diff --git a/advisories/github-reviewed/2024/07/GHSA-ch7q-gpff-h9hp/GHSA-ch7q-gpff-h9hp.json b/advisories/github-reviewed/2024/07/GHSA-ch7q-gpff-h9hp/GHSA-ch7q-gpff-h9hp.json index d009bdca65c..95034415239 100644 --- a/advisories/github-reviewed/2024/07/GHSA-ch7q-gpff-h9hp/GHSA-ch7q-gpff-h9hp.json +++ b/advisories/github-reviewed/2024/07/GHSA-ch7q-gpff-h9hp/GHSA-ch7q-gpff-h9hp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ch7q-gpff-h9hp", - "modified": "2024-08-12T15:30:47Z", + "modified": "2024-09-23T21:30:46Z", "published": "2024-07-09T00:31:40Z", "aliases": [ "CVE-2024-3653" @@ -64,6 +64,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:5147" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6437" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-3653" diff --git a/advisories/unreviewed/2022/07/GHSA-f6hq-6569-mpqg/GHSA-f6hq-6569-mpqg.json b/advisories/unreviewed/2022/07/GHSA-f6hq-6569-mpqg/GHSA-f6hq-6569-mpqg.json index d74ec7673af..d6a1ed6dd09 100644 --- a/advisories/unreviewed/2022/07/GHSA-f6hq-6569-mpqg/GHSA-f6hq-6569-mpqg.json +++ b/advisories/unreviewed/2022/07/GHSA-f6hq-6569-mpqg/GHSA-f6hq-6569-mpqg.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/10/GHSA-5pqf-6c8x-wp4f/GHSA-5pqf-6c8x-wp4f.json b/advisories/unreviewed/2022/10/GHSA-5pqf-6c8x-wp4f/GHSA-5pqf-6c8x-wp4f.json index b5a860a1e48..eb429a6d2ad 100644 --- a/advisories/unreviewed/2022/10/GHSA-5pqf-6c8x-wp4f/GHSA-5pqf-6c8x-wp4f.json +++ b/advisories/unreviewed/2022/10/GHSA-5pqf-6c8x-wp4f/GHSA-5pqf-6c8x-wp4f.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/10/GHSA-hffw-gq3g-2vr4/GHSA-hffw-gq3g-2vr4.json b/advisories/unreviewed/2022/10/GHSA-hffw-gq3g-2vr4/GHSA-hffw-gq3g-2vr4.json index bc0beb713af..80d09565e2e 100644 --- a/advisories/unreviewed/2022/10/GHSA-hffw-gq3g-2vr4/GHSA-hffw-gq3g-2vr4.json +++ b/advisories/unreviewed/2022/10/GHSA-hffw-gq3g-2vr4/GHSA-hffw-gq3g-2vr4.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/10/GHSA-r6g7-rcvh-9hfv/GHSA-r6g7-rcvh-9hfv.json b/advisories/unreviewed/2022/10/GHSA-r6g7-rcvh-9hfv/GHSA-r6g7-rcvh-9hfv.json index 38626a7c258..ab7ba3d7f5f 100644 --- a/advisories/unreviewed/2022/10/GHSA-r6g7-rcvh-9hfv/GHSA-r6g7-rcvh-9hfv.json +++ b/advisories/unreviewed/2022/10/GHSA-r6g7-rcvh-9hfv/GHSA-r6g7-rcvh-9hfv.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/10/GHSA-v8c6-95x2-q3xm/GHSA-v8c6-95x2-q3xm.json b/advisories/unreviewed/2022/10/GHSA-v8c6-95x2-q3xm/GHSA-v8c6-95x2-q3xm.json index 21eacf75190..a6f24566137 100644 --- a/advisories/unreviewed/2022/10/GHSA-v8c6-95x2-q3xm/GHSA-v8c6-95x2-q3xm.json +++ b/advisories/unreviewed/2022/10/GHSA-v8c6-95x2-q3xm/GHSA-v8c6-95x2-q3xm.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-jp22-76jc-f8rj/GHSA-jp22-76jc-f8rj.json b/advisories/unreviewed/2023/01/GHSA-jp22-76jc-f8rj/GHSA-jp22-76jc-f8rj.json index a451cd728ba..cd3d5c19ecf 100644 --- a/advisories/unreviewed/2023/01/GHSA-jp22-76jc-f8rj/GHSA-jp22-76jc-f8rj.json +++ b/advisories/unreviewed/2023/01/GHSA-jp22-76jc-f8rj/GHSA-jp22-76jc-f8rj.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-9rq4-h92q-xjrm/GHSA-9rq4-h92q-xjrm.json b/advisories/unreviewed/2023/09/GHSA-9rq4-h92q-xjrm/GHSA-9rq4-h92q-xjrm.json index 1ce90eb430f..b23668e0a9d 100644 --- a/advisories/unreviewed/2023/09/GHSA-9rq4-h92q-xjrm/GHSA-9rq4-h92q-xjrm.json +++ b/advisories/unreviewed/2023/09/GHSA-9rq4-h92q-xjrm/GHSA-9rq4-h92q-xjrm.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-35vr-x655-89wj/GHSA-35vr-x655-89wj.json b/advisories/unreviewed/2023/10/GHSA-35vr-x655-89wj/GHSA-35vr-x655-89wj.json index c9587ae3ee6..d199b873b6e 100644 --- a/advisories/unreviewed/2023/10/GHSA-35vr-x655-89wj/GHSA-35vr-x655-89wj.json +++ b/advisories/unreviewed/2023/10/GHSA-35vr-x655-89wj/GHSA-35vr-x655-89wj.