diff --git a/advisories/unreviewed/2023/06/GHSA-qhm9-gg74-g6m6/GHSA-qhm9-gg74-g6m6.json b/advisories/unreviewed/2023/06/GHSA-qhm9-gg74-g6m6/GHSA-qhm9-gg74-g6m6.json index 57f574ed3c0..93730678420 100644 --- a/advisories/unreviewed/2023/06/GHSA-qhm9-gg74-g6m6/GHSA-qhm9-gg74-g6m6.json +++ b/advisories/unreviewed/2023/06/GHSA-qhm9-gg74-g6m6/GHSA-qhm9-gg74-g6m6.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-fjh2-g557-4jxp/GHSA-fjh2-g557-4jxp.json b/advisories/unreviewed/2024/03/GHSA-fjh2-g557-4jxp/GHSA-fjh2-g557-4jxp.json index 5b9b67af294..ca6197eb6fd 100644 --- a/advisories/unreviewed/2024/03/GHSA-fjh2-g557-4jxp/GHSA-fjh2-g557-4jxp.json +++ b/advisories/unreviewed/2024/03/GHSA-fjh2-g557-4jxp/GHSA-fjh2-g557-4jxp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fjh2-g557-4jxp", - "modified": "2024-03-28T12:33:20Z", + "modified": "2024-07-08T15:31:54Z", "published": "2024-03-28T12:33:20Z", "aliases": [ "CVE-2024-30595" ], "details": "Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the addWifiMacFilter function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T12:15:53Z" diff --git a/advisories/unreviewed/2024/04/GHSA-27hf-w6wm-652c/GHSA-27hf-w6wm-652c.json b/advisories/unreviewed/2024/04/GHSA-27hf-w6wm-652c/GHSA-27hf-w6wm-652c.json index c900f24428f..ba2effee45b 100644 --- a/advisories/unreviewed/2024/04/GHSA-27hf-w6wm-652c/GHSA-27hf-w6wm-652c.json +++ b/advisories/unreviewed/2024/04/GHSA-27hf-w6wm-652c/GHSA-27hf-w6wm-652c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-27hf-w6wm-652c", - "modified": "2024-04-26T06:30:35Z", + "modified": "2024-07-08T15:31:54Z", "published": "2024-04-26T06:30:35Z", "aliases": [ "CVE-2024-3188" ], "details": "The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-26T05:15:50Z" diff --git a/advisories/unreviewed/2024/04/GHSA-2w4r-8725-xcxv/GHSA-2w4r-8725-xcxv.json b/advisories/unreviewed/2024/04/GHSA-2w4r-8725-xcxv/GHSA-2w4r-8725-xcxv.json index b44d6ae60f7..97878f718cf 100644 --- a/advisories/unreviewed/2024/04/GHSA-2w4r-8725-xcxv/GHSA-2w4r-8725-xcxv.json +++ b/advisories/unreviewed/2024/04/GHSA-2w4r-8725-xcxv/GHSA-2w4r-8725-xcxv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2w4r-8725-xcxv", - "modified": "2024-04-12T06:33:24Z", + "modified": "2024-07-08T15:31:54Z", "published": "2024-04-12T06:33:24Z", "aliases": [ "CVE-2024-22734" ], "details": "An issue was discovered in AMCS Group Trux Waste Management Software before version 7.19.0018.26912, allows local attackers to obtain sensitive information via a static, hard-coded AES Key-IV pair in the TxUtilities.dll and TruxUser.cfg components.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-12T06:15:06Z" diff --git a/advisories/unreviewed/2024/04/GHSA-3wqg-6hfx-9w42/GHSA-3wqg-6hfx-9w42.json b/advisories/unreviewed/2024/04/GHSA-3wqg-6hfx-9w42/GHSA-3wqg-6hfx-9w42.json index 8e444f48d4c..9933f46a5dc 100644 --- a/advisories/unreviewed/2024/04/GHSA-3wqg-6hfx-9w42/GHSA-3wqg-6hfx-9w42.json +++ b/advisories/unreviewed/2024/04/GHSA-3wqg-6hfx-9w42/GHSA-3wqg-6hfx-9w42.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3wqg-6hfx-9w42", - "modified": "2024-04-26T21:31:11Z", + "modified": "2024-07-08T15:31:54Z", "published": "2024-04-26T21:31:11Z", "aliases": [ "CVE-2024-25343" ], "details": "Tenda N300 F3 router vulnerability allows users to bypass intended security policy and create weak passwords.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-26T20:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-42g9-27rx-76cj/GHSA-42g9-27rx-76cj.json b/advisories/unreviewed/2024/04/GHSA-42g9-27rx-76cj/GHSA-42g9-27rx-76cj.json index a5f834bf9b5..1ba6ee52253 100644 --- a/advisories/unreviewed/2024/04/GHSA-42g9-27rx-76cj/GHSA-42g9-27rx-76cj.json +++ b/advisories/unreviewed/2024/04/GHSA-42g9-27rx-76cj/GHSA-42g9-27rx-76cj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-42g9-27rx-76cj", - "modified": "2024-04-11T21:30:52Z", + "modified": "2024-07-08T15:31:54Z", "published": "2024-04-11T21:30:52Z", "aliases": [ "CVE-2024-25376" ], "details": "An issue discovered in Thesycon Software Solutions Gmbh & Co. KG TUSBAudio MSI-based installers before 5.68.0 allows a local attacker to execute arbitrary code via the msiexec.exe repair mode.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-11T21:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-4cvp-jw4q-vr74/GHSA-4cvp-jw4q-vr74.json b/advisories/unreviewed/2024/04/GHSA-4cvp-jw4q-vr74/GHSA-4cvp-jw4q-vr74.json index ebb9574a588..83fb2886894 100644 --- a/advisories/unreviewed/2024/04/GHSA-4cvp-jw4q-vr74/GHSA-4cvp-jw4q-vr74.json +++ b/advisories/unreviewed/2024/04/GHSA-4cvp-jw4q-vr74/GHSA-4cvp-jw4q-vr74.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-4fv8-fm6j-xc9r/GHSA-4fv8-fm6j-xc9r.json b/advisories/unreviewed/2024/04/GHSA-4fv8-fm6j-xc9r/GHSA-4fv8-fm6j-xc9r.json index a7681aeb85f..eaa83c37730 100644 --- a/advisories/unreviewed/2024/04/GHSA-4fv8-fm6j-xc9r/GHSA-4fv8-fm6j-xc9r.json +++ b/advisories/unreviewed/2024/04/GHSA-4fv8-fm6j-xc9r/GHSA-4fv8-fm6j-xc9r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4fv8-fm6j-xc9r", - "modified": "2024-04-10T21:30:33Z", + "modified": "2024-07-08T15:31:54Z", "published": "2024-04-10T21:30:33Z", "aliases": [ "CVE-2024-29500" ], "details": "An issue in the kiosk mode of Secure Lockdown Multi Application Edition v2.00.219 allows attackers to execute arbitrary code via running a ClickOnce application instance.