488/GHSA-fwj7-298v-7488.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fwj7-298v-7488", + "modified": "2024-09-13T18:31:48Z", + "published": "2024-09-13T18:31:48Z", + "aliases": [ + "CVE-2024-8782" + ], + "details": "A vulnerability was found in JFinalCMS up to 1.0. It has been rated as critical. This issue affects the function delete of the file /admin/template/edit. The manipulation of the argument name leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8782" + }, + { + "type": "WEB", + "url": "https://gitee.com/heyewei/JFinalcms/issues/IAOSJG" + }, + { + "type": "WEB", + "url": "https://github.com/yhy7612/Seccode/blob/main/README1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.277433" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.277433" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.405528" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-g26j-5385-hhw3/GHSA-g26j-5385-hhw3.json b/advisories/unreviewed/2024/09/GHSA-g26j-5385-hhw3/GHSA-g26j-5385-hhw3.json new file mode 100644 index 00000000000..67be8de619f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g26j-5385-hhw3/GHSA-g26j-5385-hhw3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g26j-5385-hhw3", + "modified": "2024-09-13T18:31:47Z", + "published": "2024-09-13T18:31:47Z", + "aliases": [ + "CVE-2024-6587" + ], + "details": "A Server-Side Request Forgery (SSRF) vulnerability exists in berriai/litellm version 1.38.10. This vulnerability allows users to specify the `api_base` parameter when making requests to `POST /chat/completions`, causing the application to send the request to the domain specified by `api_base`. This request includes the OpenAI API key. A malicious user can set the `api_base` to their own domain and intercept the OpenAI API key, leading to unauthorized access and potential misuse of the API key.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6587" + }, + { + "type": "WEB", + "url": "https://github.com/berriai/litellm/commit/ba1912afd1b19e38d3704bb156adf887f91ae1e0" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/4001e1a2-7b7a-4776-a3ae-e6692ec3d997" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T16:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gpg6-84h3-cwv8/GHSA-gpg6-84h3-cwv8.json b/advisories/unreviewed/2024/09/GHSA-gpg6-84h3-cwv8/GHSA-gpg6-84h3-cwv8.json index 16f72ddb53b..146eef548e9 100644 --- a/advisories/unreviewed/2024/09/GHSA-gpg6-84h3-cwv8/GHSA-gpg6-84h3-cwv8.json +++ b/advisories/unreviewed/2024/09/GHSA-gpg6-84h3-cwv8/GHSA-gpg6-84h3-cwv8.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-122" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/09/GHSA-gq5m-j7gp-3x7q/GHSA-gq5m-j7gp-3x7q.json b/advisories/unreviewed/2024/09/GHSA-gq5m-j7gp-3x7q/GHSA-gq5m-j7gp-3x7q.json index bde0fc7f4d3..78c4a735424 100644 --- a/advisories/unreviewed/2024/09/GHSA-gq5m-j7gp-3x7q/GHSA-gq5m-j7gp-3x7q.json +++ b/advisories/unreviewed/2024/09/GHSA-gq5m-j7gp-3x7q/GHSA-gq5m-j7gp-3x7q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gq5m-j7gp-3x7q", - "modified": "2024-09-13T06:30:43Z", + "modified": "2024-09-13T18:31:47Z", "published": "2024-09-13T06:30:43Z", "aliases": [ "CVE-2024-6850" ], "details": "The Carousel Slider WordPress plugin before 2.2.4 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:15Z" diff --git a/advisories/unreviewed/2024/09/GHSA-gr4h-g2ph-j8j2/GHSA-gr4h-g2ph-j8j2.json b/advisories/unreviewed/2024/09/GHSA-gr4h-g2ph-j8j2/GHSA-gr4h-g2ph-j8j2.json index 33ee09c8528..cd358ae8a2a 100644 --- a/advisories/unreviewed/2024/09/GHSA-gr4h-g2ph-j8j2/GHSA-gr4h-g2ph-j8j2.json +++ b/advisories/unreviewed/2024/09/GHSA-gr4h-g2ph-j8j2/GHSA-gr4h-g2ph-j8j2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gr4h-g2ph-j8j2", - "modified": "2024-09-13T06:30:43Z", + "modified": "2024-09-13T18:31:47Z", "published": "2024-09-13T06:30:43Z", "aliases": [ "CVE-2024-6723" ], "details": "The AI Engine WordPress plugin before 2.4.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when viewing chatbot discussions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:15Z" diff --git a/advisories/unreviewed/2024/09/GHSA-gx3x-w926-g8pm/GHSA-gx3x-w926-g8pm.json b/advisories/unreviewed/2024/09/GHSA-gx3x-w926-g8pm/GHSA-gx3x-w926-g8pm.json index f0913d4fd6d..aeb9ceca80c 100644 --- a/advisories/unreviewed/2024/09/GHSA-gx3x-w926-g8pm/GHSA-gx3x-w926-g8pm.json +++ b/advisories/unreviewed/2024/09/GHSA-gx3x-w926-g8pm/GHSA-gx3x-w926-g8pm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gx3x-w926-g8pm", - "modified": "2024-09-13T06:30:43Z", + "modified": "2024-09-13T18:31:47Z", "published": "2024-09-13T06:30:43Z", "aliases": [ "CVE-2024-7133" ], "details": "The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.7.3 does not validate and escape some of its settings before outputting them back in the page, which could allow users with a high role to perform Stored Cross-Site Scripting attacks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:15Z" diff --git a/advisories/unreviewed/2024/09/GHSA-hggx-qfvf-7mfh/GHSA-hggx-qfvf-7mfh.json b/advisories/unreviewed/2024/09/GHSA-hggx-qfvf-7mfh/GHSA-hggx-qfvf-7mfh.json index e6a75c36020..15cc004546b 100644 --- a/advisories/unreviewed/2024/09/GHSA-hggx-qfvf-7mfh/GHSA-hggx-qfvf-7mfh.json +++ b/advisories/unreviewed/2024/09/GHSA-hggx-qfvf-7mfh/GHSA-hggx-qfvf-7mfh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hggx-qfvf-7mfh", - "modified": "2024-09-13T06:30:42Z", + "modified": "2024-09-13T18:31:45Z", "published": "2024-09-13T06:30:42Z", "aliases": [ "CVE-2024-46673" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: aacraid: Fix double-free on probe failure\n\naac_probe_one() calls hardware-specific init functions through the\naac_driver_ident::init pointer, all of which eventually call down to\naac_init_adapter().\n\nIf aac_init_adapter() fails after allocating memory for aac_dev::queues,\nit frees the memory but does not clear that member.\n\nAfter the hardware-specific init function returns an error,\naac_probe_one() goes down an error path that frees the memory pointed to\nby aac_dev::queues, resulting.in a double-free.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-415" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:11Z" diff --git a/advisories/unreviewed/2024/09/GHSA-hwwh-7cg2-3v75/GHSA-hwwh-7cg2-3v75.json b/advisories/unreviewed/2024/09/GHSA-hwwh-7cg2-3v75/GHSA-hwwh-7cg2-3v75.json new file mode 100644 index 00000000000..98ad5c078b8 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-hwwh-7cg2-3v75/GHSA-hwwh-7cg2-3v75.