From 7347beb74d75a1df874eb7635b5be16ef2b5b40a Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 2 Aug 2024 12:33:07 +0000 Subject: [PATCH] Publish Advisories GHSA-p7r4-77g3-vcrx GHSA-3qp2-9c8g-2g8x GHSA-4h47-46m8-cx7g GHSA-5f2h-gxrx-j654 GHSA-6cjc-w4j3-jjh8 GHSA-885x-f949-h663 GHSA-9mv8-jqq2-5m57 GHSA-cmmr-cc39-65m3 GHSA-f6q3-hjwj-2j45 GHSA-j6vx-r77h-44wc GHSA-jjc3-cj6j-hw3v GHSA-p7c5-whj7-83vc GHSA-qff2-8qw7-hcvw GHSA-qx3j-rj87-66pj GHSA-v352-rg37-5q5m GHSA-vh6j-6rmm-669j GHSA-whp4-jh65-8472 --- .../GHSA-p7r4-77g3-vcrx.json | 2 +- .../GHSA-3qp2-9c8g-2g8x.json | 42 +++++++++++++++++ .../GHSA-4h47-46m8-cx7g.json | 42 +++++++++++++++++ .../GHSA-5f2h-gxrx-j654.json | 42 +++++++++++++++++ .../GHSA-6cjc-w4j3-jjh8.json | 42 +++++++++++++++++ .../GHSA-885x-f949-h663.json | 42 +++++++++++++++++ .../GHSA-9mv8-jqq2-5m57.json | 42 +++++++++++++++++ .../GHSA-cmmr-cc39-65m3.json | 42 +++++++++++++++++ .../GHSA-f6q3-hjwj-2j45.json | 42 +++++++++++++++++ .../GHSA-j6vx-r77h-44wc.json | 35 ++++++++++++++ .../GHSA-jjc3-cj6j-hw3v.json | 42 +++++++++++++++++ .../GHSA-p7c5-whj7-83vc.json | 42 +++++++++++++++++ .../GHSA-qff2-8qw7-hcvw.json | 35 ++++++++++++++ .../GHSA-qx3j-rj87-66pj.json | 42 +++++++++++++++++ .../GHSA-v352-rg37-5q5m.json | 35 ++++++++++++++ .../GHSA-vh6j-6rmm-669j.json | 46 +++++++++++++++++++ .../GHSA-whp4-jh65-8472.json | 42 +++++++++++++++++ 17 files changed, 656 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2024/08/GHSA-3qp2-9c8g-2g8x/GHSA-3qp2-9c8g-2g8x.json create mode 100644 advisories/unreviewed/2024/08/GHSA-4h47-46m8-cx7g/GHSA-4h47-46m8-cx7g.json create mode 100644 advisories/unreviewed/2024/08/GHSA-5f2h-gxrx-j654/GHSA-5f2h-gxrx-j654.json create mode 100644 advisories/unreviewed/2024/08/GHSA-6cjc-w4j3-jjh8/GHSA-6cjc-w4j3-jjh8.json create mode 100644 advisories/unreviewed/2024/08/GHSA-885x-f949-h663/GHSA-885x-f949-h663.json create mode 100644 advisories/unreviewed/2024/08/GHSA-9mv8-jqq2-5m57/GHSA-9mv8-jqq2-5m57.json create mode 100644 advisories/unreviewed/2024/08/GHSA-cmmr-cc39-65m3/GHSA-cmmr-cc39-65m3.json create mode 100644 advisories/unreviewed/2024/08/GHSA-f6q3-hjwj-2j45/GHSA-f6q3-hjwj-2j45.json create mode 100644 advisories/unreviewed/2024/08/GHSA-j6vx-r77h-44wc/GHSA-j6vx-r77h-44wc.json create mode 100644 advisories/unreviewed/2024/08/GHSA-jjc3-cj6j-hw3v/GHSA-jjc3-cj6j-hw3v.json create mode 100644 advisories/unreviewed/2024/08/GHSA-p7c5-whj7-83vc/GHSA-p7c5-whj7-83vc.json create mode 100644 advisories/unreviewed/2024/08/GHSA-qff2-8qw7-hcvw/GHSA-qff2-8qw7-hcvw.json create mode 100644 advisories/unreviewed/2024/08/GHSA-qx3j-rj87-66pj/GHSA-qx3j-rj87-66pj.json create mode 100644 advisories/unreviewed/2024/08/GHSA-v352-rg37-5q5m/GHSA-v352-rg37-5q5m.json create mode 100644 advisories/unreviewed/2024/08/GHSA-vh6j-6rmm-669j/GHSA-vh6j-6rmm-669j.json create mode 100644 advisories/unreviewed/2024/08/GHSA-whp4-jh65-8472/GHSA-whp4-jh65-8472.json diff --git a/advisories/unreviewed/2023/07/GHSA-p7r4-77g3-vcrx/GHSA-p7r4-77g3-vcrx.json b/advisories/unreviewed/2023/07/GHSA-p7r4-77g3-vcrx/GHSA-p7r4-77g3-vcrx.json index 950f375c3b9..d08755acb55 100644 --- a/advisories/unreviewed/2023/07/GHSA-p7r4-77g3-vcrx/GHSA-p7r4-77g3-vcrx.json +++ b/advisories/unreviewed/2023/07/GHSA-p7r4-77g3-vcrx/GHSA-p7r4-77g3-vcrx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p7r4-77g3-vcrx", - "modified": "2024-07-03T18:32:53Z", + "modified": "2024-08-02T12:31:42Z", "published": "2023-07-06T19:24:09Z", "aliases": [ "CVE-2023-22934" diff --git a/advisories/unreviewed/2024/08/GHSA-3qp2-9c8g-2g8x/GHSA-3qp2-9c8g-2g8x.json b/advisories/unreviewed/2024/08/GHSA-3qp2-9c8g-2g8x/GHSA-3qp2-9c8g-2g8x.json new file mode 100644 index 00000000000..176d9ef4446 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3qp2-9c8g-2g8x/GHSA-3qp2-9c8g-2g8x.