From 67394de241373c4b167c78d1b8c6872e26872e27 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 26 Apr 2024 03:31:50 +0000 Subject: [PATCH] Publish Advisories GHSA-mr82-8j83-vxmv GHSA-2pg6-vw9c-qhjv GHSA-36f2-xg2m-gcm5 GHSA-46ff-m72j-q8vp GHSA-4g22-x6m7-r675 GHSA-4rv2-fpjm-34hr GHSA-5g69-hr8r-x577 GHSA-749f-97mp-r5j9 GHSA-fc5p-cp62-fgpc GHSA-jrv8-4h2c-vxmj GHSA-mxr8-qj6j-f7gq GHSA-pq98-px5v-5jjc GHSA-q447-8rfw-f6hh GHSA-xfq4-78j7-v594 --- .../GHSA-mr82-8j83-vxmv.json | 6 ++- .../GHSA-2pg6-vw9c-qhjv.json | 46 ++++++++++++++++ .../GHSA-36f2-xg2m-gcm5.json | 38 +++++++++++++ .../GHSA-46ff-m72j-q8vp.json | 35 ++++++++++++ .../GHSA-4g22-x6m7-r675.json | 50 +++++++++++++++++ .../GHSA-4rv2-fpjm-34hr.json | 35 ++++++++++++ .../GHSA-5g69-hr8r-x577.json | 35 ++++++++++++ .../GHSA-749f-97mp-r5j9.json | 38 +++++++++++++ .../GHSA-fc5p-cp62-fgpc.json | 35 ++++++++++++ .../GHSA-jrv8-4h2c-vxmj.json | 47 ++++++++++++++++ .../GHSA-mxr8-qj6j-f7gq.json | 35 ++++++++++++ .../GHSA-pq98-px5v-5jjc.json | 38 +++++++++++++ .../GHSA-q447-8rfw-f6hh.json | 38 +++++++++++++ .../GHSA-xfq4-78j7-v594.json | 54 +++++++++++++++++++ 14 files changed, 529 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2024/04/GHSA-2pg6-vw9c-qhjv/GHSA-2pg6-vw9c-qhjv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-36f2-xg2m-gcm5/GHSA-36f2-xg2m-gcm5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-46ff-m72j-q8vp/GHSA-46ff-m72j-q8vp.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4g22-x6m7-r675/GHSA-4g22-x6m7-r675.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4rv2-fpjm-34hr/GHSA-4rv2-fpjm-34hr.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5g69-hr8r-x577/GHSA-5g69-hr8r-x577.json create mode 100644 advisories/unreviewed/2024/04/GHSA-749f-97mp-r5j9/GHSA-749f-97mp-r5j9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-fc5p-cp62-fgpc/GHSA-fc5p-cp62-fgpc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-jrv8-4h2c-vxmj/GHSA-jrv8-4h2c-vxmj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mxr8-qj6j-f7gq/GHSA-mxr8-qj6j-f7gq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-pq98-px5v-5jjc/GHSA-pq98-px5v-5jjc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-q447-8rfw-f6hh/GHSA-q447-8rfw-f6hh.json create mode 100644 advisories/unreviewed/2024/04/GHSA-xfq4-78j7-v594/GHSA-xfq4-78j7-v594.json diff --git a/advisories/github-reviewed/2024/04/GHSA-mr82-8j83-vxmv/GHSA-mr82-8j83-vxmv.json b/advisories/github-reviewed/2024/04/GHSA-mr82-8j83-vxmv/GHSA-mr82-8j83-vxmv.json index eeff5e759a5..d0d2ee291d0 100644 --- a/advisories/github-reviewed/2024/04/GHSA-mr82-8j83-vxmv/GHSA-mr82-8j83-vxmv.json +++ b/advisories/github-reviewed/2024/04/GHSA-mr82-8j83-vxmv/GHSA-mr82-8j83-vxmv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mr82-8j83-vxmv", - "modified": "2024-04-15T18:11:28Z", + "modified": "2024-04-26T03:30:28Z", "published": "2024-04-15T03:31:00Z", "aliases": [ "CVE-2024-3772" @@ -74,6 +74,10 @@ { "type": "PACKAGE", "url": "https://github.com/pydantic/pydantic" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6JBZLMSH4GAZOVBMT2JUO2LXHY7M2ALI" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/04/GHSA-2pg6-vw9c-qhjv/GHSA-2pg6-vw9c-qhjv.json b/advisories/unreviewed/2024/04/GHSA-2pg6-vw9c-qhjv/GHSA-2pg6-vw9c-qhjv.json new file mode 100644 index 00000000000..18d2c6aa6d5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2pg6-vw9c-qhjv/GHSA-2pg6-vw9c-qhjv.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2pg6-vw9c-qhjv", + "modified": "2024-04-26T03:30:29Z", + "published": "2024-04-26T03:30:29Z", + "aliases": [ + "CVE-2024-33670" + ], + "details": "Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is not executed as JavaScript due to Content Security Policy (CSP) restrictions, it may still impact the appearance and user interaction of the page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33670" + }, + { + "type": "WEB", + "url": "https://help.passbolt.com/incidents/reflective-html-injection-vulnerability" + }, + { + "type": "WEB", + "url": "https://www.passbolt.com/incidents" + }, + { + "type": "WEB", + "url": "https://www.passbolt.com/security/more" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T01:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-36f2-xg2m-gcm5/GHSA-36f2-xg2m-gcm5.json