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwwh-7cg2-3v75", + "modified": "2024-09-13T18:31:48Z", + "published": "2024-09-13T18:31:48Z", + "aliases": [ + "CVE-2024-45104" + ], + "details": "A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially crafted web API call.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45104" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-154748" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-282" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-j8r5-27mh-4xh9/GHSA-j8r5-27mh-4xh9.json b/advisories/unreviewed/2024/09/GHSA-j8r5-27mh-4xh9/GHSA-j8r5-27mh-4xh9.json index 55e33b9f8e6..f3fd71c9265 100644 --- a/advisories/unreviewed/2024/09/GHSA-j8r5-27mh-4xh9/GHSA-j8r5-27mh-4xh9.json +++ b/advisories/unreviewed/2024/09/GHSA-j8r5-27mh-4xh9/GHSA-j8r5-27mh-4xh9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j8r5-27mh-4xh9", - "modified": "2024-09-11T18:31:05Z", + "modified": "2024-09-13T18:31:41Z", "published": "2024-09-11T18:31:05Z", "aliases": [ "CVE-2024-45017" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Fix IPsec RoCE MPV trace call\n\nPrevent the call trace below from happening, by not allowing IPsec\ncreation over a slave, if master device doesn't support IPsec.\n\nWARNING: CPU: 44 PID: 16136 at kernel/locking/rwsem.c:240 down_read+0x75/0x94\nModules linked in: esp4_offload esp4 act_mirred act_vlan cls_flower sch_ingress mlx5_vdpa vringh vhost_iotlb vdpa mst_pciconf(OE) nfsv3 nfs_acl nfs lockd grace fscache netfs xt_CHECKSUM xt_MASQUERADE xt_conntrack ipt_REJECT nf_reject_ipv4 nft_compat nft_counter nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 rfkill cuse fuse rpcrdma sunrpc rdma_ucm ib_srpt ib_isert iscsi_target_mod target_core_mod ib_umad ib_iser libiscsi scsi_transport_iscsi rdma_cm ib_ipoib iw_cm ib_cm ipmi_ssif intel_rapl_msr intel_rapl_common amd64_edac edac_mce_amd kvm_amd kvm irqbypass crct10dif_pclmul crc32_pclmul mlx5_ib ghash_clmulni_intel sha1_ssse3 dell_smbios ib_uverbs aesni_intel crypto_simd dcdbas wmi_bmof dell_wmi_descriptor cryptd pcspkr ib_core acpi_ipmi sp5100_tco ccp i2c_piix4 ipmi_si ptdma k10temp ipmi_devintf ipmi_msghandler acpi_power_meter acpi_cpufreq ext4 mbcache jbd2 sd_mod t10_pi sg mgag200 drm_kms_helper syscopyarea sysfillrect mlx5_core sysimgblt fb_sys_fops cec\n ahci libahci mlxfw drm pci_hyperv_intf libata tg3 sha256_ssse3 tls megaraid_sas i2c_algo_bit psample wmi dm_mirror dm_region_hash dm_log dm_mod [last unloaded: mst_pci]\nCPU: 44 PID: 16136 Comm: kworker/44:3 Kdump: loaded Tainted: GOE 5.15.0-20240509.el8uek.uek7_u3_update_v6.6_ipsec_bf.x86_64 #2\nHardware name: Dell Inc. PowerEdge R7525/074H08, BIOS 2.0.3 01/15/2021\nWorkqueue: events xfrm_state_gc_task\nRIP: 0010:down_read+0x75/0x94\nCode: 00 48 8b 45 08 65 48 8b 14 25 80 fc 01 00 83 e0 02 48 09 d0 48 83 c8 01 48 89 45 08 5d 31 c0 89 c2 89 c6 89 c7 e9 cb 88 3b 00 <0f> 0b 48 8b 45 08 a8 01 74 b2 a8 02 75 ae 48 89 c2 48 83 ca 02 f0\nRSP: 0018:ffffb26387773da8 EFLAGS: 00010282\nRAX: 0000000000000000 RBX: ffffa08b658af900 RCX: 0000000000000001\nRDX: 0000000000000000 RSI: ff886bc5e1366f2f RDI: 0000000000000000\nRBP: ffffa08b658af940 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000000 R12: ffffa0a9bfb31540\nR13: ffffa0a9bfb37900 R14: 0000000000000000 R15: ffffa0a9bfb37905\nFS: 0000000000000000(0000) GS:ffffa0a9bfb00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 000055a45ed814e8 CR3: 000000109038a000 CR4: 0000000000350ee0\nCall Trace:\n \n ? show_trace_log_lvl+0x1d6/0x2f9\n ? show_trace_log_lvl+0x1d6/0x2f9\n ? mlx5_devcom_for_each_peer_begin+0x29/0x60 [mlx5_core]\n ? down_read+0x75/0x94\n ? __warn+0x80/0x113\n ? down_read+0x75/0x94\n ? report_bug+0xa4/0x11d\n ? handle_bug+0x35/0x8b\n ? exc_invalid_op+0x14/0x75\n ? asm_exc_invalid_op+0x16/0x1b\n ? down_read+0x75/0x94\n ? down_read+0xe/0x94\n mlx5_devcom_for_each_peer_begin+0x29/0x60 [mlx5_core]\n mlx5_ipsec_fs_roce_tx_destroy+0xb1/0x130 [mlx5_core]\n tx_destroy+0x1b/0xc0 [mlx5_core]\n tx_ft_put+0x53/0xc0 [mlx5_core]\n mlx5e_xfrm_free_state+0x45/0x90 [mlx5_core]\n ___xfrm_state_destroy+0x10f/0x1a2\n xfrm_state_gc_task+0x81/0xa9\n process_one_work+0x1f1/0x3c6\n worker_thread+0x53/0x3e4\n ? process_one_work.cold+0x46/0x3c\n kthread+0x127/0x144\n ? set_kthread_struct+0x60/0x52\n ret_from_fork+0x22/0x2d\n \n---[ end trace 5ef7896144d398e1 ]---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T16:15:06Z" diff --git a/advisories/unreviewed/2024/09/GHSA-jf76-2c3p-rhc5/GHSA-jf76-2c3p-rhc5.json b/advisories/unreviewed/2024/09/GHSA-jf76-2c3p-rhc5/GHSA-jf76-2c3p-rhc5.json index 48fb462f66e..c520547a05e 100644 --- a/advisories/unreviewed/2024/09/GHSA-jf76-2c3p-rhc5/GHSA-jf76-2c3p-rhc5.json +++ b/advisories/unreviewed/2024/09/GHSA-jf76-2c3p-rhc5/GHSA-jf76-2c3p-rhc5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jf76-2c3p-rhc5", - "modified": "2024-09-11T18:31:06Z", + "modified": "2024-09-13T18:31:42Z", "published": "2024-09-11T18:31:06Z", "aliases": [ "CVE-2024-45020" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix a kernel verifier crash in stacksafe()\n\nDaniel Hodges reported a kernel verifier crash when playing with sched-ext.\nFurther investigation shows that the crash is due to invalid memory access\nin stacksafe(). More specifically, it is the following code:\n\n if (exact != NOT_EXACT &&\n old->stack[spi].slot_type[i % BPF_REG_SIZE] !=\n cur->stack[spi].slot_type[i % BPF_REG_SIZE])\n return false;\n\nThe 'i' iterates old->allocated_stack.\nIf cur->allocated_stack < old->allocated_stack the out-of-bound\naccess will happen.\n\nTo fix the issue add 'i >= cur->allocated_stack' check such that if\nthe condition is true, stacksafe() should fail. Otherwise,\ncur->stack[spi].slot_type[i % BPF_REG_SIZE] memory access is legal.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T16:15:07Z" diff --git a/advisories/unreviewed/2024/09/GHSA-jfgw-v3p5-42qh/GHSA-jfgw-v3p5-42qh.json b/advisories/unreviewed/2024/09/GHSA-jfgw-v3p5-42qh/GHSA-jfgw-v3p5-42qh.json index db639ac0253..b3bcc960a96 100644 --- a/advisories/unreviewed/2024/09/GHSA-jfgw-v3p5-42qh/GHSA-jfgw-v3p5-42qh.json +++ b/advisories/unreviewed/2024/09/GHSA-jfgw-v3p5-42qh/GHSA-jfgw-v3p5-42qh.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jfgw-v3p5-42qh", - "modified": "2024-09-11T21:30:36Z", + "modified": "2024-09-13T18:31:42Z", "published": "2024-09-11T18:31:07Z", "aliases": [ "CVE-2024-7312" ], "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects Payara Server: from 6.0.0 before 6.18.0, from 6.2022.1 before 6.2024.9, from 5.2020.2 before 5.2022.5, from 5.20.0 before 5.67.0, from 4.1.2.191.0 before 4.1.2.191.50.