From 7445a8f53e603e2712bee4d1d1209338dc378e48 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 19 Sep 2024 21:34:53 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-xpp6-8r3j-ww43.json | 6 +- .../GHSA-9623-mqmm-5rcf.json | 6 +- .../GHSA-4xx7-2cx3-x473.json | 38 +++++++++++- .../GHSA-j8gh-87rx-c7w9.json | 6 +- .../GHSA-qqv8-ph7f-h3f7.json | 6 +- .../GHSA-vvf8-2h68-9475.json | 38 +++++++++++- .../GHSA-f8x3-c29w-wfmj.json | 3 +- .../GHSA-3r5h-mjx6-6cjh.json | 3 +- .../GHSA-4g7c-75vj-hqfj.json | 3 +- .../GHSA-6j86-v54w-73w8.json | 3 +- .../GHSA-7wg5-5h5v-v89m.json | 3 +- .../GHSA-cv2c-4qf9-j5cw.json | 3 +- .../GHSA-2mhv-m6h4-3h94.json | 3 +- .../GHSA-37jr-8vrf-hwhp.json | 3 +- .../GHSA-rc83-8wmp-v9vx.json | 1 + .../GHSA-w79p-2q4q-mwmw.json | 1 + .../GHSA-9rvg-h3ph-f3v3.json | 3 +- .../GHSA-f5cr-mp3h-4jjj.json | 3 +- .../GHSA-q239-frwj-6m3v.json | 2 +- .../GHSA-wxxp-w379-49qj.json | 2 +- .../GHSA-2r79-m38c-p4mw.json | 2 +- .../GHSA-6gqg-m5mh-95hf.json | 2 +- .../GHSA-vwch-x387-pmjh.json | 2 +- .../GHSA-7xq4-g7wr-q7cw.json | 6 +- .../GHSA-cvww-5xmj-jrr4.json | 6 +- .../GHSA-f5c8-vfrq-jwqc.json | 6 +- .../GHSA-28cx-j4v5-m5fv.json | 11 ++-- .../GHSA-25f3-qj7w-25fw.json | 11 ++-- .../GHSA-2hc5-mf64-rr7f.json | 42 +++++++++++++ .../GHSA-3jrq-ghjr-jwf2.json | 11 ++-- .../GHSA-4f5p-28mj-x3pv.json | 58 +++++++++++++++++ .../GHSA-567g-p628-rg3x.json | 54 ++++++++++++++++ .../GHSA-5r8r-gqxv-82qv.json | 62 +++++++++++++++++++ .../GHSA-89vx-x763-hhwj.json | 43 +++++++++++++ .../GHSA-gmcc-j293-2h95.json | 42 +++++++++++++ .../GHSA-j9ff-392x-7q7v.json | 38 ++++++++++++ .../GHSA-j9h9-46cg-gwp9.json | 11 ++-- .../GHSA-jrwr-5jr4-cgx8.json | 38 ++++++++++++ .../GHSA-p6qw-qg3w-mhxx.json | 2 +- .../GHSA-qrvq-pfgp-2x62.json | 38 ++++++++++++ 40 files changed, 580 insertions(+), 41 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-2hc5-mf64-rr7f/GHSA-2hc5-mf64-rr7f.json create mode 100644 advisories/unreviewed/2024/09/GHSA-4f5p-28mj-x3pv/GHSA-4f5p-28mj-x3pv.json create mode 100644 advisories/unreviewed/2024/09/GHSA-567g-p628-rg3x/GHSA-567g-p628-rg3x.json create mode 100644 advisories/unreviewed/2024/09/GHSA-5r8r-gqxv-82qv/GHSA-5r8r-gqxv-82qv.json create mode 100644 advisories/unreviewed/2024/09/GHSA-89vx-x763-hhwj/GHSA-89vx-x763-hhwj.json create mode 100644 advisories/unreviewed/2024/09/GHSA-gmcc-j293-2h95/GHSA-gmcc-j293-2h95.json create mode 100644 advisories/unreviewed/2024/09/GHSA-j9ff-392x-7q7v/GHSA-j9ff-392x-7q7v.json create mode 100644 advisories/unreviewed/2024/09/GHSA-jrwr-5jr4-cgx8/GHSA-jrwr-5jr4-cgx8.json create mode 100644 advisories/unreviewed/2024/09/GHSA-qrvq-pfgp-2x62/GHSA-qrvq-pfgp-2x62.json diff --git a/advisories/github-reviewed/2024/07/GHSA-xpp6-8r3j-ww43/GHSA-xpp6-8r3j-ww43.json b/advisories/github-reviewed/2024/07/GHSA-xpp6-8r3j-ww43/GHSA-xpp6-8r3j-ww43.json index b9c139db867..c8c546c2d05 100644 --- a/advisories/github-reviewed/2024/07/GHSA-xpp6-8r3j-ww43/GHSA-xpp6-8r3j-ww43.json +++ b/advisories/github-reviewed/2024/07/GHSA-xpp6-8r3j-ww43/GHSA-xpp6-8r3j-ww43.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xpp6-8r3j-ww43", - "modified": "2024-09-10T00:30:49Z", + "modified": "2024-09-19T21:33:28Z", "published": "2024-07-08T21:31:40Z", "aliases": [ "CVE-2024-5971" @@ -72,6 +72,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:6508" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6883" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-5971" diff --git a/advisories/github-reviewed/2024/08/GHSA-9623-mqmm-5rcf/GHSA-9623-mqmm-5rcf.json b/advisories/github-reviewed/2024/08/GHSA-9623-mqmm-5rcf/GHSA-9623-mqmm-5rcf.json index 1aaa32bdb39..9748cb1dd19 100644 --- a/advisories/github-reviewed/2024/08/GHSA-9623-mqmm-5rcf/GHSA-9623-mqmm-5rcf.json +++ b/advisories/github-reviewed/2024/08/GHSA-9623-mqmm-5rcf/GHSA-9623-mqmm-5rcf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9623-mqmm-5rcf", - "modified": "2024-09-10T00:30:49Z", + "modified": "2024-09-19T21:33:29Z", "published": "2024-08-21T15:30:54Z", "aliases": [ "CVE-2024-7885" @@ -48,6 +48,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:6508" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6883" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-7885" diff --git a/advisories/github-reviewed/2024/09/GHSA-4xx7-2cx3-x473/GHSA-4xx7-2cx3-x473.json b/advisories/github-reviewed/2024/09/GHSA-4xx7-2cx3-x473/GHSA-4xx7-2cx3-x473.json index 66e7c742b41..66e5f6cf02c 100644 --- a/advisories/github-reviewed/2024/09/GHSA-4xx7-2cx3-x473/GHSA-4xx7-2cx3-x473.json +++ b/advisories/github-reviewed/2024/09/GHSA-4xx7-2cx3-x473/GHSA-4xx7-2cx3-x473.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4xx7-2cx3-x473", - "modified": "2024-09-19T19:48:27Z", + "modified": "2024-09-19T21:33:29Z", "published": "2024-09-19T18:30:52Z", "aliases": [ "CVE-2024-8698" @@ -44,6 +44,42 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8698" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6878" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6879" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6880" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6882" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6886" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6887" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6888" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6889" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6890" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-8698" diff --git a/advisories/github-reviewed/2024/09/GHSA-j8gh-87rx-c7w9/GHSA-j8gh-87rx-c7w9.json b/advisories/github-reviewed/2024/09/GHSA-j8gh-87rx-c7w9/GHSA-j8gh-87rx-c7w9.json index c3e38facf4b..b3620b19a49 100644 --- a/advisories/github-reviewed/2024/09/GHSA-j8gh-87rx-c7w9/GHSA-j8gh-87rx-c7w9.json +++ b/advisories/github-reviewed/2024/09/GHSA-j8gh-87rx-c7w9/GHSA-j8gh-87rx-c7w9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j8gh-87rx-c7w9", - "modified": "2024-09-19T15:30:49Z", + "modified": "2024-09-19T21:33:29Z", "published": "2024-09-17T00:31:06Z", "aliases": [ "CVE-2024-45496" @@ -64,6 +64,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:6691" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6705" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-45496" diff --git a/advisories/github-reviewed/2024/09/GHSA-qqv8-ph7f-h3f7/GHSA-qqv8-ph7f-h3f7.json b/advisories/github-reviewed/2024/09/GHSA-qqv8-ph7f-h3f7/GHSA-qqv8-ph7f-h3f7.json index e95d8111622..1af226a606c 100644 --- a/advisories/github-reviewed/2024/09/GHSA-qqv8-ph7f-h3f7/GHSA-qqv8-ph7f-h3f7.json +++ b/advisories/github-reviewed/2024/09/GHSA-qqv8-ph7f-h3f7/GHSA-qqv8-ph7f-h3f7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qqv8-ph7f-h3f7", - "modified": "2024-09-19T15:30:49Z", + "modified": "2024-09-19T21:33:29Z", "published": "2024-09-17T00:31:06Z", "aliases": [ "CVE-2024-7387" @@ -64,6 +64,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:6691" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6705" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-7387" diff --git a/advisories/github-reviewed/2024/09/GHSA-vvf8-2h68-9475/GHSA-vvf8-2h68-9475.json b/advisories/github-reviewed/2024/09/GHSA-vvf8-2h68-9475/GHSA-vvf8-2h68-9475.json index 29f45a27f5b..02ca888d6e4 100644 --- a/advisories/github-reviewed/2024/09/GHSA-vvf8-2h68-9475/GHSA-vvf8-2h68-9475.json +++ b/advisories/github-reviewed/2024/09/GHSA-vvf8-2h68-9475/GHSA-vvf8-2h68-9475.