diff --git a/advisories/github-reviewed/2023/06/GHSA-q2fp-jw87-86px/GHSA-q2fp-jw87-86px.json b/advisories/github-reviewed/2023/06/GHSA-q2fp-jw87-86px/GHSA-q2fp-jw87-86px.json index b629c666728..60e72f07638 100644 --- a/advisories/github-reviewed/2023/06/GHSA-q2fp-jw87-86px/GHSA-q2fp-jw87-86px.json +++ b/advisories/github-reviewed/2023/06/GHSA-q2fp-jw87-86px/GHSA-q2fp-jw87-86px.json @@ -54,7 +54,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-552" + ], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2023-06-22T20:00:46Z", diff --git a/advisories/unreviewed/2024/03/GHSA-326x-2xqq-45f9/GHSA-326x-2xqq-45f9.json b/advisories/unreviewed/2024/03/GHSA-326x-2xqq-45f9/GHSA-326x-2xqq-45f9.json index 8ed93ce7847..d0938bc0704 100644 --- a/advisories/unreviewed/2024/03/GHSA-326x-2xqq-45f9/GHSA-326x-2xqq-45f9.json +++ b/advisories/unreviewed/2024/03/GHSA-326x-2xqq-45f9/GHSA-326x-2xqq-45f9.json @@ -1,18 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-326x-2xqq-45f9", - "modified": "2024-03-27T06:30:30Z", + "modified": "2024-12-07T00:31:03Z", "published": "2024-03-27T06:30:30Z", "aliases": [ "CVE-2023-40285" ], "details": "An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.", "severity": [ - - ], - "affected": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -29,9 +30,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-27T04:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-fqmj-j6qq-43c5/GHSA-fqmj-j6qq-43c5.json b/advisories/unreviewed/2024/03/GHSA-fqmj-j6qq-43c5/GHSA-fqmj-j6qq-43c5.json index 87d924560b6..94797992594 100644 --- a/advisories/unreviewed/2024/03/GHSA-fqmj-j6qq-43c5/GHSA-fqmj-j6qq-43c5.json +++ b/advisories/unreviewed/2024/03/GHSA-fqmj-j6qq-43c5/GHSA-fqmj-j6qq-43c5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fqmj-j6qq-43c5", - "modified": "2024-03-28T03:30:58Z", + "modified": "2024-12-07T00:31:03Z", "published": "2024-03-28T03:30:58Z", "aliases": [ "CVE-2024-28005" ], "details": "Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN and MR02LN all versions allows a attacker who has obtained high privileges can execute arbitrary scripts.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,9 +26,10 @@ ], "database_specific": { "cwe_ids": [ - "CWE-250" + "CWE-250", + "CWE-94" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T01:15:47Z" diff --git a/advisories/unreviewed/2024/04/GHSA-3vx9-2ch5-m6r6/GHSA-3vx9-2ch5-m6r6.json b/advisories/unreviewed/2024/04/GHSA-3vx9-2ch5-m6r6/GHSA-3vx9-2ch5-m6r6.json index b09a4485855..e0ca8e1de40 100644 --- a/advisories/unreviewed/2024/04/GHSA-3vx9-2ch5-m6r6/GHSA-3vx9-2ch5-m6r6.json +++ b/advisories/unreviewed/2024/04/GHSA-3vx9-2ch5-m6r6/GHSA-3vx9-2ch5-m6r6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3vx9-2ch5-m6r6", - "modified": "2024-06-18T03:34:26Z", + "modified": "2024-12-07T00:31:03Z", "published": "2024-04-17T00:30:56Z", "aliases": [ "CVE-2024-21096" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21096" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00034.html" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CKWVBZ6DBRFMLDXTHJUZ6LU7MJ5RTNA7" diff --git a/advisories/unreviewed/2024/05/GHSA-h7gj-99ph-4f34/GHSA-h7gj-99ph-4f34.json b/advisories/unreviewed/2024/05/GHSA-h7gj-99ph-4f34/GHSA-h7gj-99ph-4f34.json index f70455fde5f..57987ca8934 100644 --- a/advisories/unreviewed/2024/05/GHSA-h7gj-99ph-4f34/GHSA-h7gj-99ph-4f34.json +++ b/advisories/unreviewed/2024/05/GHSA-h7gj-99ph-4f34/GHSA-h7gj-99ph-4f34.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-3gh8-3438-mqwv/GHSA-3gh8-3438-mqwv.json b/advisories/unreviewed/2024/12/GHSA-3gh8-3438-mqwv/GHSA-3gh8-3438-mqwv.json new file mode 100644 index 00000000000..fb109410d10 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3gh8-3438-mqwv/GHSA-3gh8-3438-mqwv.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gh8-3438-mqwv", + "modified": "2024-12-07T00:31:03Z", + "published": "2024-12-07T00:31:03Z", + "aliases": [ + "CVE-2024-41649" + ], + "details": "Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the executor_thread_.