From 62b9cf5822822f5900e013b836f6a9b1d151b888 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 23 Aug 2024 15:31:59 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-2qjw-rvh6-348q.json | 6 +- .../GHSA-h973-v697-qfgm.json | 6 +- .../GHSA-qggq-c955-hh78.json | 1 + .../GHSA-rqwp-r837-269c.json | 6 +- .../GHSA-2j45-xr49-x8qc.json | 11 ++-- .../GHSA-39rr-hfc3-8pcc.json | 9 ++- .../GHSA-5fvr-59fv-4jgf.json | 9 ++- .../GHSA-5j3v-wvv7-9rvc.json | 11 ++-- .../GHSA-9hrm-h2q9-qw2v.json | 9 ++- .../GHSA-fmmj-2f3w-98j5.json | 11 ++-- .../GHSA-grg4-p2px-v4hg.json | 11 ++-- .../GHSA-mhm9-743p-jfxq.json | 11 ++-- .../GHSA-mrf5-g9rq-vqv9.json | 6 +- .../GHSA-p8wp-3m3g-qg4j.json | 6 +- .../GHSA-q25c-28ww-34p7.json | 9 ++- .../GHSA-r79w-4gmj-3cfw.json | 9 ++- .../GHSA-v79c-wmw8-rqjf.json | 9 ++- .../GHSA-vcmx-3577-7jh3.json | 9 ++- .../GHSA-wx36-wgp2-fwpq.json | 9 ++- .../GHSA-x7rm-gp29-w8xw.json | 9 ++- .../GHSA-xpgc-r9hj-5jm2.json | 9 ++- .../GHSA-xxwq-5h7x-mm4x.json | 2 +- .../GHSA-338f-rfqj-8jxw.json | 38 +++++++++++ .../GHSA-3cj6-45x3-vrjj.json | 38 +++++++++++ .../GHSA-45rp-q25w-4426.json | 38 +++++++++++ .../GHSA-553w-hm5g-6ccq.json | 39 ++++++++++++ .../GHSA-5c96-24qg-f876.json | 38 +++++++++++ .../GHSA-5wvf-7fq8-m4w6.json | 9 ++- .../GHSA-6c2h-4vcm-x8p4.json | 38 +++++++++++ .../GHSA-75gr-j667-pp37.json | 63 +++++++++++++++++++ .../GHSA-7c66-8xr2-45gc.json | 38 +++++++++++ .../GHSA-9rwc-r28x-rhwh.json | 38 +++++++++++ .../GHSA-c7hp-v8hh-hvgp.json | 38 +++++++++++ .../GHSA-c9r7-wpw8-xc67.json | 39 ++++++++++++ .../GHSA-cq2c-35gp-j9qc.json | 6 +- .../GHSA-f8x5-fv5x-fcq5.json | 39 ++++++++++++ .../GHSA-fmxx-4w94-fc85.json | 38 +++++++++++ .../GHSA-h7p8-gjr9-rp7c.json | 38 +++++++++++ .../GHSA-j3cx-fj78-gw65.json | 39 ++++++++++++ .../GHSA-j9pj-4vv7-cpj9.json | 11 ++-- .../GHSA-jv3v-4vw7-mch5.json | 50 +++++++++++++++ .../GHSA-jvvm-gq28-8rgc.json | 9 ++- .../GHSA-q22q-2rrf-m27p.json | 2 +- .../GHSA-rpp5-g56w-xpgh.json | 38 +++++++++++ .../GHSA-rq5p-j687-h2vf.json | 11 ++-- .../GHSA-v25q-32rr-4cpj.json | 38 +++++++++++ .../GHSA-xh96-vq46-m9ww.json | 39 ++++++++++++ 47 files changed, 920 insertions(+), 70 deletions(-) create mode 100644 advisories/unreviewed/2024/08/GHSA-338f-rfqj-8jxw/GHSA-338f-rfqj-8jxw.json create mode 100644 advisories/unreviewed/2024/08/GHSA-3cj6-45x3-vrjj/GHSA-3cj6-45x3-vrjj.json create mode 100644 advisories/unreviewed/2024/08/GHSA-45rp-q25w-4426/GHSA-45rp-q25w-4426.json create mode 100644 advisories/unreviewed/2024/08/GHSA-553w-hm5g-6ccq/GHSA-553w-hm5g-6ccq.json create mode 100644 advisories/unreviewed/2024/08/GHSA-5c96-24qg-f876/GHSA-5c96-24qg-f876.json create mode 100644 advisories/unreviewed/2024/08/GHSA-6c2h-4vcm-x8p4/GHSA-6c2h-4vcm-x8p4.json create mode 100644 advisories/unreviewed/2024/08/GHSA-75gr-j667-pp37/GHSA-75gr-j667-pp37.json create mode 100644 advisories/unreviewed/2024/08/GHSA-7c66-8xr2-45gc/GHSA-7c66-8xr2-45gc.json create mode 100644 advisories/unreviewed/2024/08/GHSA-9rwc-r28x-rhwh/GHSA-9rwc-r28x-rhwh.json create mode 100644 advisories/unreviewed/2024/08/GHSA-c7hp-v8hh-hvgp/GHSA-c7hp-v8hh-hvgp.json create mode 100644 advisories/unreviewed/2024/08/GHSA-c9r7-wpw8-xc67/GHSA-c9r7-wpw8-xc67.json create mode 100644 advisories/unreviewed/2024/08/GHSA-f8x5-fv5x-fcq5/GHSA-f8x5-fv5x-fcq5.json create mode 100644 advisories/unreviewed/2024/08/GHSA-fmxx-4w94-fc85/GHSA-fmxx-4w94-fc85.json create mode 100644 advisories/unreviewed/2024/08/GHSA-h7p8-gjr9-rp7c/GHSA-h7p8-gjr9-rp7c.json create mode 100644 advisories/unreviewed/2024/08/GHSA-j3cx-fj78-gw65/GHSA-j3cx-fj78-gw65.json create mode 100644 advisories/unreviewed/2024/08/GHSA-jv3v-4vw7-mch5/GHSA-jv3v-4vw7-mch5.json create mode 100644 advisories/unreviewed/2024/08/GHSA-rpp5-g56w-xpgh/GHSA-rpp5-g56w-xpgh.json create mode 100644 advisories/unreviewed/2024/08/GHSA-v25q-32rr-4cpj/GHSA-v25q-32rr-4cpj.json create mode 100644 advisories/unreviewed/2024/08/GHSA-xh96-vq46-m9ww/GHSA-xh96-vq46-m9ww.json diff --git a/advisories/unreviewed/2023/06/GHSA-2qjw-rvh6-348q/GHSA-2qjw-rvh6-348q.json b/advisories/unreviewed/2023/06/GHSA-2qjw-rvh6-348q/GHSA-2qjw-rvh6-348q.json index c6fe5db5eb9..fafc079bcbc 100644 --- a/advisories/unreviewed/2023/06/GHSA-2qjw-rvh6-348q/GHSA-2qjw-rvh6-348q.json +++ b/advisories/unreviewed/2023/06/GHSA-2qjw-rvh6-348q/GHSA-2qjw-rvh6-348q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2qjw-rvh6-348q", - "modified": "2024-04-04T04:41:58Z", + "modified": "2024-08-23T15:30:32Z", "published": "2023-06-09T06:30:32Z", "aliases": [ "CVE-2023-2414" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://plugins.trac.wordpress.org/browser/meeting-scheduler-by-vcita/trunk/vcita-ajax-function.php#L88" }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/2933915/meeting-scheduler-by-vcita/trunk/vcita-ajax-function.php?contextall=1&old=2924763&old_path=%2Fmeeting-scheduler-by-vcita%2Ftrunk%2Fvcita-ajax-function.php" + }, { "type": "WEB", "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3c99aab5-a995-44ae-bc14-09f73e6b22c5?source=cve" diff --git a/advisories/unreviewed/2024/06/GHSA-h973-v697-qfgm/GHSA-h973-v697-qfgm.json b/advisories/unreviewed/2024/06/GHSA-h973-v697-qfgm/GHSA-h973-v697-qfgm.json index 31e91f0ddce..935be28e952 100644 --- a/advisories/unreviewed/2024/06/GHSA-h973-v697-qfgm/GHSA-h973-v697-qfgm.json +++ b/advisories/unreviewed/2024/06/GHSA-h973-v697-qfgm/GHSA-h973-v697-qfgm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h973-v697-qfgm", - "modified": "2024-06-09T06:30:39Z", + "modified": "2024-08-23T15:30:32Z", "published": "2024-06-09T06:30:39Z", "aliases": [ "CVE-2024-5774" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-qggq-c955-hh78/GHSA-qggq-c955-hh78.json b/advisories/unreviewed/2024/06/GHSA-qggq-c955-hh78/GHSA-qggq-c955-hh78.json index 3d393be7d39..7a443028037 100644 --- a/advisories/unreviewed/2024/06/GHSA-qggq-c955-hh78/GHSA-qggq-c955-hh78.json +++ b/advisories/unreviewed/2024/06/GHSA-qggq-c955-hh78/GHSA-qggq-c955-hh78.