Publish Advisories

GHSA-hh52-g5c4-wprh
GHSA-wxmq-v9gx-75pg
GHSA-3j7g-922g-j6r3
GHSA-qcvq-w335-8gh3
GHSA-8j56-863j-pww9
GHSA-fj3c-gq42-693w
GHSA-q4jw-3mfc-r879
GHSA-2667-9fwp-8c25
GHSA-4325-9qm2-3cg2
GHSA-4pvq-mcwh-v9jc
GHSA-5xj8-9pp7-w546
GHSA-8h8h-h8wv-7f3f
GHSA-hhj5-6fh2-3fp5
GHSA-mvg6-43mv-76rp
GHSA-pj8j-wrf5-7mgp
GHSA-qrqx-rvg9-7g66
This commit is contained in:
advisory-database[bot]
2024-04-19 15:31:52 +00:00
parent 2eca7fad0d
commit 5d1ee110a2
16 changed files with 387 additions and 8 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hh52-g5c4-wprh",
"modified": "2023-03-28T22:57:20Z",
"modified": "2024-04-19T15:30:46Z",
"published": "2023-03-23T21:30:18Z",
"aliases": [
"CVE-2023-28334"
@@ -101,6 +101,10 @@
"type": "WEB",
"url": "https://github.com/moodle/moodle/commit/0e3c8eb740e1e49a62a5f452cda7e06258712bbf"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2179423"
},
{
"type": "WEB",
"url": "https://git.moodle.org/gw?p=moodle.git;a=commit;h=0e3c8eb740e1e49a62a5f452cda7e06258712bbf"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wxmq-v9gx-75pg",
"modified": "2023-03-28T22:54:23Z",
"modified": "2024-04-19T15:30:46Z",
"published": "2023-03-23T21:30:18Z",
"aliases": [
"CVE-2023-28335"
@@ -44,6 +44,10 @@
"type": "WEB",
"url": "https://github.com/moodle/moodle/commit/355556c05f4a6d9e223164eff820cd34eb70cc35"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2179424"
},
{
"type": "WEB",
"url": "https://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=355556c05f4a6d9e223164eff820cd34eb70cc35"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3j7g-922g-j6r3",
"modified": "2023-01-23T15:30:30Z",
"modified": "2024-04-19T15:30:45Z",
"published": "2023-01-12T21:30:30Z",
"aliases": [
"CVE-2023-23456"
@@ -33,6 +33,14 @@
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2160381"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EL3BVKIGG3SH6I3KPOYQAWCBD4UMPOPI"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TGEP3FBNRZXGLIA2B2ICMB32JVMPREFZ"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EL3BVKIGG3SH6I3KPOYQAWCBD4UMPOPI"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qcvq-w335-8gh3",
"modified": "2023-01-23T15:30:33Z",
"modified": "2024-04-19T15:30:45Z",
"published": "2023-01-12T21:30:30Z",
"aliases": [
"CVE-2023-23457"
@@ -33,6 +33,14 @@
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2160382"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EL3BVKIGG3SH6I3KPOYQAWCBD4UMPOPI"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TGEP3FBNRZXGLIA2B2ICMB32JVMPREFZ"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EL3BVKIGG3SH6I3KPOYQAWCBD4UMPOPI"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8j56-863j-pww9",
"modified": "2023-03-30T15:30:19Z",
"modified": "2024-04-19T15:30:45Z",
"published": "2023-03-23T21:30:20Z",
"aliases": [
"CVE-2023-1544"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1544"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-1544"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2180364"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fj3c-gq42-693w",
"modified": "2023-03-14T18:30:22Z",
"modified": "2024-04-19T15:30:45Z",
"published": "2023-03-07T00:30:24Z",
"aliases": [
"CVE-2023-0330"
@@ -21,6 +21,14 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0330"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-0330"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2160151"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00006.html"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q4jw-3mfc-r879",
"modified": "2024-04-04T05:35:25Z",
"modified": "2024-04-19T15:30:46Z",
"published": "2023-07-06T19:24:13Z",
"aliases": [
"CVE-2021-41526"
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://github.com/mandiant/Vulnerability-Disclosures/blob/master/MNDT-2021-0011/MNDT-2021-0011.md"
},
{
"type": "WEB",
"url": "http://seclists.org/fulldisclosure/2024/Apr/24"
}
],
"database_specific": {
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2667-9fwp-8c25",
"modified": "2024-04-19T15:30:47Z",
"published": "2024-04-19T15:30:47Z",
"aliases": [
"CVE-2024-3470"
],
"details": "An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to use a deploy key pertaining to an organization to bypass an organization ruleset. An attacker would require access to a valid deploy key for a repository in the organization as well as repository administrator access. This vulnerability affected versions of GitHub Enterprise Server 3.11 to 3.12 and was fixed in versions 3.11.8 and 3.12.2. This vulnerability was reported via the GitHub Bug Bounty program.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3470"
},
{
"type": "WEB",
"url": "https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.8"
},
{
"type": "WEB",
"url": "https://docs.github.com/en/enterprise-server@3.12/admin/release-notes#3.12.2"
}
],
"database_specific": {
"cwe_ids": [
"CWE-269"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-19T15:15:51Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4325-9qm2-3cg2",
"modified": "2024-04-19T15:30:47Z",
"published": "2024-04-19T15:30:47Z",
"aliases": [
"CVE-2024-3646"
],
"details": "A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the instance when configuring the chat integration. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and access to the Management Console with the editor role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.12.2, 3.11.8, 3.10.10, and 3.9.13. This vulnerability was reported via the GitHub Bug Bounty program.\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3646"