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41649" + }, + { + "type": "WEB", + "url": "https://github.com/open-navigation/navigation2/issues/4323" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/pull/4385" + }, + { + "type": "WEB", + "url": "https://github.com/GoesM/ROS-CVE-CNVDs" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3v69-2vx2-cxcc/GHSA-3v69-2vx2-cxcc.json b/advisories/unreviewed/2024/12/GHSA-3v69-2vx2-cxcc/GHSA-3v69-2vx2-cxcc.json new file mode 100644 index 00000000000..a6213fa7ab3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3v69-2vx2-cxcc/GHSA-3v69-2vx2-cxcc.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3v69-2vx2-cxcc", + "modified": "2024-12-07T00:31:03Z", + "published": "2024-12-07T00:31:03Z", + "aliases": [ + "CVE-2024-41647" + ], + "details": "Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_mppi_controller.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41647" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/issues/4436" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/pull/4463" + }, + { + "type": "WEB", + "url": "https://github.com/GoesM/ROS-CVE-CNVDs" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4gjx-h244-c8vq/GHSA-4gjx-h244-c8vq.json b/advisories/unreviewed/2024/12/GHSA-4gjx-h244-c8vq/GHSA-4gjx-h244-c8vq.json new file mode 100644 index 00000000000..89e4a9bf02e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4gjx-h244-c8vq/GHSA-4gjx-h244-c8vq.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gjx-h244-c8vq", + "modified": "2024-12-07T00:31:04Z", + "published": "2024-12-07T00:31:04Z", + "aliases": [ + "CVE-2024-44852" + ], + "details": "Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a segmentation violation via the component theta_star::ThetaStar::isUnsafeToPlan().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44852" + }, + { + "type": "WEB", + "url": "https://github.com/open-navigation/navigation2/issues/4464" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/pull/4463" + }, + { + "type": "WEB", + "url": "https://github.com/GoesM/ROS-CVE-CNVDs" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c6wq-gv79-3q94/GHSA-c6wq-gv79-3q94.json b/advisories/unreviewed/2024/12/GHSA-c6wq-gv79-3q94/GHSA-c6wq-gv79-3q94.json new file mode 100644 index 00000000000..1a333644d37 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c6wq-gv79-3q94/GHSA-c6wq-gv79-3q94.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6wq-gv79-3q94", + "modified": "2024-12-07T00:31:03Z", + "published": "2024-12-07T00:31:03Z", + "aliases": [ + "CVE-2024-38927" + ], + "details": "Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request to change the value of dynamic-parameter `/amcl do_beamskip`.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38927" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/issues/4379" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/pull/4397" + }, + { + "type": "WEB", + "url": "https://github.com/GoesM/ROS-CVE-CNVDs" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cwjq-ghx4-v7j3/GHSA-cwjq-ghx4-v7j3.json b/advisories/unreviewed/2024/12/GHSA-cwjq-ghx4-v7j3/GHSA-cwjq-ghx4-v7j3.json new file mode 100644 index 00000000000..1c668658311 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cwjq-ghx4-v7j3/GHSA-cwjq-ghx4-v7j3.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwjq-ghx4-v7j3", + "modified": "2024-12-07T00:31:03Z", + "published": "2024-12-07T00:31:03Z", + "aliases": [ + "CVE-2024-38925" + ], + "details": "Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter`/amcl z_max` .", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38925" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/issues/4379" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/pull/4397" + }, + { + "type": "WEB", + "url": "https://github.com/GoesM/ROS-CVE-CNVDs" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-g4ph-37mq-hvxw/GHSA-g4ph-37mq-hvxw.json b/advisories/unreviewed/2024/12/GHSA-g4ph-37mq-hvxw/GHSA-g4ph-37mq-hvxw.json new file mode 100644 index 00000000000..9062dfa46ca --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-g4ph-37mq-hvxw/GHSA-g4ph-37mq-hvxw.