From 7b8a28fe4ea75980393d2f18de5a63962480e317 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 20 Aug 2024 12:31:52 +0000 Subject: [PATCH] Publish Advisories GHSA-2q7v-x8xx-mpjx GHSA-2rfm-w57j-82fx GHSA-c3gm-32gm-crw9 GHSA-f8w7-phwr-8g55 GHSA-g467-xxq2-x845 GHSA-h63c-4f8g-75qg GHSA-h64c-rqqh-q3fp GHSA-jq9m-xc37-6wph --- .../GHSA-2q7v-x8xx-mpjx.json | 38 +++++++++++++++++ .../GHSA-2rfm-w57j-82fx.json | 38 +++++++++++++++++ .../GHSA-c3gm-32gm-crw9.json | 38 +++++++++++++++++ .../GHSA-f8w7-phwr-8g55.json | 38 +++++++++++++++++ .../GHSA-g467-xxq2-x845.json | 38 +++++++++++++++++ .../GHSA-h63c-4f8g-75qg.json | 42 +++++++++++++++++++ .../GHSA-h64c-rqqh-q3fp.json | 38 +++++++++++++++++ .../GHSA-jq9m-xc37-6wph.json | 42 +++++++++++++++++++ 8 files changed, 312 insertions(+) create mode 100644 advisories/unreviewed/2024/08/GHSA-2q7v-x8xx-mpjx/GHSA-2q7v-x8xx-mpjx.json create mode 100644 advisories/unreviewed/2024/08/GHSA-2rfm-w57j-82fx/GHSA-2rfm-w57j-82fx.json create mode 100644 advisories/unreviewed/2024/08/GHSA-c3gm-32gm-crw9/GHSA-c3gm-32gm-crw9.json create mode 100644 advisories/unreviewed/2024/08/GHSA-f8w7-phwr-8g55/GHSA-f8w7-phwr-8g55.json create mode 100644 advisories/unreviewed/2024/08/GHSA-g467-xxq2-x845/GHSA-g467-xxq2-x845.json create mode 100644 advisories/unreviewed/2024/08/GHSA-h63c-4f8g-75qg/GHSA-h63c-4f8g-75qg.json create mode 100644 advisories/unreviewed/2024/08/GHSA-h64c-rqqh-q3fp/GHSA-h64c-rqqh-q3fp.json create mode 100644 advisories/unreviewed/2024/08/GHSA-jq9m-xc37-6wph/GHSA-jq9m-xc37-6wph.json diff --git a/advisories/unreviewed/2024/08/GHSA-2q7v-x8xx-mpjx/GHSA-2q7v-x8xx-mpjx.json b/advisories/unreviewed/2024/08/GHSA-2q7v-x8xx-mpjx/GHSA-2q7v-x8xx-mpjx.json new file mode 100644 index 00000000000..4a443d10cde --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2q7v-x8xx-mpjx/GHSA-2q7v-x8xx-mpjx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2q7v-x8xx-mpjx", + "modified": "2024-08-20T12:30:28Z", + "published": "2024-08-20T12:30:28Z", + "aliases": [ + "CVE-2024-41699" + ], + "details": "Priority – CWE-552: Files or Directories Accessible to External Parties", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41699" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-552" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T12:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-2rfm-w57j-82fx/GHSA-2rfm-w57j-82fx.json b/advisories/unreviewed/2024/08/GHSA-2rfm-w57j-82fx/GHSA-2rfm-w57j-82fx.json new file mode 100644 index 00000000000..55f3fa20189 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2rfm-w57j-82fx/GHSA-2rfm-w57j-82fx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rfm-w57j-82fx", + "modified": "2024-08-20T12:30:27Z", + "published": "2024-08-20T12:30:27Z", + "aliases": [ + "CVE-2024-25009" + ], + "details": "Ericsson Packet Core Controller (PCC) contains a vulnerability in Access and Mobility Management Function (AMF) where improper input validation can lead to denial of service which may result in service degradation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25009" + }, + { + "type": "WEB", + "url": "https://www.ericsson.com/en/about-us/security/psirt/security-bulletin-ericsson-packet-core-controller-pcc-august-2024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T12:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c3gm-32gm-crw9/GHSA-c3gm-32gm-crw9.json b/advisories/unreviewed/2024/08/GHSA-c3gm-32gm-crw9/GHSA-c3gm-32gm-crw9.json new file mode 100644 index 00000000000..161a41d843b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c3gm-32gm-crw9/GHSA-c3gm-32gm-crw9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3gm-32gm-crw9", + "modified": "2024-08-20T12:30:27Z", + "published": "2024-08-20T12:30:27Z", + "aliases": [ + "CVE-2024-41698" + ], + "details": "Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41698" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T12:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f8w7-phwr-8g55/GHSA-f8w7-phwr-8g55.json b/advisories/unreviewed/2024/08/GHSA-f8w7-phwr-8g55/GHSA-f8w7-phwr-8g55.json new file mode 100644 index 00000000000..b728c518d88 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f8w7-phwr-8g55/GHSA-f8w7-phwr-8g55.