From 71a4f43480ce6a2f794f0ba86d55900f06d6307a Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 29 Mar 2024 06:31:55 +0000 Subject: [PATCH] Publish Advisories GHSA-9w38-p64v-xpmv GHSA-c5q2-7r4c-mv6g GHSA-hhhv-q57g-882q GHSA-xjp4-hw94-mvp5 GHSA-2vp3-qj4j-9chv GHSA-5pj4-f8gh-j3mr GHSA-6h48-8w2f-5w94 GHSA-9764-6h7c-x5rv GHSA-gg9c-7j6m-3qq2 GHSA-m3xv-gj54-x2wv GHSA-p84f-xgwp-4frf GHSA-q75f-2pp5-9phj GHSA-qccw-wmvp-8pv9 GHSA-rg8g-7365-wq9j --- .../GHSA-9w38-p64v-xpmv.json | 6 ++- .../GHSA-c5q2-7r4c-mv6g.json | 6 ++- .../GHSA-hhhv-q57g-882q.json | 6 ++- .../GHSA-xjp4-hw94-mvp5.json | 6 ++- .../GHSA-2vp3-qj4j-9chv.json | 46 +++++++++++++++++ .../GHSA-5pj4-f8gh-j3mr.json | 6 ++- .../GHSA-6h48-8w2f-5w94.json | 39 +++++++++++++++ .../GHSA-9764-6h7c-x5rv.json | 42 ++++++++++++++++ .../GHSA-gg9c-7j6m-3qq2.json | 6 ++- .../GHSA-m3xv-gj54-x2wv.json | 50 +++++++++++++++++++ .../GHSA-p84f-xgwp-4frf.json | 42 ++++++++++++++++ .../GHSA-q75f-2pp5-9phj.json | 6 ++- .../GHSA-qccw-wmvp-8pv9.json | 6 ++- .../GHSA-rg8g-7365-wq9j.json | 42 ++++++++++++++++ 14 files changed, 301 insertions(+), 8 deletions(-) create mode 100644 advisories/unreviewed/2024/03/GHSA-2vp3-qj4j-9chv/GHSA-2vp3-qj4j-9chv.json create mode 100644 advisories/unreviewed/2024/03/GHSA-6h48-8w2f-5w94/GHSA-6h48-8w2f-5w94.json create mode 100644 advisories/unreviewed/2024/03/GHSA-9764-6h7c-x5rv/GHSA-9764-6h7c-x5rv.json create mode 100644 advisories/unreviewed/2024/03/GHSA-m3xv-gj54-x2wv/GHSA-m3xv-gj54-x2wv.json create mode 100644 advisories/unreviewed/2024/03/GHSA-p84f-xgwp-4frf/GHSA-p84f-xgwp-4frf.json create mode 100644 advisories/unreviewed/2024/03/GHSA-rg8g-7365-wq9j/GHSA-rg8g-7365-wq9j.json diff --git a/advisories/github-reviewed/2024/03/GHSA-9w38-p64v-xpmv/GHSA-9w38-p64v-xpmv.json b/advisories/github-reviewed/2024/03/GHSA-9w38-p64v-xpmv/GHSA-9w38-p64v-xpmv.json index 31d9c161e41..27e36cf1fce 100644 --- a/advisories/github-reviewed/2024/03/GHSA-9w38-p64v-xpmv/GHSA-9w38-p64v-xpmv.json +++ b/advisories/github-reviewed/2024/03/GHSA-9w38-p64v-xpmv/GHSA-9w38-p64v-xpmv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9w38-p64v-xpmv", - "modified": "2024-03-21T18:59:08Z", + "modified": "2024-03-29T06:30:30Z", "published": "2024-03-21T09:31:14Z", "aliases": [ "CVE-2024-29133" @@ -52,6 +52,10 @@ "type": "WEB", "url": "https://lists.apache.org/thread/ccb9w15bscznh6tnp3wsvrrj9crbszh2" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YD4AFTIIQW662LUAQRMWS6BBKYSZG3YS" + }, { "type": "PACKAGE", "url": "apache/commons-configuration" diff --git a/advisories/github-reviewed/2024/03/GHSA-c5q2-7r4c-mv6g/GHSA-c5q2-7r4c-mv6g.json b/advisories/github-reviewed/2024/03/GHSA-c5q2-7r4c-mv6g/GHSA-c5q2-7r4c-mv6g.json index 06085810202..21ba90f4633 100644 --- a/advisories/github-reviewed/2024/03/GHSA-c5q2-7r4c-mv6g/GHSA-c5q2-7r4c-mv6g.json +++ b/advisories/github-reviewed/2024/03/GHSA-c5q2-7r4c-mv6g/GHSA-c5q2-7r4c-mv6g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c5q2-7r4c-mv6g", - "modified": "2024-03-23T03:30:25Z", + "modified": "2024-03-29T06:30:30Z", "published": "2024-03-07T22:54:44Z", "aliases": [ "CVE-2024-28180" @@ -98,6 +98,10 @@ "type": "PACKAGE", "url": "https://github.com/go-jose/go-jose" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I6MMWFBOXJA6ZCXNVPDFJ4XMK5PVG5RG" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KXKGNCRU7OTM5AHC7YIYBNOWI742PRMY" diff --git a/advisories/github-reviewed/2024/03/GHSA-hhhv-q57g-882q/GHSA-hhhv-q57g-882q.json b/advisories/github-reviewed/2024/03/GHSA-hhhv-q57g-882q/GHSA-hhhv-q57g-882q.json