From 7358eb79cff42cc0d1bd758a4a079fd3d7dc4905 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 18 Dec 2024 18:32:19 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-p26r-5492-x5wr.json | 9 ++++- .../GHSA-93fj-478v-vmfw.json | 9 ++++- .../GHSA-2574-cw53-m29g.json | 4 +- .../GHSA-82f5-g9rg-j683.json | 4 +- .../GHSA-c8pq-5xfg-p98w.json | 4 +- .../GHSA-f99v-cqxr-cqqw.json | 6 ++- .../GHSA-ggw9-q2xm-2xhm.json | 6 ++- .../GHSA-x5qv-8w36-gxh4.json | 1 + .../GHSA-45c5-w4j9-w656.json | 3 +- .../GHSA-pmcm-f4m7-v52m.json | 3 +- .../GHSA-qv87-xf2v-gghw.json | 2 +- .../GHSA-244c-824v-c69g.json | 15 +++++-- .../GHSA-36vc-7w44-2c6h.json | 33 +++++++++++++++ .../GHSA-3mgg-3hqg-jjq6.json | 36 +++++++++++++++++ .../GHSA-527r-mrh4-wx97.json | 15 +++++-- .../GHSA-5922-vxrc-h3gf.json | 9 ++++- .../GHSA-67jx-fcjg-p4rh.json | 15 +++++-- .../GHSA-6gq9-2wfh-4rj3.json | 15 +++++-- .../GHSA-6pwv-ppw3-h39w.json | 15 +++++-- .../GHSA-7w93-5823-j96v.json | 15 +++++-- .../GHSA-8q3p-665g-pf6p.json | 40 +++++++++++++++++++ .../GHSA-8xj5-7j6q-7c3r.json | 36 +++++++++++++++++ .../GHSA-93mv-5m6w-c964.json | 15 +++++-- .../GHSA-9qjm-qmmh-mmj2.json | 7 +++- .../GHSA-c7jc-3j2x-59x8.json | 36 +++++++++++++++++ .../GHSA-cf4r-pxww-5q94.json | 33 +++++++++++++++ .../GHSA-g3fv-gcpq-5jgx.json | 36 +++++++++++++++++ .../GHSA-gfwf-x23p-xh3q.json | 15 +++++-- .../GHSA-ghpw-cph8-v3rm.json | 29 ++++++++++++++ .../GHSA-gr94-xfwg-97fp.json | 36 +++++++++++++++++ .../GHSA-hw97-cgm7-v26g.json | 15 +++++-- .../GHSA-j755-fp8f-xrcg.json | 34 ++++++++++++++++ .../GHSA-jwm8-5prh-37pj.json | 15 +++++-- .../GHSA-jxw2-jvxf-5vrp.json | 15 +++++-- .../GHSA-p586-gwq2-42qx.json | 15 +++++-- .../GHSA-p6j5-54wr-g5qj.json | 15 +++++-- .../GHSA-p988-wjfg-fj9j.json | 34 ++++++++++++++++ .../GHSA-rhw5-2j65-gx3v.json | 34 ++++++++++++++++ .../GHSA-rx5r-j988-cf3j.json | 40 +++++++++++++++++++ .../GHSA-rxw7-8x7q-4w97.json | 40 +++++++++++++++++++ .../GHSA-w5m9-xcgh-j73w.json | 15 +++++-- .../GHSA-w87m-4q2m-g66w.json | 15 +++++-- .../GHSA-wr5h-38pc-5qx7.json | 36 +++++++++++++++++ 43 files changed, 748 insertions(+), 77 deletions(-) create mode 100644 advisories/unreviewed/2024/12/GHSA-36vc-7w44-2c6h/GHSA-36vc-7w44-2c6h.json create mode 100644 advisories/unreviewed/2024/12/GHSA-3mgg-3hqg-jjq6/GHSA-3mgg-3hqg-jjq6.json create mode 100644 advisories/unreviewed/2024/12/GHSA-8q3p-665g-pf6p/GHSA-8q3p-665g-pf6p.json create mode 100644 advisories/unreviewed/2024/12/GHSA-8xj5-7j6q-7c3r/GHSA-8xj5-7j6q-7c3r.json create mode 100644 advisories/unreviewed/2024/12/GHSA-c7jc-3j2x-59x8/GHSA-c7jc-3j2x-59x8.json create mode 100644 advisories/unreviewed/2024/12/GHSA-cf4r-pxww-5q94/GHSA-cf4r-pxww-5q94.json create mode 100644 advisories/unreviewed/2024/12/GHSA-g3fv-gcpq-5jgx/GHSA-g3fv-gcpq-5jgx.json create mode 100644 advisories/unreviewed/2024/12/GHSA-ghpw-cph8-v3rm/GHSA-ghpw-cph8-v3rm.json create mode 100644 advisories/unreviewed/2024/12/GHSA-gr94-xfwg-97fp/GHSA-gr94-xfwg-97fp.json create mode 100644 advisories/unreviewed/2024/12/GHSA-j755-fp8f-xrcg/GHSA-j755-fp8f-xrcg.json create mode 100644 advisories/unreviewed/2024/12/GHSA-p988-wjfg-fj9j/GHSA-p988-wjfg-fj9j.json create mode 100644 advisories/unreviewed/2024/12/GHSA-rhw5-2j65-gx3v/GHSA-rhw5-2j65-gx3v.json create mode 100644 advisories/unreviewed/2024/12/GHSA-rx5r-j988-cf3j/GHSA-rx5r-j988-cf3j.json create mode 100644 advisories/unreviewed/2024/12/GHSA-rxw7-8x7q-4w97/GHSA-rxw7-8x7q-4w97.json create mode 100644 advisories/unreviewed/2024/12/GHSA-wr5h-38pc-5qx7/GHSA-wr5h-38pc-5qx7.json diff --git a/advisories/unreviewed/2022/01/GHSA-p26r-5492-x5wr/GHSA-p26r-5492-x5wr.json b/advisories/unreviewed/2022/01/GHSA-p26r-5492-x5wr/GHSA-p26r-5492-x5wr.json index 09f742a965e..6280f23d101 100644 --- a/advisories/unreviewed/2022/01/GHSA-p26r-5492-x5wr/GHSA-p26r-5492-x5wr.json +++ b/advisories/unreviewed/2022/01/GHSA-p26r-5492-x5wr/GHSA-p26r-5492-x5wr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p26r-5492-x5wr", - "modified": "2022-01-29T00:01:00Z", + "modified": "2024-12-18T18:30:49Z", "published": "2022-01-25T00:01:12Z", "aliases": [ "CVE-2021-40596" ], "details": "SQL injection vulnerability in Login.php in sourcecodester Online Learning System v2 by oretnom23, allows attackers to execute arbitrary SQL commands via the faculty_id parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-93fj-478v-vmfw/GHSA-93fj-478v-vmfw.json b/advisories/unreviewed/2022/05/GHSA-93fj-478v-vmfw/GHSA-93fj-478v-vmfw.json index 43e04c20001..083308a3fac 100644 --- a/advisories/unreviewed/2022/05/GHSA-93fj-478v-vmfw/GHSA-93fj-478v-vmfw.json +++ b/advisories/unreviewed/2022/05/GHSA-93fj-478v-vmfw/GHSA-93fj-478v-vmfw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-93fj-478v-vmfw", - "modified": "2022-05-24T19:20:52Z", + "modified": "2024-12-18T18:30:49Z", "published": "2022-05-24T19:20:52Z", "aliases": [ "CVE-2021-42580" ], "details": "Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and authenticated file upload in (Master.php) file , we can craft these two vunlerablities to get unauthenticated remote command execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2023/06/GHSA-2574-cw53-m29g/GHSA-2574-cw53-m29g.json b/advisories/unreviewed/2023/06/GHSA-2574-cw53-m29g/GHSA-2574-cw53-m29g.json index 1b90e8594a1..ce38521d771 100644 --- a/advisories/unreviewed/2023/06/GHSA-2574-cw53-m29g/GHSA-2574-cw53-m29g.json +++ b/advisories/unreviewed/2023/06/GHSA-2574-cw53-m29g/GHSA-2574-cw53-m29g.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-732" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-82f5-g9rg-j683/GHSA-82f5-g9rg-j683.json b/advisories/unreviewed/2023/06/GHSA-82f5-g9rg-j683/GHSA-82f5-g9rg-j683.json index 15d57f29a10..b563dcd690a 100644 --- a/advisories/unreviewed/2023/06/GHSA-82f5-g9rg-j683/GHSA-82f5-g9rg-j683.json +++ b/advisories/unreviewed/2023/06/GHSA-82f5-g9rg-j683/GHSA-82f5-g9rg-j683.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-c8pq-5xfg-p98w/GHSA-c8pq-5xfg-p98w.json b/advisories/unreviewed/2023/06/GHSA-c8pq-5xfg-p98w/GHSA-c8pq-5xfg-p98w.json index ac1fbee16e1..e7008d26ac3 100644 --- a/advisories/unreviewed/2023/06/GHSA-c8pq-5xfg-p98w/GHSA-c8pq-5xfg-p98w.json +++ b/advisories/unreviewed/2023/06/GHSA-c8pq-5xfg-p98w/GHSA-c8pq-5xfg-p98w.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-f99v-cqxr-cqqw/GHSA-f99v-cqxr-cqqw.json b/advisories/unreviewed/2024/02/GHSA-f99v-cqxr-cqqw/GHSA-f99v-cqxr-cqqw.json index 41bc613259d..78268aed6c4 100644 --- a/advisories/unreviewed/2024/02/GHSA-f99v-cqxr-cqqw/GHSA-f99v-cqxr-cqqw.json +++ b/advisories/unreviewed/2024/02/GHSA-f99v-cqxr-cqqw/GHSA-f99v-cqxr-cqqw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f99v-cqxr-cqqw", - "modified": "2024-02-15T21:31:27Z", + "modified": "2024-12-18T18:30:49Z", "published": "2024-02-15T21:31:27Z", "aliases": [ "CVE-2023-6123" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-ggw9-q2xm-2xhm/GHSA-ggw9-q2xm-2xhm.json b/advisories/unreviewed/2024/02/GHSA-ggw9-q2xm-2xhm/GHSA-ggw9-q2xm-2xhm.json index 566bf035eee..6b68c0516a6 100644 --- a/advisories/unreviewed/2024/02/GHSA-ggw9-q2xm-2xhm/GHSA-ggw9-q2xm-2xhm.json +++ b/advisories/unreviewed/2024/02/GHSA-ggw9-q2xm-2xhm/GHSA-ggw9-q2xm-2xhm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ggw9-q2xm-2xhm", - "modified": "2024-02-17T09:30:32Z", + "modified": "2024-12-18T18:30:49Z", "published": "2024-02-17T09:30:32Z", "aliases": [ "CVE-2024-1512" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-x5qv-8w36-gxh4/GHSA-x5qv-8w36-gxh4.json b/advisories/unreviewed/2024/02/GHSA-x5qv-8w36-gxh4/GHSA-x5qv-8w36-gxh4.json index 1b71aad6507..32d45a31ad2 100644 --- a/advisories/unreviewed/2024/02/GHSA-x5qv-8w36-gxh4/GHSA-x5qv-8w36-gxh4.json +++ b/advisories/unreviewed/2024/02/GHSA-x5qv-8w36-gxh4/GHSA-x5qv-8w36-gxh4.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1284", "CWE-20" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/11/GHSA-45c5-w4j9-w656/GHSA-45c5-w4j9-w656.json b/advisories/unreviewed/2024/11/GHSA-45c5-w4j9-w656/GHSA-45c5-w4j9-w656.json index c7b100ccf35..bfe0950a2a7 100644 --- a/advisories/unreviewed/2024/11/GHSA-45c5-w4j9-w656/GHSA-45c5-w4j9-w656.json +++ b/advisories/unreviewed/2024/11/GHSA-45c5-w4j9-w656/GHSA-45c5-w4j9-w656.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-787" + "CWE-787", + "CWE-843" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-pmcm-f4m7-v52m/GHSA-pmcm-f4m7-v52m.json b/advisories/unreviewed/2024/11/GHSA-pmcm-f4m7-v52m/GHSA-pmcm-f4m7-v52m.json index a6421b74f77..a643c47ed33 100644 --- a/advisories/unreviewed/2024/11/GHSA-pmcm-f4m7-v52m/GHSA-pmcm-f4m7-v52m.json +++ b/advisories/unreviewed/2024/11/GHSA-pmcm-f4m7-v52m/GHSA-pmcm-f4m7-v52m.