From 5fb047d07217106905d5b53785f54a7ecb1a5365 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 1 Feb 2024 06:32:26 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-gxmr-w5mj-v8hh.json | 4 ++ .../GHSA-2fpf-9qrw-vj6r.json | 2 +- .../GHSA-33f3-88p6-j3f9.json | 11 +++-- .../GHSA-3qmj-w5mh-5gv3.json | 11 +++-- .../GHSA-3qxr-cm3w-hpmq.json | 4 +- .../GHSA-4q7q-5p3p-5fcj.json | 11 +++-- .../GHSA-4q9c-68c7-fxff.json | 11 +++-- .../GHSA-7j85-cwr3-f2w3.json | 11 +++-- .../GHSA-8r89-2849-x8p3.json | 2 +- .../GHSA-9mx6-23q4-mcch.json | 2 +- .../GHSA-c2jp-pq2c-g7jh.json | 11 +++-- .../GHSA-cmmq-7g27-wvv8.json | 4 +- .../GHSA-cvpg-3pfh-m39w.json | 2 +- .../GHSA-g2f8-pfg4-3w3q.json | 11 +++-- .../GHSA-g5jr-34r4-rv4w.json | 5 ++- .../GHSA-h56c-gcxc-4q77.json | 11 +++-- .../GHSA-jjr8-97p7-vmmg.json | 8 ++++ .../GHSA-jm98-mxmf-qcjw.json | 11 +++-- .../GHSA-p5vr-h433-qhqr.json | 8 ++++ .../GHSA-p6rw-gvvh-q8v4.json | 8 ++++ .../GHSA-p899-8gh2-v29w.json | 11 +++-- .../GHSA-qrpx-55hc-9pr8.json | 3 +- .../GHSA-r9gf-434r-vm83.json | 11 +++-- .../GHSA-v9cm-8hxg-x4rc.json | 2 +- .../GHSA-vhm4-6qm7-jwhr.json | 4 +- .../GHSA-w5f8-jmcg-4qrj.json | 11 +++-- .../GHSA-5rhg-f75j-57f8.json | 43 +++++++++++++++++++ .../GHSA-c56q-fqmf-hg57.json | 42 ++++++++++++++++++ 28 files changed, 213 insertions(+), 62 deletions(-) create mode 100644 advisories/unreviewed/2024/02/GHSA-5rhg-f75j-57f8/GHSA-5rhg-f75j-57f8.json create mode 100644 advisories/unreviewed/2024/02/GHSA-c56q-fqmf-hg57/GHSA-c56q-fqmf-hg57.json diff --git a/advisories/unreviewed/2022/05/GHSA-gxmr-w5mj-v8hh/GHSA-gxmr-w5mj-v8hh.json b/advisories/unreviewed/2022/05/GHSA-gxmr-w5mj-v8hh/GHSA-gxmr-w5mj-v8hh.json index 1edd318045d..9c67b0b11f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxmr-w5mj-v8hh/GHSA-gxmr-w5mj-v8hh.json +++ b/advisories/unreviewed/2022/05/GHSA-gxmr-w5mj-v8hh/GHSA-gxmr-w5mj-v8hh.json @@ -317,6 +317,10 @@ "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/01/31/6" }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/02/01/1" + }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/106976" diff --git a/advisories/unreviewed/2024/01/GHSA-2fpf-9qrw-vj6r/GHSA-2fpf-9qrw-vj6r.json b/advisories/unreviewed/2024/01/GHSA-2fpf-9qrw-vj6r/GHSA-2fpf-9qrw-vj6r.json index 946c52687bd..08dc35f30df 100644 --- a/advisories/unreviewed/2024/01/GHSA-2fpf-9qrw-vj6r/GHSA-2fpf-9qrw-vj6r.json +++ b/advisories/unreviewed/2024/01/GHSA-2fpf-9qrw-vj6r/GHSA-2fpf-9qrw-vj6r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2fpf-9qrw-vj6r", - "modified": "2024-01-27T00:31:23Z", + "modified": "2024-02-01T06:31:04Z", "published": "2024-01-27T00:31:23Z", "aliases": [ "CVE-2024-23506" diff --git a/advisories/unreviewed/2024/01/GHSA-33f3-88p6-j3f9/GHSA-33f3-88p6-j3f9.json b/advisories/unreviewed/2024/01/GHSA-33f3-88p6-j3f9/GHSA-33f3-88p6-j3f9.json index 04e1b0031f9..a9fe91a219a 100644 --- a/advisories/unreviewed/2024/01/GHSA-33f3-88p6-j3f9/GHSA-33f3-88p6-j3f9.json +++ b/advisories/unreviewed/2024/01/GHSA-33f3-88p6-j3f9/GHSA-33f3-88p6-j3f9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-33f3-88p6-j3f9", - "modified": "2024-01-30T15:30:22Z", + "modified": "2024-02-01T06:31:05Z", "published": "2024-01-30T15:30:22Z", "aliases": [ "CVE-2024-24324" ], "details": "TOTOLINK A8000RU v7.1cu.643_B20200521 was discovered to contain a hardcoded password for root stored in /etc/shadow.