mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-6m93-gmrj-jf29 GHSA-7xrf-xg7m-8rqp GHSA-pq5r-rp8m-p9vh GHSA-qc99-r4wh-c8h6 GHSA-rhp6-2jj3-53p2 GHSA-rjwj-693g-mq28 GHSA-rvqv-q989-mj4r GHSA-vpm2-jf87-f6fp GHSA-w8qj-646m-h2rw GHSA-wwmq-47hw-c7vw
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-6m93-gmrj-jf29",
|
||||
"modified": "2024-01-29T18:31:48Z",
|
||||
"modified": "2024-03-29T00:30:34Z",
|
||||
"published": "2024-01-25T21:32:15Z",
|
||||
"aliases": [
|
||||
"CVE-2024-24399"
|
||||
@@ -21,9 +21,17 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24399"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/capture0x/leptoncms"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/capture0x/leptoncms/blob/main/README.md"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://packetstormsecurity.com/files/176647/Lepton-CMS-7.0.0-Remote-Code-Execution.html"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -0,0 +1,43 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-7xrf-xg7m-8rqp",
|
||||
"modified": "2024-03-29T00:30:34Z",
|
||||
"published": "2024-03-29T00:30:34Z",
|
||||
"aliases": [
|
||||
"CVE-2024-28456"
|
||||
],
|
||||
"details": "Cross Site Scripting vulnerability in Campcodes Online Marriage Registration System v.1.0 allows a remote attacker to execute arbitrary code via the text fields in the marriage registration request form.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28456"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://drive.google.com/file/d/1J3-mKlXpHYqOwlUyffRT-ibWa0joB3xC/view?usp=sharing"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://pastebin.com/CYMDR4ss"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.campcodes.com/projects/php/online-marriage-registration-system"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-03-28T23:15:46Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,47 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-pq5r-rp8m-p9vh",
|
||||
"modified": "2024-03-29T00:30:35Z",
|
||||
"published": "2024-03-29T00:30:35Z",
|
||||
"aliases": [
|
||||
"CVE-2024-29489"
|
||||
],
|
||||
"details": "Jerryscript 2.4.0 has SEGV at ./jerry-core/ecma/base/ecma-helpers.c:238:58 in ecma_get_object_type.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29489"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/jerryscript-project/jerryscript/issues/5101"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/jerryscript-project/jerryscript/pull/5129"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/jerryscript-project/jerryscript/commit/cefd391772529c8a9531d7b3c244d78d38be47c6"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://gist.github.com/gandalf4a/9826a897ae1e3c8d1c7e71a1ec71d415"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-03-28T23:15:46Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-qc99-r4wh-c8h6",
|
||||
"modified": "2024-03-29T00:30:34Z",
|
||||
"published": "2024-03-29T00:30:34Z",
|
||||
"aliases": [
|
||||
"CVE-2024-29316"
|
||||
],
|
||||
"details": "NodeBB 3.6.7 is vulnerable to Incorrect Access Control.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29316"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://medium.com/%40krityamkarma858041/broken-access-control-nodebb-v3-6-7-eebc59c24deb"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://nodebb.org/bounty"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-03-28T23:15:46Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,47 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-rhp6-2jj3-53p2",
|
||||
"modified": "2024-03-29T00:30:34Z",
|
||||
"published": "2024-03-29T00:30:34Z",
|
||||
"aliases": [
|
||||
"CVE-2024-28714"
|
||||
],
|
||||
"details": "SQL Injection vulnerability in CRMEB_Java e-commerce system v.1.3.4 allows an attacker to execute arbitrary code via the groupid parameter.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28714"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://gitee.com/ZhongBangKeJi/crmeb_java"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/JiangXiaoBaiJia/cve2/blob/main/1.md"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/JiangXiaoBaiJia/cve2/blob/main/a.png"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://crmebjava.com"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-03-28T23:15:46Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-rjwj-693g-mq28",
|
||||
"modified": "2024-03-29T00:30:34Z",
|
||||
"published": "2024-03-29T00:30:34Z",
|
||||
"aliases": [
|
||||
"CVE-2023-50969"
|
||||
],
|
||||
"details": "Thales Imperva SecureSphere WAF 14.7.0.40 allows remote attackers to bypass WAF rules via a crafted POST request, a different vulnerability than CVE-2021-45468.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50969"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://docs.imperva.com/bundle/v14.7-waf-administration-guide/page/9282.htm"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.hoyahaxa.com/2024/03/imperva-waf-bypass-cve-2023-50969.html"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-03-28T23:15:46Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-rvqv-q989-mj4r",
|
||||
"modified": "2024-03-29T00:30:34Z",
|
||||
"published": "2024-03-29T00:30:34Z",
|
||||
"aliases": [
|
||||
"CVE-2023-25341"
|
||||
],
|
||||
"details": "A Directory Traversal vulnerability in ladle dev server 2.5.1 and earlier allows an attacker on the same network to read files accessible to the user via GET requests.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25341"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.runjak.codes/posts/2024-03-21-ladle-cve"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-03-28T22:15:09Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-vpm2-jf87-f6fp",
|
||||
"modified": "2024-03-29T00:30:34Z",
|
||||
"published": "2024-03-29T00:30:34Z",
|
||||
"aliases": [
|
||||
"CVE-2024-24407"
|
||||
],
|
||||
"details": "SQL Injection vulnerability in Best Courier management system v.1.0 allows a remote attacker to obtain sensitive information via print_pdets.php component.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24407"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/modian-un/CVE/blob/main/Barangay%20Population%20Monitoring%20System.md"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/modian-un/CVE/blob/main/Best%20courier%20management%20system.md"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-03-28T23:15:46Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,43 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-w8qj-646m-h2rw",
|
||||
"modified": "2024-03-29T00:30:34Z",
|
||||
"published": "2024-03-29T00:30:34Z",
|
||||
"aliases": [
|
||||
"CVE-2021-31156"
|
||||
],
|
||||
"details": "Allied Telesis AT-S115 1.2.0 devices before 1.00.024 with Boot Loader 1.00.006 allow Directory Traversal to achieve partial access to data.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-31156"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://gist.github.com/NitescuLucian/69cf22d17bf190325118304be04828e8"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.alliedtelesis.com/en/documents/software-release-notes-s115-v120"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.alliedtelesis.com/sites/default/files/documents/release-notes/ats115v120srna.pdf"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-03-28T23:15:45Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-wwmq-47hw-c7vw",
|
||||
"modified": "2024-03-29T00:30:34Z",
|
||||
"published": "2024-03-29T00:30:34Z",
|
||||
"aliases": [
|
||||
"CVE-2023-33528"
|
||||
],
|
||||
"details": "halo v1.6.0 is vulnerable to Cross Site Scripting (XSS).",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33528"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://gist.github.com/alert-moyan/be0bd087d85c1416829b8e9659e8b66c"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/halo-dev/halo/releases/tag/v1.6.0"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-03-28T23:15:46Z"
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user