From 5f62465e8350acb23761d584e501ec01bfc571a9 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 2 Jul 2024 00:33:13 +0000 Subject: [PATCH] Publish Advisories GHSA-2x8c-95vh-gfv4 GHSA-f969-h37g-7mjc GHSA-ghf9-pcm2-m9h8 GHSA-hhqh-cfwm-qf6m GHSA-pp72-6x86-58pw GHSA-v54q-6rp3-2jhf GHSA-v8c6-9ppf-jmj9 --- .../GHSA-2x8c-95vh-gfv4.json | 10 +++++- .../GHSA-f969-h37g-7mjc.json | 35 +++++++++++++++++++ .../GHSA-ghf9-pcm2-m9h8.json | 35 +++++++++++++++++++ .../GHSA-hhqh-cfwm-qf6m.json | 35 +++++++++++++++++++ .../GHSA-pp72-6x86-58pw.json | 35 +++++++++++++++++++ .../GHSA-v54q-6rp3-2jhf.json | 35 +++++++++++++++++++ .../GHSA-v8c6-9ppf-jmj9.json | 35 +++++++++++++++++++ 7 files changed, 219 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2024/07/GHSA-f969-h37g-7mjc/GHSA-f969-h37g-7mjc.json create mode 100644 advisories/unreviewed/2024/07/GHSA-ghf9-pcm2-m9h8/GHSA-ghf9-pcm2-m9h8.json create mode 100644 advisories/unreviewed/2024/07/GHSA-hhqh-cfwm-qf6m/GHSA-hhqh-cfwm-qf6m.json create mode 100644 advisories/unreviewed/2024/07/GHSA-pp72-6x86-58pw/GHSA-pp72-6x86-58pw.json create mode 100644 advisories/unreviewed/2024/07/GHSA-v54q-6rp3-2jhf/GHSA-v54q-6rp3-2jhf.json create mode 100644 advisories/unreviewed/2024/07/GHSA-v8c6-9ppf-jmj9/GHSA-v8c6-9ppf-jmj9.json diff --git a/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json b/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json index 709c9534a7e..eb4e0c008ff 100644 --- a/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json +++ b/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2x8c-95vh-gfv4", - "modified": "2024-07-01T21:31:14Z", + "modified": "2024-07-02T00:31:46Z", "published": "2024-07-01T15:32:33Z", "aliases": [ "CVE-2024-6387" @@ -57,6 +57,10 @@ "type": "WEB", "url": "https://stackdiary.com/openssh-race-condition-in-sshd-allows-remote-code-execution" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240701-0001" + }, { "type": "WEB", "url": "https://security-tracker.debian.org/tracker/CVE-2024-6387" @@ -104,6 +108,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/07/01/12" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/01/13" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-f969-h37g-7mjc/GHSA-f969-h37g-7mjc.json b/advisories/unreviewed/2024/07/GHSA-f969-h37g-7mjc/GHSA-f969-h37g-7mjc.json new file mode 100644 index 00000000000..2f7de834ac6 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-f969-h37g-7mjc/GHSA-f969-h37g-7mjc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f969-h37g-7mjc", + "modified": "2024-07-02T00:31:47Z", + "published": "2024-07-02T00:31:47Z", + "aliases": [ + "CVE-2024-37765" + ], + "details": "Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37765" + }, + { + "type": "WEB", + "url": "https://github.com/Atreb92/cve-2024-37765" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-01T22:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-ghf9-pcm2-m9h8/GHSA-ghf9-pcm2-m9h8.json b/advisories/unreviewed/2024/07/GHSA-ghf9-pcm2-m9h8/GHSA-ghf9-pcm2-m9h8.json new file mode 100644 index 00000000000..04277149762 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-ghf9-pcm2-m9h8/GHSA-ghf9-pcm2-m9h8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghf9-pcm2-m9h8", + "modified": "2024-07-02T00:31:46Z", + "published": "2024-07-02T00:31:46Z", + "aliases": [ + "CVE-2024-37764" + ], + "details": "MachForm up to version 19 is affected by an authenticated stored cross-site scripting.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37764" + }, + { + "type": "WEB", + "url": "https://github.com/Atreb92/cve-2024-37764" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-01T22:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-hhqh-cfwm-qf6m/GHSA-hhqh-cfwm-qf6m.json b/advisories/unreviewed/2024/07/GHSA-hhqh-cfwm-qf6m/GHSA-hhqh-cfwm-qf6m.json new file mode 100644 index 00000000000..d6b0f243823 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-hhqh-cfwm-qf6m/GHSA-hhqh-cfwm-qf6m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hhqh-cfwm-qf6m", + "modified": "2024-07-02T00:31:46Z", + "published": "2024-07-02T00:31:46Z", + "aliases": [ + "CVE-2024-37762" + ], + "details": "MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37762" + }, + { + "type": "WEB", + "url": "https://github.com/Atreb92/cve-2024-37762" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-01T22:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-pp72-6x86-58pw/GHSA-pp72-6x86-58pw.json b/advisories/unreviewed/2024/07/GHSA-pp72-6x86-58pw/GHSA-pp72-6x86-58pw.json new file mode 100644 index 00000000000..2161ab80bcc --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-pp72-6x86-58pw/GHSA-pp72-6x86-58pw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pp72-6x86-58pw", + "modified": "2024-07-02T00:31:47Z", + "published": "2024-07-02T00:31:46Z", + "aliases": [ + "CVE-2024-37763" + ], + "details": "MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid sessions whom can view compiled forms results.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37763" + }, + { + "type": "WEB", + "url": "https://github.com/Atreb92/cve-2024-37763" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-01T22:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-v54q-6rp3-2jhf/GHSA-v54q-6rp3-2jhf.json b/advisories/unreviewed/2024/07/GHSA-v54q-6rp3-2jhf/GHSA-v54q-6rp3-2jhf.json new file mode 100644 index 00000000000..c74e6244a74 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-v54q-6rp3-2jhf/GHSA-v54q-6rp3-2jhf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v54q-6rp3-2jhf", + "modified": "2024-07-02T00:31:46Z", + "published": "2024-07-02T00:31:46Z", + "aliases": [ + "CVE-2024-23737" + ], + "details": "Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Jira allows attackers to allows attackers to manipulate a user's S/MIME certificate of PGP key via malicious link or email.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23737" + }, + { + "type": "WEB", + "url": "https://help.savignano.net/snotify-email-encryption/sa-2023-11-28#SA-2023-11-28-CSRFbasedvulnerabilityinuserupload" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-01T22:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-v8c6-9ppf-jmj9/GHSA-v8c6-9ppf-jmj9.json b/advisories/unreviewed/2024/07/GHSA-v8c6-9ppf-jmj9/GHSA-v8c6-9ppf-jmj9.json new file mode 100644 index 00000000000..309f66bf395 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-v8c6-9ppf-jmj9/GHSA-v8c6-9ppf-jmj9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8c6-9ppf-jmj9", + "modified": "2024-07-02T00:31:47Z", + "published": "2024-07-02T00:31:46Z", + "aliases": [ + "CVE-2024-23736" + ], + "details": "Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Confluence allows attackers to manipulate a user's S/MIME certificate of PGP key via malicious link or email.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23736" + }, + { + "type": "WEB", + "url": "https://help.savignano.net/snotify-email-encryption/sa-2023-11-28#SA-2023-11-28-CSRFbasedvulnerabilityinuserupload" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-01T22:15:02Z" + } +} \ No newline at end of file