Publish Advisories

GHSA-45c7-642q-qm9m
GHSA-2774-v47p-f5v6
GHSA-783m-7jjf-pmgr
GHSA-hfr5-33pv-p28w
GHSA-jv7c-v8gp-mvf2
GHSA-mg3w-329f-wm8c
GHSA-mq4v-mwpp-gcfh
GHSA-xfhp-jf8p-mh5w
This commit is contained in:
advisory-database[bot]
2024-06-25 18:32:51 +00:00
parent b0ad0e2fa5
commit 5f9bda5737
8 changed files with 274 additions and 1 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-45c7-642q-qm9m",
"modified": "2023-11-14T21:30:49Z",
"modified": "2024-06-25T18:31:20Z",
"published": "2023-07-20T18:33:43Z",
"aliases": [
"CVE-2023-34966"
@@ -37,6 +37,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:0580"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:4101"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-34966"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2774-v47p-f5v6",
"modified": "2024-06-25T18:31:21Z",
"published": "2024-06-25T18:31:21Z",
"aliases": [
"CVE-2024-5988"
],
"details": "Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke a local or remote executable and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5988"
},
{
"type": "WEB",
"url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1677.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-20"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-25T16:15:24Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-783m-7jjf-pmgr",
"modified": "2024-06-25T18:31:22Z",
"published": "2024-06-25T18:31:22Z",
"aliases": [
"CVE-2024-6238"
],
"details": "pgAdmin <= 8.8 has an installation Directory permission issue. Because of this issue, attackers can gain unauthorised access to the installation directory on the Debian or RHEL 8 platforms.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6238"
},
{
"type": "WEB",
"url": "https://github.com/pgadmin-org/pgadmin4/issues/7605"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-25T16:15:25Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hfr5-33pv-p28w",
"modified": "2024-06-25T18:31:22Z",
"published": "2024-06-25T18:31:22Z",
"aliases": [
"CVE-2024-5990"
],
"details": "Due to an improper input validation, an unauthenticated threat actor can send a malicious message to a monitor thread within Rockwell Automation ThinServer™ and cause a denial-of-service condition on the affected device.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5990"
},
{
"type": "WEB",
"url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1677.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-20"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-25T16:15:25Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jv7c-v8gp-mvf2",
"modified": "2024-06-25T18:31:21Z",
"published": "2024-06-25T18:31:21Z",
"aliases": [
"CVE-2024-0171"
],
"details": "Dell PowerEdge Server BIOS contains an TOCTOU race condition vulnerability. A local low privileged attacker could potentially exploit this vulnerability to gain access to otherwise unauthorized resources.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0171"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000226253/dsa-2024-039-security-update-for-dell-amd-based-poweredge-server-vulnerability"
}
],
"database_specific": {
"cwe_ids": [
"CWE-367"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-25T16:15:24Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mg3w-329f-wm8c",
"modified": "2024-06-25T18:31:21Z",
"published": "2024-06-25T18:31:21Z",
"aliases": [
"CVE-2024-5989"
],
"details": "Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the program and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5989"
},
{
"type": "WEB",
"url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1677.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-20"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-25T16:15:25Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mq4v-mwpp-gcfh",
"modified": "2024-06-25T18:31:22Z",
"published": "2024-06-25T18:31:22Z",
"aliases": [
"CVE-2024-6308"
],
"details": "A vulnerability was found in itsourcecode Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file index.php. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-269620.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6308"
},
{
"type": "WEB",
"url": "https://github.com/L1OudFd8cl09/CVE/blob/main/25_06_2024_a.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.269620"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.269620"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.363955"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-25T17:15:11Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xfhp-jf8p-mh5w",
"modified": "2024-06-25T18:31:22Z",
"published": "2024-06-25T18:31:22Z",
"aliases": [
"CVE-2024-6257"
],
"details": "HashiCorps go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6257"
},
{
"type": "WEB",
"url": "https://discuss.hashicorp.com/t/hcsec-2024-13-hashicorp-go-getter-vulnerable-to-code-execution-on-git-update-via-git-config-manipulation/68081"
}
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-25T17:15:10Z"
}
}