From 7ec3db23cc9f6a7d82bb41cd9d697811cb218c0f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 26 Feb 2024 18:31:49 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-3h6x-952r-xr8p.json | 2 +- .../GHSA-554m-v42f-hcq9.json | 10 ++- .../GHSA-73m5-j333-fcwc.json | 2 +- .../GHSA-x697-v25m-6phv.json | 6 +- .../GHSA-246p-56fr-j339.json | 38 +++++++++++ .../GHSA-25vh-f6xx-mfc3.json | 55 ++++++++++++++++ .../GHSA-273x-mxvr-9vx2.json | 42 +++++++++++++ .../GHSA-29vg-wcmp-5fp9.json | 6 +- .../GHSA-2j3h-j2q3-wxp3.json | 39 ++++++++++++ .../GHSA-32rv-jjcf-cmrm.json | 42 +++++++++++++ .../GHSA-35j4-pxc2-3gcf.json | 47 ++++++++++++++ .../GHSA-36cg-qj95-mq7x.json | 39 ++++++++++++ .../GHSA-38g6-vx2q-23wm.json | 47 ++++++++++++++ .../GHSA-3fmx-gx73-5jg7.json | 43 +++++++++++++ .../GHSA-42c4-hvg2-mp96.json | 35 +++++++++++ .../GHSA-4473-972q-596c.json | 43 +++++++++++++ .../GHSA-4pqp-3cv2-mm87.json | 63 +++++++++++++++++++ .../GHSA-5998-89hj-xhfc.json | 38 +++++++++++ .../GHSA-5m9g-hh42-2p58.json | 47 ++++++++++++++ .../GHSA-5p3m-pw6j-5jwm.json | 39 ++++++++++++ .../GHSA-5p7x-xg54-cjrq.json | 35 +++++++++++ .../GHSA-5pjp-x72x-j9r3.json | 63 +++++++++++++++++++ .../GHSA-6347-pxpp-244g.json | 35 +++++++++++ .../GHSA-672f-vpw8-x67x.json | 6 +- .../GHSA-672r-97r7-vx2q.json | 35 +++++++++++ .../GHSA-692m-8cmm-mgxx.json | 35 +++++++++++ .../GHSA-6pc7-4x73-wwc6.json | 63 +++++++++++++++++++ .../GHSA-728x-37qh-9vwv.json | 35 +++++++++++ .../GHSA-72wm-hh56-9gp6.json | 42 +++++++++++++ .../GHSA-73wx-63h7-3wh6.json | 35 +++++++++++ .../GHSA-75f4-ww24-h9gr.json | 38 +++++++++++ .../GHSA-7669-733q-3wj7.json | 35 +++++++++++ .../GHSA-785g-282q-pwvx.json | 35 +++++++++++ .../GHSA-78w9-qxr3-hqhc.json | 6 +- .../GHSA-79m3-3j97-c9x5.json | 35 +++++++++++ .../GHSA-7f2p-xwcx-975m.json | 39 ++++++++++++ .../GHSA-7j4q-xf7j-jxcp.json | 35 +++++++++++ .../GHSA-7jwf-rcqv-w98g.json | 38 +++++++++++ .../GHSA-7r53-r6j6-q893.json | 55 ++++++++++++++++ .../GHSA-7vf7-cqc9-qxj2.json | 42 +++++++++++++ .../GHSA-7xfv-2p7x-fhmv.json | 35 +++++++++++ .../GHSA-8459-gg55-8qjj.json | 10 ++- .../GHSA-89r2-jh3p-h38p.json | 46 ++++++++++++++ .../GHSA-8q86-4x73-99v8.json | 38 +++++++++++ .../GHSA-9629-73hh-qpxp.json | 39 ++++++++++++ .../GHSA-9h96-qfg7-gpv6.json | 46 ++++++++++++++ .../GHSA-c77m-cx29-7m84.json | 63 +++++++++++++++++++ .../GHSA-c9jh-pp3m-mqr9.json | 38 +++++++++++ .../GHSA-cg5m-p8pg-93cg.json | 42 +++++++++++++ .../GHSA-f49h-mjwq-cq8p.json | 43 +++++++++++++ .../GHSA-f54m-q836-9rr6.json | 63 +++++++++++++++++++ .../GHSA-f8gg-fh4p-4795.json | 6 +- .../GHSA-fhv7-8956-mv3h.json | 38 +++++++++++ .../GHSA-fq97-hv4f-crm6.json | 47 ++++++++++++++ .../GHSA-frg3-hm7v-3rpf.json | 6 +- .../GHSA-fxmj-6xv8-f3m7.json | 42 +++++++++++++ .../GHSA-gh68-jm46-84rf.json | 10 ++- .../GHSA-gj7p-vqfr-xgjw.json | 63 +++++++++++++++++++ .../GHSA-gjgc-m5jm-q72q.json | 38 +++++++++++ .../GHSA-gwh5-fh5x-ww83.json | 38 +++++++++++ .../GHSA-gxmr-rxpv-c8fq.json | 10 ++- .../GHSA-h9j7-5xvc-qhg5.json | 42 +++++++++++++ .../GHSA-hj8r-465g-5vm4.json | 35 +++++++++++ .../GHSA-j4jm-98r4-89rv.json | 38 +++++++++++ .../GHSA-j95w-c3jf-29mw.json | 42 +++++++++++++ .../GHSA-j96m-hg98-w6c4.json | 39 ++++++++++++ .../GHSA-j96v-g32v-765g.json | 43 +++++++++++++ .../GHSA-j98f-j6g4-3jp3.json | 38 +++++++++++ .../GHSA-jc66-9qcw-88hp.json | 63 +++++++++++++++++++ .../GHSA-jrrc-pqj2-c99f.json | 35 +++++++++++ .../GHSA-m3q9-44rg-xw34.json | 35 +++++++++++ .../GHSA-m5gq-732f-j9v6.json | 6 +- .../GHSA-m8mq-5vgv-8w3r.json | 42 +++++++++++++ .../GHSA-mgvp-6fwh-58v2.json | 38 +++++++++++ .../GHSA-mj54-2qgh-27pf.json | 42 +++++++++++++ .../GHSA-mp2w-hjcj-f5g9.json | 10 ++- .../GHSA-mr92-3m8f-x735.json | 63 +++++++++++++++++++ .../GHSA-mw6g-mf3x-8xg2.json | 35 +++++++++++ .../GHSA-mxgx-3gr7-j26m.json | 46 ++++++++++++++ .../GHSA-p85g-mx27-m79q.json | 38 +++++++++++ .../GHSA-p88p-j9px-cq4j.json | 43 +++++++++++++ .../GHSA-pcqc-c89r-492h.json | 43 +++++++++++++ .../GHSA-phv9-x3fj-743r.json | 31 +++++++++ .../GHSA-pv4h-p8jr-6cv2.json | 10 ++- .../GHSA-pwjx-5gv5-6j26.json | 38 +++++++++++ .../GHSA-pwr2-4v36-6qpr.json | 50 +++++++++++++++ .../GHSA-q52q-f54c-xmvp.json | 55 ++++++++++++++++ .../GHSA-q5mw-2cvx-mjj3.json | 42 +++++++++++++ .../GHSA-q8f8-rhx9-2qm4.json | 6 +- .../GHSA-q8hf-gfmq-m739.json | 46 ++++++++++++++ .../GHSA-q98m-fjjg-rxw5.json | 63 +++++++++++++++++++ .../GHSA-qmvm-mg94-c39p.json | 35 +++++++++++ .../GHSA-qpxm-689r-3849.json | 38 +++++++++++ .../GHSA-r5qg-76hh-gr9p.json | 6 +- .../GHSA-r633-2867-crc8.json | 63 +++++++++++++++++++ .../GHSA-rg89-92m2-5hj6.json | 42 +++++++++++++ .../GHSA-rg8h-4g25-hj75.json | 38 +++++++++++ .../GHSA-rjx3-xwwm-jhj5.json | 39 ++++++++++++ .../GHSA-v5qp-mx94-j49v.json | 10 ++- .../GHSA-v8r4-5m29-8242.json | 46 ++++++++++++++ .../GHSA-v8vj-cv27-hjv8.json | 35 +++++++++++ .../GHSA-vmr3-wr3f-xmpw.json | 42 +++++++++++++ .../GHSA-vqx3-p34h-gjh5.json | 42 +++++++++++++ .../GHSA-w4wv-vq5v-xp26.json | 38 +++++++++++ .../GHSA-w6r8-2m56-2cwg.json | 46 ++++++++++++++ .../GHSA-w98j-8492-h547.json | 46 ++++++++++++++ .../GHSA-wjv4-j3hc-gxvv.json | 6 +- .../GHSA-wmmx-6x56-w87j.json | 43 +++++++++++++ .../GHSA-x57x-3c65-5f3j.json | 10 ++- .../GHSA-xcvq-77qq-2wpx.json | 10 ++- .../GHSA-xf63-228h-qhch.json | 43 +++++++++++++ .../GHSA-xx6x-c9h6-h6fv.json | 35 +++++++++++ 112 files changed, 4035 insertions(+), 21 deletions(-) create mode 100644 advisories/unreviewed/2024/02/GHSA-246p-56fr-j339/GHSA-246p-56fr-j339.json create mode 100644 advisories/unreviewed/2024/02/GHSA-25vh-f6xx-mfc3/GHSA-25vh-f6xx-mfc3.json create mode 100644 advisories/unreviewed/2024/02/GHSA-273x-mxvr-9vx2/GHSA-273x-mxvr-9vx2.json create mode 100644 advisories/unreviewed/2024/02/GHSA-2j3h-j2q3-wxp3/GHSA-2j3h-j2q3-wxp3.json create mode 100644 advisories/unreviewed/2024/02/GHSA-32rv-jjcf-cmrm/GHSA-32rv-jjcf-cmrm.json create mode 100644 advisories/unreviewed/2024/02/GHSA-35j4-pxc2-3gcf/GHSA-35j4-pxc2-3gcf.json create mode 100644 advisories/unreviewed/2024/02/GHSA-36cg-qj95-mq7x/GHSA-36cg-qj95-mq7x.json create mode 100644 advisories/unreviewed/2024/02/GHSA-38g6-vx2q-23wm/GHSA-38g6-vx2q-23wm.json create mode 100644 advisories/unreviewed/2024/02/GHSA-3fmx-gx73-5jg7/GHSA-3fmx-gx73-5jg7.json create mode 100644 advisories/unreviewed/2024/02/GHSA-42c4-hvg2-mp96/GHSA-42c4-hvg2-mp96.json create mode 100644 advisories/unreviewed/2024/02/GHSA-4473-972q-596c/GHSA-4473-972q-596c.json create mode 100644 advisories/unreviewed/2024/02/GHSA-4pqp-3cv2-mm87/GHSA-4pqp-3cv2-mm87.json create mode 100644 advisories/unreviewed/2024/02/GHSA-5998-89hj-xhfc/GHSA-5998-89hj-xhfc.json create mode 100644 advisories/unreviewed/2024/02/GHSA-5m9g-hh42-2p58/GHSA-5m9g-hh42-2p58.json create mode 100644 advisories/unreviewed/2024/02/GHSA-5p3m-pw6j-5jwm/GHSA-5p3m-pw6j-5jwm.json create mode 100644 advisories/unreviewed/2024/02/GHSA-5p7x-xg54-cjrq/GHSA-5p7x-xg54-cjrq.json create mode 100644 advisories/unreviewed/2024/02/GHSA-5pjp-x72x-j9r3/GHSA-5pjp-x72x-j9r3.json create mode 100644 advisories/unreviewed/2024/02/GHSA-6347-pxpp-244g/GHSA-6347-pxpp-244g.json create mode 100644 advisories/unreviewed/2024/02/GHSA-672r-97r7-vx2q/GHSA-672r-97r7-vx2q.json create mode 100644 advisories/unreviewed/2024/02/GHSA-692m-8cmm-mgxx/GHSA-692m-8cmm-mgxx.json create mode 100644 advisories/unreviewed/2024/02/GHSA-6pc7-4x73-wwc6/GHSA-6pc7-4x73-wwc6.json create mode 100644 advisories/unreviewed/2024/02/GHSA-728x-37qh-9vwv/GHSA-728x-37qh-9vwv.json create mode 100644 advisories/unreviewed/2024/02/GHSA-72wm-hh56-9gp6/GHSA-72wm-hh56-9gp6.json create mode 100644 advisories/unreviewed/2024/02/GHSA-73wx-63h7-3wh6/GHSA-73wx-63h7-3wh6.json create mode 100644 advisories/unreviewed/2024/02/GHSA-75f4-ww24-h9gr/GHSA-75f4-ww24-h9gr.json create mode 100644 advisories/unreviewed/2024/02/GHSA-7669-733q-3wj7/GHSA-7669-733q-3wj7.json create mode 100644 advisories/unreviewed/2024/02/GHSA-785g-282q-pwvx/GHSA-785g-282q-pwvx.json create mode 100644 advisories/unreviewed/2024/02/GHSA-79m3-3j97-c9x5/GHSA-79m3-3j97-c9x5.json create mode 100644 advisories/unreviewed/2024/02/GHSA-7f2p-xwcx-975m/GHSA-7f2p-xwcx-975m.json create mode 100644 advisories/unreviewed/2024/02/GHSA-7j4q-xf7j-jxcp/GHSA-7j4q-xf7j-jxcp.json create mode 100644 advisories/unreviewed/2024/02/GHSA-7jwf-rcqv-w98g/GHSA-7jwf-rcqv-w98g.json create mode 100644 advisories/unreviewed/2024/02/GHSA-7r53-r6j6-q893/GHSA-7r53-r6j6-q893.json create mode 100644 advisories/unreviewed/2024/02/GHSA-7vf7-cqc9-qxj2/GHSA-7vf7-cqc9-qxj2.json create mode 100644 advisories/unreviewed/2024/02/GHSA-7xfv-2p7x-fhmv/GHSA-7xfv-2p7x-fhmv.json create mode 100644 advisories/unreviewed/2024/02/GHSA-89r2-jh3p-h38p/GHSA-89r2-jh3p-h38p.json create mode 100644 advisories/unreviewed/2024/02/GHSA-8q86-4x73-99v8/GHSA-8q86-4x73-99v8.json create mode 100644 advisories/unreviewed/2024/02/GHSA-9629-73hh-qpxp/GHSA-9629-73hh-qpxp.json create mode 100644 advisories/unreviewed/2024/02/GHSA-9h96-qfg7-gpv6/GHSA-9h96-qfg7-gpv6.json create mode 100644 advisories/unreviewed/2024/02/GHSA-c77m-cx29-7m84/GHSA-c77m-cx29-7m84.json create mode 100644 advisories/unreviewed/2024/02/GHSA-c9jh-pp3m-mqr9/GHSA-c9jh-pp3m-mqr9.json create mode 100644 advisories/unreviewed/2024/02/GHSA-cg5m-p8pg-93cg/GHSA-cg5m-p8pg-93cg.json create mode 100644 advisories/unreviewed/2024/02/GHSA-f49h-mjwq-cq8p/GHSA-f49h-mjwq-cq8p.json create mode 100644 advisories/unreviewed/2024/02/GHSA-f54m-q836-9rr6/GHSA-f54m-q836-9rr6.json create mode 100644 advisories/unreviewed/2024/02/GHSA-fhv7-8956-mv3h/GHSA-fhv7-8956-mv3h.json create mode 100644 advisories/unreviewed/2024/02/GHSA-fq97-hv4f-crm6/GHSA-fq97-hv4f-crm6.json create mode 100644 advisories/unreviewed/2024/02/GHSA-fxmj-6xv8-f3m7/GHSA-fxmj-6xv8-f3m7.json create mode 100644 advisories/unreviewed/2024/02/GHSA-gj7p-vqfr-xgjw/GHSA-gj7p-vqfr-xgjw.json create mode 100644 advisories/unreviewed/2024/02/GHSA-gjgc-m5jm-q72q/GHSA-gjgc-m5jm-q72q.json create mode 100644 advisories/unreviewed/2024/02/GHSA-gwh5-fh5x-ww83/GHSA-gwh5-fh5x-ww83.json create mode 100644 advisories/unreviewed/2024/02/GHSA-h9j7-5xvc-qhg5/GHSA-h9j7-5xvc-qhg5.json create mode 100644 advisories/unreviewed/2024/02/GHSA-hj8r-465g-5vm4/GHSA-hj8r-465g-5vm4.json create mode 100644 advisories/unreviewed/2024/02/GHSA-j4jm-98r4-89rv/GHSA-j4jm-98r4-89rv.json create mode 100644 advisories/unreviewed/2024/02/GHSA-j95w-c3jf-29mw/GHSA-j95w-c3jf-29mw.json create mode 100644 advisories/unreviewed/2024/02/GHSA-j96m-hg98-w6c4/GHSA-j96m-hg98-w6c4.json create mode 100644 advisories/unreviewed/2024/02/GHSA-j96v-g32v-765g/GHSA-j96v-g32v-765g.json create mode 100644 advisories/unreviewed/2024/02/GHSA-j98f-j6g4-3jp3/GHSA-j98f-j6g4-3jp3.json create mode 100644 advisories/unreviewed/2024/02/GHSA-jc66-9qcw-88hp/GHSA-jc66-9qcw-88hp.json create mode 100644 advisories/unreviewed/2024/02/GHSA-jrrc-pqj2-c99f/GHSA-jrrc-pqj2-c99f.json create mode 100644 advisories/unreviewed/2024/02/GHSA-m3q9-44rg-xw34/GHSA-m3q9-44rg-xw34.json create mode 100644 advisories/unreviewed/2024/02/GHSA-m8mq-5vgv-8w3r/GHSA-m8mq-5vgv-8w3r.json create mode 100644 advisories/unreviewed/2024/02/GHSA-mgvp-6fwh-58v2/GHSA-mgvp-6fwh-58v2.json create mode 100644 advisories/unreviewed/2024/02/GHSA-mj54-2qgh-27pf/GHSA-mj54-2qgh-27pf.json create mode 100644 advisories/unreviewed/2024/02/GHSA-mr92-3m8f-x735/GHSA-mr92-3m8f-x735.json create mode 100644 advisories/unreviewed/2024/02/GHSA-mw6g-mf3x-8xg2/GHSA-mw6g-mf3x-8xg2.json create mode 100644 advisories/unreviewed/2024/02/GHSA-mxgx-3gr7-j26m/GHSA-mxgx-3gr7-j26m.json create mode 100644 advisories/unreviewed/2024/02/GHSA-p85g-mx27-m79q/GHSA-p85g-mx27-m79q.json create mode 100644 advisories/unreviewed/2024/02/GHSA-p88p-j9px-cq4j/GHSA-p88p-j9px-cq4j.json create mode 100644 advisories/unreviewed/2024/02/GHSA-pcqc-c89r-492h/GHSA-pcqc-c89r-492h.json create mode 100644 advisories/unreviewed/2024/02/GHSA-phv9-x3fj-743r/GHSA-phv9-x3fj-743r.json create mode 100644 advisories/unreviewed/2024/02/GHSA-pwjx-5gv5-6j26/GHSA-pwjx-5gv5-6j26.json create mode 100644 advisories/unreviewed/2024/02/GHSA-pwr2-4v36-6qpr/GHSA-pwr2-4v36-6qpr.json create mode 100644 advisories/unreviewed/2024/02/GHSA-q52q-f54c-xmvp/GHSA-q52q-f54c-xmvp.json create mode 100644 advisories/unreviewed/2024/02/GHSA-q5mw-2cvx-mjj3/GHSA-q5mw-2cvx-mjj3.json create mode 100644 advisories/unreviewed/2024/02/GHSA-q8hf-gfmq-m739/GHSA-q8hf-gfmq-m739.json create mode 100644 advisories/unreviewed/2024/02/GHSA-q98m-fjjg-rxw5/GHSA-q98m-fjjg-rxw5.json create mode 100644 advisories/unreviewed/2024/02/GHSA-qmvm-mg94-c39p/GHSA-qmvm-mg94-c39p.json create mode 100644 advisories/unreviewed/2024/02/GHSA-qpxm-689r-3849/GHSA-qpxm-689r-3849.json create mode 100644 advisories/unreviewed/2024/02/GHSA-r633-2867-crc8/GHSA-r633-2867-crc8.json create mode 100644 advisories/unreviewed/2024/02/GHSA-rg89-92m2-5hj6/GHSA-rg89-92m2-5hj6.json create mode 100644 advisories/unreviewed/2024/02/GHSA-rg8h-4g25-hj75/GHSA-rg8h-4g25-hj75.json create mode 100644 advisories/unreviewed/2024/02/GHSA-rjx3-xwwm-jhj5/GHSA-rjx3-xwwm-jhj5.json create mode 100644 advisories/unreviewed/2024/02/GHSA-v8r4-5m29-8242/GHSA-v8r4-5m29-8242.json create mode 100644 advisories/unreviewed/2024/02/GHSA-v8vj-cv27-hjv8/GHSA-v8vj-cv27-hjv8.json create mode 100644 advisories/unreviewed/2024/02/GHSA-vmr3-wr3f-xmpw/GHSA-vmr3-wr3f-xmpw.json create mode 100644 advisories/unreviewed/2024/02/GHSA-vqx3-p34h-gjh5/GHSA-vqx3-p34h-gjh5.json create mode 100644 advisories/unreviewed/2024/02/GHSA-w4wv-vq5v-xp26/GHSA-w4wv-vq5v-xp26.json create mode 100644 advisories/unreviewed/2024/02/GHSA-w6r8-2m56-2cwg/GHSA-w6r8-2m56-2cwg.json create mode 100644 advisories/unreviewed/2024/02/GHSA-w98j-8492-h547/GHSA-w98j-8492-h547.json create mode 100644 advisories/unreviewed/2024/02/GHSA-wmmx-6x56-w87j/GHSA-wmmx-6x56-w87j.json create mode 100644 advisories/unreviewed/2024/02/GHSA-xf63-228h-qhch/GHSA-xf63-228h-qhch.json create mode 100644 advisories/unreviewed/2024/02/GHSA-xx6x-c9h6-h6fv/GHSA-xx6x-c9h6-h6fv.json diff --git a/advisories/unreviewed/2024/01/GHSA-3h6x-952r-xr8p/GHSA-3h6x-952r-xr8p.json b/advisories/unreviewed/2024/01/GHSA-3h6x-952r-xr8p/GHSA-3h6x-952r-xr8p.json index 9e194f7b639..13de9b6d5b5 100644 --- a/advisories/unreviewed/2024/01/GHSA-3h6x-952r-xr8p/GHSA-3h6x-952r-xr8p.json +++ b/advisories/unreviewed/2024/01/GHSA-3h6x-952r-xr8p/GHSA-3h6x-952r-xr8p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3h6x-952r-xr8p", - "modified": "2024-02-11T09:30:18Z", + "modified": "2024-02-26T18:30:27Z", "published": "2024-01-23T03:31:08Z", "aliases": [ "CVE-2024-23213" diff --git a/advisories/unreviewed/2024/01/GHSA-554m-v42f-hcq9/GHSA-554m-v42f-hcq9.json b/advisories/unreviewed/2024/01/GHSA-554m-v42f-hcq9/GHSA-554m-v42f-hcq9.json index 0bf0f7717b5..889b9c8bdba 100644 --- a/advisories/unreviewed/2024/01/GHSA-554m-v42f-hcq9/GHSA-554m-v42f-hcq9.json +++ b/advisories/unreviewed/2024/01/GHSA-554m-v42f-hcq9/GHSA-554m-v42f-hcq9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-554m-v42f-hcq9", - "modified": "2024-01-31T15:30:20Z", + "modified": "2024-02-26T18:30:27Z", "published": "2024-01-31T15:30:20Z", "aliases": [ "CVE-2023-5992" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5992" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0966" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0967" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-5992" diff --git a/advisories/unreviewed/2024/01/GHSA-73m5-j333-fcwc/GHSA-73m5-j333-fcwc.json b/advisories/unreviewed/2024/01/GHSA-73m5-j333-fcwc/GHSA-73m5-j333-fcwc.json index 3d93a7cfcff..b91d33f28f9 100644 --- a/advisories/unreviewed/2024/01/GHSA-73m5-j333-fcwc/GHSA-73m5-j333-fcwc.json +++ b/advisories/unreviewed/2024/01/GHSA-73m5-j333-fcwc/GHSA-73m5-j333-fcwc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-73m5-j333-fcwc", - "modified": "2024-02-11T09:30:18Z", + "modified": "2024-02-26T18:30:27Z", "published": "2024-01-23T03:31:08Z", "aliases": [ "CVE-2024-23206" diff --git a/advisories/unreviewed/2024/01/GHSA-x697-v25m-6phv/GHSA-x697-v25m-6phv.json b/advisories/unreviewed/2024/01/GHSA-x697-v25m-6phv/GHSA-x697-v25m-6phv.json index 672601cf17a..737c288d567 100644 --- a/advisories/unreviewed/2024/01/GHSA-x697-v25m-6phv/GHSA-x697-v25m-6phv.json +++ b/advisories/unreviewed/2024/01/GHSA-x697-v25m-6phv/GHSA-x697-v25m-6phv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x697-v25m-6phv", - "modified": "2024-02-13T09:30:31Z", + "modified": "2024-02-26T18:30:27Z", "published": "2024-01-16T12:30:26Z", "aliases": [ "CVE-2024-0553" @@ -45,6 +45,10 @@ "type": "WEB", "url": "https://gitlab.com/gnutls/gnutls/-/issues/1522" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/02/msg00010.html" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7ZEIOLORQ7N6WRPFXZSYDL2MC4LP7VFV" diff --git a/advisories/unreviewed/2024/02/GHSA-246p-56fr-j339/GHSA-246p-56fr-j339.json b/advisories/unreviewed/2024/02/GHSA-246p-56fr-j339/GHSA-246p-56fr-j339.json new file mode 100644 index 00000000000..f390d55ca7c --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-246p-56fr-j339/GHSA-246p-56fr-j339.