diff --git a/advisories/github-reviewed/2024/03/GHSA-2qph-qpvm-2qf7/GHSA-2qph-qpvm-2qf7.json b/advisories/github-reviewed/2024/03/GHSA-2qph-qpvm-2qf7/GHSA-2qph-qpvm-2qf7.json index a6392083b6b..904aa40ce30 100644 --- a/advisories/github-reviewed/2024/03/GHSA-2qph-qpvm-2qf7/GHSA-2qph-qpvm-2qf7.json +++ b/advisories/github-reviewed/2024/03/GHSA-2qph-qpvm-2qf7/GHSA-2qph-qpvm-2qf7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2qph-qpvm-2qf7", - "modified": "2024-03-15T19:57:23Z", + "modified": "2024-03-18T18:33:18Z", "published": "2024-03-15T19:57:22Z", "aliases": [ "CVE-2024-28854" @@ -43,10 +43,18 @@ "type": "WEB", "url": "https://github.com/tmccombs/tls-listener/security/advisories/GHSA-2qph-qpvm-2qf7" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28854" + }, { "type": "WEB", "url": "https://github.com/tmccombs/tls-listener/commit/d5a7655d6ea9e53ab57c3013092c5576da964bc4" }, + { + "type": "WEB", + "url": "https://en.wikipedia.org/wiki/Slowloris_(computer_security)" + }, { "type": "PACKAGE", "url": "https://github.com/tmccombs/tls-listener" @@ -58,11 +66,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-03-15T19:57:22Z", - "nvd_published_at": null + "nvd_published_at": "2024-03-15T19:15:07Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2024/03/GHSA-32jq-mv89-5rx7/GHSA-32jq-mv89-5rx7.json b/advisories/github-reviewed/2024/03/GHSA-32jq-mv89-5rx7/GHSA-32jq-mv89-5rx7.json index c8204a13048..e9c5cde7095 100644 --- a/advisories/github-reviewed/2024/03/GHSA-32jq-mv89-5rx7/GHSA-32jq-mv89-5rx7.json +++ b/advisories/github-reviewed/2024/03/GHSA-32jq-mv89-5rx7/GHSA-32jq-mv89-5rx7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-32jq-mv89-5rx7", - "modified": "2024-03-15T19:20:17Z", + "modified": "2024-03-18T18:33:15Z", "published": "2024-03-15T19:20:17Z", "aliases": [ "CVE-2024-28252" @@ -59,6 +59,10 @@ "type": "WEB", "url": "https://github.com/CoreWCF/CoreWCF/security/advisories/GHSA-32jq-mv89-5rx7" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28252" + }, { "type": "WEB", "url": "https://github.com/CoreWCF/CoreWCF/issues/1345" @@ -70,11 +74,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-404" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-03-15T19:20:17Z", - "nvd_published_at": null + "nvd_published_at": "2024-03-15T19:15:07Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2024/03/GHSA-w5wx-6g2r-r78q/GHSA-w5wx-6g2r-r78q.json b/advisories/github-reviewed/2024/03/GHSA-w5wx-6g2r-r78q/GHSA-w5wx-6g2r-r78q.json index 2d0efa59ded..bf3ea7d57cb 100644 --- a/advisories/github-reviewed/2024/03/GHSA-w5wx-6g2r-r78q/GHSA-w5wx-6g2r-r78q.json +++ b/advisories/github-reviewed/2024/03/GHSA-w5wx-6g2r-r78q/GHSA-w5wx-6g2r-r78q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w5wx-6g2r-r78q", - "modified": "2024-03-15T18:44:28Z", + "modified": "2024-03-18T18:33:13Z", "published": "2024-03-15T18:44:28Z", "aliases": [ "CVE-2024-27920" @@ -40,6 +40,10 @@ "type": "WEB", "url": "https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-w5wx-6g2r-r78q" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27920" + }, { "type": "WEB", "url": "https://github.com/projectdiscovery/nuclei/pull/4822" @@ -48,6 +52,18 @@ "type": "WEB", "url": "https://github.com/projectdiscovery/nuclei/commit/e86f38299765b82ad724fdb701557e0eaff3884d" }, + { + "type": "WEB", + "url": "https://docs.projectdiscovery.io/templates/protocols/code" + }, + { + "type": "WEB", + "url": "https://docs.projectdiscovery.io/templates/reference/template-signing" + }, + { + "type": "WEB", + "url": "https://docs.projectdiscovery.io/templates/workflows/overview" + }, { "type": "PACKAGE", "url": "https://github.com/projectdiscovery/nuclei" @@ -60,6 +76,6 @@ "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-03-15T18:44:28Z", - "nvd_published_at": null + "nvd_published_at": "2024-03-15T20:15:09Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2024/03/GHSA-wx8q-4gm9-rj2g/GHSA-wx8q-4gm9-rj2g.json b/advisories/github-reviewed/2024/03/GHSA-wx8q-4gm9-rj2g/GHSA-wx8q-4gm9-rj2g.json index 76e51feb22f..113dce9911e 100644 --- a/advisories/github-reviewed/2024/03/GHSA-wx8q-4gm9-rj2g/GHSA-wx8q-4gm9-rj2g.json +++ b/advisories/github-reviewed/2024/03/GHSA-wx8q-4gm9-rj2g/GHSA-wx8q-4gm9-rj2g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wx8q-4gm9-rj2g", - "modified": "2024-03-15T16:39:37Z", + "modified": "2024-03-18T18:33:11Z", "published": "2024-03-15T16:35:11Z", "aliases": [ "CVE-2023-51699" @@ -40,10 +40,18 @@ "type": "WEB", "url": "https://github.com/fluid-cloudnative/fluid/security/advisories/GHSA-wx8q-4gm9-rj2g" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51699" + }, { "type": "WEB", "url": "https://github.com/fluid-cloudnative/fluid/commit/02b7cd8b79a26092df95d625664994bda485c722" }, + { + "type": "WEB", + "url": "https://github.com/fluid-cloudnative/fluid/commit/e0184cff8790ad000c3e8943392c7f544fad7d66" + }, { "type": "PACKAGE", "url": "https://github.com/fluid-cloudnative/fluid" @@ -56,6 +64,6 @@ "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-03-15T16:35:11Z", - "nvd_published_at": null + "nvd_published_at": "2024-03-15T19:15:06Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-3j4f-wx4w-q2cq/GHSA-3j4f-wx4w-q2cq.json b/advisories/unreviewed/2024/02/GHSA-3j4f-wx4w-q2cq/GHSA-3j4f-wx4w-q2cq.json index 7a665750ef5..ffd2dc61a5e 100644 --- a/advisories/unreviewed/2024/02/GHSA-3j4f-wx4w-q2cq/GHSA-3j4f-wx4w-q2cq.json +++ b/advisories/unreviewed/2024/02/GHSA-3j4f-wx4w-q2cq/GHSA-3j4f-wx4w-q2cq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3j4f-wx4w-q2cq", - "modified": "2024-03-01T15:31:36Z", + "modified": "2024-03-18T18:32:18Z", "published": "2024-02-22T18:30:30Z", "aliases": [ "CVE-2024-26590" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: fix inconsistent per-file compression format\n\nEROFS can select compression algorithms on a per-file basis, and each\nper-file compression algorithm needs to be marked in the on-disk\nsuperblock for initialization.\n\nHowever, syzkaller can generate inconsistent crafted images that use\nan unsupported algorithmtype for specific inodes, e.g. use MicroLZMA\nalgorithmtype even it's not set in `sbi->available_compr_algs`. This\ncan lead to an unexpected \"BUG: kernel NULL pointer dereference\" if\nthe corresponding decompressor isn't built-in.\n\nFix this by checking against `sbi->available_compr_algs` for each\nm_algorithmformat request. Incorrect !erofs_sb_has_compr_cfgs preset\nbitmap is now fixed together since it was harmless previously.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-22T17:15:09Z" diff --git a/advisories/unreviewed/2024/02/GHSA-445q-cj49-wrrx/GHSA-445q-cj49-wrrx.json b/advisories/unreviewed/2024/02/GHSA-445q-cj49-wrrx/GHSA-445q-cj49-wrrx.json index e80605628b3..91426239770 100644 --- a/advisories/unreviewed/2024/02/GHSA-445q-cj49-wrrx/GHSA-445q-cj49-wrrx.json +++ b/advisories/unreviewed/2024/02/GHSA-445q-cj49-wrrx/GHSA-445q-cj49-wrrx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-445q-cj49-wrrx", - "modified": "2024-02-22T18:30:30Z", + "modified": "2024-03-18T18:32:17Z", "published": "2024-02-22T18:30:30Z", "aliases": [ "CVE-2023-52452" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix accesses to uninit stack slots\n\nPrivileged programs are supposed to be able to read uninitialized stack\nmemory (ever since 6715df8d5) but, before this patch, these accesses\nwere permitted inconsistently. In particular, accesses were permitted\nabove state->allocated_stack, but not below it. In other words, if the\nstack was already \"large enough\", the access was permitted, but\notherwise the access was rejected instead of being allowed to \"grow the\nstack\". This undesired rejection was happening in two places:\n- in check_stack_slot_within_bounds()\n- in check_stack_range_initialized()\nThis patch arranges for these accesses to be permitted. A bunch of tests\nthat were relying on the old rejection had to change; all of them were\nchanged to add also run unprivileged, in which case the old behavior\npersists. One tests couldn't be updated - global_func16 - because it\ncan't run unprivileged for other reasons.