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-30T15:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-3qmj-w5mh-5gv3/GHSA-3qmj-w5mh-5gv3.json b/advisories/unreviewed/2024/01/GHSA-3qmj-w5mh-5gv3/GHSA-3qmj-w5mh-5gv3.json index c3409f72024..fd33d77d532 100644 --- a/advisories/unreviewed/2024/01/GHSA-3qmj-w5mh-5gv3/GHSA-3qmj-w5mh-5gv3.json +++ b/advisories/unreviewed/2024/01/GHSA-3qmj-w5mh-5gv3/GHSA-3qmj-w5mh-5gv3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3qmj-w5mh-5gv3", - "modified": "2024-01-30T15:30:23Z", + "modified": "2024-02-01T06:31:05Z", "published": "2024-01-30T15:30:23Z", "aliases": [ "CVE-2024-24329" ], "details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setPortForwardRules function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-30T15:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-3qxr-cm3w-hpmq/GHSA-3qxr-cm3w-hpmq.json b/advisories/unreviewed/2024/01/GHSA-3qxr-cm3w-hpmq/GHSA-3qxr-cm3w-hpmq.json index fc1235f6d28..b8175ff5924 100644 --- a/advisories/unreviewed/2024/01/GHSA-3qxr-cm3w-hpmq/GHSA-3qxr-cm3w-hpmq.json +++ b/advisories/unreviewed/2024/01/GHSA-3qxr-cm3w-hpmq/GHSA-3qxr-cm3w-hpmq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3qxr-cm3w-hpmq", - "modified": "2024-01-27T06:30:23Z", + "modified": "2024-02-01T06:31:04Z", "published": "2024-01-27T06:30:23Z", "aliases": [ "CVE-2024-0618" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-4q7q-5p3p-5fcj/GHSA-4q7q-5p3p-5fcj.json b/advisories/unreviewed/2024/01/GHSA-4q7q-5p3p-5fcj/GHSA-4q7q-5p3p-5fcj.json index 720adaf82ed..dafb250b8b0 100644 --- a/advisories/unreviewed/2024/01/GHSA-4q7q-5p3p-5fcj/GHSA-4q7q-5p3p-5fcj.json +++ b/advisories/unreviewed/2024/01/GHSA-4q7q-5p3p-5fcj/GHSA-4q7q-5p3p-5fcj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4q7q-5p3p-5fcj", - "modified": "2024-01-30T15:30:23Z", + "modified": "2024-02-01T06:31:05Z", "published": "2024-01-30T15:30:23Z", "aliases": [ "CVE-2024-24328" ], "details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setMacFilterRules function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-30T15:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-4q9c-68c7-fxff/GHSA-4q9c-68c7-fxff.json b/advisories/unreviewed/2024/01/GHSA-4q9c-68c7-fxff/GHSA-4q9c-68c7-fxff.json index 9dc8444be43..324120bdd37 100644 --- a/advisories/unreviewed/2024/01/GHSA-4q9c-68c7-fxff/GHSA-4q9c-68c7-fxff.json +++ b/advisories/unreviewed/2024/01/GHSA-4q9c-68c7-fxff/GHSA-4q9c-68c7-fxff.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4q9c-68c7-fxff", - "modified": "2024-01-30T15:30:23Z", + "modified": "2024-02-01T06:31:05Z", "published": "2024-01-30T15:30:23Z", "aliases": [ "CVE-2024-24327" ], "details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pppoePass parameter in the setIpv6Cfg function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-30T15:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-7j85-cwr3-f2w3/GHSA-7j85-cwr3-f2w3.json b/advisories/unreviewed/2024/01/GHSA-7j85-cwr3-f2w3/GHSA-7j85-cwr3-f2w3.json index 3e0648dbad1..1a0e346ba29 100644 --- a/advisories/unreviewed/2024/01/GHSA-7j85-cwr3-f2w3/GHSA-7j85-cwr3-f2w3.json +++ b/advisories/unreviewed/2024/01/GHSA-7j85-cwr3-f2w3/GHSA-7j85-cwr3-f2w3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7j85-cwr3-f2w3", - "modified": "2024-01-30T15:30:23Z", + "modified": "2024-02-01T06:31:05Z", "published": "2024-01-30T15:30:23Z", "aliases": [ "CVE-2024-24332" ], "details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the url parameter in the setUrlFilterRules function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-30T15:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-8r89-2849-x8p3/GHSA-8r89-2849-x8p3.json b/advisories/unreviewed/2024/01/GHSA-8r89-2849-x8p3/GHSA-8r89-2849-x8p3.json index 2846e43ae9c..24b62d3e402 100644 --- a/advisories/unreviewed/2024/01/GHSA-8r89-2849-x8p3/GHSA-8r89-2849-x8p3.json +++ b/advisories/unreviewed/2024/01/GHSA-8r89-2849-x8p3/GHSA-8r89-2849-x8p3.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-9mx6-23q4-mcch/GHSA-9mx6-23q4-mcch.json b/advisories/unreviewed/2024/01/GHSA-9mx6-23q4-mcch/GHSA-9mx6-23q4-mcch.json index af71e3edef9..989fda3cc67 100644 --- a/advisories/unreviewed/2024/01/GHSA-9mx6-23q4-mcch/GHSA-9mx6-23q4-mcch.json +++ b/advisories/unreviewed/2024/01/GHSA-9mx6-23q4-mcch/GHSA-9mx6-23q4-mcch.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9mx6-23q4-mcch", - "modified": "2024-01-27T00:31:23Z", + "modified": "2024-02-01T06:31:04Z", "published": "2024-01-27T00:31:23Z", "aliases": [ "CVE-2023-52187" diff --git a/advisories/unreviewed/2024/01/GHSA-c2jp-pq2c-g7jh/GHSA-c2jp-pq2c-g7jh.json b/advisories/unreviewed/2024/01/GHSA-c2jp-pq2c-g7jh/GHSA-c2jp-pq2c-g7jh.json index 6324a32c6c7..e186497fd31 100644 --- a/advisories/unreviewed/2024/01/GHSA-c2jp-pq2c-g7jh/GHSA-c2jp-pq2c-g7jh.json +++ b/advisories/unreviewed/2024/01/GHSA-c2jp-pq2c-g7jh/GHSA-c2jp-pq2c-g7jh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c2jp-pq2c-g7jh", - "modified": "2024-01-27T06:30:23Z", + "modified": "2024-02-01T06:31:04Z", "published": "2024-01-27T06:30:23Z", "aliases": [ "CVE-2023-48202" ], "details": "Cross-Site Scripting (XSS) vulnerability in Sunlight CMS 8.0.1 allows an authenticated low-privileged user to escalate privileges via a crafted SVG file in the File Manager component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-27T06:15:47Z" diff --git a/advisories/unreviewed/2024/01/GHSA-cmmq-7g27-wvv8/GHSA-cmmq-7g27-wvv8.json b/advisories/unreviewed/2024/01/GHSA-cmmq-7g27-wvv8/GHSA-cmmq-7g27-wvv8.json index 01603e9ef69..9d5f0ef5612 100644 --- a/advisories/unreviewed/2024/01/GHSA-cmmq-7g27-wvv8/GHSA-cmmq-7g27-wvv8.json +++ b/advisories/unreviewed/2024/01/GHSA-cmmq-7g27-wvv8/GHSA-cmmq-7g27-wvv8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cmmq-7g27-wvv8", - "modified": "2024-01-27T06:30:23Z", + "modified": "2024-02-01T06:31:04Z", "published": "2024-01-27T06:30:23Z", "aliases": [ "CVE-2024-0697" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-cvpg-3pfh-m39w/GHSA-cvpg-3pfh-m39w.json b/advisories/unreviewed/2024/01/GHSA-cvpg-3pfh-m39w/GHSA-cvpg-3pfh-m39w.json index ecfa2344c9d..935609a0331 100644 --- a/advisories/unreviewed/2024/01/GHSA-cvpg-3pfh-m39w/GHSA-cvpg-3pfh-m39w.json +++ b/advisories/unreviewed/2024/01/GHSA-cvpg-3pfh-m39w/GHSA-cvpg-3pfh-m39w.