From 5bbfa2c1211008d086fb969890f574f93b709e6b Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 16 Sep 2024 21:32:20 +0000 Subject: [PATCH] Publish Advisories GHSA-5j2h-h5hg-3wf8 GHSA-qg36-9jxh-fj25 GHSA-pw8x-9www-h93w GHSA-5f54-x7j7-36p3 GHSA-9jg3-6mw2-g4q7 GHSA-5g5h-vp5m-chrx GHSA-v979-36xg-vp67 GHSA-r827-5p5r-w6f5 GHSA-3fpg-j8cw-vcjq GHSA-mqqf-4p7r-rf89 GHSA-q6w6-rjjj-5p52 GHSA-8g25-xmmm-86qm GHSA-2jpm-3fv2-55wf GHSA-2jvw-9p97-g4qj GHSA-42h3-v86m-8hc5 GHSA-5qfp-r7q3-257g GHSA-68ww-7h9f-48qx GHSA-7j8v-7qw4-w29q GHSA-8xm2-mrh9-q3x9 GHSA-99qx-qpwq-jm99 GHSA-f3mw-pmh2-74wc GHSA-mq89-7cwq-chfg GHSA-wpr3-95vq-q76j GHSA-x7c7-rpwp-w6fw --- .../GHSA-5j2h-h5hg-3wf8.json | 21 +++++++--- .../GHSA-qg36-9jxh-fj25.json | 6 ++- .../GHSA-pw8x-9www-h93w.json | 2 +- .../GHSA-5f54-x7j7-36p3.json | 2 +- .../GHSA-9jg3-6mw2-g4q7.json | 2 +- .../GHSA-5g5h-vp5m-chrx.json | 2 +- .../GHSA-v979-36xg-vp67.json | 2 +- .../GHSA-r827-5p5r-w6f5.json | 2 +- .../GHSA-3fpg-j8cw-vcjq.json | 6 ++- .../GHSA-mqqf-4p7r-rf89.json | 6 ++- .../GHSA-q6w6-rjjj-5p52.json | 6 ++- .../GHSA-8g25-xmmm-86qm.json | 2 +- .../GHSA-2jpm-3fv2-55wf.json | 38 ++++++++++++++++++ .../GHSA-2jvw-9p97-g4qj.json | 39 +++++++++++++++++++ .../GHSA-42h3-v86m-8hc5.json | 35 +++++++++++++++++ .../GHSA-5qfp-r7q3-257g.json | 35 +++++++++++++++++ .../GHSA-68ww-7h9f-48qx.json | 35 +++++++++++++++++ .../GHSA-7j8v-7qw4-w29q.json | 35 +++++++++++++++++ .../GHSA-8xm2-mrh9-q3x9.json | 39 +++++++++++++++++++ .../GHSA-99qx-qpwq-jm99.json | 38 ++++++++++++++++++ .../GHSA-f3mw-pmh2-74wc.json | 35 +++++++++++++++++ .../GHSA-mq89-7cwq-chfg.json | 35 +++++++++++++++++ .../GHSA-wpr3-95vq-q76j.json | 39 +++++++++++++++++++ .../GHSA-x7c7-rpwp-w6fw.json | 39 +++++++++++++++++++ 24 files changed, 485 insertions(+), 16 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-2jpm-3fv2-55wf/GHSA-2jpm-3fv2-55wf.json create mode 100644 advisories/unreviewed/2024/09/GHSA-2jvw-9p97-g4qj/GHSA-2jvw-9p97-g4qj.json create mode 100644 advisories/unreviewed/2024/09/GHSA-42h3-v86m-8hc5/GHSA-42h3-v86m-8hc5.json create mode 100644 advisories/unreviewed/2024/09/GHSA-5qfp-r7q3-257g/GHSA-5qfp-r7q3-257g.json create mode 100644 advisories/unreviewed/2024/09/GHSA-68ww-7h9f-48qx/GHSA-68ww-7h9f-48qx.json create mode 100644 advisories/unreviewed/2024/09/GHSA-7j8v-7qw4-w29q/GHSA-7j8v-7qw4-w29q.json create mode 100644 advisories/unreviewed/2024/09/GHSA-8xm2-mrh9-q3x9/GHSA-8xm2-mrh9-q3x9.json create mode 100644 advisories/unreviewed/2024/09/GHSA-99qx-qpwq-jm99/GHSA-99qx-qpwq-jm99.json create mode 100644 advisories/unreviewed/2024/09/GHSA-f3mw-pmh2-74wc/GHSA-f3mw-pmh2-74wc.json create mode 100644 advisories/unreviewed/2024/09/GHSA-mq89-7cwq-chfg/GHSA-mq89-7cwq-chfg.json create mode 100644 advisories/unreviewed/2024/09/GHSA-wpr3-95vq-q76j/GHSA-wpr3-95vq-q76j.json create mode 100644 advisories/unreviewed/2024/09/GHSA-x7c7-rpwp-w6fw/GHSA-x7c7-rpwp-w6fw.json diff --git a/advisories/github-reviewed/2018/07/GHSA-5j2h-h5hg-3wf8/GHSA-5j2h-h5hg-3wf8.json b/advisories/github-reviewed/2018/07/GHSA-5j2h-h5hg-3wf8/GHSA-5j2h-h5hg-3wf8.json index b3b38e905ad..8795ec968e6 100644 --- a/advisories/github-reviewed/2018/07/GHSA-5j2h-h5hg-3wf8/GHSA-5j2h-h5hg-3wf8.json +++ b/advisories/github-reviewed/2018/07/GHSA-5j2h-h5hg-3wf8/GHSA-5j2h-h5hg-3wf8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5j2h-h5hg-3wf8", - "modified": "2024-05-16T18:44:20Z", + "modified": "2024-09-16T21:30:38Z", "published": "2018-07-23T19:51:10Z", "aliases": [ "CVE-2011-0696" @@ -9,7 +9,14 @@ "summary": "Cross-site request forgery in Django", "details": "Django 1.1.x before 1.1.4 and 1.2.x before 1.2.5 does not properly validate HTTP requests that contain an X-Requested-With header, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via forged AJAX requests that leverage a \"combination of browser plugins and redirects,\" a related issue to CVE-2011-0447.