diff --git a/advisories/github-reviewed/2024/04/GHSA-m9w6-wp3h-vq8g/GHSA-m9w6-wp3h-vq8g.json b/advisories/github-reviewed/2024/04/GHSA-m9w6-wp3h-vq8g/GHSA-m9w6-wp3h-vq8g.json index f7bc8c8d8c6..a2f520a4aa3 100644 --- a/advisories/github-reviewed/2024/04/GHSA-m9w6-wp3h-vq8g/GHSA-m9w6-wp3h-vq8g.json +++ b/advisories/github-reviewed/2024/04/GHSA-m9w6-wp3h-vq8g/GHSA-m9w6-wp3h-vq8g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m9w6-wp3h-vq8g", - "modified": "2024-08-02T15:31:16Z", + "modified": "2024-09-04T12:30:36Z", "published": "2024-04-25T18:30:39Z", "aliases": [ "CVE-2024-0874" @@ -67,6 +67,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:4850" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6009" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-0874" diff --git a/advisories/unreviewed/2024/02/GHSA-6vr7-3j3q-8546/GHSA-6vr7-3j3q-8546.json b/advisories/unreviewed/2024/02/GHSA-6vr7-3j3q-8546/GHSA-6vr7-3j3q-8546.json index a427f4f1157..d2ebda536e6 100644 --- a/advisories/unreviewed/2024/02/GHSA-6vr7-3j3q-8546/GHSA-6vr7-3j3q-8546.json +++ b/advisories/unreviewed/2024/02/GHSA-6vr7-3j3q-8546/GHSA-6vr7-3j3q-8546.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6vr7-3j3q-8546", - "modified": "2024-06-26T00:31:34Z", + "modified": "2024-09-04T12:30:36Z", "published": "2024-02-20T21:30:25Z", "aliases": [ "CVE-2023-52435" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52435" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0d3ffbbf8631d6db0552f46250015648991c856f" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/23d05d563b7e7b0314e65c8e882bc27eac2da8e7" diff --git a/advisories/unreviewed/2024/07/GHSA-cm3g-9rxc-2598/GHSA-cm3g-9rxc-2598.json b/advisories/unreviewed/2024/07/GHSA-cm3g-9rxc-2598/GHSA-cm3g-9rxc-2598.json index 007d3a358d1..56dd8ec00e3 100644 --- a/advisories/unreviewed/2024/07/GHSA-cm3g-9rxc-2598/GHSA-cm3g-9rxc-2598.json +++ b/advisories/unreviewed/2024/07/GHSA-cm3g-9rxc-2598/GHSA-cm3g-9rxc-2598.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cm3g-9rxc-2598", - "modified": "2024-08-08T18:31:20Z", + "modified": "2024-09-04T12:30:36Z", "published": "2024-07-29T18:30:38Z", "aliases": [ "CVE-2024-41098" @@ -21,10 +21,22 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41098" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0f0d37c154bb108730c90a91aa31e3170e827962" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/119c97ace2a9ffcf4dc09a23bb057d6c281aff28" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/221e3b1297e74fdec32d0f572f4dcb2260a0a2af" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/56e62977eaaae3eb7122ee2cf9b720b6703114a9" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/5d92c7c566dc76d96e0e19e481d926bbe6631c1e" @@ -32,6 +44,14 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/8a8ff7e3b736a70d7b7c8764cbcd2724d4079ec8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d9c4df80b1b009de1eb77c07e3bb4d45bd212aa5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e83405e75d90694ee6a5d898f7f0473ac2686054" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-fv42-492h-89pj/GHSA-fv42-492h-89pj.json b/advisories/unreviewed/2024/07/GHSA-fv42-492h-89pj/GHSA-fv42-492h-89pj.json index ae3b43e670e..69248f74dcb 100644 --- a/advisories/unreviewed/2024/07/GHSA-fv42-492h-89pj/GHSA-fv42-492h-89pj.json +++ b/advisories/unreviewed/2024/07/GHSA-fv42-492h-89pj/GHSA-fv42-492h-89pj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fv42-492h-89pj", - "modified": "2024-07-18T09:30:50Z", + "modified": "2024-09-04T12:30:36Z", "published": "2024-07-18T09:30:50Z", "aliases": [ "CVE-2024-41011" @@ -18,6 +18,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41011" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/009c4d78bcf07c4ac2e3dd9f275b4eaa72b4f884" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/4b4cff994a27ebf7bd3fb9a798a1cdfa8d01b724" @@ -30,9 +34,17 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/89fffbdf535ce659c1a26b51ad62070566e33b28" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8ad4838040e5515939c071a0f511ce2661a0889d" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/be4a2a81b6b90d1a47eaeaace4cc8e2cb57b96c7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f7276cdc1912325b64c33fcb1361952c06e55f63" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-mhjg-j5hq-m4p7/GHSA-mhjg-j5hq-m4p7.json b/advisories/unreviewed/2024/07/GHSA-mhjg-j5hq-m4p7/GHSA-mhjg-j5hq-m4p7.json index 066b1c8eae8..b71bdf7e6c0 100644 --- a/advisories/unreviewed/2024/07/GHSA-mhjg-j5hq-m4p7/GHSA-mhjg-j5hq-m4p7.json +++ b/advisories/unreviewed/2024/07/GHSA-mhjg-j5hq-m4p7/GHSA-mhjg-j5hq-m4p7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mhjg-j5hq-m4p7", - "modified": "2024-07-30T21:31:27Z", + "modified": "2024-09-04T12:30:36Z", "published": "2024-07-30T09:32:04Z", "aliases": [ "CVE-2024-42228" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42228" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3b505759447637dcccb50cbd98ec6f8d2a04fc46" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/855ae72c20310e5402b2317fc537d911e87537ef" @@ -29,6 +33,22 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/88a9a467c548d0b3c7761b4fd54a68e70f9c0944" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9ee1534ecdd5b4c013064663502d7fde824d2144" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d35cf41c8eb5d9fe95b21ae6ee2910f9ba4878e8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/da6a85d197888067e8d38b5d22c986b5b5cab712" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/df02642c21c984303fe34c3f7d72965792fb1a15" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/f8f120b3de48b8b6bdf8988a9b334c2d61c17440" diff --git a/advisories/unreviewed/2024/08/GHSA-392h-pcr9-7j4w/GHSA-392h-pcr9-7j4w.json b/advisories/unreviewed/2024/08/GHSA-392h-pcr9-7j4w/GHSA-392h-pcr9-7j4w.json index 10fd7a2f1cb..a959fad20bc 100644 --- a/advisories/unreviewed/2024/08/GHSA-392h-pcr9-7j4w/GHSA-392h-pcr9-7j4w.json +++ b/advisories/unreviewed/2024/08/GHSA-392h-pcr9-7j4w/GHSA-392h-pcr9-7j4w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-392h-pcr9-7j4w", - "modified": "2024-08-26T12:31:19Z", + "modified": "2024-09-04T12:30:36Z", "published": "2024-08-26T12:31:19Z", "aliases": [ "CVE-2024-43891" @@ -18,6 +18,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43891" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4ed03758ddf0b19d69eed69386d65a92d0091e0c" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/531dc6780d94245af037c25c2371c8caf652f0f9" diff --git a/advisories/unreviewed/2024/08/GHSA-6xgm-r8j8-r5hq/GHSA-6xgm-r8j8-r5hq.json b/advisories/unreviewed/2024/08/GHSA-6xgm-r8j8-r5hq/GHSA-6xgm-r8j8-r5hq.json index e196856b8f3..41a2f120517 100644 --- a/advisories/unreviewed/2024/08/GHSA-6xgm-r8j8-r5hq/GHSA-6xgm-r8j8-r5hq.json +++ b/advisories/unreviewed/2024/08/GHSA-6xgm-r8j8-r5hq/GHSA-6xgm-r8j8-r5hq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6xgm-r8j8-r5hq", - "modified": "2024-08-22T18:31:20Z", + "modified": "2024-09-04T12:30:36Z", "published": "2024-08-17T12:30:33Z", "aliases": [ "CVE-2024-43853" @@ -21,10 +21,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43853" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/10aeaa47e4aa2432f29b3e5376df96d7dac5537a" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/1be59c97c83ccd67a519d8a49486b3a8a73ca28a" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/27d6dbdc6485d68075a0ebf8544d6425c1ed84bb" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/29a8d4e02fd4840028c38ceb1536cc8f82a257d4" @@ -33,6 +41,14 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/29ac1d238b3bf126af36037df80d7ecc4822341e" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4e8d6ac8fc9f843e940ab7389db8136634e07989" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/688325078a8b5badd6e07ae22b27cd04e9947aec" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/96226fbed566f3f686f53a489a29846f2d538080" diff --git a/advisories/unreviewed/2024/08/GHSA-cw5c-5w4g-ff67/GHSA-cw5c-5w4g-ff67.json b/advisories/unreviewed/2024/08/GHSA-cw5c-5w4g-ff67/GHSA-cw5c-5w4g-ff67.json index c18ebdf08b3..86c04a6fec5 100644 --- a/advisories/unreviewed/2024/08/GHSA-cw5c-5w4g-ff67/GHSA-cw5c-5w4g-ff67.json +++ b/advisories/unreviewed/2024/08/GHSA-cw5c-5w4g-ff67/GHSA-cw5c-5w4g-ff67.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cw5c-5w4g-ff67", - "modified": "2024-08-31T15:31:23Z", + "modified": "2024-09-04T12:30:36Z", "published": "2024-08-31T15:31:23Z", "aliases": [ "CVE-2024-44946" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nkcm: Serialise kcm_sendmsg() for the same socket.\n\nsyzkaller reported UAF in kcm_release(). [0]\n\nThe scenario is\n\n 1. Thread A builds a skb with MSG_MORE and sets kcm->seq_skb.\n\n 2. Thread A resumes building skb from kcm->seq_skb but is blocked\n by sk_stream_wait_memory()\n\n 3. Thread B calls sendmsg() concurrently, finishes building kcm->seq_skb\n and puts the skb to the write queue\n\n 4. Thread A faces an error and finally frees skb that is already in the\n write queue\n\n 5. kcm_release() does double-free the skb in the write queue\n\nWhen a thread is building a MSG_MORE skb, another thread must not touch it.\n\nLet's add a per-sk mutex and serialise kcm_sendmsg().\n\n[0]:\nBUG: KASAN: slab-use-after-free in __skb_unlink include/linux/skbuff.h:2366 [inline]\nBUG: KASAN: slab-use-after-free in __skb_dequeue include/linux/skbuff.h:2385 [inline]\nBUG: KASAN: slab-use-after-free in __skb_queue_purge_reason include/linux/skbuff.h:3175 [inline]\nBUG: KASAN: slab-use-after-free in __skb_queue_purge include/linux/skbuff.h:3181 [inline]\nBUG: KASAN: slab-use-after-free in kcm_release+0x170/0x4c8 net/kcm/kcmsock.c:1691\nRead of size 8 at addr ffff0000ced0fc80 by task syz-executor329/6167\n\nCPU: 1 PID: 6167 Comm: syz-executor329 Tainted: G B 6.8.0-rc5-syzkaller-g9abbc24128bc #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/25/2024\nCall trace:\n dump_backtrace+0x1b8/0x1e4 arch/arm64/kernel/stacktrace.c:291\n show_stack+0x2c/0x3c arch/arm64/kernel/stacktrace.c:298\n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0xd0/0x124 lib/dump_stack.c:106\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0x178/0x518 mm/kasan/report.c:488\n kasan_report+0xd8/0x138 mm/kasan/report.c:601\n __asan_report_load8_noabort+0x20/0x2c