diff --git a/advisories/unreviewed/2024/12/GHSA-239g-m969-jgx2/GHSA-239g-m969-jgx2.json b/advisories/unreviewed/2024/12/GHSA-239g-m969-jgx2/GHSA-239g-m969-jgx2.json new file mode 100644 index 00000000000..cea096d01c5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-239g-m969-jgx2/GHSA-239g-m969-jgx2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-239g-m969-jgx2", + "modified": "2024-12-12T12:31:16Z", + "published": "2024-12-12T12:31:16Z", + "aliases": [ + "CVE-2024-54109" + ], + "details": "Read/Write vulnerability in the image decoding module\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54109" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/12" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-239w-f2px-h2wv/GHSA-239w-f2px-h2wv.json b/advisories/unreviewed/2024/12/GHSA-239w-f2px-h2wv/GHSA-239w-f2px-h2wv.json new file mode 100644 index 00000000000..c9600874e79 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-239w-f2px-h2wv/GHSA-239w-f2px-h2wv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-239w-f2px-h2wv", + "modified": "2024-12-12T12:31:16Z", + "published": "2024-12-12T12:31:16Z", + "aliases": [ + "CVE-2024-8179" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. Improper output encoding could lead to XSS if CSP is not enabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8179" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2665929" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/480718" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-26j7-7472-qxpv/GHSA-26j7-7472-qxpv.json b/advisories/unreviewed/2024/12/GHSA-26j7-7472-qxpv/GHSA-26j7-7472-qxpv.json new file mode 100644 index 00000000000..56ddafb8f19 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-26j7-7472-qxpv/GHSA-26j7-7472-qxpv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-26j7-7472-qxpv", + "modified": "2024-12-12T12:31:15Z", + "published": "2024-12-12T12:31:15Z", + "aliases": [ + "CVE-2024-54101" + ], + "details": "Denial of service (DoS) vulnerability in the installation module\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54101" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/12" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-45hq-53gh-j483/GHSA-45hq-53gh-j483.json b/advisories/unreviewed/2024/12/GHSA-45hq-53gh-j483/GHSA-45hq-53gh-j483.json new file mode 100644 index 00000000000..9ea908e3dda --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-45hq-53gh-j483/GHSA-45hq-53gh-j483.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45hq-53gh-j483", + "modified": "2024-12-12T12:31:16Z", + "published": "2024-12-12T12:31:16Z", + "aliases": [ + "CVE-2024-54108" + ], + "details": "Read/Write vulnerability in the image decoding module\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54108" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/12" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4j55-r6f8-ghp4/GHSA-4j55-r6f8-ghp4.json b/advisories/unreviewed/2024/12/GHSA-4j55-r6f8-ghp4/GHSA-4j55-r6f8-ghp4.json new file mode 100644 index 00000000000..9f02354898a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4j55-r6f8-ghp4/GHSA-4j55-r6f8-ghp4.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4j55-r6f8-ghp4", + "modified": "2024-12-12T12:31:15Z", + "published": "2024-12-12T12:31:15Z", + "aliases": [ + "CVE-2024-54104" + ], + "details": "Cross-process screen stack vulnerability in the UIExtension module\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54104" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/12" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4w56-vr39-rvqr/GHSA-4w56-vr39-rvqr.json b/advisories/unreviewed/2024/12/GHSA-4w56-vr39-rvqr/GHSA-4w56-vr39-rvqr.json new file mode 100644 index 00000000000..e24f5fde755 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4w56-vr39-rvqr/GHSA-4w56-vr39-rvqr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4w56-vr39-rvqr", + "modified": "2024-12-12T12:31:16Z", + "published": "2024-12-12T12:31:16Z", + "aliases": [ + "CVE-2024-54106" + ], + "details": "Null pointer dereference vulnerability in the image decoding module\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54106" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/12" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-248" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4xpw-245v-vp2w/GHSA-4xpw-245v-vp2w.json b/advisories/unreviewed/2024/12/GHSA-4xpw-245v-vp2w/GHSA-4xpw-245v-vp2w.json new file mode 100644 index 00000000000..31bd33eb09e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4xpw-245v-vp2w/GHSA-4xpw-245v-vp2w.