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-121" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/06/GHSA-rqwp-r837-269c/GHSA-rqwp-r837-269c.json b/advisories/unreviewed/2024/06/GHSA-rqwp-r837-269c/GHSA-rqwp-r837-269c.json index 6e204d90a1c..f1664a208b6 100644 --- a/advisories/unreviewed/2024/06/GHSA-rqwp-r837-269c/GHSA-rqwp-r837-269c.json +++ b/advisories/unreviewed/2024/06/GHSA-rqwp-r837-269c/GHSA-rqwp-r837-269c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rqwp-r837-269c", - "modified": "2024-06-09T09:30:34Z", + "modified": "2024-08-23T15:30:32Z", "published": "2024-06-09T09:30:34Z", "aliases": [ "CVE-2024-5775" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/07/GHSA-2j45-xr49-x8qc/GHSA-2j45-xr49-x8qc.json b/advisories/unreviewed/2024/07/GHSA-2j45-xr49-x8qc/GHSA-2j45-xr49-x8qc.json index 579d85c78cc..b1987a33cb0 100644 --- a/advisories/unreviewed/2024/07/GHSA-2j45-xr49-x8qc/GHSA-2j45-xr49-x8qc.json +++ b/advisories/unreviewed/2024/07/GHSA-2j45-xr49-x8qc/GHSA-2j45-xr49-x8qc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2j45-xr49-x8qc", - "modified": "2024-07-30T09:32:02Z", + "modified": "2024-08-23T15:30:33Z", "published": "2024-07-30T09:32:02Z", "aliases": [ "CVE-2024-42140" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: kexec: Avoid deadlock in kexec crash path\n\nIf the kexec crash code is called in the interrupt context, the\nmachine_kexec_mask_interrupts() function will trigger a deadlock while\ntrying to acquire the irqdesc spinlock and then deactivate irqchip in\nirq_set_irqchip_state() function.\n\nUnlike arm64, riscv only requires irq_eoi handler to complete EOI and\nkeeping irq_set_irqchip_state() will only leave this possible deadlock\nwithout any use. So we simply remove it.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:05Z" diff --git a/advisories/unreviewed/2024/07/GHSA-39rr-hfc3-8pcc/GHSA-39rr-hfc3-8pcc.json b/advisories/unreviewed/2024/07/GHSA-39rr-hfc3-8pcc/GHSA-39rr-hfc3-8pcc.json index dc48be8eedc..6d001fd2c49 100644 --- a/advisories/unreviewed/2024/07/GHSA-39rr-hfc3-8pcc/GHSA-39rr-hfc3-8pcc.json +++ b/advisories/unreviewed/2024/07/GHSA-39rr-hfc3-8pcc/GHSA-39rr-hfc3-8pcc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-39rr-hfc3-8pcc", - "modified": "2024-07-30T03:30:53Z", + "modified": "2024-08-23T15:30:33Z", "published": "2024-07-30T00:34:27Z", "aliases": [ "CVE-2024-40832" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. An app may be able to view a contact's phone number in system logs.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:14Z" diff --git a/advisories/unreviewed/2024/07/GHSA-5fvr-59fv-4jgf/GHSA-5fvr-59fv-4jgf.json b/advisories/unreviewed/2024/07/GHSA-5fvr-59fv-4jgf/GHSA-5fvr-59fv-4jgf.json index f71e8767ef8..8f880133c1e 100644 --- a/advisories/unreviewed/2024/07/GHSA-5fvr-59fv-4jgf/GHSA-5fvr-59fv-4jgf.json +++ b/advisories/unreviewed/2024/07/GHSA-5fvr-59fv-4jgf/GHSA-5fvr-59fv-4jgf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5fvr-59fv-4jgf", - "modified": "2024-07-30T03:30:53Z", + "modified": "2024-08-23T15:30:33Z", "published": "2024-07-30T00:34:27Z", "aliases": [ "CVE-2024-40827" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6, macOS Monterey 12.7.6, macOS Ventura 13.6.8. An app may be able to overwrite arbitrary files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:14Z" diff --git a/advisories/unreviewed/2024/07/GHSA-5j3v-wvv7-9rvc/GHSA-5j3v-wvv7-9rvc.json b/advisories/unreviewed/2024/07/GHSA-5j3v-wvv7-9rvc/GHSA-5j3v-wvv7-9rvc.json index 1b936a05431..d985254812c 100644 --- a/advisories/unreviewed/2024/07/GHSA-5j3v-wvv7-9rvc/GHSA-5j3v-wvv7-9rvc.json +++ b/advisories/unreviewed/2024/07/GHSA-5j3v-wvv7-9rvc/GHSA-5j3v-wvv7-9rvc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5j3v-wvv7-9rvc", - "modified": "2024-07-30T09:31:53Z", + "modified": "2024-08-23T15:30:33Z", "published": "2024-07-30T09:31:53Z", "aliases": [ "CVE-2024-42123" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix double free err_addr pointer warnings\n\nIn amdgpu_umc_bad_page_polling_timeout, the amdgpu_umc_handle_bad_pages\nwill be run many times so that double free err_addr in some special case.\nSo set the err_addr to NULL to avoid the warnings.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-415" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-9hrm-h2q9-qw2v/GHSA-9hrm-h2q9-qw2v.json b/advisories/unreviewed/2024/07/GHSA-9hrm-h2q9-qw2v/GHSA-9hrm-h2q9-qw2v.json index a7d722e8282..6ca997a8408 100644 --- a/advisories/unreviewed/2024/07/GHSA-9hrm-h2q9-qw2v/GHSA-9hrm-h2q9-qw2v.json +++ b/advisories/unreviewed/2024/07/GHSA-9hrm-h2q9-qw2v/GHSA-9hrm-h2q9-qw2v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9hrm-h2q9-qw2v", - "modified": "2024-07-30T03:30:52Z", + "modified": "2024-08-23T15:30:33Z", "published": "2024-07-30T00:34:27Z", "aliases": [ "CVE-2024-40796" ], "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.6, iOS 16.7.9 and iPadOS 16.7.9, macOS Monterey 12.7.6, macOS Ventura 13.6.8. Private browsing may leak some browsing history.