mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-5j2h-h5hg-3wf8 GHSA-qg36-9jxh-fj25 GHSA-pw8x-9www-h93w GHSA-5f54-x7j7-36p3 GHSA-9jg3-6mw2-g4q7 GHSA-5g5h-vp5m-chrx GHSA-v979-36xg-vp67 GHSA-r827-5p5r-w6f5 GHSA-3fpg-j8cw-vcjq GHSA-mqqf-4p7r-rf89 GHSA-q6w6-rjjj-5p52 GHSA-8g25-xmmm-86qm GHSA-2jpm-3fv2-55wf GHSA-2jvw-9p97-g4qj GHSA-42h3-v86m-8hc5 GHSA-5qfp-r7q3-257g GHSA-68ww-7h9f-48qx GHSA-7j8v-7qw4-w29q GHSA-8xm2-mrh9-q3x9 GHSA-99qx-qpwq-jm99 GHSA-f3mw-pmh2-74wc GHSA-mq89-7cwq-chfg GHSA-wpr3-95vq-q76j GHSA-x7c7-rpwp-w6fw
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-5j2h-h5hg-3wf8",
|
||||
"modified": "2024-05-16T18:44:20Z",
|
||||
"modified": "2024-09-16T21:30:38Z",
|
||||
"published": "2018-07-23T19:51:10Z",
|
||||
"aliases": [
|
||||
"CVE-2011-0696"
|
||||
@@ -9,7 +9,14 @@
|
||||
"summary": "Cross-site request forgery in Django",
|
||||
"details": "Django 1.1.x before 1.1.4 and 1.2.x before 1.2.5 does not properly validate HTTP requests that contain an X-Requested-With header, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via forged AJAX requests that leverage a \"combination of browser plugins and redirects,\" a related issue to CVE-2011-0447.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
|
||||
},
|
||||
{
|
||||
"type": "CVSS_V4",
|
||||
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
{
|
||||
@@ -22,7 +29,7 @@
|
||||
"type": "ECOSYSTEM",
|
||||
"events": [
|
||||
{
|
||||
"introduced": "1.1.0"
|
||||
"introduced": "1.1"
|
||||
},
|
||||
{
|
||||
"fixed": "1.1.4"
|
||||
@@ -41,7 +48,7 @@
|
||||
"type": "ECOSYSTEM",
|
||||
"events": [
|
||||
{
|
||||
"introduced": "1.2.0"
|
||||
"introduced": "1.2"
|
||||
},
|
||||
{
|
||||
"fixed": "1.2.5"
|
||||
@@ -76,6 +83,10 @@
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/django/django"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2011-10.yaml"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-February/054207.html"
|
||||
@@ -149,7 +160,7 @@
|
||||
"cwe_ids": [
|
||||
"CWE-352"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2020-06-16T21:16:24Z",
|
||||
"nvd_published_at": null
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-qg36-9jxh-fj25",
|
||||
"modified": "2023-05-26T21:50:46Z",
|
||||
"modified": "2024-09-16T21:31:26Z",
|
||||
"published": "2023-05-22T19:41:56Z",
|
||||
"aliases": [
|
||||
"CVE-2023-33185"
|
||||
@@ -12,6 +12,10 @@
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L"
|
||||
},
|
||||
{
|
||||
"type": "CVSS_V4",
|
||||
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-pw8x-9www-h93w",
|
||||
"modified": "2022-10-08T00:00:18Z",
|
||||
"modified": "2024-09-16T21:30:32Z",
|
||||
"published": "2021-12-21T00:00:39Z",
|
||||
"aliases": [
|
||||
"CVE-2021-35234"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-5f54-x7j7-36p3",
|
||||
"modified": "2022-04-29T00:00:57Z",
|
||||
"modified": "2024-09-16T21:30:32Z",
|
||||
"published": "2022-01-21T00:00:48Z",
|
||||
"aliases": [
|
||||
"CVE-2021-34600"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-9jg3-6mw2-g4q7",
|
||||
"modified": "2023-02-13T06:31:00Z",
|
||||
"modified": "2024-09-16T21:30:32Z",
|
||||
"published": "2022-03-19T00:00:59Z",
|
||||
"aliases": [
|
||||
"CVE-2021-23209"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-5g5h-vp5m-chrx",
|
||||
"modified": "2023-09-03T18:30:18Z",
|
||||
"modified": "2024-09-16T21:30:32Z",
|
||||
"published": "2022-05-24T19:16:18Z",
|
||||
"aliases": [
|
||||
"CVE-2021-3825"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-v979-36xg-vp67",
|
||||
"modified": "2022-11-22T21:30:17Z",
|
||||
"modified": "2024-09-16T21:30:34Z",
|
||||
"published": "2022-11-18T09:30:25Z",
|
||||
"aliases": [
|
||||
"CVE-2022-24037"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-r827-5p5r-w6f5",
|
||||
"modified": "2024-02-01T18:31:04Z",
|
||||
"modified": "2024-09-16T21:30:35Z",
|
||||
"published": "2023-07-06T19:24:05Z",
|
||||
"aliases": [
