Publish Advisories

GHSA-q2fp-jw87-86px
GHSA-326x-2xqq-45f9
GHSA-fqmj-j6qq-43c5
GHSA-3vx9-2ch5-m6r6
GHSA-h7gj-99ph-4f34
GHSA-3gh8-3438-mqwv
GHSA-3v69-2vx2-cxcc
GHSA-4gjx-h244-c8vq
GHSA-c6wq-gv79-3q94
GHSA-cwjq-ghx4-v7j3
GHSA-g4ph-37mq-hvxw
GHSA-g59h-6mcf-fp78
GHSA-hg75-j4c9-fv98
GHSA-hv87-379m-crrp
GHSA-m73x-6gvh-9839
GHSA-p5wj-x33c-f49r
GHSA-px56-8cj3-6h4p
GHSA-pxqf-jg9m-j88f
GHSA-q28c-38vj-q7m2
GHSA-rcvw-67j5-hc25
GHSA-rj73-rm78-8mx4
GHSA-vr29-w5cg-q4xv
GHSA-wr54-9gc5-3m4h
GHSA-xpm2-f32f-q35f
This commit is contained in:
advisory-database[bot]
2024-12-07 00:32:37 +00:00
parent 88beea71b5
commit 69a12cde0b
24 changed files with 736 additions and 14 deletions
@@ -54,7 +54,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-552"
],
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2023-06-22T20:00:46Z",
@@ -1,18 +1,19 @@
{
"schema_version": "1.4.0",
"id": "GHSA-326x-2xqq-45f9",
"modified": "2024-03-27T06:30:30Z",
"modified": "2024-12-07T00:31:03Z",
"published": "2024-03-27T06:30:30Z",
"aliases": [
"CVE-2023-40285"
],
"details": "An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.",
"severity": [
],
"affected": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -29,9 +30,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-27T04:15:09Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fqmj-j6qq-43c5",
"modified": "2024-03-28T03:30:58Z",
"modified": "2024-12-07T00:31:03Z",
"published": "2024-03-28T03:30:58Z",
"aliases": [
"CVE-2024-28005"
],
"details": "Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN and MR02LN all versions allows a attacker who has obtained high privileges can execute arbitrary scripts.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [],
"references": [
{
@@ -21,9 +26,10 @@
],
"database_specific": {
"cwe_ids": [
"CWE-250"
"CWE-250",
"CWE-94"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-28T01:15:47Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3vx9-2ch5-m6r6",
"modified": "2024-06-18T03:34:26Z",
"modified": "2024-12-07T00:31:03Z",
"published": "2024-04-17T00:30:56Z",
"aliases": [
"CVE-2024-21096"
@@ -19,6 +19,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21096"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00034.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CKWVBZ6DBRFMLDXTHJUZ6LU7MJ5RTNA7"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-770"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3gh8-3438-mqwv",
"modified": "2024-12-07T00:31:03Z",
"published": "2024-12-07T00:31:03Z",
"aliases": [
"CVE-2024-41649"
],
"details": "Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the executor_thread_.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41649"
},
{
"type": "WEB",
"url": "https://github.com/open-navigation/navigation2/issues/4323"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/pull/4385"
},
{
"type": "WEB",
"url": "https://github.com/GoesM/ROS-CVE-CNVDs"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-06T22:15:21Z"
}
}
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3v69-2vx2-cxcc",
"modified": "2024-12-07T00:31:03Z",
"published": "2024-12-07T00:31:03Z",
"aliases": [
"CVE-2024-41647"
],
"details": "Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_mppi_controller.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41647"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/issues/4436"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/pull/4463"
},
{
"type": "WEB",
"url": "https://github.com/GoesM/ROS-CVE-CNVDs"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-06T22:15:20Z"
}
}
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4gjx-h244-c8vq",
"modified": "2024-12-07T00:31:04Z",
"published": "2024-12-07T00:31:04Z",
"aliases": [
"CVE-2024-44852"
],
"details": "Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a segmentation violation via the component theta_star::ThetaStar::isUnsafeToPlan().",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44852"
},
{
"type": "WEB",
"url": "https://github.com/open-navigation/navigation2/issues/4464"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/pull/4463"
},
{
"type": "WEB",
"url": "https://github.com/GoesM/ROS-CVE-CNVDs"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-06T22:15:21Z"
}
}
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c6wq-gv79-3q94",
"modified": "2024-12-07T00:31:03Z",
"published": "2024-12-07T00:31:03Z",
"aliases": [
"CVE-2024-38927"
],
"details": "Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request to change the value of dynamic-parameter `/amcl do_beamskip`.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38927"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/issues/4379"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/pull/4397"
},
{
"type": "WEB",
"url": "https://github.com/GoesM/ROS-CVE-CNVDs"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-06T22:15:20Z"
}
}
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cwjq-ghx4-v7j3",
"modified": "2024-12-07T00:31:03Z",
"published": "2024-12-07T00:31:03Z",
"aliases": [
"CVE-2024-38925"
],
"details": "Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter`/amcl z_max` .",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38925"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/issues/4379"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/pull/4397"
},
{
"type": "WEB",
"url": "https://github.com/GoesM/ROS-CVE-CNVDs"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-06T22:15:20Z"
}
}
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g4ph-37mq-hvxw",
"modified": "2024-12-07T00:31:03Z",
"published": "2024-12-07T00:31:03Z",
"aliases": [
"CVE-2024-38921"
],
"details": "Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter`/amcl z_rand ` .",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38921"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/issues/4379"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/pull/4397"