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-246p-56fr-j339", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-25909" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in JoomUnited WP Media folder.This issue affects WP Media folder: from n/a through 5.7.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25909" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-media-folder/wordpress-wp-media-folder-plugin-5-7-2-subscriber-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-25vh-f6xx-mfc3/GHSA-25vh-f6xx-mfc3.json b/advisories/unreviewed/2024/02/GHSA-25vh-f6xx-mfc3/GHSA-25vh-f6xx-mfc3.json new file mode 100644 index 00000000000..9ab905d01b7 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-25vh-f6xx-mfc3/GHSA-25vh-f6xx-mfc3.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25vh-f6xx-mfc3", + "modified": "2024-02-26T18:30:28Z", + "published": "2024-02-26T18:30:28Z", + "aliases": [ + "CVE-2023-52467" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmfd: syscon: Fix null pointer dereference in of_syscon_register()\n\nkasprintf() returns a pointer to dynamically allocated memory\nwhich can be NULL upon failure.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52467" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3ef1130deee98997275904d9bfc37af75e1e906c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/41673c66b3d0c09915698fec5c13b24336f18dd1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/527e8c5f3d00299822612c495d5adf1f8f43c001" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7f2c410ac470959b88e03dadd94b7a0b71df7973" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/927626a2073887ee30ba00633260d4d203f8e875" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c3e3a2144bf50877551138ffce9f7aa6ddfe385b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-273x-mxvr-9vx2/GHSA-273x-mxvr-9vx2.json b/advisories/unreviewed/2024/02/GHSA-273x-mxvr-9vx2/GHSA-273x-mxvr-9vx2.json new file mode 100644 index 00000000000..0d2326aed2b --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-273x-mxvr-9vx2/GHSA-273x-mxvr-9vx2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-273x-mxvr-9vx2", + "modified": "2024-02-26T18:30:28Z", + "published": "2024-02-26T18:30:28Z", + "aliases": [ + "CVE-2022-34357" + ], + "details": "IBM Cognos Analytics Mobile Server 11.1.7, 11.2.4, and 12.0.0 is vulnerable to Denial of Service due to due to weak or absence of rate limiting. By making unlimited http requests, it is possible for a single user to exhaust server resources over a period of time making service unavailable for other legitimate users. IBM X-Force ID: 230510.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34357" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/230510" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7123154" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-29vg-wcmp-5fp9/GHSA-29vg-wcmp-5fp9.json b/advisories/unreviewed/2024/02/GHSA-29vg-wcmp-5fp9/GHSA-29vg-wcmp-5fp9.json index 1d92471452e..b526c398880 100644 --- a/advisories/unreviewed/2024/02/GHSA-29vg-wcmp-5fp9/GHSA-29vg-wcmp-5fp9.json +++ b/advisories/unreviewed/2024/02/GHSA-29vg-wcmp-5fp9/GHSA-29vg-wcmp-5fp9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-29vg-wcmp-5fp9", - "modified": "2024-02-23T03:30:39Z", + "modified": "2024-02-26T18:30:28Z", "published": "2024-02-21T06:30:32Z", "aliases": [ "CVE-2024-1674" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://issues.chromium.org/issues/40095183" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PWWBMVQTSERVBXSXCZVUKIMEDNQUQ7O3" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QDCMYQ3J45NHQ4EJREM3BJNNKB5BK4Y7" diff --git a/advisories/unreviewed/2024/02/GHSA-2j3h-j2q3-wxp3/GHSA-2j3h-j2q3-wxp3.json b/advisories/unreviewed/2024/02/GHSA-2j3h-j2q3-wxp3/GHSA-2j3h-j2q3-wxp3.json new file mode 100644 index 00000000000..77a40e0bf09 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-2j3h-j2q3-wxp3/GHSA-2j3h-j2q3-wxp3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2j3h-j2q3-wxp3", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-25082" + ], + "details": "Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25082" + }, + { + "type": "WEB", + "url": "https://github.com/fontforge/fontforge/pull/5367" + }, + { + "type": "WEB", + "url": "https://fontforge.org/en-US/downloads" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-32rv-jjcf-cmrm/GHSA-32rv-jjcf-cmrm.json b/advisories/unreviewed/2024/02/GHSA-32rv-jjcf-cmrm/GHSA-32rv-jjcf-cmrm.json new file mode 100644 index 00000000000..d1e7b1253d8 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-32rv-jjcf-cmrm/GHSA-32rv-jjcf-cmrm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32rv-jjcf-cmrm", + "modified": "2024-02-26T18:30:29Z", + "published": "2024-02-26T18:30:29Z", + "aliases": [ + "CVE-2024-0455" + ], + "details": "The inclusion of the web scraper for AnythingLLM means that any user with the proper authorization level (manager, admin, and when in single user) could put in the URL\n```\nhttp://169.254.169.254/latest/meta-data/identity-credentials/ec2/security-credentials/ec2-instance\n```\nwhich is a special IP and URL that resolves only when the request comes from within an EC2 instance. This would allow the user to see the connection/secret credentials for their specific instance and be able to manage it regardless of who deployed it.\n\nThe user would have to have pre-existing knowledge of the hosting infra which the target instance is deployed on, but if sent - would resolve if on EC2 and the proper `iptable` or firewall rule is not configured for their setup.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0455" + }, + { + "type": "WEB", + "url": "https://github.com/mintplex-labs/anything-llm/commit/b2b2c2afe15c48952d57b4d01e7108f9515c5f55" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/07d83b49-7ebb-40d2-83fc-78381e3c5c9c" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-35j4-pxc2-3gcf/GHSA-35j4-pxc2-3gcf.json b/advisories/unreviewed/2024/02/GHSA-35j4-pxc2-3gcf/GHSA-35j4-pxc2-3gcf.json new file mode 100644 index 00000000000..4ef843dec87 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-35j4-pxc2-3gcf/GHSA-35j4-pxc2-3gcf.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35j4-pxc2-3gcf", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-25344" + ], + "details": "Cross Site Scripting vulnerability in ITFlow.org before commit v.432488eca3998c5be6b6b9e8f8ba01f54bc12378 allows a remtoe attacker to execute arbitrary code and obtain sensitive information via the settings.php, settings+company.php, settings_defaults.php,settings_integrations.php, settings_invoice.php, settings_localization.php, settings_mail.php components.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25344" + }, + { + "type": "WEB", + "url": "https://github.com/itflow-org/itflow/commit/432488eca3998c5be6b6b9e8f8ba01f54bc12378" + }, + { + "type": "WEB", + "url": "https://github.com/itflow-org/itflow/commit/8068cb6081e4760860a634c1066b2c64d0ee2d46" + }, + { + "type": "WEB", + "url": "https://itflow.org" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/177224/ITFlow-Cross-Site-Request-Forgery.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-36cg-qj95-mq7x/GHSA-36cg-qj95-mq7x.json b/advisories/unreviewed/2024/02/GHSA-36cg-qj95-mq7x/GHSA-36cg-qj95-mq7x.json new file mode 100644 index 00000000000..86183ff9e49 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-36cg-qj95-mq7x/GHSA-36cg-qj95-mq7x.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36cg-qj95-mq7x", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2019-25161" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: prevent memory leak\n\nIn dcn*_create_resource_pool the allocated memory should be released if\nconstruct pool fails.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-25161" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/104c307147ad379617472dd91a5bcb368d72bd6d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/60e1b411bf0fd9fda2d2de7f45dc3b1d9960b85e" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T18:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-38g6-vx2q-23wm/GHSA-38g6-vx2q-23wm.json b/advisories/unreviewed/2024/02/GHSA-38g6-vx2q-23wm/GHSA-38g6-vx2q-23wm.json new file mode 100644 index 00000000000..544b461aba0 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-38g6-vx2q-23wm/GHSA-38g6-vx2q-23wm.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38g6-vx2q-23wm", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-26601" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: regenerate buddy after block freeing failed if under fc replay\n\nThis mostly reverts commit 6bd97bf273bd (\"ext4: remove redundant\nmb_regenerate_buddy()\") and reintroduces mb_regenerate_buddy(). Based on\ncode in mb_free_blocks(), fast commit replay can end up marking as free\nblocks that are already marked as such. This causes corruption of the\nbuddy bitmap so we need to regenerate it in that case.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26601" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6b0d48647935e4b8c7b75d1eccb9043fcd4ee581" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/78327acd4cdc4a1601af718b781eece577b6b7d4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c9b528c35795b711331ed36dc3dbee90d5812d4e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ea42d6cffb0dd27a417f410b9d0011e9859328cb" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-3fmx-gx73-5jg7/GHSA-3fmx-gx73-5jg7.json b/advisories/unreviewed/2024/02/GHSA-3fmx-gx73-5jg7/GHSA-3fmx-gx73-5jg7.json new file mode 100644 index 00000000000..d4d0493d0f5 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-3fmx-gx73-5jg7/GHSA-3fmx-gx73-5jg7.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3fmx-gx73-5jg7", + "modified": "2024-02-26T18:30:28Z", + "published": "2024-02-26T18:30:28Z", + "aliases": [ + "CVE-2023-52466" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: Avoid potential out-of-bounds read in pci_dev_for_each_resource()\n\nCoverity complains that pointer in the pci_dev_for_each_resource() may be\nwrong, i.e., might be used for the out-of-bounds read.\n\nThere is no actual issue right now because we have another check afterwards\nand the out-of-bounds read is not being performed. In any case it's better\ncode with this fixed, hence the proposed change.\n\nAs Jonas pointed out \"It probably makes the code slightly less performant\nas res will now be checked for being not NULL (which will always be true),\nbut I doubt it will be significant (or in any hot paths).\"", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52466" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3171e46d677a668eed3086da78671f1e4f5b8405" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5b3e25efe16e06779a9a7c7610217c1b921ec179" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bd26159dcaaa3e9a927070efd348e7ce7e5ee933" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-42c4-hvg2-mp96/GHSA-42c4-hvg2-mp96.json b/advisories/unreviewed/2024/02/GHSA-42c4-hvg2-mp96/GHSA-42c4-hvg2-mp96.json new file mode 100644 index 00000000000..1a6ee3dd40a --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-42c4-hvg2-mp96/GHSA-42c4-hvg2-mp96.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42c4-hvg2-mp96", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-24402" + ], + "details": "An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24402" + }, + { + "type": "WEB", + "url": "https://www.nagios.com/changelog" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-4473-972q-596c/GHSA-4473-972q-596c.json b/advisories/unreviewed/2024/02/GHSA-4473-972q-596c/GHSA-4473-972q-596c.json new file mode 100644 index 00000000000..d013c2c48e2 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-4473-972q-596c/GHSA-4473-972q-596c.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4473-972q-596c", + "modified": "2024-02-26T18:30:29Z", + "published": "2024-02-26T18:30:29Z", + "aliases": [ + "CVE-2023-52473" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nthermal: core: Fix NULL pointer dereference in zone registration error path\n\nIf device_register() in thermal_zone_device_register_with_trips()\nreturns an error, the tz variable is set to NULL and subsequently\ndereferenced in kfree(tz->tzp).\n\nCommit adc8749b150c (\"thermal/drivers/core: Use put_device() if\ndevice_register() fails\") added the tz = NULL assignment in question to\navoid a possible double-free after dropping the reference to the zone\ndevice. However, after commit 4649620d9404 (\"thermal: core: Make\nthermal_zone_device_unregister() return after freeing the zone\"), that\nassignment has become redundant, because dropping the reference to the\nzone device does not cause the zone object to be freed any more.\n\nDrop it to address the NULL pointer dereference.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52473" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/02871710b93058eb1249d5847c0b2d1c2c3c98ae" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/04e6ccfc93c5a1aa1d75a537cf27e418895e20ea" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/335176dd8ebaca6493807dceea33c478305667fa" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-4pqp-3cv2-mm87/GHSA-4pqp-3cv2-mm87.json b/advisories/unreviewed/2024/02/GHSA-4pqp-3cv2-mm87/GHSA-4pqp-3cv2-mm87.json new file mode 100644 index 00000000000..695b63fa695 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-4pqp-3cv2-mm87/GHSA-4pqp-3cv2-mm87.