From 6d131da960cfea3163c6cae81ccc39405be7ff3b Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 17 Jan 2025 12:32:03 +0000 Subject: [PATCH] Publish Advisories GHSA-4cj2-2366-wgf3 GHSA-5q3j-g5r8-6rfg GHSA-9h4w-p78f-w2hw GHSA-cq4v-83wg-h467 GHSA-fh4j-49c8-h6mv GHSA-fj2j-5pmh-fq2h GHSA-h4f2-rjw2-w3jj GHSA-hvxh-2jj9-wh53 --- .../GHSA-4cj2-2366-wgf3.json | 40 +++++++++++++++++++ .../GHSA-5q3j-g5r8-6rfg.json | 40 +++++++++++++++++++ .../GHSA-9h4w-p78f-w2hw.json | 40 +++++++++++++++++++ .../GHSA-cq4v-83wg-h467.json | 40 +++++++++++++++++++ .../GHSA-fh4j-49c8-h6mv.json | 40 +++++++++++++++++++ .../GHSA-fj2j-5pmh-fq2h.json | 40 +++++++++++++++++++ .../GHSA-h4f2-rjw2-w3jj.json | 40 +++++++++++++++++++ .../GHSA-hvxh-2jj9-wh53.json | 40 +++++++++++++++++++ 8 files changed, 320 insertions(+) create mode 100644 advisories/unreviewed/2025/01/GHSA-4cj2-2366-wgf3/GHSA-4cj2-2366-wgf3.json create mode 100644 advisories/unreviewed/2025/01/GHSA-5q3j-g5r8-6rfg/GHSA-5q3j-g5r8-6rfg.json create mode 100644 advisories/unreviewed/2025/01/GHSA-9h4w-p78f-w2hw/GHSA-9h4w-p78f-w2hw.json create mode 100644 advisories/unreviewed/2025/01/GHSA-cq4v-83wg-h467/GHSA-cq4v-83wg-h467.json create mode 100644 advisories/unreviewed/2025/01/GHSA-fh4j-49c8-h6mv/GHSA-fh4j-49c8-h6mv.json create mode 100644 advisories/unreviewed/2025/01/GHSA-fj2j-5pmh-fq2h/GHSA-fj2j-5pmh-fq2h.json create mode 100644 advisories/unreviewed/2025/01/GHSA-h4f2-rjw2-w3jj/GHSA-h4f2-rjw2-w3jj.json create mode 100644 advisories/unreviewed/2025/01/GHSA-hvxh-2jj9-wh53/GHSA-hvxh-2jj9-wh53.json diff --git a/advisories/unreviewed/2025/01/GHSA-4cj2-2366-wgf3/GHSA-4cj2-2366-wgf3.json b/advisories/unreviewed/2025/01/GHSA-4cj2-2366-wgf3/GHSA-4cj2-2366-wgf3.json new file mode 100644 index 00000000000..822b116ca40 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4cj2-2366-wgf3/GHSA-4cj2-2366-wgf3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cj2-2366-wgf3", + "modified": "2025-01-17T12:30:41Z", + "published": "2025-01-17T12:30:41Z", + "aliases": [ + "CVE-2024-10498" + ], + "details": "CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that\ncould allow an unauthorized attacker to modify configuration values outside of the normal range when the\nattacker sends specific Modbus write packets to the device which could result in invalid data or loss of web\ninterface functionality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10498" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-014-08&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-014-08.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5q3j-g5r8-6rfg/GHSA-5q3j-g5r8-6rfg.json b/advisories/unreviewed/2025/01/GHSA-5q3j-g5r8-6rfg/GHSA-5q3j-g5r8-6rfg.json new file mode 100644 index 00000000000..39de1636e8c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5q3j-g5r8-6rfg/GHSA-5q3j-g5r8-6rfg.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5q3j-g5r8-6rfg", + "modified": "2025-01-17T12:30:40Z", + "published": "2025-01-17T12:30:40Z", + "aliases": [ + "CVE-2024-12399" + ], + "details": "CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability\nexists that could cause partial loss of confidentiality, loss of integrity and availability of the HMI when attacker performs\nman in the middle attack by intercepting the communication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12399" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-014-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-014-02.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-924" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T10:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9h4w-p78f-w2hw/GHSA-9h4w-p78f-w2hw.json b/advisories/unreviewed/2025/01/GHSA-9h4w-p78f-w2hw/GHSA-9h4w-p78f-w2hw.json new file mode 100644 index 00000000000..fc803f90c0c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9h4w-p78f-w2hw/GHSA-9h4w-p78f-w2hw.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9h4w-p78f-w2hw", + "modified": "2025-01-17T12:30:41Z", + "published": "2025-01-17T12:30:41Z", + "aliases": [ + "CVE-2024-12142" + ], + "details": "CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could\ncause information disclosure of restricted web page, modification of web page and denial of\nservice when specific web pages are modified and restricted functions are invoked.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12142" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-014-05&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-014-05.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cq4v-83wg-h467/GHSA-cq4v-83wg-h467.json b/advisories/unreviewed/2025/01/GHSA-cq4v-83wg-h467/GHSA-cq4v-83wg-h467.json new file mode 100644 index 00000000000..a97800f7d03 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cq4v-83wg-h467/GHSA-cq4v-83wg-h467.