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-jfrm-qx4v-5m72/GHSA-jfrm-qx4v-5m72.json b/advisories/unreviewed/2024/09/GHSA-jfrm-qx4v-5m72/GHSA-jfrm-qx4v-5m72.json new file mode 100644 index 00000000000..feaccdbf027 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-jfrm-qx4v-5m72/GHSA-jfrm-qx4v-5m72.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfrm-qx4v-5m72", + "modified": "2024-09-13T18:31:48Z", + "published": "2024-09-13T18:31:48Z", + "aliases": [ + "CVE-2024-8278" + ], + "details": "A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially crafted IPMI commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8278" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-172051" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T18:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-jhgj-6hmm-vm6v/GHSA-jhgj-6hmm-vm6v.json b/advisories/unreviewed/2024/09/GHSA-jhgj-6hmm-vm6v/GHSA-jhgj-6hmm-vm6v.json new file mode 100644 index 00000000000..3dde404e251 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-jhgj-6hmm-vm6v/GHSA-jhgj-6hmm-vm6v.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhgj-6hmm-vm6v", + "modified": "2024-09-13T18:31:47Z", + "published": "2024-09-13T18:31:47Z", + "aliases": [ + "CVE-2024-44685" + ], + "details": "Titan SFTP and Titan MFT Server 2.0.25.2426 and earlier have a vulnerability a vulnerability where sensitive information, including passwords, is exposed in clear text within the JSON response when configuring SMTP settings via the Web UI.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44685" + }, + { + "type": "WEB", + "url": "https://github.com/ShellFighter/Reports/blob/main/Titan%20MFT%20Server.md" + }, + { + "type": "WEB", + "url": "https://helpdesk.southrivertech.com/portal/en/kb/articles/security-patch-for-cve-2024-44685" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T16:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-jhh2-7qpr-2pv5/GHSA-jhh2-7qpr-2pv5.json b/advisories/unreviewed/2024/09/GHSA-jhh2-7qpr-2pv5/GHSA-jhh2-7qpr-2pv5.json index bfff8143ac5..dfbe41d7a0c 100644 --- a/advisories/unreviewed/2024/09/GHSA-jhh2-7qpr-2pv5/GHSA-jhh2-7qpr-2pv5.json +++ b/advisories/unreviewed/2024/09/GHSA-jhh2-7qpr-2pv5/GHSA-jhh2-7qpr-2pv5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jhh2-7qpr-2pv5", - "modified": "2024-09-13T15:31:34Z", + "modified": "2024-09-13T18:31:47Z", "published": "2024-09-13T15:31:34Z", "aliases": [ "CVE-2024-46045" ], "details": "Tenda CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the frmL7PlotForm function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T14:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-jm4p-4c99-gp7x/GHSA-jm4p-4c99-gp7x.json b/advisories/unreviewed/2024/09/GHSA-jm4p-4c99-gp7x/GHSA-jm4p-4c99-gp7x.json new file mode 100644 index 00000000000..fdd0a44a91a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-jm4p-4c99-gp7x/GHSA-jm4p-4c99-gp7x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jm4p-4c99-gp7x", + "modified": "2024-09-13T18:31:47Z", + "published": "2024-09-13T18:31:47Z", + "aliases": [ + "CVE-2024-44798" + ], + "details": "phpgurukul Bus Pass Management System 1.0 is vulnerable to Cross-site scripting (XSS) in /admin/pass-bwdates-reports-details.php via fromdate and todate parameters.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44798" + }, + { + "type": "WEB", + "url": "https://github.com/shouvikdutta1998/Bus_management" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T16:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-jrpv-cgg9-hfmj/GHSA-jrpv-cgg9-hfmj.json b/advisories/unreviewed/2024/09/GHSA-jrpv-cgg9-hfmj/GHSA-jrpv-cgg9-hfmj.json index 4a0dd0d57f7..f4652a2e291 100644 --- a/advisories/unreviewed/2024/09/GHSA-jrpv-cgg9-hfmj/GHSA-jrpv-cgg9-hfmj.json +++ b/advisories/unreviewed/2024/09/GHSA-jrpv-cgg9-hfmj/GHSA-jrpv-cgg9-hfmj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jrpv-cgg9-hfmj", - "modified": "2024-09-11T18:31:06Z", + "modified": "2024-09-13T18:31:42Z", "published": "2024-09-11T18:31:06Z", "aliases": [ "CVE-2024-45018" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: flowtable: initialise extack before use\n\nFix missing initialisation of extack in flow offload.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-665" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T16:15:06Z" diff --git a/advisories/unreviewed/2024/09/GHSA-m2wr-9pq6-49jc/GHSA-m2wr-9pq6-49jc.json b/advisories/unreviewed/2024/09/GHSA-m2wr-9pq6-49jc/GHSA-m2wr-9pq6-49jc.json index d7baf3ca4cc..2230ea4b559 100644 --- a/advisories/unreviewed/2024/09/GHSA-m2wr-9pq6-49jc/GHSA-m2wr-9pq6-49jc.json +++ b/advisories/unreviewed/2024/09/GHSA-m2wr-9pq6-49jc/GHSA-m2wr-9pq6-49jc.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-m3hv-89f3-wrrc/GHSA-m3hv-89f3-wrrc.json b/advisories/unreviewed/2024/09/GHSA-m3hv-89f3-wrrc/GHSA-m3hv-89f3-wrrc.json index e2bfcf62bfe..4194e6775c8 100644 --- a/advisories/unreviewed/2024/09/GHSA-m3hv-89f3-wrrc/GHSA-m3hv-89f3-wrrc.json +++ b/advisories/unreviewed/2024/09/GHSA-m3hv-89f3-wrrc/GHSA-m3hv-89f3-wrrc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m3hv-89f3-wrrc", - "modified": "2024-09-11T18:31:06Z", + "modified": "2024-09-13T18:31:42Z", "published": "2024-09-11T18:31:06Z", "aliases": [ "CVE-2024-45027" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: xhci: Check for xhci->interrupters being allocated in xhci_mem_clearup()\n\nIf xhci_mem_init() fails, it calls into xhci_mem_cleanup() to mop\nup the damage. If it fails early enough, before xhci->interrupters\nis allocated but after xhci->max_interrupters has been set, which\nhappens in most (all?) cases, things get uglier, as xhci_mem_cleanup()\nunconditionally derefences xhci->interrupters. With prejudice.\n\nGate the interrupt freeing loop with a check on xhci->interrupters\nbeing non-NULL.\n\nFound while debugging a DMA allocation issue that led the XHCI driver\non this exact path.