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-787" + "CWE-787", + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-qv87-xf2v-gghw/GHSA-qv87-xf2v-gghw.json b/advisories/unreviewed/2024/11/GHSA-qv87-xf2v-gghw/GHSA-qv87-xf2v-gghw.json index 161218954ac..3a07f9daf53 100644 --- a/advisories/unreviewed/2024/11/GHSA-qv87-xf2v-gghw/GHSA-qv87-xf2v-gghw.json +++ b/advisories/unreviewed/2024/11/GHSA-qv87-xf2v-gghw/GHSA-qv87-xf2v-gghw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qv87-xf2v-gghw", - "modified": "2024-11-30T00:32:14Z", + "modified": "2024-12-18T18:30:50Z", "published": "2024-11-28T00:39:26Z", "aliases": [ "CVE-2018-9354" diff --git a/advisories/unreviewed/2024/12/GHSA-244c-824v-c69g/GHSA-244c-824v-c69g.json b/advisories/unreviewed/2024/12/GHSA-244c-824v-c69g/GHSA-244c-824v-c69g.json index 0471033fef0..aca798e7307 100644 --- a/advisories/unreviewed/2024/12/GHSA-244c-824v-c69g/GHSA-244c-824v-c69g.json +++ b/advisories/unreviewed/2024/12/GHSA-244c-824v-c69g/GHSA-244c-824v-c69g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-244c-824v-c69g", - "modified": "2024-12-18T06:30:50Z", + "modified": "2024-12-18T18:30:51Z", "published": "2024-12-18T06:30:50Z", "aliases": [ "CVE-2024-56174" ], "details": "In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from client-side template injection in search history.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-18T06:15:23Z" diff --git a/advisories/unreviewed/2024/12/GHSA-36vc-7w44-2c6h/GHSA-36vc-7w44-2c6h.json b/advisories/unreviewed/2024/12/GHSA-36vc-7w44-2c6h/GHSA-36vc-7w44-2c6h.json new file mode 100644 index 00000000000..e7031a6f97a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-36vc-7w44-2c6h/GHSA-36vc-7w44-2c6h.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36vc-7w44-2c6h", + "modified": "2024-12-18T18:30:52Z", + "published": "2024-12-18T18:30:52Z", + "aliases": [ + "CVE-2024-55088" + ], + "details": "GetSimple CMS CE 3.3.19 is vulnerable to Server-Side Request Forgery (SSRF) in the backend plugin module.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55088" + }, + { + "type": "WEB", + "url": "https://getsimple-ce.ovh" + }, + { + "type": "WEB", + "url": "https://tasteful-stamp-da4.notion.site/CVE-2024-55088-15b1e0f227cb8064a1a8ed684607fee9?pvs=73" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-18T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3mgg-3hqg-jjq6/GHSA-3mgg-3hqg-jjq6.json b/advisories/unreviewed/2024/12/GHSA-3mgg-3hqg-jjq6/GHSA-3mgg-3hqg-jjq6.json new file mode 100644 index 00000000000..eebe1db25c2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3mgg-3hqg-jjq6/GHSA-3mgg-3hqg-jjq6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3mgg-3hqg-jjq6", + "modified": "2024-12-18T18:30:52Z", + "published": "2024-12-18T18:30:51Z", + "aliases": [ + "CVE-2023-50956" + ], + "details": "IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 \n\ncould allow a privileged user to obtain highly sensitive user credentials from secret keys that are stored in clear text.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50956" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7178587" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-256" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-18T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-527r-mrh4-wx97/GHSA-527r-mrh4-wx97.json b/advisories/unreviewed/2024/12/GHSA-527r-mrh4-wx97/GHSA-527r-mrh4-wx97.json index e08f29a32d3..a4a929e556b 100644 --- a/advisories/unreviewed/2024/12/GHSA-527r-mrh4-wx97/GHSA-527r-mrh4-wx97.json +++ b/advisories/unreviewed/2024/12/GHSA-527r-mrh4-wx97/GHSA-527r-mrh4-wx97.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-527r-mrh4-wx97", - "modified": "2024-12-17T21:30:34Z", + "modified": "2024-12-18T18:30:51Z", "published": "2024-12-17T21:30:34Z", "aliases": [ "CVE-2024-55058" ], "details": "An insecure direct object reference (IDOR) vulnerability was discovered in PHPGurukul Online Birth Certificate System v1.0. This vulnerability resides in the viewid parameter of /user/view-application-detail.php. Authenticated users can exploit this flaw by manipulating the viewid parameter in the URL to access sensitive birth certificate details of other users without proper authorization checks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-706" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-17T21:15:08Z" diff --git a/advisories/unreviewed/2024/12/GHSA-5922-vxrc-h3gf/GHSA-5922-vxrc-h3gf.json b/advisories/unreviewed/2024/12/GHSA-5922-vxrc-h3gf/GHSA-5922-vxrc-h3gf.json index 8142d1ad0ff..031b41e49f2 100644 --- a/advisories/unreviewed/2024/12/GHSA-5922-vxrc-h3gf/GHSA-5922-vxrc-h3gf.json +++ b/advisories/unreviewed/2024/12/GHSA-5922-vxrc-h3gf/GHSA-5922-vxrc-h3gf.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5922-vxrc-h3gf", - "modified": "2024-12-18T15:32:59Z", + "modified": "2024-12-18T18:30:51Z", "published": "2024-12-18T12:30:55Z", "aliases": [ "CVE-2024-4995" ], "details": "Wapro ERP Desktop is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification. This issue affects Wapro ERP Desktop versions before 9.00.0.