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T20:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-5m68-rc9v-rxh2/GHSA-5m68-rc9v-rxh2.json b/advisories/unreviewed/2024/04/GHSA-5m68-rc9v-rxh2/GHSA-5m68-rc9v-rxh2.json index 378150e52ef..48a0ae418c6 100644 --- a/advisories/unreviewed/2024/04/GHSA-5m68-rc9v-rxh2/GHSA-5m68-rc9v-rxh2.json +++ b/advisories/unreviewed/2024/04/GHSA-5m68-rc9v-rxh2/GHSA-5m68-rc9v-rxh2.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-5v78-8gv6-c945/GHSA-5v78-8gv6-c945.json b/advisories/unreviewed/2024/04/GHSA-5v78-8gv6-c945/GHSA-5v78-8gv6-c945.json index 8ca28634203..975921d8152 100644 --- a/advisories/unreviewed/2024/04/GHSA-5v78-8gv6-c945/GHSA-5v78-8gv6-c945.json +++ b/advisories/unreviewed/2024/04/GHSA-5v78-8gv6-c945/GHSA-5v78-8gv6-c945.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5v78-8gv6-c945", - "modified": "2024-04-15T12:30:34Z", + "modified": "2024-07-08T15:31:54Z", "published": "2024-04-15T12:30:34Z", "aliases": [ "CVE-2024-23486" ], "details": "Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthenticated attacker with access to the product's login page may obtain configured credentials.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-15T11:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-8wm5-mx8v-3jpf/GHSA-8wm5-mx8v-3jpf.json b/advisories/unreviewed/2024/04/GHSA-8wm5-mx8v-3jpf/GHSA-8wm5-mx8v-3jpf.json index dbf999d218d..13740c6f684 100644 --- a/advisories/unreviewed/2024/04/GHSA-8wm5-mx8v-3jpf/GHSA-8wm5-mx8v-3jpf.json +++ b/advisories/unreviewed/2024/04/GHSA-8wm5-mx8v-3jpf/GHSA-8wm5-mx8v-3jpf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8wm5-mx8v-3jpf", - "modified": "2024-04-24T06:30:31Z", + "modified": "2024-07-08T15:31:54Z", "published": "2024-04-24T06:30:31Z", "aliases": [ "CVE-2024-31406" ], "details": "Active debug code vulnerability exists in RoamWiFi R10 prior to 4.8.45. If this vulnerability is exploited, a network-adjacent unauthenticated attacker with access to the device may perform unauthorized operations.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-489" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-24T06:15:13Z" diff --git a/advisories/unreviewed/2024/04/GHSA-9gm2-28fm-hw6c/GHSA-9gm2-28fm-hw6c.json b/advisories/unreviewed/2024/04/GHSA-9gm2-28fm-hw6c/GHSA-9gm2-28fm-hw6c.json index f973be0fc80..f2e7a32df11 100644 --- a/advisories/unreviewed/2024/04/GHSA-9gm2-28fm-hw6c/GHSA-9gm2-28fm-hw6c.json +++ b/advisories/unreviewed/2024/04/GHSA-9gm2-28fm-hw6c/GHSA-9gm2-28fm-hw6c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9gm2-28fm-hw6c", - "modified": "2024-04-15T21:30:45Z", + "modified": "2024-07-08T15:31:54Z", "published": "2024-04-15T21:30:45Z", "aliases": [ "CVE-2024-24486" ], "details": "An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to edit device settings via the SAVE EEP_DATA command.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-15T19:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-f53j-pgm5-c4r3/GHSA-f53j-pgm5-c4r3.json b/advisories/unreviewed/2024/04/GHSA-f53j-pgm5-c4r3/GHSA-f53j-pgm5-c4r3.json index aa8f9355a58..5cae4daa1b7 100644 --- a/advisories/unreviewed/2024/04/GHSA-f53j-pgm5-c4r3/GHSA-f53j-pgm5-c4r3.json +++ b/advisories/unreviewed/2024/04/GHSA-f53j-pgm5-c4r3/GHSA-f53j-pgm5-c4r3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f53j-pgm5-c4r3", - "modified": "2024-06-10T18:30:55Z", + "modified": "2024-07-08T15:31:54Z", "published": "2024-04-13T15:34:58Z", "aliases": [ "CVE-2024-32487" ], "details": "less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-96" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-13T15:15:52Z" diff --git a/advisories/unreviewed/2024/04/GHSA-fm53-2cx3-crw3/GHSA-fm53-2cx3-crw3.json b/advisories/unreviewed/2024/04/GHSA-fm53-2cx3-crw3/GHSA-fm53-2cx3-crw3.json index 07c69f64fe1..57de6e9740e 100644 --- a/advisories/unreviewed/2024/04/GHSA-fm53-2cx3-crw3/GHSA-fm53-2cx3-crw3.json +++ b/advisories/unreviewed/2024/04/GHSA-fm53-2cx3-crw3/GHSA-fm53-2cx3-crw3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fm53-2cx3-crw3", - "modified": "2024-04-11T03:34:59Z", + "modified": "2024-07-08T15:31:54Z", "published": "2024-04-11T03:34:59Z", "aliases": [ "CVE-2023-51142" ], "details": "An issue in ZKTeco BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-11T01:22:43Z" diff --git a/advisories/unreviewed/2024/04/GHSA-qj2m-h9cr-4gv7/GHSA-qj2m-h9cr-4gv7.json b/advisories/unreviewed/2024/04/GHSA-qj2m-h9cr-4gv7/GHSA-qj2m-h9cr-4gv7.json index 1a78fdcff12..c2a5337a0ab 100644 --- a/advisories/unreviewed/2024/04/GHSA-qj2m-h9cr-4gv7/GHSA-qj2m-h9cr-4gv7.json +++ b/advisories/unreviewed/2024/04/GHSA-qj2m-h9cr-4gv7/GHSA-qj2m-h9cr-4gv7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qj2m-h9cr-4gv7", - "modified": "2024-04-16T18:31:34Z", + "modified": "2024-07-08T15:31:54Z", "published": "2024-04-16T18:31:34Z", "aliases": [ "CVE-2023-50872" ], "details": "The API in Accredible Credential.net December 6th, 2023 allows an Insecure Direct Object Reference attack that discloses partial information about certificates and their respective holder. NOTE: the excellium-services.com web page about this issue mentions \"Vendor says that it's not a security issue.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-16T16:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-v859-v234-c2mg/GHSA-v859-v234-c2mg.json b/advisories/unreviewed/2024/04/GHSA-v859-v234-c2mg/GHSA-v859-v234-c2mg.json index e905eafdb57..2f86436a3dd 100644 --- a/advisories/unreviewed/2024/04/GHSA-v859-v234-c2mg/GHSA-v859-v234-c2mg.json +++ b/advisories/unreviewed/2024/04/GHSA-v859-v234-c2mg/GHSA-v859-v234-c2mg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v859-v234-c2mg", - "modified": "2024-04-26T06:30:34Z", + "modified": "2024-07-08T15:31:54Z", "published": "2024-04-26T06:30:34Z", "aliases": [ "CVE-2024-0905" ], "details": "The Fancy Product Designer WordPress plugin before 6.