\n\nThis patch also fixes the tracking of the stack size for variable-offset\nreads. This second fix is bundled in the same commit as the first one\nbecause they're inter-related. Before this patch, writes to the stack\nusing registers containing a variable offset (as opposed to registers\nwith fixed, known values) were not properly contributing to the\nfunction's needed stack size. As a result, it was possible for a program\nto verify, but then to attempt to read out-of-bounds data at runtime\nbecause a too small stack had been allocated for it.\n\nEach function tracks the size of the stack it needs in\nbpf_subprog_info.stack_depth, which is maintained by\nupdate_stack_depth(). For regular memory accesses, check_mem_access()\nwas calling update_state_depth() but it was passing in only the fixed\npart of the offset register, ignoring the variable offset. This was\nincorrect; the minimum possible value of that register should be used\ninstead.\n\nThis tracking is now fixed by centralizing the tracking of stack size in\ngrow_stack_state(), and by lifting the calls to grow_stack_state() to\ncheck_stack_access_within_bounds() as suggested by Andrii. The code is\nnow simpler and more convincingly tracks the correct maximum stack size.\ncheck_stack_range_initialized() can now rely on enough stack having been\nallocated for the access; this helps with the fix for the first issue.\n\nA few tests were changed to also check the stack depth computation. The\none that fails without this patch is verifier_var_off:stack_write_priv_vs_unpriv.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-665" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-22T17:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-4828-5p9m-g4ff/GHSA-4828-5p9m-g4ff.json b/advisories/unreviewed/2024/02/GHSA-4828-5p9m-g4ff/GHSA-4828-5p9m-g4ff.json index 6af184e7046..5744d4223e5 100644 --- a/advisories/unreviewed/2024/02/GHSA-4828-5p9m-g4ff/GHSA-4828-5p9m-g4ff.json +++ b/advisories/unreviewed/2024/02/GHSA-4828-5p9m-g4ff/GHSA-4828-5p9m-g4ff.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4828-5p9m-g4ff", - "modified": "2024-02-15T15:30:26Z", + "modified": "2024-03-18T18:32:17Z", "published": "2024-02-08T15:30:27Z", "aliases": [ "CVE-2024-0985" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0985" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00017.html" + }, { "type": "WEB", "url": "https://www.postgresql.org/support/security/CVE-2024-0985" diff --git a/advisories/unreviewed/2024/02/GHSA-8pq4-pmqh-grvh/GHSA-8pq4-pmqh-grvh.json b/advisories/unreviewed/2024/02/GHSA-8pq4-pmqh-grvh/GHSA-8pq4-pmqh-grvh.json index eb121cbb64f..bd5443e1f4a 100644 --- a/advisories/unreviewed/2024/02/GHSA-8pq4-pmqh-grvh/GHSA-8pq4-pmqh-grvh.json +++ b/advisories/unreviewed/2024/02/GHSA-8pq4-pmqh-grvh/GHSA-8pq4-pmqh-grvh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8pq4-pmqh-grvh", - "modified": "2024-02-23T09:30:38Z", + "modified": "2024-03-18T18:32:17Z", "published": "2024-02-22T18:30:30Z", "aliases": [ "CVE-2024-26586" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmlxsw: spectrum_acl_tcam: Fix stack corruption\n\nWhen tc filters are first added to a net device, the corresponding local\nport gets bound to an ACL group in the device. The group contains a list\nof ACLs. In turn, each ACL points to a different TCAM region where the\nfilters are stored. During forwarding, the ACLs are sequentially\nevaluated until a match is found.\n\nOne reason to place filters in different regions is when they are added\nwith decreasing priorities and in an alternating order so that two\nconsecutive filters can never fit in the same region because of their\nkey usage.\n\nIn Spectrum-2 and newer ASICs the firmware started to report that the\nmaximum number of ACLs in a group is more than 16, but the layout of the\nregister that configures ACL groups (PAGT) was not updated to account\nfor that. It is therefore possible to hit stack corruption [1] in the\nrare case where more than 16 ACLs in a group are required.\n\nFix by limiting the maximum ACL group size to the minimum between what\nthe firmware reports and the maximum ACLs that fit in the PAGT register.\n\nAdd a test case to make sure the machine does not crash when this\ncondition is hit.\n\n[1]\nKernel panic - not syncing: stack-protector: Kernel stack is corrupted in: mlxsw_sp_acl_tcam_group_update+0x116/0x120\n[...]\n dump_stack_lvl+0x36/0x50\n panic+0x305/0x330\n __stack_chk_fail+0x15/0x20\n mlxsw_sp_acl_tcam_group_update+0x116/0x120\n mlxsw_sp_acl_tcam_group_region_attach+0x69/0x110\n mlxsw_sp_acl_tcam_vchunk_get+0x492/0xa20\n mlxsw_sp_acl_tcam_ventry_add+0x25/0xe0\n mlxsw_sp_acl_rule_add+0x47/0x240\n mlxsw_sp_flower_replace+0x1a9/0x1d0\n tc_setup_cb_add+0xdc/0x1c0\n fl_hw_replace_filter+0x146/0x1f0\n fl_change+0xc17/0x1360\n tc_new_tfilter+0x472/0xb90\n rtnetlink_rcv_msg+0x313/0x3b0\n netlink_rcv_skb+0x58/0x100\n netlink_unicast+0x244/0x390\n netlink_sendmsg+0x1e4/0x440\n ____sys_sendmsg+0x164/0x260\n ___sys_sendmsg+0x9a/0xe0\n __sys_sendmsg+0x7a/0xc0\n do_syscall_64+0x40/0xe0\n entry_SYSCALL_64_after_hwframe+0x63/0x6b", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-22T17:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-rw7c-wqqw-8w6c/GHSA-rw7c-wqqw-8w6c.json b/advisories/unreviewed/2024/02/GHSA-rw7c-wqqw-8w6c/GHSA-rw7c-wqqw-8w6c.json index 95277d9235d..270afc1cbbb 100644 --- a/advisories/unreviewed/2024/02/GHSA-rw7c-wqqw-8w6c/GHSA-rw7c-wqqw-8w6c.json +++ b/advisories/unreviewed/2024/02/GHSA-rw7c-wqqw-8w6c/GHSA-rw7c-wqqw-8w6c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rw7c-wqqw-8w6c", - "modified": "2024-02-22T18:30:30Z", + "modified": "2024-03-18T18:32:18Z", "published": "2024-02-22T18:30:30Z", "aliases": [ "CVE-2024-26589" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject variable offset alu on PTR_TO_FLOW_KEYS\n\nFor PTR_TO_FLOW_KEYS, check_flow_keys_access() only uses fixed off\nfor validation. However, variable offset ptr alu is not prohibited\nfor this ptr kind. So the variable offset is not checked.\n\nThe following prog is accepted:\n\n func#0 @0\n 0: R1=ctx() R10=fp0\n 0: (bf) r6 = r1 ; R1=ctx() R6_w=ctx()\n 1: (79) r7 = *(u64 *)(r6 +144) ; R6_w=ctx() R7_w=flow_keys()\n 2: (b7) r8 = 1024 ; R8_w=1024\n 3: (37) r8 /= 1 ; R8_w=scalar()\n 4: (57) r8 &= 1024 ; R8_w=scalar(smin=smin32=0,\n smax=umax=smax32=umax32=1024,var_off=(0x0; 0x400))\n 5: (0f) r7 += r8\n mark_precise: frame0: last_idx 5 first_idx 0 subseq_idx -1\n mark_precise: frame0: regs=r8 stack= before 4: (57) r8 &= 1024\n mark_precise: frame0: regs=r8 stack= before 3: (37) r8 /= 1\n mark_precise: frame0: regs=r8 stack= before 2: (b7) r8 = 1024\n 6: R7_w=flow_keys(smin=smin32=0,smax=umax=smax32=umax32=1024,var_off\n =(0x0; 0x400)) R8_w=scalar(smin=smin32=0,smax=umax=smax32=umax32=1024,\n var_off=(0x0; 0x400))\n 6: (79) r0 = *(u64 *)(r7 +0) ; R0_w=scalar()\n 7: (95) exit\n\nThis prog loads flow_keys to r7, and adds the variable offset r8\nto r7, and finally causes out-of-bounds access:\n\n BUG: unable to handle page fault for address: ffffc90014c80038\n [...]\n Call Trace:\n \n bpf_dispatcher_nop_func include/linux/bpf.h:1231 [inline]\n __bpf_prog_run include/linux/filter.h:651 [inline]\n bpf_prog_run include/linux/filter.h:658 [inline]\n bpf_prog_run_pin_on_cpu include/linux/filter.h:675 [inline]\n bpf_flow_dissect+0x15f/0x350 net/core/flow_dissector.c:991\n bpf_prog_test_run_flow_dissector+0x39d/0x620 net/bpf/test_run.c:1359\n bpf_prog_test_run kernel/bpf/syscall.c:4107 [inline]\n __sys_bpf+0xf8f/0x4560 kernel/bpf/syscall.c:5475\n __do_sys_bpf kernel/bpf/syscall.c:5561 [inline]\n __se_sys_bpf kernel/bpf/syscall.c:5559 [inline]\n __x64_sys_bpf+0x73/0xb0 kernel/bpf/syscall.c:5559\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0x3f/0x110 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nFix this by rejecting ptr alu with variable offset on flow_keys.