From 5a9ceedcc9e56b81d3964fed7ff4b0fff1560488 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 24 Sep 2024 21:32:48 +0000 Subject: [PATCH] Publish Advisories GHSA-38j2-mm6q-835r GHSA-3c83-x7hx-cgfx GHSA-57jv-pfhx-pfm5 GHSA-89vx-x763-hhwj GHSA-97rq-m5jx-vcxq GHSA-cmvv-gwr2-36xm GHSA-h9cp-5vvc-8wqc GHSA-m4c2-8cgc-49gg GHSA-p863-p79f-qm33 GHSA-q7q3-4cwr-583j GHSA-qcjx-5p37-v6hf --- .../09/GHSA-38j2-mm6q-835r/GHSA-38j2-mm6q-835r.json | 9 ++++++--- .../09/GHSA-3c83-x7hx-cgfx/GHSA-3c83-x7hx-cgfx.json | 9 ++++++--- .../09/GHSA-57jv-pfhx-pfm5/GHSA-57jv-pfhx-pfm5.json | 9 ++++++--- .../09/GHSA-89vx-x763-hhwj/GHSA-89vx-x763-hhwj.json | 11 +++++++---- .../09/GHSA-97rq-m5jx-vcxq/GHSA-97rq-m5jx-vcxq.json | 9 ++++++--- .../09/GHSA-cmvv-gwr2-36xm/GHSA-cmvv-gwr2-36xm.json | 11 +++++++---- .../09/GHSA-h9cp-5vvc-8wqc/GHSA-h9cp-5vvc-8wqc.json | 9 ++++++--- .../09/GHSA-m4c2-8cgc-49gg/GHSA-m4c2-8cgc-49gg.json | 9 ++++++--- .../09/GHSA-p863-p79f-qm33/GHSA-p863-p79f-qm33.json | 11 +++++++---- .../09/GHSA-q7q3-4cwr-583j/GHSA-q7q3-4cwr-583j.json | 11 +++++++---- .../09/GHSA-qcjx-5p37-v6hf/GHSA-qcjx-5p37-v6hf.json | 9 ++++++--- 11 files changed, 70 insertions(+), 37 deletions(-) diff --git a/advisories/unreviewed/2024/09/GHSA-38j2-mm6q-835r/GHSA-38j2-mm6q-835r.json b/advisories/unreviewed/2024/09/GHSA-38j2-mm6q-835r/GHSA-38j2-mm6q-835r.json index 37c95059d9f..b1f8284a778 100644 --- a/advisories/unreviewed/2024/09/GHSA-38j2-mm6q-835r/GHSA-38j2-mm6q-835r.json +++ b/advisories/unreviewed/2024/09/GHSA-38j2-mm6q-835r/GHSA-38j2-mm6q-835r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-38j2-mm6q-835r", - "modified": "2024-09-17T00:31:06Z", + "modified": "2024-09-24T21:31:22Z", "published": "2024-09-17T00:31:06Z", "aliases": [ "CVE-2024-44184" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7, iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to access user-sensitive data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:51Z" diff --git a/advisories/unreviewed/2024/09/GHSA-3c83-x7hx-cgfx/GHSA-3c83-x7hx-cgfx.json b/advisories/unreviewed/2024/09/GHSA-3c83-x7hx-cgfx/GHSA-3c83-x7hx-cgfx.json index 16382d23730..bb18dc511d6 100644 --- a/advisories/unreviewed/2024/09/GHSA-3c83-x7hx-cgfx/GHSA-3c83-x7hx-cgfx.json +++ b/advisories/unreviewed/2024/09/GHSA-3c83-x7hx-cgfx/GHSA-3c83-x7hx-cgfx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3c83-x7hx-cgfx", - "modified": "2024-09-17T00:31:05Z", + "modified": "2024-09-24T21:31:22Z", "published": "2024-09-17T00:31:05Z", "aliases": [ "CVE-2024-44130" ], "details": "This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15. An app with root privileges may be able to access private information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:50Z" diff --git a/advisories/unreviewed/2024/09/GHSA-57jv-pfhx-pfm5/GHSA-57jv-pfhx-pfm5.json b/advisories/unreviewed/2024/09/GHSA-57jv-pfhx-pfm5/GHSA-57jv-pfhx-pfm5.json index 640ca6af944..d3b3f99871a 100644 --- a/advisories/unreviewed/2024/09/GHSA-57jv-pfhx-pfm5/GHSA-57jv-pfhx-pfm5.json +++ b/advisories/unreviewed/2024/09/GHSA-57jv-pfhx-pfm5/GHSA-57jv-pfhx-pfm5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-57jv-pfhx-pfm5", - "modified": "2024-09-17T00:31:06Z", + "modified": "2024-09-24T21:31:22Z", "published": "2024-09-17T00:31:06Z", "aliases": [ "CVE-2024-44189" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15. A logic issue existed where a process may be able to capture screen contents without user consent.