Publish Advisories

GHSA-m9w6-wp3h-vq8g
GHSA-6vr7-3j3q-8546
GHSA-cm3g-9rxc-2598
GHSA-fv42-492h-89pj
GHSA-mhjg-j5hq-m4p7
GHSA-392h-pcr9-7j4w
GHSA-6xgm-r8j8-r5hq
GHSA-cw5c-5w4g-ff67
GHSA-f2jj-rmrg-9rjx
GHSA-j3xp-78w6-p4vh
GHSA-2745-8q5m-h58w
GHSA-5g3f-cpvx-g37c
GHSA-6fhp-x3v7-v4f9
GHSA-7cvv-34h5-xg2q
GHSA-f389-p3hg-3w6f
GHSA-h3f9-j6v8-7wfm
GHSA-m258-frwv-27f2
GHSA-r6vj-38w8-wv4c
GHSA-wp4r-c6wp-5m5q
GHSA-xjwh-3rm6-w25h
This commit is contained in:
advisory-database[bot]
2024-09-04 12:32:07 +00:00
parent 8c0d305596
commit 717fea4b8b
20 changed files with 257 additions and 27 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m9w6-wp3h-vq8g",
"modified": "2024-08-02T15:31:16Z",
"modified": "2024-09-04T12:30:36Z",
"published": "2024-04-25T18:30:39Z",
"aliases": [
"CVE-2024-0874"
@@ -67,6 +67,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:4850"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:6009"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-0874"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6vr7-3j3q-8546",
"modified": "2024-06-26T00:31:34Z",
"modified": "2024-09-04T12:30:36Z",
"published": "2024-02-20T21:30:25Z",
"aliases": [
"CVE-2023-52435"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52435"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/0d3ffbbf8631d6db0552f46250015648991c856f"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/23d05d563b7e7b0314e65c8e882bc27eac2da8e7"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cm3g-9rxc-2598",
"modified": "2024-08-08T18:31:20Z",
"modified": "2024-09-04T12:30:36Z",
"published": "2024-07-29T18:30:38Z",
"aliases": [
"CVE-2024-41098"
@@ -21,10 +21,22 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41098"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/0f0d37c154bb108730c90a91aa31e3170e827962"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/119c97ace2a9ffcf4dc09a23bb057d6c281aff28"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/221e3b1297e74fdec32d0f572f4dcb2260a0a2af"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/56e62977eaaae3eb7122ee2cf9b720b6703114a9"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/5d92c7c566dc76d96e0e19e481d926bbe6631c1e"
@@ -32,6 +44,14 @@
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/8a8ff7e3b736a70d7b7c8764cbcd2724d4079ec8"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/d9c4df80b1b009de1eb77c07e3bb4d45bd212aa5"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/e83405e75d90694ee6a5d898f7f0473ac2686054"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fv42-492h-89pj",
"modified": "2024-07-18T09:30:50Z",
"modified": "2024-09-04T12:30:36Z",
"published": "2024-07-18T09:30:50Z",
"aliases": [
"CVE-2024-41011"
@@ -18,6 +18,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41011"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/009c4d78bcf07c4ac2e3dd9f275b4eaa72b4f884"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/4b4cff994a27ebf7bd3fb9a798a1cdfa8d01b724"
@@ -30,9 +34,17 @@
"type": "WEB",
"url": "https://git.kernel.org/stable/c/89fffbdf535ce659c1a26b51ad62070566e33b28"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/8ad4838040e5515939c071a0f511ce2661a0889d"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/be4a2a81b6b90d1a47eaeaace4cc8e2cb57b96c7"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/f7276cdc1912325b64c33fcb1361952c06e55f63"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mhjg-j5hq-m4p7",
"modified": "2024-07-30T21:31:27Z",
"modified": "2024-09-04T12:30:36Z",
"published": "2024-07-30T09:32:04Z",
"aliases": [
"CVE-2024-42228"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42228"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/3b505759447637dcccb50cbd98ec6f8d2a04fc46"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/855ae72c20310e5402b2317fc537d911e87537ef"
@@ -29,6 +33,22 @@
"type": "WEB",
"url": "https://git.kernel.org/stable/c/88a9a467c548d0b3c7761b4fd54a68e70f9c0944"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/9ee1534ecdd5b4c013064663502d7fde824d2144"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/d35cf41c8eb5d9fe95b21ae6ee2910f9ba4878e8"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/da6a85d197888067e8d38b5d22c986b5b5cab712"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/df02642c21c984303fe34c3f7d72965792fb1a15"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/f8f120b3de48b8b6bdf8988a9b334c2d61c17440"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-392h-pcr9-7j4w",