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" + } ], "affected": [ { @@ -22,7 +29,7 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "1.1.0" + "introduced": "1.1" }, { "fixed": "1.1.4" @@ -41,7 +48,7 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "1.2.0" + "introduced": "1.2" }, { "fixed": "1.2.5" @@ -76,6 +83,10 @@ "type": "PACKAGE", "url": "https://github.com/django/django" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2011-10.yaml" + }, { "type": "WEB", "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-February/054207.html" @@ -149,7 +160,7 @@ "cwe_ids": [ "CWE-352" ], - "severity": "MODERATE", + "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2020-06-16T21:16:24Z", "nvd_published_at": null diff --git a/advisories/github-reviewed/2023/05/GHSA-qg36-9jxh-fj25/GHSA-qg36-9jxh-fj25.json b/advisories/github-reviewed/2023/05/GHSA-qg36-9jxh-fj25/GHSA-qg36-9jxh-fj25.json index 3b1eb41e89c..b0866a79d39 100644 --- a/advisories/github-reviewed/2023/05/GHSA-qg36-9jxh-fj25/GHSA-qg36-9jxh-fj25.json +++ b/advisories/github-reviewed/2023/05/GHSA-qg36-9jxh-fj25/GHSA-qg36-9jxh-fj25.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qg36-9jxh-fj25", - "modified": "2023-05-26T21:50:46Z", + "modified": "2024-09-16T21:31:26Z", "published": "2023-05-22T19:41:56Z", "aliases": [ "CVE-2023-33185" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N" } ], "affected": [ diff --git a/advisories/unreviewed/2021/12/GHSA-pw8x-9www-h93w/GHSA-pw8x-9www-h93w.json b/advisories/unreviewed/2021/12/GHSA-pw8x-9www-h93w/GHSA-pw8x-9www-h93w.json index 7da4140fabb..beec83e9372 100644 --- a/advisories/unreviewed/2021/12/GHSA-pw8x-9www-h93w/GHSA-pw8x-9www-h93w.json +++ b/advisories/unreviewed/2021/12/GHSA-pw8x-9www-h93w/GHSA-pw8x-9www-h93w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pw8x-9www-h93w", - "modified": "2022-10-08T00:00:18Z", + "modified": "2024-09-16T21:30:32Z", "published": "2021-12-21T00:00:39Z", "aliases": [ "CVE-2021-35234" diff --git a/advisories/unreviewed/2022/01/GHSA-5f54-x7j7-36p3/GHSA-5f54-x7j7-36p3.json b/advisories/unreviewed/2022/01/GHSA-5f54-x7j7-36p3/GHSA-5f54-x7j7-36p3.json index 17b7464c07f..576986db67d 100644 --- a/advisories/unreviewed/2022/01/GHSA-5f54-x7j7-36p3/GHSA-5f54-x7j7-36p3.json +++ b/advisories/unreviewed/2022/01/GHSA-5f54-x7j7-36p3/GHSA-5f54-x7j7-36p3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5f54-x7j7-36p3", - "modified": "2022-04-29T00:00:57Z", + "modified": "2024-09-16T21:30:32Z", "published": "2022-01-21T00:00:48Z", "aliases": [ "CVE-2021-34600" diff --git a/advisories/unreviewed/2022/03/GHSA-9jg3-6mw2-g4q7/GHSA-9jg3-6mw2-g4q7.json b/advisories/unreviewed/2022/03/GHSA-9jg3-6mw2-g4q7/GHSA-9jg3-6mw2-g4q7.json index 13c85eaa332..f315c825bd5 100644 --- a/advisories/unreviewed/2022/03/GHSA-9jg3-6mw2-g4q7/GHSA-9jg3-6mw2-g4q7.json +++ b/advisories/unreviewed/2022/03/GHSA-9jg3-6mw2-g4q7/GHSA-9jg3-6mw2-g4q7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9jg3-6mw2-g4q7", - "modified": "2023-02-13T06:31:00Z", + "modified": "2024-09-16T21:30:32Z", "published": "2022-03-19T00:00:59Z", "aliases": [ "CVE-2021-23209" diff --git a/advisories/unreviewed/2022/05/GHSA-5g5h-vp5m-chrx/GHSA-5g5h-vp5m-chrx.json b/advisories/unreviewed/2022/05/GHSA-5g5h-vp5m-chrx/GHSA-5g5h-vp5m-chrx.json index 2cf9fb2b35b..11c3f95cd18 100644 --- a/advisories/unreviewed/2022/05/GHSA-5g5h-vp5m-chrx/GHSA-5g5h-vp5m-chrx.json +++ b/advisories/unreviewed/2022/05/GHSA-5g5h-vp5m-chrx/GHSA-5g5h-vp5m-chrx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5g5h-vp5m-chrx", - "modified": "2023-09-03T18:30:18Z", + "modified": "2024-09-16T21:30:32Z", "published": "2022-05-24T19:16:18Z", "aliases": [ "CVE-2021-3825" diff --git a/advisories/unreviewed/2022/11/GHSA-v979-36xg-vp67/GHSA-v979-36xg-vp67.json b/advisories/unreviewed/2022/11/GHSA-v979-36xg-vp67/GHSA-v979-36xg-vp67.json index 2bee9a53d6c..1ea37b0ca56 100644 --- a/advisories/unreviewed/2022/11/GHSA-v979-36xg-vp67/GHSA-v979-36xg-vp67.json +++ b/advisories/unreviewed/2022/11/GHSA-v979-36xg-vp67/GHSA-v979-36xg-vp67.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v979-36xg-vp67", - "modified": "2022-11-22T21:30:17Z", + "modified": "2024-09-16T21:30:34Z", "published": "2022-11-18T09:30:25Z", "aliases": [ "CVE-2022-24037" diff --git a/advisories/unreviewed/2023/07/GHSA-r827-5p5r-w6f5/GHSA-r827-5p5r-w6f5.json b/advisories/unreviewed/2023/07/GHSA-r827-5p5r-w6f5/GHSA-r827-5p5r-w6f5.json index 26b8fac5fee..b83d72a4192 100644 --- a/advisories/unreviewed/2023/07/GHSA-r827-5p5r-w6f5/GHSA-r827-5p5r-w6f5.json +++ b/advisories/unreviewed/2023/07/GHSA-r827-5p5r-w6f5/GHSA-r827-5p5r-w6f5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r827-5p5r-w6f5", - "modified": "2024-02-01T18:31:04Z", + "modified": "2024-09-16T21:30:35Z", "published": "2023-07-06T19:24:05Z", "aliases": [ "CVE-2022-2808" diff --git a/advisories/unreviewed/2024/04/GHSA-3fpg-j8cw-vcjq/GHSA-3fpg-j8cw-vcjq.json b/advisories/unreviewed/2024/04/GHSA-3fpg-j8cw-vcjq/GHSA-3fpg-j8cw-vcjq.json index 92d3503ecf3..9c438184d04 100644 --- a/advisories/unreviewed/2024/04/GHSA-3fpg-j8cw-vcjq/GHSA-3fpg-j8cw-vcjq.json +++ b/advisories/unreviewed/2024/04/GHSA-3fpg-j8cw-vcjq/GHSA-3fpg-j8cw-vcjq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3fpg-j8cw-vcjq", - "modified": "2024-05-22T18:30:40Z", + "modified": "2024-09-16T21:30:37Z", "published": "2024-04-04T15:30:34Z", "aliases": [ "CVE-2024-31081" @@ -45,6 +45,10 @@ "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-31081" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:3343" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:3261" diff --git a/advisories/unreviewed/2024/04/GHSA-mqqf-4p7r-rf89/GHSA-mqqf-4p7r-rf89.json b/advisories/unreviewed/2024/04/GHSA-mqqf-4p7r-rf89/GHSA-mqqf-4p7r-rf89.json index cdaa36f3191..a6976fc328c 100644 --- a/advisories/unreviewed/2024/04/GHSA-mqqf-4p7r-rf89/GHSA-mqqf-4p7r-rf89.json +++ b/advisories/unreviewed/2024/04/GHSA-mqqf-4p7r-rf89/GHSA-mqqf-4p7r-rf89.