Publish Advisories

GHSA-f8h5-v2vg-46rr
GHSA-9623-mqmm-5rcf
GHSA-9hw9-785h-9rmw
GHSA-4gff-x4ff-9qq7
GHSA-77pc-23q5-7vg9
GHSA-gqhm-prc4-8m4c
GHSA-v9c2-w942-7r95
GHSA-xx83-cxmq-x89m
This commit is contained in:
advisory-database[bot]
2024-12-13 00:32:14 +00:00
parent 75c0454f03
commit 5e518ebfc3
8 changed files with 90 additions and 16 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f8h5-v2vg-46rr",
"modified": "2024-07-25T21:31:19Z",
"modified": "2024-12-13T00:30:50Z",
"published": "2024-04-04T15:30:34Z",
"aliases": [
"CVE-2024-2700"
@@ -100,6 +100,10 @@
"type": "WEB",
"url": "https://github.com/quarkusio/quarkus/commit/990c3ee5dd5c689f514e5e87c221bce6d5dff267"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:11023"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2106"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9623-mqmm-5rcf",
"modified": "2024-10-16T14:07:33Z",
"modified": "2024-12-13T00:30:50Z",
"published": "2024-08-21T15:30:54Z",
"aliases": [
"CVE-2024-7885"
@@ -71,6 +71,10 @@
"type": "WEB",
"url": "https://github.com/undertow-io/undertow/commit/ce5182c37376982ef0abee34fce0d8c0aab0fab8"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:11023"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:6508"
@@ -110,6 +114,10 @@
{
"type": "WEB",
"url": "https://github.com/undertow-io/undertow/blob/182e4ca1543c52f438b0244c930dca3d8b6e68e3/core/src/main/java/io/undertow/server/protocol/proxy/ProxyProtocolReadListener.java"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20241011-0004"
}
],
"database_specific": {
@@ -30,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-269"
"CWE-269",
"CWE-863"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4gff-x4ff-9qq7",
"modified": "2024-12-12T03:33:01Z",
"modified": "2024-12-13T00:30:50Z",
"published": "2024-12-11T15:31:16Z",
"aliases": [
"CVE-2024-50585"
@@ -22,6 +22,10 @@
{
"type": "WEB",
"url": "https://r.sec-consult.com/numerix"
},
{
"type": "WEB",
"url": "http://seclists.org/fulldisclosure/2024/Dec/4"
}
],
"database_specific": {
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-77pc-23q5-7vg9",
"modified": "2024-12-12T03:33:06Z",
"modified": "2024-12-13T00:30:50Z",
"published": "2024-12-12T03:33:06Z",
"aliases": [
"CVE-2024-54466"
],
"details": "An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An encrypted volume may be accessed by a different user without prompting for the password.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-12T02:15:29Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gqhm-prc4-8m4c",
"modified": "2024-12-12T03:33:06Z",
"modified": "2024-12-13T00:30:50Z",
"published": "2024-12-12T03:33:06Z",
"aliases": [
"CVE-2024-54515"
],
"details": "A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2. A malicious app may be able to gain root privileges.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-281"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-12T02:15:31Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v9c2-w942-7r95",
"modified": "2024-12-12T03:33:06Z",
"modified": "2024-12-13T00:30:50Z",
"published": "2024-12-12T03:33:06Z",
"aliases": [
"CVE-2024-54490"
],
"details": "This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Sequoia 15.2. A local attacker may gain access to user's Keychain items.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-346"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-12T02:15:30Z"
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xx83-cxmq-x89m",
"modified": "2024-12-13T00:30:50Z",
"published": "2024-12-13T00:30:50Z",
"aliases": [
"CVE-2024-12289"
],
"details": "Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initialization of the Boundary controller, which may cause the Boundary server to terminate prematurely. Boundary is only vulnerable to this flaw during the initialization of the Boundary controller, which on average is measured in milliseconds during the Boundary startup process.\n\nThis vulnerability, CVE-2024-12289, is fixed in Boundary Community Edition and Boundary Enterprise 0.16.4, 0.17.3, 0.18.2.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12289"
},
{
"type": "WEB",
"url": "https://discuss.hashicorp.com/t/hcsec-2024-28-boundary-controller-incorrectly-handles-http-requests-on-initialization-which-may-lead-to-a-denial-of-service"
}
],
"database_specific": {
"cwe_ids": [
"CWE-460"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-12T23:15:10Z"
}
}