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-327", "CWE-532" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/01/GHSA-vqhw-2g88-5gvm/GHSA-vqhw-2g88-5gvm.json b/advisories/unreviewed/2024/01/GHSA-vqhw-2g88-5gvm/GHSA-vqhw-2g88-5gvm.json index 48d98074040..24aad42627a 100644 --- a/advisories/unreviewed/2024/01/GHSA-vqhw-2g88-5gvm/GHSA-vqhw-2g88-5gvm.json +++ b/advisories/unreviewed/2024/01/GHSA-vqhw-2g88-5gvm/GHSA-vqhw-2g88-5gvm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vqhw-2g88-5gvm", - "modified": "2024-05-01T18:30:35Z", + "modified": "2024-09-23T21:30:46Z", "published": "2024-01-16T15:30:28Z", "aliases": [ "CVE-2024-0582" diff --git a/advisories/unreviewed/2024/06/GHSA-vx2h-xx2h-2744/GHSA-vx2h-xx2h-2744.json b/advisories/unreviewed/2024/06/GHSA-vx2h-xx2h-2744/GHSA-vx2h-xx2h-2744.json index 09bfbe1d41c..1588e9af096 100644 --- a/advisories/unreviewed/2024/06/GHSA-vx2h-xx2h-2744/GHSA-vx2h-xx2h-2744.json +++ b/advisories/unreviewed/2024/06/GHSA-vx2h-xx2h-2744/GHSA-vx2h-xx2h-2744.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-788" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/09/GHSA-3q47-272x-vrfj/GHSA-3q47-272x-vrfj.json b/advisories/unreviewed/2024/09/GHSA-3q47-272x-vrfj/GHSA-3q47-272x-vrfj.json index e7df847a028..1941dc2302d 100644 --- a/advisories/unreviewed/2024/09/GHSA-3q47-272x-vrfj/GHSA-3q47-272x-vrfj.json +++ b/advisories/unreviewed/2024/09/GHSA-3q47-272x-vrfj/GHSA-3q47-272x-vrfj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3q47-272x-vrfj", - "modified": "2024-09-17T00:31:03Z", + "modified": "2024-09-23T21:30:46Z", "published": "2024-09-17T00:31:03Z", "aliases": [ "CVE-2024-27861" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15. An application may be able to read restricted memory.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:47Z" diff --git a/advisories/unreviewed/2024/09/GHSA-4843-jw5m-c4mr/GHSA-4843-jw5m-c4mr.json b/advisories/unreviewed/2024/09/GHSA-4843-jw5m-c4mr/GHSA-4843-jw5m-c4mr.json new file mode 100644 index 00000000000..f7def6c5268 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-4843-jw5m-c4mr/GHSA-4843-jw5m-c4mr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4843-jw5m-c4mr", + "modified": "2024-09-23T21:30:47Z", + "published": "2024-09-23T21:30:47Z", + "aliases": [ + "CVE-2024-39843" + ], + "details": "A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL command via create user form inputs.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39843" + }, + { + "type": "WEB", + "url": "https://github.com/centreon/centreon/releases" + }, + { + "type": "WEB", + "url": "https://thewatch.centreon.com/latest-security-bulletins-64/security-bulletin-for-centreon-web-3809" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-23T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-496q-mjmq-q8ww/GHSA-496q-mjmq-q8ww.json b/advisories/unreviewed/2024/09/GHSA-496q-mjmq-q8ww/GHSA-496q-mjmq-q8ww.json index f9164b73783..fa62e466d18 100644 --- a/advisories/unreviewed/2024/09/GHSA-496q-mjmq-q8ww/GHSA-496q-mjmq-q8ww.json +++ b/advisories/unreviewed/2024/09/GHSA-496q-mjmq-q8ww/GHSA-496q-mjmq-q8ww.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-496q-mjmq-q8ww", - "modified": "2024-09-17T00:31:04Z", + "modified": "2024-09-23T21:30:46Z", "published": "2024-09-17T00:31:04Z", "aliases": [ "CVE-2024-40830" ], "details": "This issue was addressed with improved data protection. This issue is fixed in iOS 18 and iPadOS 18. An app may be able to enumerate a user's installed apps.