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-fmmj-2f3w-98j5/GHSA-fmmj-2f3w-98j5.json b/advisories/unreviewed/2024/07/GHSA-fmmj-2f3w-98j5/GHSA-fmmj-2f3w-98j5.json index 869bb226d1e..ef09ed16556 100644 --- a/advisories/unreviewed/2024/07/GHSA-fmmj-2f3w-98j5/GHSA-fmmj-2f3w-98j5.json +++ b/advisories/unreviewed/2024/07/GHSA-fmmj-2f3w-98j5/GHSA-fmmj-2f3w-98j5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fmmj-2f3w-98j5", - "modified": "2024-07-30T03:30:52Z", + "modified": "2024-08-23T15:30:33Z", "published": "2024-07-30T00:34:27Z", "aliases": [ "CVE-2024-40803" ], "details": "A type confusion issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6, macOS Monterey 12.7.6, macOS Ventura 13.6.8. An attacker may be able to cause unexpected app termination.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-843" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-grg4-p2px-v4hg/GHSA-grg4-p2px-v4hg.json b/advisories/unreviewed/2024/07/GHSA-grg4-p2px-v4hg/GHSA-grg4-p2px-v4hg.json index 65336a019a3..f48b3726064 100644 --- a/advisories/unreviewed/2024/07/GHSA-grg4-p2px-v4hg/GHSA-grg4-p2px-v4hg.json +++ b/advisories/unreviewed/2024/07/GHSA-grg4-p2px-v4hg/GHSA-grg4-p2px-v4hg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-grg4-p2px-v4hg", - "modified": "2024-07-30T15:31:28Z", + "modified": "2024-08-23T15:30:33Z", "published": "2024-07-30T15:31:28Z", "aliases": [ "CVE-2024-23091" ], "details": "Weak password hashing using MD5 in funzioni.php in HotelDruid before 1.32 allows an attacker to obtain plaintext passwords from hash values.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-916" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T14:15:02Z" diff --git a/advisories/unreviewed/2024/07/GHSA-mhm9-743p-jfxq/GHSA-mhm9-743p-jfxq.json b/advisories/unreviewed/2024/07/GHSA-mhm9-743p-jfxq/GHSA-mhm9-743p-jfxq.json index c10f4f8e770..df690043e63 100644 --- a/advisories/unreviewed/2024/07/GHSA-mhm9-743p-jfxq/GHSA-mhm9-743p-jfxq.json +++ b/advisories/unreviewed/2024/07/GHSA-mhm9-743p-jfxq/GHSA-mhm9-743p-jfxq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mhm9-743p-jfxq", - "modified": "2024-07-30T03:30:52Z", + "modified": "2024-08-23T15:30:33Z", "published": "2024-07-30T00:34:27Z", "aliases": [ "CVE-2024-40799" ], "details": "An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, macOS Ventura 13.6.8, macOS Monterey 12.7.6, iOS 17.6 and iPadOS 17.6, watchOS 10.6, tvOS 17.6, visionOS 1.3, macOS Sonoma 14.6. Processing a maliciously crafted file may lead to unexpected app termination.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -85,9 +88,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-mrf5-g9rq-vqv9/GHSA-mrf5-g9rq-vqv9.json b/advisories/unreviewed/2024/07/GHSA-mrf5-g9rq-vqv9/GHSA-mrf5-g9rq-vqv9.json index ad9f4ce8f72..719c5fd9c34 100644 --- a/advisories/unreviewed/2024/07/GHSA-mrf5-g9rq-vqv9/GHSA-mrf5-g9rq-vqv9.json +++ b/advisories/unreviewed/2024/07/GHSA-mrf5-g9rq-vqv9/GHSA-mrf5-g9rq-vqv9.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mrf5-g9rq-vqv9", - "modified": "2024-07-30T12:31:18Z", + "modified": "2024-08-23T15:30:33Z", "published": "2024-07-30T12:31:18Z", "aliases": [ "CVE-2024-7127" ], "details": "Improper Neutralization of Input During Web Page Generation vulnerability in Stackposts Social Marketing Tool allows Cross-site Scripting (XSS) attack. By submitting the payload in the username during registration, it can be executed later in the application panel. This could lead to the unauthorised acquisition of information (e.g. cookies from a logged-in user). After multiple attempts to contact the vendor we did not receive any answer. Our team has confirmed the existence of this vulnerability. We suppose this issue affects Social Marketing Tool in all versions.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:D/RE:L/U:Green" diff --git a/advisories/unreviewed/2024/07/GHSA-p8wp-3m3g-qg4j/GHSA-p8wp-3m3g-qg4j.json b/advisories/unreviewed/2024/07/GHSA-p8wp-3m3g-qg4j/GHSA-p8wp-3m3g-qg4j.json index 73d5f84eead..7b348e0e1c5 100644 --- a/advisories/unreviewed/2024/07/GHSA-p8wp-3m3g-qg4j/GHSA-p8wp-3m3g-qg4j.json +++ b/advisories/unreviewed/2024/07/GHSA-p8wp-3m3g-qg4j/GHSA-p8wp-3m3g-qg4j.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p8wp-3m3g-qg4j", - "modified": "2024-07-30T15:31:28Z", + "modified": "2024-08-23T15:30:33Z", "published": "2024-07-30T15:31:28Z", "aliases": [ "CVE-2024-6699" ], "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mikafon Electronic Inc. Mikafon MA7 allows SQL Injection.This issue affects Mikafon MA7: from v3.0 before v3.1.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:L/U:X" diff --git a/advisories/unreviewed/2024/07/GHSA-q25c-28ww-34p7/GHSA-q25c-28ww-34p7.json b/advisories/unreviewed/2024/07/GHSA-q25c-28ww-34p7/GHSA-q25c-28ww-34p7.json index 521da34afa6..5b39a2b3cd7 100644 --- a/advisories/unreviewed/2024/07/GHSA-q25c-28ww-34p7/GHSA-q25c-28ww-34p7.json +++ b/advisories/unreviewed/2024/07/GHSA-q25c-28ww-34p7/GHSA-q25c-28ww-34p7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q25c-28ww-34p7", - "modified": "2024-07-30T03:30:52Z", + "modified": "2024-08-23T15:30:33Z", "published": "2024-07-30T00:34:27Z", "aliases": [ "CVE-2024-40804" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. A malicious application may be able to access private information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-r79w-4gmj-3cfw/GHSA-r79w-4gmj-3cfw.json b/advisories/unreviewed/2024/07/GHSA-r79w-4gmj-3cfw/GHSA-r79w-4gmj-3cfw.json index 6a685b81709..303cfe92823 100644 --- a/advisories/unreviewed/2024/07/GHSA-r79w-4gmj-3cfw/GHSA-r79w-4gmj-3cfw.json +++ b/advisories/unreviewed/2024/07/GHSA-r79w-4gmj-3cfw/GHSA-r79w-4gmj-3cfw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r79w-4gmj-3cfw", - "modified": "2024-07-30T03:30:53Z", + "modified": "2024-08-23T15:30:33Z", "published": "2024-07-30T00:34:27Z", "aliases": [ "CVE-2024-40833" ], "details": "A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6, iOS 16.7.9 and iPadOS 16.7.9, macOS Monterey 12.7.6, macOS Ventura 13.6.8. A shortcut may be able to use sensitive data with certain actions without prompting the user.