diff --git a/advisories/unreviewed/2024/03/GHSA-24jp-gg22-pxj3/GHSA-24jp-gg22-pxj3.json b/advisories/unreviewed/2024/03/GHSA-24jp-gg22-pxj3/GHSA-24jp-gg22-pxj3.json index b17a3bbeb34..edc27c44aa5 100644 --- a/advisories/unreviewed/2024/03/GHSA-24jp-gg22-pxj3/GHSA-24jp-gg22-pxj3.json +++ b/advisories/unreviewed/2024/03/GHSA-24jp-gg22-pxj3/GHSA-24jp-gg22-pxj3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-24jp-gg22-pxj3", - "modified": "2024-03-26T09:32:58Z", + "modified": "2024-06-05T15:30:38Z", "published": "2024-03-26T09:32:58Z", "aliases": [ "CVE-2023-51416" diff --git a/advisories/unreviewed/2024/05/GHSA-56hg-r682-945v/GHSA-56hg-r682-945v.json b/advisories/unreviewed/2024/05/GHSA-56hg-r682-945v/GHSA-56hg-r682-945v.json index fa549bb267c..affe896b3f7 100644 --- a/advisories/unreviewed/2024/05/GHSA-56hg-r682-945v/GHSA-56hg-r682-945v.json +++ b/advisories/unreviewed/2024/05/GHSA-56hg-r682-945v/GHSA-56hg-r682-945v.json @@ -25,7 +25,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-7c88-698j-qxf8/GHSA-7c88-698j-qxf8.json b/advisories/unreviewed/2024/05/GHSA-7c88-698j-qxf8/GHSA-7c88-698j-qxf8.json index 6a2199d810b..c9ae326ae6e 100644 --- a/advisories/unreviewed/2024/05/GHSA-7c88-698j-qxf8/GHSA-7c88-698j-qxf8.json +++ b/advisories/unreviewed/2024/05/GHSA-7c88-698j-qxf8/GHSA-7c88-698j-qxf8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7c88-698j-qxf8", - "modified": "2024-05-14T18:30:54Z", + "modified": "2024-06-05T15:30:38Z", "published": "2024-05-14T18:30:54Z", "aliases": [ "CVE-2024-4231" @@ -25,7 +25,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1191" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-p55r-fqh8-ccwq/GHSA-p55r-fqh8-ccwq.json b/advisories/unreviewed/2024/05/GHSA-p55r-fqh8-ccwq/GHSA-p55r-fqh8-ccwq.json index 2f26bb5f2ad..0eaf4b29ec5 100644 --- a/advisories/unreviewed/2024/05/GHSA-p55r-fqh8-ccwq/GHSA-p55r-fqh8-ccwq.json +++ b/advisories/unreviewed/2024/05/GHSA-p55r-fqh8-ccwq/GHSA-p55r-fqh8-ccwq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p55r-fqh8-ccwq", - "modified": "2024-05-14T18:30:54Z", + "modified": "2024-06-05T15:30:38Z", "published": "2024-05-14T18:30:54Z", "aliases": [ "CVE-2024-4232" @@ -25,7 +25,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-256" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-294q-5vvf-xj65/GHSA-294q-5vvf-xj65.json b/advisories/unreviewed/2024/06/GHSA-294q-5vvf-xj65/GHSA-294q-5vvf-xj65.json new file mode 100644 index 00000000000..8488b92748d --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-294q-5vvf-xj65/GHSA-294q-5vvf-xj65.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-294q-5vvf-xj65", + "modified": "2024-06-05T15:30:39Z", + "published": "2024-06-05T15:30:39Z", + "aliases": [ + "CVE-2024-36837" + ], + "details": "SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProductList function in the ProductController.php file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36837" + }, + { + "type": "WEB", + "url": "https://7nkdkj-my.sharepoint.com/:w:/g/personal/krypt0n_7nkdkj_onmicrosoft_com/Ea8dW8YuldRMqgCy7KHjnxABTJCVPLShHIJfqQk684mD3A?e=0qmN7t" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-05T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-55rp-jrc5-px98/GHSA-55rp-jrc5-px98.json b/advisories/unreviewed/2024/06/GHSA-55rp-jrc5-px98/GHSA-55rp-jrc5-px98.json new file mode 100644 index 00000000000..d2017c8e48e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-55rp-jrc5-px98/GHSA-55rp-jrc5-px98.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55rp-jrc5-px98", + "modified": "2024-06-05T15:30:39Z", + "published": "2024-06-05T15:30:39Z", + "aliases": [ + "CVE-2024-35673" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Pure Chat by Ruby Pure Chat.This issue affects Pure Chat: from n/a through 2.22.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35673" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/pure-chat/wordpress-pure-chat-plugin-2-22-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-05T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-6crp-pv4g-xcj8/GHSA-6crp-pv4g-xcj8.json b/advisories/unreviewed/2024/06/GHSA-6crp-pv4g-xcj8/GHSA-6crp-pv4g-xcj8.json new file mode 100644 index 00000000000..a0788f3727d --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-6crp-pv4g-xcj8/GHSA-6crp-pv4g-xcj8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6crp-pv4g-xcj8", + "modified": "2024-06-05T15:30:39Z", + "published": "2024-06-05T15:30:39Z", + "aliases": [ + "CVE-2024-3469" + ], + "details": "The GP Premium plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the message parameter in all versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3469" + }, + { + "type": "WEB", + "url": "https://generatepress.com/category/changelog" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1a697391-f30d-403f-9046-8fa219a49302?