From 5d1ee110a2bd0498e000ec99fd3e6ecf409778de Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 19 Apr 2024 15:31:52 +0000 Subject: [PATCH] Publish Advisories GHSA-hh52-g5c4-wprh GHSA-wxmq-v9gx-75pg GHSA-3j7g-922g-j6r3 GHSA-qcvq-w335-8gh3 GHSA-8j56-863j-pww9 GHSA-fj3c-gq42-693w GHSA-q4jw-3mfc-r879 GHSA-2667-9fwp-8c25 GHSA-4325-9qm2-3cg2 GHSA-4pvq-mcwh-v9jc GHSA-5xj8-9pp7-w546 GHSA-8h8h-h8wv-7f3f GHSA-hhj5-6fh2-3fp5 GHSA-mvg6-43mv-76rp GHSA-pj8j-wrf5-7mgp GHSA-qrqx-rvg9-7g66 --- .../GHSA-hh52-g5c4-wprh.json | 6 ++- .../GHSA-wxmq-v9gx-75pg.json | 6 ++- .../GHSA-3j7g-922g-j6r3.json | 10 +++- .../GHSA-qcvq-w335-8gh3.json | 10 +++- .../GHSA-8j56-863j-pww9.json | 6 ++- .../GHSA-fj3c-gq42-693w.json | 10 +++- .../GHSA-q4jw-3mfc-r879.json | 6 ++- .../GHSA-2667-9fwp-8c25.json | 42 ++++++++++++++++ .../GHSA-4325-9qm2-3cg2.json | 50 +++++++++++++++++++ .../GHSA-4pvq-mcwh-v9jc.json | 39 +++++++++++++++ .../GHSA-5xj8-9pp7-w546.json | 35 +++++++++++++ .../GHSA-8h8h-h8wv-7f3f.json | 39 +++++++++++++++ .../GHSA-hhj5-6fh2-3fp5.json | 6 ++- .../GHSA-mvg6-43mv-76rp.json | 50 +++++++++++++++++++ .../GHSA-pj8j-wrf5-7mgp.json | 42 ++++++++++++++++ .../GHSA-qrqx-rvg9-7g66.json | 38 ++++++++++++++ 16 files changed, 387 insertions(+), 8 deletions(-) create mode 100644 advisories/unreviewed/2024/04/GHSA-2667-9fwp-8c25/GHSA-2667-9fwp-8c25.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4325-9qm2-3cg2/GHSA-4325-9qm2-3cg2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4pvq-mcwh-v9jc/GHSA-4pvq-mcwh-v9jc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5xj8-9pp7-w546/GHSA-5xj8-9pp7-w546.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8h8h-h8wv-7f3f/GHSA-8h8h-h8wv-7f3f.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mvg6-43mv-76rp/GHSA-mvg6-43mv-76rp.json create mode 100644 advisories/unreviewed/2024/04/GHSA-pj8j-wrf5-7mgp/GHSA-pj8j-wrf5-7mgp.json create mode 100644 advisories/unreviewed/2024/04/GHSA-qrqx-rvg9-7g66/GHSA-qrqx-rvg9-7g66.json diff --git a/advisories/github-reviewed/2023/03/GHSA-hh52-g5c4-wprh/GHSA-hh52-g5c4-wprh.json b/advisories/github-reviewed/2023/03/GHSA-hh52-g5c4-wprh/GHSA-hh52-g5c4-wprh.json index 77ceaf6c1a0..ee9e87eba90 100644 --- a/advisories/github-reviewed/2023/03/GHSA-hh52-g5c4-wprh/GHSA-hh52-g5c4-wprh.json +++ b/advisories/github-reviewed/2023/03/GHSA-hh52-g5c4-wprh/GHSA-hh52-g5c4-wprh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hh52-g5c4-wprh", - "modified": "2023-03-28T22:57:20Z", + "modified": "2024-04-19T15:30:46Z", "published": "2023-03-23T21:30:18Z", "aliases": [ "CVE-2023-28334" @@ -101,6 +101,10 @@ "type": "WEB", "url": "https://github.com/moodle/moodle/commit/0e3c8eb740e1e49a62a5f452cda7e06258712bbf" }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2179423" + }, { "type": "WEB", "url": "https://git.moodle.org/gw?p=moodle.git;a=commit;h=0e3c8eb740e1e49a62a5f452cda7e06258712bbf" diff --git a/advisories/github-reviewed/2023/03/GHSA-wxmq-v9gx-75pg/GHSA-wxmq-v9gx-75pg.json b/advisories/github-reviewed/2023/03/GHSA-wxmq-v9gx-75pg/GHSA-wxmq-v9gx-75pg.json index cb7c9d0e1b3..f692c4f14c2 100644 --- a/advisories/github-reviewed/2023/03/GHSA-wxmq-v9gx-75pg/GHSA-wxmq-v9gx-75pg.json +++ b/advisories/github-reviewed/2023/03/GHSA-wxmq-v9gx-75pg/GHSA-wxmq-v9gx-75pg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wxmq-v9gx-75pg", - "modified": "2023-03-28T22:54:23Z", + "modified": "2024-04-19T15:30:46Z", "published": "2023-03-23T21:30:18Z", "aliases": [ "CVE-2023-28335" @@ -44,6 +44,10 @@ "type": "WEB", "url": "https://github.com/moodle/moodle/commit/355556c05f4a6d9e223164eff820cd34eb70cc35" }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2179424" + }, { "type": "WEB", "url": "https://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=355556c05f4a6d9e223164eff820cd34eb70cc35" diff --git a/advisories/unreviewed/2023/01/GHSA-3j7g-922g-j6r3/GHSA-3j7g-922g-j6r3.json b/advisories/unreviewed/2023/01/GHSA-3j7g-922g-j6r3/GHSA-3j7g-922g-j6r3.json index 8f1265579ae..66067b9683e 100644 --- a/advisories/unreviewed/2023/01/GHSA-3j7g-922g-j6r3/GHSA-3j7g-922g-j6r3.json +++ b/advisories/unreviewed/2023/01/GHSA-3j7g-922g-j6r3/GHSA-3j7g-922g-j6r3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3j7g-922g-j6r3", - "modified": "2023-01-23T15:30:30Z", + "modified": "2024-04-19T15:30:45Z", "published": "2023-01-12T21:30:30Z", "aliases": [ "CVE-2023-23456" @@ -33,6 +33,14 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2160381" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EL3BVKIGG3SH6I3KPOYQAWCBD4UMPOPI" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TGEP3FBNRZXGLIA2B2ICMB32JVMPREFZ" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EL3BVKIGG3SH6I3KPOYQAWCBD4UMPOPI" diff --git a/advisories/unreviewed/2023/01/GHSA-qcvq-w335-8gh3/GHSA-qcvq-w335-8gh3.json b/advisories/unreviewed/2023/01/GHSA-qcvq-w335-8gh3/GHSA-qcvq-w335-8gh3.json index 7befd67b554..e1221c82553 100644 --- a/advisories/unreviewed/2023/01/GHSA-qcvq-w335-8gh3/GHSA-qcvq-w335-8gh3.json +++ b/advisories/unreviewed/2023/01/GHSA-qcvq-w335-8gh3/GHSA-qcvq-w335-8gh3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qcvq-w335-8gh3", - "modified": "2023-01-23T15:30:33Z", + "modified": "2024-04-19T15:30:45Z", "published": "2023-01-12T21:30:30Z", "aliases": [ "CVE-2023-23457" @@ -33,6 +33,14 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2160382" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EL3BVKIGG3SH6I3KPOYQAWCBD4UMPOPI" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TGEP3FBNRZXGLIA2B2ICMB32JVMPREFZ" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EL3BVKIGG3SH6I3KPOYQAWCBD4UMPOPI" diff --git a/advisories/unreviewed/2023/03/GHSA-8j56-863j-pww9/GHSA-8j56-863j-pww9.json b/advisories/unreviewed/2023/03/GHSA-8j56-863j-pww9/GHSA-8j56-863j-pww9.json index 531b838fc58..3591e6e83b6 100644 --- a/advisories/unreviewed/2023/03/GHSA-8j56-863j-pww9/GHSA-8j56-863j-pww9.json +++ b/advisories/unreviewed/2023/03/GHSA-8j56-863j-pww9/GHSA-8j56-863j-pww9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8j56-863j-pww9", - "modified": "2023-03-30T15:30:19Z", + "modified": "2024-04-19T15:30:45Z", "published": "2023-03-23T21:30:20Z", "aliases": [ "CVE-2023-1544" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1544" }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-1544" + }, { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2180364" diff --git a/advisories/unreviewed/2023/03/GHSA-fj3c-gq42-693w/GHSA-fj3c-gq42-693w.json b/advisories/unreviewed/2023/03/GHSA-fj3c-gq42-693w/GHSA-fj3c-gq42-693w.json index cf3f7e1abfe..514fefd810e 100644 --- a/advisories/unreviewed/2023/03/GHSA-fj3c-gq42-693w/GHSA-fj3c-gq42-693w.json +++ b/advisories/unreviewed/2023/03/GHSA-fj3c-gq42-693w/GHSA-fj3c-gq42-693w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fj3c-gq42-693w", - "modified": "2023-03-14T18:30:22Z", + "modified": "2024-04-19T15:30:45Z", "published": "2023-03-07T00:30:24Z", "aliases": [ "CVE-2023-0330" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0330" }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-0330" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2160151" + }, { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00006.html" diff --git a/advisories/unreviewed/2023/07/GHSA-q4jw-3mfc-r879/GHSA-q4jw-3mfc-r879.json b/advisories/unreviewed/2023/07/GHSA-q4jw-3mfc-r879/GHSA-q4jw-3mfc-r879.json index 24c5fa34306..f10b05530bd 100644 --- a/advisories/unreviewed/2023/07/GHSA-q4jw-3mfc-r879/GHSA-q4jw-3mfc-r879.json +++ b/advisories/unreviewed/2023/07/GHSA-q4jw-3mfc-r879/GHSA-q4jw-3mfc-r879.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q4jw-3mfc-r879", - "modified": "2024-04-04T05:35:25Z", + "modified": "2024-04-19T15:30:46Z", "published": "2023-07-06T19:24:13Z", "aliases": [ "CVE-2021-41526" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://github.com/mandiant/Vulnerability-Disclosures/blob/master/MNDT-2021-0011/MNDT-2021-0011.md" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Apr/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/04/GHSA-2667-9fwp-8c25/GHSA-2667-9fwp-8c25.json b/advisories/unreviewed/2024/04/GHSA-2667-9fwp-8c25/GHSA-2667-9fwp-8c25.json new file mode 100644 index 00000000000..e339362bc86 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2667-9fwp-8c25/GHSA-2667-9fwp-8c25.