\nApplying the patch rejects the program with \"R7 pointer arithmetic\non flow_keys prohibited\".", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-119" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-22T17:15:09Z" diff --git a/advisories/unreviewed/2024/02/GHSA-vmpq-wpxg-r7rp/GHSA-vmpq-wpxg-r7rp.json b/advisories/unreviewed/2024/02/GHSA-vmpq-wpxg-r7rp/GHSA-vmpq-wpxg-r7rp.json index d97da1a8d60..a8d43ec2e35 100644 --- a/advisories/unreviewed/2024/02/GHSA-vmpq-wpxg-r7rp/GHSA-vmpq-wpxg-r7rp.json +++ b/advisories/unreviewed/2024/02/GHSA-vmpq-wpxg-r7rp/GHSA-vmpq-wpxg-r7rp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vmpq-wpxg-r7rp", - "modified": "2024-02-22T18:30:30Z", + "modified": "2024-03-18T18:32:17Z", "published": "2024-02-22T18:30:30Z", "aliases": [ "CVE-2024-26587" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: netdevsim: don't try to destroy PHC on VFs\n\nPHC gets initialized in nsim_init_netdevsim(), which\nis only called if (nsim_dev_port_is_pf()).\n\nCreate a counterpart of nsim_init_netdevsim() and\nmove the mock_phc_destroy() there.\n\nThis fixes a crash trying to destroy netdevsim with\nVFs instantiated, as caught by running the devlink.sh test:\n\n BUG: kernel NULL pointer dereference, address: 00000000000000b8\n RIP: 0010:mock_phc_destroy+0xd/0x30\n Call Trace:\n \n nsim_destroy+0x4a/0x70 [netdevsim]\n __nsim_dev_port_del+0x47/0x70 [netdevsim]\n nsim_dev_reload_destroy+0x105/0x120 [netdevsim]\n nsim_drv_remove+0x2f/0xb0 [netdevsim]\n device_release_driver_internal+0x1a1/0x210\n bus_remove_device+0xd5/0x120\n device_del+0x159/0x490\n device_unregister+0x12/0x30\n del_device_store+0x11a/0x1a0 [netdevsim]\n kernfs_fop_write_iter+0x130/0x1d0\n vfs_write+0x30b/0x4b0\n ksys_write+0x69/0xf0\n do_syscall_64+0xcc/0x1e0\n entry_SYSCALL_64_after_hwframe+0x6f/0x77", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-22T17:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-x2wh-v69v-x2w9/GHSA-x2wh-v69v-x2w9.json b/advisories/unreviewed/2024/02/GHSA-x2wh-v69v-x2w9/GHSA-x2wh-v69v-x2w9.json index 7d0e6cde521..734969a3f5d 100644 --- a/advisories/unreviewed/2024/02/GHSA-x2wh-v69v-x2w9/GHSA-x2wh-v69v-x2w9.json +++ b/advisories/unreviewed/2024/02/GHSA-x2wh-v69v-x2w9/GHSA-x2wh-v69v-x2w9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x2wh-v69v-x2w9", - "modified": "2024-02-22T18:30:30Z", + "modified": "2024-03-18T18:32:18Z", "published": "2024-02-22T18:30:30Z", "aliases": [ "CVE-2024-26591" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix re-attachment branch in bpf_tracing_prog_attach\n\nThe following case can cause a crash due to missing attach_btf:\n\n1) load rawtp program\n2) load fentry program with rawtp as target_fd\n3) create tracing link for fentry program with target_fd = 0\n4) repeat 3\n\nIn the end we have:\n\n- prog->aux->dst_trampoline == NULL\n- tgt_prog == NULL (because we did not provide target_fd to link_create)\n- prog->aux->attach_btf == NULL (the program was loaded with attach_prog_fd=X)\n- the program was loaded for tgt_prog but we have no way to find out which one\n\n BUG: kernel NULL pointer dereference, address: 0000000000000058\n Call Trace:\n \n ? __die+0x20/0x70\n ? page_fault_oops+0x15b/0x430\n ? fixup_exception+0x22/0x330\n ? exc_page_fault+0x6f/0x170\n ? asm_exc_page_fault+0x22/0x30\n ? bpf_tracing_prog_attach+0x279/0x560\n ? btf_obj_id+0x5/0x10\n bpf_tracing_prog_attach+0x439/0x560\n __sys_bpf+0x1cf4/0x2de0\n __x64_sys_bpf+0x1c/0x30\n do_syscall_64+0x41/0xf0\n entry_SYSCALL_64_after_hwframe+0x6e/0x76\n\nReturn -EINVAL in this situation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-22T17:15:09Z" diff --git a/advisories/unreviewed/2024/02/GHSA-x6p5-7c22-qrq6/GHSA-x6p5-7c22-qrq6.json b/advisories/unreviewed/2024/02/GHSA-x6p5-7c22-qrq6/GHSA-x6p5-7c22-qrq6.json index d25e5b6e242..a19f7f9c5f4 100644 --- a/advisories/unreviewed/2024/02/GHSA-x6p5-7c22-qrq6/GHSA-x6p5-7c22-qrq6.json +++ b/advisories/unreviewed/2024/02/GHSA-x6p5-7c22-qrq6/GHSA-x6p5-7c22-qrq6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x6p5-7c22-qrq6", - "modified": "2024-02-22T18:30:30Z", + "modified": "2024-03-18T18:32:18Z", "published": "2024-02-22T18:30:30Z", "aliases": [ "CVE-2024-26588" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: BPF: Prevent out-of-bounds memory access\n\nThe test_tag test triggers an unhandled page fault:\n\n # ./test_tag\n [ 130.640218] CPU 0 Unable to handle kernel paging request at virtual address ffff80001b898004, era == 9000000003137f7c, ra == 9000000003139e70\n [ 130.640501] Oops[#3]:\n [ 130.640553] CPU: 0 PID: 1326 Comm: test_tag Tainted: G D O 6.7.0-rc4-loong-devel-gb62ab1a397cf #47 61985c1d94084daa2432f771daa45b56b10d8d2a\n [ 130.640764] Hardware name: QEMU QEMU Virtual Machine, BIOS unknown 2/2/2022\n [ 130.640874] pc 9000000003137f7c ra 9000000003139e70 tp 9000000104cb4000 sp 9000000104cb7a40\n [ 130.641001] a0 ffff80001b894000 a1 ffff80001b897ff8 a2 000000006ba210be a3 0000000000000000\n [ 130.641128] a4 000000006ba210be a5 00000000000000f1 a6 00000000000000b3 a7 0000000000000000\n [ 130.641256] t0 0000000000000000 t1 00000000000007f6 t2 0000000000000000 t3 9000000004091b70\n [ 130.641387] t4 000000006ba210be t5 0000000000000004 t6 fffffffffffffff0 t7 90000000040913e0\n [ 130.641512] t8 0000000000000005 u0 0000000000000dc0 s9 0000000000000009 s0 9000000104cb7ae0\n [ 130.641641] s1 00000000000007f6 s2 0000000000000009 s3 0000000000000095 s4 0000000000000000\n [ 130.641771] s5 ffff80001b894000 s6 ffff80001b897fb0 s7 9000000004090c50 s8 0000000000000000\n [ 130.641900] ra: 9000000003139e70 build_body+0x1fcc/0x4988\n [ 130.642007] ERA: 9000000003137f7c build_body+0xd8/0x4988\n [ 130.642112] CRMD: 000000b0 (PLV0 -IE -DA +PG DACF=CC DACM=CC -WE)\n [ 130.642261] PRMD: 00000004 (PPLV0 +PIE -PWE)\n [ 130.642353] EUEN: 00000003 (+FPE +SXE -ASXE -BTE)\n [ 130.642458] ECFG: 00071c1c (LIE=2-4,10-12 VS=7)\n [ 130.642554] ESTAT: 00010000 [PIL] (IS= ECode=1 EsubCode=0)\n [ 130.642658] BADV: ffff80001b898004\n [ 130.642719] PRID: 0014c010 (Loongson-64bit, Loongson-3A5000)\n [ 130.642815] Modules linked in: [last unloaded: bpf_testmod(O)]\n [ 130.642924] Process test_tag (pid: 1326, threadinfo=00000000f7f4015f, task=000000006499f9fd)\n [ 130.643062] Stack : 0000000000000000 9000000003380724 0000000000000000 0000000104cb7be8\n [ 130.643213] 0000000000000000 25af8d9b6e600558 9000000106250ea0 9000000104cb7ae0\n [ 130.643378] 0000000000000000 0000000000000000 9000000104cb7be8 90000000049f6000\n [ 130.643538] 0000000000000090 9000000106250ea0 ffff80001b894000 ffff80001b894000\n [ 130.643685] 00007ffffb917790 900000000313ca94 0000000000000000 0000000000000000\n [ 130.643831] ffff80001b894000 0000000000000ff7 0000000000000000 9000000100468000\n [ 130.643983] 0000000000000000 0000000000000000 0000000000000040 25af8d9b6e600558\n [ 130.644131] 0000000000000bb7 ffff80001b894048 0000000000000000 0000000000000000\n [ 130.644276] 9000000104cb7be8 90000000049f6000 0000000000000090 9000000104cb7bdc\n [ 130.644423] ffff80001b894000 0000000000000000 00007ffffb917790 90000000032acfb0\n [ 130.644572] ...\n [ 130.644629] Call Trace:\n [ 130.644641] [<9000000003137f7c>] build_body+0xd8/0x4988\n [ 130.644785] [<900000000313ca94>] bpf_int_jit_compile+0x228/0x4ec\n [ 130.644891] [<90000000032acfb0>] bpf_prog_select_runtime+0x158/0x1b0\n [ 130.645003] [<90000000032b3504>] bpf_prog_load+0x760/0xb44\n [ 130.645089] [<90000000032b6744>] __sys_bpf+0xbb8/0x2588\n [ 130.645175] [<90000000032b8388>] sys_bpf+0x20/0x2c\n [ 130.645259] [<9000000003f6ab38>] do_syscall+0x7c/0x94\n [ 130.645369] [<9000000003121c5c>] handle_syscall+0xbc/0x158\n [ 130.645507]\n [ 130.645539] Code: 380839f6 380831f9 28412bae <24000ca6> 004081ad 0014cb50 004083e8 02bff34c 58008e91\n [ 130.645729]\n [ 130.646418] ---[ end trace 0000000000000000 ]---\n\nOn my machine, which has CONFIG_PAGE_SIZE_16KB=y, the test failed at\nloading a BPF prog with 2039 instructions:\n\n prog = (struct bpf_prog *)ffff80001b894000\n insn = (struct bpf_insn *)(prog->insnsi)fff\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-119" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-22T17:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-22qf-62f9-pj62/GHSA-22qf-62f9-pj62.json b/advisories/unreviewed/2024/03/GHSA-22qf-62f9-pj62/GHSA-22qf-62f9-pj62.json new file mode 100644 index 00000000000..28034347880 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-22qf-62f9-pj62/GHSA-22qf-62f9-pj62.