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:52Z" diff --git a/advisories/unreviewed/2024/09/GHSA-89vx-x763-hhwj/GHSA-89vx-x763-hhwj.json b/advisories/unreviewed/2024/09/GHSA-89vx-x763-hhwj/GHSA-89vx-x763-hhwj.json index 534d1656ee4..83aacee346a 100644 --- a/advisories/unreviewed/2024/09/GHSA-89vx-x763-hhwj/GHSA-89vx-x763-hhwj.json +++ b/advisories/unreviewed/2024/09/GHSA-89vx-x763-hhwj/GHSA-89vx-x763-hhwj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-89vx-x763-hhwj", - "modified": "2024-09-19T21:33:29Z", + "modified": "2024-09-24T21:31:22Z", "published": "2024-09-19T21:33:29Z", "aliases": [ "CVE-2024-25673" ], "details": "Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-74" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-19T19:15:24Z" diff --git a/advisories/unreviewed/2024/09/GHSA-97rq-m5jx-vcxq/GHSA-97rq-m5jx-vcxq.json b/advisories/unreviewed/2024/09/GHSA-97rq-m5jx-vcxq/GHSA-97rq-m5jx-vcxq.json index 6ad6b2fb3a9..1fd8d3b4a5d 100644 --- a/advisories/unreviewed/2024/09/GHSA-97rq-m5jx-vcxq/GHSA-97rq-m5jx-vcxq.json +++ b/advisories/unreviewed/2024/09/GHSA-97rq-m5jx-vcxq/GHSA-97rq-m5jx-vcxq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-97rq-m5jx-vcxq", - "modified": "2024-09-17T00:31:06Z", + "modified": "2024-09-24T21:31:22Z", "published": "2024-09-17T00:31:06Z", "aliases": [ "CVE-2024-44180" ], "details": "The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical access may be able to access contacts from the lock screen.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:51Z" diff --git a/advisories/unreviewed/2024/09/GHSA-cmvv-gwr2-36xm/GHSA-cmvv-gwr2-36xm.json b/advisories/unreviewed/2024/09/GHSA-cmvv-gwr2-36xm/GHSA-cmvv-gwr2-36xm.json index d3b9e9319b5..19c9e6c887a 100644 --- a/advisories/unreviewed/2024/09/GHSA-cmvv-gwr2-36xm/GHSA-cmvv-gwr2-36xm.json +++ b/advisories/unreviewed/2024/09/GHSA-cmvv-gwr2-36xm/GHSA-cmvv-gwr2-36xm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cmvv-gwr2-36xm", - "modified": "2024-09-17T00:31:05Z", + "modified": "2024-09-24T21:31:22Z", "published": "2024-09-17T00:31:05Z", "aliases": [ "CVE-2024-44131" ], "details": "This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to access sensitive user data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:50Z" diff --git a/advisories/unreviewed/2024/09/GHSA-h9cp-5vvc-8wqc/GHSA-h9cp-5vvc-8wqc.json b/advisories/unreviewed/2024/09/GHSA-h9cp-5vvc-8wqc/GHSA-h9cp-5vvc-8wqc.json index 2358b0720eb..ea6d8d4ad2b 100644 --- a/advisories/unreviewed/2024/09/GHSA-h9cp-5vvc-8wqc/GHSA-h9cp-5vvc-8wqc.json +++ b/advisories/unreviewed/2024/09/GHSA-h9cp-5vvc-8wqc/GHSA-h9cp-5vvc-8wqc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h9cp-5vvc-8wqc", - "modified": "2024-09-17T00:31:04Z", + "modified": "2024-09-24T21:31:22Z", "published": "2024-09-17T00:31:04Z", "aliases": [ "CVE-2024-40866" ], "details": "The issue was addressed with improved UI. This issue is fixed in Safari 18, macOS Sequoia 15. Visiting a malicious website may lead to address bar spoofing.