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pqp-3cv2-mm87", + "modified": "2024-02-26T18:30:28Z", + "published": "2024-02-26T18:30:28Z", + "aliases": [ + "CVE-2022-48626" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmoxart: fix potential use-after-free on remove path\n\nIt was reported that the mmc host structure could be accessed after it\nwas freed in moxart_remove(), so fix this by saving the base register of\nthe device and using it instead of the pointer dereference.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48626" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3a0a7ec5574b510b067cfc734b8bdb6564b31d4e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7f901d53f120d1921f84f7b9b118e87e94b403c5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9c25d5ff1856b91bd4365e813f566cb59aaa9552" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/af0e6c49438b1596e4be8a267d218a0c88a42323" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bd2db32e7c3e35bd4d9b8bbff689434a50893546" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/be93028d306dac9f5b59ebebd9ec7abcfc69c156" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e6f580d0b3349646d4ee1ce0057eb273e8fb7e2e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f5dc193167591e88797262ec78515a0cbe79ff5f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-5998-89hj-xhfc/GHSA-5998-89hj-xhfc.json b/advisories/unreviewed/2024/02/GHSA-5998-89hj-xhfc/GHSA-5998-89hj-xhfc.json new file mode 100644 index 00000000000..12a30bbf43f --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-5998-89hj-xhfc/GHSA-5998-89hj-xhfc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5998-89hj-xhfc", + "modified": "2024-02-26T18:30:30Z", + "published": "2024-02-26T18:30:30Z", + "aliases": [ + "CVE-2024-21825" + ], + "details": "A heap-based buffer overflow vulnerability exists in the GGUF library GGUF_TYPE_ARRAY/GGUF_TYPE_STRING parsing functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21825" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1912" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-5m9g-hh42-2p58/GHSA-5m9g-hh42-2p58.json b/advisories/unreviewed/2024/02/GHSA-5m9g-hh42-2p58/GHSA-5m9g-hh42-2p58.json new file mode 100644 index 00000000000..4767eb4ae51 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-5m9g-hh42-2p58/GHSA-5m9g-hh42-2p58.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5m9g-hh42-2p58", + "modified": "2024-02-26T18:30:30Z", + "published": "2024-02-26T18:30:30Z", + "aliases": [ + "CVE-2024-22873" + ], + "details": "Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subscription function (/service/subscription.go). This vulnerability allows attackers to access internal requests via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22873" + }, + { + "type": "WEB", + "url": "https://gist.github.com/exp1orer/0f190c6a64b668a9b1c4c47789affa09" + }, + { + "type": "WEB", + "url": "https://sphenoid-enquiry-9be.notion.site/BK-CMDB-SSRF-ba21e94f4976460188fa52d26c15a6ae?pvs=4" + }, + { + "type": "WEB", + "url": "http://blueking.com" + }, + { + "type": "WEB", + "url": "http://tencent.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-5p3m-pw6j-5jwm/GHSA-5p3m-pw6j-5jwm.json b/advisories/unreviewed/2024/02/GHSA-5p3m-pw6j-5jwm/GHSA-5p3m-pw6j-5jwm.json new file mode 100644 index 00000000000..c59742d6a06 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-5p3m-pw6j-5jwm/GHSA-5p3m-pw6j-5jwm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5p3m-pw6j-5jwm", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-26605" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI/ASPM: Fix deadlock when enabling ASPM\n\nA last minute revert in 6.7-final introduced a potential deadlock when\nenabling ASPM during probe of Qualcomm PCIe controllers as reported by\nlockdep:\n\n ============================================\n WARNING: possible recursive locking detected\n 6.7.0 #40 Not tainted\n --------------------------------------------\n kworker/u16:5/90 is trying to acquire lock:\n ffffacfa78ced000 (pci_bus_sem){++++}-{3:3}, at: pcie_aspm_pm_state_change+0x58/0xdc\n\n but task is already holding lock:\n ffffacfa78ced000 (pci_bus_sem){++++}-{3:3}, at: pci_walk_bus+0x34/0xbc\n\n other info that might help us debug this:\n Possible unsafe locking scenario:\n\n CPU0\n ----\n lock(pci_bus_sem);\n lock(pci_bus_sem);\n\n *** DEADLOCK ***\n\n Call trace:\n print_deadlock_bug+0x25c/0x348\n __lock_acquire+0x10a4/0x2064\n lock_acquire+0x1e8/0x318\n down_read+0x60/0x184\n pcie_aspm_pm_state_change+0x58/0xdc\n pci_set_full_power_state+0xa8/0x114\n pci_set_power_state+0xc4/0x120\n qcom_pcie_enable_aspm+0x1c/0x3c [pcie_qcom]\n pci_walk_bus+0x64/0xbc\n qcom_pcie_host_post_init_2_7_0+0x28/0x34 [pcie_qcom]\n\nThe deadlock can easily be reproduced on machines like the Lenovo ThinkPad\nX13s by adding a delay to increase the race window during asynchronous\nprobe where another thread can take a write lock.\n\nAdd a new pci_set_power_state_locked() and associated helper functions that\ncan be called with the PCI bus semaphore held to avoid taking the read lock\ntwice.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26605" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1e560864159d002b453da42bd2c13a1805515a20" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ef90508574d7af48420bdc5f7b9a4f1cdd26bc70" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:28:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-5p7x-xg54-cjrq/GHSA-5p7x-xg54-cjrq.json b/advisories/unreviewed/2024/02/GHSA-5p7x-xg54-cjrq/GHSA-5p7x-xg54-cjrq.json new file mode 100644 index 00000000000..728bb8e270c --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-5p7x-xg54-cjrq/GHSA-5p7x-xg54-cjrq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5p7x-xg54-cjrq", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-25770" + ], + "details": "libming 0.4.8 contains a memory leak vulnerability in /libming/src/actioncompiler/listaction.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25770" + }, + { + "type": "WEB", + "url": "https://github.com/LuMingYinDetect/libming_defects/blob/main/libming_detect_1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-5pjp-x72x-j9r3/GHSA-5pjp-x72x-j9r3.json b/advisories/unreviewed/2024/02/GHSA-5pjp-x72x-j9r3/GHSA-5pjp-x72x-j9r3.json new file mode 100644 index 00000000000..289b78e950e --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-5pjp-x72x-j9r3/GHSA-5pjp-x72x-j9r3.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5pjp-x72x-j9r3", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-26602" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched/membarrier: reduce the ability to hammer on sys_membarrier\n\nOn some systems, sys_membarrier can be very expensive, causing overall\nslowdowns for everything. So put a lock on the path in order to\nserialize the accesses to prevent the ability for this to be called at\ntoo high of a frequency and saturate the machine.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26602" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2441a64070b85c14eecc3728cc87e883f953f265" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/24ec7504a08a67247fbe798d1de995208a8c128a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3cd139875e9a7688b3fc715264032620812a5fa3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/50fb4e17df319bb33be6f14e2a856950c1577dee" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/944d5fe50f3f03daacfea16300e656a1691c4a23" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b6a2a9cbb67545c825ec95f06adb7ff300a2ad71" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c5b2063c65d05e79fad8029324581d86cfba7eea" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/db896bbe4a9c67cee377e5f6a743350d3ae4acf6" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:28:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-6347-pxpp-244g/GHSA-6347-pxpp-244g.json b/advisories/unreviewed/2024/02/GHSA-6347-pxpp-244g/GHSA-6347-pxpp-244g.json new file mode 100644 index 00000000000..389f022bd68 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-6347-pxpp-244g/GHSA-6347-pxpp-244g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6347-pxpp-244g", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-26466" + ], + "details": "A DOM based cross-site scripting (XSS) vulnerability in the component /dom/ranges/Range-test-iframe.html of web-platform-tests/wpt before commit 938e843 allows attackers to execute arbitrary Javascript via sending a crafted URL.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26466" + }, + { + "type": "WEB", + "url": "https://gist.github.com/cd80/8e41a17bc0c2113f6347581cec726d11" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-672f-vpw8-x67x/GHSA-672f-vpw8-x67x.json b/advisories/unreviewed/2024/02/GHSA-672f-vpw8-x67x/GHSA-672f-vpw8-x67x.json index 927bad37d2a..f340add39eb 100644 --- a/advisories/unreviewed/2024/02/GHSA-672f-vpw8-x67x/GHSA-672f-vpw8-x67x.json +++ b/advisories/unreviewed/2024/02/GHSA-672f-vpw8-x67x/GHSA-672f-vpw8-x67x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-672f-vpw8-x67x", - "modified": "2024-02-23T03:30:39Z", + "modified": "2024-02-26T18:30:28Z", "published": "2024-02-21T06:30:32Z", "aliases": [ "CVE-2024-1673" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://issues.chromium.org/issues/41490491" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PWWBMVQTSERVBXSXCZVUKIMEDNQUQ7O3" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QDCMYQ3J45NHQ4EJREM3BJNNKB5BK4Y7" diff --git a/advisories/unreviewed/2024/02/GHSA-672r-97r7-vx2q/GHSA-672r-97r7-vx2q.json b/advisories/unreviewed/2024/02/GHSA-672r-97r7-vx2q/GHSA-672r-97r7-vx2q.json new file mode 100644 index 00000000000..5ebb4af170d --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-672r-97r7-vx2q/GHSA-672r-97r7-vx2q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-672r-97r7-vx2q", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-27447" + ], + "details": "pretix before 2024.1.1 mishandles file validation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27447" + }, + { + "type": "WEB", + "url": "https://github.com/pretix/pretix/compare/v2023.10.2...v2024.1.1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:28:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-692m-8cmm-mgxx/GHSA-692m-8cmm-mgxx.json b/advisories/unreviewed/2024/02/GHSA-692m-8cmm-mgxx/GHSA-692m-8cmm-mgxx.json new file mode 100644 index 00000000000..b88b81d1057 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-692m-8cmm-mgxx/GHSA-692m-8cmm-mgxx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-692m-8cmm-mgxx", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-25768" + ], + "details": "OpenDMARC 1.4.2 contains a null pointer dereference vulnerability in /OpenDMARC/libopendmarc/opendmarc_policy.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25768" + }, + { + "type": "WEB", + "url": "https://github.com/LuMingYinDetect/OpenDMARC_defects/blob/main/OpenDMARC_detect_1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-6pc7-4x73-wwc6/GHSA-6pc7-4x73-wwc6.json b/advisories/unreviewed/2024/02/GHSA-6pc7-4x73-wwc6/GHSA-6pc7-4x73-wwc6.json new file mode 100644 index 00000000000..87b6e8376b7 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-6pc7-4x73-wwc6/GHSA-6pc7-4x73-wwc6.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pc7-4x73-wwc6", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-26606" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbinder: signal epoll threads of self-work\n\nIn (e)poll mode, threads often depend on I/O events to determine when\ndata is ready for consumption. Within binder, a thread may initiate a\ncommand via BINDER_WRITE_READ without a read buffer and then make use\nof epoll_wait() or similar to consume any responses afterwards.\n\nIt is then crucial that epoll threads are signaled via wakeup when they\nqueue their own work. Otherwise, they risk waiting indefinitely for an\nevent leaving their work unhandled. What is worse, subsequent commands\nwon't trigger a wakeup either as the thread has pending work.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26606" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/42beab162dcee1e691ee4934292d51581c29df61" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/82722b453dc2f967b172603e389ee7dc1b3137cc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/90e09c016d72b91e76de25f71c7b93d94cc3c769" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/93b372c39c40cbf179e56621e6bc48240943af69" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/97830f3c3088638ff90b20dfba2eb4d487bf14d7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a423042052ec2bdbf1e552e621e6a768922363cc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a7ae586f6f6024f490b8546c8c84670f96bb9b68" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dd64bb8329ce0ea27bc557e4160c2688835402ac" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:28:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-728x-37qh-9vwv/GHSA-728x-37qh-9vwv.json b/advisories/unreviewed/2024/02/GHSA-728x-37qh-9vwv/GHSA-728x-37qh-9vwv.json new file mode 100644 index 00000000000..d8a7bb9cb10 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-728x-37qh-9vwv/GHSA-728x-37qh-9vwv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-728x-37qh-9vwv", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-25760" + ], + "details": "yasm 1.3.0 contains a memory leak via /yasm/tools/genmacro/genmacro.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25760" + }, + { + "type": "WEB", + "url": "https://github.com/LuMingYinDetect/yasm_defects/blob/main/yasm_detect_2.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-72wm-hh56-9gp6/GHSA-72wm-hh56-9gp6.json b/advisories/unreviewed/2024/02/GHSA-72wm-hh56-9gp6/GHSA-72wm-hh56-9gp6.json new file mode 100644 index 00000000000..cff4b3ee34f --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-72wm-hh56-9gp6/GHSA-72wm-hh56-9gp6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-72wm-hh56-9gp6", + "modified": "2024-02-26T18:30:29Z", + "published": "2024-02-26T18:30:29Z", + "aliases": [ + "CVE-2024-0440" + ], + "details": "Attacker, with permission to submit a link or submits a link via POST to be collected that is using the file:// protocol can then introspect host files and other relatively stored files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0440" + }, + { + "type": "WEB", + "url": "https://github.com/mintplex-labs/anything-llm/commit/1563a1b20f72846d617a88510970d0426ab880d3" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/263fd7eb-f9a9-4578-9655-0e28c609272f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-73wx-63h7-3wh6/GHSA-73wx-63h7-3wh6.json b/advisories/unreviewed/2024/02/GHSA-73wx-63h7-3wh6/GHSA-73wx-63h7-3wh6.json new file mode 100644 index 00000000000..5a77ab2fc61 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-73wx-63h7-3wh6/GHSA-73wx-63h7-3wh6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73wx-63h7-3wh6", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-24401" + ], + "details": "SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.php component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24401" + }, + { + "type": "WEB", + "url": "https://www.nagios.com/changelog" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-75f4-ww24-h9gr/GHSA-75f4-ww24-h9gr.json b/advisories/unreviewed/2024/02/GHSA-75f4-ww24-h9gr/GHSA-75f4-ww24-h9gr.json new file mode 100644 index 00000000000..137752f6dd9 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-75f4-ww24-h9gr/GHSA-75f4-ww24-h9gr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75f4-ww24-h9gr", + "modified": "2024-02-26T18:30:29Z", + "published": "2024-02-26T18:30:29Z", + "aliases": [ + "CVE-2024-1622" + ], + "details": "Due to a mistake in error checking, Routinator will terminate when an incoming RTR connection is reset by the peer too quickly after opening.