},
{
"type": "WEB",
"url": "https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.10"
},
{
"type": "WEB",
"url": "https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.8"
},
{
"type": "WEB",
"url": "https://docs.github.com/en/enterprise-server@3.12/admin/release-notes#3.12.2"
},
{
"type": "WEB",
"url": "https://docs.github.com/en/enterprise-server@3.9/admin/release-notes#3.9.13"
}
],
"database_specific": {
"cwe_ids": [
"CWE-20"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-19T15:15:51Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4pvq-mcwh-v9jc",
"modified": "2024-04-19T15:30:46Z",
"published": "2024-04-19T15:30:46Z",
"aliases": [
"CVE-2024-31744"
],
"details": "In Jasper 4.2.2, the jpc_streamlist_remove function in src/libjasper/jpc/jpc_dec.c:2407 has an assertion failure vulnerability, allowing attackers to cause a denial of service attack through a specific image file.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31744"
},
{
"type": "WEB",
"url": "https://github.com/jasper-software/jasper/issues/381"
},
{
"type": "WEB",
"url": "https://github.com/jasper-software/jasper/commit/6d084c53a77762f41bb5310713a5f1872fef55f5"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-19T13:15:13Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5xj8-9pp7-w546",
"modified": "2024-04-19T15:30:46Z",
"published": "2024-04-19T15:30:46Z",
"aliases": [
"CVE-2024-32166"
],
"details": "Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now an auction that is suspended (horizontal privilege escalation).",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32166"
},
{
"type": "WEB",
"url": "https://github.com/Fewword/Poc/blob/main/webid/webid-poc14.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-19T14:15:11Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8h8h-h8wv-7f3f",
"modified": "2024-04-19T15:30:46Z",
"published": "2024-04-19T15:30:46Z",
"aliases": [
"CVE-2024-31745"
],
"details": "Libdwarf v0.9.1 was discovered to contain a heap use-after-free via the dw_empty_errlist_item function at /libdwarf/dwarf_alloc.c.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31745"
},
{
"type": "WEB",
"url": "https://github.com/davea42/libdwarf-code/issues/238"
},
{
"type": "WEB",
"url": "https://github.com/davea42/libdwarf-code/commit/404e6b1b14f60c81388d50b4239f81d461b3c3ad"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-19T13:15:13Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hhj5-6fh2-3fp5",
"modified": "2024-04-18T09:30:44Z",
"modified": "2024-04-19T15:30:46Z",
"published": "2024-04-18T09:30:44Z",
"aliases": [
"CVE-2024-28076"
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-28073"
},
{
"type": "WEB",
"url": "https://www.solarwinds.com/trust-center/security-advisories/cve-2024-28076"
}
],
"database_specific": {
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mvg6-43mv-76rp",
"modified": "2024-04-19T15:30:47Z",
"published": "2024-04-19T15:30:47Z",
"aliases": [
"CVE-2024-3684"
],
"details": "A server side request forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin access to the appliance when configuring the Artifacts & Logs and Migrations Storage. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and access to the Management Console with the editor role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.12.2, 3.11.8, 3.10.10, and 3.9.13. This vulnerability was reported via the GitHub Bug Bounty program.\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3684"
},
{
"type": "WEB",
"url": "https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.10"
},
{
"type": "WEB",
"url": "https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.8"
},
{
"type": "WEB",
"url": "https://docs.github.com/en/enterprise-server@3.12/admin/release-notes#3.12.2"
},
{
"type": "WEB",
"url": "https://docs.github.com/en/enterprise-server@3.9/admin/release-notes#3.9.13"
}
],
"database_specific": {
"cwe_ids": [
"CWE-88"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-19T15:15:51Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pj8j-wrf5-7mgp",
"modified": "2024-04-19T15:30:47Z",
"published": "2024-04-19T15:30:46Z",
"aliases": [
"CVE-2023-37400"
],
"details": "IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to escalate their privileges due to insecure credential storage. IBM X-Force ID: 259677.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37400"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/259677"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7148631"
}
],
"database_specific": {
"cwe_ids": [
"CWE-522"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-19T14:15:10Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qrqx-rvg9-7g66",
"modified": "2024-04-19T15:30:46Z",
"published": "2024-04-19T15:30:46Z",
"aliases": [
"CVE-2024-3654"
],
"details": "An XSS vulnerability has been found in Teimas Global's Teixo, version 1.42.42-stable. This vulnerability could allow an attacker to send a specially crafted JavaScript payload via the \"seconds\" parameter in the program's URL, resulting in a possible takeover of a registered user's session.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3654"
},
{
"type": "WEB",
"url": "https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-vulnerability-teixo-teimas-global"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-19T13:15:13Z"
}
}