From 570ffb642fda805743eef6eb6acb8c82eee65a3d Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 12 Dec 2024 21:32:10 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-vmj7-g8jh-7fqp.json | 9 +++-- .../GHSA-2gpj-wh36-7xwf.json | 3 +- .../GHSA-2wh8-mpmc-rwwm.json | 4 ++- .../GHSA-79xr-w992-c9fw.json | 4 ++- .../GHSA-8h7f-r98h-27p8.json | 4 ++- .../GHSA-pfwq-49pr-pf8x.json | 3 +- .../GHSA-6x7g-3w67-hj7p.json | 2 +- .../GHSA-qq56-5xwp-c89r.json | 2 +- .../GHSA-v8xr-rghj-pvv9.json | 2 +- .../GHSA-wrfg-qw24-93h8.json | 5 +-- .../GHSA-4wj3-7p36-wmrw.json | 2 +- .../GHSA-fj43-9cjj-qw2v.json | 5 +-- .../GHSA-w9q2-p57h-r357.json | 5 +-- .../GHSA-9h7f-r33v-rw4r.json | 4 ++- .../GHSA-cjjq-cwpw-fx4q.json | 4 ++- .../GHSA-v8c4-4ghf-7jv6.json | 4 ++- .../GHSA-75qv-hw7p-g75w.json | 4 ++- .../GHSA-7m3j-r733-g8p5.json | 3 +- .../GHSA-q557-m5m4-m7pc.json | 3 +- .../GHSA-536h-wxcg-vp88.json | 1 + .../GHSA-56g4-wf8m-979x.json | 1 + .../GHSA-f8v8-jqrr-5mhq.json | 1 + .../GHSA-2j3v-9566-775v.json | 29 +++++++++++++++ .../GHSA-49ff-m2jv-96mv.json | 36 +++++++++++++++++++ .../GHSA-4w56-vr39-rvqr.json | 3 +- .../GHSA-5hph-wf32-7rmr.json | 2 +- .../GHSA-fw24-x4v5-9x55.json | 15 +++++--- .../GHSA-hwhg-f3ff-q3c4.json | 36 +++++++++++++++++++ .../GHSA-j2cg-2g7j-2gm8.json | 1 + .../GHSA-mmmw-7pph-f6m3.json | 3 +- .../GHSA-mpm8-4rhh-qr48.json | 1 + .../GHSA-p98j-34x2-jg46.json | 11 ++++-- .../GHSA-qfp8-pvg8-2xph.json | 15 +++++--- .../GHSA-rw7h-3g54-j855.json | 11 ++++-- .../GHSA-w8h6-mg97-8mq2.json | 1 + .../GHSA-wj49-p585-9263.json | 15 +++++--- 36 files changed, 210 insertions(+), 44 deletions(-) create mode 100644 advisories/unreviewed/2024/12/GHSA-2j3v-9566-775v/GHSA-2j3v-9566-775v.json create mode 100644 advisories/unreviewed/2024/12/GHSA-49ff-m2jv-96mv/GHSA-49ff-m2jv-96mv.json create mode 100644 advisories/unreviewed/2024/12/GHSA-hwhg-f3ff-q3c4/GHSA-hwhg-f3ff-q3c4.json diff --git a/advisories/unreviewed/2022/05/GHSA-vmj7-g8jh-7fqp/GHSA-vmj7-g8jh-7fqp.json b/advisories/unreviewed/2022/05/GHSA-vmj7-g8jh-7fqp/GHSA-vmj7-g8jh-7fqp.json index 5747e47af3f..d86b9c7c332 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmj7-g8jh-7fqp/GHSA-vmj7-g8jh-7fqp.json +++ b/advisories/unreviewed/2022/05/GHSA-vmj7-g8jh-7fqp/GHSA-vmj7-g8jh-7fqp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vmj7-g8jh-7fqp", - "modified": "2022-05-14T00:58:34Z", + "modified": "2024-12-12T21:30:44Z", "published": "2022-05-14T00:58:34Z", "aliases": [ "CVE-2013-3572" ], "details": "Cross-site scripting (XSS) vulnerability in the administer interface in the UniFi Controller in Ubiquiti Networks UniFi 2.3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted client hostname.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2023/06/GHSA-2gpj-wh36-7xwf/GHSA-2gpj-wh36-7xwf.json b/advisories/unreviewed/2023/06/GHSA-2gpj-wh36-7xwf/GHSA-2gpj-wh36-7xwf.json index b7cab806a06..aab747a0a3e 100644 --- a/advisories/unreviewed/2023/06/GHSA-2gpj-wh36-7xwf/GHSA-2gpj-wh36-7xwf.json +++ b/advisories/unreviewed/2023/06/GHSA-2gpj-wh36-7xwf/GHSA-2gpj-wh36-7xwf.