From 5328ada22fd4e25d36b1306d269125e1ff0c4f5e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 21 Dec 2024 00:34:23 +0000 Subject: [PATCH] Publish Advisories GHSA-36vc-7w44-2c6h GHSA-5855-pjcr-9mh8 GHSA-62rj-q587-5xq8 GHSA-665g-3f9r-875q GHSA-77mp-qmr4-jggx GHSA-8g3g-85w5-qrm6 GHSA-c3vh-vj4j-ph6x GHSA-ghpw-cph8-v3rm GHSA-gp3c-h68x-v9g8 GHSA-pq62-7rf2-mhcm --- .../GHSA-36vc-7w44-2c6h.json | 15 ++++-- .../GHSA-5855-pjcr-9mh8.json | 52 +++++++++++++++++++ .../GHSA-62rj-q587-5xq8.json | 29 +++++++++++ .../GHSA-665g-3f9r-875q.json | 40 ++++++++++++++ .../GHSA-77mp-qmr4-jggx.json | 15 ++++-- .../GHSA-8g3g-85w5-qrm6.json | 31 +++++++++++ .../GHSA-c3vh-vj4j-ph6x.json | 36 +++++++++++++ .../GHSA-ghpw-cph8-v3rm.json | 4 +- .../GHSA-gp3c-h68x-v9g8.json | 15 ++++-- .../GHSA-pq62-7rf2-mhcm.json | 36 +++++++++++++ 10 files changed, 260 insertions(+), 13 deletions(-) create mode 100644 advisories/unreviewed/2024/12/GHSA-5855-pjcr-9mh8/GHSA-5855-pjcr-9mh8.json create mode 100644 advisories/unreviewed/2024/12/GHSA-62rj-q587-5xq8/GHSA-62rj-q587-5xq8.json create mode 100644 advisories/unreviewed/2024/12/GHSA-665g-3f9r-875q/GHSA-665g-3f9r-875q.json create mode 100644 advisories/unreviewed/2024/12/GHSA-8g3g-85w5-qrm6/GHSA-8g3g-85w5-qrm6.json create mode 100644 advisories/unreviewed/2024/12/GHSA-c3vh-vj4j-ph6x/GHSA-c3vh-vj4j-ph6x.json create mode 100644 advisories/unreviewed/2024/12/GHSA-pq62-7rf2-mhcm/GHSA-pq62-7rf2-mhcm.json diff --git a/advisories/unreviewed/2024/12/GHSA-36vc-7w44-2c6h/GHSA-36vc-7w44-2c6h.json b/advisories/unreviewed/2024/12/GHSA-36vc-7w44-2c6h/GHSA-36vc-7w44-2c6h.json index e7031a6f97a..003ff05ecb3 100644 --- a/advisories/unreviewed/2024/12/GHSA-36vc-7w44-2c6h/GHSA-36vc-7w44-2c6h.json +++ b/advisories/unreviewed/2024/12/GHSA-36vc-7w44-2c6h/GHSA-36vc-7w44-2c6h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-36vc-7w44-2c6h", - "modified": "2024-12-18T18:30:52Z", + "modified": "2024-12-21T00:33:01Z", "published": "2024-12-18T18:30:52Z", "aliases": [ "CVE-2024-55088" ], "details": "GetSimple CMS CE 3.3.19 is vulnerable to Server-Side Request Forgery (SSRF) in the backend plugin module.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-18T18:15:07Z" diff --git a/advisories/unreviewed/2024/12/GHSA-5855-pjcr-9mh8/GHSA-5855-pjcr-9mh8.json b/advisories/unreviewed/2024/12/GHSA-5855-pjcr-9mh8/GHSA-5855-pjcr-9mh8.json new file mode 100644 index 00000000000..c431b91d265 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5855-pjcr-9mh8/GHSA-5855-pjcr-9mh8.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5855-pjcr-9mh8", + "modified": "2024-12-21T00:33:05Z", + "published": "2024-12-21T00:33:05Z", + "aliases": [ + "CVE-2024-12845" + ], + "details": "A vulnerability classified as problematic was found in Emlog Pro up to 2.4.1. Affected by this vulnerability is an unknown functionality in the library /include/lib/common.php. The manipulation of the argument msg leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12845" + }, + { + "type": "WEB", + "url": "https://github.com/emlog/emlog/issues/306" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289081" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289081" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.462477" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-20T22:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-62rj-q587-5xq8/GHSA-62rj-q587-5xq8.json b/advisories/unreviewed/2024/12/GHSA-62rj-q587-5xq8/GHSA-62rj-q587-5xq8.json new file mode 100644 index 00000000000..cc6e58a3583 