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4ph-37mq-hvxw", + "modified": "2024-12-07T00:31:03Z", + "published": "2024-12-07T00:31:03Z", + "aliases": [ + "CVE-2024-38921" + ], + "details": "Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter`/amcl z_rand ` .", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38921" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/issues/4379" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/pull/4397" + }, + { + "type": "WEB", + "url": "https://github.com/GoesM/ROS-CVE-CNVDs" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-g59h-6mcf-fp78/GHSA-g59h-6mcf-fp78.json b/advisories/unreviewed/2024/12/GHSA-g59h-6mcf-fp78/GHSA-g59h-6mcf-fp78.json new file mode 100644 index 00000000000..565c6eee95c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-g59h-6mcf-fp78/GHSA-g59h-6mcf-fp78.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g59h-6mcf-fp78", + "modified": "2024-12-07T00:31:03Z", + "published": "2024-12-07T00:31:03Z", + "aliases": [ + "CVE-2024-38924" + ], + "details": "Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request to change the value of dynamic-parameter`/amcl laser_model_type` .", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38924" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/issues/4379" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/pull/4397" + }, + { + "type": "WEB", + "url": "https://github.com/GoesM/ROS-CVE-CNVDs" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hg75-j4c9-fv98/GHSA-hg75-j4c9-fv98.json b/advisories/unreviewed/2024/12/GHSA-hg75-j4c9-fv98/GHSA-hg75-j4c9-fv98.json new file mode 100644 index 00000000000..d9ce25ec7c9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hg75-j4c9-fv98/GHSA-hg75-j4c9-fv98.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hg75-j4c9-fv98", + "modified": "2024-12-07T00:31:03Z", + "published": "2024-12-07T00:31:03Z", + "aliases": [ + "CVE-2024-41645" + ], + "details": "Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2__amcl.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41645" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/issues/4497" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/pull/4521" + }, + { + "type": "WEB", + "url": "https://github.com/GoesM/ROS-CVE-CNVDs" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hv87-379m-crrp/GHSA-hv87-379m-crrp.json b/advisories/unreviewed/2024/12/GHSA-hv87-379m-crrp/GHSA-hv87-379m-crrp.json new file mode 100644 index 00000000000..21a67c0aeb3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hv87-379m-crrp/GHSA-hv87-379m-crrp.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hv87-379m-crrp", + "modified": "2024-12-07T00:31:04Z", + "published": "2024-12-07T00:31:04Z", + "aliases": [ + "CVE-2024-44856" + ], + "details": "Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component nav2_smac_planner().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44856" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/issues/4468" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/pull/4463" + }, + { + "type": "WEB", + "url": "https://github.com/GoesM/ROS-CVE-CNVDs" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-m73x-6gvh-9839/GHSA-m73x-6gvh-9839.json b/advisories/unreviewed/2024/12/GHSA-m73x-6gvh-9839/GHSA-m73x-6gvh-9839.json new file mode 100644 index 00000000000..62c2e445e2f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-m73x-6gvh-9839/GHSA-m73x-6gvh-9839.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m73x-6gvh-9839", + "modified": "2024-12-07T00:31:04Z", + "published": "2024-12-07T00:31:04Z", + "aliases": [ + "CVE-2024-44855" + ], + "details": "Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component nav2_navfn_planner().