Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-11-29 18:35:45 +00:00
parent d0370b16bd
commit 6db6a99654
57 changed files with 933 additions and 127 deletions
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-922"
],
"severity": "LOW",
"github_reviewed": false,
@@ -1,18 +1,19 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hv8g-gp7c-5rcj",
"modified": "2024-04-15T06:30:34Z",
"modified": "2024-11-29T18:34:01Z",
"published": "2024-04-15T06:30:34Z",
"aliases": [
"CVE-2024-1754"
],
"details": "The NPS computy WordPress plugin through 2.7.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)",
"severity": [
],
"affected": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -24,10 +25,8 @@
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-15T05:15:15Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w9xx-xhpg-c678",
"modified": "2024-04-09T00:30:41Z",
"modified": "2024-11-29T18:34:01Z",
"published": "2024-04-05T21:32:44Z",
"aliases": [
"CVE-2024-29748"
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -24,6 +22,10 @@
{
"type": "WEB",
"url": "https://source.android.com/security/bulletin/pixel/2024-04-01"
},
{
"type": "WEB",
"url": "https://twitter.com/GrapheneOS/status/1775308208472813609"
}
],
"database_specific": {
@@ -1,18 +1,19 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5j2x-3vh5-xrw2",
"modified": "2024-05-03T06:30:36Z",
"modified": "2024-11-29T18:34:01Z",
"published": "2024-05-03T06:30:36Z",
"aliases": [
"CVE-2024-3703"
],
"details": "The Carousel Slider WordPress plugin before 2.2.10 does not validate and escape some of its Slide options before outputting them back in the page/post where the related Slide shortcode is embed, which could allow users with the Editor role and above to perform Stored Cross-Site Scripting attacks",
"severity": [
],
"affected": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -24,10 +25,8 @@
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-03T06:15:14Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4jq7-4qmf-m333",
"modified": "2024-08-22T00:31:03Z",
"modified": "2024-11-29T18:34:01Z",
"published": "2024-08-22T00:31:03Z",
"aliases": [
"CVE-2024-28987"
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,6 +26,10 @@
{
"type": "WEB",
"url": "https://www.solarwinds.com/trust-center/security-advisories/cve-2024-28987"
},
{
"type": "WEB",
"url": "https://www.theregister.com/2024/08/22/hardcoded_credentials_bug_solarwinds_whd"
}
],
"database_specific": {
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2jfw-8cwj-3579",
"modified": "2024-11-29T18:34:03Z",
"published": "2024-11-29T18:34:03Z",
"aliases": [
"CVE-2024-36622"
],
"details": "In RaspAP raspap-webgui 3.0.9 and earlier, a command injection vulnerability exists in the clearlog.php script. The vulnerability is due to improper sanitization of user input passed via the logfile parameter.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36622"
},
{
"type": "WEB",
"url": "https://github.com/raspap/raspap-webgui/commit/c98d2b0c15942b4829d31dec615b9b40cc6faa14#diff-939ee414d82245c3b3dd7d36b57f10706e06e8f0871b24bdcf9de6e0d181c4c9"
},
{
"type": "WEB",
"url": "https://gist.github.com/1047524396/ab997b902ec892e592a0df93f38e6941"
},
{
"type": "WEB",
"url": "https://github.com/RaspAP/raspap-webgui/blob/3.0.9/ajax/logging/clearlog.php"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-29T18:15:08Z"
}
}
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2mj3-vfvx-fc43",
"modified": "2024-11-29T18:34:03Z",
"published": "2024-11-29T18:34:03Z",
"aliases": [
"CVE-2024-36621"
],
"details": "moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36621"
},
{
"type": "WEB",
"url": "https://github.com/moby/moby/commit/37545cc644344dcb576cba67eb7b6f51a463d31e"
},
{
"type": "WEB",
"url": "https://gist.github.com/1047524396/5d44459edab5fafcdf86b43909b81135"
},
{
"type": "WEB",
"url": "https://github.com/moby/moby/blob/v25.0.5/builder/builder-next/adapters/snapshot/layer.go#L24"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-29T18:15:07Z"
}
}
@@ -13,9 +13,7 @@
"score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-44gv-75g5-gcm5",
"modified": "2024-11-29T18:34:03Z",
"published": "2024-11-29T18:34:03Z",
"aliases": [
"CVE-2024-36617"
],
"details": "FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36617"
},
{
"type": "WEB",
"url": "https://github.com/ffmpeg/ffmpeg/commit/d973fcbcc2f944752ff10e6a76b0b2d9329937a7"