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qp2-9c8g-2g8x", + "modified": "2024-08-02T12:31:44Z", + "published": "2024-08-02T12:31:44Z", + "aliases": [ + "CVE-2024-7204" + ], + "details": "Ai3 QbiBot does not properly filter user input, allowing unauthenticated remote attackers to insert JavaScript code into the chat box. Once the recipient views the message, they will be subject to a Stored XSS attack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7204" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-7975-3e810-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-7969-7827e-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-02T11:16:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4h47-46m8-cx7g/GHSA-4h47-46m8-cx7g.json b/advisories/unreviewed/2024/08/GHSA-4h47-46m8-cx7g/GHSA-4h47-46m8-cx7g.json new file mode 100644 index 00000000000..fa165dd3f85 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4h47-46m8-cx7g/GHSA-4h47-46m8-cx7g.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4h47-46m8-cx7g", + "modified": "2024-08-02T12:31:43Z", + "published": "2024-08-02T12:31:43Z", + "aliases": [ + "CVE-2024-38879" + ], + "details": "A vulnerability has been identified in Omnivise T3000 Application Server (All versions). The affected system exposes the port of an internal application on the public network interface allowing an attacker to circumvent authentication and directly access the exposed application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38879" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-857368.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-02T11:16:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5f2h-gxrx-j654/GHSA-5f2h-gxrx-j654.json b/advisories/unreviewed/2024/08/GHSA-5f2h-gxrx-j654/GHSA-5f2h-gxrx-j654.json new file mode 100644 index 00000000000..1b8b858252b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5f2h-gxrx-j654/GHSA-5f2h-gxrx-j654.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5f2h-gxrx-j654", + "modified": "2024-08-02T12:31:43Z", + "published": "2024-08-02T12:31:43Z", + "aliases": [ + "CVE-2024-38877" + ], + "details": "A vulnerability has been identified in Omnivise T3000 Application Server (All versions), Omnivise T3000 Domain Controller (All versions), Omnivise T3000 Network Intrusion Detection System (NIDS) (All versions), Omnivise T3000 Product Data Management (PDM) (All versions), Omnivise T3000 Security Server (All versions), Omnivise T3000 Terminal Server (All versions), Omnivise T3000 Thin Client (All versions), Omnivise T3000 Whitelisting Server (All versions). The affected devices stores initial system credentials without sufficient protection. An attacker with remote shell access or physical access could retrieve the credentials leading to confidentiality loss allowing the attacker to laterally move within the affected network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38877" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-857368.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-312" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-02T11:16:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6cjc-w4j3-jjh8/GHSA-6cjc-w4j3-jjh8.json b/advisories/unreviewed/2024/08/GHSA-6cjc-w4j3-jjh8/GHSA-6cjc-w4j3-jjh8.json new file mode 100644 index 00000000000..2fa3710b05b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6cjc-w4j3-jjh8/GHSA-6cjc-w4j3-jjh8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cjc-w4j3-jjh8", + "modified": "2024-08-02T12:31:43Z", + "published": "2024-08-02T12:31:43Z", + "aliases": [ + "CVE-2024-38878" + ], + "details": "A vulnerability has been identified in Omnivise T3000 Application Server (All versions). Affected devices allow authenticated users to export diagnostics data. The corresponding API endpoint is susceptible to path traversal and could allow an authenticated attacker to download arbitrary files from the file system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38878" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-857368.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-02T11:16:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-885x-f949-h663/GHSA-885x-f949-h663.json b/advisories/unreviewed/2024/08/GHSA-885x-f949-h663/GHSA-885x-f949-h663.json new file mode 100644 index 00000000000..5407e42ac7b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-885x-f949-h663/GHSA-885x-f949-h663.