|
||||
"CVE-2022-2808"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-3fpg-j8cw-vcjq",
|
||||
"modified": "2024-05-22T18:30:40Z",
|
||||
"modified": "2024-09-16T21:30:37Z",
|
||||
"published": "2024-04-04T15:30:34Z",
|
||||
"aliases": [
|
||||
"CVE-2024-31081"
|
||||
@@ -45,6 +45,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/security/cve/CVE-2024-31081"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/errata/RHSA-2024:3343"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/errata/RHSA-2024:3261"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-mqqf-4p7r-rf89",
|
||||
"modified": "2024-05-22T18:30:40Z",
|
||||
"modified": "2024-09-16T21:30:37Z",
|
||||
"published": "2024-04-04T15:30:34Z",
|
||||
"aliases": [
|
||||
"CVE-2024-31080"
|
||||
@@ -45,6 +45,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/security/cve/CVE-2024-31080"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/errata/RHSA-2024:3343"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/errata/RHSA-2024:3261"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-q6w6-rjjj-5p52",
|
||||
"modified": "2024-05-22T18:30:40Z",
|
||||
"modified": "2024-09-16T21:30:37Z",
|
||||
"published": "2024-04-05T12:31:17Z",
|
||||
"aliases": [
|
||||
"CVE-2024-31083"
|
||||
@@ -45,6 +45,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/security/cve/CVE-2024-31083"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/errata/RHSA-2024:3343"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/errata/RHSA-2024:3261"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-8g25-xmmm-86qm",
|
||||
"modified": "2024-06-27T03:30:55Z",
|
||||
"modified": "2024-09-16T21:30:37Z",
|
||||
"published": "2024-06-12T09:30:48Z",
|
||||
"aliases": [
|
||||
"CVE-2024-3183"
|
||||
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-2jpm-3fv2-55wf",
|
||||
"modified": "2024-09-16T21:30:38Z",
|
||||
"published": "2024-09-16T21:30:38Z",
|
||||
"aliases": [
|
||||
"CVE-2024-8766"
|
||||
],
|
||||
"details": "Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 38235.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8766"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security-advisory.acronis.com/advisories/SEC-7218"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-427"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-09-16T20:15:47Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-2jvw-9p97-g4qj",
|
||||
"modified": "2024-09-16T21:30:38Z",
|
||||
"published": "2024-09-16T21:30:38Z",
|
||||
"aliases": [
|
||||
"CVE-2024-42796"
|
||||
],
|
||||
"details": "An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_genre in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid music genre entries.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42796"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Music%20Management%20System%20v1.0/Broken%20Access%20Control%20-%20Delete%20Genre.pdf"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.kashipara.com/project/php/12978/music-management-system-in-php-php-project-source-code"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-09-16T20:15:46Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-42h3-v86m-8hc5",
|
||||
"modified": "2024-09-16T21:30:38Z",
|
||||
"published": "2024-09-16T21:30:38Z",
|
||||
"aliases": [
|
||||
"CVE-2024-45414"
|
||||
],
|
||||
"details": "The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in webPrivateDecrypt function. This function is responsible for decrypting RSA encrypted ciphertext, the encrypted data is supplied base64 encoded. The decoded ciphertext is stored on the stack without checking its length. An unauthenticated attacker can get RCE as root by exploiting this vulnerability.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45414"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://wr3nchsr.github.io/zte-multiple-routers-httpd-vulnerabilities-advisory"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-09-16T21:15:45Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-5qfp-r7q3-257g",
