diff --git a/advisories/unreviewed/2024/04/GHSA-wcqp-hrg4-jgjg/GHSA-wcqp-hrg4-jgjg.json b/advisories/unreviewed/2024/04/GHSA-wcqp-hrg4-jgjg/GHSA-wcqp-hrg4-jgjg.json index 3b384d5708f..7f871faaa0a 100644 --- a/advisories/unreviewed/2024/04/GHSA-wcqp-hrg4-jgjg/GHSA-wcqp-hrg4-jgjg.json +++ b/advisories/unreviewed/2024/04/GHSA-wcqp-hrg4-jgjg/GHSA-wcqp-hrg4-jgjg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wcqp-hrg4-jgjg", - "modified": "2024-07-11T21:31:12Z", + "modified": "2024-07-18T12:30:51Z", "published": "2024-04-03T15:30:43Z", "aliases": [ "CVE-2024-26720" @@ -20,47 +20,7 @@ }, { "type": "WEB", - "url": "https://git.kernel.org/stable/c/000099d71648504fb9c7a4616f92c2b70c3e44ec" - }, - { - "type": "WEB", - "url": "https://git.kernel.org/stable/c/16b1025eaa8fc223ab4273ece20d1c3a4211a95d" - }, - { - "type": "WEB", - "url": "https://git.kernel.org/stable/c/1f12e4b3284d6c863f272eb2de0d4248ed211cf4" - }, - { - "type": "WEB", - "url": "https://git.kernel.org/stable/c/5099871b370335809c0fd1abad74d9c7c205d43f" - }, - { - "type": "WEB", - "url": "https://git.kernel.org/stable/c/65977bed167a92e87085e757fffa5798f7314c9f" - }, - { - "type": "WEB", - "url": "https://git.kernel.org/stable/c/81e7d2530d458548b90a5c5e76b77ad5e5d1c0df" - }, - { - "type": "WEB", - "url": "https://git.kernel.org/stable/c/9319b647902cbd5cc884ac08a8a6d54ce111fc78" - }, - { - "type": "WEB", - "url": "https://git.kernel.org/stable/c/c593d26fb5d577ef31b6e49a31e08ae3ebc1bc1e" - }, - { - "type": "WEB", - "url": "https://git.kernel.org/stable/c/cbbe17a324437c0ff99881a3ee453da45b228a00" - }, - { - "type": "WEB", - "url": "https://git.kernel.org/stable/c/ec18ec230301583395576915d274b407743d8f6c" - }, - { - "type": "WEB", - "url": "https://git.kernel.org/stable/c/f6620df12cb6bdcad671d269debbb23573502f9d" + "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html" }, { "type": "WEB", @@ -68,7 +28,63 @@ }, { "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html" + "url": "https://git.kernel.org/stable/c/f6620df12cb6bdcad671d269debbb23573502f9d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ec18ec230301583395576915d274b407743d8f6c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cbbe17a324437c0ff99881a3ee453da45b228a00" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c593d26fb5d577ef31b6e49a31e08ae3ebc1bc1e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9319b647902cbd5cc884ac08a8a6d54ce111fc78" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/81e7d2530d458548b90a5c5e76b77ad5e5d1c0df" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/65977bed167a92e87085e757fffa5798f7314c9f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5099871b370335809c0fd1abad74d9c7c205d43f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2820005edae13b140f2d54267d1bd6bb23915f59" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/253f9ea7e8e53a5176bd80ceb174907b10724c1a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/23a28f5f3f6ca1e4184bd0e9631cd0944cf1c807" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1f12e4b3284d6c863f272eb2de0d4248ed211cf4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/16b1025eaa8fc223ab4273ece20d1c3a4211a95d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/145faa3d03688cbb7bbaaecbd84c01539852942c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/000099d71648504fb9c7a4616f92c2b70c3e44ec" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/05/GHSA-v93c-228v-m7cm/GHSA-v93c-228v-m7cm.json b/advisories/unreviewed/2024/05/GHSA-v93c-228v-m7cm/GHSA-v93c-228v-m7cm.json index a9d9ee0353a..0fab39f6b78 100644 --- a/advisories/unreviewed/2024/05/GHSA-v93c-228v-m7cm/GHSA-v93c-228v-m7cm.json +++ b/advisories/unreviewed/2024/05/GHSA-v93c-228v-m7cm/GHSA-v93c-228v-m7cm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v93c-228v-m7cm", - "modified": "2024-05-21T18:31:21Z", + "modified": "2024-07-18T12:30:51Z", "published": "2024-05-21T18:31:21Z", "aliases": [ "CVE-2023-52803" @@ -18,6 +18,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52803" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/17866066b8ac1cc38fb449670bc15dc9fee4b40a" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/194454afa6aa9d6ed74f0c57127bc8beb27c20df" @@ -30,6 +34,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/7749fd2dbef72a52b5c9ffdbf877691950ed4680" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7d61d1da2ed1f682c41cae0c8d4719cdaccee5c5" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/bfca5fb4e97c46503ddfc582335917b0cc228264" diff --git a/advisories/unreviewed/2024/07/GHSA-2jcw-rxcr-pwmp/GHSA-2jcw-rxcr-pwmp.json b/advisories/unreviewed/2024/07/GHSA-2jcw-rxcr-pwmp/GHSA-2jcw-rxcr-pwmp.json index a5b8642cafe..100f059107a 100644 --- a/advisories/unreviewed/2024/07/GHSA-2jcw-rxcr-pwmp/GHSA-2jcw-rxcr-pwmp.json +++ b/advisories/unreviewed/2024/07/GHSA-2jcw-rxcr-pwmp/GHSA-2jcw-rxcr-pwmp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2jcw-rxcr-pwmp", - "modified": "2024-07-15T09:36:30Z", + "modified": "2024-07-18T12:30:52Z", "published": "2024-07-15T09:36:30Z", "aliases": [ "CVE-2024-41007" @@ -18,9 +18,37 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41007" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/04317a2471c2f637b4c49cbd0e9c0d04a519f570" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5d7e64d70a11d988553a08239c810a658e841982" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/66cb64a1d2239cd0309f9b5038b05462570a5be1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7bb7670f92bfbd05fc41a8f9a8f358b7ffed65f4" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/97a9063518f198ec0adb2ecb89789de342bb8283" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d2346fca5bed130dc712f276ac63450201d52969" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dfcdd7f89e401d2c6616be90c76c2fac3fa98fde" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e113cddefa27bbf5a79f72387b8fbd432a61a466" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-659h-c7mc-5hrw/GHSA-659h-c7mc-5hrw.json b/advisories/unreviewed/2024/07/GHSA-659h-c7mc-5hrw/GHSA-659h-c7mc-5hrw.json new file mode 100644 index 00000000000..4eecdc10795 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-659h-c7mc-5hrw/GHSA-659h-c7mc-5hrw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-659h-c7mc-5hrw", + "modified": "2024-07-18T12:30:52Z", + "published": "2024-07-18T12:30:52Z", + "aliases": [ + "CVE-2024-6504" + ], + "details": "Rapid7 InsightVM Console versions below 6.6.260 suffer from a protection mechanism failure whereby an attacker with network access to the InsightVM Console can cause it to overload or crash by sending repeated invalid REST requests in a short timeframe, to the Console's port 443 causing the console to enter an exception handling logging loop, exhausting the CPU. There is no indication that an attacker can use this method to escalate privilege, acquire unauthorized access to data, or gain control of protected resources. This issue is fixed in version 6.6.261.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6504" + }, + { + "type": "WEB", + "url": "https://docs.rapid7.com/release-notes/insightvm/20240717" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-18T10:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-7rc8-rqg8-27m3/GHSA-7rc8-rqg8-27m3.json b/advisories/unreviewed/2024/07/GHSA-7rc8-rqg8-27m3/GHSA-7rc8-rqg8-27m3.json index 663389d32ab..30aaa856947 100644 --- a/advisories/unreviewed/2024/07/GHSA-7rc8-rqg8-27m3/GHSA-7rc8-rqg8-27m3.json +++ b/advisories/unreviewed/2024/07/GHSA-7rc8-rqg8-27m3/GHSA-7rc8-rqg8-27m3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7rc8-rqg8-27m3", - "modified": "2024-07-17T09:30:47Z", + "modified": "2024-07-18T12:30:52Z", "published": "2024-07-17T09:30:47Z", "aliases": [ "CVE-2024-41010" @@ -21,6 +21,14 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/1cb6f0bae50441f4b4b32a28315853b279c7404e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/230bb13650b0f186f540500fd5f5f7096a822a2a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f61ecf1bd5b562ebfd7d430ccb31619857e80857" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-f6mg-hq7f-jw2j/GHSA-f6mg-hq7f-jw2j.json b/advisories/unreviewed/2024/07/GHSA-f6mg-hq7f-jw2j/GHSA-f6mg-hq7f-jw2j.json new file mode 100644 index 00000000000..f704ea83b43 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-f6mg-hq7f-jw2j/GHSA-f6mg-hq7f-jw2j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6mg-hq7f-jw2j", + "modified": "2024-07-18T12:30:52Z", + "published": "2024-07-18T12:30:52Z", + "aliases": [ + "CVE-2024-40898" + ], + "details": "SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests.\n\nUsers are recommended to upgrade to version 2.4.62 which fixes this issue. ", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40898" + }, + { + "type": "WEB", + "url": "https://httpd.apache.org/security/vulnerabilities_24.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-18T10:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-mcj2-pgr8-h65p/GHSA-mcj2-pgr8-h65p.json b/advisories/unreviewed/2024/07/GHSA-mcj2-pgr8-h65p/GHSA-mcj2-pgr8-h65p.json index 3e59e5a0b5e..644868fd740 100644 --- a/advisories/unreviewed/2024/07/GHSA-mcj2-pgr8-h65p/GHSA-mcj2-pgr8-h65p.json +++ b/advisories/unreviewed/2024/07/GHSA-mcj2-pgr8-h65p/GHSA-mcj2-pgr8-h65p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mcj2-pgr8-h65p", - "modified": "2024-07-12T15:31:28Z", + "modified": "2024-07-18T12:30:51Z", "published": "2024-07-12T15:31:28Z", "aliases": [ "CVE-2024-40947" @@ -33,6 +33,14 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/9c3906c3738562b1fedc6f1cfc81756a7cfefff0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a38e02265c681b51997a264aaf743095e2ee400a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a6176a802c4bfb83bf7524591aa75f44a639a853" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-q8cp-9q2j-mfj8/GHSA-q8cp-9q2j-mfj8.json b/advisories/unreviewed/2024/07/GHSA-q8cp-9q2j-mfj8/GHSA-q8cp-9q2j-mfj8.json index eaff8779750..e111b1e4f19 100644 --- a/advisories/unreviewed/2024/07/GHSA-q8cp-9q2j-mfj8/GHSA-q8cp-9q2j-mfj8.json +++ b/advisories/unreviewed/2024/07/GHSA-q8cp-9q2j-mfj8/GHSA-q8cp-9q2j-mfj8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q8cp-9q2j-mfj8", - "modified": "2024-07-11T21:31:12Z", + "modified": "2024-07-18T12:30:51Z", "published": "2024-07-09T12:30:56Z", "aliases": [ "CVE-2024-39487" @@ -18,6 +18,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39487" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6a8a4fd082c439e19fede027e80c79bc4c84bb8e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6b21346b399fd1336fe59233a17eb5ce73041ee1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/707c85ba3527ad6aa25552033576b0f1ff835d7b" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/9f835e48bd4c75fdf6a9cff3f0b806a7abde78da" @@ -26,6 +38,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/b75e33eae8667084bd4a63e67657c6a5a0f8d1e8" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bfd14e5915c2669f292a31d028e75dcd82f1e7e9" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/c8eb8ab9a44ff0e73492d0a12a643c449f641a9f" diff --git a/advisories/unreviewed/2024/07/GHSA-vv8h-m63v-53pq/GHSA-vv8h-m63v-53pq.json b/advisories/unreviewed/2024/07/GHSA-vv8h-m63v-53pq/GHSA-vv8h-m63v-53pq.json new file mode 100644 index 00000000000..cc164af0e90 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-vv8h-m63v-53pq/GHSA-vv8h-m63v-53pq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vv8h-m63v-53pq", + "modified": "2024-07-18T12:30:52Z", + "published": "2024-07-18T12:30:52Z", + "aliases": [ + "CVE-2024-29178" + ], + "details": "On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker must successfully log into the system to launch an attack, so this is a moderate-impact vulnerability.\n\nMitigation:\n\nall users should upgrade to 2.1.4\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29178" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/n6dhnl68knpxy80t35qxkkw2691l8sfn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-18T12:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-x749-289q-pg9q/GHSA-x749-289q-pg9q.json b/advisories/unreviewed/2024/07/GHSA-x749-289q-pg9q/GHSA-x749-289q-pg9q.json new file mode 100644 index 00000000000..0111e75b746 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-x749-289q-pg9q/GHSA-x749-289q-pg9q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x749-289q-pg9q", + "modified": "2024-07-18T12:30:52Z", + "published": "2024-07-18T12:30:52Z", + "aliases": [ + "CVE-2024-40725" + ], + "details": "A partial fix for  CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. \"AddType\" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted.\n\nUsers are recommended to upgrade to version 2.4.62, which fixes this issue.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40725" + }, + { + "type": "WEB", + "url": "https://httpd.apache.org/security/vulnerabilities_24.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-668" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-18T10:15:02Z" + } +} \ No newline at end of file