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:C/RE:M/U:Amber" @@ -34,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-311" + "CWE-311", + "CWE-922" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-67jx-fcjg-p4rh/GHSA-67jx-fcjg-p4rh.json b/advisories/unreviewed/2024/12/GHSA-67jx-fcjg-p4rh/GHSA-67jx-fcjg-p4rh.json index 543c0ef288f..af5c3dcab38 100644 --- a/advisories/unreviewed/2024/12/GHSA-67jx-fcjg-p4rh/GHSA-67jx-fcjg-p4rh.json +++ b/advisories/unreviewed/2024/12/GHSA-67jx-fcjg-p4rh/GHSA-67jx-fcjg-p4rh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-67jx-fcjg-p4rh", - "modified": "2024-12-12T03:33:06Z", + "modified": "2024-12-18T18:30:50Z", "published": "2024-12-12T03:33:06Z", "aliases": [ "CVE-2024-44245" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.3, visionOS 2.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Sonoma 14.7.2. An app may be able to cause unexpected system termination or corrupt kernel memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:24Z" diff --git a/advisories/unreviewed/2024/12/GHSA-6gq9-2wfh-4rj3/GHSA-6gq9-2wfh-4rj3.json b/advisories/unreviewed/2024/12/GHSA-6gq9-2wfh-4rj3/GHSA-6gq9-2wfh-4rj3.json index 9c21caab48e..0ae2faf2b5c 100644 --- a/advisories/unreviewed/2024/12/GHSA-6gq9-2wfh-4rj3/GHSA-6gq9-2wfh-4rj3.json +++ b/advisories/unreviewed/2024/12/GHSA-6gq9-2wfh-4rj3/GHSA-6gq9-2wfh-4rj3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6gq9-2wfh-4rj3", - "modified": "2024-12-18T00:31:23Z", + "modified": "2024-12-18T18:30:51Z", "published": "2024-12-18T00:31:23Z", "aliases": [ "CVE-2024-29646" ], "details": "Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the name, type, or group fields.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-17T22:15:06Z" diff --git a/advisories/unreviewed/2024/12/GHSA-6pwv-ppw3-h39w/GHSA-6pwv-ppw3-h39w.json b/advisories/unreviewed/2024/12/GHSA-6pwv-ppw3-h39w/GHSA-6pwv-ppw3-h39w.json index a8f6f25a2be..66907edff5d 100644 --- a/advisories/unreviewed/2024/12/GHSA-6pwv-ppw3-h39w/GHSA-6pwv-ppw3-h39w.json +++ b/advisories/unreviewed/2024/12/GHSA-6pwv-ppw3-h39w/GHSA-6pwv-ppw3-h39w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6pwv-ppw3-h39w", - "modified": "2024-12-17T21:30:34Z", + "modified": "2024-12-18T18:30:51Z", "published": "2024-12-17T21:30:34Z", "aliases": [ "CVE-2024-55514" ], "details": "A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_sfmig.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded, potentially leading to unauthorized access to server permissions.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-17T20:15:22Z" diff --git a/advisories/unreviewed/2024/12/GHSA-7w93-5823-j96v/GHSA-7w93-5823-j96v.json b/advisories/unreviewed/2024/12/GHSA-7w93-5823-j96v/GHSA-7w93-5823-j96v.json index 78dd772476b..8ae83a6f8ca 100644 --- a/advisories/unreviewed/2024/12/GHSA-7w93-5823-j96v/GHSA-7w93-5823-j96v.json +++ b/advisories/unreviewed/2024/12/GHSA-7w93-5823-j96v/GHSA-7w93-5823-j96v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7w93-5823-j96v", - "modified": "2024-12-17T18:33:50Z", + "modified": "2024-12-18T18:30:51Z", "published": "2024-12-17T18:33:50Z", "aliases": [ "CVE-2024-54662" ], "details": "Dante 1.4.0 through 1.4.3 (fixed in 1.4.4) has incorrect access control for some sockd.conf configurations involving socksmethod.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-863" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-17T18:15:24Z" diff --git a/advisories/unreviewed/2024/12/GHSA-8q3p-665g-pf6p/GHSA-8q3p-665g-pf6p.json b/advisories/unreviewed/2024/12/GHSA-8q3p-665g-pf6p/GHSA-8q3p-665g-pf6p.json new file mode 100644 index 00000000000..2cdbff193a5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8q3p-665g-pf6p/GHSA-8q3p-665g-pf6p.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8q3p-665g-pf6p", + "modified": "2024-12-18T18:30:52Z", + "published": "2024-12-18T18:30:52Z", + "aliases": [ + "CVE-2024-55492" + ], + "details": "Winmail Server 4.4 is vulnerable to f_user=%22%3E%3Csvg%20onload Cross Site Scripting (XSS).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55492" + }, + { + "type": "WEB", + "url": "https://github.com/qtxz54/Vul/blob/main/XSS/Winmail-Server.md" + }, + { + "type": "WEB", + "url": "http://winmail.