Publish Advisories

GHSA-24jp-gg22-pxj3
GHSA-56hg-r682-945v
GHSA-7c88-698j-qxf8
GHSA-p55r-fqh8-ccwq
GHSA-294q-5vvf-xj65
GHSA-55rp-jrc5-px98
GHSA-6crp-pv4g-xcj8
GHSA-jjqv-cfcp-2xj7
GHSA-m87m-mmvp-v9qm
GHSA-q9gh-wgf2-5fp3
GHSA-vg42-hcc7-h8cf
This commit is contained in:
advisory-database[bot]
2024-06-05 15:32:03 +00:00
parent 00478718b3
commit 5aa9beb3ae
11 changed files with 301 additions and 6 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-24jp-gg22-pxj3",
"modified": "2024-03-26T09:32:58Z",
"modified": "2024-06-05T15:30:38Z",
"published": "2024-03-26T09:32:58Z",
"aliases": [
"CVE-2023-51416"
@@ -25,7 +25,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-20"
],
"severity": null,
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7c88-698j-qxf8",
"modified": "2024-05-14T18:30:54Z",
"modified": "2024-06-05T15:30:38Z",
"published": "2024-05-14T18:30:54Z",
"aliases": [
"CVE-2024-4231"
@@ -25,7 +25,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-1191"
],
"severity": null,
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p55r-fqh8-ccwq",
"modified": "2024-05-14T18:30:54Z",
"modified": "2024-06-05T15:30:38Z",
"published": "2024-05-14T18:30:54Z",
"aliases": [
"CVE-2024-4232"
@@ -25,7 +25,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-256"
],
"severity": null,
"github_reviewed": false,
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-294q-5vvf-xj65",
"modified": "2024-06-05T15:30:39Z",
"published": "2024-06-05T15:30:39Z",
"aliases": [
"CVE-2024-36837"
],
"details": "SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProductList function in the ProductController.php file.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36837"
},
{
"type": "WEB",
"url": "https://7nkdkj-my.sharepoint.com/:w:/g/personal/krypt0n_7nkdkj_onmicrosoft_com/Ea8dW8YuldRMqgCy7KHjnxABTJCVPLShHIJfqQk684mD3A?e=0qmN7t"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-05T15:15:11Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-55rp-jrc5-px98",
"modified": "2024-06-05T15:30:39Z",
"published": "2024-06-05T15:30:39Z",
"aliases": [
"CVE-2024-35673"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in Pure Chat by Ruby Pure Chat.This issue affects Pure Chat: from n/a through 2.22.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35673"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/pure-chat/wordpress-pure-chat-plugin-2-22-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-05T14:15:13Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6crp-pv4g-xcj8",
"modified": "2024-06-05T15:30:39Z",
"published": "2024-06-05T15:30:39Z",
"aliases": [
"CVE-2024-3469"
],
"details": "The GP Premium plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the message parameter in all versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3469"
},
{
"type": "WEB",
"url": "https://generatepress.com/category/changelog"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1a697391-f30d-403f-9046-8fa219a49302?source=cve"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-05T13:15:12Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jjqv-cfcp-2xj7",
"modified": "2024-06-05T15:30:39Z",
"published": "2024-06-05T15:30:39Z",
"aliases": [
"CVE-2024-4812"
],
"details": "A flaw was found in the Katello plugin for Foreman, where it is possible to store malicious JavaScript code in the \"Description\" field of a user. This code can be executed when opening certain pages, for example, Host Collections.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4812"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-4812"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2280187"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-05T15:15:12Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m87m-mmvp-v9qm",
"modified": "2024-06-05T15:30:39Z",
"published": "2024-06-05T15:30:39Z",
"aliases": [
"CVE-2024-5629"
],
"details": "An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a Server to raise an exception which may contain arbitrary application memory.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5629"
},
{
"type": "WEB",
"url": "https://jira.mongodb.org/browse/PYTHON-4305"
}
],
"database_specific": {
"cwe_ids": [
"CWE-125"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-05T15:15:12Z"
}
}
@@ -0,0 +1,58 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q9gh-wgf2-5fp3",
"modified": "2024-06-05T15:30:39Z",
"published": "2024-06-05T15:30:39Z",
"aliases": [
"CVE-2024-5459"
],
"details": "The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on 'add_section', 'add_menu', 'add_menu_item', and 'add_menu_page' functions in all versions up to, and including, 2.4.16. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create menu sections, menus, food items, and new menu pages.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5459"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/food-and-drink-menu/trunk/includes/class-installation-walkthrough.php#L111"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/food-and-drink-menu/trunk/includes/class-installation-walkthrough.php#L144"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/food-and-drink-menu/trunk/includes/class-installation-walkthrough.php#L62"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/food-and-drink-menu/trunk/includes/class-installation-walkthrough.php#L80"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3097599"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/03f9d9bb-6a87-4da9-bbb0-65203d7250e9?source=cve"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-05T13:15:13Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vg42-hcc7-h8cf",
"modified": "2024-06-05T15:30:39Z",
"published": "2024-06-05T15:30:39Z",
"aliases": [
"CVE-2024-3716"
],
"details": "A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue leaks the password in the process list and allows an attacker to take advantage and obtain the password.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3716"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-3716"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2274755"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-05T15:15:12Z"
}
}