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mqqf-4p7r-rf89", - "modified": "2024-05-22T18:30:40Z", + "modified": "2024-09-16T21:30:37Z", "published": "2024-04-04T15:30:34Z", "aliases": [ "CVE-2024-31080" @@ -45,6 +45,10 @@ "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-31080" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:3343" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:3261" diff --git a/advisories/unreviewed/2024/04/GHSA-q6w6-rjjj-5p52/GHSA-q6w6-rjjj-5p52.json b/advisories/unreviewed/2024/04/GHSA-q6w6-rjjj-5p52/GHSA-q6w6-rjjj-5p52.json index f949d5f3abc..98787ea7e09 100644 --- a/advisories/unreviewed/2024/04/GHSA-q6w6-rjjj-5p52/GHSA-q6w6-rjjj-5p52.json +++ b/advisories/unreviewed/2024/04/GHSA-q6w6-rjjj-5p52/GHSA-q6w6-rjjj-5p52.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q6w6-rjjj-5p52", - "modified": "2024-05-22T18:30:40Z", + "modified": "2024-09-16T21:30:37Z", "published": "2024-04-05T12:31:17Z", "aliases": [ "CVE-2024-31083" @@ -45,6 +45,10 @@ "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-31083" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:3343" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:3261" diff --git a/advisories/unreviewed/2024/06/GHSA-8g25-xmmm-86qm/GHSA-8g25-xmmm-86qm.json b/advisories/unreviewed/2024/06/GHSA-8g25-xmmm-86qm/GHSA-8g25-xmmm-86qm.json index 1fbdd630911..75558ee67e0 100644 --- a/advisories/unreviewed/2024/06/GHSA-8g25-xmmm-86qm/GHSA-8g25-xmmm-86qm.json +++ b/advisories/unreviewed/2024/06/GHSA-8g25-xmmm-86qm/GHSA-8g25-xmmm-86qm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8g25-xmmm-86qm", - "modified": "2024-06-27T03:30:55Z", + "modified": "2024-09-16T21:30:37Z", "published": "2024-06-12T09:30:48Z", "aliases": [ "CVE-2024-3183" diff --git a/advisories/unreviewed/2024/09/GHSA-2jpm-3fv2-55wf/GHSA-2jpm-3fv2-55wf.json b/advisories/unreviewed/2024/09/GHSA-2jpm-3fv2-55wf/GHSA-2jpm-3fv2-55wf.json new file mode 100644 index 00000000000..f821a5a97c0 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-2jpm-3fv2-55wf/GHSA-2jpm-3fv2-55wf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jpm-3fv2-55wf", + "modified": "2024-09-16T21:30:38Z", + "published": "2024-09-16T21:30:38Z", + "aliases": [ + "CVE-2024-8766" + ], + "details": "Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 38235.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8766" + }, + { + "type": "WEB", + "url": "https://security-advisory.acronis.com/advisories/SEC-7218" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T20:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-2jvw-9p97-g4qj/GHSA-2jvw-9p97-g4qj.json b/advisories/unreviewed/2024/09/GHSA-2jvw-9p97-g4qj/GHSA-2jvw-9p97-g4qj.json new file mode 100644 index 00000000000..f5f4354fe32 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-2jvw-9p97-g4qj/GHSA-2jvw-9p97-g4qj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jvw-9p97-g4qj", + "modified": "2024-09-16T21:30:38Z", + "published": "2024-09-16T21:30:38Z", + "aliases": [ + "CVE-2024-42796" + ], + "details": "An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_genre in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid music genre entries.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42796" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Music%20Management%20System%20v1.0/Broken%20Access%20Control%20-%20Delete%20Genre.pdf" + }, + { + "type": "WEB", + "url": "https://www.kashipara.com/project/php/12978/music-management-system-in-php-php-project-source-code" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T20:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-42h3-v86m-8hc5/GHSA-42h3-v86m-8hc5.json b/advisories/unreviewed/2024/09/GHSA-42h3-v86m-8hc5/GHSA-42h3-v86m-8hc5.json