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-885x-f949-h663", + "modified": "2024-08-02T12:31:43Z", + "published": "2024-08-02T12:31:43Z", + "aliases": [ + "CVE-2024-38876" + ], + "details": "A vulnerability has been identified in Omnivise T3000 Application Server (All versions >= R9.2), Omnivise T3000 Domain Controller (All versions >= R9.2), Omnivise T3000 Product Data Management (PDM) (All versions >= R9.2), Omnivise T3000 Terminal Server (All versions >= R9.2), Omnivise T3000 Thin Client (All versions >= R9.2), Omnivise T3000 Whitelisting Server (All versions >= R9.2). The affected application regularly executes user modifiable code as a privileged user. This could allow a local authenticated attacker to execute arbitrary code with elevated privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38876" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-857368.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-552" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-02T11:16:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9mv8-jqq2-5m57/GHSA-9mv8-jqq2-5m57.json b/advisories/unreviewed/2024/08/GHSA-9mv8-jqq2-5m57/GHSA-9mv8-jqq2-5m57.json new file mode 100644 index 00000000000..582cf4604ad --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9mv8-jqq2-5m57/GHSA-9mv8-jqq2-5m57.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mv8-jqq2-5m57", + "modified": "2024-08-02T12:31:44Z", + "published": "2024-08-02T12:31:44Z", + "aliases": [ + "CVE-2024-7323" + ], + "details": "Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately filter user input. A remote attacker with regular privilege can exploit this vulnerability to download arbitrary files from the remote server .", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7323" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-7990-87183-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-7989-9c4ea-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-36" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-02T11:16:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cmmr-cc39-65m3/GHSA-cmmr-cc39-65m3.json b/advisories/unreviewed/2024/08/GHSA-cmmr-cc39-65m3/GHSA-cmmr-cc39-65m3.json new file mode 100644 index 00000000000..e13cd4e6126 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cmmr-cc39-65m3/GHSA-cmmr-cc39-65m3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmmr-cc39-65m3", + "modified": "2024-08-02T12:31:43Z", + "published": "2024-08-02T12:31:43Z", + "aliases": [ + "CVE-2024-4643" + ], + "details": "The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘end_redirect_link’ parameter in versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4643" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/bdthemes-element-pack-lite/trunk/modules/countdown/widgets/countdown.php#L2501" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0f281ef5-bb2e-42f9-be51-6f7bd3069f59?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-02T10:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f6q3-hjwj-2j45/GHSA-f6q3-hjwj-2j45.json b/advisories/unreviewed/2024/08/GHSA-f6q3-hjwj-2j45/GHSA-f6q3-hjwj-2j45.json new file mode 100644 index 00000000000..46d982830b6 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f6q3-hjwj-2j45/GHSA-f6q3-hjwj-2j45.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6q3-hjwj-2j45", + "modified": "2024-08-02T12:31:43Z", + "published": "2024-08-02T12:31:43Z", + "aliases": [ + "CVE-2024-40721" + ], + "details": "The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-side input. When a user visits a spoofed website, unauthenticated remote attackers can cause the TCBServiSign to load a DLL from an arbitrary path.