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:48Z" diff --git a/advisories/unreviewed/2024/09/GHSA-6r2w-57p9-f5hh/GHSA-6r2w-57p9-f5hh.json b/advisories/unreviewed/2024/09/GHSA-6r2w-57p9-f5hh/GHSA-6r2w-57p9-f5hh.json new file mode 100644 index 00000000000..4754a8f6436 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6r2w-57p9-f5hh/GHSA-6r2w-57p9-f5hh.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6r2w-57p9-f5hh", + "modified": "2024-09-23T21:30:47Z", + "published": "2024-09-23T21:30:47Z", + "aliases": [ + "CVE-2024-43201" + ], + "details": "The Planet Fitness Workouts iOS and Android mobile apps prior to version 9.8.12 (released on 2024-07-25) fail to properly validate TLS certificates, allowing an attacker with appropriate network access to obtain session tokens and sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:D/RE:L/U:Amber" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43201" + }, + { + "type": "WEB", + "url": "https://apps.apple.com/us/app/planet-fitness-workouts/id399857015" + }, + { + "type": "WEB", + "url": "https://dontvacuum.me/bugs/pf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-23T20:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-7pp5-7gq3-2q5p/GHSA-7pp5-7gq3-2q5p.json b/advisories/unreviewed/2024/09/GHSA-7pp5-7gq3-2q5p/GHSA-7pp5-7gq3-2q5p.json new file mode 100644 index 00000000000..a467c8d2e06 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-7pp5-7gq3-2q5p/GHSA-7pp5-7gq3-2q5p.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pp5-7gq3-2q5p", + "modified": "2024-09-23T21:30:47Z", + "published": "2024-09-23T21:30:47Z", + "aliases": [ + "CVE-2024-46639" + ], + "details": "A cross-site scripting (XSS) vulnerability in HelpDeskZ v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field of Custom Fields message box.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46639" + }, + { + "type": "WEB", + "url": "https://gist.github.com/0xashfaq/45c3f300d125468161c3fa6e38576769" + }, + { + "type": "WEB", + "url": "https://github.com/0xashfaq/-HelpDeskZ-v2.0.2---Stored-Cross-Site-Scripting-XSS-" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-23T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-85x9-4hm3-78m9/GHSA-85x9-4hm3-78m9.json b/advisories/unreviewed/2024/09/GHSA-85x9-4hm3-78m9/GHSA-85x9-4hm3-78m9.json new file mode 100644 index 00000000000..08a52c7838d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-85x9-4hm3-78m9/GHSA-85x9-4hm3-78m9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85x9-4hm3-78m9", + "modified": "2024-09-23T21:30:47Z", + "published": "2024-09-23T21:30:47Z", + "aliases": [ + "CVE-2024-37779" + ], + "details": "WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant script functionality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37779" + }, + { + "type": "WEB", + "url": "https://medium.com/%40daviddepaulasantos/our-brand-new-cve-authenticated-remote-code-execution-rce-on-elvis-dam-c544d879ef1e" + }, + { + "type": "WEB", + "url": "https://www.woodwing.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-23T20:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8x82-8rpw-g64h/GHSA-8x82-8rpw-g64h.json b/advisories/unreviewed/2024/09/GHSA-8x82-8rpw-g64h/GHSA-8x82-8rpw-g64h.json index 61cdd5410e2..846df0a8248 100644 --- a/advisories/unreviewed/2024/09/GHSA-8x82-8rpw-g64h/GHSA-8x82-8rpw-g64h.json +++ b/advisories/unreviewed/2024/09/GHSA-8x82-8rpw-g64h/GHSA-8x82-8rpw-g64h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8x82-8rpw-g64h", - "modified": "2024-09-17T00:31:03Z", + "modified": "2024-09-23T21:30:46Z", "published": "2024-09-17T00:31:03Z", "aliases": [ "CVE-2024-27860" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15. An application may be able to read restricted memory.