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xpw-245v-vp2w", + "modified": "2024-12-12T12:31:16Z", + "published": "2024-12-12T12:31:16Z", + "aliases": [ + "CVE-2024-8647" + ], + "details": "An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2. On self hosted installs, it was possible to leak the anti-CSRF-token to an external site while the Harbor integration was enabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8647" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2666341" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/486051" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5fpq-xm8v-3843/GHSA-5fpq-xm8v-3843.json b/advisories/unreviewed/2024/12/GHSA-5fpq-xm8v-3843/GHSA-5fpq-xm8v-3843.json new file mode 100644 index 00000000000..30ad839fba4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5fpq-xm8v-3843/GHSA-5fpq-xm8v-3843.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fpq-xm8v-3843", + "modified": "2024-12-12T12:31:13Z", + "published": "2024-12-12T12:31:13Z", + "aliases": [ + "CVE-2024-10043" + ], + "details": "An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 17.4.6, all versions starting from 17.5 before 17.5.4 all versions starting from 17.6 before 17.6.2, that allows group users to view confidential incident title through the Wiki History Diff feature, potentially leading to information disclosure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10043" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2774817" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/499577" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-73f4-r8c7-58q3/GHSA-73f4-r8c7-58q3.json b/advisories/unreviewed/2024/12/GHSA-73f4-r8c7-58q3/GHSA-73f4-r8c7-58q3.json new file mode 100644 index 00000000000..3ea58826973 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-73f4-r8c7-58q3/GHSA-73f4-r8c7-58q3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73f4-r8c7-58q3", + "modified": "2024-12-12T12:31:15Z", + "published": "2024-12-12T12:31:15Z", + "aliases": [ + "CVE-2024-54096" + ], + "details": "Vulnerability of improper access control in the MTP module\nImpact: Successful exploitation of this vulnerability may affect integrity and accuracy.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54096" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/12" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-767v-73c5-h8xv/GHSA-767v-73c5-h8xv.json b/advisories/unreviewed/2024/12/GHSA-767v-73c5-h8xv/GHSA-767v-73c5-h8xv.json new file mode 100644 index 00000000000..5035f3fa013 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-767v-73c5-h8xv/GHSA-767v-73c5-h8xv.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-767v-73c5-h8xv", + "modified": "2024-12-12T12:31:16Z", + "published": "2024-12-12T12:31:16Z", + "aliases": [ + "CVE-2024-54112" + ], + "details": "Cross-process screen stack vulnerability in the UIExtension module\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54112" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/12" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7p4h-rr3m-4xwj/GHSA-7p4h-rr3m-4xwj.json b/advisories/unreviewed/2024/12/GHSA-7p4h-rr3m-4xwj/GHSA-7p4h-rr3m-4xwj.json new file mode 100644 index 00000000000..f02ccf67e50 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7p4h-rr3m-4xwj/GHSA-7p4h-rr3m-4xwj.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7p4h-rr3m-4xwj", + "modified": "2024-12-12T12:31:15Z", + "published": "2024-12-12T12:31:15Z", + "aliases": [ + "CVE-2024-54098" + ], + "details": "Service logic error vulnerability in the system service module\nImpact: Successful exploitation of this vulnerability may affect service integrity.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54098" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/12" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7p75-9h8v-vxq4/GHSA-7p75-9h8v-vxq4.json b/advisories/unreviewed/2024/12/GHSA-7p75-9h8v-vxq4/GHSA-7p75-9h8v-vxq4.json new file mode 100644 index 00000000000..2bc1a87b2f6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7p75-9h8v-vxq4/GHSA-7p75-9h8v-vxq4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7p75-9h8v-vxq4", + "modified": "2024-12-12T12:31:15Z", + "published": "2024-12-12T12:31:15Z", + "aliases": [ + "CVE-2024-12570" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior to 17.5.4, and from 17.6 prior to 17.6.2. It may have been possible for an attacker with a victim's `CI_JOB_TOKEN` to obtain a GitLab session token belonging to the victim.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12570" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2724948" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/494694" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-270" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8556-p458-qc84/GHSA-8556-p458-qc84.json b/advisories/unreviewed/2024/12/GHSA-8556-p458-qc84/GHSA-8556-p458-qc84.json new file mode 100644 index 00000000000..1e2a893ee0e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8556-p458-qc84/GHSA-8556-p458-qc84.