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-459" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T16:15:07Z" diff --git a/advisories/unreviewed/2024/09/GHSA-m48w-79jh-f8w7/GHSA-m48w-79jh-f8w7.json b/advisories/unreviewed/2024/09/GHSA-m48w-79jh-f8w7/GHSA-m48w-79jh-f8w7.json index cbe9afd7c94..e436bf50c5d 100644 --- a/advisories/unreviewed/2024/09/GHSA-m48w-79jh-f8w7/GHSA-m48w-79jh-f8w7.json +++ b/advisories/unreviewed/2024/09/GHSA-m48w-79jh-f8w7/GHSA-m48w-79jh-f8w7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m48w-79jh-f8w7", - "modified": "2024-09-12T21:32:02Z", + "modified": "2024-09-13T18:31:45Z", "published": "2024-09-12T21:32:02Z", "aliases": [ "CVE-2024-25270" ], "details": "An issue in Mirapolis LMS 4.6.XX allows authenticated users to exploit an Insecure Direct Object Reference (IDOR) vulnerability by manipulating the ID parameter and increment STEP parameter, leading to the exposure of sensitive user data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-639" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-12T19:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-mfw6-959v-265j/GHSA-mfw6-959v-265j.json b/advisories/unreviewed/2024/09/GHSA-mfw6-959v-265j/GHSA-mfw6-959v-265j.json index 31c801f1e6d..a9848379ac0 100644 --- a/advisories/unreviewed/2024/09/GHSA-mfw6-959v-265j/GHSA-mfw6-959v-265j.json +++ b/advisories/unreviewed/2024/09/GHSA-mfw6-959v-265j/GHSA-mfw6-959v-265j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mfw6-959v-265j", - "modified": "2024-09-11T18:31:05Z", + "modified": "2024-09-13T18:31:41Z", "published": "2024-09-11T18:31:05Z", "aliases": [ "CVE-2024-45010" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: only mark 'subflow' endp as available\n\nAdding the following warning ...\n\n WARN_ON_ONCE(msk->pm.local_addr_used == 0)\n\n... before decrementing the local_addr_used counter helped to find a bug\nwhen running the \"remove single address\" subtest from the mptcp_join.sh\nselftests.\n\nRemoving a 'signal' endpoint will trigger the removal of all subflows\nlinked to this endpoint via mptcp_pm_nl_rm_addr_or_subflow() with\nrm_type == MPTCP_MIB_RMSUBFLOW. This will decrement the local_addr_used\ncounter, which is wrong in this case because this counter is linked to\n'subflow' endpoints, and here it is a 'signal' endpoint that is being\nremoved.\n\nNow, the counter is decremented, only if the ID is being used outside\nof mptcp_pm_nl_rm_addr_or_subflow(), only for 'subflow' endpoints, and\nif the ID is not 0 -- local_addr_used is not taking into account these\nones. This marking of the ID as being available, and the decrement is\ndone no matter if a subflow using this ID is currently available,\nbecause the subflow could have been closed before.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T16:15:06Z" diff --git a/advisories/unreviewed/2024/09/GHSA-mpm4-ggh2-c745/GHSA-mpm4-ggh2-c745.json b/advisories/unreviewed/2024/09/GHSA-mpm4-ggh2-c745/GHSA-mpm4-ggh2-c745.json index dcbfa4c454b..bf53624c756 100644 --- a/advisories/unreviewed/2024/09/GHSA-mpm4-ggh2-c745/GHSA-mpm4-ggh2-c745.json +++ b/advisories/unreviewed/2024/09/GHSA-mpm4-ggh2-c745/GHSA-mpm4-ggh2-c745.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mpm4-ggh2-c745", - "modified": "2024-09-13T06:30:43Z", + "modified": "2024-09-13T18:31:46Z", "published": "2024-09-13T06:30:43Z", "aliases": [ "CVE-2024-46699" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Disable preemption while updating GPU stats\n\nWe forgot to disable preemption around the write_seqcount_begin/end() pair\nwhile updating GPU stats:\n\n [ ] WARNING: CPU: 2 PID: 12 at include/linux/seqlock.h:221 __seqprop_assert.isra.0+0x128/0x150 [v3d]\n [ ] Workqueue: v3d_bin drm_sched_run_job_work [gpu_sched]\n <...snip...>\n [ ] Call trace:\n [ ] __seqprop_assert.isra.0+0x128/0x150 [v3d]\n [ ] v3d_job_start_stats.isra.0+0x90/0x218 [v3d]\n [ ] v3d_bin_job_run+0x23c/0x388 [v3d]\n [ ] drm_sched_run_job_work+0x520/0x6d0 [gpu_sched]\n [ ] process_one_work+0x62c/0xb48\n [ ] worker_thread+0x468/0x5b0\n [ ] kthread+0x1c4/0x1e0\n [ ] ret_from_fork+0x10/0x20\n\nFix it.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-p5f6-v7vq-6742/GHSA-p5f6-v7vq-6742.json b/advisories/unreviewed/2024/09/GHSA-p5f6-v7vq-6742/GHSA-p5f6-v7vq-6742.json new file mode 100644 index 00000000000..46a65114f88 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-p5f6-v7vq-6742/GHSA-p5f6-v7vq-6742.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5f6-v7vq-6742", + "modified": "2024-09-13T18:31:48Z", + "published": "2024-09-13T18:31:48Z", + "aliases": [ + "CVE-2024-45103" + ], + "details": "A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45103" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-154748" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-282" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-p5xc-g9x9-74jh/GHSA-p5xc-g9x9-74jh.json b/advisories/unreviewed/2024/09/GHSA-p5xc-g9x9-74jh/GHSA-p5xc-g9x9-74jh.json index 3120a5eb309..ccb7c5d754b 100644 --- a/advisories/unreviewed/2024/09/GHSA-p5xc-g9x9-74jh/GHSA-p5xc-g9x9-74jh.json +++ b/advisories/unreviewed/2024/09/GHSA-p5xc-g9x9-74jh/GHSA-p5xc-g9x9-74jh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p5xc-g9x9-74jh", - "modified": "2024-09-11T18:31:06Z", + "modified": "2024-09-13T18:31:42Z", "published": "2024-09-11T18:31:06Z", "aliases": [ "CVE-2024-45023" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid1: Fix data corruption for degraded array with slow disk\n\nread_balance() will avoid reading from slow disks as much as possible,\nhowever, if valid data only lands in slow disks, and a new normal disk\nis still in recovery, unrecovered data can be read:\n\nraid1_read_request\n read_balance\n raid1_should_read_first\n -> return false\n choose_best_rdev\n -> normal disk is not recovered, return -1\n choose_bb_rdev\n -> missing the checking of recovery, return the normal disk\n -> read unrecovered data\n\nRoot cause is that the checking of recovery is missing in\nchoose_bb_rdev(). Hence add such checking to fix the problem.\n\nAlso fix similar problem in choose_slow_rdev().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T16:15:07Z" diff --git a/advisories/unreviewed/2024/09/GHSA-p9p3-pvmx-pxrh/GHSA-p9p3-pvmx-pxrh.json b/advisories/unreviewed/2024/09/GHSA-p9p3-pvmx-pxrh/GHSA-p9p3-pvmx-pxrh.json index c5dca3ff8f9..6cb88a78847 100644 --- a/advisories/unreviewed/2024/09/GHSA-p9p3-pvmx-pxrh/GHSA-p9p3-pvmx-pxrh.json +++ b/advisories/unreviewed/2024/09/GHSA-p9p3-pvmx-pxrh/GHSA-p9p3-pvmx-pxrh.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-77", "CWE-94" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/09/GHSA-pc7p-wr8c-6r5f/GHSA-pc7p-wr8c-6r5f.json b/advisories/unreviewed/2024/09/GHSA-pc7p-wr8c-6r5f/GHSA-pc7p-wr8c-6r5f.json index 29e02814d70..41c4e5de8a6 100644 --- a/advisories/unreviewed/2024/09/GHSA-pc7p-wr8c-6r5f/GHSA-pc7p-wr8c-6r5f.json +++ b/advisories/unreviewed/2024/09/GHSA-pc7p-wr8c-6r5f/GHSA-pc7p-wr8c-6r5f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pc7p-wr8c-6r5f", - "modified": "2024-09-11T18:31:07Z", + "modified": "2024-09-13T18:31:42Z", "published": "2024-09-11T18:31:07Z", "aliases": [ "CVE-2024-45030" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nigb: cope with large MAX_SKB_FRAGS\n\nSabrina reports that the igb driver does not cope well with large\nMAX_SKB_FRAG values: setting MAX_SKB_FRAG to 45 causes payload\ncorruption on TX.