},
{
"type": "WEB",
"url": "https://github.com/GoesM/ROS-CVE-CNVDs"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-06T22:15:19Z"
}
}
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g59h-6mcf-fp78",
"modified": "2024-12-07T00:31:03Z",
"published": "2024-12-07T00:31:03Z",
"aliases": [
"CVE-2024-38924"
],
"details": "Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request to change the value of dynamic-parameter`/amcl laser_model_type` .",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38924"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/issues/4379"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/pull/4397"
},
{
"type": "WEB",
"url": "https://github.com/GoesM/ROS-CVE-CNVDs"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-06T22:15:19Z"
}
}
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hg75-j4c9-fv98",
"modified": "2024-12-07T00:31:03Z",
"published": "2024-12-07T00:31:03Z",
"aliases": [
"CVE-2024-41645"
],
"details": "Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2__amcl.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41645"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/issues/4497"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/pull/4521"
},
{
"type": "WEB",
"url": "https://github.com/GoesM/ROS-CVE-CNVDs"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-06T22:15:20Z"
}
}
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hv87-379m-crrp",
"modified": "2024-12-07T00:31:04Z",
"published": "2024-12-07T00:31:04Z",
"aliases": [
"CVE-2024-44856"
],
"details": "Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component nav2_smac_planner().",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44856"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/issues/4468"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/pull/4463"
},
{
"type": "WEB",
"url": "https://github.com/GoesM/ROS-CVE-CNVDs"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-06T22:15:21Z"
}
}
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m73x-6gvh-9839",
"modified": "2024-12-07T00:31:04Z",
"published": "2024-12-07T00:31:04Z",
"aliases": [
"CVE-2024-44855"
],
"details": "Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component nav2_navfn_planner().",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44855"
},
{
"type": "WEB",
"url": "https://github.com/open-navigation/navigation2/issues/4466"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/pull/4463"
},
{
"type": "WEB",
"url": "https://github.com/GoesM/ROS-CVE-CNVDs"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-06T22:15:21Z"
}
}
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p5wj-x33c-f49r",
"modified": "2024-12-07T00:31:03Z",
"published": "2024-12-07T00:31:03Z",
"aliases": [
"CVE-2024-38926"
],
"details": "Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter `/amcl z_short`.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38926"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/issues/4379"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/pull/4397"
},
{
"type": "WEB",
"url": "https://github.com/GoesM/ROS-CVE-CNVDs"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-06T22:15:20Z"
}
}
@@ -0,0 +1,41 @@
{
"schema_version": "1.4.0",
"id": "GHSA-px56-8cj3-6h4p",
"modified": "2024-12-07T00:31:03Z",
"published": "2024-12-07T00:31:03Z",
"aliases": [
"CVE-2024-38922"
],
"details": "Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a heap overflow in the nav2_amcl process. This vulnerability is triggered via sending a crafted message to the component /initialpose.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38922"
},
{
"type": "WEB",
"url": "https://github.com/open-navigation/navigation2/issues/4307"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/issues/4294"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/pull/4301"
},
{
"type": "WEB",
"url": "https://github.com/GoesM/ROS-CVE-CNVDs"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-06T22:15:19Z"
}
}
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pxqf-jg9m-j88f",
"modified": "2024-12-07T00:31:03Z",
"published": "2024-12-07T00:31:03Z",
"aliases": [
"CVE-2024-41644"
],
"details": "Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via the dyn_param_handler_ component.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41644"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/issues/4496"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/pull/4521"
},
{
"type": "WEB",
"url": "https://github.com/GoesM/ROS-CVE-CNVDs"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-06T22:15:20Z"
}
}
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q28c-38vj-q7m2",
"modified": "2024-12-07T00:31:04Z",
"published": "2024-12-07T00:31:04Z",
"aliases": [
"CVE-2024-44854"
],
"details": "Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component smoothPlan().",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44854"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/issues/4538"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/pull/4544"
},
{
"type": "WEB",
"url": "https://github.com/GoesM/ROS-CVE-CNVDs"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-06T22:15:21Z"
}
}
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rcvw-67j5-hc25",
"modified": "2024-12-07T00:31:03Z",
"published": "2024-12-07T00:31:03Z",
"aliases": [
"CVE-2024-41646"
],
"details": "Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_dwb_controller.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41646"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/issues/4437"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/pull/4463"
},
{
"type": "WEB",
"url": "https://github.com/GoesM/ROS-CVE-CNVDs"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-06T22:15:20Z"
}
}

Some files were not shown because too many files have changed in this diff Show More