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-346" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-2wh8-mpmc-rwwm/GHSA-2wh8-mpmc-rwwm.json b/advisories/unreviewed/2023/06/GHSA-2wh8-mpmc-rwwm/GHSA-2wh8-mpmc-rwwm.json index a618a32e125..f97cc5e64c1 100644 --- a/advisories/unreviewed/2023/06/GHSA-2wh8-mpmc-rwwm/GHSA-2wh8-mpmc-rwwm.json +++ b/advisories/unreviewed/2023/06/GHSA-2wh8-mpmc-rwwm/GHSA-2wh8-mpmc-rwwm.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-346" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-79xr-w992-c9fw/GHSA-79xr-w992-c9fw.json b/advisories/unreviewed/2023/06/GHSA-79xr-w992-c9fw/GHSA-79xr-w992-c9fw.json index 6f44701c3bb..81f9a035c93 100644 --- a/advisories/unreviewed/2023/06/GHSA-79xr-w992-c9fw/GHSA-79xr-w992-c9fw.json +++ b/advisories/unreviewed/2023/06/GHSA-79xr-w992-c9fw/GHSA-79xr-w992-c9fw.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-346" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-8h7f-r98h-27p8/GHSA-8h7f-r98h-27p8.json b/advisories/unreviewed/2023/06/GHSA-8h7f-r98h-27p8/GHSA-8h7f-r98h-27p8.json index 3e363250f4b..97d8348ea5a 100644 --- a/advisories/unreviewed/2023/06/GHSA-8h7f-r98h-27p8/GHSA-8h7f-r98h-27p8.json +++ b/advisories/unreviewed/2023/06/GHSA-8h7f-r98h-27p8/GHSA-8h7f-r98h-27p8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-pfwq-49pr-pf8x/GHSA-pfwq-49pr-pf8x.json b/advisories/unreviewed/2023/06/GHSA-pfwq-49pr-pf8x/GHSA-pfwq-49pr-pf8x.json index 1915ba942e9..81f3712cfd2 100644 --- a/advisories/unreviewed/2023/06/GHSA-pfwq-49pr-pf8x/GHSA-pfwq-49pr-pf8x.json +++ b/advisories/unreviewed/2023/06/GHSA-pfwq-49pr-pf8x/GHSA-pfwq-49pr-pf8x.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-345" + "CWE-345", + "CWE-352" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-6x7g-3w67-hj7p/GHSA-6x7g-3w67-hj7p.json b/advisories/unreviewed/2024/02/GHSA-6x7g-3w67-hj7p/GHSA-6x7g-3w67-hj7p.json index 57dc06dfebf..fa18caa3ff7 100644 --- a/advisories/unreviewed/2024/02/GHSA-6x7g-3w67-hj7p/GHSA-6x7g-3w67-hj7p.json +++ b/advisories/unreviewed/2024/02/GHSA-6x7g-3w67-hj7p/GHSA-6x7g-3w67-hj7p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6x7g-3w67-hj7p", - "modified": "2024-02-14T18:30:25Z", + "modified": "2024-12-12T21:30:45Z", "published": "2024-02-14T18:30:25Z", "aliases": [ "CVE-2024-23308" diff --git a/advisories/unreviewed/2024/02/GHSA-qq56-5xwp-c89r/GHSA-qq56-5xwp-c89r.json b/advisories/unreviewed/2024/02/GHSA-qq56-5xwp-c89r/GHSA-qq56-5xwp-c89r.json index e6e2b93ba3a..8721362dea8 100644 --- a/advisories/unreviewed/2024/02/GHSA-qq56-5xwp-c89r/GHSA-qq56-5xwp-c89r.json +++ b/advisories/unreviewed/2024/02/GHSA-qq56-5xwp-c89r/GHSA-qq56-5xwp-c89r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qq56-5xwp-c89r", - "modified": "2024-02-14T18:30:25Z", + "modified": "2024-12-12T21:30:45Z", "published": "2024-02-14T18:30:25Z", "aliases": [ "CVE-2024-21789" diff --git a/advisories/unreviewed/2024/02/GHSA-v8xr-rghj-pvv9/GHSA-v8xr-rghj-pvv9.json b/advisories/unreviewed/2024/02/GHSA-v8xr-rghj-pvv9/GHSA-v8xr-rghj-pvv9.json