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vvf8-2h68-9475", - "modified": "2024-09-19T19:48:17Z", + "modified": "2024-09-19T21:33:29Z", "published": "2024-09-19T18:30:52Z", "aliases": [ "CVE-2024-8883" @@ -44,6 +44,42 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8883" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6878" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6879" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6880" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6882" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6886" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6887" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6888" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6889" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6890" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-8883" diff --git a/advisories/unreviewed/2023/01/GHSA-f8x3-c29w-wfmj/GHSA-f8x3-c29w-wfmj.json b/advisories/unreviewed/2023/01/GHSA-f8x3-c29w-wfmj/GHSA-f8x3-c29w-wfmj.json index f393a7f3d9c..e6717ae7d28 100644 --- a/advisories/unreviewed/2023/01/GHSA-f8x3-c29w-wfmj/GHSA-f8x3-c29w-wfmj.json +++ b/advisories/unreviewed/2023/01/GHSA-f8x3-c29w-wfmj/GHSA-f8x3-c29w-wfmj.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-306" + "CWE-306", + "CWE-502" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-3r5h-mjx6-6cjh/GHSA-3r5h-mjx6-6cjh.json b/advisories/unreviewed/2023/06/GHSA-3r5h-mjx6-6cjh/GHSA-3r5h-mjx6-6cjh.json index cf5ed7230a2..67087796206 100644 --- a/advisories/unreviewed/2023/06/GHSA-3r5h-mjx6-6cjh/GHSA-3r5h-mjx6-6cjh.json +++ b/advisories/unreviewed/2023/06/GHSA-3r5h-mjx6-6cjh/GHSA-3r5h-mjx6-6cjh.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-79" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-4g7c-75vj-hqfj/GHSA-4g7c-75vj-hqfj.json b/advisories/unreviewed/2023/06/GHSA-4g7c-75vj-hqfj/GHSA-4g7c-75vj-hqfj.json index 213228eee9a..cc330af2311 100644 --- a/advisories/unreviewed/2023/06/GHSA-4g7c-75vj-hqfj/GHSA-4g7c-75vj-hqfj.json +++ b/advisories/unreviewed/2023/06/GHSA-4g7c-75vj-hqfj/GHSA-4g7c-75vj-hqfj.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-73" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-6j86-v54w-73w8/GHSA-6j86-v54w-73w8.json b/advisories/unreviewed/2023/06/GHSA-6j86-v54w-73w8/GHSA-6j86-v54w-73w8.json index 2e9ffb01522..ed0af13955d 100644 --- a/advisories/unreviewed/2023/06/GHSA-6j86-v54w-73w8/GHSA-6j86-v54w-73w8.json +++ b/advisories/unreviewed/2023/06/GHSA-6j86-v54w-73w8/GHSA-6j86-v54w-73w8.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-347" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-7wg5-5h5v-v89m/GHSA-7wg5-5h5v-v89m.json b/advisories/unreviewed/2023/06/GHSA-7wg5-5h5v-v89m/GHSA-7wg5-5h5v-v89m.json index 24adc489a9d..9c9d5600e9a 100644 --- a/advisories/unreviewed/2023/06/GHSA-7wg5-5h5v-v89m/GHSA-7wg5-5h5v-v89m.json +++ b/advisories/unreviewed/2023/06/GHSA-7wg5-5h5v-v89m/GHSA-7wg5-5h5v-v89m.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-378" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-cv2c-4qf9-j5cw/GHSA-cv2c-4qf9-j5cw.json b/advisories/unreviewed/2023/06/GHSA-cv2c-4qf9-j5cw/GHSA-cv2c-4qf9-j5cw.json index 22bf3851db0..c9094de6529 100644 --- a/advisories/unreviewed/2023/06/GHSA-cv2c-4qf9-j5cw/GHSA-cv2c-4qf9-j5cw.json +++ b/advisories/unreviewed/2023/06/GHSA-cv2c-4qf9-j5cw/GHSA-cv2c-4qf9-j5cw.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-358" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-2mhv-m6h4-3h94/GHSA-2mhv-m6h4-3h94.json b/advisories/unreviewed/2023/07/GHSA-2mhv-m6h4-3h94/GHSA-2mhv-m6h4-3h94.json index a21c23a0ad1..8ffd60f13c7 100644 --- a/advisories/unreviewed/2023/07/GHSA-2mhv-m6h4-3h94/GHSA-2mhv-m6h4-3h94.json +++ b/advisories/unreviewed/2023/07/GHSA-2mhv-m6h4-3h94/GHSA-2mhv-m6h4-3h94.