diff --git a/advisories/unreviewed/2024/08/GHSA-79g4-f35r-g3f6/GHSA-79g4-f35r-g3f6.json b/advisories/unreviewed/2024/08/GHSA-79g4-f35r-g3f6/GHSA-79g4-f35r-g3f6.json new file mode 100644 index 00000000000..d2083ef2247 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-79g4-f35r-g3f6/GHSA-79g4-f35r-g3f6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79g4-f35r-g3f6", + "modified": "2024-08-26T09:30:44Z", + "published": "2024-08-26T09:30:44Z", + "aliases": [ + "CVE-2024-43443" + ], + "details": "Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in Process Management modules of OTRS and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the Process Management targeting other admins.\nThis issue affects: \n\n * OTRS from 7.0.X through 7.0.50\n * OTRS 8.0.X\n * OTRS 2023.X\n * OTRS from 2024.X through 2024.5.X\n * ((OTRS)) Community Edition: 6.0.x\n\nProducts based on the ((OTRS)) Community Edition also very likely to be affected", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43443" + }, + { + "type": "WEB", + "url": "https://otrs.com/release-notes/otrs-security-advisory-2024-11" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-790" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T09:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f2jj-rmrg-9rjx/GHSA-f2jj-rmrg-9rjx.json b/advisories/unreviewed/2024/08/GHSA-f2jj-rmrg-9rjx/GHSA-f2jj-rmrg-9rjx.json new file mode 100644 index 00000000000..c1e698aa761 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f2jj-rmrg-9rjx/GHSA-f2jj-rmrg-9rjx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2jj-rmrg-9rjx", + "modified": "2024-08-26T09:30:44Z", + "published": "2024-08-26T09:30:44Z", + "aliases": [ + "CVE-2024-43884" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: MGMT: Add error handling to pair_device()\n\nhci_conn_params_add() never checks for a NULL value and could lead to a NULL\npointer dereference causing a crash.\n\nFixed by adding error handling in the function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43884" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/538fd3921afac97158d4177139a0ad39f056dbb2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T08:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fw5q-5jr8-g3vh/GHSA-fw5q-5jr8-g3vh.json b/advisories/unreviewed/2024/08/GHSA-fw5q-5jr8-g3vh/GHSA-fw5q-5jr8-g3vh.json new file mode 100644 index 00000000000..6425eee0d73 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fw5q-5jr8-g3vh/GHSA-fw5q-5jr8-g3vh.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fw5q-5jr8-g3vh", + "modified": "2024-08-26T09:30:44Z", + "published": "2024-08-26T09:30:44Z", + "aliases": [ + "CVE-2024-45256" + ], + "details": "An arbitrary file write issue in the exfiltration endpoint in BYOB (Build Your Own Botnet) 2.0 allows attackers to overwrite SQLite databases and bypass authentication via an unauthenticated HTTP request with a crafted parameter. This occurs in file_add in api/files/routes.py.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45256" + }, + { + "type": "WEB", + "url": "https://blog.chebuya.com/posts/unauthenticated-remote-command-execution-on-byob" + }, + { + "type": "WEB", + "url": "https://github.com/chebuya/exploits/tree/main/BYOB-RCE" + }, + { + "type": "WEB", + "url": "https://github.com/malwaredllc/byob" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T07:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g24f-94pq-jr67/GHSA-g24f-94pq-jr67.json b/advisories/unreviewed/2024/08/GHSA-g24f-94pq-jr67/GHSA-g24f-94pq-jr67.json new file mode 100644 index 00000000000..2ab8ec4c590 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-g24f-94pq-jr67/GHSA-g24f-94pq-jr67.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g24f-94pq-jr67", + "modified": "2024-08-26T09:30:44Z", + "published": "2024-08-26T09:30:44Z", + "aliases": [ + "CVE-2024-43442" + ], + "details": "Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in  OTRS (System Configuration modules) and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the System Configuration targeting other admins.\nThis issue affects: \n\n * OTRS from 7.0.X through 7.0.50\n * OTRS 8.0.X\n * OTRS 2023.X\n * OTRS from 2024.X through 2024.5.X\n * ((OTRS)) Community Edition: 6.0.x\n\nProducts based on the ((OTRS)) Community Edition also very likely to be affected", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43442" + }, + { + "type": "WEB", + "url": "https://otrs.com/release-notes/otrs-security-advisory-2024-10" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-790" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T09:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-m8cw-854g-5gvm/GHSA-m8cw-854g-5gvm.json b/advisories/unreviewed/2024/08/GHSA-m8cw-854g-5gvm/GHSA-m8cw-854g-5gvm.json new file mode 100644 index 00000000000..c2b7ce6dbf3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-m8cw-854g-5gvm/GHSA-m8cw-854g-5gvm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m8cw-854g-5gvm", + "modified": "2024-08-26T09:30:44Z", + "published": "2024-08-26T09:30:44Z", + "aliases": [ + "CVE-2024-43444" + ], + "details": "Passwords of agents and customers are displayed in plain text in the OTRS admin log module if certain configurations regarding the authentication sources match and debugging for the authentication backend has been enabled.\n\nThis issue affects: \n\n * OTRS from 7.0.X through 7.0.50\n * OTRS 8.0.X\n * OTRS 2023.X\n * OTRS from 2024.X through 2024.5.X\n * ((OTRS)) Community Edition: 6.0.x\n\nProducts based on the ((OTRS)) Community Edition also very likely to be affected", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43444" + }, + { + "type": "WEB", + "url": "https://otrs.com/release-notes/otrs-security-advisory-2024-12" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T09:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v5f5-778p-qh56/GHSA-v5f5-778p-qh56.json b/advisories/unreviewed/2024/08/GHSA-v5f5-778p-qh56/GHSA-v5f5-778p-qh56.json new file mode 100644 index 00000000000..9ecc9aa5852 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v5f5-778p-qh56/GHSA-v5f5-778p-qh56.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5f5-778p-qh56", + "modified": "2024-08-26T09:30:44Z", + "published": "2024-08-26T09:30:44Z", + "aliases": [ + "CVE-2024-45241" + ], + "details": "A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allows unauthenticated attackers to read files outside of the working web directory via the rpt parameter, leading to the disclosure of sensitive information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45241" + }, + { + "type": "WEB", + "url": "https://daly.wtf/cve-2024-45241-path-traversal-in-centralsquare-crywolf" + }, + { + "type": "WEB", + "url": "https://github.com/d4lyw/CVE-2024-45241" + }, + { + "type": "WEB", + "url": "https://www.centralsquare.com/solutions/public-safety-software/public-safety-agency-operations/crywolf-false-alarm-management-solution" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T07:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wj96-5g7r-c538/GHSA-wj96-5g7r-c538.json b/advisories/unreviewed/2024/08/GHSA-wj96-5g7r-c538/GHSA-wj96-5g7r-c538.json new file mode 100644 index 00000000000..6c6315200b4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-wj96-5g7r-c538/GHSA-wj96-5g7r-c538.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wj96-5g7r-c538", + "modified": "2024-08-26T09:30:44Z", + "published": "2024-08-26T09:30:44Z", + "aliases": [ + "CVE-2024-8161" + ], + "details": "SQL injection vulnerability in ATISolutions CIGES affecting versions lower than 2.15.5. This vulnerability allows a remote attacker to send a specially crafted SQL query to the /modules/ajaxServiciosCentro.php point in the idCentro parameter and retrieve all the information stored in the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8161" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/sql-injection-vulnerability-cigesv2-system" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T09:15:04Z" + } +} \ No newline at end of file