mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-mr82-8j83-vxmv GHSA-2pg6-vw9c-qhjv GHSA-36f2-xg2m-gcm5 GHSA-46ff-m72j-q8vp GHSA-4g22-x6m7-r675 GHSA-4rv2-fpjm-34hr GHSA-5g69-hr8r-x577 GHSA-749f-97mp-r5j9 GHSA-fc5p-cp62-fgpc GHSA-jrv8-4h2c-vxmj GHSA-mxr8-qj6j-f7gq GHSA-pq98-px5v-5jjc GHSA-q447-8rfw-f6hh GHSA-xfq4-78j7-v594
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-mr82-8j83-vxmv",
|
||||
"modified": "2024-04-15T18:11:28Z",
|
||||
"modified": "2024-04-26T03:30:28Z",
|
||||
"published": "2024-04-15T03:31:00Z",
|
||||
"aliases": [
|
||||
"CVE-2024-3772"
|
||||
@@ -74,6 +74,10 @@
|
||||
{
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/pydantic/pydantic"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6JBZLMSH4GAZOVBMT2JUO2LXHY7M2ALI"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -0,0 +1,46 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-2pg6-vw9c-qhjv",
|
||||
"modified": "2024-04-26T03:30:29Z",
|
||||
"published": "2024-04-26T03:30:29Z",
|
||||
"aliases": [
|
||||
"CVE-2024-33670"
|
||||
],
|
||||
"details": "Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is not executed as JavaScript due to Content Security Policy (CSP) restrictions, it may still impact the appearance and user interaction of the page.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33670"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://help.passbolt.com/incidents/reflective-html-injection-vulnerability"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.passbolt.com/incidents"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.passbolt.com/security/more"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-04-26T01:15:46Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-36f2-xg2m-gcm5",
|
||||
"modified": "2024-04-26T03:30:29Z",
|
||||
"published": "2024-04-26T03:30:29Z",
|
||||
"aliases": [
|
||||
"CVE-2024-33672"
|
||||
],
|
||||
"details": "An issue was discovered in Veritas NetBackup before 10.4. The Multi-Threaded Agent used in NetBackup can be leveraged to perform arbitrary file deletion on protected files.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33672"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.veritas.com/support/en_US/security/VTS24-001"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-04-26T02:15:06Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-46ff-m72j-q8vp",
|
||||
"modified": "2024-04-26T03:30:29Z",
|
||||
"published": "2024-04-26T03:30:29Z",
|
||||
"aliases": [
|
||||
"CVE-2023-47252"
|
||||
],
|
||||
"details": "An issue was discovered in PnpSmm in Insyde InsydeH2O with kernel 5.0 through 5.6. There is a possible out-of-bounds access in the SMM communication buffer, leading to tampering. The PNP-related SMI sub-functions do not verify data size before getting it from the communication buffer, which could lead to possible circumstances where the data immediately following the command buffer could be destroyed with a fixed value. This is fixed in kernel 5.2 v05.28.45, kernel 5.3 v05.37.45, kernel 5.4 v05.45.45, kernel 5.5 v05.53.45, and kernel 5.6 v05.60.45.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47252"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.insyde.com/security-pledge/SA-2023067"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-04-26T03:15:06Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,50 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4g22-x6m7-r675",
|
||||
"modified": "2024-04-26T03:30:28Z",
|
||||
"published": "2024-04-26T03:30:28Z",
|
||||
"aliases": [
|
||||
"CVE-2022-48682"
|
||||
],
|
||||
"details": "In deletefiles in FDUPES before 2.2.0, a TOCTOU race condition allows arbitrary file deletion via a symlink.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48682"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/adrianlopezroche/fdupes/commit/85680897148f1ac33b55418e00334116e419717f"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://bugzilla.suse.com/show_bug.cgi?id=1200381"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/adrianlopezroche/fdupes/blob/4b6bcde1b3eb1cebe87cd30814f7d6cf4ee46e95/fdupes.c"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/adrianlopezroche/fdupes/compare/v2.1.2...v2.2.0"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-04-26T01:15:45Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4rv2-fpjm-34hr",
|
||||
"modified": "2024-04-26T03:30:28Z",
|
||||
"published": "2024-04-26T03:30:28Z",
|
||||
"aliases": [
|
||||
"CVE-2024-33666"
|
||||
],
|
||||
"details": "An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounting details of this ticket via the API. This data should be available only to agents.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33666"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://zammad.com/en/advisories/zaa-2024-01"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-04-26T01:15:46Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-5g69-hr8r-x577",
|
||||
"modified": "2024-04-26T03:30:29Z",
|
||||
"published": "2024-04-26T03:30:29Z",
|
||||
"aliases": [
|
||||
"CVE-2024-31755"
|
||||
],
|
||||
"details": "cJSON v1.7.17 was discovered to contain a segmentation violation, which can trigger through the second parameter of function cJSON_SetValuestring at cJSON.c.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31755"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/DaveGamble/cJSON/issues/839"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-04-26T03:15:06Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-749f-97mp-r5j9",
|
||||
"modified": "2024-04-26T03:30:29Z",
|
||||
"published": "2024-04-26T03:30:29Z",
|
||||
"aliases": [
|
||||
"CVE-2024-33671"
|
||||
],
|
||||