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:14Z" diff --git a/advisories/unreviewed/2024/07/GHSA-v79c-wmw8-rqjf/GHSA-v79c-wmw8-rqjf.json b/advisories/unreviewed/2024/07/GHSA-v79c-wmw8-rqjf/GHSA-v79c-wmw8-rqjf.json index c94cd7bc219..209eb5518f9 100644 --- a/advisories/unreviewed/2024/07/GHSA-v79c-wmw8-rqjf/GHSA-v79c-wmw8-rqjf.json +++ b/advisories/unreviewed/2024/07/GHSA-v79c-wmw8-rqjf/GHSA-v79c-wmw8-rqjf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v79c-wmw8-rqjf", - "modified": "2024-07-30T03:30:52Z", + "modified": "2024-08-23T15:30:33Z", "published": "2024-07-30T00:34:27Z", "aliases": [ "CVE-2024-40795" ], "details": "This issue was addressed with improved data protection. This issue is fixed in watchOS 10.6, macOS Sonoma 14.6, iOS 17.6 and iPadOS 17.6, tvOS 17.6. An app may be able to read sensitive location information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-vcmx-3577-7jh3/GHSA-vcmx-3577-7jh3.json b/advisories/unreviewed/2024/07/GHSA-vcmx-3577-7jh3/GHSA-vcmx-3577-7jh3.json index 17d1bb4d00c..c96f1df1603 100644 --- a/advisories/unreviewed/2024/07/GHSA-vcmx-3577-7jh3/GHSA-vcmx-3577-7jh3.json +++ b/advisories/unreviewed/2024/07/GHSA-vcmx-3577-7jh3/GHSA-vcmx-3577-7jh3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vcmx-3577-7jh3", - "modified": "2024-07-30T03:30:52Z", + "modified": "2024-08-23T15:30:33Z", "published": "2024-07-30T00:34:27Z", "aliases": [ "CVE-2024-40794" ], "details": "This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.6, iOS 17.6 and iPadOS 17.6, Safari 17.6. Private Browsing tabs may be accessed without authentication.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-wx36-wgp2-fwpq/GHSA-wx36-wgp2-fwpq.json b/advisories/unreviewed/2024/07/GHSA-wx36-wgp2-fwpq/GHSA-wx36-wgp2-fwpq.json index 8ebb735f422..24977f378d2 100644 --- a/advisories/unreviewed/2024/07/GHSA-wx36-wgp2-fwpq/GHSA-wx36-wgp2-fwpq.json +++ b/advisories/unreviewed/2024/07/GHSA-wx36-wgp2-fwpq/GHSA-wx36-wgp2-fwpq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wx36-wgp2-fwpq", - "modified": "2024-07-30T03:30:53Z", + "modified": "2024-08-23T15:30:33Z", "published": "2024-07-30T00:34:27Z", "aliases": [ "CVE-2024-40834" ], "details": "This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sonoma 14.6, macOS Monterey 12.7.6, macOS Ventura 13.6.8. A shortcut may be able to bypass sensitive Shortcuts app settings.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:14Z" diff --git a/advisories/unreviewed/2024/07/GHSA-x7rm-gp29-w8xw/GHSA-x7rm-gp29-w8xw.json b/advisories/unreviewed/2024/07/GHSA-x7rm-gp29-w8xw/GHSA-x7rm-gp29-w8xw.json index c5b41adb89e..0458e935a70 100644 --- a/advisories/unreviewed/2024/07/GHSA-x7rm-gp29-w8xw/GHSA-x7rm-gp29-w8xw.json +++ b/advisories/unreviewed/2024/07/GHSA-x7rm-gp29-w8xw/GHSA-x7rm-gp29-w8xw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x7rm-gp29-w8xw", - "modified": "2024-07-30T03:30:52Z", + "modified": "2024-08-23T15:30:33Z", "published": "2024-07-30T00:34:27Z", "aliases": [ "CVE-2024-40798" ], "details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sonoma 14.6, iOS 16.7.9 and iPadOS 16.7.9, macOS Monterey 12.7.6, macOS Ventura 13.6.8. An app may be able to read Safari's browsing history.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-xpgc-r9hj-5jm2/GHSA-xpgc-r9hj-5jm2.json b/advisories/unreviewed/2024/07/GHSA-xpgc-r9hj-5jm2/GHSA-xpgc-r9hj-5jm2.json index 86e02eb6fbd..c482d422ded 100644 --- a/advisories/unreviewed/2024/07/GHSA-xpgc-r9hj-5jm2/GHSA-xpgc-r9hj-5jm2.json +++ b/advisories/unreviewed/2024/07/GHSA-xpgc-r9hj-5jm2/GHSA-xpgc-r9hj-5jm2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xpgc-r9hj-5jm2", - "modified": "2024-07-30T03:30:53Z", + "modified": "2024-08-23T15:30:33Z", "published": "2024-07-30T00:34:27Z", "aliases": [ "CVE-2024-40835" ], "details": "A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, macOS Ventura 13.6.8, macOS Monterey 12.7.6, iOS 17.6 and iPadOS 17.6, watchOS 10.6, macOS Sonoma 14.6. A shortcut may be able to use sensitive data with certain actions without prompting the user.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -71,7 +74,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:14Z" diff --git a/advisories/unreviewed/2024/07/GHSA-xxwq-5h7x-mm4x/GHSA-xxwq-5h7x-mm4x.json b/advisories/unreviewed/2024/07/GHSA-xxwq-5h7x-mm4x/GHSA-xxwq-5h7x-mm4x.json index 8b127a5b060..8156990f907 100644 --- a/advisories/unreviewed/2024/07/GHSA-xxwq-5h7x-mm4x/GHSA-xxwq-5h7x-mm4x.json +++ b/advisories/unreviewed/2024/07/GHSA-xxwq-5h7x-mm4x/GHSA-xxwq-5h7x-mm4x.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-338f-rfqj-8jxw/GHSA-338f-rfqj-8jxw.json b/advisories/unreviewed/2024/08/GHSA-338f-rfqj-8jxw/GHSA-338f-rfqj-8jxw.json new file mode 100644 index 00000000000..141741a5755 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-338f-rfqj-8jxw/GHSA-338f-rfqj-8jxw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-338f-rfqj-8jxw", + "modified": "2024-08-23T15:30:34Z", + "published": "2024-08-23T15:30:34Z", + "aliases": [ + "CVE-2024-36516" + ], + "details": "Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard.\nNote: This vulnerability is different from another vulnerability (CVE-2024-36515), both of which have affected ADAudit Plus' dashboard.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36516" + }, + { + "type": "WEB", + "url": "https://www.manageengine.com/products/active-directory-audit/cve-2024-36516.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3cj6-45x3-vrjj/GHSA-3cj6-45x3-vrjj.json b/advisories/unreviewed/2024/08/GHSA-3cj6-45x3-vrjj/GHSA-3cj6-45x3-vrjj.json new file mode 100644 index 00000000000..5648b2c04f9 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3cj6-45x3-vrjj/GHSA-3cj6-45x3-vrjj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3cj6-45x3-vrjj", + "modified": "2024-08-23T15:30:34Z", + "published": "2024-08-23T15:30:34Z", + "aliases": [ + "CVE-2024-5466" + ], + "details": "Zohocorp ManageEngine OpManager and Remote Monitoring and Management versions 128329 and below are vulnerable to the authenticated remote code execution in the deploy agent option.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5466" + }, + { + "type": "WEB", + "url": "https://www.manageengine.com/itom/advisory/cve-2024-5466.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-45rp-q25w-4426/GHSA-45rp-q25w-4426.json b/advisories/unreviewed/2024/08/GHSA-45rp-q25w-4426/GHSA-45rp-q25w-4426.json new file mode 100644 index 00000000000..8463fd9300b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-45rp-q25w-4426/GHSA-45rp-q25w-4426.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45rp-q25w-4426", + "modified": "2024-08-23T15:30:34Z", + "published": "2024-08-23T15:30:34Z", + "aliases": [ + "CVE-2024-8113" + ], + "details": "Stored XSS in organizer and event settings of pretix up to 2024.7.0 allows malicious event organizers to inject HTML tags into e-mail previews on settings page. The default Content Security Policy of pretix prevents execution of attacker-provided scripts, making exploitation unlikely. However, combined with a CSP bypass (which is not currently known) the vulnerability could be used to impersonate other organizers or staff users.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:X/RE:L/U:Green" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8113" + }, + { + "type": "WEB", + "url": "https://pretix.eu/about/en/blog/20240823-release-2024-7-1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-553w-hm5g-6ccq/GHSA-553w-hm5g-6ccq.json b/advisories/unreviewed/2024/08/GHSA-553w-hm5g-6ccq/GHSA-553w-hm5g-6ccq.json new file mode 100644 index 00000000000..972366abd93 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-553w-hm5g-6ccq/GHSA-553w-hm5g-6ccq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-553w-hm5g-6ccq", + "modified": "2024-08-23T15:30:34Z", + "published": "2024-08-23T15:30:34Z", + "aliases": [ + "CVE-2024-42766" + ], + "details": "Kashipara Bus Ticket Reservation System v1.0 0 is vulnerable to Incorrect Access Control via /deleteTicket.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42766" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Bus%20Ticket%20Reservation%20System%20v1.0/Broken%20Access%20Control%20-%20Delete%20Bookings.pdf" + }, + { + "type": "WEB", + "url": "https://www.kashipara.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5c96-24qg-f876/GHSA-5c96-24qg-f876.json b/advisories/unreviewed/2024/08/GHSA-5c96-24qg-f876/GHSA-5c96-24qg-f876.json new file mode 100644 index 00000000000..b885dae00da --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5c96-24qg-f876/GHSA-5c96-24qg-f876.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c96-24qg-f876", + "modified": "2024-08-23T15:30:34Z", + "published": "2024-08-23T15:30:34Z", + "aliases": [ + "CVE-2024-38869" + ], + "details": "An Stored Cross-site Scripting vulnerability affects Zohocorp ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus.This issue affects ServiceDesk Plus versions: through 14810; ServiceDesk Plus MSP: through 14800; SupportCenter Plus: through 14800.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38869" + }, + { + "type": "WEB", + "url": "https://www.manageengine.com/products/service-desk/CVE-2024-41150.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5wvf-7fq8-m4w6/GHSA-5wvf-7fq8-m4w6.json b/advisories/unreviewed/2024/08/GHSA-5wvf-7fq8-m4w6/GHSA-5wvf-7fq8-m4w6.json index ce9d5b8cf2f..8b68e4e2d90 100644 --- a/advisories/unreviewed/2024/08/GHSA-5wvf-7fq8-m4w6/GHSA-5wvf-7fq8-m4w6.json +++ b/advisories/unreviewed/2024/08/GHSA-5wvf-7fq8-m4w6/GHSA-5wvf-7fq8-m4w6.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5wvf-7fq8-m4w6", - "modified": "2024-08-07T15:30:41Z", + "modified": "2024-08-23T15:30:33Z", "published": "2024-08-07T12:31:28Z", "aliases": [ "CVE-2024-7266" ], "details": "Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to list all users in the system, including those from other organizations. This issue affects EZD RP: from 15 before 15.84, from 16 before 16.15, from 17 before 17.2.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:A/V:D/RE:L/U:Green" @@ -36,7 +40,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-286" + "CWE-286", + "CWE-863" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-6c2h-4vcm-x8p4/GHSA-6c2h-4vcm-x8p4.json b/advisories/unreviewed/2024/08/GHSA-6c2h-4vcm-x8p4/GHSA-6c2h-4vcm-x8p4.json new file mode 100644 index 00000000000..fb16f178a97 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6c2h-4vcm-x8p4/GHSA-6c2h-4vcm-x8p4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6c2h-4vcm-x8p4", + "modified": "2024-08-23T15:30:34Z", + "published": "2024-08-23T15:30:34Z", + "aliases": [ + "CVE-2024-41150" + ], + "details": "An Stored Cross-site Scripting vulnerability in request module affects Zohocorp ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus.This issue affects ServiceDesk Plus versions: through 14810; ServiceDesk Plus MSP: through 14800; SupportCenter Plus: through 14800.