diff --git a/advisories/github-reviewed/2024/04/GHSA-f8h5-v2vg-46rr/GHSA-f8h5-v2vg-46rr.json b/advisories/github-reviewed/2024/04/GHSA-f8h5-v2vg-46rr/GHSA-f8h5-v2vg-46rr.json index 14d971fed97..9a796e779be 100644 --- a/advisories/github-reviewed/2024/04/GHSA-f8h5-v2vg-46rr/GHSA-f8h5-v2vg-46rr.json +++ b/advisories/github-reviewed/2024/04/GHSA-f8h5-v2vg-46rr/GHSA-f8h5-v2vg-46rr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f8h5-v2vg-46rr", - "modified": "2024-07-25T21:31:19Z", + "modified": "2024-12-13T00:30:50Z", "published": "2024-04-04T15:30:34Z", "aliases": [ "CVE-2024-2700" @@ -100,6 +100,10 @@ "type": "WEB", "url": "https://github.com/quarkusio/quarkus/commit/990c3ee5dd5c689f514e5e87c221bce6d5dff267" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:11023" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:2106" diff --git a/advisories/github-reviewed/2024/08/GHSA-9623-mqmm-5rcf/GHSA-9623-mqmm-5rcf.json b/advisories/github-reviewed/2024/08/GHSA-9623-mqmm-5rcf/GHSA-9623-mqmm-5rcf.json index 39fca7a8d4d..0eb6eb6ff61 100644 --- a/advisories/github-reviewed/2024/08/GHSA-9623-mqmm-5rcf/GHSA-9623-mqmm-5rcf.json +++ b/advisories/github-reviewed/2024/08/GHSA-9623-mqmm-5rcf/GHSA-9623-mqmm-5rcf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9623-mqmm-5rcf", - "modified": "2024-10-16T14:07:33Z", + "modified": "2024-12-13T00:30:50Z", "published": "2024-08-21T15:30:54Z", "aliases": [ "CVE-2024-7885" @@ -71,6 +71,10 @@ "type": "WEB", "url": "https://github.com/undertow-io/undertow/commit/ce5182c37376982ef0abee34fce0d8c0aab0fab8" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:11023" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:6508" @@ -110,6 +114,10 @@ { "type": "WEB", "url": "https://github.com/undertow-io/undertow/blob/182e4ca1543c52f438b0244c930dca3d8b6e68e3/core/src/main/java/io/undertow/server/protocol/proxy/ProxyProtocolReadListener.java" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241011-0004" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/06/GHSA-9hw9-785h-9rmw/GHSA-9hw9-785h-9rmw.json b/advisories/unreviewed/2023/06/GHSA-9hw9-785h-9rmw/GHSA-9hw9-785h-9rmw.json index 83878741544..395ab386439 100644 --- a/advisories/unreviewed/2023/06/GHSA-9hw9-785h-9rmw/GHSA-9hw9-785h-9rmw.json +++ b/advisories/unreviewed/2023/06/GHSA-9hw9-785h-9rmw/GHSA-9hw9-785h-9rmw.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-863" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-4gff-x4ff-9qq7/GHSA-4gff-x4ff-9qq7.json b/advisories/unreviewed/2024/12/GHSA-4gff-x4ff-9qq7/GHSA-4gff-x4ff-9qq7.json index 61588aa3c27..84344211e1f 100644 --- a/advisories/unreviewed/2024/12/GHSA-4gff-x4ff-9qq7/GHSA-4gff-x4ff-9qq7.json +++ b/advisories/unreviewed/2024/12/GHSA-4gff-x4ff-9qq7/GHSA-4gff-x4ff-9qq7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4gff-x4ff-9qq7", - "modified": "2024-12-12T03:33:01Z", + "modified": "2024-12-13T00:30:50Z", "published": "2024-12-11T15:31:16Z", "aliases": [ "CVE-2024-50585" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://r.sec-consult.com/numerix" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Dec/4" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-77pc-23q5-7vg9/GHSA-77pc-23q5-7vg9.json b/advisories/unreviewed/2024/12/GHSA-77pc-23q5-7vg9/GHSA-77pc-23q5-7vg9.json index 20096a3471b..427aee2ab8f 100644 --- a/advisories/unreviewed/2024/12/GHSA-77pc-23q5-7vg9/GHSA-77pc-23q5-7vg9.json +++ b/advisories/unreviewed/2024/12/GHSA-77pc-23q5-7vg9/GHSA-77pc-23q5-7vg9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-77pc-23q5-7vg9", - "modified": "2024-12-12T03:33:06Z", + "modified": "2024-12-13T00:30:50Z", "published": "2024-12-12T03:33:06Z", "aliases": [ "CVE-2024-54466" ], "details": "An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An encrypted volume may be accessed by a different user without prompting for the password.