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-18T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8xj5-7j6q-7c3r/GHSA-8xj5-7j6q-7c3r.json b/advisories/unreviewed/2024/12/GHSA-8xj5-7j6q-7c3r/GHSA-8xj5-7j6q-7c3r.json new file mode 100644 index 00000000000..d851ea48742 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8xj5-7j6q-7c3r/GHSA-8xj5-7j6q-7c3r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xj5-7j6q-7c3r", + "modified": "2024-12-18T18:30:52Z", + "published": "2024-12-18T18:30:52Z", + "aliases": [ + "CVE-2024-47119" + ], + "details": "IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 does not properly validate a certificate which could allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47119" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7178587" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-18T16:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-93mv-5m6w-c964/GHSA-93mv-5m6w-c964.json b/advisories/unreviewed/2024/12/GHSA-93mv-5m6w-c964/GHSA-93mv-5m6w-c964.json index 8f9008057a4..5ea0d830f36 100644 --- a/advisories/unreviewed/2024/12/GHSA-93mv-5m6w-c964/GHSA-93mv-5m6w-c964.json +++ b/advisories/unreviewed/2024/12/GHSA-93mv-5m6w-c964/GHSA-93mv-5m6w-c964.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-93mv-5m6w-c964", - "modified": "2024-12-18T00:31:23Z", + "modified": "2024-12-18T18:30:51Z", "published": "2024-12-18T00:31:23Z", "aliases": [ "CVE-2024-51175" ], "details": "An issue in H3C switch h3c-S1526 allows a remote attacker to obtain sensitive information via the S1526.cfg component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-312" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-17T22:15:06Z" diff --git a/advisories/unreviewed/2024/12/GHSA-9qjm-qmmh-mmj2/GHSA-9qjm-qmmh-mmj2.json b/advisories/unreviewed/2024/12/GHSA-9qjm-qmmh-mmj2/GHSA-9qjm-qmmh-mmj2.json index da24a422fb9..654107b00c8 100644 --- a/advisories/unreviewed/2024/12/GHSA-9qjm-qmmh-mmj2/GHSA-9qjm-qmmh-mmj2.json +++ b/advisories/unreviewed/2024/12/GHSA-9qjm-qmmh-mmj2/GHSA-9qjm-qmmh-mmj2.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9qjm-qmmh-mmj2", - "modified": "2024-12-18T09:31:35Z", + "modified": "2024-12-18T18:30:51Z", "published": "2024-12-18T09:31:35Z", "aliases": [ "CVE-2024-1610" ], "details": "In OPPO Store APP, there's a possible escalation of privilege due to improper input validation.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" @@ -26,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1284", "CWE-287" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/12/GHSA-c7jc-3j2x-59x8/GHSA-c7jc-3j2x-59x8.json b/advisories/unreviewed/2024/12/GHSA-c7jc-3j2x-59x8/GHSA-c7jc-3j2x-59x8.json new file mode 100644 index 00000000000..48153f66103 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c7jc-3j2x-59x8/GHSA-c7jc-3j2x-59x8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7jc-3j2x-59x8", + "modified": "2024-12-18T18:30:52Z", + "published": "2024-12-18T18:30:52Z", + "aliases": [ + "CVE-2024-52361" + ], + "details": "IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 \n\n\n\n stores user credentials in plain text which can be read by an authenticated user with access to the pod.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52361" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7178587" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-256" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-18T16:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cf4r-pxww-5q94/GHSA-cf4r-pxww-5q94.json b/advisories/unreviewed/2024/12/GHSA-cf4r-pxww-5q94/GHSA-cf4r-pxww-5q94.json new file mode 100644 index 00000000000..15faa2a43a5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cf4r-pxww-5q94/GHSA-cf4r-pxww-5q94.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cf4r-pxww-5q94", + "modified": "2024-12-18T18:30:52Z", + "published": "2024-12-18T18:30:52Z", + "aliases": [ + "CVE-2024-55086" + ], + "details": "In the GetSimple CMS CE 3.3.19 management page, Server-Side Request Forgery (SSRF) can be achieved in the plug-in download address in the backend management system.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55086" + }, + { + "type": "WEB", + "url": "https://getsimple-ce.ovh" + }, + { + "type": "WEB", + "url": "https://tasteful-stamp-da4.notion.site/CVE-2024-55086-15b1e0f227cb80e4bf4ed76aac53f795" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-18T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-g3fv-gcpq-5jgx/GHSA-g3fv-gcpq-5jgx.json b/advisories/unreviewed/2024/12/GHSA-g3fv-gcpq-5jgx/GHSA-g3fv-gcpq-5jgx.json new file mode 100644 index 00000000000..01096ad9801 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-g3fv-gcpq-5jgx/GHSA-g3fv-gcpq-5jgx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3fv-gcpq-5jgx", + "modified": "2024-12-18T18:30:52Z", + "published": "2024-12-18T18:30:52Z", + "aliases": [ + "CVE-2024-25042" + ], + "details": "IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 \n\n\n\nis potentially vulnerable to Cross Site Scripting (XSS). A remote attacker could execute malicious commands due to improper validation of column headings in Cognos Explorations.