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-354" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-37jr-8vrf-hwhp/GHSA-37jr-8vrf-hwhp.json b/advisories/unreviewed/2023/07/GHSA-37jr-8vrf-hwhp/GHSA-37jr-8vrf-hwhp.json index e015853bcb2..3739a32b03d 100644 --- a/advisories/unreviewed/2023/07/GHSA-37jr-8vrf-hwhp/GHSA-37jr-8vrf-hwhp.json +++ b/advisories/unreviewed/2023/07/GHSA-37jr-8vrf-hwhp/GHSA-37jr-8vrf-hwhp.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-rc83-8wmp-v9vx/GHSA-rc83-8wmp-v9vx.json b/advisories/unreviewed/2023/07/GHSA-rc83-8wmp-v9vx/GHSA-rc83-8wmp-v9vx.json index 358d5265ea3..a597f304414 100644 --- a/advisories/unreviewed/2023/07/GHSA-rc83-8wmp-v9vx/GHSA-rc83-8wmp-v9vx.json +++ b/advisories/unreviewed/2023/07/GHSA-rc83-8wmp-v9vx/GHSA-rc83-8wmp-v9vx.json @@ -29,6 +29,7 @@ "database_specific": { "cwe_ids": [ "CWE-377", + "CWE-426", "CWE-668" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/07/GHSA-w79p-2q4q-mwmw/GHSA-w79p-2q4q-mwmw.json b/advisories/unreviewed/2023/07/GHSA-w79p-2q4q-mwmw/GHSA-w79p-2q4q-mwmw.json index 6c8d9f004a2..1e026c00020 100644 --- a/advisories/unreviewed/2023/07/GHSA-w79p-2q4q-mwmw/GHSA-w79p-2q4q-mwmw.json +++ b/advisories/unreviewed/2023/07/GHSA-w79p-2q4q-mwmw/GHSA-w79p-2q4q-mwmw.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-250", "CWE-269" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/08/GHSA-9rvg-h3ph-f3v3/GHSA-9rvg-h3ph-f3v3.json b/advisories/unreviewed/2023/08/GHSA-9rvg-h3ph-f3v3/GHSA-9rvg-h3ph-f3v3.json index 9013f8ccc32..2a90c4b4f41 100644 --- a/advisories/unreviewed/2023/08/GHSA-9rvg-h3ph-f3v3/GHSA-9rvg-h3ph-f3v3.json +++ b/advisories/unreviewed/2023/08/GHSA-9rvg-h3ph-f3v3/GHSA-9rvg-h3ph-f3v3.json @@ -29,7 +29,8 @@ "database_specific": { "cwe_ids": [ "CWE-269", - "CWE-59" + "CWE-59", + "CWE-610" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-f5cr-mp3h-4jjj/GHSA-f5cr-mp3h-4jjj.json b/advisories/unreviewed/2023/08/GHSA-f5cr-mp3h-4jjj/GHSA-f5cr-mp3h-4jjj.json index ee4523e5b60..d2007533e10 100644 --- a/advisories/unreviewed/2023/08/GHSA-f5cr-mp3h-4jjj/GHSA-f5cr-mp3h-4jjj.json +++ b/advisories/unreviewed/2023/08/GHSA-f5cr-mp3h-4jjj/GHSA-f5cr-mp3h-4jjj.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-772" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-q239-frwj-6m3v/GHSA-q239-frwj-6m3v.json b/advisories/unreviewed/2023/09/GHSA-q239-frwj-6m3v/GHSA-q239-frwj-6m3v.json index f66b8abddd2..d5e668974c1 100644 --- a/advisories/unreviewed/2023/09/GHSA-q239-frwj-6m3v/GHSA-q239-frwj-6m3v.json +++ b/advisories/unreviewed/2023/09/GHSA-q239-frwj-6m3v/GHSA-q239-frwj-6m3v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q239-frwj-6m3v", - "modified": "2023-12-21T03:30:32Z", + "modified": "2024-09-19T21:33:28Z", "published": "2023-09-11T09:31:45Z", "aliases": [ "CVE-2023-4585" diff --git a/advisories/unreviewed/2023/09/GHSA-wxxp-w379-49qj/GHSA-wxxp-w379-49qj.json b/advisories/unreviewed/2023/09/GHSA-wxxp-w379-49qj/GHSA-wxxp-w379-49qj.json index 518cb55eb01..832ab4d809a 100644 --- a/advisories/unreviewed/2023/09/GHSA-wxxp-w379-49qj/GHSA-wxxp-w379-49qj.json +++ b/advisories/unreviewed/2023/09/GHSA-wxxp-w379-49qj/GHSA-wxxp-w379-49qj.json @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-754" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-2r79-m38c-p4mw/GHSA-2r79-m38c-p4mw.json b/advisories/unreviewed/2023/10/GHSA-2r79-m38c-p4mw/GHSA-2r79-m38c-p4mw.json index a1cddbd1824..188cb87f1a3 100644 --- a/advisories/unreviewed/2023/10/GHSA-2r79-m38c-p4mw/GHSA-2r79-m38c-p4mw.json +++ b/advisories/unreviewed/2023/10/GHSA-2r79-m38c-p4mw/GHSA-2r79-m38c-p4mw.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-693" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-6gqg-m5mh-95hf/GHSA-6gqg-m5mh-95hf.json b/advisories/unreviewed/2023/10/GHSA-6gqg-m5mh-95hf/GHSA-6gqg-m5mh-95hf.json index bd1a097c69b..ece122b1a33 100644 --- a/advisories/unreviewed/2023/10/GHSA-6gqg-m5mh-95hf/GHSA-6gqg-m5mh-95hf.json +++ b/advisories/unreviewed/2023/10/GHSA-6gqg-m5mh-95hf/GHSA-6gqg-m5mh-95hf.