new file mode 100644 index 00000000000..b856178578c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-42h3-v86m-8hc5/GHSA-42h3-v86m-8hc5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42h3-v86m-8hc5", + "modified": "2024-09-16T21:30:38Z", + "published": "2024-09-16T21:30:38Z", + "aliases": [ + "CVE-2024-45414" + ], + "details": "The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in webPrivateDecrypt function. This function is responsible for decrypting RSA encrypted ciphertext, the encrypted data is supplied base64 encoded. The decoded ciphertext is stored on the stack without checking its length. An unauthenticated attacker can get RCE as root by exploiting this vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45414" + }, + { + "type": "WEB", + "url": "https://wr3nchsr.github.io/zte-multiple-routers-httpd-vulnerabilities-advisory" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T21:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-5qfp-r7q3-257g/GHSA-5qfp-r7q3-257g.json b/advisories/unreviewed/2024/09/GHSA-5qfp-r7q3-257g/GHSA-5qfp-r7q3-257g.json new file mode 100644 index 00000000000..3a15be7d06f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5qfp-r7q3-257g/GHSA-5qfp-r7q3-257g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qfp-r7q3-257g", + "modified": "2024-09-16T21:30:38Z", + "published": "2024-09-16T21:30:38Z", + "aliases": [ + "CVE-2024-45416" + ], + "details": "The HTTPD binary in multiple ZTE routers has a local file inclusion vulnerability in session_init function. The session -LUA- files are stored in the directory /var/lua_session, the function iterates on all files in this directory and executes them using the function dofile without any validation if it is a valid session file or not. An attacker who is able to write a malicious file in the sessions directory can get RCE as root.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45416" + }, + { + "type": "WEB", + "url": "https://wr3nchsr.github.io/zte-multiple-routers-httpd-vulnerabilities-advisory" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T21:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-68ww-7h9f-48qx/GHSA-68ww-7h9f-48qx.json b/advisories/unreviewed/2024/09/GHSA-68ww-7h9f-48qx/GHSA-68ww-7h9f-48qx.json new file mode 100644 index 00000000000..e1b25af30ff --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-68ww-7h9f-48qx/GHSA-68ww-7h9f-48qx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68ww-7h9f-48qx", + "modified": "2024-09-16T21:30:38Z", + "published": "2024-09-16T21:30:38Z", + "aliases": [ + "CVE-2024-45415" + ], + "details": "The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in check_data_integrity function. This function is responsible for validating the checksum of data in post request. The checksum is sent encrypted in the request, the function decrypts it and stores the checksum on the stack without validating it. An unauthenticated attacker can get RCE as root by exploiting this vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45415" + }, + { + "type": "WEB", + "url": "https://wr3nchsr.github.io/zte-multiple-routers-httpd-vulnerabilities-advisory" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T21:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-7j8v-7qw4-w29q/GHSA-7j8v-7qw4-w29q.json b/advisories/unreviewed/2024/09/GHSA-7j8v-7qw4-w29q/GHSA-7j8v-7qw4-w29q.json new file mode 100644 index 00000000000..bf8d8cf8c3b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-7j8v-7qw4-w29q/GHSA-7j8v-7qw4-w29q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7j8v-7qw4-w29q", + "modified": "2024-09-16T21:30:38Z", + "published": "2024-09-16T21:30:38Z", + "aliases": [ + "CVE-2024-22013" + ], + "details": "U-Boot environment is read from unauthenticated partition.