"details": "An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. The Backup Exec Deduplication Multi-threaded Streaming Agent can be leveraged to perform arbitrary file deletion on protected files.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33671"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.veritas.com/support/en_US/security/VTS24-002#H1"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-04-26T02:15:06Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-fc5p-cp62-fgpc",
|
||||
"modified": "2024-04-26T03:30:29Z",
|
||||
"published": "2024-04-26T03:30:29Z",
|
||||
"aliases": [
|
||||
"CVE-2024-33667"
|
||||
],
|
||||
"details": "An issue was discovered in Zammad before 6.3.0. An authenticated agent could perform a remote Denial of Service attack by calling an endpoint that accepts a generic method name, which was not properly sanitized against an allowlist.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33667"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://zammad.com/en/advisories/zaa-2024-03"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-04-26T01:15:46Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,47 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-jrv8-4h2c-vxmj",
|
||||
"modified": "2024-04-26T03:30:28Z",
|
||||
"published": "2024-04-26T03:30:28Z",
|
||||
"aliases": [
|
||||
"CVE-2024-33665"
|
||||
],
|
||||
"details": "angular-translate through 2.19.1 allows XSS via a crafted key that is used by the translate directive. NOTE: the vendor indicates that there is no documentation indicating that a key is supposed to be safe against XSS attacks.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33665"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/angular-translate/angular-translate/issues/1418"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/angular-translate/angular-translate/issues/1418#issuecomment-252498855"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://stackblitz.com/github/neverendingsupport/angular-translate-xss-2024?file=public%2Findex.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://docs.herodevs.com/docs/2024-Angular-Translate-XSS"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-04-26T01:15:46Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-mxr8-qj6j-f7gq",
|
||||
"modified": "2024-04-26T03:30:29Z",
|
||||
"published": "2024-04-26T03:30:29Z",
|
||||
"aliases": [
|
||||
"CVE-2024-33668"
|
||||
],
|
||||
"details": "An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker could try to brute force them to upload malicious content to article drafts they have no access to.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33668"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://zammad.com/en/advisories/zaa-2024-02"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-04-26T01:15:46Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-pq98-px5v-5jjc",
|
||||
"modified": "2024-04-26T03:30:29Z",
|
||||
"published": "2024-04-26T03:30:29Z",
|
||||
"aliases": [
|
||||
"CVE-2024-4163"
|
||||
],
|
||||
"details": "The Skylab IGX IIoT Gateway allowed users to connect to it via a limited shell terminal (IGX). However, it was discovered that the process was running under root privileges. This allowed the attacker to read, write, and modify any file in the operating system by utilizing the limited shell file exec and download functions. By replacing the /etc/passwd file with a new root user entry, the attacker was able to breakout from the limited shell and login to a unrestricted shell with root access. With the root access, the attacker will be able take full control of the IIoT Gateway.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4163"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://govtech-csg.github.io/security-advisories/2024/04/25/CVE-2024-4163.html"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-04-26T03:15:06Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-q447-8rfw-f6hh",
|
||||
"modified": "2024-04-26T03:30:29Z",
|
||||
"published": "2024-04-26T03:30:29Z",
|
||||
"aliases": [
|
||||
"CVE-2024-33673"
|
||||
],
|
||||
"details": "An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. Improper access controls allow for DLL Hijacking in the Windows DLL Search path.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33673"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.veritas.com/support/en_US/security/VTS24-002#H2"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-04-26T02:15:06Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,54 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-xfq4-78j7-v594",
|
||||
"modified": "2024-04-26T03:30:29Z",
|
||||
"published": "2024-04-26T03:30:29Z",
|
||||
"aliases": [
|
||||
"CVE-2024-33669"
|
||||
],
|
||||
"details": "An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results in an information leak. This allows an attacker capable of observing Passbolt's HTTPS queries to the Pwned Password API to more easily brute force passwords that are manually typed by the user.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33669"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://blog.quarkslab.com/passbolt-a-bold-use-of-haveibeenpwned.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://haveibeenpwned.com"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://help.passbolt.com/incidents/pwned-password-service-information-leak"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.passbolt.com"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.passbolt.com/security/more"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-04-26T01:15:46Z"
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user