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-vwch-x387-pmjh/GHSA-vwch-x387-pmjh.json b/advisories/unreviewed/2023/10/GHSA-vwch-x387-pmjh/GHSA-vwch-x387-pmjh.json index 7545fddeb14..09cb17a7f17 100644 --- a/advisories/unreviewed/2023/10/GHSA-vwch-x387-pmjh/GHSA-vwch-x387-pmjh.json +++ b/advisories/unreviewed/2023/10/GHSA-vwch-x387-pmjh/GHSA-vwch-x387-pmjh.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-7xq4-g7wr-q7cw/GHSA-7xq4-g7wr-q7cw.json b/advisories/unreviewed/2023/11/GHSA-7xq4-g7wr-q7cw/GHSA-7xq4-g7wr-q7cw.json index 6c0aa06e0a9..68192e36366 100644 --- a/advisories/unreviewed/2023/11/GHSA-7xq4-g7wr-q7cw/GHSA-7xq4-g7wr-q7cw.json +++ b/advisories/unreviewed/2023/11/GHSA-7xq4-g7wr-q7cw/GHSA-7xq4-g7wr-q7cw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7xq4-g7wr-q7cw", - "modified": "2023-11-16T18:30:24Z", + "modified": "2024-09-19T21:33:28Z", "published": "2023-11-05T00:33:05Z", "aliases": [ "CVE-2023-46382" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://seclists.org/fulldisclosure/2023/Nov/0" }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-247-01" + }, { "type": "WEB", "url": "https://www.txone.com/blog/ten-unpatched-vulnerabilities-in-building-automation-products-identified-by-txone-networks" diff --git a/advisories/unreviewed/2023/11/GHSA-cvww-5xmj-jrr4/GHSA-cvww-5xmj-jrr4.json b/advisories/unreviewed/2023/11/GHSA-cvww-5xmj-jrr4/GHSA-cvww-5xmj-jrr4.json index 1332d44e615..7386d60c202 100644 --- a/advisories/unreviewed/2023/11/GHSA-cvww-5xmj-jrr4/GHSA-cvww-5xmj-jrr4.json +++ b/advisories/unreviewed/2023/11/GHSA-cvww-5xmj-jrr4/GHSA-cvww-5xmj-jrr4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cvww-5xmj-jrr4", - "modified": "2023-11-16T18:30:24Z", + "modified": "2024-09-19T21:33:29Z", "published": "2023-11-05T00:33:05Z", "aliases": [ "CVE-2023-46381" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://seclists.org/fulldisclosure/2023/Nov/0" }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-247-01" + }, { "type": "WEB", "url": "https://www.txone.com/blog/ten-unpatched-vulnerabilities-in-building-automation-products-identified-by-txone-networks" diff --git a/advisories/unreviewed/2023/11/GHSA-f5c8-vfrq-jwqc/GHSA-f5c8-vfrq-jwqc.json b/advisories/unreviewed/2023/11/GHSA-f5c8-vfrq-jwqc/GHSA-f5c8-vfrq-jwqc.json index 0d144db4b0b..68b29aa8b15 100644 --- a/advisories/unreviewed/2023/11/GHSA-f5c8-vfrq-jwqc/GHSA-f5c8-vfrq-jwqc.json +++ b/advisories/unreviewed/2023/11/GHSA-f5c8-vfrq-jwqc/GHSA-f5c8-vfrq-jwqc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f5c8-vfrq-jwqc", - "modified": "2023-11-16T18:30:24Z", + "modified": "2024-09-19T21:33:28Z", "published": "2023-11-05T00:33:05Z", "aliases": [ "CVE-2023-46380" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://seclists.org/fulldisclosure/2023/Nov/0" }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-247-01" + }, { "type": "WEB", "url": "https://www.txone.com/blog/ten-unpatched-vulnerabilities-in-building-automation-products-identified-by-txone-networks" diff --git a/advisories/unreviewed/2024/08/GHSA-28cx-j4v5-m5fv/GHSA-28cx-j4v5-m5fv.json b/advisories/unreviewed/2024/08/GHSA-28cx-j4v5-m5fv/GHSA-28cx-j4v5-m5fv.json index 72975dba44a..4d24d89a064 100644 --- a/advisories/unreviewed/2024/08/GHSA-28cx-j4v5-m5fv/GHSA-28cx-j4v5-m5fv.json +++ b/advisories/unreviewed/2024/08/GHSA-28cx-j4v5-m5fv/GHSA-28cx-j4v5-m5fv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-28cx-j4v5-m5fv", - "modified": "2024-08-16T21:32:36Z", + "modified": "2024-09-19T21:33:28Z", "published": "2024-08-16T21:32:36Z", "aliases": [ "CVE-2024-43042" ], "details": "Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-307" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-16T20:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-25f3-qj7w-25fw/GHSA-25f3-qj7w-25fw.json