index dee2c440a92..a2fb0ad3e6b 100644 --- a/advisories/unreviewed/2024/02/GHSA-v8xr-rghj-pvv9/GHSA-v8xr-rghj-pvv9.json +++ b/advisories/unreviewed/2024/02/GHSA-v8xr-rghj-pvv9/GHSA-v8xr-rghj-pvv9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v8xr-rghj-pvv9", - "modified": "2024-02-14T18:30:25Z", + "modified": "2024-12-12T21:30:45Z", "published": "2024-02-14T18:30:25Z", "aliases": [ "CVE-2024-21763" diff --git a/advisories/unreviewed/2024/02/GHSA-wrfg-qw24-93h8/GHSA-wrfg-qw24-93h8.json b/advisories/unreviewed/2024/02/GHSA-wrfg-qw24-93h8/GHSA-wrfg-qw24-93h8.json index ef1d6db36ad..2c95b3224ac 100644 --- a/advisories/unreviewed/2024/02/GHSA-wrfg-qw24-93h8/GHSA-wrfg-qw24-93h8.json +++ b/advisories/unreviewed/2024/02/GHSA-wrfg-qw24-93h8/GHSA-wrfg-qw24-93h8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wrfg-qw24-93h8", - "modified": "2024-02-14T18:30:26Z", + "modified": "2024-12-12T21:30:45Z", "published": "2024-02-14T18:30:26Z", "aliases": [ "CVE-2024-23982" @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-4wj3-7p36-wmrw/GHSA-4wj3-7p36-wmrw.json b/advisories/unreviewed/2024/05/GHSA-4wj3-7p36-wmrw/GHSA-4wj3-7p36-wmrw.json index 93ce45aacbf..d964c8c6d20 100644 --- a/advisories/unreviewed/2024/05/GHSA-4wj3-7p36-wmrw/GHSA-4wj3-7p36-wmrw.json +++ b/advisories/unreviewed/2024/05/GHSA-4wj3-7p36-wmrw/GHSA-4wj3-7p36-wmrw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4wj3-7p36-wmrw", - "modified": "2024-05-08T15:30:43Z", + "modified": "2024-12-12T21:30:45Z", "published": "2024-05-08T15:30:43Z", "aliases": [ "CVE-2024-33612" diff --git a/advisories/unreviewed/2024/05/GHSA-fj43-9cjj-qw2v/GHSA-fj43-9cjj-qw2v.json b/advisories/unreviewed/2024/05/GHSA-fj43-9cjj-qw2v/GHSA-fj43-9cjj-qw2v.json index 66bfa957497..072531a512b 100644 --- a/advisories/unreviewed/2024/05/GHSA-fj43-9cjj-qw2v/GHSA-fj43-9cjj-qw2v.json +++ b/advisories/unreviewed/2024/05/GHSA-fj43-9cjj-qw2v/GHSA-fj43-9cjj-qw2v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fj43-9cjj-qw2v", - "modified": "2024-05-08T15:30:42Z", + "modified": "2024-12-12T21:30:45Z", "published": "2024-05-08T15:30:42Z", "aliases": [ "CVE-2024-26026" @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-89" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-w9q2-p57h-r357/GHSA-w9q2-p57h-r357.json b/advisories/unreviewed/2024/05/GHSA-w9q2-p57h-r357/GHSA-w9q2-p57h-r357.json index d7be745c0b3..1fe9413af8d 100644 --- a/advisories/unreviewed/2024/05/GHSA-w9q2-p57h-r357/GHSA-w9q2-p57h-r357.json +++ b/advisories/unreviewed/2024/05/GHSA-w9q2-p57h-r357/GHSA-w9q2-p57h-r357.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w9q2-p57h-r357", - "modified": "2024-05-08T15:30:42Z", + "modified": "2024-12-12T21:30:45Z", "published": "2024-05-08T15:30:42Z", "aliases": [ "CVE-2024-21793" @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-89" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-9h7f-r33v-rw4r/GHSA-9h7f-r33v-rw4r.json b/advisories/unreviewed/2024/08/GHSA-9h7f-r33v-rw4r/GHSA-9h7f-r33v-rw4r.json index 9601dd4db25..7a91922283f 100644 --- a/advisories/unreviewed/2024/08/GHSA-9h7f-r33v-rw4r/GHSA-9h7f-r33v-rw4r.json +++ b/advisories/unreviewed/2024/08/GHSA-9h7f-r33v-rw4r/GHSA-9h7f-r33v-rw4r.