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22qf-62f9-pj62", + "modified": "2024-03-18T18:32:19Z", + "published": "2024-03-18T18:32:19Z", + "aliases": [ + "CVE-2024-2390" + ], + "details": "\nAs a part of Tenable’s vulnerability disclosure program, a vulnerability in a Nessus plugin was identified and reported. This vulnerability could allow a malicious actor with sufficient permissions on a scan target to place a binary in a specific filesystem location, and abuse the impacted plugin in order to escalate privileges.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2390" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/tns-2024-05" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-2j6j-3rj5-q42q/GHSA-2j6j-3rj5-q42q.json b/advisories/unreviewed/2024/03/GHSA-2j6j-3rj5-q42q/GHSA-2j6j-3rj5-q42q.json new file mode 100644 index 00000000000..13ff645179f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-2j6j-3rj5-q42q/GHSA-2j6j-3rj5-q42q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2j6j-3rj5-q42q", + "modified": "2024-03-18T18:32:22Z", + "published": "2024-03-18T18:32:22Z", + "aliases": [ + "CVE-2024-26124" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26124" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-2jhg-m9q6-9g5r/GHSA-2jhg-m9q6-9g5r.json b/advisories/unreviewed/2024/03/GHSA-2jhg-m9q6-9g5r/GHSA-2jhg-m9q6-9g5r.json new file mode 100644 index 00000000000..bc3f3240090 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-2jhg-m9q6-9g5r/GHSA-2jhg-m9q6-9g5r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jhg-m9q6-9g5r", + "modified": "2024-03-18T18:32:20Z", + "published": "2024-03-18T18:32:20Z", + "aliases": [ + "CVE-2024-26031" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26031" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-2m47-v5fj-pw7f/GHSA-2m47-v5fj-pw7f.json b/advisories/unreviewed/2024/03/GHSA-2m47-v5fj-pw7f/GHSA-2m47-v5fj-pw7f.json new file mode 100644 index 00000000000..d4990040db7 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-2m47-v5fj-pw7f/GHSA-2m47-v5fj-pw7f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2m47-v5fj-pw7f", + "modified": "2024-03-18T18:32:22Z", + "published": "2024-03-18T18:32:22Z", + "aliases": [ + "CVE-2024-26118" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26118" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-2xch-p52g-f698/GHSA-2xch-p52g-f698.json b/advisories/unreviewed/2024/03/GHSA-2xch-p52g-f698/GHSA-2xch-p52g-f698.json new file mode 100644 index 00000000000..147281ec240 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-2xch-p52g-f698/GHSA-2xch-p52g-f698.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2xch-p52g-f698", + "modified": "2024-03-18T18:32:22Z", + "published": "2024-03-18T18:32:22Z", + "aliases": [ + "CVE-2024-26069" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26069" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-32v3-7hw6-xgvj/GHSA-32v3-7hw6-xgvj.json b/advisories/unreviewed/2024/03/GHSA-32v3-7hw6-xgvj/GHSA-32v3-7hw6-xgvj.json new file mode 100644 index 00000000000..265b65922c6 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-32v3-7hw6-xgvj/GHSA-32v3-7hw6-xgvj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32v3-7hw6-xgvj", + "modified": "2024-03-18T18:32:21Z", + "published": "2024-03-18T18:32:21Z", + "aliases": [ + "CVE-2024-26062" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26062" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-344f-3xh7-82cg/GHSA-344f-3xh7-82cg.json b/advisories/unreviewed/2024/03/GHSA-344f-3xh7-82cg/GHSA-344f-3xh7-82cg.json new file mode 100644 index 00000000000..5071ad3ff6e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-344f-3xh7-82cg/GHSA-344f-3xh7-82cg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-344f-3xh7-82cg", + "modified": "2024-03-18T18:32:21Z", + "published": "2024-03-18T18:32:21Z", + "aliases": [ + "CVE-2024-26044" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into a webpage. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable script. This could result in arbitrary code execution in the context of the victim's browser.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26044" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-35xr-m7j2-qj4j/GHSA-35xr-m7j2-qj4j.json b/advisories/unreviewed/2024/03/GHSA-35xr-m7j2-qj4j/GHSA-35xr-m7j2-qj4j.json new file mode 100644 index 00000000000..c9d8dbc29c1 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-35xr-m7j2-qj4j/GHSA-35xr-m7j2-qj4j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35xr-m7j2-qj4j", + "modified": "2024-03-18T18:32:22Z", + "published": "2024-03-18T18:32:22Z", + "aliases": [ + "CVE-2024-26105" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26105" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-4486-4g8h-533q/GHSA-4486-4g8h-533q.json b/advisories/unreviewed/2024/03/GHSA-4486-4g8h-533q/GHSA-4486-4g8h-533q.json new file mode 100644 index 00000000000..343120973b9 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-4486-4g8h-533q/GHSA-4486-4g8h-533q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4486-4g8h-533q", + "modified": "2024-03-18T18:32:22Z", + "published": "2024-03-18T18:32:22Z", + "aliases": [ + "CVE-2024-26120" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26120" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-46wq-gr73-cq3w/GHSA-46wq-gr73-cq3w.json b/advisories/unreviewed/2024/03/GHSA-46wq-gr73-cq3w/GHSA-46wq-gr73-cq3w.json new file mode 100644 index 00000000000..06c517c58fe --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-46wq-gr73-cq3w/GHSA-46wq-gr73-cq3w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46wq-gr73-cq3w", + "modified": "2024-03-18T18:32:21Z", + "published": "2024-03-18T18:32:21Z", + "aliases": [ + "CVE-2024-26034" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26034" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-47wp-357w-7g4p/GHSA-47wp-357w-7g4p.json b/advisories/unreviewed/2024/03/GHSA-47wp-357w-7g4p/GHSA-47wp-357w-7g4p.json new file mode 100644 index 00000000000..1f6eace6f67 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-47wp-357w-7g4p/GHSA-47wp-357w-7g4p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47wp-357w-7g4p", + "modified": "2024-03-18T18:32:18Z", + "published": "2024-03-18T18:32:18Z", + "aliases": [ + "CVE-2024-20755" + ], + "details": "Bridge versions 13.0.5, 14.0.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20755" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/bridge/apsb24-15.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-49mg-fmq8-qjx2/GHSA-49mg-fmq8-qjx2.json b/advisories/unreviewed/2024/03/GHSA-49mg-fmq8-qjx2/GHSA-49mg-fmq8-qjx2.json new file mode 100644 index 00000000000..95bdb3df6f6 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-49mg-fmq8-qjx2/GHSA-49mg-fmq8-qjx2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49mg-fmq8-qjx2", + "modified": "2024-03-18T18:32:18Z", + "published": "2024-03-18T18:32:18Z", + "aliases": [ + "CVE-2024-20757" + ], + "details": "Bridge versions 13.0.5, 14.0.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20757" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/bridge/apsb24-15.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-4v5r-2vpm-gvgv/GHSA-4v5r-2vpm-gvgv.json b/advisories/unreviewed/2024/03/GHSA-4v5r-2vpm-gvgv/GHSA-4v5r-2vpm-gvgv.json new file mode 100644 index 00000000000..bba305e5291 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-4v5r-2vpm-gvgv/GHSA-4v5r-2vpm-gvgv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4v5r-2vpm-gvgv", + "modified": "2024-03-18T18:32:20Z", + "published": "2024-03-18T18:32:20Z", + "aliases": [ + "CVE-2024-26033" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26033" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-4wvj-qq8r-j7f5/GHSA-4wvj-qq8r-j7f5.json b/advisories/unreviewed/2024/03/GHSA-4wvj-qq8r-j7f5/GHSA-4wvj-qq8r-j7f5.json new file mode 100644 index 00000000000..6f0ce3afe15 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-4wvj-qq8r-j7f5/GHSA-4wvj-qq8r-j7f5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wvj-qq8r-j7f5", + "modified": "2024-03-18T18:32:21Z", + "published": "2024-03-18T18:32:21Z", + "aliases": [ + "CVE-2024-26042" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable web pages. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable script. This could result in arbitrary code execution in the context of the victim's browser.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26042" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-5397-vmv2-vf75/GHSA-5397-vmv2-vf75.json b/advisories/unreviewed/2024/03/GHSA-5397-vmv2-vf75/GHSA-5397-vmv2-vf75.json new file mode 100644 index 00000000000..18c90bd94b3 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-5397-vmv2-vf75/GHSA-5397-vmv2-vf75.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5397-vmv2-vf75", + "modified": "2024-03-18T18:32:18Z", + "published": "2024-03-18T18:32:18Z", + "aliases": [ + "CVE-2024-20756" + ], + "details": "Bridge versions 13.0.5, 14.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20756" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/bridge/apsb24-15.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-5hc3-jgcx-6wj9/GHSA-5hc3-jgcx-6wj9.json b/advisories/unreviewed/2024/03/GHSA-5hc3-jgcx-6wj9/GHSA-5hc3-jgcx-6wj9.json new file mode 100644 index 00000000000..1de11d8192f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-5hc3-jgcx-6wj9/GHSA-5hc3-jgcx-6wj9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hc3-jgcx-6wj9", + "modified": "2024-03-18T18:32:20Z", + "published": "2024-03-18T18:32:20Z", + "aliases": [ + "CVE-2024-20762" + ], + "details": "Animate versions 24.0, 23.0.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20762" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/animate/apsb24-19.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-5hmm-p9xx-45x3/GHSA-5hmm-p9xx-45x3.json b/advisories/unreviewed/2024/03/GHSA-5hmm-p9xx-45x3/GHSA-5hmm-p9xx-45x3.json new file mode 100644 index 00000000000..f6d0680345f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-5hmm-p9xx-45x3/GHSA-5hmm-p9xx-45x3.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hmm-p9xx-45x3", + "modified": "2024-03-18T18:32:19Z", + "published": "2024-03-18T18:32:19Z", + "aliases": [ + "CVE-2024-28054" + ], + "details": "Amavis before 2.12.3 and 2.13.x before 2.13.1, in part because of its use of MIME-tools, has an Interpretation Conflict (relative to some mail user agents) when there are multiple boundary parameters in a MIME email message. Consequently, there can be an incorrect check for banned files or malware.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28054" + }, + { + "type": "WEB", + "url": "https://gitlab.com/amavis/amavis/-/issues/112" + }, + { + "type": "WEB", + "url": "https://gitlab.com/amavis/amavis/-/raw/v2.13.1/README_FILES/README.CVE-2024-28054" + }, + { + "type": "WEB", + "url": "https://lists.amavis.org/pipermail/amavis-users/2024-March/006811.html" + }, + { + "type": "WEB", + "url": "https://metacpan.org/pod/MIME::Tools" + }, + { + "type": "WEB", + "url": "https://www.amavis.org/release-notes.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-5q47-v43c-crgw/GHSA-5q47-v43c-crgw.json b/advisories/unreviewed/2024/03/GHSA-5q47-v43c-crgw/GHSA-5q47-v43c-crgw.json new file mode 100644 index 00000000000..db96ac5408f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-5q47-v43c-crgw/GHSA-5q47-v43c-crgw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5q47-v43c-crgw", + "modified": "2024-03-18T18:32:22Z", + "published": "2024-03-18T18:32:22Z", + "aliases": [ + "CVE-2024-26096" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26096" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-642x-2cm7-w2f3/GHSA-642x-2cm7-w2f3.json b/advisories/unreviewed/2024/03/GHSA-642x-2cm7-w2f3/GHSA-642x-2cm7-w2f3.json new file mode 100644 index 00000000000..c725103538b --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-642x-2cm7-w2f3/GHSA-642x-2cm7-w2f3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-642x-2cm7-w2f3", + "modified": "2024-03-18T18:32:22Z", + "published": "2024-03-18T18:32:22Z", + "aliases": [ + "CVE-2024-26101" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26101" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-67fh-mwc3-f4mg/GHSA-67fh-mwc3-f4mg.json b/advisories/unreviewed/2024/03/GHSA-67fh-mwc3-f4mg/GHSA-67fh-mwc3-f4mg.json new file mode 100644 index 00000000000..2b704877ec7 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-67fh-mwc3-f4mg/GHSA-67fh-mwc3-f4mg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67fh-mwc3-f4mg", + "modified": "2024-03-18T18:32:21Z", + "published": "2024-03-18T18:32:21Z", + "aliases": [ + "CVE-2024-26052" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26052" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-686x-3pf5-phx7/GHSA-686x-3pf5-phx7.json b/advisories/unreviewed/2024/03/GHSA-686x-3pf5-phx7/GHSA-686x-3pf5-phx7.json new file mode 100644 index 00000000000..5e1088ca6f4 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-686x-3pf5-phx7/GHSA-686x-3pf5-phx7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-686x-3pf5-phx7", + "modified": "2024-03-18T18:32:20Z", + "published": "2024-03-18T18:32:20Z", + "aliases": [ + "CVE-2024-20768" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20768" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-6cc9-hqx2-m8hv/GHSA-6cc9-hqx2-m8hv.json b/advisories/unreviewed/2024/03/GHSA-6cc9-hqx2-m8hv/GHSA-6cc9-hqx2-m8hv.json new file mode 100644 index 00000000000..5fe2be59f71 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-6cc9-hqx2-m8hv/GHSA-6cc9-hqx2-m8hv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cc9-hqx2-m8hv", + "modified": "2024-03-18T18:32:21Z", + "published": "2024-03-18T18:32:21Z", + "aliases": [ + "CVE-2024-26035" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26035" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-6cqr-v52p-q7rj/GHSA-6cqr-v52p-q7rj.json b/advisories/unreviewed/2024/03/GHSA-6cqr-v52p-q7rj/GHSA-6cqr-v52p-q7rj.json new file mode 100644 index 00000000000..28ae549e689 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-6cqr-v52p-q7rj/GHSA-6cqr-v52p-q7rj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cqr-v52p-q7rj", + "modified": "2024-03-18T18:32:22Z", + "published": "2024-03-18T18:32:22Z", + "aliases": [ + "CVE-2024-26102" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26102" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-6fvf-9vjh-q8x9/GHSA-6fvf-9vjh-q8x9.json b/advisories/unreviewed/2024/03/GHSA-6fvf-9vjh-q8x9/GHSA-6fvf-9vjh-q8x9.json new file mode 100644 index 00000000000..3286460d980 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-6fvf-9vjh-q8x9/GHSA-6fvf-9vjh-q8x9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6fvf-9vjh-q8x9", + "modified": "2024-03-18T18:32:22Z", + "published": "2024-03-18T18:32:22Z", + "aliases": [ + "CVE-2024-26064" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into a webpage. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable script. This could result in arbitrary code execution in the context of the victim's browser. Exploitation of this issue requires user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26064" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-6h67-x962-pr3h/GHSA-6h67-x962-pr3h.json b/advisories/unreviewed/2024/03/GHSA-6h67-x962-pr3h/GHSA-6h67-x962-pr3h.json new file mode 100644 index 00000000000..e1a9ba4155c --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-6h67-x962-pr3h/GHSA-6h67-x962-pr3h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6h67-x962-pr3h", + "modified": "2024-03-18T18:32:22Z", + "published": "2024-03-18T18:32:22Z", + "aliases": [ + "CVE-2024-26107" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26107" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-7v4v-w93x-2p85/GHSA-7v4v-w93x-2p85.json b/advisories/unreviewed/2024/03/GHSA-7v4v-w93x-2p85/GHSA-7v4v-w93x-2p85.json new file mode 100644 index 00000000000..3d8dced6018 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-7v4v-w93x-2p85/GHSA-7v4v-w93x-2p85.