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2667-9fwp-8c25", + "modified": "2024-04-19T15:30:47Z", + "published": "2024-04-19T15:30:47Z", + "aliases": [ + "CVE-2024-3470" + ], + "details": "An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to use a deploy key pertaining to an organization to bypass an organization ruleset. An attacker would require access to a valid deploy key for a repository in the organization as well as repository administrator access. This vulnerability affected versions of GitHub Enterprise Server 3.11 to 3.12 and was fixed in versions 3.11.8 and 3.12.2. This vulnerability was reported via the GitHub Bug Bounty program.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3470" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.8" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.12/admin/release-notes#3.12.2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T15:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4325-9qm2-3cg2/GHSA-4325-9qm2-3cg2.json b/advisories/unreviewed/2024/04/GHSA-4325-9qm2-3cg2/GHSA-4325-9qm2-3cg2.json new file mode 100644 index 00000000000..f7cc079bf87 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4325-9qm2-3cg2/GHSA-4325-9qm2-3cg2.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4325-9qm2-3cg2", + "modified": "2024-04-19T15:30:47Z", + "published": "2024-04-19T15:30:47Z", + "aliases": [ + "CVE-2024-3646" + ], + "details": "A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the instance when configuring the chat integration. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and access to the Management Console with the editor role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.12.2, 3.11.8, 3.10.10, and 3.9.13. This vulnerability was reported via the GitHub Bug Bounty program.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3646" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.10" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.8" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.12/admin/release-notes#3.12.2" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.9/admin/release-notes#3.9.13" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T15:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4pvq-mcwh-v9jc/GHSA-4pvq-mcwh-v9jc.json b/advisories/unreviewed/2024/04/GHSA-4pvq-mcwh-v9jc/GHSA-4pvq-mcwh-v9jc.json new file mode 100644 index 00000000000..7d65238445a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4pvq-mcwh-v9jc/GHSA-4pvq-mcwh-v9jc.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pvq-mcwh-v9jc", + "modified": "2024-04-19T15:30:46Z", + "published": "2024-04-19T15:30:46Z", + "aliases": [ + "CVE-2024-31744" + ], + "details": "In Jasper 4.2.2, the jpc_streamlist_remove function in src/libjasper/jpc/jpc_dec.c:2407 has an assertion failure vulnerability, allowing attackers to cause a denial of service attack through a specific image file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31744" + }, + { + "type": "WEB", + "url": "https://github.com/jasper-software/jasper/issues/381" + }, + { + "type": "WEB", + "url": "https://github.com/jasper-software/jasper/commit/6d084c53a77762f41bb5310713a5f1872fef55f5" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5xj8-9pp7-w546/GHSA-5xj8-9pp7-w546.json b/advisories/unreviewed/2024/04/GHSA-5xj8-9pp7-w546/GHSA-5xj8-9pp7-w546.json new file mode 100644 index 00000000000..65d6f0a530e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5xj8-9pp7-w546/GHSA-5xj8-9pp7-w546.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xj8-9pp7-w546", + "modified": "2024-04-19T15:30:46Z", + "published": "2024-04-19T15:30:46Z", + "aliases": [ + "CVE-2024-32166" + ], + "details": "Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now an auction that is suspended (horizontal privilege escalation).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32166" + }, + { + "type": "WEB", + "url": "https://github.com/Fewword/Poc/blob/main/webid/webid-poc14.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8h8h-h8wv-7f3f/GHSA-8h8h-h8wv-7f3f.json b/advisories/unreviewed/2024/04/GHSA-8h8h-h8wv-7f3f/GHSA-8h8h-h8wv-7f3f.json new file mode 100644 index 00000000000..dec5a0267ee --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8h8h-h8wv-7f3f/GHSA-8h8h-h8wv-7f3f.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8h8h-h8wv-7f3f", + "modified": "2024-04-19T15:30:46Z", + "published": "2024-04-19T15:30:46Z", + "aliases": [ + "CVE-2024-31745" + ], + "details": "Libdwarf v0.9.1 was discovered to contain a heap use-after-free via the dw_empty_errlist_item function at /libdwarf/dwarf_alloc.