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-cjjq-cwpw-fx4q/GHSA-cjjq-cwpw-fx4q.json b/advisories/unreviewed/2024/08/GHSA-cjjq-cwpw-fx4q/GHSA-cjjq-cwpw-fx4q.json index 2e903952c3c..90b2d3d06ff 100644 --- a/advisories/unreviewed/2024/08/GHSA-cjjq-cwpw-fx4q/GHSA-cjjq-cwpw-fx4q.json +++ b/advisories/unreviewed/2024/08/GHSA-cjjq-cwpw-fx4q/GHSA-cjjq-cwpw-fx4q.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-v8c4-4ghf-7jv6/GHSA-v8c4-4ghf-7jv6.json b/advisories/unreviewed/2024/08/GHSA-v8c4-4ghf-7jv6/GHSA-v8c4-4ghf-7jv6.json index 0633a712575..c2a51fbd48b 100644 --- a/advisories/unreviewed/2024/08/GHSA-v8c4-4ghf-7jv6/GHSA-v8c4-4ghf-7jv6.json +++ b/advisories/unreviewed/2024/08/GHSA-v8c4-4ghf-7jv6/GHSA-v8c4-4ghf-7jv6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-665" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-75qv-hw7p-g75w/GHSA-75qv-hw7p-g75w.json b/advisories/unreviewed/2024/10/GHSA-75qv-hw7p-g75w/GHSA-75qv-hw7p-g75w.json index ef171f8f582..d0290302494 100644 --- a/advisories/unreviewed/2024/10/GHSA-75qv-hw7p-g75w/GHSA-75qv-hw7p-g75w.json +++ b/advisories/unreviewed/2024/10/GHSA-75qv-hw7p-g75w/GHSA-75qv-hw7p-g75w.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-7m3j-r733-g8p5/GHSA-7m3j-r733-g8p5.json b/advisories/unreviewed/2024/10/GHSA-7m3j-r733-g8p5/GHSA-7m3j-r733-g8p5.json index de588563440..273c5d0fd72 100644 --- a/advisories/unreviewed/2024/10/GHSA-7m3j-r733-g8p5/GHSA-7m3j-r733-g8p5.json +++ b/advisories/unreviewed/2024/10/GHSA-7m3j-r733-g8p5/GHSA-7m3j-r733-g8p5.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-q557-m5m4-m7pc/GHSA-q557-m5m4-m7pc.json b/advisories/unreviewed/2024/10/GHSA-q557-m5m4-m7pc/GHSA-q557-m5m4-m7pc.json index c58e6a3308e..b4064f1794b 100644 --- a/advisories/unreviewed/2024/10/GHSA-q557-m5m4-m7pc/GHSA-q557-m5m4-m7pc.json +++ b/advisories/unreviewed/2024/10/GHSA-q557-m5m4-m7pc/GHSA-q557-m5m4-m7pc.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-536h-wxcg-vp88/GHSA-536h-wxcg-vp88.json b/advisories/unreviewed/2024/11/GHSA-536h-wxcg-vp88/GHSA-536h-wxcg-vp88.json index 9c5f59e068f..6feb0cc7f45 100644 --- a/advisories/unreviewed/2024/11/GHSA-536h-wxcg-vp88/GHSA-536h-wxcg-vp88.json +++ b/advisories/unreviewed/2024/11/GHSA-536h-wxcg-vp88/GHSA-536h-wxcg-vp88.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-611", "CWE-91" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/11/GHSA-56g4-wf8m-979x/GHSA-56g4-wf8m-979x.json b/advisories/unreviewed/2024/11/GHSA-56g4-wf8m-979x/GHSA-56g4-wf8m-979x.json index 6e0a2b7d640..95d6f5e07ea 100644 --- a/advisories/unreviewed/2024/11/GHSA-56g4-wf8m-979x/GHSA-56g4-wf8m-979x.json +++ b/advisories/unreviewed/2024/11/GHSA-56g4-wf8m-979x/GHSA-56g4-wf8m-979x.