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against unauthenticated and admin-level users", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-26T05:15:49Z" diff --git a/advisories/unreviewed/2024/04/GHSA-vfmv-3fmr-wr8p/GHSA-vfmv-3fmr-wr8p.json b/advisories/unreviewed/2024/04/GHSA-vfmv-3fmr-wr8p/GHSA-vfmv-3fmr-wr8p.json index e9636d6c7b2..9c09d0f0fcd 100644 --- a/advisories/unreviewed/2024/04/GHSA-vfmv-3fmr-wr8p/GHSA-vfmv-3fmr-wr8p.json +++ b/advisories/unreviewed/2024/04/GHSA-vfmv-3fmr-wr8p/GHSA-vfmv-3fmr-wr8p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vfmv-3fmr-wr8p", - "modified": "2024-04-10T21:30:30Z", + "modified": "2024-07-08T15:31:54Z", "published": "2024-04-10T21:30:30Z", "aliases": [ "CVE-2021-47186" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: check for null after calling kmemdup\n\nkmemdup can return a null pointer so need to check for it, otherwise\nthe null key will be dereferenced later in tipc_crypto_key_xmit as\ncan be seen in the trace [1].\n\n\n[1] https://syzkaller.appspot.com/bug?id=bca180abb29567b189efdbdb34cbf7ba851c2a58", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-690" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T19:15:47Z" diff --git a/advisories/unreviewed/2024/04/GHSA-w5hw-wf94-wxwj/GHSA-w5hw-wf94-wxwj.json b/advisories/unreviewed/2024/04/GHSA-w5hw-wf94-wxwj/GHSA-w5hw-wf94-wxwj.json index 7db9d7e2ebb..fc90cb1feb3 100644 --- a/advisories/unreviewed/2024/04/GHSA-w5hw-wf94-wxwj/GHSA-w5hw-wf94-wxwj.json +++ b/advisories/unreviewed/2024/04/GHSA-w5hw-wf94-wxwj/GHSA-w5hw-wf94-wxwj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w5hw-wf94-wxwj", - "modified": "2024-04-15T06:30:34Z", + "modified": "2024-07-08T15:31:54Z", "published": "2024-04-15T06:30:34Z", "aliases": [ "CVE-2024-1755" ], "details": "The NPS computy WordPress plugin through 2.7.5 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-15T05:15:15Z" diff --git a/advisories/unreviewed/2024/05/GHSA-59j5-r3pj-3q9p/GHSA-59j5-r3pj-3q9p.json b/advisories/unreviewed/2024/05/GHSA-59j5-r3pj-3q9p/GHSA-59j5-r3pj-3q9p.json index a5b06cb2bba..08555cbdb93 100644 --- a/advisories/unreviewed/2024/05/GHSA-59j5-r3pj-3q9p/GHSA-59j5-r3pj-3q9p.json +++ b/advisories/unreviewed/2024/05/GHSA-59j5-r3pj-3q9p/GHSA-59j5-r3pj-3q9p.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-295", "CWE-843" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/05/GHSA-gc8r-vh42-27g4/GHSA-gc8r-vh42-27g4.json b/advisories/unreviewed/2024/05/GHSA-gc8r-vh42-27g4/GHSA-gc8r-vh42-27g4.json index 71eb212c662..90c0657a24d 100644 --- a/advisories/unreviewed/2024/05/GHSA-gc8r-vh42-27g4/GHSA-gc8r-vh42-27g4.json +++ b/advisories/unreviewed/2024/05/GHSA-gc8r-vh42-27g4/GHSA-gc8r-vh42-27g4.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1281" + "CWE-1281", + "CWE-667" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-3g4h-66cq-c8vg/GHSA-3g4h-66cq-c8vg.json b/advisories/unreviewed/2024/06/GHSA-3g4h-66cq-c8vg/GHSA-3g4h-66cq-c8vg.json index d91c9958a12..d4c341e7e53 100644 --- a/advisories/unreviewed/2024/06/GHSA-3g4h-66cq-c8vg/GHSA-3g4h-66cq-c8vg.json +++ b/advisories/unreviewed/2024/06/GHSA-3g4h-66cq-c8vg/GHSA-3g4h-66cq-c8vg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3g4h-66cq-c8vg", - "modified": "2024-06-25T06:30:38Z", + "modified": "2024-07-08T15:31:54Z", "published": "2024-06-24T09:30:53Z", "aliases": [ "CVE-2024-36495" ], "details": "The application Faronics WINSelect (Standard + Enterprise) saves its configuration in an encrypted file on the file system which \"Everyone\" has read and write access to, path to file:\n\n\n\nC:\\ProgramData\\WINSelect\\WINSelect.wsd\n\nThe path for the affected WINSelect Enterprise configuration file is:\n\nC:\\ProgramData\\Faronics\\StorageSpace\\WS\\WINSelect.wsd", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-276" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-24T09:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-4jh7-m9q3-3qw9/GHSA-4jh7-m9q3-3qw9.json b/advisories/unreviewed/2024/06/GHSA-4jh7-m9q3-3qw9/GHSA-4jh7-m9q3-3qw9.json index 1998429c4b4..4589c99b313 100644 --- a/advisories/unreviewed/2024/06/GHSA-4jh7-m9q3-3qw9/GHSA-4jh7-m9q3-3qw9.json +++ b/advisories/unreviewed/2024/06/GHSA-4jh7-m9q3-3qw9/GHSA-4jh7-m9q3-3qw9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4jh7-m9q3-3qw9", - "modified": "2024-06-22T00:30:56Z", + "modified": "2024-07-08T15:31:54Z", "published": "2024-06-22T00:30:56Z", "aliases": [ "CVE-2024-34452" ], "details": "CMSimple_XH 1.7.6 allows XSS by uploading a crafted SVG document.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-21T22:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-8c4j-c9q8-whxc/GHSA-8c4j-c9q8-whxc.json b/advisories/unreviewed/2024/06/GHSA-8c4j-c9q8-whxc/GHSA-8c4j-c9q8-whxc.json index 1c596ea0a90..24da6fedc9e 100644 --- a/advisories/unreviewed/2024/06/GHSA-8c4j-c9q8-whxc/GHSA-8c4j-c9q8-whxc.json +++ b/advisories/unreviewed/2024/06/GHSA-8c4j-c9q8-whxc/GHSA-8c4j-c9q8-whxc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8c4j-c9q8-whxc", - "modified": "2024-06-21T06:31:13Z", + "modified": "2024-07-08T15:31:54Z", "published": "2024-06-21T06:31:13Z", "aliases": [ "CVE-2024-4384" ], "details": "The CSSable Countdown WordPress plugin through 1.