b/advisories/unreviewed/2024/09/GHSA-25f3-qj7w-25fw/GHSA-25f3-qj7w-25fw.json index 421d45e99c8..4c33010c815 100644 --- a/advisories/unreviewed/2024/09/GHSA-25f3-qj7w-25fw/GHSA-25f3-qj7w-25fw.json +++ b/advisories/unreviewed/2024/09/GHSA-25f3-qj7w-25fw/GHSA-25f3-qj7w-25fw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-25f3-qj7w-25fw", - "modified": "2024-09-18T21:30:48Z", + "modified": "2024-09-19T21:33:29Z", "published": "2024-09-18T21:30:48Z", "aliases": [ "CVE-2024-46374" ], "details": "Best House Rental Management System 1.0 contains a SQL injection vulnerability in the delete_category() function of the file rental/admin_class.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T21:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-2hc5-mf64-rr7f/GHSA-2hc5-mf64-rr7f.json b/advisories/unreviewed/2024/09/GHSA-2hc5-mf64-rr7f/GHSA-2hc5-mf64-rr7f.json new file mode 100644 index 00000000000..93a150a6a1d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-2hc5-mf64-rr7f/GHSA-2hc5-mf64-rr7f.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2hc5-mf64-rr7f", + "modified": "2024-09-19T21:33:29Z", + "published": "2024-09-19T21:33:29Z", + "aliases": [ + "CVE-2024-33109" + ], + "details": "Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the phone via the Ringtone upload function.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33109" + }, + { + "type": "WEB", + "url": "https://www.bdosecurity.de/en-gb/advisories/cve-2024-33109" + }, + { + "type": "WEB", + "url": "http://tiptel.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-19T19:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3jrq-ghjr-jwf2/GHSA-3jrq-ghjr-jwf2.json b/advisories/unreviewed/2024/09/GHSA-3jrq-ghjr-jwf2/GHSA-3jrq-ghjr-jwf2.json index b19e7f5b0cf..054c4bcc99d 100644 --- a/advisories/unreviewed/2024/09/GHSA-3jrq-ghjr-jwf2/GHSA-3jrq-ghjr-jwf2.json +++ b/advisories/unreviewed/2024/09/GHSA-3jrq-ghjr-jwf2/GHSA-3jrq-ghjr-jwf2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3jrq-ghjr-jwf2", - "modified": "2024-09-18T21:30:48Z", + "modified": "2024-09-19T21:33:29Z", "published": "2024-09-18T21:30:48Z", "aliases": [ "CVE-2024-40568" ], "details": "Buffer Overflow vulnerability in btstack mesh commit before v.864e2f2b6b7878c8fab3cf5ee84ae566e3380c58 allows a remote attacker to execute arbitrary code via the pb_adv_handle_tranaction_cont function in the src/mesh/pb_adv.c component", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T21:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-4f5p-28mj-x3pv/GHSA-4f5p-28mj-x3pv.json b/advisories/unreviewed/2024/09/GHSA-4f5p-28mj-x3pv/GHSA-4f5p-28mj-x3pv.json new file mode 100644 index 00000000000..e994c8697d5 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-4f5p-28mj-x3pv/GHSA-4f5p-28mj-x3pv.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4f5p-28mj-x3pv", + "modified": "2024-09-19T21:33:29Z", + "published": "2024-09-19T21:33:29Z", + "aliases": [ + "CVE-2024-9001" + ], + "details": "A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. This vulnerability affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument command leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9001" + }, + { + "type": "WEB", + "url": "https://github.com/C9Y57/TOTOLINK_setTracerouteCfg/blob/main/setTracerouteCfg.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.278152" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.278152" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.406140" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-19T20:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-567g-p628-rg3x/GHSA-567g-p628-rg3x.json b/advisories/unreviewed/2024/09/GHSA-567g-p628-rg3x/GHSA-567g-p628-rg3x.json new file mode 100644 index 00000000000..f4b0bdff3f7 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-567g-p628-rg3x/GHSA-567g-p628-rg3x.