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1622" + }, + { + "type": "WEB", + "url": "https://www.nlnetlabs.nl/downloads/routinator/CVE-2024-1622.txt" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-253" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-7669-733q-3wj7/GHSA-7669-733q-3wj7.json b/advisories/unreviewed/2024/02/GHSA-7669-733q-3wj7/GHSA-7669-733q-3wj7.json new file mode 100644 index 00000000000..358465d4e44 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-7669-733q-3wj7/GHSA-7669-733q-3wj7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7669-733q-3wj7", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-25767" + ], + "details": "nanomq 0.21.2 contains a Use-After-Free vulnerability in /nanomq/nng/src/core/socket.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25767" + }, + { + "type": "WEB", + "url": "https://github.com/LuMingYinDetect/nanomq_defects/blob/main/nanomq_detect_1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-785g-282q-pwvx/GHSA-785g-282q-pwvx.json b/advisories/unreviewed/2024/02/GHSA-785g-282q-pwvx/GHSA-785g-282q-pwvx.json new file mode 100644 index 00000000000..29411950203 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-785g-282q-pwvx/GHSA-785g-282q-pwvx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-785g-282q-pwvx", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-27456" + ], + "details": "rack-cors (aka Rack CORS Middleware) 2.0.1 has 0666 permissions for the .rb files.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27456" + }, + { + "type": "WEB", + "url": "https://github.com/cyu/rack-cors/issues/274" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:28:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-78w9-qxr3-hqhc/GHSA-78w9-qxr3-hqhc.json b/advisories/unreviewed/2024/02/GHSA-78w9-qxr3-hqhc/GHSA-78w9-qxr3-hqhc.json index f60efcb62b2..2cf8c1789c7 100644 --- a/advisories/unreviewed/2024/02/GHSA-78w9-qxr3-hqhc/GHSA-78w9-qxr3-hqhc.json +++ b/advisories/unreviewed/2024/02/GHSA-78w9-qxr3-hqhc/GHSA-78w9-qxr3-hqhc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-78w9-qxr3-hqhc", - "modified": "2024-02-23T03:30:39Z", + "modified": "2024-02-26T18:30:28Z", "published": "2024-02-21T06:30:32Z", "aliases": [ "CVE-2024-1675" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://issues.chromium.org/issues/41486208" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PWWBMVQTSERVBXSXCZVUKIMEDNQUQ7O3" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QDCMYQ3J45NHQ4EJREM3BJNNKB5BK4Y7" diff --git a/advisories/unreviewed/2024/02/GHSA-79m3-3j97-c9x5/GHSA-79m3-3j97-c9x5.json b/advisories/unreviewed/2024/02/GHSA-79m3-3j97-c9x5/GHSA-79m3-3j97-c9x5.json new file mode 100644 index 00000000000..3a09e385e27 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-79m3-3j97-c9x5/GHSA-79m3-3j97-c9x5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79m3-3j97-c9x5", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-27359" + ], + "details": "Certain WithSecure products allow a Denial of Service because the engine scanner can go into an infinite loop when processing an archive file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, WithSecure Linux Security 64 12.0, WithSecure Linux Protection 12.0, and WithSecure Atlant 1.0.35-1.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27359" + }, + { + "type": "WEB", + "url": "https://www.withsecure.com/en/support/security-advisories/cve-2034-n1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:28:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-7f2p-xwcx-975m/GHSA-7f2p-xwcx-975m.json b/advisories/unreviewed/2024/02/GHSA-7f2p-xwcx-975m/GHSA-7f2p-xwcx-975m.json new file mode 100644 index 00000000000..e96486db83d --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-7f2p-xwcx-975m/GHSA-7f2p-xwcx-975m.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7f2p-xwcx-975m", + "modified": "2024-02-26T18:30:28Z", + "published": "2024-02-26T18:30:28Z", + "aliases": [ + "CVE-2023-49960" + ], + "details": "In Indo-Sol PROFINET-INspektor NT through 2.4.0, a path traversal vulnerability in the httpuploadd service of the firmware allows remote attackers to write to arbitrary files via a crafted filename parameter in requests to the /upload endpoint.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49960" + }, + { + "type": "WEB", + "url": "https://code-white.com/public-vulnerability-list" + }, + { + "type": "WEB", + "url": "https://www.indu-sol.com/en/products/profinet/diagnostics/profinet-inspektorr-nt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-7j4q-xf7j-jxcp/GHSA-7j4q-xf7j-jxcp.json b/advisories/unreviewed/2024/02/GHSA-7j4q-xf7j-jxcp/GHSA-7j4q-xf7j-jxcp.json new file mode 100644 index 00000000000..a5d973dc9e7 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-7j4q-xf7j-jxcp/GHSA-7j4q-xf7j-jxcp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7j4q-xf7j-jxcp", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-26467" + ], + "details": "A DOM based cross-site scripting (XSS) vulnerability in the component generator.html of tabatkins/railroad-diagrams before commit ea9a123 allows attackers to execute arbitrary Javascript via sending a crafted URL.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26467" + }, + { + "type": "WEB", + "url": "https://gist.github.com/cd80/50463b0e62067ec861b7006cbf46b068" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-7jwf-rcqv-w98g/GHSA-7jwf-rcqv-w98g.json b/advisories/unreviewed/2024/02/GHSA-7jwf-rcqv-w98g/GHSA-7jwf-rcqv-w98g.json new file mode 100644 index 00000000000..d31a051b363 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-7jwf-rcqv-w98g/GHSA-7jwf-rcqv-w98g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jwf-rcqv-w98g", + "modified": "2024-02-26T18:30:30Z", + "published": "2024-02-26T18:30:30Z", + "aliases": [ + "CVE-2024-1886" + ], + "details": "\n\n\nThis vulnerability allows remote attackers to traverse the directory on the affected webOS of LG Signage TV.\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1886" + }, + { + "type": "WEB", + "url": "https://lgsecurity.lge.com/bulletins/idproducts#updateDetails" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-7r53-r6j6-q893/GHSA-7r53-r6j6-q893.json b/advisories/unreviewed/2024/02/GHSA-7r53-r6j6-q893/GHSA-7r53-r6j6-q893.json new file mode 100644 index 00000000000..cde54cedc9b --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-7r53-r6j6-q893/GHSA-7r53-r6j6-q893.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7r53-r6j6-q893", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2023-52474" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nIB/hfi1: Fix bugs with non-PAGE_SIZE-end multi-iovec user SDMA requests\n\nhfi1 user SDMA request processing has two bugs that can cause data\ncorruption for user SDMA requests that have multiple payload iovecs\nwhere an iovec other than the tail iovec does not run up to the page\nboundary for the buffer pointed to by that iovec.a\n\nHere are the specific bugs:\n1. user_sdma_txadd() does not use struct user_sdma_iovec->iov.iov_len.\n Rather, user_sdma_txadd() will add up to PAGE_SIZE bytes from iovec\n to the packet, even if some of those bytes are past\n iovec->iov.iov_len and are thus not intended to be in the packet.\n2. user_sdma_txadd() and user_sdma_send_pkts() fail to advance to the\n next iovec in user_sdma_request->iovs when the current iovec\n is not PAGE_SIZE and does not contain enough data to complete the\n packet. The transmitted packet will contain the wrong data from the\n iovec pages.\n\nThis has not been an issue with SDMA packets from hfi1 Verbs or PSM2\nbecause they only produce iovecs that end short of PAGE_SIZE as the tail\niovec of an SDMA request.\n\nFixing these bugs exposes other bugs with the SDMA pin cache\n(struct mmu_rb_handler) that get in way of supporting user SDMA requests\nwith multiple payload iovecs whose buffers do not end at PAGE_SIZE. So\nthis commit fixes those issues as well.\n\nHere are the mmu_rb_handler bugs that non-PAGE_SIZE-end multi-iovec\npayload user SDMA requests can hit:\n1. Overlapping memory ranges in mmu_rb_handler will result in duplicate\n pinnings.\n2. When extending an existing mmu_rb_handler entry (struct mmu_rb_node),\n the mmu_rb code (1) removes the existing entry under a lock, (2)\n releases that lock, pins the new pages, (3) then reacquires the lock\n to insert the extended mmu_rb_node.\n\n If someone else comes in and inserts an overlapping entry between (2)\n and (3), insert in (3) will fail.\n\n The failure path code in this case unpins _all_ pages in either the\n original mmu_rb_node or the new mmu_rb_node that was inserted between\n (2) and (3).\n3. In hfi1_mmu_rb_remove_unless_exact(), mmu_rb_node->refcount is\n incremented outside of mmu_rb_handler->lock. As a result, mmu_rb_node\n could be evicted by another thread that gets mmu_rb_handler->lock and\n checks mmu_rb_node->refcount before mmu_rb_node->refcount is\n incremented.\n4. Related to #2 above, SDMA request submission failure path does not\n check mmu_rb_node->refcount before freeing mmu_rb_node object.\n\n If there are other SDMA requests in progress whose iovecs have\n pointers to the now-freed mmu_rb_node(s), those pointers to the\n now-freed mmu_rb nodes will be dereferenced when those SDMA requests\n complete.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52474" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/00cbce5cbf88459cd1aa1d60d0f1df15477df127" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7e6010f79b58f45b204cf18aa58f4b73c3f30adc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9c4c6512d7330b743c4ffd18bd999a86ca26db0d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a2bd706ab63509793b5cd5065e685b7ef5cba678" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c76cb8f4bdf26d04cfa5485a93ce297dba5e6a80" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dce59b5443700fbd0d2433ec6e4d4cf063448844" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-7vf7-cqc9-qxj2/GHSA-7vf7-cqc9-qxj2.json b/advisories/unreviewed/2024/02/GHSA-7vf7-cqc9-qxj2/GHSA-7vf7-cqc9-qxj2.json new file mode 100644 index 00000000000..8ce689b1bfd --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-7vf7-cqc9-qxj2/GHSA-7vf7-cqc9-qxj2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7vf7-cqc9-qxj2", + "modified": "2024-02-26T18:30:29Z", + "published": "2024-02-26T18:30:29Z", + "aliases": [ + "CVE-2024-1710" + ], + "details": "The Addon Library plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the onAjaxAction function action in all versions up to, and including, 1.3.76. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform several unauthorized actions including uploading arbitrary files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1710" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/addon-library/trunk/inc_php/unitecreator_actions.class.php#L39" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/15cf34d8-256b-495e-9385-a5d526bfb335?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-7xfv-2p7x-fhmv/GHSA-7xfv-2p7x-fhmv.json b/advisories/unreviewed/2024/02/GHSA-7xfv-2p7x-fhmv/GHSA-7xfv-2p7x-fhmv.json new file mode 100644 index 00000000000..8ca7a1314bb --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-7xfv-2p7x-fhmv/GHSA-7xfv-2p7x-fhmv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xfv-2p7x-fhmv", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-26455" + ], + "details": "fluent-bit 2.2.2 contains a Use-After-Free vulnerability in /fluent-bit/plugins/custom_calyptia/calyptia.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26455" + }, + { + "type": "WEB", + "url": "https://github.com/LuMingYinDetect/fluent-bit_defects/blob/main/fluent-bit_detect_1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-8459-gg55-8qjj/GHSA-8459-gg55-8qjj.json b/advisories/unreviewed/2024/02/GHSA-8459-gg55-8qjj/GHSA-8459-gg55-8qjj.json index 99d047c589b..a948a798b6f 100644 --- a/advisories/unreviewed/2024/02/GHSA-8459-gg55-8qjj/GHSA-8459-gg55-8qjj.json +++ b/advisories/unreviewed/2024/02/GHSA-8459-gg55-8qjj/GHSA-8459-gg55-8qjj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8459-gg55-8qjj", - "modified": "2024-02-23T03:30:39Z", + "modified": "2024-02-26T18:30:28Z", "published": "2024-02-14T18:30:25Z", "aliases": [ "CVE-2023-50387" @@ -53,10 +53,18 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BUIP7T7Z4T3UHLXFWG6XIVDP4GYPD3AI" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVRDSJVZKMCXKKPP6PNR62T7RWZ3YSDZ" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PNNHZSZPG2E7NBMBNYPGHCFI4V4XRWNQ" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGS7JN6FZXUSTC2XKQHH27574XOULYYJ" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVYA42BLXUCIDLD35YIJPJSHDIADNYMP" diff --git a/advisories/unreviewed/2024/02/GHSA-89r2-jh3p-h38p/GHSA-89r2-jh3p-h38p.json b/advisories/unreviewed/2024/02/GHSA-89r2-jh3p-h38p/GHSA-89r2-jh3p-h38p.json new file mode 100644 index 00000000000..9fca56c3e3b --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-89r2-jh3p-h38p/GHSA-89r2-jh3p-h38p.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89r2-jh3p-h38p", + "modified": "2024-02-26T18:30:29Z", + "published": "2024-02-26T18:30:29Z", + "aliases": [ + "CVE-2024-1165" + ], + "details": "The Brizy – Page Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.39 via the 'id'. This makes it possible for authenticated attackers, with contributor-level access and above, to upload files to arbitrary locations on the server", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1165" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/brizy/tags/2.4.39/editor/screenshot/manager.php#L33" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3034945/brizy/tags/2.4.41/editor/screenshot/manager.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7673b2ba-5d7a-4ae9-92e7-1a910687fdb8?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-8q86-4x73-99v8/GHSA-8q86-4x73-99v8.json b/advisories/unreviewed/2024/02/GHSA-8q86-4x73-99v8/GHSA-8q86-4x73-99v8.json new file mode 100644 index 00000000000..3d47822cca0 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-8q86-4x73-99v8/GHSA-8q86-4x73-99v8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8q86-4x73-99v8", + "modified": "2024-02-26T18:30:29Z", + "published": "2024-02-26T18:30:29Z", + "aliases": [ + "CVE-2024-0387" + ], + "details": "The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the product and have it forwarded to the target. An attacker can bypass access controls or hide the source of malicious requests.