index e8ff0fcd1a0..11e7518c1c3 100644 --- a/advisories/github-reviewed/2024/03/GHSA-hhhv-q57g-882q/GHSA-hhhv-q57g-882q.json +++ b/advisories/github-reviewed/2024/03/GHSA-hhhv-q57g-882q/GHSA-hhhv-q57g-882q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hhhv-q57g-882q", - "modified": "2024-03-23T03:30:25Z", + "modified": "2024-03-29T06:30:29Z", "published": "2024-03-07T17:40:57Z", "aliases": [ "CVE-2024-28176" @@ -122,6 +122,10 @@ "type": "PACKAGE", "url": "https://github.com/panva/jose" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I6MMWFBOXJA6ZCXNVPDFJ4XMK5PVG5RG" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KXKGNCRU7OTM5AHC7YIYBNOWI742PRMY" diff --git a/advisories/github-reviewed/2024/03/GHSA-xjp4-hw94-mvp5/GHSA-xjp4-hw94-mvp5.json b/advisories/github-reviewed/2024/03/GHSA-xjp4-hw94-mvp5/GHSA-xjp4-hw94-mvp5.json index edb89751c1f..4f9af50bd5f 100644 --- a/advisories/github-reviewed/2024/03/GHSA-xjp4-hw94-mvp5/GHSA-xjp4-hw94-mvp5.json +++ b/advisories/github-reviewed/2024/03/GHSA-xjp4-hw94-mvp5/GHSA-xjp4-hw94-mvp5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xjp4-hw94-mvp5", - "modified": "2024-03-21T18:58:52Z", + "modified": "2024-03-29T06:30:30Z", "published": "2024-03-21T09:31:14Z", "aliases": [ "CVE-2024-29131" @@ -55,6 +55,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/03nzzzjn4oknyw5y0871tw7ltj0t3r37" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YD4AFTIIQW662LUAQRMWS6BBKYSZG3YS" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-2vp3-qj4j-9chv/GHSA-2vp3-qj4j-9chv.json b/advisories/unreviewed/2024/03/GHSA-2vp3-qj4j-9chv/GHSA-2vp3-qj4j-9chv.json new file mode 100644 index 00000000000..0edbe7c3294 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-2vp3-qj4j-9chv/GHSA-2vp3-qj4j-9chv.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2vp3-qj4j-9chv", + "modified": "2024-03-29T06:30:30Z", + "published": "2024-03-29T06:30:30Z", + "aliases": [ + "CVE-2024-2844" + ], + "details": "The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient user validation on the ajax_cancel_appointment() function in all versions up to, and including, 3.11.18. This makes it possible for unauthenticated attackers to cancel other users orders.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2844" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/easy-appointments/trunk/src/ajax.php#L380" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3059359%40easy-appointments&new=3059359%40easy-appointments&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c0d8ac01-ac73-47ea-839b-edc820436f27?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-5pj4-f8gh-j3mr/GHSA-5pj4-f8gh-j3mr.json b/advisories/unreviewed/2024/03/GHSA-5pj4-f8gh-j3mr/GHSA-5pj4-f8gh-j3mr.json index 66d663fcbce..8429960d628 100644 --- a/advisories/unreviewed/2024/03/GHSA-5pj4-f8gh-j3mr/GHSA-5pj4-f8gh-j3mr.json +++ b/advisories/unreviewed/2024/03/GHSA-5pj4-f8gh-j3mr/GHSA-5pj4-f8gh-j3mr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5pj4-f8gh-j3mr", - "modified": "2024-03-29T03:30:29Z", + "modified": "2024-03-29T06:30:30Z", "published": "2024-03-26T21:30:48Z", "aliases": [ "CVE-2024-2886" @@ -33,6 +33,10 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G3RKI7VTQSIAI3PVZGRCHOSELTQXQ5FQ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IQMRHKDEG4J7TMRRRGUGW6GS4MVBX5IT" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-6h48-8w2f-5w94/GHSA-6h48-8w2f-5w94.json b/advisories/unreviewed/2024/03/GHSA-6h48-8w2f-5w94/GHSA-6h48-8w2f-5w94.json new file mode 100644 index 00000000000..76256303686 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-6h48-8w2f-5w94/GHSA-6h48-8w2f-5w94.