mm/kasan/report_generic.c:381\n __skb_unlink include/linux/skbuff.h:2366 [inline]\n __skb_dequeue include/linux/skbuff.h:2385 [inline]\n __skb_queue_purge_reason include/linux/skbuff.h:3175 [inline]\n __skb_queue_purge include/linux/skbuff.h:3181 [inline]\n kcm_release+0x170/0x4c8 net/kcm/kcmsock.c:1691\n __sock_release net/socket.c:659 [inline]\n sock_close+0xa4/0x1e8 net/socket.c:1421\n __fput+0x30c/0x738 fs/file_table.c:376\n ____fput+0x20/0x30 fs/file_table.c:404\n task_work_run+0x230/0x2e0 kernel/task_work.c:180\n exit_task_work include/linux/task_work.h:38 [inline]\n do_exit+0x618/0x1f64 kernel/exit.c:871\n do_group_exit+0x194/0x22c kernel/exit.c:1020\n get_signal+0x1500/0x15ec kernel/signal.c:2893\n do_signal+0x23c/0x3b44 arch/arm64/kernel/signal.c:1249\n do_notify_resume+0x74/0x1f4 arch/arm64/kernel/entry-common.c:148\n exit_to_user_mode_prepare arch/arm64/kernel/entry-common.c:169 [inline]\n exit_to_user_mode arch/arm64/kernel/entry-common.c:178 [inline]\n el0_svc+0xac/0x168 arch/arm64/kernel/entry-common.c:713\n el0t_64_sync_handler+0x84/0xfc arch/arm64/kernel/entry-common.c:730\n el0t_64_sync+0x190/0x194 arch/arm64/kernel/entry.S:598\n\nAllocated by task 6166:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x40/0x78 mm/kasan/common.c:68\n kasan_save_alloc_info+0x70/0x84 mm/kasan/generic.c:626\n unpoison_slab_object mm/kasan/common.c:314 [inline]\n __kasan_slab_alloc+0x74/0x8c mm/kasan/common.c:340\n kasan_slab_alloc include/linux/kasan.h:201 [inline]\n slab_post_alloc_hook mm/slub.c:3813 [inline]\n slab_alloc_node mm/slub.c:3860 [inline]\n kmem_cache_alloc_node+0x204/0x4c0 mm/slub.c:3903\n __alloc_skb+0x19c/0x3d8 net/core/skbuff.c:641\n alloc_skb include/linux/skbuff.h:1296 [inline]\n kcm_sendmsg+0x1d3c/0x2124 net/kcm/kcmsock.c:783\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg net/socket.c:745 [inline]\n sock_sendmsg+0x220/0x2c0 net/socket.c:768\n splice_to_socket+0x7cc/0xd58 fs/splice.c:889\n do_splice_from fs/splice.c:941 [inline]\n direct_splice_actor+0xec/0x1d8 fs/splice.c:1164\n splice_direct_to_actor+0x438/0xa0c fs/splice.c:1108\n do_splice_direct_actor \n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -22,6 +25,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/00425508f30baa5ab6449a1f478480ca7cffa6da" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6633b17840bf828921254d788ccd15602843fe9b" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/72da240aafb142630cf16adc803ccdacb3780849" @@ -30,16 +37,28 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/807067bf014d4a3ae2cc55bd3de16f22a01eb580" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8c9cdbf600143bd6835c8b8351e5ac956da79aec" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/9c8d544ed619f704e2b70e63e08ab75630c2ea23" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/eb06c8d3022ce6738711191c89f9b3e9cfb91914" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fa6c23fe6dcac8c8bd63920ee8681292a2bd544e" } ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-31T14:15:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-f2jj-rmrg-9rjx/GHSA-f2jj-rmrg-9rjx.json b/advisories/unreviewed/2024/08/GHSA-f2jj-rmrg-9rjx/GHSA-f2jj-rmrg-9rjx.json index 37df2efa239..75e5aa6f4a7 100644 --- a/advisories/unreviewed/2024/08/GHSA-f2jj-rmrg-9rjx/GHSA-f2jj-rmrg-9rjx.json +++ b/advisories/unreviewed/2024/08/GHSA-f2jj-rmrg-9rjx/GHSA-f2jj-rmrg-9rjx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f2jj-rmrg-9rjx", - "modified": "2024-08-29T18:31:35Z", + "modified": "2024-09-04T12:30:36Z", "published": "2024-08-26T09:30:44Z", "aliases": [ "CVE-2024-43884" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/064dd929c76532359d2905d90a7c12348043cfd4" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/11b4b0e63f2621b33b2e107407a7d67a65994ca1" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/538fd3921afac97158d4177139a0ad39f056dbb2" @@ -33,6 +37,18 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/5da2884292329bc9be32a7778e0e119f06abe503" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/90e1ff1c15e5a8f3023ca8266e3a85869ed03ee9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/951d6cb5eaac5130d076c728f2a6db420621afdb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9df9783bd85610d3d6e126a1aca221531f6f6dcb" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/ee0799103b1ae4bcfd80dc11a15df085f6ee1b61" diff --git a/advisories/unreviewed/2024/08/GHSA-j3xp-78w6-p4vh/GHSA-j3xp-78w6-p4vh.json b/advisories/unreviewed/2024/08/GHSA-j3xp-78w6-p4vh/GHSA-j3xp-78w6-p4vh.json index 84fbdc1e3b1..73f4ea154c8 100644 --- a/advisories/unreviewed/2024/08/GHSA-j3xp-78w6-p4vh/GHSA-j3xp-78w6-p4vh.json +++ b/advisories/unreviewed/2024/08/GHSA-j3xp-78w6-p4vh/GHSA-j3xp-78w6-p4vh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j3xp-78w6-p4vh", - "modified": "2024-08-22T18:31:20Z", + "modified": "2024-09-04T12:30:36Z", "published": "2024-08-17T09:30:25Z", "aliases": [ "CVE-2024-42314" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/b7859ff398b6b656e1689daa860eb34837b4bb89" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c1cc3326e27b0bd7a2806b40bc48e49afaf951e7" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/c205565e0f2f439f278a4a94ee97b67ef7b56ae8" diff --git a/advisories/unreviewed/2024/09/GHSA-2745-8q5m-h58w/GHSA-2745-8q5m-h58w.json b/advisories/unreviewed/2024/09/GHSA-2745-8q5m-h58w/GHSA-2745-8q5m-h58w.json index 1f7c57a43d9..67309ae59e0 100644 --- a/advisories/unreviewed/2024/09/GHSA-2745-8q5m-h58w/GHSA-2745-8q5m-h58w.json +++ b/advisories/unreviewed/2024/09/GHSA-2745-8q5m-h58w/GHSA-2745-8q5m-h58w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2745-8q5m-h58w", - "modified": "2024-09-02T00:30:35Z", + "modified": "2024-09-04T12:30:36Z", "published": "2024-09-02T00:30:35Z", "aliases": [ "CVE-2024-45270" ], "details": "WordPress plugin \"Carousel Slider\" provided by Sayful Islam contains a cross-site request forgery vulnerability on Hero image selection feature. While logged in to the WordPress site with Carousel Slider plugin enabled, accessing a crafted page may cause a user to alter the contents of the WordPress site.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-02T00:15:11Z" diff --git a/advisories/unreviewed/2024/09/GHSA-5g3f-cpvx-g37c/GHSA-5g3f-cpvx-g37c.json b/advisories/unreviewed/2024/09/GHSA-5g3f-cpvx-g37c/GHSA-5g3f-cpvx-g37c.json new file mode 100644 index 00000000000..b09149558a4 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5g3f-cpvx-g37c/GHSA-5g3f-cpvx-g37c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g3f-cpvx-g37c", + "modified": "2024-09-04T12:30:37Z", + "published": "2024-09-04T12:30:37Z", + "aliases": [ + "CVE-2024-8413" + ], + "details": "Cross Site Scripting (XSS) vulnerability through the action parameter in index.php. Affected product codebase https://github.com/Bioshox/Raspcontrol and forks such as https://github.com/harmon25/raspcontrol . An attacker could exploit this vulnerability by sending a specially crafted JavaScript payload to an authenticated user and partially hijacking their session details.