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0387" + }, + { + "type": "WEB", + "url": "https://www.moxa.com/en/support/product-support/security-advisory/mpsa-237129-eds-4000-g4000-series-ip-forwarding-vulnerability?viewmode=0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-441" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-9629-73hh-qpxp/GHSA-9629-73hh-qpxp.json b/advisories/unreviewed/2024/02/GHSA-9629-73hh-qpxp/GHSA-9629-73hh-qpxp.json new file mode 100644 index 00000000000..9e76e6f4adb --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-9629-73hh-qpxp/GHSA-9629-73hh-qpxp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9629-73hh-qpxp", + "modified": "2024-02-26T18:30:29Z", + "published": "2024-02-26T18:30:29Z", + "aliases": [ + "CVE-2023-52471" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nice: Fix some null pointer dereference issues in ice_ptp.c\n\ndevm_kasprintf() returns a pointer to dynamically allocated memory\nwhich can be NULL upon failure.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52471" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3027e7b15b02d2d37e3f82d6b8404f6d37e3b8cf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3cd9b9bee33f39f6c6d52360fe381b89a7b12695" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-9h96-qfg7-gpv6/GHSA-9h96-qfg7-gpv6.json b/advisories/unreviewed/2024/02/GHSA-9h96-qfg7-gpv6/GHSA-9h96-qfg7-gpv6.json new file mode 100644 index 00000000000..cae95911d8e --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-9h96-qfg7-gpv6/GHSA-9h96-qfg7-gpv6.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9h96-qfg7-gpv6", + "modified": "2024-02-26T18:30:30Z", + "published": "2024-02-26T18:30:30Z", + "aliases": [ + "CVE-2024-1877" + ], + "details": "A vulnerability was found in SourceCodester Employee Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /cancel.php. The manipulation of the argument id with the input 1%20or%201=1 leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-254725 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1877" + }, + { + "type": "WEB", + "url": "https://github.com/skid-nochizplz/skid-nochizplz/blob/main/TrashBin/CVE/SOURCECODESTER%20EMPLOYEE%20MANAGEMENT%20SYSTEM/Employee%20Leave%20Cancel%20SQL%20Injection.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.254725" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.254725" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-c77m-cx29-7m84/GHSA-c77m-cx29-7m84.json b/advisories/unreviewed/2024/02/GHSA-c77m-cx29-7m84/GHSA-c77m-cx29-7m84.json new file mode 100644 index 00000000000..192500afb2b --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-c77m-cx29-7m84/GHSA-c77m-cx29-7m84.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c77m-cx29-7m84", + "modified": "2024-02-26T18:30:29Z", + "published": "2024-02-26T18:30:29Z", + "aliases": [ + "CVE-2023-52470" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/radeon: check the alloc_workqueue return value in radeon_crtc_init()\n\ncheck the alloc_workqueue return value in radeon_crtc_init()\nto avoid null-ptr-deref.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52470" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0b813a6a0087451cb702b6eb841f10856f49d088" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/14bbfaa5df273b26cde6707f6e655585700e6fe1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/21b1645660717d6126dd4866c850fcc5c4703a41" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/57ca7984806d79b38af528de88fd803babf27feb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5d12c5d75f7c78b83a738025947651ec5c95b4d4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7a2464fac80d42f6f8819fed97a553e9c2f43310" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c4ff55408187f2595066967047363ca84e76db85" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fb2d8bc9b5e55848b8a7c3c028e2ee8d49f28f97" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-c9jh-pp3m-mqr9/GHSA-c9jh-pp3m-mqr9.json b/advisories/unreviewed/2024/02/GHSA-c9jh-pp3m-mqr9/GHSA-c9jh-pp3m-mqr9.json new file mode 100644 index 00000000000..1b6da10862f --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-c9jh-pp3m-mqr9/GHSA-c9jh-pp3m-mqr9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9jh-pp3m-mqr9", + "modified": "2024-02-26T18:30:30Z", + "published": "2024-02-26T18:30:30Z", + "aliases": [ + "CVE-2024-23605" + ], + "details": "A heap-based buffer overflow vulnerability exists in the GGUF library header.n_kv functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23605" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1916" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-cg5m-p8pg-93cg/GHSA-cg5m-p8pg-93cg.json b/advisories/unreviewed/2024/02/GHSA-cg5m-p8pg-93cg/GHSA-cg5m-p8pg-93cg.json new file mode 100644 index 00000000000..6198ab7ab43 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-cg5m-p8pg-93cg/GHSA-cg5m-p8pg-93cg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cg5m-p8pg-93cg", + "modified": "2024-02-26T18:30:29Z", + "published": "2024-02-26T18:30:29Z", + "aliases": [ + "CVE-2024-0436" + ], + "details": "Theoretically, it would be possible for an attacker to brute-force the password for an instance in single-user password protection mode via a timing attack given the linear nature of the `!==` used for comparison.\n\nThe risk is minified by the additional overhead of the request, which varies in a non-constant nature making the attack less reliable to execute ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0436" + }, + { + "type": "WEB", + "url": "https://github.com/mintplex-labs/anything-llm/commit/3c859ba3038121b67fb98e87dc52617fa27cbef0" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/3e73cb96-c038-46a1-81b7-4d2215b36268" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-764" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-f49h-mjwq-cq8p/GHSA-f49h-mjwq-cq8p.json b/advisories/unreviewed/2024/02/GHSA-f49h-mjwq-cq8p/GHSA-f49h-mjwq-cq8p.json new file mode 100644 index 00000000000..67c9299b005 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-f49h-mjwq-cq8p/GHSA-f49h-mjwq-cq8p.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f49h-mjwq-cq8p", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-27350" + ], + "details": "Amazon Fire OS 7 before 7.6.6.9 and 8 before 8.1.0.3 allows Fire TV applications to establish local ADB (Android Debug Bridge) connections. NOTE: some third parties dispute whether this has security relevance, because an ADB connection is only possible after the (non-default) ADB Debugging option is enabled, and after the initiator of that specific connection attempt has been approved via a full-screen prompt.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27350" + }, + { + "type": "WEB", + "url": "https://developer.amazon.com/docs/fire-tv/fire-os-overview.html" + }, + { + "type": "WEB", + "url": "https://news.ycombinator.com/item?id=39496861" + }, + { + "type": "WEB", + "url": "https://www.aftvnews.com/amazon-blocks-long-running-fire-tv-capability-breaking-popular-apps-with-no-warning-and-giving-developers-the-runaround" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:28:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-f54m-q836-9rr6/GHSA-f54m-q836-9rr6.json b/advisories/unreviewed/2024/02/GHSA-f54m-q836-9rr6/GHSA-f54m-q836-9rr6.json new file mode 100644 index 00000000000..8c3f37ec00c --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-f54m-q836-9rr6/GHSA-f54m-q836-9rr6.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f54m-q836-9rr6", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-26600" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nphy: ti: phy-omap-usb2: Fix NULL pointer dereference for SRP\n\nIf the external phy working together with phy-omap-usb2 does not implement\nsend_srp(), we may still attempt to call it. This can happen on an idle\nEthernet gadget triggering a wakeup for example:\n\nconfigfs-gadget.g1 gadget.0: ECM Suspend\nconfigfs-gadget.g1 gadget.0: Port suspended. Triggering wakeup\n...\nUnable to handle kernel NULL pointer dereference at virtual address\n00000000 when execute\n...\nPC is at 0x0\nLR is at musb_gadget_wakeup+0x1d4/0x254 [musb_hdrc]\n...\nmusb_gadget_wakeup [musb_hdrc] from usb_gadget_wakeup+0x1c/0x3c [udc_core]\nusb_gadget_wakeup [udc_core] from eth_start_xmit+0x3b0/0x3d4 [u_ether]\neth_start_xmit [u_ether] from dev_hard_start_xmit+0x94/0x24c\ndev_hard_start_xmit from sch_direct_xmit+0x104/0x2e4\nsch_direct_xmit from __dev_queue_xmit+0x334/0xd88\n__dev_queue_xmit from arp_solicit+0xf0/0x268\narp_solicit from neigh_probe+0x54/0x7c\nneigh_probe from __neigh_event_send+0x22c/0x47c\n__neigh_event_send from neigh_resolve_output+0x14c/0x1c0\nneigh_resolve_output from ip_finish_output2+0x1c8/0x628\nip_finish_output2 from ip_send_skb+0x40/0xd8\nip_send_skb from udp_send_skb+0x124/0x340\nudp_send_skb from udp_sendmsg+0x780/0x984\nudp_sendmsg from __sys_sendto+0xd8/0x158\n__sys_sendto from ret_fast_syscall+0x0/0x58\n\nLet's fix the issue by checking for send_srp() and set_vbus() before\ncalling them. For USB peripheral only cases these both could be NULL.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26600" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0430bfcd46657d9116a26cd377f112cbc40826a4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/14ef61594a5a286ae0d493b8acbf9eac46fd04c4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/396e17af6761b3cc9e6e4ca94b4de7f642bfece1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/486218c11e8d1c8f515a3bdd70d62203609d4b6b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7104ba0f1958adb250319e68a15eff89ec4fd36d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8398d8d735ee93a04fb9e9f490e8cacd737e3bf5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8cc889b9dea0579726be9520fcc766077890b462" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/be3b82e4871ba00e9b5d0ede92d396d579d7b3b3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-f8gg-fh4p-4795/GHSA-f8gg-fh4p-4795.json b/advisories/unreviewed/2024/02/GHSA-f8gg-fh4p-4795/GHSA-f8gg-fh4p-4795.json index 4c6718dde53..12aee891b0f 100644 --- a/advisories/unreviewed/2024/02/GHSA-f8gg-fh4p-4795/GHSA-f8gg-fh4p-4795.json +++ b/advisories/unreviewed/2024/02/GHSA-f8gg-fh4p-4795/GHSA-f8gg-fh4p-4795.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f8gg-fh4p-4795", - "modified": "2024-02-23T03:30:39Z", + "modified": "2024-02-26T18:30:28Z", "published": "2024-02-21T06:30:32Z", "aliases": [ "CVE-2024-1669" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://issues.chromium.org/issues/41495060" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PWWBMVQTSERVBXSXCZVUKIMEDNQUQ7O3" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QDCMYQ3J45NHQ4EJREM3BJNNKB5BK4Y7" diff --git a/advisories/unreviewed/2024/02/GHSA-fhv7-8956-mv3h/GHSA-fhv7-8956-mv3h.json b/advisories/unreviewed/2024/02/GHSA-fhv7-8956-mv3h/GHSA-fhv7-8956-mv3h.json new file mode 100644 index 00000000000..1dd50d07ad1 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-fhv7-8956-mv3h/GHSA-fhv7-8956-mv3h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhv7-8956-mv3h", + "modified": "2024-02-26T18:30:30Z", + "published": "2024-02-26T18:30:30Z", + "aliases": [ + "CVE-2024-21836" + ], + "details": "A heap-based buffer overflow vulnerability exists in the GGUF library header.n_tensors functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21836" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1915" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-fq97-hv4f-crm6/GHSA-fq97-hv4f-crm6.json b/advisories/unreviewed/2024/02/GHSA-fq97-hv4f-crm6/GHSA-fq97-hv4f-crm6.json new file mode 100644 index 00000000000..d12a20b0c11 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-fq97-hv4f-crm6/GHSA-fq97-hv4f-crm6.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fq97-hv4f-crm6", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-26603" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/fpu: Stop relying on userspace for info to fault in xsave buffer\n\nBefore this change, the expected size of the user space buffer was\ntaken from fx_sw->xstate_size. fx_sw->xstate_size can be changed\nfrom user-space, so it is possible construct a sigreturn frame where:\n\n * fx_sw->xstate_size is smaller than the size required by valid bits in\n fx_sw->xfeatures.\n * user-space unmaps parts of the sigrame fpu buffer so that not all of\n the buffer required by xrstor is accessible.\n\nIn this case, xrstor tries to restore and accesses the unmapped area\nwhich results in a fault. But fault_in_readable succeeds because buf +\nfx_sw->xstate_size is within the still mapped area, so it goes back and\ntries xrstor again. It will spin in this loop forever.\n\nInstead, fault in the maximum size which can be touched by XRSTOR (taken\nfrom fpstate->user_size).\n\n[ dhansen: tweak subject / changelog ]", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26603" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/627339cccdc9166792ecf96bc3c9f711a60ce996" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/627e28cbb65564e55008315d9e02fbb90478beda" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b2479ab426cef7ab79a13005650eff956223ced2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d877550eaf2dc9090d782864c96939397a3c6835" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:28:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-frg3-hm7v-3rpf/GHSA-frg3-hm7v-3rpf.json b/advisories/unreviewed/2024/02/GHSA-frg3-hm7v-3rpf/GHSA-frg3-hm7v-3rpf.json index 12b74b19a4b..74ad6e50c21 100644 --- a/advisories/unreviewed/2024/02/GHSA-frg3-hm7v-3rpf/GHSA-frg3-hm7v-3rpf.json +++ b/advisories/unreviewed/2024/02/GHSA-frg3-hm7v-3rpf/GHSA-frg3-hm7v-3rpf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-frg3-hm7v-3rpf", - "modified": "2024-02-23T03:30:39Z", + "modified": "2024-02-26T18:30:28Z", "published": "2024-02-21T06:30:32Z", "aliases": [ "CVE-2024-1671" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://issues.chromium.org/issues/41487933" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PWWBMVQTSERVBXSXCZVUKIMEDNQUQ7O3" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QDCMYQ3J45NHQ4EJREM3BJNNKB5BK4Y7" diff --git a/advisories/unreviewed/2024/02/GHSA-fxmj-6xv8-f3m7/GHSA-fxmj-6xv8-f3m7.json b/advisories/unreviewed/2024/02/GHSA-fxmj-6xv8-f3m7/GHSA-fxmj-6xv8-f3m7.json new file mode 100644 index 00000000000..34ce6ee2c0b --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-fxmj-6xv8-f3m7/GHSA-fxmj-6xv8-f3m7.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fxmj-6xv8-f3m7", + "modified": "2024-02-26T18:30:28Z", + "published": "2024-02-26T18:30:28Z", + "aliases": [ + "CVE-2023-32344" + ], + "details": "IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to form action hijacking where it is possible to modify the form action to reference an arbitrary path. IBM X-Force ID: 255898.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32344" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/255898" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7123154" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-gh68-jm46-84rf/GHSA-gh68-jm46-84rf.json b/advisories/unreviewed/2024/02/GHSA-gh68-jm46-84rf/GHSA-gh68-jm46-84rf.json index 4b57a7fe633..7c1062bfbf6 100644 --- a/advisories/unreviewed/2024/02/GHSA-gh68-jm46-84rf/GHSA-gh68-jm46-84rf.json +++ b/advisories/unreviewed/2024/02/GHSA-gh68-jm46-84rf/GHSA-gh68-jm46-84rf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gh68-jm46-84rf", - "modified": "2024-02-09T03:32:59Z", + "modified": "2024-02-26T18:30:27Z", "published": "2024-02-04T21:30:43Z", "aliases": [ "CVE-2023-52425" @@ -24,6 +24,14 @@ { "type": "WEB", "url": "https://github.com/libexpat/libexpat/pull/789" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PNRIHC7DVVRAIWFRGV23Y6UZXFBXSQDB" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WNUBSGZFEZOBHJFTAD42SAN4ATW2VEMV" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-gj7p-vqfr-xgjw/GHSA-gj7p-vqfr-xgjw.json b/advisories/unreviewed/2024/02/GHSA-gj7p-vqfr-xgjw/GHSA-gj7p-vqfr-xgjw.json new file mode 100644 index 00000000000..f1a21fcbfa7 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-gj7p-vqfr-xgjw/GHSA-gj7p-vqfr-xgjw.