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8556-p458-qc84", + "modified": "2024-12-12T12:31:16Z", + "published": "2024-12-12T12:31:16Z", + "aliases": [ + "CVE-2024-54117" + ], + "details": "Cross-process screen stack vulnerability in the UIExtension module\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54117" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/12" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-86fp-jr93-hvv2/GHSA-86fp-jr93-hvv2.json b/advisories/unreviewed/2024/12/GHSA-86fp-jr93-hvv2/GHSA-86fp-jr93-hvv2.json new file mode 100644 index 00000000000..933857fe269 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-86fp-jr93-hvv2/GHSA-86fp-jr93-hvv2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86fp-jr93-hvv2", + "modified": "2024-12-12T12:31:15Z", + "published": "2024-12-12T12:31:15Z", + "aliases": [ + "CVE-2024-12292" + ], + "details": "An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, where sensitive information passed in GraphQL mutations may have been retained in GraphQL logs.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12292" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/475211" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8gw5-c82w-7vmp/GHSA-8gw5-c82w-7vmp.json b/advisories/unreviewed/2024/12/GHSA-8gw5-c82w-7vmp/GHSA-8gw5-c82w-7vmp.json new file mode 100644 index 00000000000..49ad987ae0c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8gw5-c82w-7vmp/GHSA-8gw5-c82w-7vmp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8gw5-c82w-7vmp", + "modified": "2024-12-12T12:31:16Z", + "published": "2024-12-12T12:31:16Z", + "aliases": [ + "CVE-2024-54107" + ], + "details": "Read/Write vulnerability in the image decoding module\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54107" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/12" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8pvq-gm8g-p647/GHSA-8pvq-gm8g-p647.json b/advisories/unreviewed/2024/12/GHSA-8pvq-gm8g-p647/GHSA-8pvq-gm8g-p647.json new file mode 100644 index 00000000000..71c05a4c2f7 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8pvq-gm8g-p647/GHSA-8pvq-gm8g-p647.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8pvq-gm8g-p647", + "modified": "2024-12-12T12:31:16Z", + "published": "2024-12-12T12:31:16Z", + "aliases": [ + "CVE-2024-54110" + ], + "details": "Cross-process screen stack vulnerability in the UIExtension module\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54110" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/12" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-97hj-hr5w-4qr9/GHSA-97hj-hr5w-4qr9.json b/advisories/unreviewed/2024/12/GHSA-97hj-hr5w-4qr9/GHSA-97hj-hr5w-4qr9.json new file mode 100644 index 00000000000..070c3ec2a63 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-97hj-hr5w-4qr9/GHSA-97hj-hr5w-4qr9.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97hj-hr5w-4qr9", + "modified": "2024-12-12T12:31:16Z", + "published": "2024-12-12T12:31:16Z", + "aliases": [ + "CVE-2024-54113" + ], + "details": "Process residence vulnerability in abnormal scenarios in the print module\nImpact: Successful exploitation of this vulnerability may affect power consumption.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54113" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/12" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c4g3-63f2-rg7g/GHSA-c4g3-63f2-rg7g.json b/advisories/unreviewed/2024/12/GHSA-c4g3-63f2-rg7g/GHSA-c4g3-63f2-rg7g.json new file mode 100644 index 00000000000..852562da109 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c4g3-63f2-rg7g/GHSA-c4g3-63f2-rg7g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4g3-63f2-rg7g", + "modified": "2024-12-12T12:31:16Z", + "published": "2024-12-12T12:31:16Z", + "aliases": [ + "CVE-2024-54111" + ], + "details": "Read/Write vulnerability in the image decoding module\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54111" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/12" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-345" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-f5vw-w9v8-6hjh/GHSA-f5vw-w9v8-6hjh.json b/advisories/unreviewed/2024/12/GHSA-f5vw-w9v8-6hjh/GHSA-f5vw-w9v8-6hjh.json new file mode 100644 index 00000000000..d0e2679bd1a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-f5vw-w9v8-6hjh/GHSA-f5vw-w9v8-6hjh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5vw-w9v8-6hjh", + "modified": "2024-12-12T12:31:15Z", + "published": "2024-12-12T12:31:15Z", + "aliases": [ + "CVE-2024-54102" + ], + "details": "Race condition vulnerability in the DDR module\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54102" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/12" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fr8h-r296-xggf/GHSA-fr8h-r296-xggf.json b/advisories/unreviewed/2024/12/GHSA-fr8h-r296-xggf/GHSA-fr8h-r296-xggf.json new file mode 100644 index 00000000000..e56d502e69f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fr8h-r296-xggf/GHSA-fr8h-r296-xggf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fr8h-r296-xggf", + "modified": "2024-12-12T12:31:14Z", + "published": "2024-12-12T12:31:14Z", + "aliases": [ + "CVE-2024-11274" + ], + "details": "An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, injection of NEL headers in k8s proxy response could lead to session data exfiltration.