diff --git a/advisories/unreviewed/2024/10/GHSA-2qw8-ppr5-m96c/GHSA-2qw8-ppr5-m96c.json b/advisories/unreviewed/2024/10/GHSA-2qw8-ppr5-m96c/GHSA-2qw8-ppr5-m96c.json new file mode 100644 index 00000000000..423492cf58c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2qw8-ppr5-m96c/GHSA-2qw8-ppr5-m96c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2qw8-ppr5-m96c", + "modified": "2024-10-31T12:30:32Z", + "published": "2024-10-31T12:30:32Z", + "aliases": [ + "CVE-2024-43383" + ], + "details": "Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator.\n\nThis issue affects Apache Lucene.NET's Replicator library: from 4.8.0-beta00005 through 4.8.0-beta00016.\n\nAn attacker that can intercept traffic between a replication client and server, or control the target replication node URL, can provide a specially-crafted JSON response that is deserialized as an attacker-provided exception type. This can result in remote code execution or other potential unauthorized access.\n\n\nUsers are recommended to upgrade to version 4.8.0-beta00017, which fixes the issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43383" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/wlz1p76dxpt4rl9o29voxjd5zl7717nh" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-31T10:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-72qw-2vp3-gvg9/GHSA-72qw-2vp3-gvg9.json b/advisories/unreviewed/2024/10/GHSA-72qw-2vp3-gvg9/GHSA-72qw-2vp3-gvg9.json index 35a396a41db..aaf325434e5 100644 --- a/advisories/unreviewed/2024/10/GHSA-72qw-2vp3-gvg9/GHSA-72qw-2vp3-gvg9.json +++ b/advisories/unreviewed/2024/10/GHSA-72qw-2vp3-gvg9/GHSA-72qw-2vp3-gvg9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-72qw-2vp3-gvg9", - "modified": "2024-10-11T18:32:50Z", + "modified": "2024-10-31T12:30:32Z", "published": "2024-10-11T18:32:50Z", "aliases": [ "CVE-2024-8376" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8376" }, + { + "type": "WEB", + "url": "https://github.com/eclipse-mosquitto/mosquitto/commit/1914b3ee2a18102d0a94cbdbbfeae1afa03edd17" + }, { "type": "WEB", "url": "https://github.com/eclipse/mosquitto/releases/tag/v2.0.19" diff --git a/advisories/unreviewed/2024/10/GHSA-7gfw-hc24-935p/GHSA-7gfw-hc24-935p.json b/advisories/unreviewed/2024/10/GHSA-7gfw-hc24-935p/GHSA-7gfw-hc24-935p.json new file mode 100644 index 00000000000..7cb00115fb0 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7gfw-hc24-935p/GHSA-7gfw-hc24-935p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7gfw-hc24-935p", + "modified": "2024-10-31T12:30:32Z", + "published": "2024-10-31T12:30:32Z", + "aliases": [ + "CVE-2024-43984" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher allows Code Injection.This issue affects Podlove Podcast Publisher: from n/a through 4.1.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43984" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/podlove-podcasting-plugin-for-wordpress/wordpress-podlove-podcast-publisher-plugin-4-1-13-csrf-to-remote-code-execution-rce-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-31T10:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-cm54-mprw-5279/GHSA-cm54-mprw-5279.json b/advisories/unreviewed/2024/10/GHSA-cm54-mprw-5279/GHSA-cm54-mprw-5279.json index 8ca35cd89bb..2072f5592f7 100644 --- a/advisories/unreviewed/2024/10/GHSA-cm54-mprw-5279/GHSA-cm54-mprw-5279.json +++ b/advisories/unreviewed/2024/10/GHSA-cm54-mprw-5279/GHSA-cm54-mprw-5279.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cm54-mprw-5279", - "modified": "2024-10-30T15:30:46Z", + "modified": "2024-10-31T12:30:33Z", "published": "2024-10-30T12:31:24Z", "aliases": [ "CVE-2024-10525" @@ -25,6 +25,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10525" }, + { + "type": "WEB", + "url": "https://github.com/eclipse-mosquitto/mosquitto/commit/8ab20b4ba4204fdcdec78cb4d9f03c944a6e0e1c" + }, { "type": "WEB", "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/190" diff --git a/advisories/unreviewed/2024/10/GHSA-g44m-wxp5-6q6h/GHSA-g44m-wxp5-6q6h.json b/advisories/unreviewed/2024/10/GHSA-g44m-wxp5-6q6h/GHSA-g44m-wxp5-6q6h.json new file mode 100644 index 00000000000..eb38762d4c4 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-g44m-wxp5-6q6h/GHSA-g44m-wxp5-6q6h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g44m-wxp5-6q6h", + "modified": "2024-10-31T12:30:32Z", + "published": "2024-10-31T12:30:32Z", + "aliases": [ + "CVE-2024-43930" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in eyecix JobSearch allows Cross Site Request Forgery.This issue affects JobSearch: from n/a through 2.5.