b/advisories/unreviewed/2024/04/GHSA-36f2-xg2m-gcm5/GHSA-36f2-xg2m-gcm5.json new file mode 100644 index 00000000000..46211b22c58 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-36f2-xg2m-gcm5/GHSA-36f2-xg2m-gcm5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36f2-xg2m-gcm5", + "modified": "2024-04-26T03:30:29Z", + "published": "2024-04-26T03:30:29Z", + "aliases": [ + "CVE-2024-33672" + ], + "details": "An issue was discovered in Veritas NetBackup before 10.4. The Multi-Threaded Agent used in NetBackup can be leveraged to perform arbitrary file deletion on protected files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33672" + }, + { + "type": "WEB", + "url": "https://www.veritas.com/support/en_US/security/VTS24-001" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T02:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-46ff-m72j-q8vp/GHSA-46ff-m72j-q8vp.json b/advisories/unreviewed/2024/04/GHSA-46ff-m72j-q8vp/GHSA-46ff-m72j-q8vp.json new file mode 100644 index 00000000000..de3a932cbae --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-46ff-m72j-q8vp/GHSA-46ff-m72j-q8vp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46ff-m72j-q8vp", + "modified": "2024-04-26T03:30:29Z", + "published": "2024-04-26T03:30:29Z", + "aliases": [ + "CVE-2023-47252" + ], + "details": "An issue was discovered in PnpSmm in Insyde InsydeH2O with kernel 5.0 through 5.6. There is a possible out-of-bounds access in the SMM communication buffer, leading to tampering. The PNP-related SMI sub-functions do not verify data size before getting it from the communication buffer, which could lead to possible circumstances where the data immediately following the command buffer could be destroyed with a fixed value. This is fixed in kernel 5.2 v05.28.45, kernel 5.3 v05.37.45, kernel 5.4 v05.45.45, kernel 5.5 v05.53.45, and kernel 5.6 v05.60.45.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47252" + }, + { + "type": "WEB", + "url": "https://www.insyde.com/security-pledge/SA-2023067" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T03:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4g22-x6m7-r675/GHSA-4g22-x6m7-r675.json b/advisories/unreviewed/2024/04/GHSA-4g22-x6m7-r675/GHSA-4g22-x6m7-r675.json new file mode 100644 index 00000000000..8e13adfb06e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4g22-x6m7-r675/GHSA-4g22-x6m7-r675.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4g22-x6m7-r675", + "modified": "2024-04-26T03:30:28Z", + "published": "2024-04-26T03:30:28Z", + "aliases": [ + "CVE-2022-48682" + ], + "details": "In deletefiles in FDUPES before 2.2.0, a TOCTOU race condition allows arbitrary file deletion via a symlink.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48682" + }, + { + "type": "WEB", + "url": "https://github.com/adrianlopezroche/fdupes/commit/85680897148f1ac33b55418e00334116e419717f" + }, + { + "type": "WEB", + "url": "https://bugzilla.suse.com/show_bug.cgi?id=1200381" + }, + { + "type": "WEB", + "url": "https://github.com/adrianlopezroche/fdupes/blob/4b6bcde1b3eb1cebe87cd30814f7d6cf4ee46e95/fdupes.c" + }, + { + "type": "WEB", + "url": "https://github.com/adrianlopezroche/fdupes/compare/v2.1.2...v2.2.0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T01:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4rv2-fpjm-34hr/GHSA-4rv2-fpjm-34hr.json b/advisories/unreviewed/2024/04/GHSA-4rv2-fpjm-34hr/GHSA-4rv2-fpjm-34hr.json new file mode 100644 index 00000000000..63596a61334 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4rv2-fpjm-34hr/GHSA-4rv2-fpjm-34hr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rv2-fpjm-34hr", + "modified": "2024-04-26T03:30:28Z", + "published": "2024-04-26T03:30:28Z", + "aliases": [ + "CVE-2024-33666" + ], + "details": "An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounting details of this ticket via the API. This data should be available only to agents.