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22013" + }, + { + "type": "WEB", + "url": "https://support.google.com/product-documentation/answer/14950962?hl=en&ref_topic=12974021&sjid=9595902703262170957-NA#zippy=%2Cwifi" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T20:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8xm2-mrh9-q3x9/GHSA-8xm2-mrh9-q3x9.json b/advisories/unreviewed/2024/09/GHSA-8xm2-mrh9-q3x9/GHSA-8xm2-mrh9-q3x9.json new file mode 100644 index 00000000000..ba4e5e4e2e0 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8xm2-mrh9-q3x9/GHSA-8xm2-mrh9-q3x9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xm2-mrh9-q3x9", + "modified": "2024-09-16T21:30:38Z", + "published": "2024-09-16T21:30:38Z", + "aliases": [ + "CVE-2024-42798" + ], + "details": "An Incorrect Access Control vulnerability was found in /music/index.php?page=user_list and /music/index.php?page=edit_user in Kashipara Music Management System v1.0. This allows a low privileged attacker to take over the administrator account.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42798" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Music%20Management%20System%20v1.0/Broken%20Access%20Control%20-%20Priv%20Esc%20-%20Save%20Edit%20User%20-%20AC%20Takeover.pdf" + }, + { + "type": "WEB", + "url": "https://www.kashipara.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T20:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-99qx-qpwq-jm99/GHSA-99qx-qpwq-jm99.json b/advisories/unreviewed/2024/09/GHSA-99qx-qpwq-jm99/GHSA-99qx-qpwq-jm99.json new file mode 100644 index 00000000000..05b502848f3 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-99qx-qpwq-jm99/GHSA-99qx-qpwq-jm99.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99qx-qpwq-jm99", + "modified": "2024-09-16T21:30:38Z", + "published": "2024-09-16T21:30:38Z", + "aliases": [ + "CVE-2024-34016" + ], + "details": "Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 38235.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34016" + }, + { + "type": "WEB", + "url": "https://security-advisory.acronis.com/advisories/SEC-7188" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T20:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-f3mw-pmh2-74wc/GHSA-f3mw-pmh2-74wc.json b/advisories/unreviewed/2024/09/GHSA-f3mw-pmh2-74wc/GHSA-f3mw-pmh2-74wc.json new file mode 100644 index 00000000000..cf4fcd82f9c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-f3mw-pmh2-74wc/GHSA-f3mw-pmh2-74wc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3mw-pmh2-74wc", + "modified": "2024-09-16T21:30:38Z", + "published": "2024-09-16T21:30:38Z", + "aliases": [ + "CVE-2024-44445" + ], + "details": "An issue was discovered in BSC Smart Contract 0x0506e571aba3dd4c9d71bed479a4e6d40d95c833. Attackers are able to perform state manipulation attacks by borrowing a large amount of money and then using this amount to inflate the token balance in the token pair, leading to increased profits without cost.