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43930" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-jobsearch/wordpress-jobsearch-wp-job-board-wordpress-plugin-plugin-2-5-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-31T10:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-h45x-8r23-7cxx/GHSA-h45x-8r23-7cxx.json b/advisories/unreviewed/2024/10/GHSA-h45x-8r23-7cxx/GHSA-h45x-8r23-7cxx.json new file mode 100644 index 00000000000..1b654f5f5bd --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-h45x-8r23-7cxx/GHSA-h45x-8r23-7cxx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h45x-8r23-7cxx", + "modified": "2024-10-31T12:30:33Z", + "published": "2024-10-31T12:30:33Z", + "aliases": [ + "CVE-2024-49674" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Lukas Huser EKC Tournament Manager allows Upload a Web Shell to a Web Server.This issue affects EKC Tournament Manager: from n/a through 2.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49674" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ekc-tournament-manager/wordpress-ekc-tournament-manager-plugin-2-2-1-csrf-to-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-31T10:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jrrv-7qxg-9qwh/GHSA-jrrv-7qxg-9qwh.json b/advisories/unreviewed/2024/10/GHSA-jrrv-7qxg-9qwh/GHSA-jrrv-7qxg-9qwh.json new file mode 100644 index 00000000000..eebd1d3f8aa --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jrrv-7qxg-9qwh/GHSA-jrrv-7qxg-9qwh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrrv-7qxg-9qwh", + "modified": "2024-10-31T12:30:33Z", + "published": "2024-10-31T12:30:33Z", + "aliases": [ + "CVE-2024-49685" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds (Tweets Widget) allows Cross Site Request Forgery.This issue affects Custom Twitter Feeds (Tweets Widget): from n/a through 2.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49685" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/custom-twitter-feeds/wordpress-custom-twitter-feeds-plugin-2-2-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-31T10:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-r5mw-c5jc-r788/GHSA-r5mw-c5jc-r788.json b/advisories/unreviewed/2024/10/GHSA-r5mw-c5jc-r788/GHSA-r5mw-c5jc-r788.json index d34372773ae..d67d7e5f887 100644 --- a/advisories/unreviewed/2024/10/GHSA-r5mw-c5jc-r788/GHSA-r5mw-c5jc-r788.json +++ b/advisories/unreviewed/2024/10/GHSA-r5mw-c5jc-r788/GHSA-r5mw-c5jc-r788.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r5mw-c5jc-r788", - "modified": "2024-10-30T15:30:46Z", + "modified": "2024-10-31T12:30:32Z", "published": "2024-10-30T12:31:24Z", "aliases": [ "CVE-2024-3935" @@ -25,6 +25,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3935" }, + { + "type": "WEB", + "url": "https://github.com/eclipse-mosquitto/mosquitto/commit/ae7a804dadac8f2aaedb24336df8496a9680fda9" + }, { "type": "WEB", "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/197" diff --git a/advisories/unreviewed/2024/10/GHSA-xrf5-2fh4-5hqj/GHSA-xrf5-2fh4-5hqj.json b/advisories/unreviewed/2024/10/GHSA-xrf5-2fh4-5hqj/GHSA-xrf5-2fh4-5hqj.json new file mode 100644 index 00000000000..6437fa52636 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xrf5-2fh4-5hqj/GHSA-xrf5-2fh4-5hqj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrf5-2fh4-5hqj", + "modified": "2024-10-31T12:30:33Z", + "published": "2024-10-31T12:30:32Z", + "aliases": [ + "CVE-2024-43933" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WPMobile.App allows Stored XSS.This issue affects WPMobile.App: from n/a through 11.48.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43933" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wpappninja/wordpress-wpmobile-app-android-and-ios-mobile-application-plugin-11-48-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-31T10:15:05Z" + } +} \ No newline at end of file