diff --git a/advisories/unreviewed/2023/07/GHSA-45c7-642q-qm9m/GHSA-45c7-642q-qm9m.json b/advisories/unreviewed/2023/07/GHSA-45c7-642q-qm9m/GHSA-45c7-642q-qm9m.json index eaea4542599..05d5e00a753 100644 --- a/advisories/unreviewed/2023/07/GHSA-45c7-642q-qm9m/GHSA-45c7-642q-qm9m.json +++ b/advisories/unreviewed/2023/07/GHSA-45c7-642q-qm9m/GHSA-45c7-642q-qm9m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-45c7-642q-qm9m", - "modified": "2023-11-14T21:30:49Z", + "modified": "2024-06-25T18:31:20Z", "published": "2023-07-20T18:33:43Z", "aliases": [ "CVE-2023-34966" @@ -37,6 +37,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:0580" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4101" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-34966" diff --git a/advisories/unreviewed/2024/06/GHSA-2774-v47p-f5v6/GHSA-2774-v47p-f5v6.json b/advisories/unreviewed/2024/06/GHSA-2774-v47p-f5v6/GHSA-2774-v47p-f5v6.json new file mode 100644 index 00000000000..2d5069c62ac --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-2774-v47p-f5v6/GHSA-2774-v47p-f5v6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2774-v47p-f5v6", + "modified": "2024-06-25T18:31:21Z", + "published": "2024-06-25T18:31:21Z", + "aliases": [ + "CVE-2024-5988" + ], + "details": "Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke a local or remote executable and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5988" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1677.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-783m-7jjf-pmgr/GHSA-783m-7jjf-pmgr.json b/advisories/unreviewed/2024/06/GHSA-783m-7jjf-pmgr/GHSA-783m-7jjf-pmgr.json new file mode 100644 index 00000000000..d630f7f883f --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-783m-7jjf-pmgr/GHSA-783m-7jjf-pmgr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-783m-7jjf-pmgr", + "modified": "2024-06-25T18:31:22Z", + "published": "2024-06-25T18:31:22Z", + "aliases": [ + "CVE-2024-6238" + ], + "details": "pgAdmin <= 8.8 has an installation Directory permission issue. Because of this issue, attackers can gain unauthorised access to the installation directory on the Debian or RHEL 8 platforms.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6238" + }, + { + "type": "WEB", + "url": "https://github.com/pgadmin-org/pgadmin4/issues/7605" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-hfr5-33pv-p28w/GHSA-hfr5-33pv-p28w.json b/advisories/unreviewed/2024/06/GHSA-hfr5-33pv-p28w/GHSA-hfr5-33pv-p28w.json new file mode 100644 index 00000000000..543fefa77d9 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-hfr5-33pv-p28w/GHSA-hfr5-33pv-p28w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hfr5-33pv-p28w", + "modified": "2024-06-25T18:31:22Z", + "published": "2024-06-25T18:31:22Z", + "aliases": [ + "CVE-2024-5990" + ], + "details": "Due to an improper input validation, an unauthenticated threat actor can send a malicious message to a monitor thread within Rockwell Automation ThinServer™ and cause a denial-of-service condition on the affected device.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5990" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1677.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-jv7c-v8gp-mvf2/GHSA-jv7c-v8gp-mvf2.json b/advisories/unreviewed/2024/06/GHSA-jv7c-v8gp-mvf2/GHSA-jv7c-v8gp-mvf2.json new file mode 100644 index 00000000000..96e3cb09410 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-jv7c-v8gp-mvf2/GHSA-jv7c-v8gp-mvf2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jv7c-v8gp-mvf2", + "modified": "2024-06-25T18:31:21Z", + "published": "2024-06-25T18:31:21Z", + "aliases": [ + "CVE-2024-0171" + ], + "details": "Dell PowerEdge Server BIOS contains an TOCTOU race condition vulnerability. A local low privileged attacker could potentially exploit this vulnerability to gain access to otherwise unauthorized resources.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0171" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000226253/dsa-2024-039-security-update-for-dell-amd-based-poweredge-server-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-mg3w-329f-wm8c/GHSA-mg3w-329f-wm8c.json b/advisories/unreviewed/2024/06/GHSA-mg3w-329f-wm8c/GHSA-mg3w-329f-wm8c.json new file mode 100644 index 00000000000..95c4e21e124 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-mg3w-329f-wm8c/GHSA-mg3w-329f-wm8c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mg3w-329f-wm8c", + "modified": "2024-06-25T18:31:21Z", + "published": "2024-06-25T18:31:21Z", + "aliases": [ + "CVE-2024-5989" + ], + "details": "Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the program and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5989" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1677.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-mq4v-mwpp-gcfh/GHSA-mq4v-mwpp-gcfh.json b/advisories/unreviewed/2024/06/GHSA-mq4v-mwpp-gcfh/GHSA-mq4v-mwpp-gcfh.json new file mode 100644 index 00000000000..c86d5f8d529 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-mq4v-mwpp-gcfh/GHSA-mq4v-mwpp-gcfh.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq4v-mwpp-gcfh", + "modified": "2024-06-25T18:31:22Z", + "published": "2024-06-25T18:31:22Z", + "aliases": [ + "CVE-2024-6308" + ], + "details": "A vulnerability was found in itsourcecode Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file index.php. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-269620.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6308" + }, + { + "type": "WEB", + "url": "https://github.com/L1OudFd8cl09/CVE/blob/main/25_06_2024_a.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.269620" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.269620" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.363955" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-xfhp-jf8p-mh5w/GHSA-xfhp-jf8p-mh5w.json b/advisories/unreviewed/2024/06/GHSA-xfhp-jf8p-mh5w/GHSA-xfhp-jf8p-mh5w.json new file mode 100644 index 00000000000..9e7c2dbb9fd --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-xfhp-jf8p-mh5w/GHSA-xfhp-jf8p-mh5w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xfhp-jf8p-mh5w", + "modified": "2024-06-25T18:31:22Z", + "published": "2024-06-25T18:31:22Z", + "aliases": [ + "CVE-2024-6257" + ], + "details": "HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6257" + }, + { + "type": "WEB", + "url": "https://discuss.hashicorp.com/t/hcsec-2024-13-hashicorp-go-getter-vulnerable-to-code-execution-on-git-update-via-git-config-manipulation/68081" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T17:15:10Z" + } +} \ No newline at end of file