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gj7p-vqfr-xgjw", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2019-25160" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetlabel: fix out-of-bounds memory accesses\n\nThere are two array out-of-bounds memory accesses, one in\ncipso_v4_map_lvl_valid(), the other in netlbl_bitmap_walk(). Both\nerrors are embarassingly simple, and the fixes are straightforward.\n\nAs a FYI for anyone backporting this patch to kernels prior to v4.8,\nyou'll want to apply the netlbl_bitmap_walk() patch to\ncipso_v4_bitmap_walk() as netlbl_bitmap_walk() doesn't exist before\nLinux v4.8.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-25160" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1c973f9c7cc2b3caae93192fdc8ecb3f0b4ac000" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5578de4834fe0f2a34fedc7374be691443396d1f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/97bc3683c24999ee621d847c9348c75d2fe86272" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c61d01faa5550e06794dcf86125ccd325bfad950" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dc18101f95fa6e815f426316b8b9a5cee28a334e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e3713abc4248aa6bcc11173d754c418b02a62cbb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fbf9578919d6c91100ec63acf2cba641383f6c78" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fcfe700acdc1c72eab231300e82b962bac2b2b2c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T18:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-gjgc-m5jm-q72q/GHSA-gjgc-m5jm-q72q.json b/advisories/unreviewed/2024/02/GHSA-gjgc-m5jm-q72q/GHSA-gjgc-m5jm-q72q.json new file mode 100644 index 00000000000..53ebda2c233 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-gjgc-m5jm-q72q/GHSA-gjgc-m5jm-q72q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gjgc-m5jm-q72q", + "modified": "2024-02-26T18:30:29Z", + "published": "2024-02-26T18:30:29Z", + "aliases": [ + "CVE-2024-1436" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wiloke WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit.This issue affects WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit: from n/a through 1.0.9.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1436" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/myshopkit-popup-smartbar-slidein/wordpress-woocommerce-myshopkit-plugin-1-0-9-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-gwh5-fh5x-ww83/GHSA-gwh5-fh5x-ww83.json b/advisories/unreviewed/2024/02/GHSA-gwh5-fh5x-ww83/GHSA-gwh5-fh5x-ww83.json new file mode 100644 index 00000000000..2068403eda4 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-gwh5-fh5x-ww83/GHSA-gwh5-fh5x-ww83.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwh5-fh5x-ww83", + "modified": "2024-02-26T18:30:30Z", + "published": "2024-02-26T18:30:30Z", + "aliases": [ + "CVE-2024-21802" + ], + "details": "A heap-based buffer overflow vulnerability exists in the GGUF library info->ne functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21802" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1914" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-gxmr-rxpv-c8fq/GHSA-gxmr-rxpv-c8fq.json b/advisories/unreviewed/2024/02/GHSA-gxmr-rxpv-c8fq/GHSA-gxmr-rxpv-c8fq.json index 8f6bfd1c801..127c36453ca 100644 --- a/advisories/unreviewed/2024/02/GHSA-gxmr-rxpv-c8fq/GHSA-gxmr-rxpv-c8fq.json +++ b/advisories/unreviewed/2024/02/GHSA-gxmr-rxpv-c8fq/GHSA-gxmr-rxpv-c8fq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gxmr-rxpv-c8fq", - "modified": "2024-02-22T00:31:00Z", + "modified": "2024-02-26T18:30:27Z", "published": "2024-02-01T21:30:31Z", "aliases": [ "CVE-2023-5841" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5841" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LSB6DB5LAKGPLRXEF5HDNGUMT7GIFT2C" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XWMINVKQLSUHECXBSQMZFCSDRIHFOJJI" + }, { "type": "WEB", "url": "https://takeonme.org/cves/CVE-2023-5841.html" diff --git a/advisories/unreviewed/2024/02/GHSA-h9j7-5xvc-qhg5/GHSA-h9j7-5xvc-qhg5.json b/advisories/unreviewed/2024/02/GHSA-h9j7-5xvc-qhg5/GHSA-h9j7-5xvc-qhg5.json new file mode 100644 index 00000000000..f6e36b7f96d --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-h9j7-5xvc-qhg5/GHSA-h9j7-5xvc-qhg5.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9j7-5xvc-qhg5", + "modified": "2024-02-26T18:30:29Z", + "published": "2024-02-26T18:30:29Z", + "aliases": [ + "CVE-2024-0243" + ], + "details": "With the following crawler configuration:\n\n```python\nfrom bs4 import BeautifulSoup as Soup\n\nurl = \"https://example.com\"\nloader = RecursiveUrlLoader(\n url=url, max_depth=2, extractor=lambda x: Soup(x, \"html.parser\").text\n)\ndocs = loader.load()\n```\n\nAn attacker in control of the contents of `https://example.com` could place a malicious HTML file in there with links like \"https://example.completely.different/my_file.html\" and the crawler would proceed to download that file as well even though `prevent_outside=True`.\n\nhttps://github.com/langchain-ai/langchain/blob/bf0b3cc0b5ade1fb95a5b1b6fa260e99064c2e22/libs/community/langchain_community/document_loaders/recursive_url_loader.py#L51-L51\n\nResolved in https://github.com/langchain-ai/langchain/pull/15559", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0243" + }, + { + "type": "WEB", + "url": "https://github.com/langchain-ai/langchain/commit/bf0b3cc0b5ade1fb95a5b1b6fa260e99064c2e22" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/370904e7-10ac-40a4-a8d4-e2d16e1ca861" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-hj8r-465g-5vm4/GHSA-hj8r-465g-5vm4.json b/advisories/unreviewed/2024/02/GHSA-hj8r-465g-5vm4/GHSA-hj8r-465g-5vm4.json new file mode 100644 index 00000000000..6da1636dbdd --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-hj8r-465g-5vm4/GHSA-hj8r-465g-5vm4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hj8r-465g-5vm4", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-25410" + ], + "details": "flusity-CMS 2.33 is vulnerable to Unrestricted Upload of File with Dangerous Type in update_setting.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25410" + }, + { + "type": "WEB", + "url": "https://github.com/flusity/flusity-CMS/issues/9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-j4jm-98r4-89rv/GHSA-j4jm-98r4-89rv.json b/advisories/unreviewed/2024/02/GHSA-j4jm-98r4-89rv/GHSA-j4jm-98r4-89rv.json new file mode 100644 index 00000000000..5353eebffc1 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-j4jm-98r4-89rv/GHSA-j4jm-98r4-89rv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4jm-98r4-89rv", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-25925" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in SYSBASICS WooCommerce Easy Checkout Field Editor, Fees & Discounts.This issue affects WooCommerce Easy Checkout Field Editor, Fees & Discounts: from n/a through 3.5.12.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25925" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/phppoet-checkout-fields/wordpress-woocommerce-easy-checkout-field-editor-fees-discounts-plugin-3-5-12-unauthenticated-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-j95w-c3jf-29mw/GHSA-j95w-c3jf-29mw.json b/advisories/unreviewed/2024/02/GHSA-j95w-c3jf-29mw/GHSA-j95w-c3jf-29mw.json new file mode 100644 index 00000000000..d4af91fe89d --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-j95w-c3jf-29mw/GHSA-j95w-c3jf-29mw.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j95w-c3jf-29mw", + "modified": "2024-02-26T18:30:28Z", + "published": "2024-02-26T18:30:28Z", + "aliases": [ + "CVE-2023-43051" + ], + "details": "IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 267451.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43051" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/267451" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7123154" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-j96m-hg98-w6c4/GHSA-j96m-hg98-w6c4.json b/advisories/unreviewed/2024/02/GHSA-j96m-hg98-w6c4/GHSA-j96m-hg98-w6c4.json new file mode 100644 index 00000000000..5dfb09f3ea2 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-j96m-hg98-w6c4/GHSA-j96m-hg98-w6c4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j96m-hg98-w6c4", + "modified": "2024-02-26T18:30:28Z", + "published": "2024-02-26T18:30:28Z", + "aliases": [ + "CVE-2023-49959" + ], + "details": "In Indo-Sol PROFINET-INspektor NT through 2.4.0, a command injection vulnerability in the gedtupdater service of the firmware allows remote attackers to execute arbitrary system commands with root privileges via a crafted filename parameter in POST requests to the /api/updater/ctrl/start_update endpoint.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49959" + }, + { + "type": "WEB", + "url": "https://code-white.com/public-vulnerability-list" + }, + { + "type": "WEB", + "url": "https://www.indu-sol.com/en/products/profinet/diagnostics/profinet-inspektorr-nt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-j96v-g32v-765g/GHSA-j96v-g32v-765g.json b/advisories/unreviewed/2024/02/GHSA-j96v-g32v-765g/GHSA-j96v-g32v-765g.json new file mode 100644 index 00000000000..663010eaeb0 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-j96v-g32v-765g/GHSA-j96v-g32v-765g.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j96v-g32v-765g", + "modified": "2024-02-26T18:30:28Z", + "published": "2024-02-26T18:30:28Z", + "aliases": [ + "CVE-2023-52465" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: Fix null pointer dereference in smb2_probe\n\ndevm_kasprintf and devm_kzalloc return a pointer to dynamically\nallocated memory which can be NULL upon failure.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52465" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/88f04bc3e737155e13caddf0ba8ed19db87f0212" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bd3d2ec447ede9da822addf3960a5f4275e3ae76" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e2717302fbc20f148bcda362facee0444b949a3a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-j98f-j6g4-3jp3/GHSA-j98f-j6g4-3jp3.json b/advisories/unreviewed/2024/02/GHSA-j98f-j6g4-3jp3/GHSA-j98f-j6g4-3jp3.json new file mode 100644 index 00000000000..6da2fa50f3d --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-j98f-j6g4-3jp3/GHSA-j98f-j6g4-3jp3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j98f-j6g4-3jp3", + "modified": "2024-02-26T18:30:30Z", + "published": "2024-02-26T18:30:30Z", + "aliases": [ + "CVE-2024-1885" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on the affected webOS of LG Signage TV.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1885" + }, + { + "type": "WEB", + "url": "https://lgsecurity.lge.com/bulletins/idproducts#updateDetails" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-jc66-9qcw-88hp/GHSA-jc66-9qcw-88hp.json b/advisories/unreviewed/2024/02/GHSA-jc66-9qcw-88hp/GHSA-jc66-9qcw-88hp.json new file mode 100644 index 00000000000..0315e274ce9 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-jc66-9qcw-88hp/GHSA-jc66-9qcw-88hp.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jc66-9qcw-88hp", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2021-46906" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: usbhid: fix info leak in hid_submit_ctrl\n\nIn hid_submit_ctrl(), the way of calculating the report length doesn't\ntake into account that report->size can be zero. When running the\nsyzkaller reproducer, a report of size 0 causes hid_submit_ctrl) to\ncalculate transfer_buffer_length as 16384. When this urb is passed to\nthe usb core layer, KMSAN reports an info leak of 16384 bytes.\n\nTo fix this, first modify hid_report_len() to account for the zero\nreport size case by using DIV_ROUND_UP for the division. Then, call it\nfrom hid_submit_ctrl().", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-46906" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0e280502be1b003c3483ae03fc60dea554fcfa82" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/21883bff0fd854e07429a773ff18f1e9658f50e8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/41b1e71a2c57366b08dcca1a28b0d45ca69429ce" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6be388f4a35d2ce5ef7dbf635a8964a5da7f799f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7f5a4b24cdbd7372770a02f23e347d7d9a9ac8f1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8c064eece9a51856f3f275104520c7e3017fc5c0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b1e3596416d74ce95cc0b7b38472329a3818f8a9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c5d3c142f2d57d40c55e65d5622d319125a45366" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-jrrc-pqj2-c99f/GHSA-jrrc-pqj2-c99f.json b/advisories/unreviewed/2024/02/GHSA-jrrc-pqj2-c99f/GHSA-jrrc-pqj2-c99f.json new file mode 100644 index 00000000000..8741db9e0ca --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-jrrc-pqj2-c99f/GHSA-jrrc-pqj2-c99f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrrc-pqj2-c99f", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-25763" + ], + "details": "openNDS 10.2.0 is vulnerable to Use-After-Free via /openNDS/src/auth.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25763" + }, + { + "type": "WEB", + "url": "https://github.com/LuMingYinDetect/openNDS_defects/blob/main/openNDS_detect_1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-m3q9-44rg-xw34/GHSA-m3q9-44rg-xw34.json b/advisories/unreviewed/2024/02/GHSA-m3q9-44rg-xw34/GHSA-m3q9-44rg-xw34.json new file mode 100644 index 00000000000..9ca368c6590 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-m3q9-44rg-xw34/GHSA-m3q9-44rg-xw34.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3q9-44rg-xw34", + "modified": "2024-02-26T18:30:28Z", + "published": "2024-02-26T18:30:28Z", + "aliases": [ + "CVE-2023-49114" + ], + "details": "A DLL hijacking vulnerability was identified in the Qognify VMS Client Viewer version 7.1 or higher, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL, if some specific pre-conditions are met.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49114" + }, + { + "type": "WEB", + "url": "https://r.sec-consult.com/qognify" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-m5gq-732f-j9v6/GHSA-m5gq-732f-j9v6.json b/advisories/unreviewed/2024/02/GHSA-m5gq-732f-j9v6/GHSA-m5gq-732f-j9v6.json index 3e80251b1f8..8919a2102a8 100644 --- a/advisories/unreviewed/2024/02/GHSA-m5gq-732f-j9v6/GHSA-m5gq-732f-j9v6.json +++ b/advisories/unreviewed/2024/02/GHSA-m5gq-732f-j9v6/GHSA-m5gq-732f-j9v6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m5gq-732f-j9v6", - "modified": "2024-02-15T06:31:34Z", + "modified": "2024-02-26T18:30:27Z", "published": "2024-02-08T18:30:39Z", "aliases": [ "CVE-2024-25189" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://github.com/P3ngu1nW/CVE_Request/blob/main/benmcollins%3Alibjwt.md" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/02/msg00009.