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44855" + }, + { + "type": "WEB", + "url": "https://github.com/open-navigation/navigation2/issues/4466" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/pull/4463" + }, + { + "type": "WEB", + "url": "https://github.com/GoesM/ROS-CVE-CNVDs" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p5wj-x33c-f49r/GHSA-p5wj-x33c-f49r.json b/advisories/unreviewed/2024/12/GHSA-p5wj-x33c-f49r/GHSA-p5wj-x33c-f49r.json new file mode 100644 index 00000000000..ec18f0e2f7b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p5wj-x33c-f49r/GHSA-p5wj-x33c-f49r.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5wj-x33c-f49r", + "modified": "2024-12-07T00:31:03Z", + "published": "2024-12-07T00:31:03Z", + "aliases": [ + "CVE-2024-38926" + ], + "details": "Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter `/amcl z_short`.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38926" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/issues/4379" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/pull/4397" + }, + { + "type": "WEB", + "url": "https://github.com/GoesM/ROS-CVE-CNVDs" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-px56-8cj3-6h4p/GHSA-px56-8cj3-6h4p.json b/advisories/unreviewed/2024/12/GHSA-px56-8cj3-6h4p/GHSA-px56-8cj3-6h4p.json new file mode 100644 index 00000000000..77e14e5ad1a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-px56-8cj3-6h4p/GHSA-px56-8cj3-6h4p.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-px56-8cj3-6h4p", + "modified": "2024-12-07T00:31:03Z", + "published": "2024-12-07T00:31:03Z", + "aliases": [ + "CVE-2024-38922" + ], + "details": "Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a heap overflow in the nav2_amcl process. This vulnerability is triggered via sending a crafted message to the component /initialpose.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38922" + }, + { + "type": "WEB", + "url": "https://github.com/open-navigation/navigation2/issues/4307" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/issues/4294" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/pull/4301" + }, + { + "type": "WEB", + "url": "https://github.com/GoesM/ROS-CVE-CNVDs" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pxqf-jg9m-j88f/GHSA-pxqf-jg9m-j88f.json b/advisories/unreviewed/2024/12/GHSA-pxqf-jg9m-j88f/GHSA-pxqf-jg9m-j88f.json new file mode 100644 index 00000000000..2ea1af5f255 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pxqf-jg9m-j88f/GHSA-pxqf-jg9m-j88f.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxqf-jg9m-j88f", + "modified": "2024-12-07T00:31:03Z", + "published": "2024-12-07T00:31:03Z", + "aliases": [ + "CVE-2024-41644" + ], + "details": "Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via the dyn_param_handler_ component.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41644" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/issues/4496" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/pull/4521" + }, + { + "type": "WEB", + "url": "https://github.com/GoesM/ROS-CVE-CNVDs" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-q28c-38vj-q7m2/GHSA-q28c-38vj-q7m2.json b/advisories/unreviewed/2024/12/GHSA-q28c-38vj-q7m2/GHSA-q28c-38vj-q7m2.json new file mode 100644 index 00000000000..80bbb61adbe --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-q28c-38vj-q7m2/GHSA-q28c-38vj-q7m2.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q28c-38vj-q7m2", + "modified": "2024-12-07T00:31:04Z", + "published": "2024-12-07T00:31:04Z", + "aliases": [ + "CVE-2024-44854" + ], + "details": "Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component smoothPlan().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44854" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/issues/4538" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/pull/4544" + }, + { + "type": "WEB", + "url": "https://github.com/GoesM/ROS-CVE-CNVDs" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rcvw-67j5-hc25/GHSA-rcvw-67j5-hc25.json b/advisories/unreviewed/2024/12/GHSA-rcvw-67j5-hc25/GHSA-rcvw-67j5-hc25.json new file mode 100644 index 00000000000..70252beb9be --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rcvw-67j5-hc25/GHSA-rcvw-67j5-hc25.