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:47Z" diff --git a/advisories/unreviewed/2024/09/GHSA-c4jq-v98x-5qm2/GHSA-c4jq-v98x-5qm2.json b/advisories/unreviewed/2024/09/GHSA-c4jq-v98x-5qm2/GHSA-c4jq-v98x-5qm2.json index 1c09ee6e233..e36665098b9 100644 --- a/advisories/unreviewed/2024/09/GHSA-c4jq-v98x-5qm2/GHSA-c4jq-v98x-5qm2.json +++ b/advisories/unreviewed/2024/09/GHSA-c4jq-v98x-5qm2/GHSA-c4jq-v98x-5qm2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c4jq-v98x-5qm2", - "modified": "2024-09-19T18:30:52Z", + "modified": "2024-09-23T21:30:47Z", "published": "2024-09-19T18:30:52Z", "aliases": [ "CVE-2024-31570" ], "details": "libfreeimage in FreeImage 3.4.0 through 3.18.0 has a stack-based buffer overflow in the PluginXPM.cpp Load function via an XPM file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-19T17:15:12Z" diff --git a/advisories/unreviewed/2024/09/GHSA-hc48-m7gp-vcrj/GHSA-hc48-m7gp-vcrj.json b/advisories/unreviewed/2024/09/GHSA-hc48-m7gp-vcrj/GHSA-hc48-m7gp-vcrj.json index b111160c1f2..65ec34dc95d 100644 --- a/advisories/unreviewed/2024/09/GHSA-hc48-m7gp-vcrj/GHSA-hc48-m7gp-vcrj.json +++ b/advisories/unreviewed/2024/09/GHSA-hc48-m7gp-vcrj/GHSA-hc48-m7gp-vcrj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hc48-m7gp-vcrj", - "modified": "2024-09-23T18:30:34Z", + "modified": "2024-09-23T21:30:47Z", "published": "2024-09-23T18:30:34Z", "aliases": [ "CVE-2023-46948" ], "details": "A reflected Cross-Site Scripting (XSS) vulnerability was found on Temenos T24 Browser R19.40 that enables a remote attacker to execute arbitrary JavaScript code via the skin parameter in the about.jsp and genrequest.jsp components.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-23T18:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-jm9x-rx9x-wpqj/GHSA-jm9x-rx9x-wpqj.json b/advisories/unreviewed/2024/09/GHSA-jm9x-rx9x-wpqj/GHSA-jm9x-rx9x-wpqj.json index 0040a0181f1..77be46225be 100644 --- a/advisories/unreviewed/2024/09/GHSA-jm9x-rx9x-wpqj/GHSA-jm9x-rx9x-wpqj.json +++ b/advisories/unreviewed/2024/09/GHSA-jm9x-rx9x-wpqj/GHSA-jm9x-rx9x-wpqj.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-522" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-m62c-4m95-xpcr/GHSA-m62c-4m95-xpcr.json b/advisories/unreviewed/2024/09/GHSA-m62c-4m95-xpcr/GHSA-m62c-4m95-xpcr.json new file mode 100644 index 00000000000..f6d4a8d9126 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-m62c-4m95-xpcr/GHSA-m62c-4m95-xpcr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m62c-4m95-xpcr", + "modified": "2024-09-23T21:30:47Z", + "published": "2024-09-23T21:30:47Z", + "aliases": [ + "CVE-2024-47222" + ], + "details": "New Cloud MyOffice SDK Collaborative Editing Server 2.2.2 through 2.8 allows SSRF via manipulation of requests from external document storage via the MS-WOPI protocol.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47222" + }, + { + "type": "WEB", + "url": "https://myoffice.ru" + }, + { + "type": "WEB", + "url": "https://support.myoffice.ru/products/myoffice-sdk" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-23T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-p2h5-37jh-59fx/GHSA-p2h5-37jh-59fx.json b/advisories/unreviewed/2024/09/GHSA-p2h5-37jh-59fx/GHSA-p2h5-37jh-59fx.json new file mode 100644 index 00000000000..5efc6006399 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-p2h5-37jh-59fx/GHSA-p2h5-37jh-59fx.