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7v4v-w93x-2p85", + "modified": "2024-03-18T18:32:22Z", + "published": "2024-03-18T18:32:22Z", + "aliases": [ + "CVE-2024-26073" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26073" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-7wc9-x26x-7jcr/GHSA-7wc9-x26x-7jcr.json b/advisories/unreviewed/2024/03/GHSA-7wc9-x26x-7jcr/GHSA-7wc9-x26x-7jcr.json new file mode 100644 index 00000000000..ce301fbea6d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-7wc9-x26x-7jcr/GHSA-7wc9-x26x-7jcr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wc9-x26x-7jcr", + "modified": "2024-03-18T18:32:22Z", + "published": "2024-03-18T18:32:22Z", + "aliases": [ + "CVE-2024-26125" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26125" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-82c7-8cqr-qmv6/GHSA-82c7-8cqr-qmv6.json b/advisories/unreviewed/2024/03/GHSA-82c7-8cqr-qmv6/GHSA-82c7-8cqr-qmv6.json new file mode 100644 index 00000000000..65eb9a8e8c9 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-82c7-8cqr-qmv6/GHSA-82c7-8cqr-qmv6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82c7-8cqr-qmv6", + "modified": "2024-03-18T18:32:22Z", + "published": "2024-03-18T18:32:22Z", + "aliases": [ + "CVE-2024-26080" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable web pages. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable script.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26080" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-82r6-xqp6-439v/GHSA-82r6-xqp6-439v.json b/advisories/unreviewed/2024/03/GHSA-82r6-xqp6-439v/GHSA-82r6-xqp6-439v.json new file mode 100644 index 00000000000..67927a97550 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-82r6-xqp6-439v/GHSA-82r6-xqp6-439v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82r6-xqp6-439v", + "modified": "2024-03-18T18:32:22Z", + "published": "2024-03-18T18:32:22Z", + "aliases": [ + "CVE-2024-26106" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26106" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-8342-5mrm-xwwg/GHSA-8342-5mrm-xwwg.json b/advisories/unreviewed/2024/03/GHSA-8342-5mrm-xwwg/GHSA-8342-5mrm-xwwg.json new file mode 100644 index 00000000000..bab8f8c904d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-8342-5mrm-xwwg/GHSA-8342-5mrm-xwwg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8342-5mrm-xwwg", + "modified": "2024-03-18T18:32:18Z", + "published": "2024-03-18T18:32:18Z", + "aliases": [ + "CVE-2024-2229" + ], + "details": "\nCWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code\nexecution when a malicious project file is loaded into the application by a valid user.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2229" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-072-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-072-02.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-842p-2vmc-h4jw/GHSA-842p-2vmc-h4jw.json b/advisories/unreviewed/2024/03/GHSA-842p-2vmc-h4jw/GHSA-842p-2vmc-h4jw.json new file mode 100644 index 00000000000..e4e274abd53 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-842p-2vmc-h4jw/GHSA-842p-2vmc-h4jw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-842p-2vmc-h4jw", + "modified": "2024-03-18T18:32:18Z", + "published": "2024-03-18T18:32:18Z", + "aliases": [ + "CVE-2024-2050" + ], + "details": "\nCWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)\nvulnerability exists when an attacker injects then executes arbitrary malicious JavaScript code\nwithin the context of the product.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2050" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-072-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-072-01.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-89p2-cvfx-5rv6/GHSA-89p2-cvfx-5rv6.json b/advisories/unreviewed/2024/03/GHSA-89p2-cvfx-5rv6/GHSA-89p2-cvfx-5rv6.json new file mode 100644 index 00000000000..7e845e1968e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-89p2-cvfx-5rv6/GHSA-89p2-cvfx-5rv6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89p2-cvfx-5rv6", + "modified": "2024-03-18T18:32:19Z", + "published": "2024-03-18T18:32:19Z", + "aliases": [ + "CVE-2024-20761" + ], + "details": "Animate versions 24.0, 23.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20761" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/animate/apsb24-19.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-9g7g-qqxg-h82x/GHSA-9g7g-qqxg-h82x.json b/advisories/unreviewed/2024/03/GHSA-9g7g-qqxg-h82x/GHSA-9g7g-qqxg-h82x.json new file mode 100644 index 00000000000..633af2ed310 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-9g7g-qqxg-h82x/GHSA-9g7g-qqxg-h82x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9g7g-qqxg-h82x", + "modified": "2024-03-18T18:32:22Z", + "published": "2024-03-18T18:32:22Z", + "aliases": [ + "CVE-2024-26067" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26067" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-9p58-h634-47q5/GHSA-9p58-h634-47q5.json b/advisories/unreviewed/2024/03/GHSA-9p58-h634-47q5/GHSA-9p58-h634-47q5.json new file mode 100644 index 00000000000..90a699cd203 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-9p58-h634-47q5/GHSA-9p58-h634-47q5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9p58-h634-47q5", + "modified": "2024-03-18T18:32:22Z", + "published": "2024-03-18T18:32:22Z", + "aliases": [ + "CVE-2024-26119" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26119" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-c6jc-hpww-995r/GHSA-c6jc-hpww-995r.json b/advisories/unreviewed/2024/03/GHSA-c6jc-hpww-995r/GHSA-c6jc-hpww-995r.json new file mode 100644 index 00000000000..69a36d07650 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-c6jc-hpww-995r/GHSA-c6jc-hpww-995r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6jc-hpww-995r", + "modified": "2024-03-18T18:32:22Z", + "published": "2024-03-18T18:32:22Z", + "aliases": [ + "CVE-2024-26104" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26104" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-c737-8pj3-c7c7/GHSA-c737-8pj3-c7c7.json b/advisories/unreviewed/2024/03/GHSA-c737-8pj3-c7c7/GHSA-c737-8pj3-c7c7.json new file mode 100644 index 00000000000..f5fa34f4450 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-c737-8pj3-c7c7/GHSA-c737-8pj3-c7c7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c737-8pj3-c7c7", + "modified": "2024-03-18T18:32:21Z", + "published": "2024-03-18T18:32:21Z", + "aliases": [ + "CVE-2024-26056" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26056" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-cv5w-6cf2-xxvj/GHSA-cv5w-6cf2-xxvj.json b/advisories/unreviewed/2024/03/GHSA-cv5w-6cf2-xxvj/GHSA-cv5w-6cf2-xxvj.json new file mode 100644 index 00000000000..d76d5d6fc73 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-cv5w-6cf2-xxvj/GHSA-cv5w-6cf2-xxvj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cv5w-6cf2-xxvj", + "modified": "2024-03-18T18:32:21Z", + "published": "2024-03-18T18:32:21Z", + "aliases": [ + "CVE-2024-26040" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26040" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-cwg6-9jmv-938r/GHSA-cwg6-9jmv-938r.json b/advisories/unreviewed/2024/03/GHSA-cwg6-9jmv-938r/GHSA-cwg6-9jmv-938r.json new file mode 100644 index 00000000000..45acb1a8283 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-cwg6-9jmv-938r/GHSA-cwg6-9jmv-938r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwg6-9jmv-938r", + "modified": "2024-03-18T18:32:21Z", + "published": "2024-03-18T18:32:21Z", + "aliases": [ + "CVE-2024-26059" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26059" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-cwg9-5f2g-87h2/GHSA-cwg9-5f2g-87h2.json