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-62rj-q587-5xq8/GHSA-62rj-q587-5xq8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62rj-q587-5xq8", + "modified": "2024-12-21T00:33:05Z", + "published": "2024-12-21T00:33:05Z", + "aliases": [ + "CVE-2021-40959" + ], + "details": "A reflected cross-site scripting vulnerability in MONITORAPP Application Insight Web Application Firewall (AIWAF) <= 4.1.6 and <=5.0 was identified on the subpage `/process_management/process_status.xhr.php`. This vulnerability allows an attacker to inject malicious scripts that execute in the context of the victim's session.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-40959" + }, + { + "type": "WEB", + "url": "https://rubiya.kr/CVE-2021-40959" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-20T22:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-665g-3f9r-875q/GHSA-665g-3f9r-875q.json b/advisories/unreviewed/2024/12/GHSA-665g-3f9r-875q/GHSA-665g-3f9r-875q.json new file mode 100644 index 00000000000..f358b345027 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-665g-3f9r-875q/GHSA-665g-3f9r-875q.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-665g-3f9r-875q", + "modified": "2024-12-21T00:33:05Z", + "published": "2024-12-21T00:33:05Z", + "aliases": [ + "CVE-2024-11811" + ], + "details": "The Feedify – Web Push Notifications plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'platform', 'phone', 'email', and 'store_url' parameters. in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11811" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3209183%40push-notification-by-feedify%2Ftrunk&old=3177773%40push-notification-by-feedify%2Ftrunk&sfp_email=&sfph_mail=#file15" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7a5a33fd-ecc6-40bf-93a5-10ead1c4c1f5?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-20T23:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-77mp-qmr4-jggx/GHSA-77mp-qmr4-jggx.json b/advisories/unreviewed/2024/12/GHSA-77mp-qmr4-jggx/GHSA-77mp-qmr4-jggx.json index a88bc186807..b200eb78b2d 100644 --- a/advisories/unreviewed/2024/12/GHSA-77mp-qmr4-jggx/GHSA-77mp-qmr4-jggx.json +++ b/advisories/unreviewed/2024/12/GHSA-77mp-qmr4-jggx/GHSA-77mp-qmr4-jggx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-77mp-qmr4-jggx", - "modified": "2024-12-18T21:30:55Z", + "modified": "2024-12-21T00:33:04Z", "published": "2024-12-18T21:30:55Z", "aliases": [ "CVE-2024-49201" ], "details": "Keyfactor Remote File Orchestrator (aka remote-file-orchestrator) 2.8 before 2.8.1 allows Information Disclosure: sensitive information could be exposed at the debug logging level.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-922" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-18T19:15:11Z" diff --git a/advisories/unreviewed/2024/12/GHSA-8g3g-85w5-qrm6/GHSA-8g3g-85w5-qrm6.json b/advisories/unreviewed/2024/12/GHSA-8g3g-85w5-qrm6/GHSA-8g3g-85w5-qrm6.json new file mode 100644 index 00000000000..5c2ed291b32 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8g3g-85w5-qrm6/GHSA-8g3g-85w5-qrm6.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8g3g-85w5-qrm6", + "modified": "2024-12-21T00:33:04Z", + "published": "2024-12-21T00:33:04Z", + "aliases": [ + "CVE-2020-13712" + ], + "details": "A command injection is possible through the user interface, allowing arbitrary command execution as \nthe root user. oMG2000 running MGOS 3.15.1 or earlier is affected. \n\nMG90 running MGOS 4.2.1 or earlier is affected.