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-21T06:15:12Z" diff --git a/advisories/unreviewed/2024/06/GHSA-9j9j-hw77-49hh/GHSA-9j9j-hw77-49hh.json b/advisories/unreviewed/2024/06/GHSA-9j9j-hw77-49hh/GHSA-9j9j-hw77-49hh.json index 57e1152b810..f38f9b4cfd1 100644 --- a/advisories/unreviewed/2024/06/GHSA-9j9j-hw77-49hh/GHSA-9j9j-hw77-49hh.json +++ b/advisories/unreviewed/2024/06/GHSA-9j9j-hw77-49hh/GHSA-9j9j-hw77-49hh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9j9j-hw77-49hh", - "modified": "2024-06-12T03:31:15Z", + "modified": "2024-07-08T15:31:54Z", "published": "2024-06-12T03:31:15Z", "aliases": [ "CVE-2024-36103" ], "details": "OS command injection vulnerability in WRC-X5400GS-B v1.0.10 and earlier, and WRC-X5400GSA-B v1.0.10 and earlier allows a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by sending a specially crafted request to the product.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-12T01:15:49Z" diff --git a/advisories/unreviewed/2024/06/GHSA-vwhp-3xvr-4jc2/GHSA-vwhp-3xvr-4jc2.json b/advisories/unreviewed/2024/06/GHSA-vwhp-3xvr-4jc2/GHSA-vwhp-3xvr-4jc2.json index 774d2cb1788..e92cf917f97 100644 --- a/advisories/unreviewed/2024/06/GHSA-vwhp-3xvr-4jc2/GHSA-vwhp-3xvr-4jc2.json +++ b/advisories/unreviewed/2024/06/GHSA-vwhp-3xvr-4jc2/GHSA-vwhp-3xvr-4jc2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vwhp-3xvr-4jc2", - "modified": "2024-06-27T15:30:45Z", + "modified": "2024-07-08T15:31:54Z", "published": "2024-06-27T15:30:45Z", "aliases": [ "CVE-2024-39154" ], "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mudi=del&dataType=word&dataTypeCN.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-27T14:15:15Z" diff --git a/advisories/unreviewed/2024/06/GHSA-w54f-vq4c-7637/GHSA-w54f-vq4c-7637.json b/advisories/unreviewed/2024/06/GHSA-w54f-vq4c-7637/GHSA-w54f-vq4c-7637.json index a3c85f8a5ea..6e5625bd6e0 100644 --- a/advisories/unreviewed/2024/06/GHSA-w54f-vq4c-7637/GHSA-w54f-vq4c-7637.json +++ b/advisories/unreviewed/2024/06/GHSA-w54f-vq4c-7637/GHSA-w54f-vq4c-7637.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w54f-vq4c-7637", - "modified": "2024-06-26T21:32:17Z", + "modified": "2024-07-08T15:31:54Z", "published": "2024-06-26T21:32:17Z", "aliases": [ "CVE-2024-38949" ], "details": "Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to display444as420 function at sdl.cc", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-26T20:15:16Z" diff --git a/advisories/unreviewed/2024/07/GHSA-37mw-xfjf-m6pf/GHSA-37mw-xfjf-m6pf.json b/advisories/unreviewed/2024/07/GHSA-37mw-xfjf-m6pf/GHSA-37mw-xfjf-m6pf.json index 190af97cf7b..b876f9d158e 100644 --- a/advisories/unreviewed/2024/07/GHSA-37mw-xfjf-m6pf/GHSA-37mw-xfjf-m6pf.json +++ b/advisories/unreviewed/2024/07/GHSA-37mw-xfjf-m6pf/GHSA-37mw-xfjf-m6pf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-37mw-xfjf-m6pf", - "modified": "2024-07-04T03:31:39Z", + "modified": "2024-07-08T15:31:55Z", "published": "2024-07-04T03:31:39Z", "aliases": [ "CVE-2024-38471" ], "details": "Multiple TP-LINK products allow a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by restoring a crafted backup file. The affected device, with the initial configuration, allows login only from the LAN port or Wi-Fi.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-04T01:15:02Z" diff --git a/advisories/unreviewed/2024/07/GHSA-54wv-c7pf-j4j8/GHSA-54wv-c7pf-j4j8.json b/advisories/unreviewed/2024/07/GHSA-54wv-c7pf-j4j8/GHSA-54wv-c7pf-j4j8.json index 98445c4ed55..421326a38b2 100644 --- a/advisories/unreviewed/2024/07/GHSA-54wv-c7pf-j4j8/GHSA-54wv-c7pf-j4j8.json +++ b/advisories/unreviewed/2024/07/GHSA-54wv-c7pf-j4j8/GHSA-54wv-c7pf-j4j8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-54wv-c7pf-j4j8", - "modified": "2024-07-05T18:34:18Z", + "modified": "2024-07-08T15:31:55Z", "published": "2024-07-05T18:34:18Z", "aliases": [ "CVE-2024-27716" ], "details": "Cross Site Scripting vulnerability in Eskooly Web Product v.3.0 and before allows a remote attacker to execute arbitrary code via the message sending and user input fields.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-80" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-05T17:15:11Z" diff --git a/advisories/unreviewed/2024/07/GHSA-5cqg-h2ff-24hv/GHSA-5cqg-h2ff-24hv.json b/advisories/unreviewed/2024/07/GHSA-5cqg-h2ff-24hv/GHSA-5cqg-h2ff-24hv.json index 7863d6e7c2d..d554f180cf8 100644 --- a/advisories/unreviewed/2024/07/GHSA-5cqg-h2ff-24hv/GHSA-5cqg-h2ff-24hv.json +++ b/advisories/unreviewed/2024/07/GHSA-5cqg-h2ff-24hv/GHSA-5cqg-h2ff-24hv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5cqg-h2ff-24hv", - "modified": "2024-07-07T00:37:45Z", + "modified": "2024-07-08T15:31:56Z", "published": "2024-07-07T00:37:45Z", "aliases": [ "CVE-2024-40597" ], "details": "An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. It can expose suppressed information for log events. (The log_deleted attribute is not respected.)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-07T00:15:10Z" diff --git a/advisories/unreviewed/2024/07/GHSA-5f4x-hwv2-w9w2/GHSA-5f4x-hwv2-w9w2.json b/advisories/unreviewed/2024/07/GHSA-5f4x-hwv2-w9w2/GHSA-5f4x-hwv2-w9w2.json index 7bf73aa144c..99f4cceaa46 100644 --- a/advisories/unreviewed/2024/07/GHSA-5f4x-hwv2-w9w2/GHSA-5f4x-hwv2-w9w2.json +++ b/advisories/unreviewed/2024/07/GHSA-5f4x-hwv2-w9w2/GHSA-5f4x-hwv2-w9w2.