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-611", "CWE-91" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/11/GHSA-f8v8-jqrr-5mhq/GHSA-f8v8-jqrr-5mhq.json b/advisories/unreviewed/2024/11/GHSA-f8v8-jqrr-5mhq/GHSA-f8v8-jqrr-5mhq.json index a869fa0b038..2e2303d1861 100644 --- a/advisories/unreviewed/2024/11/GHSA-f8v8-jqrr-5mhq/GHSA-f8v8-jqrr-5mhq.json +++ b/advisories/unreviewed/2024/11/GHSA-f8v8-jqrr-5mhq/GHSA-f8v8-jqrr-5mhq.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-611", "CWE-91" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/12/GHSA-2j3v-9566-775v/GHSA-2j3v-9566-775v.json b/advisories/unreviewed/2024/12/GHSA-2j3v-9566-775v/GHSA-2j3v-9566-775v.json new file mode 100644 index 00000000000..26b96c1cc6e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2j3v-9566-775v/GHSA-2j3v-9566-775v.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2j3v-9566-775v", + "modified": "2024-12-12T21:30:47Z", + "published": "2024-12-12T21:30:47Z", + "aliases": [ + "CVE-2024-54811" + ], + "details": "A SQL injection vulnerability in /index.php in PHPGurukul Park Ticketing Management System v1.0 allows an attacker to execute arbitrary SQL commands via the \"login\" parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54811" + }, + { + "type": "WEB", + "url": "https://github.com/Santoshcyber1/CVE-wirteup/blob/main/Phpgurukul/Park%20ticket/report%20sql.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-49ff-m2jv-96mv/GHSA-49ff-m2jv-96mv.json b/advisories/unreviewed/2024/12/GHSA-49ff-m2jv-96mv/GHSA-49ff-m2jv-96mv.json new file mode 100644 index 00000000000..f3ea7b5216d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-49ff-m2jv-96mv/GHSA-49ff-m2jv-96mv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49ff-m2jv-96mv", + "modified": "2024-12-12T21:30:47Z", + "published": "2024-12-12T21:30:47Z", + "aliases": [ + "CVE-2024-49071" + ], + "details": "Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49071" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49071" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-612" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4w56-vr39-rvqr/GHSA-4w56-vr39-rvqr.json b/advisories/unreviewed/2024/12/GHSA-4w56-vr39-rvqr/GHSA-4w56-vr39-rvqr.json index e24f5fde755..841c5d1d8c3 100644 --- a/advisories/unreviewed/2024/12/GHSA-4w56-vr39-rvqr/GHSA-4w56-vr39-rvqr.json +++ b/advisories/unreviewed/2024/12/GHSA-4w56-vr39-rvqr/GHSA-4w56-vr39-rvqr.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-248" + "CWE-248", + "CWE-476" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-5hph-wf32-7rmr/GHSA-5hph-wf32-7rmr.json b/advisories/unreviewed/2024/12/GHSA-5hph-wf32-7rmr/GHSA-5hph-wf32-7rmr.json index 2fdc1c82573..3c712fca4a7 100644 --- a/advisories/unreviewed/2024/12/GHSA-5hph-wf32-7rmr/GHSA-5hph-wf32-7rmr.json +++ b/advisories/unreviewed/2024/12/GHSA-5hph-wf32-7rmr/GHSA-5hph-wf32-7rmr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5hph-wf32-7rmr", - "modified": "2024-12-11T00:31:27Z", + "modified": "2024-12-12T21:30:46Z", "published": "2024-12-11T00:31:27Z", "aliases": [ "CVE-2024-52865" diff --git a/advisories/unreviewed/2024/12/GHSA-fw24-x4v5-9x55/GHSA-fw24-x4v5-9x55.json b/advisories/unreviewed/2024/12/GHSA-fw24-x4v5-9x55/GHSA-fw24-x4v5-9x55.json index 0e734c37c87..0b7de579690 100644 --- a/advisories/unreviewed/2024/12/GHSA-fw24-x4v5-9x55/GHSA-fw24-x4v5-9x55.json +++ b/advisories/unreviewed/2024/12/GHSA-fw24-x4v5-9x55/GHSA-fw24-x4v5-9x55.