\n\nAn easy reproducer is to run ssh to connect to the machine. With\nMAX_SKB_FRAGS=17 it works, with MAX_SKB_FRAGS=45 it fails. This has\nbeen reported originally in\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2265320\n\nThe root cause of the issue is that the driver does not take into\naccount properly the (possibly large) shared info size when selecting\nthe ring layout, and will try to fit two packets inside the same 4K\npage even when the 1st fraglist will trump over the 2nd head.\n\nAddress the issue by checking if 2K buffers are insufficient.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T16:15:07Z" diff --git a/advisories/unreviewed/2024/09/GHSA-q53p-qm4c-c2wj/GHSA-q53p-qm4c-c2wj.json b/advisories/unreviewed/2024/09/GHSA-q53p-qm4c-c2wj/GHSA-q53p-qm4c-c2wj.json index db2f2a522f8..65a41c96879 100644 --- a/advisories/unreviewed/2024/09/GHSA-q53p-qm4c-c2wj/GHSA-q53p-qm4c-c2wj.json +++ b/advisories/unreviewed/2024/09/GHSA-q53p-qm4c-c2wj/GHSA-q53p-qm4c-c2wj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q53p-qm4c-c2wj", - "modified": "2024-09-11T18:31:05Z", + "modified": "2024-09-13T18:31:41Z", "published": "2024-09-11T18:31:05Z", "aliases": [ "CVE-2024-45016" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetem: fix return value if duplicate enqueue fails\n\nThere is a bug in netem_enqueue() introduced by\ncommit 5845f706388a (\"net: netem: fix skb length BUG_ON in __skb_to_sgvec\")\nthat can lead to a use-after-free.\n\nThis commit made netem_enqueue() always return NET_XMIT_SUCCESS\nwhen a packet is duplicated, which can cause the parent qdisc's q.qlen\nto be mistakenly incremented. When this happens qlen_notify() may be\nskipped on the parent during destruction, leaving a dangling pointer\nfor some classful qdiscs like DRR.\n\nThere are two ways for the bug happen:\n\n- If the duplicated packet is dropped by rootq->enqueue() and then\n the original packet is also dropped.\n- If rootq->enqueue() sends the duplicated packet to a different qdisc\n and the original packet is dropped.\n\nIn both cases NET_XMIT_SUCCESS is returned even though no packets\nare enqueued at the netem qdisc.\n\nThe fix is to defer the enqueue of the duplicate packet until after\nthe original packet has been guaranteed to return NET_XMIT_SUCCESS.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T16:15:06Z" diff --git a/advisories/unreviewed/2024/09/GHSA-q7vm-868g-mvqm/GHSA-q7vm-868g-mvqm.json b/advisories/unreviewed/2024/09/GHSA-q7vm-868g-mvqm/GHSA-q7vm-868g-mvqm.json new file mode 100644 index 00000000000..ec2cc84a264 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-q7vm-868g-mvqm/GHSA-q7vm-868g-mvqm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7vm-868g-mvqm", + "modified": "2024-09-13T18:31:48Z", + "published": "2024-09-13T18:31:48Z", + "aliases": [ + "CVE-2024-7756" + ], + "details": "A potential vulnerability was reported in the ThinkPad L390 Yoga and 10w Notebook that could allow a local attacker to escalate privileges by accessing an embedded UEFI shell.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7756" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-165524" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-489" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T18:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-q993-jv9q-jjjm/GHSA-q993-jv9q-jjjm.json b/advisories/unreviewed/2024/09/GHSA-q993-jv9q-jjjm/GHSA-q993-jv9q-jjjm.json index 9c46e1cb6cc..357804b7d95 100644 --- a/advisories/unreviewed/2024/09/GHSA-q993-jv9q-jjjm/GHSA-q993-jv9q-jjjm.json +++ b/advisories/unreviewed/2024/09/GHSA-q993-jv9q-jjjm/GHSA-q993-jv9q-jjjm.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-122" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/09/GHSA-r268-64hq-mv45/GHSA-r268-64hq-mv45.json b/advisories/unreviewed/2024/09/GHSA-r268-64hq-mv45/GHSA-r268-64hq-mv45.json index ed8398b741f..a26e2b44b3b 100644 --- a/advisories/unreviewed/2024/09/GHSA-r268-64hq-mv45/GHSA-r268-64hq-mv45.json +++ b/advisories/unreviewed/2024/09/GHSA-r268-64hq-mv45/GHSA-r268-64hq-mv45.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-611" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-r3gx-4wx6-8mr3/GHSA-r3gx-4wx6-8mr3.json b/advisories/unreviewed/2024/09/GHSA-r3gx-4wx6-8mr3/GHSA-r3gx-4wx6-8mr3.json index aec439f112d..a94516482cb 100644 --- a/advisories/unreviewed/2024/09/GHSA-r3gx-4wx6-8mr3/GHSA-r3gx-4wx6-8mr3.json +++ b/advisories/unreviewed/2024/09/GHSA-r3gx-4wx6-8mr3/GHSA-r3gx-4wx6-8mr3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r3gx-4wx6-8mr3", - "modified": "2024-09-13T06:30:42Z", + "modified": "2024-09-13T18:31:46Z", "published": "2024-09-13T06:30:42Z", "aliases": [ "CVE-2024-46674" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: dwc3: st: fix probed platform device ref count on probe error path\n\nThe probe function never performs any paltform device allocation, thus\nerror path \"undo_platform_dev_alloc\" is entirely bogus. It drops the\nreference count from the platform device being probed. If error path is\ntriggered, this will lead to unbalanced device reference counts and\npremature release of device resources, thus possible use-after-free when\nreleasing remaining devm-managed resources.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:12Z" diff --git a/advisories/unreviewed/2024/09/GHSA-r89w-9fr4-c7c9/GHSA-r89w-9fr4-c7c9.json b/advisories/unreviewed/2024/09/GHSA-r89w-9fr4-c7c9/GHSA-r89w-9fr4-c7c9.json new file mode 100644 index 00000000000..9ac96bbfad3 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-r89w-9fr4-c7c9/GHSA-r89w-9fr4-c7c9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r89w-9fr4-c7c9", + "modified": "2024-09-13T18:31:48Z", + "published": "2024-09-13T18:31:48Z", + "aliases": [ + "CVE-2024-39925" + ], + "details": "An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. It lacks an offboarding process for members who leave an organization. As a result, the shared organization key is not rotated when a member departs. Consequently, the departing member, whose access should be revoked, retains a copy of the organization key. Additionally, the application fails to adequately protect some encrypted data stored on the server. Consequently, an authenticated user could gain unauthorized access to encrypted data of any organization, even if the user is not a member of the targeted organization. However, the user would need to know the corresponding organizationId. Hence, if a user (whose access to an organization has been revoked) already possesses the organization key, that user could use the key to decrypt the leaked data.