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44445" + }, + { + "type": "WEB", + "url": "https://gist.github.com/shuo-young/fcb18cca532ff26de0fe3a18cc5555b6" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T20:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mq89-7cwq-chfg/GHSA-mq89-7cwq-chfg.json b/advisories/unreviewed/2024/09/GHSA-mq89-7cwq-chfg/GHSA-mq89-7cwq-chfg.json new file mode 100644 index 00000000000..582f08813ed --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mq89-7cwq-chfg/GHSA-mq89-7cwq-chfg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq89-7cwq-chfg", + "modified": "2024-09-16T21:30:38Z", + "published": "2024-09-16T21:30:38Z", + "aliases": [ + "CVE-2024-45413" + ], + "details": "The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in rsa_decrypt function. This function is an API wrapper for LUA to decrypt RSA encrypted ciphertext, the decrypted data is stored on the stack without checking its length. An authenticated attacker can get RCE as root by exploiting this vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45413" + }, + { + "type": "WEB", + "url": "https://wr3nchsr.github.io/zte-multiple-routers-httpd-vulnerabilities-advisory" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T21:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-wpr3-95vq-q76j/GHSA-wpr3-95vq-q76j.json b/advisories/unreviewed/2024/09/GHSA-wpr3-95vq-q76j/GHSA-wpr3-95vq-q76j.json new file mode 100644 index 00000000000..d519515642b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-wpr3-95vq-q76j/GHSA-wpr3-95vq-q76j.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpr3-95vq-q76j", + "modified": "2024-09-16T21:30:38Z", + "published": "2024-09-16T21:30:38Z", + "aliases": [ + "CVE-2024-42795" + ], + "details": "An Incorrect Access Control vulnerability was found in /music/view_user.php?id=3 and /music/controller.php?page=edit_user&id=3 in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to view valid user details.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42795" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Music%20Management%20System%20v1.0/Broken%20Access%20Control%20-%20View%20User.pdf" + }, + { + "type": "WEB", + "url": "https://www.kashipara.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T20:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-x7c7-rpwp-w6fw/GHSA-x7c7-rpwp-w6fw.json b/advisories/unreviewed/2024/09/GHSA-x7c7-rpwp-w6fw/GHSA-x7c7-rpwp-w6fw.json new file mode 100644 index 00000000000..ca6cd71ca98 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-x7c7-rpwp-w6fw/GHSA-x7c7-rpwp-w6fw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7c7-rpwp-w6fw", + "modified": "2024-09-16T21:30:38Z", + "published": "2024-09-16T21:30:38Z", + "aliases": [ + "CVE-2024-42794" + ], + "details": "Kashipara Music Management System v1.0 is vulnerable to Incorrect Access Control via /music/ajax.php?action=save_user.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42794" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Music%20Management%20System%20v1.0/Broken%20Access%20Control%20-%20Save%20User%20%26%20Account%20Takeover.pdf" + }, + { + "type": "WEB", + "url": "https://www.kashipara.com/project/php/12978/music-management-system-in-php-php-project-source-code" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T20:15:46Z" + } +} \ No newline at end of file