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-05T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-jjqv-cfcp-2xj7/GHSA-jjqv-cfcp-2xj7.json b/advisories/unreviewed/2024/06/GHSA-jjqv-cfcp-2xj7/GHSA-jjqv-cfcp-2xj7.json new file mode 100644 index 00000000000..f2d51e58101 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-jjqv-cfcp-2xj7/GHSA-jjqv-cfcp-2xj7.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjqv-cfcp-2xj7", + "modified": "2024-06-05T15:30:39Z", + "published": "2024-06-05T15:30:39Z", + "aliases": [ + "CVE-2024-4812" + ], + "details": "A flaw was found in the Katello plugin for Foreman, where it is possible to store malicious JavaScript code in the \"Description\" field of a user. This code can be executed when opening certain pages, for example, Host Collections.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4812" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-4812" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2280187" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-05T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-m87m-mmvp-v9qm/GHSA-m87m-mmvp-v9qm.json b/advisories/unreviewed/2024/06/GHSA-m87m-mmvp-v9qm/GHSA-m87m-mmvp-v9qm.json new file mode 100644 index 00000000000..d0142b560c5 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-m87m-mmvp-v9qm/GHSA-m87m-mmvp-v9qm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m87m-mmvp-v9qm", + "modified": "2024-06-05T15:30:39Z", + "published": "2024-06-05T15:30:39Z", + "aliases": [ + "CVE-2024-5629" + ], + "details": "An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a Server to raise an exception which may contain arbitrary application memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5629" + }, + { + "type": "WEB", + "url": "https://jira.mongodb.org/browse/PYTHON-4305" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-05T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-q9gh-wgf2-5fp3/GHSA-q9gh-wgf2-5fp3.json b/advisories/unreviewed/2024/06/GHSA-q9gh-wgf2-5fp3/GHSA-q9gh-wgf2-5fp3.json new file mode 100644 index 00000000000..db31b7b3e01 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-q9gh-wgf2-5fp3/GHSA-q9gh-wgf2-5fp3.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q9gh-wgf2-5fp3", + "modified": "2024-06-05T15:30:39Z", + "published": "2024-06-05T15:30:39Z", + "aliases": [ + "CVE-2024-5459" + ], + "details": "The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on 'add_section', 'add_menu', 'add_menu_item', and 'add_menu_page' functions in all versions up to, and including, 2.4.16. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create menu sections, menus, food items, and new menu pages.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5459" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/food-and-drink-menu/trunk/includes/class-installation-walkthrough.php#L111" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/food-and-drink-menu/trunk/includes/class-installation-walkthrough.php#L144" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/food-and-drink-menu/trunk/includes/class-installation-walkthrough.php#L62" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/food-and-drink-menu/trunk/includes/class-installation-walkthrough.php#L80" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3097599" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/03f9d9bb-6a87-4da9-bbb0-65203d7250e9?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-05T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-vg42-hcc7-h8cf/GHSA-vg42-hcc7-h8cf.json b/advisories/unreviewed/2024/06/GHSA-vg42-hcc7-h8cf/GHSA-vg42-hcc7-h8cf.json new file mode 100644 index 00000000000..6abd348ca1d --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-vg42-hcc7-h8cf/GHSA-vg42-hcc7-h8cf.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vg42-hcc7-h8cf", + "modified": "2024-06-05T15:30:39Z", + "published": "2024-06-05T15:30:39Z", + "aliases": [ + "CVE-2024-3716" + ], + "details": "A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue leaks the password in the process list and allows an attacker to take advantage and obtain the password.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3716" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-3716" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2274755" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-05T15:15:12Z" + } +} \ No newline at end of file