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-62xc-vffq-mcgg/GHSA-62xc-vffq-mcgg.json b/advisories/unreviewed/2024/07/GHSA-62xc-vffq-mcgg/GHSA-62xc-vffq-mcgg.json index 9998aa8071d..b86d20c055c 100644 --- a/advisories/unreviewed/2024/07/GHSA-62xc-vffq-mcgg/GHSA-62xc-vffq-mcgg.json +++ b/advisories/unreviewed/2024/07/GHSA-62xc-vffq-mcgg/GHSA-62xc-vffq-mcgg.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-75", "CWE-77" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/07/GHSA-6q3c-chw7-6f3j/GHSA-6q3c-chw7-6f3j.json b/advisories/unreviewed/2024/07/GHSA-6q3c-chw7-6f3j/GHSA-6q3c-chw7-6f3j.json index 6bd136f9540..d71b4d7c350 100644 --- a/advisories/unreviewed/2024/07/GHSA-6q3c-chw7-6f3j/GHSA-6q3c-chw7-6f3j.json +++ b/advisories/unreviewed/2024/07/GHSA-6q3c-chw7-6f3j/GHSA-6q3c-chw7-6f3j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6q3c-chw7-6f3j", - "modified": "2024-07-02T21:32:15Z", + "modified": "2024-07-08T15:31:55Z", "published": "2024-07-02T21:32:15Z", "aliases": [ "CVE-2024-39206" ], "details": "An issue discovered in MSP360 Backup Agent v7.8.5.15 and v7.9.4.84 allows attackers to obtain network share credentials used in a backup due to enginesettings.list being encrypted with a hard coded key.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-02T18:15:03Z" diff --git a/advisories/unreviewed/2024/07/GHSA-74r2-gj4j-w655/GHSA-74r2-gj4j-w655.json b/advisories/unreviewed/2024/07/GHSA-74r2-gj4j-w655/GHSA-74r2-gj4j-w655.json new file mode 100644 index 00000000000..c97786425cc --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-74r2-gj4j-w655/GHSA-74r2-gj4j-w655.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-74r2-gj4j-w655", + "modified": "2024-07-08T15:31:56Z", + "published": "2024-07-08T15:31:56Z", + "aliases": [ + "CVE-2024-39743" + ], + "details": "IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to cause a denial of service under certain configurations due to a partial string comparison vulnerability. IBM X-Force ID: 297172.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39743" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/297172" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7159714" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-187" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-08T14:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-7g4v-8cvx-gp5q/GHSA-7g4v-8cvx-gp5q.json b/advisories/unreviewed/2024/07/GHSA-7g4v-8cvx-gp5q/GHSA-7g4v-8cvx-gp5q.json index 26530dfb526..fba006ca316 100644 --- a/advisories/unreviewed/2024/07/GHSA-7g4v-8cvx-gp5q/GHSA-7g4v-8cvx-gp5q.json +++ b/advisories/unreviewed/2024/07/GHSA-7g4v-8cvx-gp5q/GHSA-7g4v-8cvx-gp5q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7g4v-8cvx-gp5q", - "modified": "2024-07-05T15:32:06Z", + "modified": "2024-07-08T15:31:55Z", "published": "2024-07-05T15:32:06Z", "aliases": [ "CVE-2024-38346" ], "details": "The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands on targeted hypervisors and CloudStack management server hosts. Some of these commands were found to have command injection vulnerabilities that can result in arbitrary code execution via agents on the hosts that may run as a privileged user. An attacker that can reach the cluster service on the unauthenticated port (default 9090), can exploit this to perform remote code execution on CloudStack managed hosts and result in complete compromise of the confidentiality, integrity, and availability of CloudStack managed infrastructure.\n\nUsers are recommended to restrict the network access to the cluster service port (default 9090) on a CloudStack management server host to only its peer CloudStack management server hosts. Users are recommended to upgrade to version 4.18.2.1, 4.19.0.2 or later, which addresses this issue.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-05T14:15:02Z" diff --git a/advisories/unreviewed/2024/07/GHSA-7q6c-8c2j-p7xp/GHSA-7q6c-8c2j-p7xp.json b/advisories/unreviewed/2024/07/GHSA-7q6c-8c2j-p7xp/GHSA-7q6c-8c2j-p7xp.json index 17a31bde8c1..cc9fc4fa832 100644 --- a/advisories/unreviewed/2024/07/GHSA-7q6c-8c2j-p7xp/GHSA-7q6c-8c2j-p7xp.json +++ b/advisories/unreviewed/2024/07/GHSA-7q6c-8c2j-p7xp/GHSA-7q6c-8c2j-p7xp.json @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-98p3-57xf-2q44/GHSA-98p3-57xf-2q44.json b/advisories/unreviewed/2024/07/GHSA-98p3-57xf-2q44/GHSA-98p3-57xf-2q44.json index d40fd7ac114..e48ae1c31c4 100644 --- a/advisories/unreviewed/2024/07/GHSA-98p3-57xf-2q44/GHSA-98p3-57xf-2q44.json +++ b/advisories/unreviewed/2024/07/GHSA-98p3-57xf-2q44/GHSA-98p3-57xf-2q44.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-9xcq-99h4-2ffj/GHSA-9xcq-99h4-2ffj.json b/advisories/unreviewed/2024/07/GHSA-9xcq-99h4-2ffj/GHSA-9xcq-99h4-2ffj.json index 69a6eaf3af7..640ccd25c2d 100644 --- a/advisories/unreviewed/2024/07/GHSA-9xcq-99h4-2ffj/GHSA-9xcq-99h4-2ffj.json +++ b/advisories/unreviewed/2024/07/GHSA-9xcq-99h4-2ffj/GHSA-9xcq-99h4-2ffj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9xcq-99h4-2ffj", - "modified": "2024-07-05T18:34:18Z", + "modified": "2024-07-08T15:31:56Z", "published": "2024-07-05T18:34:18Z", "aliases": [ "CVE-2024-27717" ], "details": "Cross Site Request Forgery vulnerability in Eskooly Free Online School Management Software v.3.0 and before allows a remote attacker to escalate privileges via the Token Handling component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-05T17:15:11Z" diff --git a/advisories/unreviewed/2024/07/GHSA-c6gx-2rc7-2pg3/GHSA-c6gx-2rc7-2pg3.json b/advisories/unreviewed/2024/07/GHSA-c6gx-2rc7-2pg3/GHSA-c6gx-2rc7-2pg3.json index 2c8ad7739cf..fd961dcb5d7 100644 --- a/advisories/unreviewed/2024/07/GHSA-c6gx-2rc7-2pg3/GHSA-c6gx-2rc7-2pg3.json +++ b/advisories/unreviewed/2024/07/GHSA-c6gx-2rc7-2pg3/GHSA-c6gx-2rc7-2pg3.