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11274" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2813673" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/504707" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-g8v2-8wgj-gwx8/GHSA-g8v2-8wgj-gwx8.json b/advisories/unreviewed/2024/12/GHSA-g8v2-8wgj-gwx8/GHSA-g8v2-8wgj-gwx8.json new file mode 100644 index 00000000000..c619435307a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-g8v2-8wgj-gwx8/GHSA-g8v2-8wgj-gwx8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8v2-8wgj-gwx8", + "modified": "2024-12-12T12:31:16Z", + "published": "2024-12-12T12:31:16Z", + "aliases": [ + "CVE-2024-8233" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions from 9.4 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could cause a denial of service with requests for diff files on a commit or merge request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8233" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2650086" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/480867" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-407" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gx86-89j2-8xm8/GHSA-gx86-89j2-8xm8.json b/advisories/unreviewed/2024/12/GHSA-gx86-89j2-8xm8/GHSA-gx86-89j2-8xm8.json new file mode 100644 index 00000000000..84c3551cd80 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gx86-89j2-8xm8/GHSA-gx86-89j2-8xm8.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gx86-89j2-8xm8", + "modified": "2024-12-12T12:31:15Z", + "published": "2024-12-12T12:31:15Z", + "aliases": [ + "CVE-2024-54099" + ], + "details": "File replacement vulnerability on some devices\nImpact: Successful exploitation of this vulnerability will affect integrity and confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54099" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/12" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hwhg-29fx-c3jc/GHSA-hwhg-29fx-c3jc.json b/advisories/unreviewed/2024/12/GHSA-hwhg-29fx-c3jc/GHSA-hwhg-29fx-c3jc.json new file mode 100644 index 00000000000..53eafedd456 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hwhg-29fx-c3jc/GHSA-hwhg-29fx-c3jc.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwhg-29fx-c3jc", + "modified": "2024-12-12T12:31:16Z", + "published": "2024-12-12T12:31:16Z", + "aliases": [ + "CVE-2024-9367" + ], + "details": "An issue was discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (DoS) condition while parsing templates to generate changelogs.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9367" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2735311" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/496631" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j2cg-2g7j-2gm8/GHSA-j2cg-2g7j-2gm8.json b/advisories/unreviewed/2024/12/GHSA-j2cg-2g7j-2gm8/GHSA-j2cg-2g7j-2gm8.json new file mode 100644 index 00000000000..1589b1e2e83 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j2cg-2g7j-2gm8/GHSA-j2cg-2g7j-2gm8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2cg-2g7j-2gm8", + "modified": "2024-12-12T12:31:16Z", + "published": "2024-12-12T12:31:16Z", + "aliases": [ + "CVE-2024-54116" + ], + "details": "Out-of-bounds read vulnerability in the M3U8 module\nImpact: Successful exploitation of this vulnerability may cause features to perform abnormally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54116" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/12" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-754" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mpm8-4rhh-qr48/GHSA-mpm8-4rhh-qr48.json b/advisories/unreviewed/2024/12/GHSA-mpm8-4rhh-qr48/GHSA-mpm8-4rhh-qr48.json new file mode 100644 index 00000000000..1870451f2fb --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mpm8-4rhh-qr48/GHSA-mpm8-4rhh-qr48.