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25042" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7173592" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-18T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gfwf-x23p-xh3q/GHSA-gfwf-x23p-xh3q.json b/advisories/unreviewed/2024/12/GHSA-gfwf-x23p-xh3q/GHSA-gfwf-x23p-xh3q.json index 8599bf87871..8d8f172f565 100644 --- a/advisories/unreviewed/2024/12/GHSA-gfwf-x23p-xh3q/GHSA-gfwf-x23p-xh3q.json +++ b/advisories/unreviewed/2024/12/GHSA-gfwf-x23p-xh3q/GHSA-gfwf-x23p-xh3q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gfwf-x23p-xh3q", - "modified": "2024-12-06T00:31:47Z", + "modified": "2024-12-18T18:30:50Z", "published": "2024-12-06T00:31:47Z", "aliases": [ "CVE-2024-30962" ], "details": "Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the nav2_amcl process", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-05T23:15:05Z" diff --git a/advisories/unreviewed/2024/12/GHSA-ghpw-cph8-v3rm/GHSA-ghpw-cph8-v3rm.json b/advisories/unreviewed/2024/12/GHSA-ghpw-cph8-v3rm/GHSA-ghpw-cph8-v3rm.json new file mode 100644 index 00000000000..bcf5a4a340c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-ghpw-cph8-v3rm/GHSA-ghpw-cph8-v3rm.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghpw-cph8-v3rm", + "modified": "2024-12-18T18:30:52Z", + "published": "2024-12-18T18:30:52Z", + "aliases": [ + "CVE-2024-55089" + ], + "details": "Rhymix 2.1.19 is vulnerable to Server-Side Request Forgery (SSRF) in the background import data function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55089" + }, + { + "type": "WEB", + "url": "https://tasteful-stamp-da4.notion.site/CVE-2024-55089-15b1e0f227cb8064a563c697709b7530?pvs=73" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-18T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gr94-xfwg-97fp/GHSA-gr94-xfwg-97fp.json b/advisories/unreviewed/2024/12/GHSA-gr94-xfwg-97fp/GHSA-gr94-xfwg-97fp.json new file mode 100644 index 00000000000..4f07d76b479 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gr94-xfwg-97fp/GHSA-gr94-xfwg-97fp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gr94-xfwg-97fp", + "modified": "2024-12-18T18:30:52Z", + "published": "2024-12-18T18:30:52Z", + "aliases": [ + "CVE-2024-45082" + ], + "details": "IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 \n\ncould allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45082" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7177223" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-18T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hw97-cgm7-v26g/GHSA-hw97-cgm7-v26g.json b/advisories/unreviewed/2024/12/GHSA-hw97-cgm7-v26g/GHSA-hw97-cgm7-v26g.json index 19daa93ac1b..9a6e168d432 100644 --- a/advisories/unreviewed/2024/12/GHSA-hw97-cgm7-v26g/GHSA-hw97-cgm7-v26g.json +++ b/advisories/unreviewed/2024/12/GHSA-hw97-cgm7-v26g/GHSA-hw97-cgm7-v26g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hw97-cgm7-v26g", - "modified": "2024-12-17T21:30:34Z", + "modified": "2024-12-18T18:30:51Z", "published": "2024-12-17T21:30:34Z", "aliases": [ "CVE-2024-55059" ], "details": "A stored HTML Injection vulnerability was identified in PHPGurukul Online Birth Certificate System v1.0 in /user/certificate-form.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-17T21:15:08Z" diff --git a/advisories/unreviewed/2024/12/GHSA-j755-fp8f-xrcg/GHSA-j755-fp8f-xrcg.json b/advisories/unreviewed/2024/12/GHSA-j755-fp8f-xrcg/GHSA-j755-fp8f-xrcg.json new file mode 100644 index 00000000000..11a9cae7be2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j755-fp8f-xrcg/GHSA-j755-fp8f-xrcg.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j755-fp8f-xrcg", + "modified": "2024-12-18T18:30:52Z", + "published": "2024-12-18T18:30:52Z", + "aliases": [ + "CVE-2024-12371" + ], + "details": "A device takeover vulnerability exists in the Rockwell Automation Power Monitor 1000. This vulnerability allows configuration of a new Policyholder user without any authentication via API. Policyholder user is the most privileged user that can perform edit operations, creating admin users and performing factory reset.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12371" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1714.