|
||||
"modified": "2024-09-16T21:30:38Z",
|
||||
"published": "2024-09-16T21:30:38Z",
|
||||
"aliases": [
|
||||
"CVE-2024-45416"
|
||||
],
|
||||
"details": "The HTTPD binary in multiple ZTE routers has a local file inclusion vulnerability in session_init function. The session -LUA- files are stored in the directory /var/lua_session, the function iterates on all files in this directory and executes them using the function dofile without any validation if it is a valid session file or not. An attacker who is able to write a malicious file in the sessions directory can get RCE as root.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45416"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://wr3nchsr.github.io/zte-multiple-routers-httpd-vulnerabilities-advisory"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-09-16T21:15:46Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-68ww-7h9f-48qx",
|
||||
"modified": "2024-09-16T21:30:38Z",
|
||||
"published": "2024-09-16T21:30:38Z",
|
||||
"aliases": [
|
||||
"CVE-2024-45415"
|
||||
],
|
||||
"details": "The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in check_data_integrity function. This function is responsible for validating the checksum of data in post request. The checksum is sent encrypted in the request, the function decrypts it and stores the checksum on the stack without validating it. An unauthenticated attacker can get RCE as root by exploiting this vulnerability.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45415"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://wr3nchsr.github.io/zte-multiple-routers-httpd-vulnerabilities-advisory"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-09-16T21:15:45Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-7j8v-7qw4-w29q",
|
||||
"modified": "2024-09-16T21:30:38Z",
|
||||
"published": "2024-09-16T21:30:38Z",
|
||||
"aliases": [
|
||||
"CVE-2024-22013"
|
||||
],
|
||||
"details": "U-Boot environment is read from unauthenticated partition.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22013"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://support.google.com/product-documentation/answer/14950962?hl=en&ref_topic=12974021&sjid=9595902703262170957-NA#zippy=%2Cwifi"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-09-16T20:15:45Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-8xm2-mrh9-q3x9",
|
||||
"modified": "2024-09-16T21:30:38Z",
|
||||
"published": "2024-09-16T21:30:38Z",
|
||||
"aliases": [
|
||||
"CVE-2024-42798"
|
||||
],
|
||||
"details": "An Incorrect Access Control vulnerability was found in /music/index.php?page=user_list and /music/index.php?page=edit_user in Kashipara Music Management System v1.0. This allows a low privileged attacker to take over the administrator account.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42798"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Music%20Management%20System%20v1.0/Broken%20Access%20Control%20-%20Priv%20Esc%20-%20Save%20Edit%20User%20-%20AC%20Takeover.pdf"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.kashipara.com"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-09-16T20:15:46Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-99qx-qpwq-jm99",
|
||||
"modified": "2024-09-16T21:30:38Z",
|
||||
"published": "2024-09-16T21:30:38Z",
|
||||
"aliases": [
|
||||
"CVE-2024-34016"
|
||||
],
|
||||
"details": "Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 38235.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34016"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security-advisory.acronis.com/advisories/SEC-7188"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-427"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-09-16T20:15:46Z"
|
||||
}
|
||||
}
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user