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-g2f8-pfg4-3w3q/GHSA-g2f8-pfg4-3w3q.json b/advisories/unreviewed/2024/01/GHSA-g2f8-pfg4-3w3q/GHSA-g2f8-pfg4-3w3q.json index f5b64ad371f..32ad8e2e1b0 100644 --- a/advisories/unreviewed/2024/01/GHSA-g2f8-pfg4-3w3q/GHSA-g2f8-pfg4-3w3q.json +++ b/advisories/unreviewed/2024/01/GHSA-g2f8-pfg4-3w3q/GHSA-g2f8-pfg4-3w3q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g2f8-pfg4-3w3q", - "modified": "2024-01-30T15:30:23Z", + "modified": "2024-02-01T06:31:05Z", "published": "2024-01-30T15:30:23Z", "aliases": [ "CVE-2024-24331" ], "details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setWiFiScheduleCfg function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-30T15:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-g5jr-34r4-rv4w/GHSA-g5jr-34r4-rv4w.json b/advisories/unreviewed/2024/01/GHSA-g5jr-34r4-rv4w/GHSA-g5jr-34r4-rv4w.json index 015f53e5237..af7dce6f41b 100644 --- a/advisories/unreviewed/2024/01/GHSA-g5jr-34r4-rv4w/GHSA-g5jr-34r4-rv4w.json +++ b/advisories/unreviewed/2024/01/GHSA-g5jr-34r4-rv4w/GHSA-g5jr-34r4-rv4w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g5jr-34r4-rv4w", - "modified": "2024-01-29T18:31:48Z", + "modified": "2024-02-01T06:31:04Z", "published": "2024-01-27T03:30:21Z", "aliases": [ "CVE-2023-6482" @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-321" + "CWE-321", + "CWE-798" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-h56c-gcxc-4q77/GHSA-h56c-gcxc-4q77.json b/advisories/unreviewed/2024/01/GHSA-h56c-gcxc-4q77/GHSA-h56c-gcxc-4q77.json index 4011b1943d0..5fe23a36908 100644 --- a/advisories/unreviewed/2024/01/GHSA-h56c-gcxc-4q77/GHSA-h56c-gcxc-4q77.json +++ b/advisories/unreviewed/2024/01/GHSA-h56c-gcxc-4q77/GHSA-h56c-gcxc-4q77.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h56c-gcxc-4q77", - "modified": "2024-01-30T15:30:23Z", + "modified": "2024-02-01T06:31:05Z", "published": "2024-01-30T15:30:23Z", "aliases": [ "CVE-2024-24333" ], "details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the desc parameter in the setWiFiAclRules function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-30T15:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-jjr8-97p7-vmmg/GHSA-jjr8-97p7-vmmg.json b/advisories/unreviewed/2024/01/GHSA-jjr8-97p7-vmmg/GHSA-jjr8-97p7-vmmg.json index 174cbd0f760..80ecbaaa789 100644 --- a/advisories/unreviewed/2024/01/GHSA-jjr8-97p7-vmmg/GHSA-jjr8-97p7-vmmg.json +++ b/advisories/unreviewed/2024/01/GHSA-jjr8-97p7-vmmg/GHSA-jjr8-97p7-vmmg.json @@ -29,6 +29,14 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2254396" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D2FIH77VHY3KCRROCXOT6L27WMZXSJ2G/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MWQ6BZJ6CV5UAW4VZSKJ6TO4KIW2KWAQ/" + }, { "type": "WEB", "url": "https://www.openwall.com/lists/oss-security/2024/01/30/6" diff --git a/advisories/unreviewed/2024/01/GHSA-jm98-mxmf-qcjw/GHSA-jm98-mxmf-qcjw.json b/advisories/unreviewed/2024/01/GHSA-jm98-mxmf-qcjw/GHSA-jm98-mxmf-qcjw.json index 8c923343c23..5abeb59efd8 100644 --- a/advisories/unreviewed/2024/01/GHSA-jm98-mxmf-qcjw/GHSA-jm98-mxmf-qcjw.json +++ b/advisories/unreviewed/2024/01/GHSA-jm98-mxmf-qcjw/GHSA-jm98-mxmf-qcjw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jm98-mxmf-qcjw", - "modified": "2024-01-30T15:30:23Z", + "modified": "2024-02-01T06:31:05Z", "published": "2024-01-30T15:30:23Z", "aliases": [ "CVE-2024-24330" ], "details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the port or enable parameter in the setRemoteCfg function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-30T15:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-p5vr-h433-qhqr/GHSA-p5vr-h433-qhqr.json b/advisories/unreviewed/2024/01/GHSA-p5vr-h433-qhqr/GHSA-p5vr-h433-qhqr.json index 0dd485d0706..3b361655355 100644 --- a/advisories/unreviewed/2024/01/GHSA-p5vr-h433-qhqr/GHSA-p5vr-h433-qhqr.json +++ b/advisories/unreviewed/2024/01/GHSA-p5vr-h433-qhqr/GHSA-p5vr-h433-qhqr.json @@ -29,6 +29,14 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2254395" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D2FIH77VHY3KCRROCXOT6L27WMZXSJ2G/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MWQ6BZJ6CV5UAW4VZSKJ6TO4KIW2KWAQ/" + }, { "type": "WEB", "url": "https://www.openwall.com/lists/oss-security/2024/01/30/6" diff --git a/advisories/unreviewed/2024/01/GHSA-p6rw-gvvh-q8v4/GHSA-p6rw-gvvh-q8v4.json b/advisories/unreviewed/2024/01/GHSA-p6rw-gvvh-q8v4/GHSA-p6rw-gvvh-q8v4.json index 80030b3a730..a5ea6f0655b 100644 --- a/advisories/unreviewed/2024/01/GHSA-p6rw-gvvh-q8v4/GHSA-p6rw-gvvh-q8v4.json +++ b/advisories/unreviewed/2024/01/GHSA-p6rw-gvvh-q8v4/GHSA-p6rw-gvvh-q8v4.json @@ -29,6 +29,14 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2249053" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D2FIH77VHY3KCRROCXOT6L27WMZXSJ2G/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MWQ6BZJ6CV5UAW4VZSKJ6TO4KIW2KWAQ/" + }, { "type": "WEB", "url": "https://www.openwall.com/lists/oss-security/2024/01/30/6" diff --git a/advisories/unreviewed/2024/01/GHSA-p899-8gh2-v29w/GHSA-p899-8gh2-v29w.json b/advisories/unreviewed/2024/01/GHSA-p899-8gh2-v29w/GHSA-p899-8gh2-v29w.json index 2aa90c7f109..50a6d95ddd2 100644 --- a/advisories/unreviewed/2024/01/GHSA-p899-8gh2-v29w/GHSA-p899-8gh2-v29w.json +++ b/advisories/unreviewed/2024/01/GHSA-p899-8gh2-v29w/GHSA-p899-8gh2-v29w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p899-8gh2-v29w", - "modified": "2024-01-27T06:30:23Z", + "modified": "2024-02-01T06:31:04Z", "published": "2024-01-27T06:30:23Z", "aliases": [ "CVE-2023-48201" ], "details": "Cross Site Scripting (XSS) vulnerability in Sunlight CMS v.8.0.1, allows remote authenticated attackers to execute arbitrary code and escalate privileges via a crafted script to the Content text editor component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-27T06:15:47Z" diff --git a/advisories/unreviewed/2024/01/GHSA-qrpx-55hc-9pr8/GHSA-qrpx-55hc-9pr8.json b/advisories/unreviewed/2024/01/GHSA-qrpx-55hc-9pr8/GHSA-qrpx-55hc-9pr8.json index 2cedaa762a8..ffce22608aa 100644 --- a/advisories/unreviewed/2024/01/GHSA-qrpx-55hc-9pr8/GHSA-qrpx-55hc-9pr8.json +++ b/advisories/unreviewed/2024/01/GHSA-qrpx-55hc-9pr8/GHSA-qrpx-55hc-9pr8.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-r9gf-434r-vm83/GHSA-r9gf-434r-vm83.json b/advisories/unreviewed/2024/01/GHSA-r9gf-434r-vm83/GHSA-r9gf-434r-vm83.json index 9c4b3dd4c5f..eaea96189d8 100644 --- a/advisories/unreviewed/2024/01/GHSA-r9gf-434r-vm83/GHSA-r9gf-434r-vm83.json +++ b/advisories/unreviewed/2024/01/GHSA-r9gf-434r-vm83/GHSA-r9gf-434r-vm83.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r9gf-434r-vm83", - "modified": "2024-01-30T15:30:22Z", + "modified": "2024-02-01T06:31:05Z", "published": "2024-01-30T15:30:22Z", "aliases": [ "CVE-2024-24326" ], "details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the arpEnable parameter in the setStaticDhcpRules function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-30T15:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-v9cm-8hxg-x4rc/GHSA-v9cm-8hxg-x4rc.json b/advisories/unreviewed/2024/01/GHSA-v9cm-8hxg-x4rc/GHSA-v9cm-8hxg-x4rc.json index 4c82650afa0..f260054f1ce 100644 --- a/advisories/unreviewed/2024/01/GHSA-v9cm-8hxg-x4rc/GHSA-v9cm-8hxg-x4rc.json +++ b/advisories/unreviewed/2024/01/GHSA-v9cm-8hxg-x4rc/GHSA-v9cm-8hxg-x4rc.