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39925" + }, + { + "type": "WEB", + "url": "https://github.com/dani-garcia/vaultwarden/releases" + }, + { + "type": "WEB", + "url": "https://github.com/dani-garcia/vaultwarden/releases/tag/1.32.0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T18:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-rhqc-rfxh-qj7g/GHSA-rhqc-rfxh-qj7g.json b/advisories/unreviewed/2024/09/GHSA-rhqc-rfxh-qj7g/GHSA-rhqc-rfxh-qj7g.json index 78b0a45fa7f..92c925a5093 100644 --- a/advisories/unreviewed/2024/09/GHSA-rhqc-rfxh-qj7g/GHSA-rhqc-rfxh-qj7g.json +++ b/advisories/unreviewed/2024/09/GHSA-rhqc-rfxh-qj7g/GHSA-rhqc-rfxh-qj7g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rhqc-rfxh-qj7g", - "modified": "2024-09-12T12:30:28Z", + "modified": "2024-09-13T18:31:41Z", "published": "2024-09-11T18:31:04Z", "aliases": [ "CVE-2024-45009" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: only decrement add_addr_accepted for MPJ req\n\nAdding the following warning ...\n\n WARN_ON_ONCE(msk->pm.add_addr_accepted == 0)\n\n... before decrementing the add_addr_accepted counter helped to find a\nbug when running the \"remove single subflow\" subtest from the\nmptcp_join.sh selftest.\n\nRemoving a 'subflow' endpoint will first trigger a RM_ADDR, then the\nsubflow closure. Before this patch, and upon the reception of the\nRM_ADDR, the other peer will then try to decrement this\nadd_addr_accepted. That's not correct because the attached subflows have\nnot been created upon the reception of an ADD_ADDR.\n\nA way to solve that is to decrement the counter only if the attached\nsubflow was an MP_JOIN to a remote id that was not 0, and initiated by\nthe host receiving the RM_ADDR.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T16:15:06Z" diff --git a/advisories/unreviewed/2024/09/GHSA-rp3x-cq62-cvh4/GHSA-rp3x-cq62-cvh4.json b/advisories/unreviewed/2024/09/GHSA-rp3x-cq62-cvh4/GHSA-rp3x-cq62-cvh4.json index f83e15bac4d..43c5a448a32 100644 --- a/advisories/unreviewed/2024/09/GHSA-rp3x-cq62-cvh4/GHSA-rp3x-cq62-cvh4.json +++ b/advisories/unreviewed/2024/09/GHSA-rp3x-cq62-cvh4/GHSA-rp3x-cq62-cvh4.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-v6x6-4v4x-2fx9/GHSA-v6x6-4v4x-2fx9.json b/advisories/unreviewed/2024/09/GHSA-v6x6-4v4x-2fx9/GHSA-v6x6-4v4x-2fx9.json new file mode 100644 index 00000000000..83eb725eb97 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-v6x6-4v4x-2fx9/GHSA-v6x6-4v4x-2fx9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6x6-4v4x-2fx9", + "modified": "2024-09-13T18:31:48Z", + "published": "2024-09-13T18:31:48Z", + "aliases": [ + "CVE-2024-6862" + ], + "details": "A Cross-Site Request Forgery (CSRF) vulnerability exists in lunary-ai/lunary version 1.2.34 due to overly permissive CORS settings. This vulnerability allows an attacker to sign up for and create projects or use the instance as if they were a user with local access. The main attack vector is for instances hosted locally on personal machines, which are not publicly accessible. The CORS settings in the backend permit all origins, exposing unauthenticated endpoints to CSRF attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6862" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/3451fcd7b9d95e9091d62c515752f39f2faa6e54" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/0b1d851e-3455-480c-ad5a-23565894976f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vfwm-h968-g65h/GHSA-vfwm-h968-g65h.json b/advisories/unreviewed/2024/09/GHSA-vfwm-h968-g65h/GHSA-vfwm-h968-g65h.json new file mode 100644 index 00000000000..35044b5fc1b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vfwm-h968-g65h/GHSA-vfwm-h968-g65h.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfwm-h968-g65h", + "modified": "2024-09-13T18:31:48Z", + "published": "2024-09-13T18:31:48Z", + "aliases": [ + "CVE-2024-39926" + ], + "details": "An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A stored cross-site scripting (XSS) or, due to the default CSP, HTML injection vulnerability has been discovered in the admin dashboard. This potentially allows an authenticated attacker to inject malicious code into the dashboard, which is then executed or rendered in the context of an administrator's browser when viewing the injected content. However, it is important to note that the default Content Security Policy (CSP) of the application blocks most exploitation paths, significantly mitigating the potential impact.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39926" + }, + { + "type": "WEB", + "url": "https://github.com/dani-garcia/vaultwarden/blob/1.30.3/src/static/scripts/admin_users.js#L201" + }, + { + "type": "WEB", + "url": "https://github.com/dani-garcia/vaultwarden/releases/tag/1.32.0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vg62-5q72-657x/GHSA-vg62-5q72-657x.json b/advisories/unreviewed/2024/09/GHSA-vg62-5q72-657x/GHSA-vg62-5q72-657x.json index 0080d4202ca..aefa55ab41c 100644 --- a/advisories/unreviewed/2024/09/GHSA-vg62-5q72-657x/GHSA-vg62-5q72-657x.json +++ b/advisories/unreviewed/2024/09/GHSA-vg62-5q72-657x/GHSA-vg62-5q72-657x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vg62-5q72-657x", - "modified": "2024-09-13T15:31:34Z", + "modified": "2024-09-13T18:31:47Z", "published": "2024-09-13T15:31:34Z", "aliases": [ "CVE-2024-46047" ], "details": "Tenda FH451 v1.0.0.9 has a stack overflow vulnerability in the fromDhcpListClient function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T14:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-vp87-57rp-pq64/GHSA-vp87-57rp-pq64.json b/advisories/unreviewed/2024/09/GHSA-vp87-57rp-pq64/GHSA-vp87-57rp-pq64.json new file mode 100644 index 00000000000..4cffe842f59 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vp87-57rp-pq64/GHSA-vp87-57rp-pq64.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vp87-57rp-pq64", + "modified": "2024-09-13T18:31:48Z", + "published": "2024-09-13T18:31:48Z", + "aliases": [ + "CVE-2024-8279" + ], + "details": "A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially crafted file uploads.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8279" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-172051" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T18:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-w25j-fg8w-7xmx/GHSA-w25j-fg8w-7xmx.json b/advisories/unreviewed/2024/09/GHSA-w25j-fg8w-7xmx/GHSA-w25j-fg8w-7xmx.json new file mode 100644 index 00000000000..454412cda7d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-w25j-fg8w-7xmx/GHSA-w25j-fg8w-7xmx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w25j-fg8w-7xmx", + "modified": "2024-09-13T18:31:48Z", + "published": "2024-09-13T18:31:48Z", + "aliases": [ + "CVE-2024-8281" + ], + "details": "An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection through specially crafted command line input in the XCC SSH captive shell.