Publish Advisories

GHSA-2x8c-95vh-gfv4
GHSA-f969-h37g-7mjc
GHSA-ghf9-pcm2-m9h8
GHSA-hhqh-cfwm-qf6m
GHSA-pp72-6x86-58pw
GHSA-v54q-6rp3-2jhf
GHSA-v8c6-9ppf-jmj9
This commit is contained in:
advisory-database[bot]
2024-07-02 00:33:13 +00:00
parent ca790a5ce1
commit 5f62465e83
7 changed files with 219 additions and 1 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2x8c-95vh-gfv4",
"modified": "2024-07-01T21:31:14Z",
"modified": "2024-07-02T00:31:46Z",
"published": "2024-07-01T15:32:33Z",
"aliases": [
"CVE-2024-6387"
@@ -57,6 +57,10 @@
"type": "WEB",
"url": "https://stackdiary.com/openssh-race-condition-in-sshd-allows-remote-code-execution"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240701-0001"
},
{
"type": "WEB",
"url": "https://security-tracker.debian.org/tracker/CVE-2024-6387"
@@ -104,6 +108,10 @@
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/07/01/12"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/07/01/13"
}
],
"database_specific": {
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f969-h37g-7mjc",
"modified": "2024-07-02T00:31:47Z",
"published": "2024-07-02T00:31:47Z",
"aliases": [
"CVE-2024-37765"
],
"details": "Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37765"
},
{
"type": "WEB",
"url": "https://github.com/Atreb92/cve-2024-37765"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-01T22:15:03Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ghf9-pcm2-m9h8",
"modified": "2024-07-02T00:31:46Z",
"published": "2024-07-02T00:31:46Z",
"aliases": [
"CVE-2024-37764"
],
"details": "MachForm up to version 19 is affected by an authenticated stored cross-site scripting.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37764"
},
{
"type": "WEB",
"url": "https://github.com/Atreb92/cve-2024-37764"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-01T22:15:03Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hhqh-cfwm-qf6m",
"modified": "2024-07-02T00:31:46Z",
"published": "2024-07-02T00:31:46Z",
"aliases": [
"CVE-2024-37762"
],
"details": "MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37762"
},
{
"type": "WEB",
"url": "https://github.com/Atreb92/cve-2024-37762"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-01T22:15:02Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pp72-6x86-58pw",
"modified": "2024-07-02T00:31:47Z",
"published": "2024-07-02T00:31:46Z",
"aliases": [
"CVE-2024-37763"
],
"details": "MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid sessions whom can view compiled forms results.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37763"
},
{
"type": "WEB",
"url": "https://github.com/Atreb92/cve-2024-37763"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-01T22:15:03Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v54q-6rp3-2jhf",
"modified": "2024-07-02T00:31:46Z",
"published": "2024-07-02T00:31:46Z",
"aliases": [
"CVE-2024-23737"
],
"details": "Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Jira allows attackers to allows attackers to manipulate a user's S/MIME certificate of PGP key via malicious link or email.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23737"
},
{
"type": "WEB",
"url": "https://help.savignano.net/snotify-email-encryption/sa-2023-11-28#SA-2023-11-28-CSRFbasedvulnerabilityinuserupload"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-01T22:15:02Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v8c6-9ppf-jmj9",
"modified": "2024-07-02T00:31:47Z",
"published": "2024-07-02T00:31:46Z",
"aliases": [
"CVE-2024-23736"
],
"details": "Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Confluence allows attackers to manipulate a user's S/MIME certificate of PGP key via malicious link or email.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23736"
},
{
"type": "WEB",
"url": "https://help.savignano.net/snotify-email-encryption/sa-2023-11-28#SA-2023-11-28-CSRFbasedvulnerabilityinuserupload"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-01T22:15:02Z"
}
}