},
{
"type": "WEB",
"url": "https://gist.github.com/1047524396/f20749f8addc8f86de9cfacf17ba29df"
},
{
"type": "WEB",
"url": "https://github.com/FFmpeg/FFmpeg/blob/n6.1.1/libavformat/cafdec.c#L274"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-29T18:15:07Z"
}
}
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-49pw-2xfg-hw49",
"modified": "2024-11-29T18:34:03Z",
"published": "2024-11-29T18:34:03Z",
"aliases": [
"CVE-2024-36624"
],
"details": "Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the construct_copy_div function in copy_and_paste.js.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36624"
},
{
"type": "WEB",
"url": "https://github.com/zulip/zulip/commit/e1029b59ede0c4f314c367ffa1ba2904ffaf6768"
},
{
"type": "WEB",
"url": "https://gist.github.com/1047524396/64720d2aa5afd943eb7e5a1ed4808ad6"
},
{
"type": "WEB",
"url": "https://github.com/zulip/zulip/blob/8.3/web/src/copy_and_paste.js#L90"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-29T18:15:08Z"
}
}
@@ -0,0 +1,34 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4f8j-4r9h-5jxr",
"modified": "2024-11-29T18:34:03Z",
"published": "2024-11-29T18:34:03Z",
"aliases": [
"CVE-2024-52779"
],
"details": "DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/audit/newstatistics/mon_stat_top10.php.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52779"
},
{
"type": "WEB",
"url": "https://ba1100n.tech/%E6%BC%8F%E6%B4%9E%E6%8A%A5%E5%91%8A/dcme-all-series-rcessix-one"
}
],
"database_specific": {
"cwe_ids": [],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-29T16:15:10Z"
}
}
@@ -0,0 +1,34 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4pv5-72jr-q9hw",
"modified": "2024-11-29T18:34:03Z",
"published": "2024-11-29T18:34:03Z",
"aliases": [
"CVE-2024-47193"
],
"details": "WithSecure Elements Agent for Mac before 24.3, MDR before 24.3, and Elements Client Security for Mac before 16.10 allow a remote Denial of Service.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47193"
},
{
"type": "WEB",
"url": "https://www.withsecure.com/en/support/security-advisories/cve-2024-47193"
}
],
"database_specific": {
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-29T17:15:08Z"
}
}
@@ -13,9 +13,7 @@
"score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -13,9 +13,7 @@
"score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -0,0 +1,34 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5rf6-c453-hr4g",
"modified": "2024-11-29T18:34:03Z",
"published": "2024-11-29T18:34:03Z",
"aliases": [
"CVE-2024-52780"
],
"details": "DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/system/basic/mgmt_edit.php.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52780"
},
{
"type": "WEB",
"url": "https://ba1100n.tech/%E6%BC%8F%E6%B4%9E%E6%8A%A5%E5%91%8A/dcme-all-series-rcessix-one"
}
],
"database_specific": {
"cwe_ids": [],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-29T16:15:10Z"
}
}
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5xvj-wwgx-xf7x",
"modified": "2024-11-28T06:32:42Z",
"modified": "2024-11-29T18:34:03Z",
"published": "2024-11-28T06:32:42Z",
"aliases": [
"CVE-2024-10473"
],
"details": "The Logo Slider WordPress plugin before 4.5.0 does not sanitise and escape some of its Logo Settings when outputing them in pages where the Logo Slider shortcode is embed, which could allow users with a role as low as Author to perform Cross-Site Scripting attacks.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-28T06:15:07Z"
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -13,9 +13,7 @@
"score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -0,0 +1,34 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7w34-8gpx-5fr8",
"modified": "2024-11-29T18:34:03Z",
"published": "2024-11-29T18:34:03Z",
"aliases": [
"CVE-2024-52777"
],
"details": "DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L, <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/system/basic/license_update.php.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52777"
},
{
"type": "WEB",
"url": "https://ba1100n.tech/%E6%BC%8F%E6%B4%9E%E6%8A%A5%E5%91%8A/dcme-all-series-rcessix-one"
}
],
"database_specific": {
"cwe_ids": [],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-29T16:15:10Z"
}
}
@@ -13,9 +13,7 @@
"score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",

Some files were not shown because too many files have changed in this diff Show More