Publish Advisories

GHSA-2367-v666-24m6
GHSA-hrw3-f4qp-9h27
GHSA-m6q8-3vcx-vm5c
GHSA-q3p2-f3g7-w74p
GHSA-r2jx-292h-wx26
GHSA-598h-v73f-rx7f
GHSA-c84x-657q-q6vq
GHSA-h964-f4gx-gw3x
GHSA-jr8c-49mm-qhr4
This commit is contained in:
advisory-database[bot]
2024-08-26 06:32:07 +00:00
parent 794f628298
commit 6277a710f3
9 changed files with 167 additions and 6 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2367-v666-24m6",
"modified": "2024-08-06T12:30:32Z",
"modified": "2024-08-26T06:30:45Z",
"published": "2024-07-15T00:30:40Z",
"aliases": [
"CVE-2024-6732"
@@ -37,6 +37,10 @@
"type": "WEB",
"url": "https://reports-kunull.vercel.app/CVEs/2024/CVE-2024-6732"
},
{
"type": "WEB",
"url": "https://reports.kunull.net/CVEs/2024/CVE-2024-6732"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.271450"
@@ -48,6 +52,10 @@
{
"type": "WEB",
"url": "https://vuldb.com/?submit.374370"
},
{
"type": "WEB",
"url": "https://www.sourcecodester.com"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hrw3-f4qp-9h27",
"modified": "2024-08-06T12:30:32Z",
"modified": "2024-08-26T06:30:46Z",
"published": "2024-07-17T03:31:38Z",
"aliases": [
"CVE-2024-6802"
@@ -41,6 +41,14 @@
"type": "WEB",
"url": "https://reports-kunull.vercel.app/CVEs/CVE-2024-6802"
},
{
"type": "WEB",
"url": "https://reports.kunull.net/CVEs/2024/CVE-2024-6802"
},
{
"type": "WEB",
"url": "https://reports.kunull.net/CVEs/CVE-2024-6802"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.271704"
@@ -52,6 +60,10 @@
{
"type": "WEB",
"url": "https://vuldb.com/?submit.374797"
},
{
"type": "WEB",
"url": "https://www.sourcecodester.com"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m6q8-3vcx-vm5c",
"modified": "2024-08-06T12:30:32Z",
"modified": "2024-08-26T06:30:45Z",
"published": "2024-07-15T00:30:40Z",
"aliases": [
"CVE-2024-6731"
@@ -37,6 +37,10 @@
"type": "WEB",
"url": "https://reports-kunull.vercel.app/CVEs/2024/CVE-2024-6731"
},
{
"type": "WEB",
"url": "https://reports.kunull.net/CVEs/2024/CVE-2024-6731"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.271449"
@@ -48,6 +52,10 @@
{
"type": "WEB",
"url": "https://vuldb.com/?submit.374362"
},
{
"type": "WEB",
"url": "https://www.sourcecodester.com"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q3p2-f3g7-w74p",
"modified": "2024-08-06T12:30:32Z",
"modified": "2024-08-26T06:30:45Z",
"published": "2024-07-14T03:30:37Z",
"aliases": [
"CVE-2024-6729"
@@ -37,6 +37,10 @@
"type": "WEB",
"url": "https://reports-kunull.vercel.app/sourcecodester-advocate-Management-system-add-act"
},
{
"type": "WEB",
"url": "https://reports.kunull.net/CVEs/2024/CVE-2024-6729"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.271402"
@@ -48,6 +52,10 @@
{
"type": "WEB",
"url": "https://vuldb.com/?submit.373488"
},
{
"type": "WEB",
"url": "https://www.sourcecodester.com"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r2jx-292h-wx26",
"modified": "2024-08-06T12:30:32Z",
"modified": "2024-08-26T06:30:46Z",
"published": "2024-07-17T06:30:47Z",
"aliases": [
"CVE-2024-6807"
@@ -37,6 +37,10 @@
"type": "WEB",
"url": "https://reports-kunull.vercel.app/CVEs/2024/CVE-2024-6807"
},
{
"type": "WEB",
"url": "https://reports.kunull.net/CVEs/2024/CVE-2024-6807"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.271706"
@@ -48,6 +52,10 @@
{
"type": "WEB",
"url": "https://vuldb.com/?submit.374853"
},
{
"type": "WEB",
"url": "https://www.sourcecodester.com"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-598h-v73f-rx7f",
"modified": "2024-08-20T06:31:37Z",
"modified": "2024-08-26T06:30:46Z",
"published": "2024-08-20T06:31:37Z",
"aliases": [
"CVE-2024-43688"
@@ -22,6 +22,10 @@
"type": "WEB",
"url": "https://github.com/vixie/cron/commit/9cc8ab1087bb9ab861dd5595c41200683c9f6712"
},
{
"type": "WEB",
"url": "https://www.supernetworks.org/CVE-2024-43688/openbsd-cron-heap-underflow.txt"
},
{
"type": "WEB",
"url": "https://www.supernetworks.org/advisories/CVE-2024-43688-openbsd-cron-heap-underflow.txt"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c84x-657q-q6vq",
"modified": "2024-08-26T06:30:47Z",
"published": "2024-08-26T06:30:47Z",
"aliases": [
"CVE-2024-7313"
],
"details": "The Shield Security WordPress plugin before 20.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7313"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/83a1bdc6-098e-43d5-89e5-f4202ecd78a1"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-26T06:15:04Z"
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h964-f4gx-gw3x",
"modified": "2024-08-26T06:30:46Z",
"published": "2024-08-26T06:30:46Z",
"aliases": [
"CVE-2024-41996"
],
"details": "Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41996"
},
{
"type": "WEB",
"url": "https://dheatattack.gitlab.io/details"
},
{
"type": "WEB",
"url": "https://dheatattack.gitlab.io/faq"
},
{
"type": "WEB",
"url": "https://gist.github.com/c0r0n3r/abccc14d4d96c0442f3a77fa5ca255d1"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-26T06:15:04Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jr8c-49mm-qhr4",
"modified": "2024-08-26T06:30:46Z",
"published": "2024-08-26T06:30:46Z",
"aliases": [
"CVE-2024-6879"
],
"details": "The Quiz and Survey Master (QSM) WordPress plugin before 9.1.1 fails to validate and escape certain Quiz fields before displaying them on a page or post where the Quiz is embedded, which could allows contributor and above roles to perform Stored Cross-Site Scripting (XSS) attacks.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6879"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/4da0b318-03e7-409d-9b02-f108e4232c87"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-26T06:15:04Z"
}
}