From 71cc9bad0ce968d4e5dbcbc8a491d64458709e3f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 8 Jul 2024 09:33:50 +0000 Subject: [PATCH] Publish Advisories GHSA-j2vp-ggq4-7c56 GHSA-h658-qqv9-qwv8 GHSA-hvjp-8mx5-93c2 GHSA-xvvf-rwfm-7qrx --- .../GHSA-j2vp-ggq4-7c56.json | 2 +- .../GHSA-h658-qqv9-qwv8.json | 38 +++++++++++++++++++ .../GHSA-hvjp-8mx5-93c2.json | 38 +++++++++++++++++++ .../GHSA-xvvf-rwfm-7qrx.json | 38 +++++++++++++++++++ 4 files changed, 115 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2024/07/GHSA-h658-qqv9-qwv8/GHSA-h658-qqv9-qwv8.json create mode 100644 advisories/unreviewed/2024/07/GHSA-hvjp-8mx5-93c2/GHSA-hvjp-8mx5-93c2.json create mode 100644 advisories/unreviewed/2024/07/GHSA-xvvf-rwfm-7qrx/GHSA-xvvf-rwfm-7qrx.json diff --git a/advisories/unreviewed/2023/11/GHSA-j2vp-ggq4-7c56/GHSA-j2vp-ggq4-7c56.json b/advisories/unreviewed/2023/11/GHSA-j2vp-ggq4-7c56/GHSA-j2vp-ggq4-7c56.json index 12053ae83c0..d1655eafe22 100644 --- a/advisories/unreviewed/2023/11/GHSA-j2vp-ggq4-7c56/GHSA-j2vp-ggq4-7c56.json +++ b/advisories/unreviewed/2023/11/GHSA-j2vp-ggq4-7c56/GHSA-j2vp-ggq4-7c56.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j2vp-ggq4-7c56", - "modified": "2024-02-29T03:32:36Z", + "modified": "2024-07-08T09:32:21Z", "published": "2023-11-13T03:30:36Z", "aliases": [ "CVE-2023-26531" diff --git a/advisories/unreviewed/2024/07/GHSA-h658-qqv9-qwv8/GHSA-h658-qqv9-qwv8.json b/advisories/unreviewed/2024/07/GHSA-h658-qqv9-qwv8/GHSA-h658-qqv9-qwv8.json new file mode 100644 index 00000000000..3893715c5be --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-h658-qqv9-qwv8/GHSA-h658-qqv9-qwv8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h658-qqv9-qwv8", + "modified": "2024-07-08T09:32:22Z", + "published": "2024-07-08T09:32:22Z", + "aliases": [ + "CVE-2024-37389" + ], + "details": "Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter arbitrary JavaScript code, which the client browser will execute within the session context of the authenticated user. Upgrading to Apache NiFi 1.27.0 or 2.0.0-M4 is the recommended mitigation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37389" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/yso9fr0wtff53nk046h1o83hdyb1lrxh" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-08T08:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-hvjp-8mx5-93c2/GHSA-hvjp-8mx5-93c2.json b/advisories/unreviewed/2024/07/GHSA-hvjp-8mx5-93c2/GHSA-hvjp-8mx5-93c2.json new file mode 100644 index 00000000000..5c2a413921f --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-hvjp-8mx5-93c2/GHSA-hvjp-8mx5-93c2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvjp-8mx5-93c2", + "modified": "2024-07-08T09:32:21Z", + "published": "2024-07-08T09:32:21Z", + "aliases": [ + "CVE-2024-34602" + ], + "details": "Use of implicit intent for sensitive communication in Samsung Messages prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34602" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-08T07:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-xvvf-rwfm-7qrx/GHSA-xvvf-rwfm-7qrx.json b/advisories/unreviewed/2024/07/GHSA-xvvf-rwfm-7qrx/GHSA-xvvf-rwfm-7qrx.json new file mode 100644 index 00000000000..10a92634158 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-xvvf-rwfm-7qrx/GHSA-xvvf-rwfm-7qrx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xvvf-rwfm-7qrx", + "modified": "2024-07-08T09:32:22Z", + "published": "2024-07-08T09:32:22Z", + "aliases": [ + "CVE-2024-34603" + ], + "details": "Improper access control in Samsung Message prior to SMR Jul-2024 Release 1 allows local attackers to access location data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34603" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-08T07:15:04Z" + } +} \ No newline at end of file