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-567g-p628-rg3x", + "modified": "2024-09-19T21:33:29Z", + "published": "2024-09-19T21:33:29Z", + "aliases": [ + "CVE-2024-9003" + ], + "details": "A vulnerability was found in Jinan Chicheng Company JFlow 2.0.0. It has been rated as problematic. This issue affects the function AttachmentUploadController of the file /WF/Ath/EntityMutliFile_Load.do of the component Attachment Handler. The manipulation of the argument oid leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9003" + }, + { + "type": "WEB", + "url": "https://github.com/sweatxi/BugHub/blob/main/Jinan%20Gallop%20JFlow%20CMS%20port%20is%20not%20authorized%20to%20cause%20the%20leakage%20of%20database%20attachment%20information.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.278153" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.278153" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.406225" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-19T21:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-5r8r-gqxv-82qv/GHSA-5r8r-gqxv-82qv.json b/advisories/unreviewed/2024/09/GHSA-5r8r-gqxv-82qv/GHSA-5r8r-gqxv-82qv.json new file mode 100644 index 00000000000..9af1975c570 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5r8r-gqxv-82qv/GHSA-5r8r-gqxv-82qv.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5r8r-gqxv-82qv", + "modified": "2024-09-19T21:33:29Z", + "published": "2024-09-19T21:33:29Z", + "aliases": [ + "CVE-2024-9004" + ], + "details": "A vulnerability classified as critical has been found in D-Link DAR-7000 up to 20240912. Affected is an unknown function of the file /view/DBManage/Backup_Server_commit.php. The manipulation of the argument host leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9004" + }, + { + "type": "WEB", + "url": "https://github.com/mhtcshe/cve/blob/main/cve.md" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10354" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.278154" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.278154" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.407023" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-19T21:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-89vx-x763-hhwj/GHSA-89vx-x763-hhwj.json b/advisories/unreviewed/2024/09/GHSA-89vx-x763-hhwj/GHSA-89vx-x763-hhwj.json new file mode 100644 index 00000000000..534d1656ee4 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-89vx-x763-hhwj/GHSA-89vx-x763-hhwj.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89vx-x763-hhwj", + "modified": "2024-09-19T21:33:29Z", + "published": "2024-09-19T21:33:29Z", + "aliases": [ + "CVE-2024-25673" + ], + "details": "Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25673" + }, + { + "type": "WEB", + "url": "https://docs.couchbase.com/server/current/release-notes/relnotes.html" + }, + { + "type": "WEB", + "url": "https://forums.couchbase.com/tags/security" + }, + { + "type": "WEB", + "url": "https://www.couchbase.com/alerts" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-19T19:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gmcc-j293-2h95/GHSA-gmcc-j293-2h95.json b/advisories/unreviewed/2024/09/GHSA-gmcc-j293-2h95/GHSA-gmcc-j293-2h95.json new file mode 100644 index 00000000000..31338c40794 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-gmcc-j293-2h95/GHSA-gmcc-j293-2h95.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gmcc-j293-2h95", + "modified": "2024-09-19T21:33:29Z", + "published": "2024-09-19T21:33:29Z", + "aliases": [ + "CVE-2024-40125" + ], + "details": "An arbitrary file upload vulnerability in the Media Manager function of Closed-Loop Technology CLESS Server v4.5.2 allows attackers to execute arbitrary code via uploading a crafted PHP file to the upload endpoint.