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:49Z" diff --git a/advisories/unreviewed/2024/09/GHSA-m4c2-8cgc-49gg/GHSA-m4c2-8cgc-49gg.json b/advisories/unreviewed/2024/09/GHSA-m4c2-8cgc-49gg/GHSA-m4c2-8cgc-49gg.json index 076e3c13e92..868aa127685 100644 --- a/advisories/unreviewed/2024/09/GHSA-m4c2-8cgc-49gg/GHSA-m4c2-8cgc-49gg.json +++ b/advisories/unreviewed/2024/09/GHSA-m4c2-8cgc-49gg/GHSA-m4c2-8cgc-49gg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m4c2-8cgc-49gg", - "modified": "2024-09-17T00:31:06Z", + "modified": "2024-09-24T21:31:22Z", "published": "2024-09-17T00:31:06Z", "aliases": [ "CVE-2024-44183" ], "details": "A logic error was addressed with improved error handling. This issue is fixed in macOS Ventura 13.7, iOS 17.7 and iPadOS 17.7, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iPadOS 18, macOS Sonoma 14.7, tvOS 18. An app may be able to cause a denial-of-service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:51Z" diff --git a/advisories/unreviewed/2024/09/GHSA-p863-p79f-qm33/GHSA-p863-p79f-qm33.json b/advisories/unreviewed/2024/09/GHSA-p863-p79f-qm33/GHSA-p863-p79f-qm33.json index 070c754fcba..78f00d8bb69 100644 --- a/advisories/unreviewed/2024/09/GHSA-p863-p79f-qm33/GHSA-p863-p79f-qm33.json +++ b/advisories/unreviewed/2024/09/GHSA-p863-p79f-qm33/GHSA-p863-p79f-qm33.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p863-p79f-qm33", - "modified": "2024-09-17T00:31:06Z", + "modified": "2024-09-24T21:31:22Z", "published": "2024-09-17T00:31:06Z", "aliases": [ "CVE-2024-44188" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. An app may be able to access protected user data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-281" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:52Z" diff --git a/advisories/unreviewed/2024/09/GHSA-q7q3-4cwr-583j/GHSA-q7q3-4cwr-583j.json b/advisories/unreviewed/2024/09/GHSA-q7q3-4cwr-583j/GHSA-q7q3-4cwr-583j.json index 2c4ab0db3f8..c8b07be25bc 100644 --- a/advisories/unreviewed/2024/09/GHSA-q7q3-4cwr-583j/GHSA-q7q3-4cwr-583j.json +++ b/advisories/unreviewed/2024/09/GHSA-q7q3-4cwr-583j/GHSA-q7q3-4cwr-583j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q7q3-4cwr-583j", - "modified": "2024-09-17T00:31:04Z", + "modified": "2024-09-24T21:31:22Z", "published": "2024-09-17T00:31:04Z", "aliases": [ "CVE-2024-40859" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. An app may be able to access user-sensitive data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-281" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:49Z" diff --git a/advisories/unreviewed/2024/09/GHSA-qcjx-5p37-v6hf/GHSA-qcjx-5p37-v6hf.json b/advisories/unreviewed/2024/09/GHSA-qcjx-5p37-v6hf/GHSA-qcjx-5p37-v6hf.json index feb5fe45b30..605ed0886cf 100644 --- a/advisories/unreviewed/2024/09/GHSA-qcjx-5p37-v6hf/GHSA-qcjx-5p37-v6hf.json +++ b/advisories/unreviewed/2024/09/GHSA-qcjx-5p37-v6hf/GHSA-qcjx-5p37-v6hf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qcjx-5p37-v6hf", - "modified": "2024-09-17T00:31:06Z", + "modified": "2024-09-24T21:31:22Z", "published": "2024-09-17T00:31:06Z", "aliases": [ "CVE-2024-44181" ], "details": "An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to read sensitive location information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:51Z"