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-m8mq-5vgv-8w3r/GHSA-m8mq-5vgv-8w3r.json b/advisories/unreviewed/2024/02/GHSA-m8mq-5vgv-8w3r/GHSA-m8mq-5vgv-8w3r.json new file mode 100644 index 00000000000..9a31489fe97 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-m8mq-5vgv-8w3r/GHSA-m8mq-5vgv-8w3r.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m8mq-5vgv-8w3r", + "modified": "2024-02-26T18:30:29Z", + "published": "2024-02-26T18:30:29Z", + "aliases": [ + "CVE-2024-0435" + ], + "details": "User can send a chat that contains an XSS opportunity that will then run when the chat is sent and on subsequent page loads.\n\nGiven the minimum requirement for a user to send a chat is to be given access to a workspace via an admin the risk is low. Additionally, the location in which the XSS renders is only limited to the user who submits the XSS. \n\nUltimately, this attack is limited to the user attacking themselves. There is no anonymous chat submission unless the user does not take the minimum steps required to protect their instance.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0435" + }, + { + "type": "WEB", + "url": "https://github.com/mintplex-labs/anything-llm/commit/a4ace56a401ffc8ce0082d7444159dfd5dc28834" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/53308220-8b2e-492f-b248-0985b7c2db61" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-mgvp-6fwh-58v2/GHSA-mgvp-6fwh-58v2.json b/advisories/unreviewed/2024/02/GHSA-mgvp-6fwh-58v2/GHSA-mgvp-6fwh-58v2.json new file mode 100644 index 00000000000..54b95fa6d2b --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-mgvp-6fwh-58v2/GHSA-mgvp-6fwh-58v2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgvp-6fwh-58v2", + "modified": "2024-02-26T18:30:30Z", + "published": "2024-02-26T18:30:30Z", + "aliases": [ + "CVE-2024-1890" + ], + "details": "Vulnerability whereby an attacker could send a malicious link to an authenticated operator, which could allow remote attackers to perform a clickjacking attack on Sunny WebBox firmware version 1.6.1 and earlier.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1890" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-sma-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1021" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-mj54-2qgh-27pf/GHSA-mj54-2qgh-27pf.json b/advisories/unreviewed/2024/02/GHSA-mj54-2qgh-27pf/GHSA-mj54-2qgh-27pf.json new file mode 100644 index 00000000000..8e2d958d39d --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-mj54-2qgh-27pf/GHSA-mj54-2qgh-27pf.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mj54-2qgh-27pf", + "modified": "2024-02-26T18:30:28Z", + "published": "2024-02-26T18:30:28Z", + "aliases": [ + "CVE-2023-30996" + ], + "details": "IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 could be vulnerable to information leakage due to unverified sources in messages sent between Windows objects of different origins. IBM X-Force ID: 254290.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30996" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/254290" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7123154" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-346" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-mp2w-hjcj-f5g9/GHSA-mp2w-hjcj-f5g9.json b/advisories/unreviewed/2024/02/GHSA-mp2w-hjcj-f5g9/GHSA-mp2w-hjcj-f5g9.json index 6fc5d46c367..873176244b7 100644 --- a/advisories/unreviewed/2024/02/GHSA-mp2w-hjcj-f5g9/GHSA-mp2w-hjcj-f5g9.json +++ b/advisories/unreviewed/2024/02/GHSA-mp2w-hjcj-f5g9/GHSA-mp2w-hjcj-f5g9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mp2w-hjcj-f5g9", - "modified": "2024-02-09T03:32:59Z", + "modified": "2024-02-26T18:30:27Z", "published": "2024-02-04T21:30:43Z", "aliases": [ "CVE-2023-52426" @@ -32,6 +32,14 @@ { "type": "WEB", "url": "https://cwe.mitre.org/data/definitions/776.html" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PNRIHC7DVVRAIWFRGV23Y6UZXFBXSQDB" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WNUBSGZFEZOBHJFTAD42SAN4ATW2VEMV" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-mr92-3m8f-x735/GHSA-mr92-3m8f-x735.json b/advisories/unreviewed/2024/02/GHSA-mr92-3m8f-x735/GHSA-mr92-3m8f-x735.json new file mode 100644 index 00000000000..9c457fe107b --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-mr92-3m8f-x735/GHSA-mr92-3m8f-x735.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr92-3m8f-x735", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2019-25162" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: Fix a potential use after free\n\nFree the adap structure only after we are done using it.\nThis patch just moves the put_device() down a bit to avoid the\nuse after free.\n\n[wsa: added comment to the code, added Fixes tag]", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-25162" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/12b0606000d0828630c033bf0c74c748464fe87d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/23a191b132cd87f746c62f3dc27da33683d85829" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/35927d7509ab9bf41896b7e44f639504eae08af7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/81cb31756888bb062e92d2dca21cd629d77a46a9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/871a1e94929a27bf6e2cd99523865c840bbc2d87" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e4c72c06c367758a14f227c847f9d623f1994ecf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e6412ba3b6508bdf9c074d310bf4144afa6aec1a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e8e1a046cf87c8b1363e5de835114f2779e2aaf4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-mw6g-mf3x-8xg2/GHSA-mw6g-mf3x-8xg2.json b/advisories/unreviewed/2024/02/GHSA-mw6g-mf3x-8xg2/GHSA-mw6g-mf3x-8xg2.json new file mode 100644 index 00000000000..d54c3777f25 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-mw6g-mf3x-8xg2/GHSA-mw6g-mf3x-8xg2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw6g-mf3x-8xg2", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-26468" + ], + "details": "A DOM based cross-site scripting (XSS) vulnerability in the component index.html of jstrieb/urlpages before commit 035b647 allows attackers to execute arbitrary Javascript via sending a crafted URL.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26468" + }, + { + "type": "WEB", + "url": "https://gist.github.com/cd80/87b41cf58ba04564d55f4a26152bf0a9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-mxgx-3gr7-j26m/GHSA-mxgx-3gr7-j26m.json b/advisories/unreviewed/2024/02/GHSA-mxgx-3gr7-j26m/GHSA-mxgx-3gr7-j26m.json new file mode 100644 index 00000000000..ad66283dbc2 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-mxgx-3gr7-j26m/GHSA-mxgx-3gr7-j26m.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxgx-3gr7-j26m", + "modified": "2024-02-26T18:30:30Z", + "published": "2024-02-26T18:30:30Z", + "aliases": [ + "CVE-2024-1878" + ], + "details": "A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /myprofile.php. The manipulation of the argument id with the input 1%20or%201=1 leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-254726 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1878" + }, + { + "type": "WEB", + "url": "https://github.com/skid-nochizplz/skid-nochizplz/blob/main/TrashBin/CVE/SOURCECODESTER%20EMPLOYEE%20MANAGEMENT%20SYSTEM/IDOR%20Employee%20Profile.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.254726" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.254726" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-p85g-mx27-m79q/GHSA-p85g-mx27-m79q.json b/advisories/unreviewed/2024/02/GHSA-p85g-mx27-m79q/GHSA-p85g-mx27-m79q.json new file mode 100644 index 00000000000..ea30a4262a7 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-p85g-mx27-m79q/GHSA-p85g-mx27-m79q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p85g-mx27-m79q", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-25913" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25913" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/moveto/wordpress-moveto-plugin-6-2-unauthenticated-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-p88p-j9px-cq4j/GHSA-p88p-j9px-cq4j.json b/advisories/unreviewed/2024/02/GHSA-p88p-j9px-cq4j/GHSA-p88p-j9px-cq4j.json new file mode 100644 index 00000000000..a7ad8e434fe --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-p88p-j9px-cq4j/GHSA-p88p-j9px-cq4j.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p88p-j9px-cq4j", + "modified": "2024-02-26T18:30:28Z", + "published": "2024-02-26T18:30:28Z", + "aliases": [ + "CVE-2023-52468" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nclass: fix use-after-free in class_register()\n\nThe lock_class_key is still registered and can be found in\nlock_keys_hash hlist after subsys_private is freed in error\nhandler path.A task who iterate over the lock_keys_hash\nlater may cause use-after-free.So fix that up and unregister\nthe lock_class_key before kfree(cp).\n\nOn our platform, a driver fails to kset_register because of\ncreating duplicate filename '/class/xxx'.With Kasan enabled,\nit prints a invalid-access bug report.\n\nKASAN bug report:\n\nBUG: KASAN: invalid-access in lockdep_register_key+0x19c/0x1bc\nWrite of size 8 at addr 15ffff808b8c0368 by task modprobe/252\nPointer tag: [15], memory tag: [fe]\n\nCPU: 7 PID: 252 Comm: modprobe Tainted: G W\n 6.6.0-mainline-maybe-dirty #1\n\nCall trace:\ndump_backtrace+0x1b0/0x1e4\nshow_stack+0x2c/0x40\ndump_stack_lvl+0xac/0xe0\nprint_report+0x18c/0x4d8\nkasan_report+0xe8/0x148\n__hwasan_store8_noabort+0x88/0x98\nlockdep_register_key+0x19c/0x1bc\nclass_register+0x94/0x1ec\ninit_module+0xbc/0xf48 [rfkill]\ndo_one_initcall+0x17c/0x72c\ndo_init_module+0x19c/0x3f8\n...\nMemory state around the buggy address:\nffffff808b8c0100: 8a 8a 8a 8a 8a 8a 8a 8a 8a 8a 8a 8a 8a 8a 8a 8a\nffffff808b8c0200: 8a 8a 8a 8a 8a 8a 8a 8a fe fe fe fe fe fe fe fe\n>ffffff808b8c0300: fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe fe\n ^\nffffff808b8c0400: 03 03 03 03 03 03 03 03 03 03 03 03 03 03 03 03\n\nAs CONFIG_KASAN_GENERIC is not set, Kasan reports invalid-access\nnot use-after-free here.In this case, modprobe is manipulating\nthe corrupted lock_keys_hash hlish where lock_class_key is already\nfreed before.\n\nIt's worth noting that this only can happen if lockdep is enabled,\nwhich is not true for normal system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52468" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0f1486dafca3398c4c46b9f6e6452fa27e73b559" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/93ec4a3b76404bce01bd5c9032bef5df6feb1d62" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b57196a5ec5e4c0ffecde8348b085b778c7dce04" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-pcqc-c89r-492h/GHSA-pcqc-c89r-492h.json b/advisories/unreviewed/2024/02/GHSA-pcqc-c89r-492h/GHSA-pcqc-c89r-492h.json new file mode 100644 index 00000000000..100099ac1eb --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-pcqc-c89r-492h/GHSA-pcqc-c89r-492h.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcqc-c89r-492h", + "modified": "2024-02-26T18:30:29Z", + "published": "2024-02-26T18:30:29Z", + "aliases": [ + "CVE-2023-52472" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: rsa - add a check for allocation failure\n\nStatic checkers insist that the mpi_alloc() allocation can fail so add\na check to prevent a NULL dereference. Small allocations like this\ncan't actually fail in current kernels, but adding a check is very\nsimple and makes the static checkers happy.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52472" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2831f4d3bfa68e64c5f83e96688be779c87b3511" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/95ad8b6879e2e49d02e3bfc0e1fb46421633fe2a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d872ca165cb67112f2841ef9c37d51ef7e63d1e4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-phv9-x3fj-743r/GHSA-phv9-x3fj-743r.json b/advisories/unreviewed/2024/02/GHSA-phv9-x3fj-743r/GHSA-phv9-x3fj-743r.json new file mode 100644 index 00000000000..b3fb5d44f94 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-phv9-x3fj-743r/GHSA-phv9-x3fj-743r.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phv9-x3fj-743r", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-27084" + ], + "details": "Rejected reason: This CVE is a duplicate of CVE-2024-1631.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27084" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-pv4h-p8jr-6cv2/GHSA-pv4h-p8jr-6cv2.json b/advisories/unreviewed/2024/02/GHSA-pv4h-p8jr-6cv2/GHSA-pv4h-p8jr-6cv2.json index c0da9dd0a12..56a2973ea7e 100644 --- a/advisories/unreviewed/2024/02/GHSA-pv4h-p8jr-6cv2/GHSA-pv4h-p8jr-6cv2.json +++ b/advisories/unreviewed/2024/02/GHSA-pv4h-p8jr-6cv2/GHSA-pv4h-p8jr-6cv2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pv4h-p8jr-6cv2", - "modified": "2024-02-23T03:30:39Z", + "modified": "2024-02-26T18:30:28Z", "published": "2024-02-14T18:30:25Z", "aliases": [ "CVE-2023-50868" @@ -50,10 +50,18 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BUIP7T7Z4T3UHLXFWG6XIVDP4GYPD3AI" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVRDSJVZKMCXKKPP6PNR62T7RWZ3YSDZ" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PNNHZSZPG2E7NBMBNYPGHCFI4V4XRWNQ" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGS7JN6FZXUSTC2XKQHH27574XOULYYJ" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVYA42BLXUCIDLD35YIJPJSHDIADNYMP" diff --git a/advisories/unreviewed/2024/02/GHSA-pwjx-5gv5-6j26/GHSA-pwjx-5gv5-6j26.json b/advisories/unreviewed/2024/02/GHSA-pwjx-5gv5-6j26/GHSA-pwjx-5gv5-6j26.json new file mode 100644 index 00000000000..e277b8045bb --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-pwjx-5gv5-6j26/GHSA-pwjx-5gv5-6j26.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwjx-5gv5-6j26", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-24714" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in bPlugins LLC Icons Font Loader.This issue affects Icons Font Loader: from n/a through 1.1.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24714" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/icons-font-loader/wordpress-icons-font-loader-plugin-1-1-4-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-pwr2-4v36-6qpr/GHSA-pwr2-4v36-6qpr.json b/advisories/unreviewed/2024/02/GHSA-pwr2-4v36-6qpr/GHSA-pwr2-4v36-6qpr.json new file mode 100644 index 00000000000..b53a0d04ee6 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-pwr2-4v36-6qpr/GHSA-pwr2-4v36-6qpr.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwr2-4v36-6qpr", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-27454" + ], + "details": "orjson.loads in orjson before 3.9.15 does not limit recursion for deeply nested JSON documents.