b/advisories/unreviewed/2024/03/GHSA-cwg9-5f2g-87h2/GHSA-cwg9-5f2g-87h2.json new file mode 100644 index 00000000000..afff9e64679 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-cwg9-5f2g-87h2/GHSA-cwg9-5f2g-87h2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwg9-5f2g-87h2", + "modified": "2024-03-18T18:32:18Z", + "published": "2024-03-18T18:32:18Z", + "aliases": [ + "CVE-2024-1658" + ], + "details": "The Grid Shortcodes WordPress plugin before 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1658" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/9489925e-5a47-4608-90a2-0139c5e1c43c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-f584-69cf-f97p/GHSA-f584-69cf-f97p.json b/advisories/unreviewed/2024/03/GHSA-f584-69cf-f97p/GHSA-f584-69cf-f97p.json new file mode 100644 index 00000000000..84782160c4a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-f584-69cf-f97p/GHSA-f584-69cf-f97p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f584-69cf-f97p", + "modified": "2024-03-18T18:32:21Z", + "published": "2024-03-18T18:32:21Z", + "aliases": [ + "CVE-2024-26038" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26038" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-f5pr-p2jr-pvpx/GHSA-f5pr-p2jr-pvpx.json b/advisories/unreviewed/2024/03/GHSA-f5pr-p2jr-pvpx/GHSA-f5pr-p2jr-pvpx.json new file mode 100644 index 00000000000..2b956de1b51 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-f5pr-p2jr-pvpx/GHSA-f5pr-p2jr-pvpx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5pr-p2jr-pvpx", + "modified": "2024-03-18T18:32:21Z", + "published": "2024-03-18T18:32:21Z", + "aliases": [ + "CVE-2024-26051" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26051" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-fp59-qf9c-5497/GHSA-fp59-qf9c-5497.json b/advisories/unreviewed/2024/03/GHSA-fp59-qf9c-5497/GHSA-fp59-qf9c-5497.json new file mode 100644 index 00000000000..3ce4fa74a67 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-fp59-qf9c-5497/GHSA-fp59-qf9c-5497.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fp59-qf9c-5497", + "modified": "2024-03-18T18:32:21Z", + "published": "2024-03-18T18:32:21Z", + "aliases": [ + "CVE-2024-26043" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26043" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-fw2j-mfgx-82c8/GHSA-fw2j-mfgx-82c8.json b/advisories/unreviewed/2024/03/GHSA-fw2j-mfgx-82c8/GHSA-fw2j-mfgx-82c8.json new file mode 100644 index 00000000000..123b4cd0143 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-fw2j-mfgx-82c8/GHSA-fw2j-mfgx-82c8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fw2j-mfgx-82c8", + "modified": "2024-03-18T18:32:19Z", + "published": "2024-03-18T18:32:19Z", + "aliases": [ + "CVE-2024-20760" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20760" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-gjwh-9473-rcfm/GHSA-gjwh-9473-rcfm.json b/advisories/unreviewed/2024/03/GHSA-gjwh-9473-rcfm/GHSA-gjwh-9473-rcfm.json new file mode 100644 index 00000000000..236d944154a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-gjwh-9473-rcfm/GHSA-gjwh-9473-rcfm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gjwh-9473-rcfm", + "modified": "2024-03-18T18:32:18Z", + "published": "2024-03-18T18:32:18Z", + "aliases": [ + "CVE-2024-1333" + ], + "details": "The Responsive Pricing Table WordPress plugin before 5.1.11 does not validate and escape some of its Pricing Table options before outputting them back in a page/post where the related shortcode is embed, which could allow users with the author role and above to perform Stored Cross-Site Scripting attacks", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1333" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/30546402-03b8-4e18-ad7e-04a6b556ffd7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-gm6q-8vw8-pwh3/GHSA-gm6q-8vw8-pwh3.json b/advisories/unreviewed/2024/03/GHSA-gm6q-8vw8-pwh3/GHSA-gm6q-8vw8-pwh3.json new file mode 100644 index 00000000000..1597d95058a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-gm6q-8vw8-pwh3/GHSA-gm6q-8vw8-pwh3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gm6q-8vw8-pwh3", + "modified": "2024-03-18T18:32:22Z", + "published": "2024-03-18T18:32:22Z", + "aliases": [ + "CVE-2024-26094" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26094" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-h3f6-796g-336v/GHSA-h3f6-796g-336v.json b/advisories/unreviewed/2024/03/GHSA-h3f6-796g-336v/GHSA-h3f6-796g-336v.json new file mode 100644 index 00000000000..ccf9ba73709 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-h3f6-796g-336v/GHSA-h3f6-796g-336v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h3f6-796g-336v", + "modified": "2024-03-18T18:32:20Z", + "published": "2024-03-18T18:32:20Z", + "aliases": [ + "CVE-2024-20764" + ], + "details": "Animate versions 24.0, 23.0.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20764" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/animate/apsb24-19.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-hfjr-9ppp-8xq8/GHSA-hfjr-9ppp-8xq8.json b/advisories/unreviewed/2024/03/GHSA-hfjr-9ppp-8xq8/GHSA-hfjr-9ppp-8xq8.json new file mode 100644 index 00000000000..ba65cc3ff0f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-hfjr-9ppp-8xq8/GHSA-hfjr-9ppp-8xq8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hfjr-9ppp-8xq8", + "modified": "2024-03-18T18:32:21Z", + "published": "2024-03-18T18:32:21Z", + "aliases": [ + "CVE-2024-26061" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26061" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-jc6h-994m-9mhq/GHSA-jc6h-994m-9mhq.json b/advisories/unreviewed/2024/03/GHSA-jc6h-994m-9mhq/GHSA-jc6h-994m-9mhq.json new file mode 100644 index 00000000000..9a6e7c8a89e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-jc6h-994m-9mhq/GHSA-jc6h-994m-9mhq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jc6h-994m-9mhq", + "modified": "2024-03-18T18:32:21Z", + "published": "2024-03-18T18:32:21Z", + "aliases": [ + "CVE-2024-26041" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26041" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-jvxm-6mgq-929w/GHSA-jvxm-6mgq-929w.json b/advisories/unreviewed/2024/03/GHSA-jvxm-6mgq-929w/GHSA-jvxm-6mgq-929w.json new file mode 100644 index 00000000000..1de1079386c --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-jvxm-6mgq-929w/GHSA-jvxm-6mgq-929w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvxm-6mgq-929w", + "modified": "2024-03-18T18:32:18Z", + "published": "2024-03-18T18:32:18Z", + "aliases": [ + "CVE-2024-2051" + ], + "details": "\nCWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that\ncould cause account takeover and unauthorized access to the system when an attacker\nconducts brute-force attacks against the login form.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2051" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-072-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-072-01.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-mcqr-9wgj-9623/GHSA-mcqr-9wgj-9623.json b/advisories/unreviewed/2024/03/GHSA-mcqr-9wgj-9623/GHSA-mcqr-9wgj-9623.json new file mode 100644 index 00000000000..cb675590914 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-mcqr-9wgj-9623/GHSA-mcqr-9wgj-9623.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcqr-9wgj-9623", + "modified": "2024-03-18T18:32:20Z", + "published": "2024-03-18T18:32:20Z", + "aliases": [ + "CVE-2024-26028" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26028" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-mqq9-x2f4-47xp/GHSA-mqq9-x2f4-47xp.json b/advisories/unreviewed/2024/03/GHSA-mqq9-x2f4-47xp/GHSA-mqq9-x2f4-47xp.json new file mode 100644 index 00000000000..2888bdc81d3 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-mqq9-x2f4-47xp/GHSA-mqq9-x2f4-47xp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqq9-x2f4-47xp", + "modified": "2024-03-18T18:32:20Z", + "published": "2024-03-18T18:32:20Z", + "aliases": [ + "CVE-2024-26030" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26030" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-p833-v842-wj4m/GHSA-p833-v842-wj4m.json b/advisories/unreviewed/2024/03/GHSA-p833-v842-wj4m/GHSA-p833-v842-wj4m.json new file mode 100644 index 00000000000..dd5a8d1d1e2 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-p833-v842-wj4m/GHSA-p833-v842-wj4m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p833-v842-wj4m", + "modified": "2024-03-18T18:32:18Z", + "published": "2024-03-18T18:32:18Z", + "aliases": [ + "CVE-2024-2052" + ], + "details": "\nCWE-552: Files or Directories Accessible to External Parties vulnerability exists that could allow\nunauthenticated files and logs exfiltration and download of files when an attacker modifies the\nURL to download to a different location.