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2h5-37jh-59fx", + "modified": "2024-09-23T21:30:47Z", + "published": "2024-09-23T21:30:47Z", + "aliases": [ + "CVE-2024-8770" + ], + "details": "A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server, which allows attackers to steal sensitive user information via social engineering. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15, 3.12.9, 3.13.4, and 3.14.1. This vulnerability was reported via the GitHub Bug Bounty program.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:L/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8770" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.17" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.15" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.12/admin/release-notes#3.12.9" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.13/admin/release-notes#3.13.4" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.14/admin/release-notes#3.14.1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-23T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-q224-5f7q-w92f/GHSA-q224-5f7q-w92f.json b/advisories/unreviewed/2024/09/GHSA-q224-5f7q-w92f/GHSA-q224-5f7q-w92f.json new file mode 100644 index 00000000000..4dde6ec89e6 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-q224-5f7q-w92f/GHSA-q224-5f7q-w92f.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q224-5f7q-w92f", + "modified": "2024-09-23T21:30:47Z", + "published": "2024-09-23T21:30:47Z", + "aliases": [ + "CVE-2024-39842" + ], + "details": "A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL command via user massive changes inputs.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39842" + }, + { + "type": "WEB", + "url": "https://github.com/centreon/centreon/releases" + }, + { + "type": "WEB", + "url": "https://thewatch.centreon.com/latest-security-bulletins-64/security-bulletin-for-centreon-web-3809" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-23T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-q27x-q82p-47rv/GHSA-q27x-q82p-47rv.json b/advisories/unreviewed/2024/09/GHSA-q27x-q82p-47rv/GHSA-q27x-q82p-47rv.json index 84d5befd6b5..00b4c24f724 100644 --- a/advisories/unreviewed/2024/09/GHSA-q27x-q82p-47rv/GHSA-q27x-q82p-47rv.json +++ b/advisories/unreviewed/2024/09/GHSA-q27x-q82p-47rv/GHSA-q27x-q82p-47rv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q27x-q82p-47rv", - "modified": "2024-09-17T00:31:03Z", + "modified": "2024-09-23T21:30:46Z", "published": "2024-09-17T00:31:03Z", "aliases": [ "CVE-2024-27858" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. An app may be able to access protected user data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-281" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:47Z" diff --git a/advisories/unreviewed/2024/09/GHSA-q586-q77x-838f/GHSA-q586-q77x-838f.json b/advisories/unreviewed/2024/09/GHSA-q586-q77x-838f/GHSA-q586-q77x-838f.json new file mode 100644 index 00000000000..8d7d3c6e3b5 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-q586-q77x-838f/GHSA-q586-q77x-838f.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q586-q77x-838f", + "modified": "2024-09-23T21:30:48Z", + "published": "2024-09-23T21:30:47Z", + "aliases": [ + "CVE-2024-8263" + ], + "details": "An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15, 3.12.9, 3.13.4, and 3.14.1. This vulnerability was reported via the GitHub Bug Bounty program.