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40721" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-7972-01a6e-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-7966-8c6c3-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-02T11:16:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j6vx-r77h-44wc/GHSA-j6vx-r77h-44wc.json b/advisories/unreviewed/2024/08/GHSA-j6vx-r77h-44wc/GHSA-j6vx-r77h-44wc.json new file mode 100644 index 00000000000..54ae69e13a0 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j6vx-r77h-44wc/GHSA-j6vx-r77h-44wc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6vx-r77h-44wc", + "modified": "2024-08-02T12:31:43Z", + "published": "2024-08-02T12:31:43Z", + "aliases": [ + "CVE-2024-27182" + ], + "details": "In Apache Linkis <= 1.5.0,\n\nArbitrary file deletion in Basic management services on \n\nA user with an administrator account could delete any file accessible by the Linkis system user\n\n.\nUsers are recommended to upgrade to version 1.6.0, which fixes this issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27182" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/2of1p433h8rbq2bx525rtftnk19oz38h" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-552" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-02T10:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jjc3-cj6j-hw3v/GHSA-jjc3-cj6j-hw3v.json b/advisories/unreviewed/2024/08/GHSA-jjc3-cj6j-hw3v/GHSA-jjc3-cj6j-hw3v.json new file mode 100644 index 00000000000..2bf3c8ae8f6 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jjc3-cj6j-hw3v/GHSA-jjc3-cj6j-hw3v.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjc3-cj6j-hw3v", + "modified": "2024-08-02T12:31:43Z", + "published": "2024-08-02T12:31:43Z", + "aliases": [ + "CVE-2024-40723" + ], + "details": "The specific API in HWATAIServiSign Windows Version from CHANGING Information Technology does not properly validate the length of server-side inputs. When a user visits a spoofed website, unauthenticated remote attackers can cause a stack-based buffer overflow in the HWATAIServiSign, temporarily disrupting its service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40723" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-7974-0562f-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-7968-ce2ef-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-02T11:16:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p7c5-whj7-83vc/GHSA-p7c5-whj7-83vc.json b/advisories/unreviewed/2024/08/GHSA-p7c5-whj7-83vc/GHSA-p7c5-whj7-83vc.json new file mode 100644 index 00000000000..6c1bfb9493e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-p7c5-whj7-83vc/GHSA-p7c5-whj7-83vc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7c5-whj7-83vc", + "modified": "2024-08-02T12:31:43Z", + "published": "2024-08-02T12:31:43Z", + "aliases": [ + "CVE-2024-40722" + ], + "details": "The specific API in TCBServiSign Windows Version from CHANGING Information Technology does does not properly validate the length of server-side input. When a user visits a spoofed website, unauthenticated remote attackers can cause a stack-based buffer overflow in the TCBServiSign, temporarily disrupting its service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40722" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-7973-e10c6-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-7967-9efdf-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-02T11:16:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qff2-8qw7-hcvw/GHSA-qff2-8qw7-hcvw.json b/advisories/unreviewed/2024/08/GHSA-qff2-8qw7-hcvw/GHSA-qff2-8qw7-hcvw.json new file mode 100644 index 00000000000..448046b0ea2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qff2-8qw7-hcvw/GHSA-qff2-8qw7-hcvw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qff2-8qw7-hcvw", + "modified": "2024-08-02T12:31:43Z", + "published": "2024-08-02T12:31:43Z", + "aliases": [ + "CVE-2024-36268" + ], + "details": "Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.\n\nThis issue affects Apache InLong: from 1.10.0 through 1.12.0, which could lead to Remote Code Execution. Users are advised to upgrade to Apache InLong's 1.13.0 or cherry-pick [1] to solve it.