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6h48-8w2f-5w94", + "modified": "2024-03-29T06:30:30Z", + "published": "2024-03-29T06:30:30Z", + "aliases": [ + "CVE-2024-28960" + ], + "details": "An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28960" + }, + { + "type": "WEB", + "url": "https://github.com/Mbed-TLS/mbedtls-docs/blob/main/security-advisories/mbedtls-security-advisory-2024-03.md" + }, + { + "type": "WEB", + "url": "https://mbed-tls.readthedocs.io/en/latest/tech-updates/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T06:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-9764-6h7c-x5rv/GHSA-9764-6h7c-x5rv.json b/advisories/unreviewed/2024/03/GHSA-9764-6h7c-x5rv/GHSA-9764-6h7c-x5rv.json new file mode 100644 index 00000000000..533f9524d1a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-9764-6h7c-x5rv/GHSA-9764-6h7c-x5rv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9764-6h7c-x5rv", + "modified": "2024-03-29T06:30:30Z", + "published": "2024-03-29T06:30:30Z", + "aliases": [ + "CVE-2024-2842" + ], + "details": "The Easy Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ea_full_calendar' shortcode in all versions up to, and including, 3.11.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2842" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3059359%40easy-appointments&new=3059359%40easy-appointments&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9e1514c8-3752-4d0a-87a3-3f245a7cb914?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T06:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-gg9c-7j6m-3qq2/GHSA-gg9c-7j6m-3qq2.json b/advisories/unreviewed/2024/03/GHSA-gg9c-7j6m-3qq2/GHSA-gg9c-7j6m-3qq2.json index 5b6c32c8610..11b40501419 100644 --- a/advisories/unreviewed/2024/03/GHSA-gg9c-7j6m-3qq2/GHSA-gg9c-7j6m-3qq2.json +++ b/advisories/unreviewed/2024/03/GHSA-gg9c-7j6m-3qq2/GHSA-gg9c-7j6m-3qq2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gg9c-7j6m-3qq2", - "modified": "2024-03-29T03:30:28Z", + "modified": "2024-03-29T06:30:30Z", "published": "2024-03-26T21:30:48Z", "aliases": [ "CVE-2024-2883" @@ -33,6 +33,10 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G3RKI7VTQSIAI3PVZGRCHOSELTQXQ5FQ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IQMRHKDEG4J7TMRRRGUGW6GS4MVBX5IT" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-m3xv-gj54-x2wv/GHSA-m3xv-gj54-x2wv.json b/advisories/unreviewed/2024/03/GHSA-m3xv-gj54-x2wv/GHSA-m3xv-gj54-x2wv.json new file mode 100644 index 00000000000..ab83df6d2f4 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-m3xv-gj54-x2wv/GHSA-m3xv-gj54-x2wv.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3xv-gj54-x2wv", + "modified": "2024-03-29T06:30:30Z", + "published": "2024-03-29T06:30:30Z", + "aliases": [ + "CVE-2024-2475" + ], + "details": "The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2475" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/media-library-assistant/trunk/includes/class-mla-shortcode-support.php#L1517" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/media-library-assistant/trunk/includes/class-mla-shortcode-support.php#L1535" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/media-library-assistant/trunk/includes/class-mla-shortcode-support.php#L2166" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/63ed73c9-2b61-4811-ba7f-1803982f17bc?