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8263" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.17" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.15" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.12/admin/release-notes#3.12.9" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.13/admin/release-notes#3.13.4" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.14/admin/release-notes#3.14.1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-23T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-qwh7-hq65-xwrr/GHSA-qwh7-hq65-xwrr.json b/advisories/unreviewed/2024/09/GHSA-qwh7-hq65-xwrr/GHSA-qwh7-hq65-xwrr.json new file mode 100644 index 00000000000..04fe3eed7c9 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-qwh7-hq65-xwrr/GHSA-qwh7-hq65-xwrr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qwh7-hq65-xwrr", + "modified": "2024-09-23T21:30:47Z", + "published": "2024-09-23T21:30:47Z", + "aliases": [ + "CVE-2024-44540" + ], + "details": "Ubiquiti AirMax firmware version firmware version 8 allows attackers with physical access to gain a privileged command shell via the UART Debugging Port.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44540" + }, + { + "type": "WEB", + "url": "https://www.linkedin.com/pulse/bypass-de-login-en-airmax-ubiquiti-usando-uart-paso-tillerias-ley-hk1gf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-23T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-r45q-ffrj-cr66/GHSA-r45q-ffrj-cr66.json b/advisories/unreviewed/2024/09/GHSA-r45q-ffrj-cr66/GHSA-r45q-ffrj-cr66.json index 51c53c04a7d..f75b104ed0e 100644 --- a/advisories/unreviewed/2024/09/GHSA-r45q-ffrj-cr66/GHSA-r45q-ffrj-cr66.json +++ b/advisories/unreviewed/2024/09/GHSA-r45q-ffrj-cr66/GHSA-r45q-ffrj-cr66.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r45q-ffrj-cr66", - "modified": "2024-09-17T00:31:04Z", + "modified": "2024-09-23T21:30:46Z", "published": "2024-09-17T00:31:04Z", "aliases": [ "CVE-2024-40837" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. An app may be able to access protected user data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:48Z" diff --git a/advisories/unreviewed/2024/09/GHSA-r7j7-4rc9-m5m3/GHSA-r7j7-4rc9-m5m3.json b/advisories/unreviewed/2024/09/GHSA-r7j7-4rc9-m5m3/GHSA-r7j7-4rc9-m5m3.json index 2ef0808b3e5..05128902dca 100644 --- a/advisories/unreviewed/2024/09/GHSA-r7j7-4rc9-m5m3/GHSA-r7j7-4rc9-m5m3.json +++ b/advisories/unreviewed/2024/09/GHSA-r7j7-4rc9-m5m3/GHSA-r7j7-4rc9-m5m3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r7j7-4rc9-m5m3", - "modified": "2024-09-17T00:31:03Z", + "modified": "2024-09-23T21:30:46Z", "published": "2024-09-17T00:31:03Z", "aliases": [ "CVE-2024-23237" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15. An app may be able to cause a denial-of-service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:47Z" diff --git a/advisories/unreviewed/2024/09/GHSA-wfqq-7288-2hgf/GHSA-wfqq-7288-2hgf.json b/advisories/unreviewed/2024/09/GHSA-wfqq-7288-2hgf/GHSA-wfqq-7288-2hgf.json index 73fd9618afd..f9e2145f78e 100644 --- a/advisories/unreviewed/2024/09/GHSA-wfqq-7288-2hgf/GHSA-wfqq-7288-2hgf.json +++ b/advisories/unreviewed/2024/09/GHSA-wfqq-7288-2hgf/GHSA-wfqq-7288-2hgf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wfqq-7288-2hgf", - "modified": "2024-09-17T00:31:04Z", + "modified": "2024-09-23T21:30:46Z", "published": "2024-09-17T00:31:04Z", "aliases": [ "CVE-2024-40831" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. An app may be able to access a user's Photos Library.