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40125" + }, + { + "type": "WEB", + "url": "https://github.com/brendontkl/My-CVEs/tree/main/CVE-2024-40125" + }, + { + "type": "WEB", + "url": "https://www.closed-loop.biz" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-19T19:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-j9ff-392x-7q7v/GHSA-j9ff-392x-7q7v.json b/advisories/unreviewed/2024/09/GHSA-j9ff-392x-7q7v/GHSA-j9ff-392x-7q7v.json new file mode 100644 index 00000000000..d150d3794df --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-j9ff-392x-7q7v/GHSA-j9ff-392x-7q7v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9ff-392x-7q7v", + "modified": "2024-09-19T21:33:29Z", + "published": "2024-09-19T21:33:29Z", + "aliases": [ + "CVE-2024-43489" + ], + "details": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43489" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43489" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-19T21:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-j9h9-46cg-gwp9/GHSA-j9h9-46cg-gwp9.json b/advisories/unreviewed/2024/09/GHSA-j9h9-46cg-gwp9/GHSA-j9h9-46cg-gwp9.json index d43f148e68b..4992ff3c4b8 100644 --- a/advisories/unreviewed/2024/09/GHSA-j9h9-46cg-gwp9/GHSA-j9h9-46cg-gwp9.json +++ b/advisories/unreviewed/2024/09/GHSA-j9h9-46cg-gwp9/GHSA-j9h9-46cg-gwp9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j9h9-46cg-gwp9", - "modified": "2024-09-18T21:30:48Z", + "modified": "2024-09-19T21:33:29Z", "published": "2024-09-18T21:30:48Z", "aliases": [ "CVE-2024-46373" ], "details": "Dedecms V5.7.115 contains an arbitrary code execution via file upload vulnerability in the backend.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T21:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-jrwr-5jr4-cgx8/GHSA-jrwr-5jr4-cgx8.json b/advisories/unreviewed/2024/09/GHSA-jrwr-5jr4-cgx8/GHSA-jrwr-5jr4-cgx8.json new file mode 100644 index 00000000000..2386a3b2b92 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-jrwr-5jr4-cgx8/GHSA-jrwr-5jr4-cgx8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrwr-5jr4-cgx8", + "modified": "2024-09-19T21:33:29Z", + "published": "2024-09-19T21:33:29Z", + "aliases": [ + "CVE-2024-43496" + ], + "details": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43496" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43496" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-19T21:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-p6qw-qg3w-mhxx/GHSA-p6qw-qg3w-mhxx.json b/advisories/unreviewed/2024/09/GHSA-p6qw-qg3w-mhxx/GHSA-p6qw-qg3w-mhxx.json index e9109beb39a..6d4520c6bee 100644 --- a/advisories/unreviewed/2024/09/GHSA-p6qw-qg3w-mhxx/GHSA-p6qw-qg3w-mhxx.json +++ b/advisories/unreviewed/2024/09/GHSA-p6qw-qg3w-mhxx/GHSA-p6qw-qg3w-mhxx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p6qw-qg3w-mhxx", - "modified": "2024-09-05T15:33:34Z", + "modified": "2024-09-19T21:33:29Z", "published": "2024-09-04T18:30:58Z", "aliases": [ "CVE-2024-8417" diff --git a/advisories/unreviewed/2024/09/GHSA-qrvq-pfgp-2x62/GHSA-qrvq-pfgp-2x62.json b/advisories/unreviewed/2024/09/GHSA-qrvq-pfgp-2x62/GHSA-qrvq-pfgp-2x62.json new file mode 100644 index 00000000000..2d942be49d5 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-qrvq-pfgp-2x62/GHSA-qrvq-pfgp-2x62.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrvq-pfgp-2x62", + "modified": "2024-09-19T21:33:29Z", + "published": "2024-09-19T21:33:29Z", + "aliases": [ + "CVE-2024-38221" + ], + "details": "Microsoft Edge (Chromium-based) Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38221" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38221" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-19T21:15:13Z" + } +} \ No newline at end of file