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T05:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-p84f-xgwp-4frf/GHSA-p84f-xgwp-4frf.json b/advisories/unreviewed/2024/03/GHSA-p84f-xgwp-4frf/GHSA-p84f-xgwp-4frf.json new file mode 100644 index 00000000000..65ed22badb3 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-p84f-xgwp-4frf/GHSA-p84f-xgwp-4frf.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p84f-xgwp-4frf", + "modified": "2024-03-29T06:30:30Z", + "published": "2024-03-29T06:30:30Z", + "aliases": [ + "CVE-2024-2936" + ], + "details": "The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id attribute of widgets in all versions up to, and including, 1.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2936" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3059286%40sydney-toolbox&new=3059286%40sydney-toolbox&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0b20d638-82cb-48ce-96fa-fd42d06f649f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-q75f-2pp5-9phj/GHSA-q75f-2pp5-9phj.json b/advisories/unreviewed/2024/03/GHSA-q75f-2pp5-9phj/GHSA-q75f-2pp5-9phj.json index 4ff5035b3c9..26e2c07b417 100644 --- a/advisories/unreviewed/2024/03/GHSA-q75f-2pp5-9phj/GHSA-q75f-2pp5-9phj.json +++ b/advisories/unreviewed/2024/03/GHSA-q75f-2pp5-9phj/GHSA-q75f-2pp5-9phj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q75f-2pp5-9phj", - "modified": "2024-03-29T03:30:29Z", + "modified": "2024-03-29T06:30:30Z", "published": "2024-03-26T21:30:48Z", "aliases": [ "CVE-2024-2887" @@ -33,6 +33,10 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G3RKI7VTQSIAI3PVZGRCHOSELTQXQ5FQ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IQMRHKDEG4J7TMRRRGUGW6GS4MVBX5IT" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-qccw-wmvp-8pv9/GHSA-qccw-wmvp-8pv9.json b/advisories/unreviewed/2024/03/GHSA-qccw-wmvp-8pv9/GHSA-qccw-wmvp-8pv9.json index bf563ce3a71..2482ce28b8f 100644 --- a/advisories/unreviewed/2024/03/GHSA-qccw-wmvp-8pv9/GHSA-qccw-wmvp-8pv9.json +++ b/advisories/unreviewed/2024/03/GHSA-qccw-wmvp-8pv9/GHSA-qccw-wmvp-8pv9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qccw-wmvp-8pv9", - "modified": "2024-03-29T03:30:29Z", + "modified": "2024-03-29T06:30:30Z", "published": "2024-03-26T21:30:48Z", "aliases": [ "CVE-2024-2885" @@ -33,6 +33,10 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G3RKI7VTQSIAI3PVZGRCHOSELTQXQ5FQ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IQMRHKDEG4J7TMRRRGUGW6GS4MVBX5IT" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-rg8g-7365-wq9j/GHSA-rg8g-7365-wq9j.json b/advisories/unreviewed/2024/03/GHSA-rg8g-7365-wq9j/GHSA-rg8g-7365-wq9j.json new file mode 100644 index 00000000000..d3102e70bae --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-rg8g-7365-wq9j/GHSA-rg8g-7365-wq9j.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rg8g-7365-wq9j", + "modified": "2024-03-29T06:30:30Z", + "published": "2024-03-29T06:30:30Z", + "aliases": [ + "CVE-2024-2841" + ], + "details": "The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.6.5 due to insufficient input sanitization and output escaping on user supplied attributes such as 'id'. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2841" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3059761%40otter-blocks&new=3059761%40otter-blocks&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/99e24496-0e3b-4bff-ba14-dc535be10633?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T05:15:46Z" + } +} \ No newline at end of file