"modified": "2024-08-26T12:31:19Z",
"modified": "2024-09-04T12:30:36Z",
"published": "2024-08-26T12:31:19Z",
"aliases": [
"CVE-2024-43891"
@@ -18,6 +18,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43891"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/4ed03758ddf0b19d69eed69386d65a92d0091e0c"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/531dc6780d94245af037c25c2371c8caf652f0f9"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6xgm-r8j8-r5hq",
"modified": "2024-08-22T18:31:20Z",
"modified": "2024-09-04T12:30:36Z",
"published": "2024-08-17T12:30:33Z",
"aliases": [
"CVE-2024-43853"
@@ -21,10 +21,18 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43853"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/10aeaa47e4aa2432f29b3e5376df96d7dac5537a"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/1be59c97c83ccd67a519d8a49486b3a8a73ca28a"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/27d6dbdc6485d68075a0ebf8544d6425c1ed84bb"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/29a8d4e02fd4840028c38ceb1536cc8f82a257d4"
@@ -33,6 +41,14 @@
"type": "WEB",
"url": "https://git.kernel.org/stable/c/29ac1d238b3bf126af36037df80d7ecc4822341e"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/4e8d6ac8fc9f843e940ab7389db8136634e07989"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/688325078a8b5badd6e07ae22b27cd04e9947aec"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/96226fbed566f3f686f53a489a29846f2d538080"
File diff suppressed because one or more lines are too long
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f2jj-rmrg-9rjx",
"modified": "2024-08-29T18:31:35Z",
"modified": "2024-09-04T12:30:36Z",
"published": "2024-08-26T09:30:44Z",
"aliases": [
"CVE-2024-43884"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://git.kernel.org/stable/c/064dd929c76532359d2905d90a7c12348043cfd4"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/11b4b0e63f2621b33b2e107407a7d67a65994ca1"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/538fd3921afac97158d4177139a0ad39f056dbb2"
@@ -33,6 +37,18 @@
"type": "WEB",
"url": "https://git.kernel.org/stable/c/5da2884292329bc9be32a7778e0e119f06abe503"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/90e1ff1c15e5a8f3023ca8266e3a85869ed03ee9"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/951d6cb5eaac5130d076c728f2a6db420621afdb"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/9df9783bd85610d3d6e126a1aca221531f6f6dcb"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/ee0799103b1ae4bcfd80dc11a15df085f6ee1b61"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j3xp-78w6-p4vh",
"modified": "2024-08-22T18:31:20Z",
"modified": "2024-09-04T12:30:36Z",
"published": "2024-08-17T09:30:25Z",
"aliases": [
"CVE-2024-42314"
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://git.kernel.org/stable/c/b7859ff398b6b656e1689daa860eb34837b4bb89"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/c1cc3326e27b0bd7a2806b40bc48e49afaf951e7"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/c205565e0f2f439f278a4a94ee97b67ef7b56ae8"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2745-8q5m-h58w",
"modified": "2024-09-02T00:30:35Z",
"modified": "2024-09-04T12:30:36Z",
"published": "2024-09-02T00:30:35Z",
"aliases": [
"CVE-2024-45270"
],
"details": "WordPress plugin \"Carousel Slider\" provided by Sayful Islam contains a cross-site request forgery vulnerability on Hero image selection feature. While logged in to the WordPress site with Carousel Slider plugin enabled, accessing a crafted page may cause a user to alter the contents of the WordPress site.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-02T00:15:11Z"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5g3f-cpvx-g37c",
"modified": "2024-09-04T12:30:37Z",
"published": "2024-09-04T12:30:37Z",
"aliases": [
"CVE-2024-8413"
],