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-fjq7-jr7j-jh92/GHSA-fjq7-jr7j-jh92.json b/advisories/unreviewed/2024/07/GHSA-fjq7-jr7j-jh92/GHSA-fjq7-jr7j-jh92.json new file mode 100644 index 00000000000..0d40a456b48 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-fjq7-jr7j-jh92/GHSA-fjq7-jr7j-jh92.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjq7-jr7j-jh92", + "modified": "2024-07-08T15:31:56Z", + "published": "2024-07-08T15:31:56Z", + "aliases": [ + "CVE-2024-6163" + ], + "details": "Certain http endpoints of Checkmk in Checkmk < 2.3.0p10 < 2.2.0p31, < 2.1.0p46, <= 2.0.0p39 allows remote attacker to bypass authentication and access data", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6163" + }, + { + "type": "WEB", + "url": "https://checkmk.com/werk/17011" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-290" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-08T13:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-g5qj-pfmg-p3jp/GHSA-g5qj-pfmg-p3jp.json b/advisories/unreviewed/2024/07/GHSA-g5qj-pfmg-p3jp/GHSA-g5qj-pfmg-p3jp.json index 99a61e77a90..08625f2fc26 100644 --- a/advisories/unreviewed/2024/07/GHSA-g5qj-pfmg-p3jp/GHSA-g5qj-pfmg-p3jp.json +++ b/advisories/unreviewed/2024/07/GHSA-g5qj-pfmg-p3jp/GHSA-g5qj-pfmg-p3jp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g5qj-pfmg-p3jp", - "modified": "2024-07-03T18:47:58Z", + "modified": "2024-07-08T15:31:55Z", "published": "2024-07-02T21:32:15Z", "aliases": [ "CVE-2024-39894" ], "details": "OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-367" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-02T18:15:03Z" diff --git a/advisories/unreviewed/2024/07/GHSA-g9m4-vfq7-w439/GHSA-g9m4-vfq7-w439.json b/advisories/unreviewed/2024/07/GHSA-g9m4-vfq7-w439/GHSA-g9m4-vfq7-w439.json index 8ff7b5966e1..b207af0d5ab 100644 --- a/advisories/unreviewed/2024/07/GHSA-g9m4-vfq7-w439/GHSA-g9m4-vfq7-w439.json +++ b/advisories/unreviewed/2024/07/GHSA-g9m4-vfq7-w439/GHSA-g9m4-vfq7-w439.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g9m4-vfq7-w439", - "modified": "2024-07-03T21:39:43Z", + "modified": "2024-07-08T15:31:55Z", "published": "2024-07-03T21:39:43Z", "aliases": [ "CVE-2024-29511" ], "details": "Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-489" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-03T19:15:03Z" diff --git a/advisories/unreviewed/2024/07/GHSA-mq7h-fm69-h6xq/GHSA-mq7h-fm69-h6xq.json b/advisories/unreviewed/2024/07/GHSA-mq7h-fm69-h6xq/GHSA-mq7h-fm69-h6xq.json index b95b08a265d..f28e30eeccf 100644 --- a/advisories/unreviewed/2024/07/GHSA-mq7h-fm69-h6xq/GHSA-mq7h-fm69-h6xq.json +++ b/advisories/unreviewed/2024/07/GHSA-mq7h-fm69-h6xq/GHSA-mq7h-fm69-h6xq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mq7h-fm69-h6xq", - "modified": "2024-07-03T21:39:44Z", + "modified": "2024-07-08T15:31:55Z", "published": "2024-07-03T21:39:44Z", "aliases": [ "CVE-2024-33871" ], "details": "An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, exploitable via a crafted PostScript document. This occurs because the Driver parameter for opvp (and oprp) devices can have an arbitrary name for a dynamic library; this library is then loaded.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-03T19:15:03Z" diff --git a/advisories/unreviewed/2024/07/GHSA-pf44-j75v-mhr8/GHSA-pf44-j75v-mhr8.json b/advisories/unreviewed/2024/07/GHSA-pf44-j75v-mhr8/GHSA-pf44-j75v-mhr8.json index d2321671041..a94f518faba 100644 --- a/advisories/unreviewed/2024/07/GHSA-pf44-j75v-mhr8/GHSA-pf44-j75v-mhr8.json +++ b/advisories/unreviewed/2024/07/GHSA-pf44-j75v-mhr8/GHSA-pf44-j75v-mhr8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pf44-j75v-mhr8", - "modified": "2024-07-01T21:31:14Z", + "modified": "2024-07-08T15:31:55Z", "published": "2024-07-01T21:31:14Z", "aliases": [ "CVE-2024-38475" ], "details": "Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. \n\nSubstitutions in server context that use a backreferences or variables as the first segment of the substitution are affected.  Some unsafe RewiteRules will be broken by this change and the rewrite flag \"UnsafePrefixStat\" can be used to opt back in once ensuring the substitution is appropriately constrained.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-116" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-01T19:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-pqhg-95v7-rfjf/GHSA-pqhg-95v7-rfjf.json b/advisories/unreviewed/2024/07/GHSA-pqhg-95v7-rfjf/GHSA-pqhg-95v7-rfjf.json index 27ab94f7fed..280ce66199d 100644 --- a/advisories/unreviewed/2024/07/GHSA-pqhg-95v7-rfjf/GHSA-pqhg-95v7-rfjf.json +++ b/advisories/unreviewed/2024/07/GHSA-pqhg-95v7-rfjf/GHSA-pqhg-95v7-rfjf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pqhg-95v7-rfjf", - "modified": "2024-07-05T18:34:18Z", + "modified": "2024-07-08T15:31:56Z", "published": "2024-07-05T18:34:18Z", "aliases": [ "CVE-2024-39174" ], "details": "A cross-site scripting (XSS) vulnerability in the Publish Article function of yzmcms v7.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a published article.