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8w7-phwr-8g55", + "modified": "2024-08-20T12:30:27Z", + "published": "2024-08-20T12:30:27Z", + "aliases": [ + "CVE-2024-41697" + ], + "details": "Priority - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41697" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T12:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g467-xxq2-x845/GHSA-g467-xxq2-x845.json b/advisories/unreviewed/2024/08/GHSA-g467-xxq2-x845/GHSA-g467-xxq2-x845.json new file mode 100644 index 00000000000..4d51bf65675 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-g467-xxq2-x845/GHSA-g467-xxq2-x845.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g467-xxq2-x845", + "modified": "2024-08-20T12:30:28Z", + "published": "2024-08-20T12:30:28Z", + "aliases": [ + "CVE-2024-41700" + ], + "details": "Barix – CWE-200 Exposure of Sensitive Information to an Unauthorized Actor", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41700" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T12:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-h63c-4f8g-75qg/GHSA-h63c-4f8g-75qg.json b/advisories/unreviewed/2024/08/GHSA-h63c-4f8g-75qg/GHSA-h63c-4f8g-75qg.json new file mode 100644 index 00000000000..a05b9c89f50 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-h63c-4f8g-75qg/GHSA-h63c-4f8g-75qg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h63c-4f8g-75qg", + "modified": "2024-08-20T12:30:27Z", + "published": "2024-08-20T12:30:27Z", + "aliases": [ + "CVE-2024-21689" + ], + "details": "This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689  was introduced in versions 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0, and 9.6.0 of Bamboo Data Center and Server.\n\nThis RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.6, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction.\n\nAtlassian recommends that Bamboo Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\n Bamboo Data Center and Server 9.2: Upgrade to a release greater than or equal to 9.2.17\n\n Bamboo Data Center and Server 9.6: Upgrade to a release greater than or equal to 9.6.5\n\nSee the release notes ([https://confluence.atlassian.com/bambooreleases/bamboo-release-notes-1189793869.html]). You can download the latest version of Bamboo Data Center and Server from the download center ([https://www.atlassian.com/software/bamboo/download-archives]).\n\nThis vulnerability was reported via our Bug Bounty program.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21689" + }, + { + "type": "WEB", + "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1431535667" + }, + { + "type": "WEB", + "url": "https://jira.atlassian.com/browse/BAM-25858" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T10:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-h64c-rqqh-q3fp/GHSA-h64c-rqqh-q3fp.json b/advisories/unreviewed/2024/08/GHSA-h64c-rqqh-q3fp/GHSA-h64c-rqqh-q3fp.json new file mode 100644 index 00000000000..49a83e45463 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-h64c-rqqh-q3fp/GHSA-h64c-rqqh-q3fp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h64c-rqqh-q3fp", + "modified": "2024-08-20T12:30:27Z", + "published": "2024-08-20T12:30:27Z", + "aliases": [ + "CVE-2024-28829" + ], + "details": "Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0p12, 2.2.0p32, 2.1.0p47 and 2.0.0 (EOL) allows local users to escalate privileges.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28829" + }, + { + "type": "WEB", + "url": "https://checkmk.com/werk/16249" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-272" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T10:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jq9m-xc37-6wph/GHSA-jq9m-xc37-6wph.json b/advisories/unreviewed/2024/08/GHSA-jq9m-xc37-6wph/GHSA-jq9m-xc37-6wph.json new file mode 100644 index 00000000000..c0465242ee6 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jq9m-xc37-6wph/GHSA-jq9m-xc37-6wph.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jq9m-xc37-6wph", + "modified": "2024-08-20T12:30:27Z", + "published": "2024-08-20T12:30:27Z", + "aliases": [ + "CVE-2024-7054" + ], + "details": "The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘close_text’ parameter in all versions up to, and including, 1.19.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7054" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3137126" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/73524687-7703-4912-aad5-2a31122ba9b2?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T11:15:03Z" + } +} \ No newline at end of file