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8281" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-172051" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-w6fj-6wrc-6vhr/GHSA-w6fj-6wrc-6vhr.json b/advisories/unreviewed/2024/09/GHSA-w6fj-6wrc-6vhr/GHSA-w6fj-6wrc-6vhr.json index 162149fe2cc..6b21d35290d 100644 --- a/advisories/unreviewed/2024/09/GHSA-w6fj-6wrc-6vhr/GHSA-w6fj-6wrc-6vhr.json +++ b/advisories/unreviewed/2024/09/GHSA-w6fj-6wrc-6vhr/GHSA-w6fj-6wrc-6vhr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w6fj-6wrc-6vhr", - "modified": "2024-09-13T06:30:42Z", + "modified": "2024-09-13T18:31:46Z", "published": "2024-09-13T06:30:42Z", "aliases": [ "CVE-2024-46683" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: prevent UAF around preempt fence\n\nThe fence lock is part of the queue, therefore in the current design\nanything locking the fence should then also hold a ref to the queue to\nprevent the queue from being freed.\n\nHowever, currently it looks like we signal the fence and then drop the\nqueue ref, but if something is waiting on the fence, the waiter is\nkicked to wake up at some later point, where upon waking up it first\ngrabs the lock before checking the fence state. But if we have already\ndropped the queue ref, then the lock might already be freed as part of\nthe queue, leading to uaf.\n\nTo prevent this, move the fence lock into the fence itself so we don't\nrun into lifetime issues. Alternative might be to have device level\nlock, or only release the queue in the fence release callback, however\nthat might require pushing to another worker to avoid locking issues.\n\nReferences: https://gitlab.freedesktop.org/drm/xe/kernel/-/issues/2454\nReferences: https://gitlab.freedesktop.org/drm/xe/kernel/-/issues/2342\nReferences: https://gitlab.freedesktop.org/drm/xe/kernel/-/issues/2020\n(cherry picked from commit 7116c35aacedc38be6d15bd21b2fc936eed0008b)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:12Z" diff --git a/advisories/unreviewed/2024/09/GHSA-w73r-8mm4-cfvf/GHSA-w73r-8mm4-cfvf.json b/advisories/unreviewed/2024/09/GHSA-w73r-8mm4-cfvf/GHSA-w73r-8mm4-cfvf.json new file mode 100644 index 00000000000..224842b106f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-w73r-8mm4-cfvf/GHSA-w73r-8mm4-cfvf.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w73r-8mm4-cfvf", + "modified": "2024-09-13T18:31:48Z", + "published": "2024-09-13T18:31:48Z", + "aliases": [ + "CVE-2024-6582" + ], + "details": "A broken access control vulnerability exists in the latest version of lunary-ai/lunary. The `saml.ts` file allows a user from one organization to update the Identity Provider (IDP) settings and view the SSO metadata of another organization. This vulnerability can lead to unauthorized access and potential account takeover if the email of a user in the target organization is known.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6582" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/1f043d8798ad87346dfe378eea723bff78ad7433" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/251d138c-3911-4a81-96e5-5a4ab59a0b59" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-w8pf-f5g8-5xgv/GHSA-w8pf-f5g8-5xgv.json b/advisories/unreviewed/2024/09/GHSA-w8pf-f5g8-5xgv/GHSA-w8pf-f5g8-5xgv.json index 32ec9195b2f..d811fb4bb97 100644 --- a/advisories/unreviewed/2024/09/GHSA-w8pf-f5g8-5xgv/GHSA-w8pf-f5g8-5xgv.json +++ b/advisories/unreviewed/2024/09/GHSA-w8pf-f5g8-5xgv/GHSA-w8pf-f5g8-5xgv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w8pf-f5g8-5xgv", - "modified": "2024-09-13T06:30:43Z", + "modified": "2024-09-13T18:31:47Z", "published": "2024-09-13T06:30:43Z", "aliases": [ "CVE-2024-6493" ], "details": "The NinjaTeam Header Footer Custom Code WordPress plugin before 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:15Z" diff --git a/advisories/unreviewed/2024/09/GHSA-wcv7-2grg-g5qr/GHSA-wcv7-2grg-g5qr.json b/advisories/unreviewed/2024/09/GHSA-wcv7-2grg-g5qr/GHSA-wcv7-2grg-g5qr.json new file mode 100644 index 00000000000..d99a4b36308 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-wcv7-2grg-g5qr/GHSA-wcv7-2grg-g5qr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wcv7-2grg-g5qr", + "modified": "2024-09-13T18:31:48Z", + "published": "2024-09-13T18:31:48Z", + "aliases": [ + "CVE-2024-3100" + ], + "details": "A potential buffer overflow vulnerability was reported in some Lenovo Notebook products that could allow a local attacker with elevated privileges to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3100" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-165524" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-ww57-48hq-5w83/GHSA-ww57-48hq-5w83.json b/advisories/unreviewed/2024/09/GHSA-ww57-48hq-5w83/GHSA-ww57-48hq-5w83.json index bb35509e268..8d6076eb5b2 100644 --- a/advisories/unreviewed/2024/09/GHSA-ww57-48hq-5w83/GHSA-ww57-48hq-5w83.json +++ b/advisories/unreviewed/2024/09/GHSA-ww57-48hq-5w83/GHSA-ww57-48hq-5w83.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ww57-48hq-5w83", - "modified": "2024-09-11T18:31:07Z", + "modified": "2024-09-13T18:31:42Z", "published": "2024-09-11T18:31:07Z", "aliases": [ "CVE-2024-45029" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: tegra: Do not mark ACPI devices as irq safe\n\nOn ACPI machines, the tegra i2c module encounters an issue due to a\nmutex being called inside a spinlock. This leads to the following bug:\n\n\tBUG: sleeping function called from invalid context at kernel/locking/mutex.c:585\n\t...\n\n\tCall trace:\n\t__might_sleep\n\t__mutex_lock_common\n\tmutex_lock_nested\n\tacpi_subsys_runtime_resume\n\trpm_resume\n\ttegra_i2c_xfer\n\nThe problem arises because during __pm_runtime_resume(), the spinlock\n&dev->power.lock is acquired before rpm_resume() is called. Later,\nrpm_resume() invokes acpi_subsys_runtime_resume(), which relies on\nmutexes, triggering the error.\n\nTo address this issue, devices on ACPI are now marked as not IRQ-safe,\nconsidering the dependency of acpi_subsys_runtime_resume() on mutexes.