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-05T18:15:32Z" diff --git a/advisories/unreviewed/2024/07/GHSA-q45p-9x4j-2gjf/GHSA-q45p-9x4j-2gjf.json b/advisories/unreviewed/2024/07/GHSA-q45p-9x4j-2gjf/GHSA-q45p-9x4j-2gjf.json index 522e64c21b1..4b2c14fba70 100644 --- a/advisories/unreviewed/2024/07/GHSA-q45p-9x4j-2gjf/GHSA-q45p-9x4j-2gjf.json +++ b/advisories/unreviewed/2024/07/GHSA-q45p-9x4j-2gjf/GHSA-q45p-9x4j-2gjf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q45p-9x4j-2gjf", - "modified": "2024-07-05T18:34:18Z", + "modified": "2024-07-08T15:31:55Z", "published": "2024-07-05T18:34:18Z", "aliases": [ "CVE-2024-27715" ], "details": "An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via a crafted request to the Password Change mechanism.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-620" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-05T17:15:11Z" diff --git a/advisories/unreviewed/2024/07/GHSA-q9mv-48mg-vv6w/GHSA-q9mv-48mg-vv6w.json b/advisories/unreviewed/2024/07/GHSA-q9mv-48mg-vv6w/GHSA-q9mv-48mg-vv6w.json index c5a0131cbc2..a4574ee2690 100644 --- a/advisories/unreviewed/2024/07/GHSA-q9mv-48mg-vv6w/GHSA-q9mv-48mg-vv6w.json +++ b/advisories/unreviewed/2024/07/GHSA-q9mv-48mg-vv6w/GHSA-q9mv-48mg-vv6w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q9mv-48mg-vv6w", - "modified": "2024-07-01T18:32:40Z", + "modified": "2024-07-08T15:31:55Z", "published": "2024-07-01T18:32:40Z", "aliases": [ "CVE-2024-36985" @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-253", "CWE-687" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/07/GHSA-qcg7-r5qq-mqmw/GHSA-qcg7-r5qq-mqmw.json b/advisories/unreviewed/2024/07/GHSA-qcg7-r5qq-mqmw/GHSA-qcg7-r5qq-mqmw.json index ba2c7433dfc..7c398f1e308 100644 --- a/advisories/unreviewed/2024/07/GHSA-qcg7-r5qq-mqmw/GHSA-qcg7-r5qq-mqmw.json +++ b/advisories/unreviewed/2024/07/GHSA-qcg7-r5qq-mqmw/GHSA-qcg7-r5qq-mqmw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qcg7-r5qq-mqmw", - "modified": "2024-07-05T15:32:06Z", + "modified": "2024-07-08T15:31:55Z", "published": "2024-07-05T15:32:06Z", "aliases": [ "CVE-2024-39864" ], "details": "The CloudStack integration API service allows running its unauthenticated API server (usually on port 8096 when configured and enabled via integration.api.port global setting) for internal portal integrations and for testing purposes. By default, the integration API service port is disabled and is considered disabled when integration.api.port is set to 0 or negative. Due to an improper initialisation logic, the integration API service would listen on a random port when its port value is set to 0 (default value). An attacker that can access the CloudStack management network could scan and find the randomised integration API service port and exploit it to perform unauthorised administrative actions and perform remote code execution on CloudStack managed hosts and result in complete compromise of the confidentiality, integrity, and availability of CloudStack managed infrastructure.\n\nUsers are recommended to restrict the network access on the CloudStack management server hosts to only essential ports. Users are recommended to upgrade to version 4.18.2.1, 4.19.0.2 or later, which addresses this issue.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ "CWE-665" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-05T14:15:03Z" diff --git a/advisories/unreviewed/2024/07/GHSA-qfw8-4q4g-qh9j/GHSA-qfw8-4q4g-qh9j.json b/advisories/unreviewed/2024/07/GHSA-qfw8-4q4g-qh9j/GHSA-qfw8-4q4g-qh9j.json new file mode 100644 index 00000000000..f12da673f95 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-qfw8-4q4g-qh9j/GHSA-qfw8-4q4g-qh9j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfw8-4q4g-qh9j", + "modified": "2024-07-08T15:31:56Z", + "published": "2024-07-08T15:31:56Z", + "aliases": [ + "CVE-2024-4341" + ], + "details": "Improper Privilege Management vulnerability in Ekstrem Bir Bilgisayar Danismanlik Ic Ve Dis Ticaret Ltd. Sti. Extreme XDS allows Collect Data as Provided by Users.This issue affects Extreme XDS: before 3928.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4341" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-0893" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-08T14:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-qh94-pjxq-88v7/GHSA-qh94-pjxq-88v7.json b/advisories/unreviewed/2024/07/GHSA-qh94-pjxq-88v7/GHSA-qh94-pjxq-88v7.json index 141ced7dd45..90a179b4700 100644 --- a/advisories/unreviewed/2024/07/GHSA-qh94-pjxq-88v7/GHSA-qh94-pjxq-88v7.json +++ b/advisories/unreviewed/2024/07/GHSA-qh94-pjxq-88v7/GHSA-qh94-pjxq-88v7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qh94-pjxq-88v7", - "modified": "2024-07-03T21:39:43Z", + "modified": "2024-07-08T15:31:55Z", "published": "2024-07-03T18:48:27Z", "aliases": [ "CVE-2024-39844" ], "details": "In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-03T17:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-qmqh-r82r-6q87/GHSA-qmqh-r82r-6q87.json b/advisories/unreviewed/2024/07/GHSA-qmqh-r82r-6q87/GHSA-qmqh-r82r-6q87.json index d55a351903e..373b719f18c 100644 --- a/advisories/unreviewed/2024/07/GHSA-qmqh-r82r-6q87/GHSA-qmqh-r82r-6q87.json +++ b/advisories/unreviewed/2024/07/GHSA-qmqh-r82r-6q87/GHSA-qmqh-r82r-6q87.