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mpm8-4rhh-qr48", + "modified": "2024-12-12T12:31:16Z", + "published": "2024-12-12T12:31:16Z", + "aliases": [ + "CVE-2024-54115" + ], + "details": "Out-of-bounds read vulnerability in the DASH module\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54115" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/12" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-754" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-q9qg-x25c-5q6j/GHSA-q9qg-x25c-5q6j.json b/advisories/unreviewed/2024/12/GHSA-q9qg-x25c-5q6j/GHSA-q9qg-x25c-5q6j.json new file mode 100644 index 00000000000..dff6b7728bd --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-q9qg-x25c-5q6j/GHSA-q9qg-x25c-5q6j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q9qg-x25c-5q6j", + "modified": "2024-12-12T12:31:15Z", + "published": "2024-12-12T12:31:15Z", + "aliases": [ + "CVE-2024-54097" + ], + "details": "Security vulnerability in the HiView module\nImpact: Successful exploitation of this vulnerability may affect feature implementation and integrity.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54097" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/12" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-15" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-r7cq-m9jp-fmvq/GHSA-r7cq-m9jp-fmvq.json b/advisories/unreviewed/2024/12/GHSA-r7cq-m9jp-fmvq/GHSA-r7cq-m9jp-fmvq.json new file mode 100644 index 00000000000..aea3e0298bf --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-r7cq-m9jp-fmvq/GHSA-r7cq-m9jp-fmvq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7cq-m9jp-fmvq", + "modified": "2024-12-12T12:31:16Z", + "published": "2024-12-12T12:31:16Z", + "aliases": [ + "CVE-2024-54105" + ], + "details": "Read/Write vulnerability in the image decoding module\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54105" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/12" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rc33-5h6m-p67v/GHSA-rc33-5h6m-p67v.json b/advisories/unreviewed/2024/12/GHSA-rc33-5h6m-p67v/GHSA-rc33-5h6m-p67v.json new file mode 100644 index 00000000000..a3975a97588 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rc33-5h6m-p67v/GHSA-rc33-5h6m-p67v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rc33-5h6m-p67v", + "modified": "2024-12-12T12:31:15Z", + "published": "2024-12-12T12:31:15Z", + "aliases": [ + "CVE-2024-54100" + ], + "details": "Vulnerability of improper access control in the secure input module\nImpact: Successful exploitation of this vulnerability may cause features to perform abnormally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54100" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/12" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rgm4-w4gp-j4w6/GHSA-rgm4-w4gp-j4w6.json b/advisories/unreviewed/2024/12/GHSA-rgm4-w4gp-j4w6/GHSA-rgm4-w4gp-j4w6.json new file mode 100644 index 00000000000..ac6ac591007 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rgm4-w4gp-j4w6/GHSA-rgm4-w4gp-j4w6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgm4-w4gp-j4w6", + "modified": "2024-12-12T12:31:15Z", + "published": "2024-12-12T12:31:15Z", + "aliases": [ + "CVE-2024-54103" + ], + "details": "Vulnerability of improper access control in the album module\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54103" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/12" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-v6xp-h7ww-6xqf/GHSA-v6xp-h7ww-6xqf.json b/advisories/unreviewed/2024/12/GHSA-v6xp-h7ww-6xqf/GHSA-v6xp-h7ww-6xqf.json new file mode 100644 index 00000000000..bf5ac44352a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-v6xp-h7ww-6xqf/GHSA-v6xp-h7ww-6xqf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6xp-h7ww-6xqf", + "modified": "2024-12-12T12:31:16Z", + "published": "2024-12-12T12:31:16Z", + "aliases": [ + "CVE-2024-9387" + ], + "details": "An issue was discovered in GitLab CE/EE affecting all versions from 11.8 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could potentially perform an open redirect against a given releases API endpoint.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9387" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2732235" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/496659" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w8h6-mg97-8mq2/GHSA-w8h6-mg97-8mq2.json b/advisories/unreviewed/2024/12/GHSA-w8h6-mg97-8mq2/GHSA-w8h6-mg97-8mq2.json new file mode 100644 index 00000000000..037ef1b013c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w8h6-mg97-8mq2/GHSA-w8h6-mg97-8mq2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8h6-mg97-8mq2", + "modified": "2024-12-12T12:31:16Z", + "published": "2024-12-12T12:31:16Z", + "aliases": [ + "CVE-2024-54114" + ], + "details": "Out-of-bounds access vulnerability in playback in the DASH module\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54114" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/12" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-754" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T12:15:27Z" + } +} \ No newline at end of file