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-13712" + }, + { + "type": "WEB", + "url": "https://source.sierrawireless.com/-/media/support_downloads/security-bulletins/pdf/swi-psa-2020-006---mgos-security-update.ashx" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-20T22:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c3vh-vj4j-ph6x/GHSA-c3vh-vj4j-ph6x.json b/advisories/unreviewed/2024/12/GHSA-c3vh-vj4j-ph6x/GHSA-c3vh-vj4j-ph6x.json new file mode 100644 index 00000000000..f3ebd6c493b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c3vh-vj4j-ph6x/GHSA-c3vh-vj4j-ph6x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3vh-vj4j-ph6x", + "modified": "2024-12-21T00:33:05Z", + "published": "2024-12-21T00:33:05Z", + "aliases": [ + "CVE-2023-31280" + ], + "details": "An AirVantage online Warranty Checker tool vulnerability could allow an attacker to \nperform bulk enumeration of IMEI and Serial Numbers pairs. The AirVantage Warranty Checker is updated to no longer return the IMEI and Serial \nNumber in addition to the warranty status when the Serial Number or IMEI is used to look up \nwarranty status.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31280" + }, + { + "type": "WEB", + "url": "https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-002" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-21T00:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-ghpw-cph8-v3rm/GHSA-ghpw-cph8-v3rm.json b/advisories/unreviewed/2024/12/GHSA-ghpw-cph8-v3rm/GHSA-ghpw-cph8-v3rm.json index bcf5a4a340c..7b66f2f3898 100644 --- a/advisories/unreviewed/2024/12/GHSA-ghpw-cph8-v3rm/GHSA-ghpw-cph8-v3rm.json +++ b/advisories/unreviewed/2024/12/GHSA-ghpw-cph8-v3rm/GHSA-ghpw-cph8-v3rm.json @@ -20,7 +20,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-gp3c-h68x-v9g8/GHSA-gp3c-h68x-v9g8.json b/advisories/unreviewed/2024/12/GHSA-gp3c-h68x-v9g8/GHSA-gp3c-h68x-v9g8.json index 2ca43eb6a84..d2a0770f4c6 100644 --- a/advisories/unreviewed/2024/12/GHSA-gp3c-h68x-v9g8/GHSA-gp3c-h68x-v9g8.json +++ b/advisories/unreviewed/2024/12/GHSA-gp3c-h68x-v9g8/GHSA-gp3c-h68x-v9g8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gp3c-h68x-v9g8", - "modified": "2024-12-18T21:30:55Z", + "modified": "2024-12-21T00:33:04Z", "published": "2024-12-18T21:30:55Z", "aliases": [ "CVE-2024-49202" ], "details": "Keyfactor Command before 12.5.0 has Incorrect Access Control: access tokens are over permissioned, aka 64099. The fixed versions are 11.5.1.1, 11.5.2.1, 11.5.3.1, 11.5.4.5, 11.5.6.1, 11.6.0, 12.2.0.1, 12.3.0.1, 12.4.0.1, 12.5.0, and 24.4.0.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-18T19:15:11Z" diff --git a/advisories/unreviewed/2024/12/GHSA-pq62-7rf2-mhcm/GHSA-pq62-7rf2-mhcm.json b/advisories/unreviewed/2024/12/GHSA-pq62-7rf2-mhcm/GHSA-pq62-7rf2-mhcm.json new file mode 100644 index 00000000000..a2561f4417a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pq62-7rf2-mhcm/GHSA-pq62-7rf2-mhcm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pq62-7rf2-mhcm", + "modified": "2024-12-21T00:33:05Z", + "published": "2024-12-21T00:33:05Z", + "aliases": [ + "CVE-2023-31279" + ], + "details": "The AirVantage platform is vulnerable to an unauthorized attacker registering previously unregistered \ndevices on the AirVantage platform when the owner has not disabled the AirVantage Management \nService on the devices or registered the device. This could enable an attacker to configure, manage, \nand execute AT commands on an unsuspecting user’s devices.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31279" + }, + { + "type": "WEB", + "url": "https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-002" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-21T00:15:27Z" + } +} \ No newline at end of file