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2052" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-072-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-072-01.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-552" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-pwj3-wjc3-227r/GHSA-pwj3-wjc3-227r.json b/advisories/unreviewed/2024/03/GHSA-pwj3-wjc3-227r/GHSA-pwj3-wjc3-227r.json new file mode 100644 index 00000000000..0dc75f39dbd --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-pwj3-wjc3-227r/GHSA-pwj3-wjc3-227r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwj3-wjc3-227r", + "modified": "2024-03-18T18:32:20Z", + "published": "2024-03-18T18:32:20Z", + "aliases": [ + "CVE-2024-26032" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable web pages. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable script. This could result in arbitrary code execution in the context of the victim's browser. Exploitation of this issue requires user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26032" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-q677-9v9j-jjwq/GHSA-q677-9v9j-jjwq.json b/advisories/unreviewed/2024/03/GHSA-q677-9v9j-jjwq/GHSA-q677-9v9j-jjwq.json new file mode 100644 index 00000000000..23d90e4c599 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-q677-9v9j-jjwq/GHSA-q677-9v9j-jjwq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q677-9v9j-jjwq", + "modified": "2024-03-18T18:32:19Z", + "published": "2024-03-18T18:32:19Z", + "aliases": [ + "CVE-2024-20754" + ], + "details": "Lightroom Desktop versions 7.1.2 and earlier are affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. If the application uses a search path to locate critical resources such as programs, then an attacker could modify that search path to point to a malicious program, which the targeted application would then execute. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20754" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/lightroom/apsb24-17.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-426" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-r653-48jc-r5p7/GHSA-r653-48jc-r5p7.json b/advisories/unreviewed/2024/03/GHSA-r653-48jc-r5p7/GHSA-r653-48jc-r5p7.json new file mode 100644 index 00000000000..fbf89345de7 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-r653-48jc-r5p7/GHSA-r653-48jc-r5p7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r653-48jc-r5p7", + "modified": "2024-03-18T18:32:18Z", + "published": "2024-03-18T18:32:18Z", + "aliases": [ + "CVE-2024-20752" + ], + "details": "Bridge versions 13.0.5, 14.0.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20752" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/bridge/apsb24-15.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-v9j9-5qh2-v6qr/GHSA-v9j9-5qh2-v6qr.json b/advisories/unreviewed/2024/03/GHSA-v9j9-5qh2-v6qr/GHSA-v9j9-5qh2-v6qr.json new file mode 100644 index 00000000000..6bb513830cf --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-v9j9-5qh2-v6qr/GHSA-v9j9-5qh2-v6qr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9j9-5qh2-v6qr", + "modified": "2024-03-18T18:32:20Z", + "published": "2024-03-18T18:32:20Z", + "aliases": [ + "CVE-2024-20763" + ], + "details": "Animate versions 24.0, 23.0.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20763" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/animate/apsb24-19.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-vgx2-q9gg-j722/GHSA-vgx2-q9gg-j722.json b/advisories/unreviewed/2024/03/GHSA-vgx2-q9gg-j722/GHSA-vgx2-q9gg-j722.json new file mode 100644 index 00000000000..22ce8804556 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-vgx2-q9gg-j722/GHSA-vgx2-q9gg-j722.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vgx2-q9gg-j722", + "modified": "2024-03-18T18:32:22Z", + "published": "2024-03-18T18:32:22Z", + "aliases": [ + "CVE-2024-26103" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26103" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-vhh4-7pjp-752m/GHSA-vhh4-7pjp-752m.json b/advisories/unreviewed/2024/03/GHSA-vhh4-7pjp-752m/GHSA-vhh4-7pjp-752m.json new file mode 100644 index 00000000000..70d6683ee4c --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-vhh4-7pjp-752m/GHSA-vhh4-7pjp-752m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhh4-7pjp-752m", + "modified": "2024-03-18T18:32:18Z", + "published": "2024-03-18T18:32:18Z", + "aliases": [ + "CVE-2024-1331" + ], + "details": "The Team Members WordPress plugin before 5.3.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the author role and above to perform Stored Cross-Site Scripting attacks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1331" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/b2bac900-3d8f-406c-b03d-c8db156acc59" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-vhpf-4rj9-jr37/GHSA-vhpf-4rj9-jr37.json b/advisories/unreviewed/2024/03/GHSA-vhpf-4rj9-jr37/GHSA-vhpf-4rj9-jr37.json new file mode 100644 index 00000000000..db6c0b72386 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-vhpf-4rj9-jr37/GHSA-vhpf-4rj9-jr37.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhpf-4rj9-jr37", + "modified": "2024-03-18T18:32:22Z", + "published": "2024-03-18T18:32:22Z", + "aliases": [ + "CVE-2024-26065" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26065" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-vrj4-6h4v-jh5g/GHSA-vrj4-6h4v-jh5g.json b/advisories/unreviewed/2024/03/GHSA-vrj4-6h4v-jh5g/GHSA-vrj4-6h4v-jh5g.json new file mode 100644 index 00000000000..912bda2fde2 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-vrj4-6h4v-jh5g/GHSA-vrj4-6h4v-jh5g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrj4-6h4v-jh5g", + "modified": "2024-03-18T18:32:21Z", + "published": "2024-03-18T18:32:21Z", + "aliases": [ + "CVE-2024-26045" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26045" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-xcpx-x4rg-25pv/GHSA-xcpx-x4rg-25pv.json b/advisories/unreviewed/2024/03/GHSA-xcpx-x4rg-25pv/GHSA-xcpx-x4rg-25pv.json new file mode 100644 index 00000000000..8baae454aad --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-xcpx-x4rg-25pv/GHSA-xcpx-x4rg-25pv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xcpx-x4rg-25pv", + "modified": "2024-03-18T18:32:21Z", + "published": "2024-03-18T18:32:21Z", + "aliases": [ + "CVE-2024-26050" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26050" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-xxjh-5gpj-36xr/GHSA-xxjh-5gpj-36xr.json b/advisories/unreviewed/2024/03/GHSA-xxjh-5gpj-36xr/GHSA-xxjh-5gpj-36xr.json new file mode 100644 index 00000000000..ef1ca75a574 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-xxjh-5gpj-36xr/GHSA-xxjh-5gpj-36xr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxjh-5gpj-36xr", + "modified": "2024-03-18T18:32:21Z", + "published": "2024-03-18T18:32:21Z", + "aliases": [ + "CVE-2024-26063" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by an Information Exposure vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to gain unauthorized access to sensitive information, potentially bypassing security measures. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26063" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-18T18:15:14Z" + } +} \ No newline at end of file