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31745" + }, + { + "type": "WEB", + "url": "https://github.com/davea42/libdwarf-code/issues/238" + }, + { + "type": "WEB", + "url": "https://github.com/davea42/libdwarf-code/commit/404e6b1b14f60c81388d50b4239f81d461b3c3ad" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hhj5-6fh2-3fp5/GHSA-hhj5-6fh2-3fp5.json b/advisories/unreviewed/2024/04/GHSA-hhj5-6fh2-3fp5/GHSA-hhj5-6fh2-3fp5.json index 3b54e6bf5cc..f508d8f096a 100644 --- a/advisories/unreviewed/2024/04/GHSA-hhj5-6fh2-3fp5/GHSA-hhj5-6fh2-3fp5.json +++ b/advisories/unreviewed/2024/04/GHSA-hhj5-6fh2-3fp5/GHSA-hhj5-6fh2-3fp5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hhj5-6fh2-3fp5", - "modified": "2024-04-18T09:30:44Z", + "modified": "2024-04-19T15:30:46Z", "published": "2024-04-18T09:30:44Z", "aliases": [ "CVE-2024-28076" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-28073" + }, + { + "type": "WEB", + "url": "https://www.solarwinds.com/trust-center/security-advisories/cve-2024-28076" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/04/GHSA-mvg6-43mv-76rp/GHSA-mvg6-43mv-76rp.json b/advisories/unreviewed/2024/04/GHSA-mvg6-43mv-76rp/GHSA-mvg6-43mv-76rp.json new file mode 100644 index 00000000000..061a941770e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mvg6-43mv-76rp/GHSA-mvg6-43mv-76rp.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mvg6-43mv-76rp", + "modified": "2024-04-19T15:30:47Z", + "published": "2024-04-19T15:30:47Z", + "aliases": [ + "CVE-2024-3684" + ], + "details": "A server side request forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin access to the appliance when configuring the Artifacts & Logs and Migrations Storage. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and access to the Management Console with the editor role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.12.2, 3.11.8, 3.10.10, and 3.9.13. This vulnerability was reported via the GitHub Bug Bounty program.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3684" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.10" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.8" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.12/admin/release-notes#3.12.2" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.9/admin/release-notes#3.9.13" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-88" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T15:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pj8j-wrf5-7mgp/GHSA-pj8j-wrf5-7mgp.json b/advisories/unreviewed/2024/04/GHSA-pj8j-wrf5-7mgp/GHSA-pj8j-wrf5-7mgp.json new file mode 100644 index 00000000000..4f2a61a1a6b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pj8j-wrf5-7mgp/GHSA-pj8j-wrf5-7mgp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pj8j-wrf5-7mgp", + "modified": "2024-04-19T15:30:47Z", + "published": "2024-04-19T15:30:46Z", + "aliases": [ + "CVE-2023-37400" + ], + "details": "IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to escalate their privileges due to insecure credential storage. IBM X-Force ID: 259677.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37400" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/259677" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7148631" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-qrqx-rvg9-7g66/GHSA-qrqx-rvg9-7g66.json b/advisories/unreviewed/2024/04/GHSA-qrqx-rvg9-7g66/GHSA-qrqx-rvg9-7g66.json new file mode 100644 index 00000000000..cba7ccff53e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-qrqx-rvg9-7g66/GHSA-qrqx-rvg9-7g66.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrqx-rvg9-7g66", + "modified": "2024-04-19T15:30:46Z", + "published": "2024-04-19T15:30:46Z", + "aliases": [ + "CVE-2024-3654" + ], + "details": "An XSS vulnerability has been found in Teimas Global's Teixo, version 1.42.42-stable. This vulnerability could allow an attacker to send a specially crafted JavaScript payload via the \"seconds\" parameter in the program's URL, resulting in a possible takeover of a registered user's session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3654" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-vulnerability-teixo-teimas-global" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T13:15:13Z" + } +} \ No newline at end of file