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41150" + }, + { + "type": "WEB", + "url": "https://www.manageengine.com/products/service-desk/CVE-2024-41150.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-75gr-j667-pp37/GHSA-75gr-j667-pp37.json b/advisories/unreviewed/2024/08/GHSA-75gr-j667-pp37/GHSA-75gr-j667-pp37.json new file mode 100644 index 00000000000..8b592d1a028 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-75gr-j667-pp37/GHSA-75gr-j667-pp37.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75gr-j667-pp37", + "modified": "2024-08-23T15:30:34Z", + "published": "2024-08-23T15:30:34Z", + "aliases": [ + "CVE-2024-43883" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: vhci-hcd: Do not drop references before new references are gained\n\nAt a few places the driver carries stale pointers\nto references that can still be used. Make sure that does not happen.\nThis strictly speaking closes ZDI-CAN-22273, though there may be\nsimilar races in the driver.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43883" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/128e82e41cf7d74a562726c1587d9d2ede1a0a37" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4dacdb9720aaab10b6be121eae55820174d97174" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/585e6bc7d0a9bf73a8be3d3fb34e86b90cc61a14" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5a3c473b28ae1c1f7c4dc129e30cb19ae6e96f89" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9c3746ce8d8fcb3a2405644fc0eec7fc5312de80" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/afdcfd3d6fcdeca2735ca8d994c5f2d24a368f0a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c3d0857b7fc2c49f68f89128a5440176089a8f54" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e8c1e606dab8c56cf074b43b98d0805de7322ba2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T13:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7c66-8xr2-45gc/GHSA-7c66-8xr2-45gc.json b/advisories/unreviewed/2024/08/GHSA-7c66-8xr2-45gc/GHSA-7c66-8xr2-45gc.json new file mode 100644 index 00000000000..40710251cb0 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7c66-8xr2-45gc/GHSA-7c66-8xr2-45gc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7c66-8xr2-45gc", + "modified": "2024-08-23T15:30:34Z", + "published": "2024-08-23T15:30:34Z", + "aliases": [ + "CVE-2024-36514" + ], + "details": "Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in file summary option.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36514" + }, + { + "type": "WEB", + "url": "https://www.manageengine.com/products/active-directory-audit/cve-2024-36514.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9rwc-r28x-rhwh/GHSA-9rwc-r28x-rhwh.json b/advisories/unreviewed/2024/08/GHSA-9rwc-r28x-rhwh/GHSA-9rwc-r28x-rhwh.json new file mode 100644 index 00000000000..a0067d51243 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9rwc-r28x-rhwh/GHSA-9rwc-r28x-rhwh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rwc-r28x-rhwh", + "modified": "2024-08-23T15:30:34Z", + "published": "2024-08-23T15:30:34Z", + "aliases": [ + "CVE-2024-5490" + ], + "details": "Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in aggregate reports option.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5490" + }, + { + "type": "WEB", + "url": "https://www.manageengine.com/products/active-directory-audit/cve-2024-5490.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c7hp-v8hh-hvgp/GHSA-c7hp-v8hh-hvgp.json b/advisories/unreviewed/2024/08/GHSA-c7hp-v8hh-hvgp/GHSA-c7hp-v8hh-hvgp.json new file mode 100644 index 00000000000..46a8de9d668 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c7hp-v8hh-hvgp/GHSA-c7hp-v8hh-hvgp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7hp-v8hh-hvgp", + "modified": "2024-08-23T15:30:34Z", + "published": "2024-08-23T15:30:34Z", + "aliases": [ + "CVE-2024-5556" + ], + "details": "Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in reports module.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5556" + }, + { + "type": "WEB", + "url": "https://www.manageengine.com/products/active-directory-audit/cve-2024-5556.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c9r7-wpw8-xc67/GHSA-c9r7-wpw8-xc67.json b/advisories/unreviewed/2024/08/GHSA-c9r7-wpw8-xc67/GHSA-c9r7-wpw8-xc67.json new file mode 100644 index 00000000000..d20b949c293 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c9r7-wpw8-xc67/GHSA-c9r7-wpw8-xc67.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9r7-wpw8-xc67", + "modified": "2024-08-23T15:30:34Z", + "published": "2024-08-23T15:30:34Z", + "aliases": [ + "CVE-2024-42915" + ], + "details": "A host header injection vulnerability in Staff Appraisal System v1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This will allow attackers to arbitrarily reset other users' passwords and compromise their accounts.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42915" + }, + { + "type": "WEB", + "url": "https://github.com/debashish-choudhury/staff-appraisal-system" + }, + { + "type": "WEB", + "url": "https://github.com/soursec/CVEs/tree/main/CVE-2024-42915" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cq2c-35gp-j9qc/GHSA-cq2c-35gp-j9qc.json b/advisories/unreviewed/2024/08/GHSA-cq2c-35gp-j9qc/GHSA-cq2c-35gp-j9qc.json index 8b590762e95..5980403a011 100644 --- a/advisories/unreviewed/2024/08/GHSA-cq2c-35gp-j9qc/GHSA-cq2c-35gp-j9qc.json +++ b/advisories/unreviewed/2024/08/GHSA-cq2c-35gp-j9qc/GHSA-cq2c-35gp-j9qc.