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:29Z" diff --git a/advisories/unreviewed/2024/12/GHSA-gqhm-prc4-8m4c/GHSA-gqhm-prc4-8m4c.json b/advisories/unreviewed/2024/12/GHSA-gqhm-prc4-8m4c/GHSA-gqhm-prc4-8m4c.json index 8dd2f43b9f2..14e39cc7a5a 100644 --- a/advisories/unreviewed/2024/12/GHSA-gqhm-prc4-8m4c/GHSA-gqhm-prc4-8m4c.json +++ b/advisories/unreviewed/2024/12/GHSA-gqhm-prc4-8m4c/GHSA-gqhm-prc4-8m4c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gqhm-prc4-8m4c", - "modified": "2024-12-12T03:33:06Z", + "modified": "2024-12-13T00:30:50Z", "published": "2024-12-12T03:33:06Z", "aliases": [ "CVE-2024-54515" ], "details": "A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2. A malicious app may be able to gain root privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-281" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:31Z" diff --git a/advisories/unreviewed/2024/12/GHSA-v9c2-w942-7r95/GHSA-v9c2-w942-7r95.json b/advisories/unreviewed/2024/12/GHSA-v9c2-w942-7r95/GHSA-v9c2-w942-7r95.json index 6bca853a5c4..75357aaea5a 100644 --- a/advisories/unreviewed/2024/12/GHSA-v9c2-w942-7r95/GHSA-v9c2-w942-7r95.json +++ b/advisories/unreviewed/2024/12/GHSA-v9c2-w942-7r95/GHSA-v9c2-w942-7r95.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v9c2-w942-7r95", - "modified": "2024-12-12T03:33:06Z", + "modified": "2024-12-13T00:30:50Z", "published": "2024-12-12T03:33:06Z", "aliases": [ "CVE-2024-54490" ], "details": "This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Sequoia 15.2. A local attacker may gain access to user's Keychain items.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-346" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:30Z" diff --git a/advisories/unreviewed/2024/12/GHSA-xx83-cxmq-x89m/GHSA-xx83-cxmq-x89m.json b/advisories/unreviewed/2024/12/GHSA-xx83-cxmq-x89m/GHSA-xx83-cxmq-x89m.json new file mode 100644 index 00000000000..d4fb2c87ae3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xx83-cxmq-x89m/GHSA-xx83-cxmq-x89m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xx83-cxmq-x89m", + "modified": "2024-12-13T00:30:50Z", + "published": "2024-12-13T00:30:50Z", + "aliases": [ + "CVE-2024-12289" + ], + "details": "Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initialization of the Boundary controller, which may cause the Boundary server to terminate prematurely. Boundary is only vulnerable to this flaw during the initialization of the Boundary controller, which on average is measured in milliseconds during the Boundary startup process.\n\nThis vulnerability, CVE-2024-12289, is fixed in Boundary Community Edition and Boundary Enterprise 0.16.4, 0.17.3, 0.18.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12289" + }, + { + "type": "WEB", + "url": "https://discuss.hashicorp.com/t/hcsec-2024-28-boundary-controller-incorrectly-handles-http-requests-on-initialization-which-may-lead-to-a-denial-of-service" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-460" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T23:15:10Z" + } +} \ No newline at end of file