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-18T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jwm8-5prh-37pj/GHSA-jwm8-5prh-37pj.json b/advisories/unreviewed/2024/12/GHSA-jwm8-5prh-37pj/GHSA-jwm8-5prh-37pj.json index 07061888faa..8c2fba92393 100644 --- a/advisories/unreviewed/2024/12/GHSA-jwm8-5prh-37pj/GHSA-jwm8-5prh-37pj.json +++ b/advisories/unreviewed/2024/12/GHSA-jwm8-5prh-37pj/GHSA-jwm8-5prh-37pj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jwm8-5prh-37pj", - "modified": "2024-12-18T06:30:49Z", + "modified": "2024-12-18T18:30:51Z", "published": "2024-12-18T06:30:49Z", "aliases": [ "CVE-2024-56173" ], "details": "In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from JavaScript in an SVG document.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-18T06:15:23Z" diff --git a/advisories/unreviewed/2024/12/GHSA-jxw2-jvxf-5vrp/GHSA-jxw2-jvxf-5vrp.json b/advisories/unreviewed/2024/12/GHSA-jxw2-jvxf-5vrp/GHSA-jxw2-jvxf-5vrp.json index c38022ea330..2539333dcf4 100644 --- a/advisories/unreviewed/2024/12/GHSA-jxw2-jvxf-5vrp/GHSA-jxw2-jvxf-5vrp.json +++ b/advisories/unreviewed/2024/12/GHSA-jxw2-jvxf-5vrp/GHSA-jxw2-jvxf-5vrp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jxw2-jvxf-5vrp", - "modified": "2024-12-17T21:30:34Z", + "modified": "2024-12-18T18:30:51Z", "published": "2024-12-17T21:30:34Z", "aliases": [ "CVE-2024-49194" ], "details": "Databricks JDBC Driver before 2.6.40 could potentially allow remote code execution (RCE) by triggering a JNDI injection via a JDBC URL parameter. The vulnerability is rooted in the improper handling of the krbJAASFile parameter. An attacker could potentially exploit this vulnerability to achieve Remote Code Execution in the context of the driver by tricking a victim into using a crafted connection URL that uses the property krbJAASFile.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-17T20:15:22Z" diff --git a/advisories/unreviewed/2024/12/GHSA-p586-gwq2-42qx/GHSA-p586-gwq2-42qx.json b/advisories/unreviewed/2024/12/GHSA-p586-gwq2-42qx/GHSA-p586-gwq2-42qx.json index 5bbb6c21d60..2f57a4c0d16 100644 --- a/advisories/unreviewed/2024/12/GHSA-p586-gwq2-42qx/GHSA-p586-gwq2-42qx.json +++ b/advisories/unreviewed/2024/12/GHSA-p586-gwq2-42qx/GHSA-p586-gwq2-42qx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p586-gwq2-42qx", - "modified": "2024-12-17T21:30:34Z", + "modified": "2024-12-18T18:30:51Z", "published": "2024-12-17T21:30:34Z", "aliases": [ "CVE-2024-55515" ], "details": "A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_ipslib.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-17T20:15:22Z" diff --git a/advisories/unreviewed/2024/12/GHSA-p6j5-54wr-g5qj/GHSA-p6j5-54wr-g5qj.json b/advisories/unreviewed/2024/12/GHSA-p6j5-54wr-g5qj/GHSA-p6j5-54wr-g5qj.json index 0fe2d8171be..36b60476c27 100644 --- a/advisories/unreviewed/2024/12/GHSA-p6j5-54wr-g5qj/GHSA-p6j5-54wr-g5qj.json +++ b/advisories/unreviewed/2024/12/GHSA-p6j5-54wr-g5qj/GHSA-p6j5-54wr-g5qj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p6j5-54wr-g5qj", - "modified": "2024-12-17T21:30:34Z", + "modified": "2024-12-18T18:30:51Z", "published": "2024-12-17T21:30:34Z", "aliases": [ "CVE-2024-55516" ], "details": "A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 v3.90. The component affected by this issue is /upload_sysconfig.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded, potentially leading to unauthorized access to server permissions.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-17T20:15:23Z" diff --git a/advisories/unreviewed/2024/12/GHSA-p988-wjfg-fj9j/GHSA-p988-wjfg-fj9j.json b/advisories/unreviewed/2024/12/GHSA-p988-wjfg-fj9j/GHSA-p988-wjfg-fj9j.json new file mode 100644 index 00000000000..f15d236b308 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p988-wjfg-fj9j/GHSA-p988-wjfg-fj9j.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p988-wjfg-fj9j", + "modified": "2024-12-18T18:30:52Z", + "published": "2024-12-18T18:30:52Z", + "aliases": [ + "CVE-2024-12372" + ], + "details": "A denial-of-service and possible remote code execution vulnerability exists in the Rockwell Automation Power Monitor 1000. The vulnerability results in corruption of the heap memory which may compromise the integrity of the system, potentially allowing for remote code execution or a denial-of-service attack.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12372" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1714.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-18T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rhw5-2j65-gx3v/GHSA-rhw5-2j65-gx3v.json b/advisories/unreviewed/2024/12/GHSA-rhw5-2j65-gx3v/GHSA-rhw5-2j65-gx3v.json new file mode 100644 index 00000000000..647114827ef --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rhw5-2j65-gx3v/GHSA-rhw5-2j65-gx3v.