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33666" + }, + { + "type": "WEB", + "url": "https://zammad.com/en/advisories/zaa-2024-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T01:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5g69-hr8r-x577/GHSA-5g69-hr8r-x577.json b/advisories/unreviewed/2024/04/GHSA-5g69-hr8r-x577/GHSA-5g69-hr8r-x577.json new file mode 100644 index 00000000000..3d37758be3e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5g69-hr8r-x577/GHSA-5g69-hr8r-x577.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g69-hr8r-x577", + "modified": "2024-04-26T03:30:29Z", + "published": "2024-04-26T03:30:29Z", + "aliases": [ + "CVE-2024-31755" + ], + "details": "cJSON v1.7.17 was discovered to contain a segmentation violation, which can trigger through the second parameter of function cJSON_SetValuestring at cJSON.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31755" + }, + { + "type": "WEB", + "url": "https://github.com/DaveGamble/cJSON/issues/839" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T03:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-749f-97mp-r5j9/GHSA-749f-97mp-r5j9.json b/advisories/unreviewed/2024/04/GHSA-749f-97mp-r5j9/GHSA-749f-97mp-r5j9.json new file mode 100644 index 00000000000..3de019397b4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-749f-97mp-r5j9/GHSA-749f-97mp-r5j9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-749f-97mp-r5j9", + "modified": "2024-04-26T03:30:29Z", + "published": "2024-04-26T03:30:29Z", + "aliases": [ + "CVE-2024-33671" + ], + "details": "An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. The Backup Exec Deduplication Multi-threaded Streaming Agent can be leveraged to perform arbitrary file deletion on protected files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33671" + }, + { + "type": "WEB", + "url": "https://www.veritas.com/support/en_US/security/VTS24-002#H1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T02:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fc5p-cp62-fgpc/GHSA-fc5p-cp62-fgpc.json b/advisories/unreviewed/2024/04/GHSA-fc5p-cp62-fgpc/GHSA-fc5p-cp62-fgpc.json new file mode 100644 index 00000000000..b2b3c7aa51f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fc5p-cp62-fgpc/GHSA-fc5p-cp62-fgpc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc5p-cp62-fgpc", + "modified": "2024-04-26T03:30:29Z", + "published": "2024-04-26T03:30:29Z", + "aliases": [ + "CVE-2024-33667" + ], + "details": "An issue was discovered in Zammad before 6.3.0. An authenticated agent could perform a remote Denial of Service attack by calling an endpoint that accepts a generic method name, which was not properly sanitized against an allowlist.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33667" + }, + { + "type": "WEB", + "url": "https://zammad.com/en/advisories/zaa-2024-03" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T01:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jrv8-4h2c-vxmj/GHSA-jrv8-4h2c-vxmj.json b/advisories/unreviewed/2024/04/GHSA-jrv8-4h2c-vxmj/GHSA-jrv8-4h2c-vxmj.json new file mode 100644 index 00000000000..e8a5ed29012 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jrv8-4h2c-vxmj/GHSA-jrv8-4h2c-vxmj.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrv8-4h2c-vxmj", + "modified": "2024-04-26T03:30:28Z", + "published": "2024-04-26T03:30:28Z", + "aliases": [ + "CVE-2024-33665" + ], + "details": "angular-translate through 2.19.1 allows XSS via a crafted key that is used by the translate directive. NOTE: the vendor indicates that there is no documentation indicating that a key is supposed to be safe against XSS attacks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33665" + }, + { + "type": "WEB", + "url": "https://github.com/angular-translate/angular-translate/issues/1418" + }, + { + "type": "WEB", + "url": "https://github.com/angular-translate/angular-translate/issues/1418#issuecomment-252498855" + }, + { + "type": "WEB", + "url": "https://stackblitz.com/github/neverendingsupport/angular-translate-xss-2024?file=public%2Findex.html" + }, + { + "type": "WEB", + "url": "http://docs.herodevs.com/docs/2024-Angular-Translate-XSS" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T01:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mxr8-qj6j-f7gq/GHSA-mxr8-qj6j-f7gq.json b/advisories/unreviewed/2024/04/GHSA-mxr8-qj6j-f7gq/GHSA-mxr8-qj6j-f7gq.json new file mode 100644 index 00000000000..927bd30a686 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mxr8-qj6j-f7gq/GHSA-mxr8-qj6j-f7gq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxr8-qj6j-f7gq", + "modified": "2024-04-26T03:30:29Z", + "published": "2024-04-26T03:30:29Z", + "aliases": [ + "CVE-2024-33668" + ], + "details": "An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker could try to brute force them to upload malicious content to article drafts they have no access to.