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-vhm4-6qm7-jwhr/GHSA-vhm4-6qm7-jwhr.json b/advisories/unreviewed/2024/01/GHSA-vhm4-6qm7-jwhr/GHSA-vhm4-6qm7-jwhr.json index 5376897c620..03c2a4b689f 100644 --- a/advisories/unreviewed/2024/01/GHSA-vhm4-6qm7-jwhr/GHSA-vhm4-6qm7-jwhr.json +++ b/advisories/unreviewed/2024/01/GHSA-vhm4-6qm7-jwhr/GHSA-vhm4-6qm7-jwhr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vhm4-6qm7-jwhr", - "modified": "2024-01-27T06:30:22Z", + "modified": "2024-02-01T06:31:04Z", "published": "2024-01-27T06:30:22Z", "aliases": [ "CVE-2024-0667" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-w5f8-jmcg-4qrj/GHSA-w5f8-jmcg-4qrj.json b/advisories/unreviewed/2024/01/GHSA-w5f8-jmcg-4qrj/GHSA-w5f8-jmcg-4qrj.json index 9387dc5f314..f0bc1c1fc47 100644 --- a/advisories/unreviewed/2024/01/GHSA-w5f8-jmcg-4qrj/GHSA-w5f8-jmcg-4qrj.json +++ b/advisories/unreviewed/2024/01/GHSA-w5f8-jmcg-4qrj/GHSA-w5f8-jmcg-4qrj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w5f8-jmcg-4qrj", - "modified": "2024-01-30T15:30:22Z", + "modified": "2024-02-01T06:31:05Z", "published": "2024-01-30T15:30:22Z", "aliases": [ "CVE-2024-24325" ], "details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setParentalRules function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-30T15:15:09Z" diff --git a/advisories/unreviewed/2024/02/GHSA-5rhg-f75j-57f8/GHSA-5rhg-f75j-57f8.json b/advisories/unreviewed/2024/02/GHSA-5rhg-f75j-57f8/GHSA-5rhg-f75j-57f8.json new file mode 100644 index 00000000000..b8d4dbe305b --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-5rhg-f75j-57f8/GHSA-5rhg-f75j-57f8.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rhg-f75j-57f8", + "modified": "2024-02-01T06:31:05Z", + "published": "2024-02-01T06:31:05Z", + "aliases": [ + "CVE-2024-23941" + ], + "details": "Cross-site scripting vulnerability exists in Group Office prior to v6.6.182, prior to v6.7.64 and prior to v6.8.31, which may allow a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23941" + }, + { + "type": "WEB", + "url": "https://github.com/Intermesh/groupoffice/" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN63567545/" + }, + { + "type": "WEB", + "url": "https://www.group-office.com/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T04:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-c56q-fqmf-hg57/GHSA-c56q-fqmf-hg57.json b/advisories/unreviewed/2024/02/GHSA-c56q-fqmf-hg57/GHSA-c56q-fqmf-hg57.json new file mode 100644 index 00000000000..77dd79f078f --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-c56q-fqmf-hg57/GHSA-c56q-fqmf-hg57.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c56q-fqmf-hg57", + "modified": "2024-02-01T06:31:05Z", + "published": "2024-02-01T06:31:05Z", + "aliases": [ + "CVE-2023-7069" + ], + "details": "The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2023.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7069" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3027702%40advanced-iframe&new=3027702%40advanced-iframe&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2e32c51d-2d96-4545-956f-64f65c54b33b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T04:15:49Z" + } +} \ No newline at end of file