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhw5-2j65-gx3v", + "modified": "2024-12-18T18:30:52Z", + "published": "2024-12-18T18:30:52Z", + "aliases": [ + "CVE-2024-12373" + ], + "details": "A denial-of-service vulnerability exists in the Rockwell Automation Power Monitor 1000. The vulnerability results in a buffer-overflow, potentially causing denial-of-service.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12373" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1714.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-18T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rx5r-j988-cf3j/GHSA-rx5r-j988-cf3j.json b/advisories/unreviewed/2024/12/GHSA-rx5r-j988-cf3j/GHSA-rx5r-j988-cf3j.json new file mode 100644 index 00000000000..84b8dcffe0d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rx5r-j988-cf3j/GHSA-rx5r-j988-cf3j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rx5r-j988-cf3j", + "modified": "2024-12-18T18:30:52Z", + "published": "2024-12-18T18:30:52Z", + "aliases": [ + "CVE-2024-49576" + ], + "details": "A use-after-free vulnerability exists in the way Foxit Reader 2024.3.0.26795 handles a checkbox CBF_Widget object. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49576" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2093" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2093" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-18T16:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rxw7-8x7q-4w97/GHSA-rxw7-8x7q-4w97.json b/advisories/unreviewed/2024/12/GHSA-rxw7-8x7q-4w97/GHSA-rxw7-8x7q-4w97.json new file mode 100644 index 00000000000..fe63e0912bc --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rxw7-8x7q-4w97/GHSA-rxw7-8x7q-4w97.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rxw7-8x7q-4w97", + "modified": "2024-12-18T18:30:52Z", + "published": "2024-12-18T18:30:52Z", + "aliases": [ + "CVE-2024-47810" + ], + "details": "A use-after-free vulnerability exists in the way Foxit Reader 2024.3.0.26795 handles a 3D page object. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47810" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2094" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2094" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-18T16:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w5m9-xcgh-j73w/GHSA-w5m9-xcgh-j73w.json b/advisories/unreviewed/2024/12/GHSA-w5m9-xcgh-j73w/GHSA-w5m9-xcgh-j73w.json index 9640f5b1900..d02db0a847b 100644 --- a/advisories/unreviewed/2024/12/GHSA-w5m9-xcgh-j73w/GHSA-w5m9-xcgh-j73w.json +++ b/advisories/unreviewed/2024/12/GHSA-w5m9-xcgh-j73w/GHSA-w5m9-xcgh-j73w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w5m9-xcgh-j73w", - "modified": "2024-12-17T21:30:34Z", + "modified": "2024-12-18T18:30:51Z", "published": "2024-12-17T21:30:34Z", "aliases": [ "CVE-2024-55513" ], "details": "A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_netaction.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded, potentially leading to unauthorized access to server permissions.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-17T20:15:22Z" diff --git a/advisories/unreviewed/2024/12/GHSA-w87m-4q2m-g66w/GHSA-w87m-4q2m-g66w.json b/advisories/unreviewed/2024/12/GHSA-w87m-4q2m-g66w/GHSA-w87m-4q2m-g66w.json index 5763efc685b..a14b939e65d 100644 --- a/advisories/unreviewed/2024/12/GHSA-w87m-4q2m-g66w/GHSA-w87m-4q2m-g66w.json +++ b/advisories/unreviewed/2024/12/GHSA-w87m-4q2m-g66w/GHSA-w87m-4q2m-g66w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w87m-4q2m-g66w", - "modified": "2024-12-18T00:31:23Z", + "modified": "2024-12-18T18:30:51Z", "published": "2024-12-18T00:31:23Z", "aliases": [ "CVE-2024-31668" ], "details": "rizin before v0.6.3 is vulnerable to Improper Neutralization of Special Elements via meta_set function in librz/analysis/meta.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-17T22:15:06Z" diff --git a/advisories/unreviewed/2024/12/GHSA-wr5h-38pc-5qx7/GHSA-wr5h-38pc-5qx7.json b/advisories/unreviewed/2024/12/GHSA-wr5h-38pc-5qx7/GHSA-wr5h-38pc-5qx7.json new file mode 100644 index 00000000000..5b5ed554daf --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wr5h-38pc-5qx7/GHSA-wr5h-38pc-5qx7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wr5h-38pc-5qx7", + "modified": "2024-12-18T18:30:52Z", + "published": "2024-12-18T18:30:52Z", + "aliases": [ + "CVE-2024-41752" + ], + "details": "IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41752" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7177223" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-18T17:15:13Z" + } +} \ No newline at end of file