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33668" + }, + { + "type": "WEB", + "url": "https://zammad.com/en/advisories/zaa-2024-02" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T01:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pq98-px5v-5jjc/GHSA-pq98-px5v-5jjc.json b/advisories/unreviewed/2024/04/GHSA-pq98-px5v-5jjc/GHSA-pq98-px5v-5jjc.json new file mode 100644 index 00000000000..3cb45864c7c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pq98-px5v-5jjc/GHSA-pq98-px5v-5jjc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pq98-px5v-5jjc", + "modified": "2024-04-26T03:30:29Z", + "published": "2024-04-26T03:30:29Z", + "aliases": [ + "CVE-2024-4163" + ], + "details": "The Skylab IGX IIoT Gateway allowed users to connect to it via a limited shell terminal (IGX). However, it was discovered that the process was running under root privileges. This allowed the attacker to read, write, and modify any file in the operating system by utilizing the limited shell file exec and download functions. By replacing the /etc/passwd file with a new root user entry, the attacker was able to breakout from the limited shell and login to a unrestricted shell with root access. With the root access, the attacker will be able take full control of the IIoT Gateway.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4163" + }, + { + "type": "WEB", + "url": "https://govtech-csg.github.io/security-advisories/2024/04/25/CVE-2024-4163.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T03:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-q447-8rfw-f6hh/GHSA-q447-8rfw-f6hh.json b/advisories/unreviewed/2024/04/GHSA-q447-8rfw-f6hh/GHSA-q447-8rfw-f6hh.json new file mode 100644 index 00000000000..8ea467e1b49 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-q447-8rfw-f6hh/GHSA-q447-8rfw-f6hh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q447-8rfw-f6hh", + "modified": "2024-04-26T03:30:29Z", + "published": "2024-04-26T03:30:29Z", + "aliases": [ + "CVE-2024-33673" + ], + "details": "An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. Improper access controls allow for DLL Hijacking in the Windows DLL Search path.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33673" + }, + { + "type": "WEB", + "url": "https://www.veritas.com/support/en_US/security/VTS24-002#H2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T02:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xfq4-78j7-v594/GHSA-xfq4-78j7-v594.json b/advisories/unreviewed/2024/04/GHSA-xfq4-78j7-v594/GHSA-xfq4-78j7-v594.json new file mode 100644 index 00000000000..f31f2cfa8b4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xfq4-78j7-v594/GHSA-xfq4-78j7-v594.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xfq4-78j7-v594", + "modified": "2024-04-26T03:30:29Z", + "published": "2024-04-26T03:30:29Z", + "aliases": [ + "CVE-2024-33669" + ], + "details": "An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results in an information leak. This allows an attacker capable of observing Passbolt's HTTPS queries to the Pwned Password API to more easily brute force passwords that are manually typed by the user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33669" + }, + { + "type": "WEB", + "url": "https://blog.quarkslab.com/passbolt-a-bold-use-of-haveibeenpwned.html" + }, + { + "type": "WEB", + "url": "https://haveibeenpwned.com" + }, + { + "type": "WEB", + "url": "https://help.passbolt.com/incidents/pwned-password-service-information-leak" + }, + { + "type": "WEB", + "url": "https://www.passbolt.com" + }, + { + "type": "WEB", + "url": "https://www.passbolt.com/security/more" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T01:15:46Z" + } +} \ No newline at end of file