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-75", "CWE-79" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/07/GHSA-r824-gq56-gjgx/GHSA-r824-gq56-gjgx.json b/advisories/unreviewed/2024/07/GHSA-r824-gq56-gjgx/GHSA-r824-gq56-gjgx.json index 7671009f1d1..9f1515b931a 100644 --- a/advisories/unreviewed/2024/07/GHSA-r824-gq56-gjgx/GHSA-r824-gq56-gjgx.json +++ b/advisories/unreviewed/2024/07/GHSA-r824-gq56-gjgx/GHSA-r824-gq56-gjgx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r824-gq56-gjgx", - "modified": "2024-07-03T21:39:43Z", + "modified": "2024-07-08T15:31:55Z", "published": "2024-07-03T21:39:43Z", "aliases": [ "CVE-2024-29510" ], "details": "Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-693" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-03T19:15:03Z" diff --git a/advisories/unreviewed/2024/07/GHSA-rfwq-7qrf-xm4m/GHSA-rfwq-7qrf-xm4m.json b/advisories/unreviewed/2024/07/GHSA-rfwq-7qrf-xm4m/GHSA-rfwq-7qrf-xm4m.json new file mode 100644 index 00000000000..49dcfcc842c --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-rfwq-7qrf-xm4m/GHSA-rfwq-7qrf-xm4m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfwq-7qrf-xm4m", + "modified": "2024-07-08T15:31:55Z", + "published": "2024-07-08T15:31:54Z", + "aliases": [ + "CVE-2024-5728" + ], + "details": "The Animated AL List WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5728" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/287c4e8c-9092-4cb9-9642-e4f3d10f46fa" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-28T06:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-vpjf-pg9h-vm9f/GHSA-vpjf-pg9h-vm9f.json b/advisories/unreviewed/2024/07/GHSA-vpjf-pg9h-vm9f/GHSA-vpjf-pg9h-vm9f.json new file mode 100644 index 00000000000..cf0107b8d4d --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-vpjf-pg9h-vm9f/GHSA-vpjf-pg9h-vm9f.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vpjf-pg9h-vm9f", + "modified": "2024-07-08T15:31:56Z", + "published": "2024-07-08T15:31:56Z", + "aliases": [ + "CVE-2024-39742" + ], + "details": "IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass authentication under certain configurations due to a partial string comparison vulnerability. IBM X-Force ID: 297169.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39742" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/297169" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7159714" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-187" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-08T14:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-vq89-g5m5-675r/GHSA-vq89-g5m5-675r.json b/advisories/unreviewed/2024/07/GHSA-vq89-g5m5-675r/GHSA-vq89-g5m5-675r.json index 628fe4033b1..09ab0d4a706 100644 --- a/advisories/unreviewed/2024/07/GHSA-vq89-g5m5-675r/GHSA-vq89-g5m5-675r.json +++ b/advisories/unreviewed/2024/07/GHSA-vq89-g5m5-675r/GHSA-vq89-g5m5-675r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vq89-g5m5-675r", - "modified": "2024-07-05T09:33:44Z", + "modified": "2024-07-08T15:31:55Z", "published": "2024-07-05T09:33:44Z", "aliases": [ "CVE-2024-39479" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/hwmon: Get rid of devm\n\nWhen both hwmon and hwmon drvdata (on which hwmon depends) are device\nmanaged resources, the expectation, on device unbind, is that hwmon will be\nreleased before drvdata. However, in i915 there are two separate code\npaths, which both release either drvdata or hwmon and either can be\nreleased before the other. These code paths (for device unbind) are as\nfollows (see also the bug referenced below):\n\nCall Trace:\nrelease_nodes+0x11/0x70\ndevres_release_group+0xb2/0x110\ncomponent_unbind_all+0x8d/0xa0\ncomponent_del+0xa5/0x140\nintel_pxp_tee_component_fini+0x29/0x40 [i915]\nintel_pxp_fini+0x33/0x80 [i915]\ni915_driver_remove+0x4c/0x120 [i915]\ni915_pci_remove+0x19/0x30 [i915]\npci_device_remove+0x32/0xa0\ndevice_release_driver_internal+0x19c/0x200\nunbind_store+0x9c/0xb0\n\nand\n\nCall Trace:\nrelease_nodes+0x11/0x70\ndevres_release_all+0x8a/0xc0\ndevice_unbind_cleanup+0x9/0x70\ndevice_release_driver_internal+0x1c1/0x200\nunbind_store+0x9c/0xb0\n\nThis means that in i915, if use devm, we cannot gurantee that hwmon will\nalways be released before drvdata. Which means that we have a uaf if hwmon\nsysfs is accessed when drvdata has been released but hwmon hasn't.\n\nThe only way out of this seems to be do get rid of devm_ and release/free\neverything explicitly during device unbind.\n\nv2: Change commit message and other minor code changes\nv3: Cleanup from i915_hwmon_register on error (Armin Wolf)\nv4: Eliminate potential static analyzer warning (Rodrigo)\n Eliminate fetch_and_zero (Jani)\nv5: Restore previous logic for ddat_gt->hwmon_dev error return (Andi)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-05T07:15:10Z" diff --git a/advisories/unreviewed/2024/07/GHSA-x4p5-hg55-839v/GHSA-x4p5-hg55-839v.json b/advisories/unreviewed/2024/07/GHSA-x4p5-hg55-839v/GHSA-x4p5-hg55-839v.json index ad5780346d3..ea8ba1e4316 100644 --- a/advisories/unreviewed/2024/07/GHSA-x4p5-hg55-839v/GHSA-x4p5-hg55-839v.json +++ b/advisories/unreviewed/2024/07/GHSA-x4p5-hg55-839v/GHSA-x4p5-hg55-839v.json @@ -36,6 +36,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/07/GHSA-x84h-4cj8-32mv/GHSA-x84h-4cj8-32mv.json b/advisories/unreviewed/2024/07/GHSA-x84h-4cj8-32mv/GHSA-x84h-4cj8-32mv.json index fe4a2d8d2a8..784ea237cc3 100644 --- a/advisories/unreviewed/2024/07/GHSA-x84h-4cj8-32mv/GHSA-x84h-4cj8-32mv.json +++ b/advisories/unreviewed/2024/07/GHSA-x84h-4cj8-32mv/GHSA-x84h-4cj8-32mv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x84h-4cj8-32mv", - "modified": "2024-07-01T21:31:16Z", + "modified": "2024-07-08T15:31:55Z", "published": "2024-07-01T21:31:16Z", "aliases": [ "CVE-2024-32229" ], "details": "FFmpeg 7.0 contains a heap-buffer-overflow at libavfilter/vf_tiltandshift.c:189:5 in copy_column.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-01T21:15:03Z"