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-281" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:48Z" diff --git a/advisories/unreviewed/2024/09/GHSA-wg8v-xr35-c5fj/GHSA-wg8v-xr35-c5fj.json b/advisories/unreviewed/2024/09/GHSA-wg8v-xr35-c5fj/GHSA-wg8v-xr35-c5fj.json index d0cda6a11d9..62fcac9f590 100644 --- a/advisories/unreviewed/2024/09/GHSA-wg8v-xr35-c5fj/GHSA-wg8v-xr35-c5fj.json +++ b/advisories/unreviewed/2024/09/GHSA-wg8v-xr35-c5fj/GHSA-wg8v-xr35-c5fj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wg8v-xr35-c5fj", - "modified": "2024-09-23T18:30:35Z", + "modified": "2024-09-23T21:30:47Z", "published": "2024-09-23T18:30:35Z", "aliases": [ "CVE-2024-39342" ], "details": "Entrust Instant Financial Issuance (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier uses a DLL library (i.e. DCG.Security.dll) with a custom AES encryption process that relies on static hard-coded key values. These keys are not uniquely generated per installation of the software. Combined with the encrypted password that can be obtained from \"WebAPI.cfg.xml\" in CVE-2024-39341, the decryption is trivial and can lead to privilege escalation on the Windows host.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-23T18:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-x2j8-283m-qc6h/GHSA-x2j8-283m-qc6h.json b/advisories/unreviewed/2024/09/GHSA-x2j8-283m-qc6h/GHSA-x2j8-283m-qc6h.json index 2d211528c8b..6905ed252e0 100644 --- a/advisories/unreviewed/2024/09/GHSA-x2j8-283m-qc6h/GHSA-x2j8-283m-qc6h.json +++ b/advisories/unreviewed/2024/09/GHSA-x2j8-283m-qc6h/GHSA-x2j8-283m-qc6h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x2j8-283m-qc6h", - "modified": "2024-09-17T00:31:04Z", + "modified": "2024-09-23T21:30:46Z", "published": "2024-09-17T00:31:04Z", "aliases": [ "CVE-2024-40826" ], "details": "A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An unencrypted document may be written to a temporary file when using print preview.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:48Z" diff --git a/advisories/unreviewed/2024/09/GHSA-xgfh-jv6x-46xv/GHSA-xgfh-jv6x-46xv.json b/advisories/unreviewed/2024/09/GHSA-xgfh-jv6x-46xv/GHSA-xgfh-jv6x-46xv.json new file mode 100644 index 00000000000..f10659b95d8 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xgfh-jv6x-46xv/GHSA-xgfh-jv6x-46xv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xgfh-jv6x-46xv", + "modified": "2024-09-23T21:30:47Z", + "published": "2024-09-23T21:30:47Z", + "aliases": [ + "CVE-2024-42861" + ], + "details": "An issue in IEEE 802.1AS linuxptp v.4.2 and before allowing a remote attacker to cause a denial of service via a crafted Pdelay_Req message to the time synchronization function", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42861" + }, + { + "type": "WEB", + "url": "https://github.com/qiupy123/CVE-2024-42861" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-23T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xrvp-gx9p-8ch2/GHSA-xrvp-gx9p-8ch2.json b/advisories/unreviewed/2024/09/GHSA-xrvp-gx9p-8ch2/GHSA-xrvp-gx9p-8ch2.json index bcc778817cc..26c7b7aa8ca 100644 --- a/advisories/unreviewed/2024/09/GHSA-xrvp-gx9p-8ch2/GHSA-xrvp-gx9p-8ch2.json +++ b/advisories/unreviewed/2024/09/GHSA-xrvp-gx9p-8ch2/GHSA-xrvp-gx9p-8ch2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xrvp-gx9p-8ch2", - "modified": "2024-09-17T00:31:03Z", + "modified": "2024-09-23T21:30:46Z", "published": "2024-09-17T00:31:03Z", "aliases": [ "CVE-2024-27795" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A camera extension may be able to access the internet.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-281" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:47Z"