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fw24-x4v5-9x55", - "modified": "2024-12-12T03:33:06Z", + "modified": "2024-12-12T21:30:46Z", "published": "2024-12-12T03:33:06Z", "aliases": [ "CVE-2024-54513" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2. An app may be able to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-281" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:31Z" diff --git a/advisories/unreviewed/2024/12/GHSA-hwhg-f3ff-q3c4/GHSA-hwhg-f3ff-q3c4.json b/advisories/unreviewed/2024/12/GHSA-hwhg-f3ff-q3c4/GHSA-hwhg-f3ff-q3c4.json new file mode 100644 index 00000000000..ae85ffceac9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hwhg-f3ff-q3c4/GHSA-hwhg-f3ff-q3c4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwhg-f3ff-q3c4", + "modified": "2024-12-12T21:30:47Z", + "published": "2024-12-12T21:30:47Z", + "aliases": [ + "CVE-2024-49147" + ], + "details": "Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49147" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49147" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j2cg-2g7j-2gm8/GHSA-j2cg-2g7j-2gm8.json b/advisories/unreviewed/2024/12/GHSA-j2cg-2g7j-2gm8/GHSA-j2cg-2g7j-2gm8.json index 1589b1e2e83..86be585ab28 100644 --- a/advisories/unreviewed/2024/12/GHSA-j2cg-2g7j-2gm8/GHSA-j2cg-2g7j-2gm8.json +++ b/advisories/unreviewed/2024/12/GHSA-j2cg-2g7j-2gm8/GHSA-j2cg-2g7j-2gm8.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-754" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/12/GHSA-mmmw-7pph-f6m3/GHSA-mmmw-7pph-f6m3.json b/advisories/unreviewed/2024/12/GHSA-mmmw-7pph-f6m3/GHSA-mmmw-7pph-f6m3.json index 1cdc37f44fa..8040102c9ef 100644 --- a/advisories/unreviewed/2024/12/GHSA-mmmw-7pph-f6m3/GHSA-mmmw-7pph-f6m3.json +++ b/advisories/unreviewed/2024/12/GHSA-mmmw-7pph-f6m3/GHSA-mmmw-7pph-f6m3.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-mpm8-4rhh-qr48/GHSA-mpm8-4rhh-qr48.json b/advisories/unreviewed/2024/12/GHSA-mpm8-4rhh-qr48/GHSA-mpm8-4rhh-qr48.json index 1870451f2fb..24d0ffda527 100644 --- a/advisories/unreviewed/2024/12/GHSA-mpm8-4rhh-qr48/GHSA-mpm8-4rhh-qr48.json +++ b/advisories/unreviewed/2024/12/GHSA-mpm8-4rhh-qr48/GHSA-mpm8-4rhh-qr48.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-754" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/12/GHSA-p98j-34x2-jg46/GHSA-p98j-34x2-jg46.json b/advisories/unreviewed/2024/12/GHSA-p98j-34x2-jg46/GHSA-p98j-34x2-jg46.json index dc268cb1c52..78900b37215 100644 --- a/advisories/unreviewed/2024/12/GHSA-p98j-34x2-jg46/GHSA-p98j-34x2-jg46.json +++ b/advisories/unreviewed/2024/12/GHSA-p98j-34x2-jg46/GHSA-p98j-34x2-jg46.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p98j-34x2-jg46", - "modified": "2024-12-12T03:33:06Z", + "modified": "2024-12-12T21:30:46Z", "published": "2024-12-12T03:33:06Z", "aliases": [ "CVE-2024-44299" ], "details": "The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP firmware.