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cq2c-35gp-j9qc", - "modified": "2024-08-07T15:30:41Z", + "modified": "2024-08-23T15:30:33Z", "published": "2024-08-07T12:31:28Z", "aliases": [ "CVE-2024-7267" ], "details": "Exposure of Sensitive Information vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to retrieve information about IP infrastructure and credentials. This issue affects EZD RP all versions before 19.6", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:A/V:D/RE:L/U:Green" diff --git a/advisories/unreviewed/2024/08/GHSA-f8x5-fv5x-fcq5/GHSA-f8x5-fv5x-fcq5.json b/advisories/unreviewed/2024/08/GHSA-f8x5-fv5x-fcq5/GHSA-f8x5-fv5x-fcq5.json new file mode 100644 index 00000000000..4535aeff3cb --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f8x5-fv5x-fcq5/GHSA-f8x5-fv5x-fcq5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8x5-fv5x-fcq5", + "modified": "2024-08-23T15:30:34Z", + "published": "2024-08-23T15:30:34Z", + "aliases": [ + "CVE-2024-42764" + ], + "details": "Kashipara Bus Ticket Reservation System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via /deleteTicket.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42764" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Bus%20Ticket%20Reservation%20System%20v1.0/CSRF.pdf" + }, + { + "type": "WEB", + "url": "https://www.kashipara.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fmxx-4w94-fc85/GHSA-fmxx-4w94-fc85.json b/advisories/unreviewed/2024/08/GHSA-fmxx-4w94-fc85/GHSA-fmxx-4w94-fc85.json new file mode 100644 index 00000000000..b5fcb0d1d6d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fmxx-4w94-fc85/GHSA-fmxx-4w94-fc85.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmxx-4w94-fc85", + "modified": "2024-08-23T15:30:34Z", + "published": "2024-08-23T15:30:34Z", + "aliases": [ + "CVE-2024-5467" + ], + "details": "Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in account lockout report.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5467" + }, + { + "type": "WEB", + "url": "https://www.manageengine.com/products/active-directory-audit/cve-2024-5467.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-h7p8-gjr9-rp7c/GHSA-h7p8-gjr9-rp7c.json b/advisories/unreviewed/2024/08/GHSA-h7p8-gjr9-rp7c/GHSA-h7p8-gjr9-rp7c.json new file mode 100644 index 00000000000..33da2068716 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-h7p8-gjr9-rp7c/GHSA-h7p8-gjr9-rp7c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h7p8-gjr9-rp7c", + "modified": "2024-08-23T15:30:34Z", + "published": "2024-08-23T15:30:34Z", + "aliases": [ + "CVE-2024-36515" + ], + "details": "Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard.\nNote: This vulnerability is different from another vulnerability (CVE-2024-36516), both of which have affected ADAudit Plus' dashboard.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36515" + }, + { + "type": "WEB", + "url": "https://www.manageengine.com/products/active-directory-audit/cve-2024-36515.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j3cx-fj78-gw65/GHSA-j3cx-fj78-gw65.json b/advisories/unreviewed/2024/08/GHSA-j3cx-fj78-gw65/GHSA-j3cx-fj78-gw65.json new file mode 100644 index 00000000000..d2bd6b113e8 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j3cx-fj78-gw65/GHSA-j3cx-fj78-gw65.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3cx-fj78-gw65", + "modified": "2024-08-23T15:30:34Z", + "published": "2024-08-23T15:30:34Z", + "aliases": [ + "CVE-2024-42765" + ], + "details": "A SQL injection vulnerability in \"/login.php\" of the Kashipara Bus Ticket Reservation System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the \"email\" or \"password\" Login page parameters.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42765" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Bus%20Ticket%20Reservation%20System%20v1.0/SQL%20Injection%20-%20Login.pdf" + }, + { + "type": "WEB", + "url": "https://www.kashipara.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j9pj-4vv7-cpj9/GHSA-j9pj-4vv7-cpj9.json b/advisories/unreviewed/2024/08/GHSA-j9pj-4vv7-cpj9/GHSA-j9pj-4vv7-cpj9.json index be72808c76a..d4ab7513f8a 100644 --- a/advisories/unreviewed/2024/08/GHSA-j9pj-4vv7-cpj9/GHSA-j9pj-4vv7-cpj9.json +++ b/advisories/unreviewed/2024/08/GHSA-j9pj-4vv7-cpj9/GHSA-j9pj-4vv7-cpj9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j9pj-4vv7-cpj9", - "modified": "2024-08-22T21:31:29Z", + "modified": "2024-08-23T15:30:34Z", "published": "2024-08-22T21:31:29Z", "aliases": [ "CVE-2024-42762" ], "details": "A Stored Cross Site Scripting (XSS) vulnerability was found in \"/history.php\" in Kashipara Bus Ticket Reservation System v1.0, which allows remote attackers to execute arbitrary code via the Name, Phone, and Email parameter fields.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-22T21:15:17Z" diff --git a/advisories/unreviewed/2024/08/GHSA-jv3v-4vw7-mch5/GHSA-jv3v-4vw7-mch5.json b/advisories/unreviewed/2024/08/GHSA-jv3v-4vw7-mch5/GHSA-jv3v-4vw7-mch5.json new file mode 100644 index 00000000000..d7c28704f26 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jv3v-4vw7-mch5/GHSA-jv3v-4vw7-mch5.