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T16:15:07Z" diff --git a/advisories/unreviewed/2024/09/GHSA-wxmv-3hm7-2jqh/GHSA-wxmv-3hm7-2jqh.json b/advisories/unreviewed/2024/09/GHSA-wxmv-3hm7-2jqh/GHSA-wxmv-3hm7-2jqh.json new file mode 100644 index 00000000000..ae0e1401158 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-wxmv-3hm7-2jqh/GHSA-wxmv-3hm7-2jqh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxmv-3hm7-2jqh", + "modified": "2024-09-13T18:31:48Z", + "published": "2024-09-13T18:31:48Z", + "aliases": [ + "CVE-2024-45368" + ], + "details": "The H2-DM1E PLC's authentication protocol appears to utilize either a custom encoding scheme or a challenge-response protocol. However, there's an observed anomaly in the H2-DM1E PLC's protocol execution, namely its acceptance of multiple distinct packets as valid authentication responses. This behavior deviates from standard security practices where a single, specific response or encoding pattern is expected for successful authentication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45368" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-256-17" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-384" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-x863-gchp-57m3/GHSA-x863-gchp-57m3.json b/advisories/unreviewed/2024/09/GHSA-x863-gchp-57m3/GHSA-x863-gchp-57m3.json index 4ce6bc5468e..8783c72b263 100644 --- a/advisories/unreviewed/2024/09/GHSA-x863-gchp-57m3/GHSA-x863-gchp-57m3.json +++ b/advisories/unreviewed/2024/09/GHSA-x863-gchp-57m3/GHSA-x863-gchp-57m3.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-312" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-x9q5-m7gx-rf9w/GHSA-x9q5-m7gx-rf9w.json b/advisories/unreviewed/2024/09/GHSA-x9q5-m7gx-rf9w/GHSA-x9q5-m7gx-rf9w.json new file mode 100644 index 00000000000..7928eb9901d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-x9q5-m7gx-rf9w/GHSA-x9q5-m7gx-rf9w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9q5-m7gx-rf9w", + "modified": "2024-09-13T18:31:48Z", + "published": "2024-09-13T18:31:48Z", + "aliases": [ + "CVE-2024-45105" + ], + "details": "An internal product security audit discovered a UEFI SMM (System Management Mode) callout vulnerability in some ThinkSystem servers that could allow a local attacker with elevated privileges to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45105" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-165524" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-825" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xg5q-q7c3-jvmv/GHSA-xg5q-q7c3-jvmv.json b/advisories/unreviewed/2024/09/GHSA-xg5q-q7c3-jvmv/GHSA-xg5q-q7c3-jvmv.json index cb5921e19bc..0a93e0dc3de 100644 --- a/advisories/unreviewed/2024/09/GHSA-xg5q-q7c3-jvmv/GHSA-xg5q-q7c3-jvmv.json +++ b/advisories/unreviewed/2024/09/GHSA-xg5q-q7c3-jvmv/GHSA-xg5q-q7c3-jvmv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xg5q-q7c3-jvmv", - "modified": "2024-09-11T18:31:05Z", + "modified": "2024-09-13T18:31:41Z", "published": "2024-09-11T18:31:05Z", "aliases": [ "CVE-2024-45011" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nchar: xillybus: Check USB endpoints when probing device\n\nEnsure, as the driver probes the device, that all endpoints that the\ndriver may attempt to access exist and are of the correct type.\n\nAll XillyUSB devices must have a Bulk IN and Bulk OUT endpoint at\naddress 1. This is verified in xillyusb_setup_base_eps().\n\nOn top of that, a XillyUSB device may have additional Bulk OUT\nendpoints. The information about these endpoints' addresses is deduced\nfrom a data structure (the IDT) that the driver fetches from the device\nwhile probing it. These endpoints are checked in setup_channels().\n\nA XillyUSB device never has more than one IN endpoint, as all data\ntowards the host is multiplexed in this single Bulk IN endpoint. This is\nwhy setup_channels() only checks OUT endpoints.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T16:15:06Z" diff --git a/advisories/unreviewed/2024/09/GHSA-xqww-5c9g-v62q/GHSA-xqww-5c9g-v62q.json b/advisories/unreviewed/2024/09/GHSA-xqww-5c9g-v62q/GHSA-xqww-5c9g-v62q.json new file mode 100644 index 00000000000..a12f67905c1 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xqww-5c9g-v62q/GHSA-xqww-5c9g-v62q.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqww-5c9g-v62q", + "modified": "2024-09-13T18:31:47Z", + "published": "2024-09-13T18:31:47Z", + "aliases": [ + "CVE-2024-43099" + ], + "details": "The session hijacking attack targets the application layer's control mechanism, which manages authenticated sessions between a host PC and a PLC. During such sessions, a session key is utilized to maintain security. However, if an attacker captures this session key, they can inject traffic into an ongoing authenticated session. To successfully achieve this, the attacker also needs to spoof both the IP address and MAC address of the originating host which is typical of a session-based attack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43099" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-256-17" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-294" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-13T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xrjv-8x73-5h7v/GHSA-xrjv-8x73-5h7v.json b/advisories/unreviewed/2024/09/GHSA-xrjv-8x73-5h7v/GHSA-xrjv-8x73-5h7v.json index 0b5eda6c3ba..53775808e64 100644 --- a/advisories/unreviewed/2024/09/GHSA-xrjv-8x73-5h7v/GHSA-xrjv-8x73-5h7v.json +++ b/advisories/unreviewed/2024/09/GHSA-xrjv-8x73-5h7v/GHSA-xrjv-8x73-5h7v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xrjv-8x73-5h7v", - "modified": "2024-09-13T06:30:42Z", + "modified": "2024-09-13T18:31:46Z", "published": "2024-09-13T06:30:42Z", "aliases": [ "CVE-2024-46682" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: prevent panic for nfsv4.0 closed files in nfs4_show_open\n\nPrior to commit 3f29cc82a84c (\"nfsd: split sc_status out of\nsc_type\") states_show() relied on sc_type field to be of valid\ntype before calling into a subfunction to show content of a\nparticular stateid. From that commit, we split the validity of\nthe stateid into sc_status and no longer changed sc_type to 0\nwhile unhashing the stateid. This resulted in kernel oopsing\nfor nfsv4.0 opens that stay around and in nfs4_show_open()\nwould derefence sc_file which was NULL.\n\nInstead, for closed open stateids forgo displaying information\nthat relies of having a valid sc_file.\n\nTo reproduce: mount the server with 4.0, read and close\na file and then on the server cat /proc/fs/nfsd/clients/2/states\n\n[ 513.590804] Call trace:\n[ 513.590925] _raw_spin_lock+0xcc/0x160\n[ 513.591119] nfs4_show_open+0x78/0x2c0 [nfsd]\n[ 513.591412] states_show+0x44c/0x488 [nfsd]\n[ 513.591681] seq_read_iter+0x5d8/0x760\n[ 513.591896] seq_read+0x188/0x208\n[ 513.592075] vfs_read+0x148/0x470\n[ 513.592241] ksys_read+0xcc/0x178", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:12Z"