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:24Z" diff --git a/advisories/unreviewed/2024/12/GHSA-qfp8-pvg8-2xph/GHSA-qfp8-pvg8-2xph.json b/advisories/unreviewed/2024/12/GHSA-qfp8-pvg8-2xph/GHSA-qfp8-pvg8-2xph.json index d9c0946c81c..886b69b154a 100644 --- a/advisories/unreviewed/2024/12/GHSA-qfp8-pvg8-2xph/GHSA-qfp8-pvg8-2xph.json +++ b/advisories/unreviewed/2024/12/GHSA-qfp8-pvg8-2xph/GHSA-qfp8-pvg8-2xph.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qfp8-pvg8-2xph", - "modified": "2024-12-12T03:33:06Z", + "modified": "2024-12-12T21:30:46Z", "published": "2024-12-12T03:33:06Z", "aliases": [ "CVE-2024-54505" ], "details": "A type confusion issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.3, watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, Safari 18.2, iOS 18.2 and iPadOS 18.2. Processing maliciously crafted web content may lead to memory corruption.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-843" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:31Z" diff --git a/advisories/unreviewed/2024/12/GHSA-rw7h-3g54-j855/GHSA-rw7h-3g54-j855.json b/advisories/unreviewed/2024/12/GHSA-rw7h-3g54-j855/GHSA-rw7h-3g54-j855.json index 9a4aa91ac6d..b23ee33749c 100644 --- a/advisories/unreviewed/2024/12/GHSA-rw7h-3g54-j855/GHSA-rw7h-3g54-j855.json +++ b/advisories/unreviewed/2024/12/GHSA-rw7h-3g54-j855/GHSA-rw7h-3g54-j855.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rw7h-3g54-j855", - "modified": "2024-12-12T06:30:50Z", + "modified": "2024-12-12T21:30:46Z", "published": "2024-12-12T06:30:50Z", "aliases": [ "CVE-2024-10637" ], "details": "The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.54 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T06:15:20Z" diff --git a/advisories/unreviewed/2024/12/GHSA-w8h6-mg97-8mq2/GHSA-w8h6-mg97-8mq2.json b/advisories/unreviewed/2024/12/GHSA-w8h6-mg97-8mq2/GHSA-w8h6-mg97-8mq2.json index 037ef1b013c..b3a2196cbb0 100644 --- a/advisories/unreviewed/2024/12/GHSA-w8h6-mg97-8mq2/GHSA-w8h6-mg97-8mq2.json +++ b/advisories/unreviewed/2024/12/GHSA-w8h6-mg97-8mq2/GHSA-w8h6-mg97-8mq2.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-754" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/12/GHSA-wj49-p585-9263/GHSA-wj49-p585-9263.json b/advisories/unreviewed/2024/12/GHSA-wj49-p585-9263/GHSA-wj49-p585-9263.json index 37dee1ec886..dae7558e203 100644 --- a/advisories/unreviewed/2024/12/GHSA-wj49-p585-9263/GHSA-wj49-p585-9263.json +++ b/advisories/unreviewed/2024/12/GHSA-wj49-p585-9263/GHSA-wj49-p585-9263.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wj49-p585-9263", - "modified": "2024-12-12T03:33:06Z", + "modified": "2024-12-12T21:30:46Z", "published": "2024-12-12T03:33:06Z", "aliases": [ "CVE-2024-44220" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. Parsing a maliciously crafted video file may lead to unexpected system termination.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:23Z"