"details": "Cross Site Scripting (XSS) vulnerability through the action parameter in index.php. Affected product codebase https://github.com/Bioshox/Raspcontrol and forks such as https://github.com/harmon25/raspcontrol . An attacker could exploit this vulnerability by sending a specially crafted JavaScript payload to an authenticated user and partially hijacking their session details.\n\nReferences list",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8413"
},
{
"type": "WEB",
"url": "https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-xss-raspcontrol"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-04T11:15:12Z"
}
}
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6fhp-x3v7-v4f9",
"modified": "2024-09-02T06:30:49Z",
"modified": "2024-09-04T12:30:37Z",
"published": "2024-09-02T06:30:49Z",
"aliases": [
"CVE-2024-43776"
],
"details": "SQL Injection in mock exam function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the qlevel parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7cvv-34h5-xg2q",
"modified": "2024-09-02T00:30:35Z",
"modified": "2024-09-04T12:30:36Z",
"published": "2024-09-02T00:30:35Z",
"aliases": [
"CVE-2024-45269"
],
"details": "WordPress plugin \"Carousel Slider\" provided by Sayful Islam contains a cross-site request forgery vulnerability on Carousel image selection feature. While logged in to the WordPress site with Carousel Slider plugin enabled, accessing a crafted page may cause a user to alter the contents of the WordPress site.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-02T00:15:11Z"
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f389-p3hg-3w6f",
"modified": "2024-09-02T06:30:49Z",
"modified": "2024-09-04T12:30:37Z",
"published": "2024-09-02T06:30:49Z",
"aliases": [
"CVE-2024-43773"
],
"details": "SQL Injection in download class learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the cstr parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h3f9-j6v8-7wfm",
"modified": "2024-09-02T06:30:49Z",
"modified": "2024-09-04T12:30:37Z",
"published": "2024-09-02T06:30:49Z",
"aliases": [
"CVE-2024-43774"
],
"details": "SQL Injection in download personal learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the uid parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
@@ -0,0 +1,31 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m258-frwv-27f2",
"modified": "2024-09-04T12:30:37Z",
"published": "2024-09-04T12:30:37Z",
"aliases": [
"CVE-2024-7821"
],
"details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7821"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-04T10:15:03Z"
}
}
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r6vj-38w8-wv4c",
"modified": "2024-09-02T06:30:49Z",
"modified": "2024-09-04T12:30:37Z",
"published": "2024-09-02T06:30:49Z",
"aliases": [
"CVE-2024-43775"
],
"details": "SQL Injection in search course titles function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the search parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wp4r-c6wp-5m5q",
"modified": "2024-09-02T06:30:49Z",
"modified": "2024-09-04T12:30:37Z",
"published": "2024-09-02T06:30:49Z",
"aliases": [
"CVE-2024-43772"
],
"details": "SQL Injection in download student learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the uid parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xjwh-3rm6-w25h",
"modified": "2024-09-02T18:31:25Z",
"modified": "2024-09-04T12:30:37Z",
"published": "2024-09-02T18:31:25Z",
"aliases": [
"CVE-2024-44947"
@@ -22,14 +22,30 @@
"type": "WEB",
"url": "https://git.kernel.org/stable/c/18a067240817bee8a9360539af5d79a4bf5398a5"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/33168db352c7b56ae18aa55c2cae1a1c5905d30e"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/3c0da3d163eb32f1f91891efaade027fa9b245b9"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/4690e2171f651e2b415e3941ce17f2f7b813aff6"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/49934861514d36d0995be8e81bb3312a499d8d9a"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/831433527773e665bdb635ab5783d0b95d1246f4"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/8c78303eafbf85a728dd84d1750e89240c677dd9"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/ac42e0f0eb66af966015ee33fd355bc6f5d80cd6"