\n\n[1]  https://github.com/apache/inlong/pull/10251", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36268" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/1w1yp1bg5sjvn46dszkf00tz1vfs0frc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-02T10:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qx3j-rj87-66pj/GHSA-qx3j-rj87-66pj.json b/advisories/unreviewed/2024/08/GHSA-qx3j-rj87-66pj/GHSA-qx3j-rj87-66pj.json new file mode 100644 index 00000000000..52f03b14907 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qx3j-rj87-66pj/GHSA-qx3j-rj87-66pj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qx3j-rj87-66pj", + "modified": "2024-08-02T12:31:43Z", + "published": "2024-08-02T12:31:43Z", + "aliases": [ + "CVE-2024-40719" + ], + "details": "The encryption strength of the authorization keys in CHANGING Information Technology TCBServiSign Windows Version is insufficient. When a remote attacker tricks a victim into visiting a malicious website, TCBServiSign will treat that website as a legitimate server and interact with it.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40719" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-7970-e8ac5-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-7964-5b266-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-326" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-02T10:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v352-rg37-5q5m/GHSA-v352-rg37-5q5m.json b/advisories/unreviewed/2024/08/GHSA-v352-rg37-5q5m/GHSA-v352-rg37-5q5m.json new file mode 100644 index 00000000000..8e659c2db07 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v352-rg37-5q5m/GHSA-v352-rg37-5q5m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v352-rg37-5q5m", + "modified": "2024-08-02T12:31:43Z", + "published": "2024-08-02T12:31:43Z", + "aliases": [ + "CVE-2024-27181" + ], + "details": "In Apache Linkis <= 1.5.0,\n\nPrivilege Escalation in Basic management services where the attacking user is \n\na trusted account\n\n allows access to Linkis's Token information. Users are advised to upgrade to version 1.6.0, which fixes this issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27181" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/hosd73l7hxb3rpt5rb0yg0ld11zph4c6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-02T10:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vh6j-6rmm-669j/GHSA-vh6j-6rmm-669j.json b/advisories/unreviewed/2024/08/GHSA-vh6j-6rmm-669j/GHSA-vh6j-6rmm-669j.json new file mode 100644 index 00000000000..ce06a018bb4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vh6j-6rmm-669j/GHSA-vh6j-6rmm-669j.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vh6j-6rmm-669j", + "modified": "2024-08-02T12:31:43Z", + "published": "2024-08-02T12:31:43Z", + "aliases": [ + "CVE-2024-6704" + ], + "details": "The Comments – wpDiscuz plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 7.6.21. This is due to a lack of filtering of HTML tags in comments. This makes it possible for unauthenticated attackers to add HTML such as hyperlinks to comments when rich editing is disabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6704" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wpdiscuz/trunk/class.WpdiscuzCore.php#L335" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3124810" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/fa3501a4-7975-4f90-8037-f8a06c293c07?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-02T11:16:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-whp4-jh65-8472/GHSA-whp4-jh65-8472.json b/advisories/unreviewed/2024/08/GHSA-whp4-jh65-8472/GHSA-whp4-jh65-8472.json new file mode 100644 index 00000000000..3eb4c1d7af1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-whp4-jh65-8472/GHSA-whp4-jh65-8472.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whp4-jh65-8472", + "modified": "2024-08-02T12:31:43Z", + "published": "2024-08-02T12:31:43Z", + "aliases": [ + "CVE-2024-40720" + ], + "details": "The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-side input. When a user visits a spoofed website, unauthenticated remote attackers can modify the `HKEY_CURRENT_USER` registry to execute arbitrary commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40720" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-7971-d9584-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-7965-8285d-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-02T11:16:42Z" + } +} \ No newline at end of file