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cq4v-83wg-h467", + "modified": "2025-01-17T12:30:40Z", + "published": "2025-01-17T12:30:40Z", + "aliases": [ + "CVE-2024-13377" + ], + "details": "The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alt’ parameter in all versions up to, and including, 2.9.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13377" + }, + { + "type": "WEB", + "url": "https://docs.gravityforms.com/gravityforms-change-log" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/03623f00-2c3c-4590-92fe-a5eaac15b944?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fh4j-49c8-h6mv/GHSA-fh4j-49c8-h6mv.json b/advisories/unreviewed/2025/01/GHSA-fh4j-49c8-h6mv/GHSA-fh4j-49c8-h6mv.json new file mode 100644 index 00000000000..0d3d908a39c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fh4j-49c8-h6mv/GHSA-fh4j-49c8-h6mv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fh4j-49c8-h6mv", + "modified": "2025-01-17T12:30:40Z", + "published": "2025-01-17T12:30:40Z", + "aliases": [ + "CVE-2024-13378" + ], + "details": "The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style_settings’ parameter in versions 2.9.0.1 up to, and including, 2.9.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The attack is only successful in the Chrome web browser, and requires directly browsing the media file via the attachment post.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13378" + }, + { + "type": "WEB", + "url": "https://docs.gravityforms.com/gravityforms-change-log" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f884ea43-e1a5-4b44-8a24-f68f71b0fcfb?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fj2j-5pmh-fq2h/GHSA-fj2j-5pmh-fq2h.json b/advisories/unreviewed/2025/01/GHSA-fj2j-5pmh-fq2h/GHSA-fj2j-5pmh-fq2h.json new file mode 100644 index 00000000000..adca80ba665 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fj2j-5pmh-fq2h/GHSA-fj2j-5pmh-fq2h.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fj2j-5pmh-fq2h", + "modified": "2025-01-17T12:30:40Z", + "published": "2025-01-17T12:30:40Z", + "aliases": [ + "CVE-2024-10497" + ], + "details": "CWE-639: Authorization Bypass Through User-Controlled Key vulnerability exists that could allow an\nauthorized attacker to modify values outside those defined by their privileges (Elevation of Privileges) when the\nattacker sends modified HTTPS requests to the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10497" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-014-08&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-014-08.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T11:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h4f2-rjw2-w3jj/GHSA-h4f2-rjw2-w3jj.json b/advisories/unreviewed/2025/01/GHSA-h4f2-rjw2-w3jj/GHSA-h4f2-rjw2-w3jj.json new file mode 100644 index 00000000000..fe7047a7e8c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h4f2-rjw2-w3jj/GHSA-h4f2-rjw2-w3jj.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4f2-rjw2-w3jj", + "modified": "2025-01-17T12:30:41Z", + "published": "2025-01-17T12:30:41Z", + "aliases": [ + "CVE-2024-12703" + ], + "details": "CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity\nand potential remote code execution on workstation when a non-admin authenticated user opens a malicious\nproject file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12703" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-014-06&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-014-06.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hvxh-2jj9-wh53/GHSA-hvxh-2jj9-wh53.json b/advisories/unreviewed/2025/01/GHSA-hvxh-2jj9-wh53/GHSA-hvxh-2jj9-wh53.json new file mode 100644 index 00000000000..a3449f7eb15 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hvxh-2jj9-wh53/GHSA-hvxh-2jj9-wh53.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvxh-2jj9-wh53", + "modified": "2025-01-17T12:30:40Z", + "published": "2025-01-17T12:30:40Z", + "aliases": [ + "CVE-2024-12476" + ], + "details": "CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could\ncause information disclosure, impacts workstation integrity and potential remote code execution on the\ncompromised computer, when specific crafted XML file is imported in the Web Designer configuration tool.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12476" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-014-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-014-04.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T10:15:07Z" + } +} \ No newline at end of file