\n\nReferences list", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8413" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-xss-raspcontrol" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T11:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6fhp-x3v7-v4f9/GHSA-6fhp-x3v7-v4f9.json b/advisories/unreviewed/2024/09/GHSA-6fhp-x3v7-v4f9/GHSA-6fhp-x3v7-v4f9.json index 94711688a07..790729cc013 100644 --- a/advisories/unreviewed/2024/09/GHSA-6fhp-x3v7-v4f9/GHSA-6fhp-x3v7-v4f9.json +++ b/advisories/unreviewed/2024/09/GHSA-6fhp-x3v7-v4f9/GHSA-6fhp-x3v7-v4f9.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6fhp-x3v7-v4f9", - "modified": "2024-09-02T06:30:49Z", + "modified": "2024-09-04T12:30:37Z", "published": "2024-09-02T06:30:49Z", "aliases": [ "CVE-2024-43776" ], "details": "SQL Injection in mock exam function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the qlevel parameter.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-7cvv-34h5-xg2q/GHSA-7cvv-34h5-xg2q.json b/advisories/unreviewed/2024/09/GHSA-7cvv-34h5-xg2q/GHSA-7cvv-34h5-xg2q.json index 37c16c693dd..bc93c39ba5b 100644 --- a/advisories/unreviewed/2024/09/GHSA-7cvv-34h5-xg2q/GHSA-7cvv-34h5-xg2q.json +++ b/advisories/unreviewed/2024/09/GHSA-7cvv-34h5-xg2q/GHSA-7cvv-34h5-xg2q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7cvv-34h5-xg2q", - "modified": "2024-09-02T00:30:35Z", + "modified": "2024-09-04T12:30:36Z", "published": "2024-09-02T00:30:35Z", "aliases": [ "CVE-2024-45269" ], "details": "WordPress plugin \"Carousel Slider\" provided by Sayful Islam contains a cross-site request forgery vulnerability on Carousel image selection feature. While logged in to the WordPress site with Carousel Slider plugin enabled, accessing a crafted page may cause a user to alter the contents of the WordPress site.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-02T00:15:11Z" diff --git a/advisories/unreviewed/2024/09/GHSA-f389-p3hg-3w6f/GHSA-f389-p3hg-3w6f.json b/advisories/unreviewed/2024/09/GHSA-f389-p3hg-3w6f/GHSA-f389-p3hg-3w6f.json index ad90ca63794..4415ad0f8af 100644 --- a/advisories/unreviewed/2024/09/GHSA-f389-p3hg-3w6f/GHSA-f389-p3hg-3w6f.json +++ b/advisories/unreviewed/2024/09/GHSA-f389-p3hg-3w6f/GHSA-f389-p3hg-3w6f.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f389-p3hg-3w6f", - "modified": "2024-09-02T06:30:49Z", + "modified": "2024-09-04T12:30:37Z", "published": "2024-09-02T06:30:49Z", "aliases": [ "CVE-2024-43773" ], "details": "SQL Injection in download class learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the cstr parameter.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-h3f9-j6v8-7wfm/GHSA-h3f9-j6v8-7wfm.json b/advisories/unreviewed/2024/09/GHSA-h3f9-j6v8-7wfm/GHSA-h3f9-j6v8-7wfm.json index 698a679213c..6f8fa7a795b 100644 --- a/advisories/unreviewed/2024/09/GHSA-h3f9-j6v8-7wfm/GHSA-h3f9-j6v8-7wfm.json +++ b/advisories/unreviewed/2024/09/GHSA-h3f9-j6v8-7wfm/GHSA-h3f9-j6v8-7wfm.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h3f9-j6v8-7wfm", - "modified": "2024-09-02T06:30:49Z", + "modified": "2024-09-04T12:30:37Z", "published": "2024-09-02T06:30:49Z", "aliases": [ "CVE-2024-43774" ], "details": "SQL Injection in download personal learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the uid parameter.