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rcvw-67j5-hc25", + "modified": "2024-12-07T00:31:03Z", + "published": "2024-12-07T00:31:03Z", + "aliases": [ + "CVE-2024-41646" + ], + "details": "Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_dwb_controller.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41646" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/issues/4437" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/pull/4463" + }, + { + "type": "WEB", + "url": "https://github.com/GoesM/ROS-CVE-CNVDs" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rj73-rm78-8mx4/GHSA-rj73-rm78-8mx4.json b/advisories/unreviewed/2024/12/GHSA-rj73-rm78-8mx4/GHSA-rj73-rm78-8mx4.json new file mode 100644 index 00000000000..bce63f3bc39 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rj73-rm78-8mx4/GHSA-rj73-rm78-8mx4.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rj73-rm78-8mx4", + "modified": "2024-12-07T00:31:03Z", + "published": "2024-12-07T00:31:03Z", + "aliases": [ + "CVE-2024-41650" + ], + "details": "Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_costmap_2d.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41650" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/issues/4489" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/pull/4495" + }, + { + "type": "WEB", + "url": "https://github.com/GoesM/ROS-CVE-CNVDs" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vr29-w5cg-q4xv/GHSA-vr29-w5cg-q4xv.json b/advisories/unreviewed/2024/12/GHSA-vr29-w5cg-q4xv/GHSA-vr29-w5cg-q4xv.json new file mode 100644 index 00000000000..6ebc7924fe6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vr29-w5cg-q4xv/GHSA-vr29-w5cg-q4xv.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vr29-w5cg-q4xv", + "modified": "2024-12-07T00:31:04Z", + "published": "2024-12-07T00:31:04Z", + "aliases": [ + "CVE-2024-44853" + ], + "details": "Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component computeControl().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44853" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/issues/4547" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/pull/4548" + }, + { + "type": "WEB", + "url": "https://github.com/GoesM/ROS-CVE-CNVDs" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wr54-9gc5-3m4h/GHSA-wr54-9gc5-3m4h.json b/advisories/unreviewed/2024/12/GHSA-wr54-9gc5-3m4h/GHSA-wr54-9gc5-3m4h.json new file mode 100644 index 00000000000..b383e5c3156 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wr54-9gc5-3m4h/GHSA-wr54-9gc5-3m4h.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wr54-9gc5-3m4h", + "modified": "2024-12-07T00:31:03Z", + "published": "2024-12-07T00:31:03Z", + "aliases": [ + "CVE-2024-38923" + ], + "details": "Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request to change the value of dynamic-parameter`/amcl odom_frame_id` .", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38923" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/issues/4379" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/pull/4397" + }, + { + "type": "WEB", + "url": "https://github.com/GoesM/ROS-CVE-CNVDs" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xpm2-f32f-q35f/GHSA-xpm2-f32f-q35f.json b/advisories/unreviewed/2024/12/GHSA-xpm2-f32f-q35f/GHSA-xpm2-f32f-q35f.json new file mode 100644 index 00000000000..88a8187530e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xpm2-f32f-q35f/GHSA-xpm2-f32f-q35f.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpm2-f32f-q35f", + "modified": "2024-12-07T00:31:03Z", + "published": "2024-12-07T00:31:03Z", + "aliases": [ + "CVE-2024-41648" + ], + "details": "Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_regulated_pure_pursuit_controller.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41648" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/issues/4438" + }, + { + "type": "WEB", + "url": "https://github.com/ros-navigation/navigation2/pull/4463" + }, + { + "type": "WEB", + "url": "https://github.com/GoesM/ROS-CVE-CNVDs" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T22:15:20Z" + } +} \ No newline at end of file