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jv3v-4vw7-mch5", + "modified": "2024-08-23T15:30:35Z", + "published": "2024-08-23T15:30:34Z", + "aliases": [ + "CVE-2024-8112" + ], + "details": "A vulnerability was found in thinkgem JeeSite 5.3. It has been rated as problematic. This issue affects some unknown processing of the file /js/a/login of the component Cookie Handler. The manipulation of the argument skinName leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8112" + }, + { + "type": "WEB", + "url": "https://gitee.com/thinkgem/jeesite5/issues/IAKGTV" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.275633" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.275633" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jvvm-gq28-8rgc/GHSA-jvvm-gq28-8rgc.json b/advisories/unreviewed/2024/08/GHSA-jvvm-gq28-8rgc/GHSA-jvvm-gq28-8rgc.json index 802ea282c29..5a5816c90e6 100644 --- a/advisories/unreviewed/2024/08/GHSA-jvvm-gq28-8rgc/GHSA-jvvm-gq28-8rgc.json +++ b/advisories/unreviewed/2024/08/GHSA-jvvm-gq28-8rgc/GHSA-jvvm-gq28-8rgc.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jvvm-gq28-8rgc", - "modified": "2024-08-07T15:30:40Z", + "modified": "2024-08-23T15:30:34Z", "published": "2024-08-07T12:31:28Z", "aliases": [ "CVE-2024-7265" ], "details": "Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to change the password of any user, including root user, which could lead to privilege escalation. This issue affects EZD RP: from 15 before 15.84, from 16 before 16.15, from 17 before 17.2.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:D/RE:L/U:Amber" @@ -36,7 +40,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-286" + "CWE-286", + "CWE-863" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-q22q-2rrf-m27p/GHSA-q22q-2rrf-m27p.json b/advisories/unreviewed/2024/08/GHSA-q22q-2rrf-m27p/GHSA-q22q-2rrf-m27p.json index 2a520a50a50..45a85024faf 100644 --- a/advisories/unreviewed/2024/08/GHSA-q22q-2rrf-m27p/GHSA-q22q-2rrf-m27p.json +++ b/advisories/unreviewed/2024/08/GHSA-q22q-2rrf-m27p/GHSA-q22q-2rrf-m27p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q22q-2rrf-m27p", - "modified": "2024-08-01T15:32:23Z", + "modified": "2024-08-23T15:30:33Z", "published": "2024-08-01T15:32:23Z", "aliases": [ "CVE-2024-39777" diff --git a/advisories/unreviewed/2024/08/GHSA-rpp5-g56w-xpgh/GHSA-rpp5-g56w-xpgh.json b/advisories/unreviewed/2024/08/GHSA-rpp5-g56w-xpgh/GHSA-rpp5-g56w-xpgh.json new file mode 100644 index 00000000000..f87e4c32424 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rpp5-g56w-xpgh/GHSA-rpp5-g56w-xpgh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpp5-g56w-xpgh", + "modified": "2024-08-23T15:30:34Z", + "published": "2024-08-23T15:30:34Z", + "aliases": [ + "CVE-2024-5586" + ], + "details": "Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in extranet lockouts report option.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5586" + }, + { + "type": "WEB", + "url": "https://www.manageengine.com/products/active-directory-audit/cve-2024-5586.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rq5p-j687-h2vf/GHSA-rq5p-j687-h2vf.json b/advisories/unreviewed/2024/08/GHSA-rq5p-j687-h2vf/GHSA-rq5p-j687-h2vf.json index b181db6f9f5..425afd7e79e 100644 --- a/advisories/unreviewed/2024/08/GHSA-rq5p-j687-h2vf/GHSA-rq5p-j687-h2vf.json +++ b/advisories/unreviewed/2024/08/GHSA-rq5p-j687-h2vf/GHSA-rq5p-j687-h2vf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rq5p-j687-h2vf", - "modified": "2024-08-22T15:31:19Z", + "modified": "2024-08-23T15:30:33Z", "published": "2024-08-22T15:31:19Z", "aliases": [ "CVE-2024-36442" ], "details": "cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an authenticated attacker to gain access to arbitrary files on the device's file system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-552" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-22T15:15:16Z" diff --git a/advisories/unreviewed/2024/08/GHSA-v25q-32rr-4cpj/GHSA-v25q-32rr-4cpj.json b/advisories/unreviewed/2024/08/GHSA-v25q-32rr-4cpj/GHSA-v25q-32rr-4cpj.json new file mode 100644 index 00000000000..8fc1d7e841b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v25q-32rr-4cpj/GHSA-v25q-32rr-4cpj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v25q-32rr-4cpj", + "modified": "2024-08-23T15:30:34Z", + "published": "2024-08-23T15:30:34Z", + "aliases": [ + "CVE-2024-36517" + ], + "details": "Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in alerts module.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36517" + }, + { + "type": "WEB", + "url": "https://www.manageengine.com/products/active-directory-audit/cve-2024-36517.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xh96-vq46-m9ww/GHSA-xh96-vq46-m9ww.json b/advisories/unreviewed/2024/08/GHSA-xh96-vq46-m9ww/GHSA-xh96-vq46-m9ww.json new file mode 100644 index 00000000000..fab9c95b493 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xh96-vq46-m9ww/GHSA-xh96-vq46-m9ww.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xh96-vq46-m9ww", + "modified": "2024-08-23T15:30:34Z", + "published": "2024-08-23T15:30:34Z", + "aliases": [ + "CVE-2024-42040" + ], + "details": "Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four up to 32 bytes of memory stored behind the packet to the network depending on the later use of DHCP-provided parameters via crafted DHCP responses.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42040" + }, + { + "type": "WEB", + "url": "https://github.com/u-boot/u-boot/tags" + }, + { + "type": "WEB", + "url": "https://www.schutzwerk.com/advisories/SCHUTZWERK-SA-2024-004.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T15:15:16Z" + } +} \ No newline at end of file