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-m258-frwv-27f2/GHSA-m258-frwv-27f2.json b/advisories/unreviewed/2024/09/GHSA-m258-frwv-27f2/GHSA-m258-frwv-27f2.json new file mode 100644 index 00000000000..0f224d9ecbf --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-m258-frwv-27f2/GHSA-m258-frwv-27f2.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m258-frwv-27f2", + "modified": "2024-09-04T12:30:37Z", + "published": "2024-09-04T12:30:37Z", + "aliases": [ + "CVE-2024-7821" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7821" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T10:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-r6vj-38w8-wv4c/GHSA-r6vj-38w8-wv4c.json b/advisories/unreviewed/2024/09/GHSA-r6vj-38w8-wv4c/GHSA-r6vj-38w8-wv4c.json index 3799925674c..62f6330fa08 100644 --- a/advisories/unreviewed/2024/09/GHSA-r6vj-38w8-wv4c/GHSA-r6vj-38w8-wv4c.json +++ b/advisories/unreviewed/2024/09/GHSA-r6vj-38w8-wv4c/GHSA-r6vj-38w8-wv4c.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r6vj-38w8-wv4c", - "modified": "2024-09-02T06:30:49Z", + "modified": "2024-09-04T12:30:37Z", "published": "2024-09-02T06:30:49Z", "aliases": [ "CVE-2024-43775" ], "details": "SQL Injection in search course titles function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the search parameter.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-wp4r-c6wp-5m5q/GHSA-wp4r-c6wp-5m5q.json b/advisories/unreviewed/2024/09/GHSA-wp4r-c6wp-5m5q/GHSA-wp4r-c6wp-5m5q.json index b20254c49a8..75b33cf8726 100644 --- a/advisories/unreviewed/2024/09/GHSA-wp4r-c6wp-5m5q/GHSA-wp4r-c6wp-5m5q.json +++ b/advisories/unreviewed/2024/09/GHSA-wp4r-c6wp-5m5q/GHSA-wp4r-c6wp-5m5q.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wp4r-c6wp-5m5q", - "modified": "2024-09-02T06:30:49Z", + "modified": "2024-09-04T12:30:37Z", "published": "2024-09-02T06:30:49Z", "aliases": [ "CVE-2024-43772" ], "details": "SQL Injection in download student learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the uid parameter.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-xjwh-3rm6-w25h/GHSA-xjwh-3rm6-w25h.json b/advisories/unreviewed/2024/09/GHSA-xjwh-3rm6-w25h/GHSA-xjwh-3rm6-w25h.json index b8ec2856c78..ec7f55dca7f 100644 --- a/advisories/unreviewed/2024/09/GHSA-xjwh-3rm6-w25h/GHSA-xjwh-3rm6-w25h.json +++ b/advisories/unreviewed/2024/09/GHSA-xjwh-3rm6-w25h/GHSA-xjwh-3rm6-w25h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xjwh-3rm6-w25h", - "modified": "2024-09-02T18:31:25Z", + "modified": "2024-09-04T12:30:37Z", "published": "2024-09-02T18:31:25Z", "aliases": [ "CVE-2024-44947" @@ -22,14 +22,30 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/18a067240817bee8a9360539af5d79a4bf5398a5" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/33168db352c7b56ae18aa55c2cae1a1c5905d30e" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/3c0da3d163eb32f1f91891efaade027fa9b245b9" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4690e2171f651e2b415e3941ce17f2f7b813aff6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/49934861514d36d0995be8e81bb3312a499d8d9a" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/831433527773e665bdb635ab5783d0b95d1246f4" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8c78303eafbf85a728dd84d1750e89240c677dd9" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/ac42e0f0eb66af966015ee33fd355bc6f5d80cd6"