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27454" + }, + { + "type": "WEB", + "url": "https://github.com/ijl/orjson/issues/458" + }, + { + "type": "WEB", + "url": "https://github.com/ijl/orjson/commit/b0e4d2c06ce06c6e63981bf0276e4b7c74e5845e" + }, + { + "type": "WEB", + "url": "https://github.com/ijl/orjson/blob/master/CHANGELOG.md#3915" + }, + { + "type": "WEB", + "url": "https://monicz.dev/CVE-2024-27454" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:28:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-q52q-f54c-xmvp/GHSA-q52q-f54c-xmvp.json b/advisories/unreviewed/2024/02/GHSA-q52q-f54c-xmvp/GHSA-q52q-f54c-xmvp.json new file mode 100644 index 00000000000..ed559f7380d --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-q52q-f54c-xmvp/GHSA-q52q-f54c-xmvp.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q52q-f54c-xmvp", + "modified": "2024-02-26T18:30:28Z", + "published": "2024-02-26T18:30:28Z", + "aliases": [ + "CVE-2021-46905" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hso: fix NULL-deref on disconnect regression\n\nCommit 8a12f8836145 (\"net: hso: fix null-ptr-deref during tty device\nunregistration\") fixed the racy minor allocation reported by syzbot, but\nintroduced an unconditional NULL-pointer dereference on every disconnect\ninstead.\n\nSpecifically, the serial device table must no longer be accessed after\nthe minor has been released by hso_serial_tty_unregister().", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-46905" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0f000005da31f6947f843ce6b3e3a960540c6e00" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2ad5692db72874f02b9ad551d26345437ea4f7f3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/41c44e1f3112d7265dae522c026399b2a42d19ef" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5c17cfe155d21954b4c7e2a78fa771cebcd86725" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/90642ee9eb581a13569b1c0bd57e85d962215273" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d7fad2ce15bdbbd0fec3ebe999fd7cab2267f53e" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-q5mw-2cvx-mjj3/GHSA-q5mw-2cvx-mjj3.json b/advisories/unreviewed/2024/02/GHSA-q5mw-2cvx-mjj3/GHSA-q5mw-2cvx-mjj3.json new file mode 100644 index 00000000000..73185e3db42 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-q5mw-2cvx-mjj3/GHSA-q5mw-2cvx-mjj3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q5mw-2cvx-mjj3", + "modified": "2024-02-26T18:30:28Z", + "published": "2024-02-26T18:30:28Z", + "aliases": [ + "CVE-2023-38359" + ], + "details": "IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 260744.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38359" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/260744" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7123154" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-q8f8-rhx9-2qm4/GHSA-q8f8-rhx9-2qm4.json b/advisories/unreviewed/2024/02/GHSA-q8f8-rhx9-2qm4/GHSA-q8f8-rhx9-2qm4.json index 15321f4f07a..94307c1ef3d 100644 --- a/advisories/unreviewed/2024/02/GHSA-q8f8-rhx9-2qm4/GHSA-q8f8-rhx9-2qm4.json +++ b/advisories/unreviewed/2024/02/GHSA-q8f8-rhx9-2qm4/GHSA-q8f8-rhx9-2qm4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q8f8-rhx9-2qm4", - "modified": "2024-02-23T03:30:39Z", + "modified": "2024-02-26T18:30:28Z", "published": "2024-02-21T06:30:32Z", "aliases": [ "CVE-2024-1672" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://issues.chromium.org/issues/41485789" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PWWBMVQTSERVBXSXCZVUKIMEDNQUQ7O3" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QDCMYQ3J45NHQ4EJREM3BJNNKB5BK4Y7" diff --git a/advisories/unreviewed/2024/02/GHSA-q8hf-gfmq-m739/GHSA-q8hf-gfmq-m739.json b/advisories/unreviewed/2024/02/GHSA-q8hf-gfmq-m739/GHSA-q8hf-gfmq-m739.json new file mode 100644 index 00000000000..00a5fe5b685 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-q8hf-gfmq-m739/GHSA-q8hf-gfmq-m739.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8hf-gfmq-m739", + "modified": "2024-02-26T18:30:30Z", + "published": "2024-02-26T18:30:30Z", + "aliases": [ + "CVE-2024-1875" + ], + "details": "A vulnerability was found in SourceCodester Complaint Management System 1.0 and classified as critical. This issue affects some unknown processing of the file users/register-complaint.php of the component Lodge Complaint Section. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-254723.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1875" + }, + { + "type": "WEB", + "url": "https://toradah.notion.site/Remote-Code-Execution-RCE-via-Unrestricted-File-Upload-6ed7ae9c833c4d8baaae7d64ae0c4a47?pvs=4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.254723" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.254723" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-q98m-fjjg-rxw5/GHSA-q98m-fjjg-rxw5.json b/advisories/unreviewed/2024/02/GHSA-q98m-fjjg-rxw5/GHSA-q98m-fjjg-rxw5.json new file mode 100644 index 00000000000..1e20b85049c --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-q98m-fjjg-rxw5/GHSA-q98m-fjjg-rxw5.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q98m-fjjg-rxw5", + "modified": "2024-02-26T18:30:29Z", + "published": "2024-02-26T18:30:29Z", + "aliases": [ + "CVE-2023-52469" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrivers/amd/pm: fix a use-after-free in kv_parse_power_table\n\nWhen ps allocated by kzalloc equals to NULL, kv_parse_power_table\nfrees adev->pm.dpm.ps that allocated before. However, after the control\nflow goes through the following call chains:\n\nkv_parse_power_table\n |-> kv_dpm_init\n |-> kv_dpm_sw_init\n\t |-> kv_dpm_fini\n\nThe adev->pm.dpm.ps is used in the for loop of kv_dpm_fini after its\nfirst free in kv_parse_power_table and causes a use-after-free bug.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52469" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/28dd788382c43b330480f57cd34cde0840896743" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3426f059eacc33ecc676b0d66539297e1cfafd02" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/35fa2394d26e919f63600ce631e6aefc95ec2706" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/520e213a0b97b64735a13950e9371e0a5d7a5dc3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8a27d9d9fc9b5564b8904c3a77a7dea482bfa34e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8b55b06e737feb2a645b0293ea27e38418876d63" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/95084632a65d5c0d682a83b55935560bdcd2a1e3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b6dcba02ee178282e0d28684d241e0b8462dea6a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-qmvm-mg94-c39p/GHSA-qmvm-mg94-c39p.json b/advisories/unreviewed/2024/02/GHSA-qmvm-mg94-c39p/GHSA-qmvm-mg94-c39p.json new file mode 100644 index 00000000000..c037cd59981 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-qmvm-mg94-c39p/GHSA-qmvm-mg94-c39p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qmvm-mg94-c39p", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-27455" + ], + "details": "In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attempts to download files. This is fixed in Assetwise ALIM Web 23.00.02.03 and Assetwise Information Integrity Server 23.00.04.04.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27455" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/advisories/be-2024-0001" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:28:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-qpxm-689r-3849/GHSA-qpxm-689r-3849.json b/advisories/unreviewed/2024/02/GHSA-qpxm-689r-3849/GHSA-qpxm-689r-3849.json new file mode 100644 index 00000000000..a4f134bbb06 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-qpxm-689r-3849/GHSA-qpxm-689r-3849.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpxm-689r-3849", + "modified": "2024-02-26T18:30:30Z", + "published": "2024-02-26T18:30:30Z", + "aliases": [ + "CVE-2024-22371" + ], + "details": "Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel.This issue affects Apache Camel: from 3.21.X through 3.21.3, from 3.22.X through 3.22.0, from 4.0.X through 4.0.3, from 4.X through 4.3.0.\n\nUsers are recommended to upgrade to version 3.21.4, 3.22.1, 4.0.4 or 4.4.0, which fixes the issue.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22371" + }, + { + "type": "WEB", + "url": "https://camel.apache.org/security/CVE-2024-22371.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-r5qg-76hh-gr9p/GHSA-r5qg-76hh-gr9p.json b/advisories/unreviewed/2024/02/GHSA-r5qg-76hh-gr9p/GHSA-r5qg-76hh-gr9p.json index 834aeddaa83..a675a1e3bca 100644 --- a/advisories/unreviewed/2024/02/GHSA-r5qg-76hh-gr9p/GHSA-r5qg-76hh-gr9p.json +++ b/advisories/unreviewed/2024/02/GHSA-r5qg-76hh-gr9p/GHSA-r5qg-76hh-gr9p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r5qg-76hh-gr9p", - "modified": "2024-02-23T03:30:39Z", + "modified": "2024-02-26T18:30:28Z", "published": "2024-02-21T06:30:32Z", "aliases": [ "CVE-2024-1676" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://issues.chromium.org/issues/40944847" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PWWBMVQTSERVBXSXCZVUKIMEDNQUQ7O3" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QDCMYQ3J45NHQ4EJREM3BJNNKB5BK4Y7" diff --git a/advisories/unreviewed/2024/02/GHSA-r633-2867-crc8/GHSA-r633-2867-crc8.json b/advisories/unreviewed/2024/02/GHSA-r633-2867-crc8/GHSA-r633-2867-crc8.json new file mode 100644 index 00000000000..c5c709fa3bf --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-r633-2867-crc8/GHSA-r633-2867-crc8.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r633-2867-crc8", + "modified": "2024-02-26T18:30:28Z", + "published": "2024-02-26T18:30:28Z", + "aliases": [ + "CVE-2021-46904" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hso: fix null-ptr-deref during tty device unregistration\n\nMultiple ttys try to claim the same the minor number causing a double\nunregistration of the same device. The first unregistration succeeds\nbut the next one results in a null-ptr-deref.\n\nThe get_free_serial_index() function returns an available minor number\nbut doesn't assign it immediately. The assignment is done by the caller\nlater. But before this assignment, calls to get_free_serial_index()\nwould return the same minor number.\n\nFix this by modifying get_free_serial_index to assign the minor number\nimmediately after one is found to be and rename it to obtain_minor()\nto better reflect what it does. Similary, rename set_serial_by_index()\nto release_minor() and modify it to free up the minor number of the\ngiven hso_serial. Every obtain_minor() should have corresponding\nrelease_minor() call.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-46904" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/145c89c441d27696961752bf51b323f347601bee" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/388d05f70f1ee0cac4a2068fd295072f1a44152a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4a2933c88399c0ebc738db39bbce3ae89786d723" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8a12f8836145ffe37e9c8733dce18c22fb668b66" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/92028d7a31e55d53e41cff679156b9432cffcb36" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a462067d7c8e6953a733bf5ade8db947b1bb5449" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/caf5ac93b3b5d5fac032fc11fbea680e115421b4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dc195928d7e4ec7b5cfc6cd10dc4c8d87a7c72ac" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-rg89-92m2-5hj6/GHSA-rg89-92m2-5hj6.json b/advisories/unreviewed/2024/02/GHSA-rg89-92m2-5hj6/GHSA-rg89-92m2-5hj6.json new file mode 100644 index 00000000000..2b1e1e1ae9e --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-rg89-92m2-5hj6/GHSA-rg89-92m2-5hj6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rg89-92m2-5hj6", + "modified": "2024-02-26T18:30:29Z", + "published": "2024-02-26T18:30:29Z", + "aliases": [ + "CVE-2024-0798" + ], + "details": "A user with a `default` role given to them by the admin can sent `DELETE` HTTP requests to `remove-folder` and `remove-document` to delete folders and source files from the instance even when their role should explicitly not allow this action on the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0798" + }, + { + "type": "WEB", + "url": "https://github.com/mintplex-labs/anything-llm/commit/d5cde8b7c27a47ab45b05b441db16751537f1733" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/607f03a0-ab4d-4905-b253-3d28bbbd363c" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-272" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-rg8h-4g25-hj75/GHSA-rg8h-4g25-hj75.json b/advisories/unreviewed/2024/02/GHSA-rg8h-4g25-hj75/GHSA-rg8h-4g25-hj75.json new file mode 100644 index 00000000000..ee768b129dc --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-rg8h-4g25-hj75/GHSA-rg8h-4g25-hj75.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rg8h-4g25-hj75", + "modified": "2024-02-26T18:30:30Z", + "published": "2024-02-26T18:30:30Z", + "aliases": [ + "CVE-2024-1889" + ], + "details": "Cross-Site Request Forgery vulnerability in SMA Cluster Controller, affecting version 01.05.01.R. This vulnerability could allow an attacker to send a malicious link to an authenticated user to perform actions with these user permissions on the affected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1889" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-sma-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-rjx3-xwwm-jhj5/GHSA-rjx3-xwwm-jhj5.json b/advisories/unreviewed/2024/02/GHSA-rjx3-xwwm-jhj5/GHSA-rjx3-xwwm-jhj5.json new file mode 100644 index 00000000000..1aa948cb342 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-rjx3-xwwm-jhj5/GHSA-rjx3-xwwm-jhj5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rjx3-xwwm-jhj5", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-25081" + ], + "details": "Splinefont in FontForge through 20230101 allows command injection via crafted filenames.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25081" + }, + { + "type": "WEB", + "url": "https://github.com/fontforge/fontforge/pull/5367" + }, + { + "type": "WEB", + "url": "https://fontforge.org/en-US/downloads" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-v5qp-mx94-j49v/GHSA-v5qp-mx94-j49v.json b/advisories/unreviewed/2024/02/GHSA-v5qp-mx94-j49v/GHSA-v5qp-mx94-j49v.json index 8759a364782..7b839433bfb 100644 --- a/advisories/unreviewed/2024/02/GHSA-v5qp-mx94-j49v/GHSA-v5qp-mx94-j49v.json +++ b/advisories/unreviewed/2024/02/GHSA-v5qp-mx94-j49v/GHSA-v5qp-mx94-j49v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v5qp-mx94-j49v", - "modified": "2024-02-19T03:30:24Z", + "modified": "2024-02-26T18:30:28Z", "published": "2024-02-13T15:31:12Z", "aliases": [ "CVE-2023-5679" @@ -25,10 +25,18 @@ "type": "WEB", "url": "https://kb.isc.org/docs/cve-2023-5679" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HVRDSJVZKMCXKKPP6PNR62T7RWZ3YSDZ" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PNNHZSZPG2E7NBMBNYPGHCFI4V4XRWNQ" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RGS7JN6FZXUSTC2XKQHH27574XOULYYJ" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/02/13/1" diff --git a/advisories/unreviewed/2024/02/GHSA-v8r4-5m29-8242/GHSA-v8r4-5m29-8242.json b/advisories/unreviewed/2024/02/GHSA-v8r4-5m29-8242/GHSA-v8r4-5m29-8242.json new file mode 100644 index 00000000000..b785c76b40c --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-v8r4-5m29-8242/GHSA-v8r4-5m29-8242.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8r4-5m29-8242", + "modified": "2024-02-26T18:30:30Z", + "published": "2024-02-26T18:30:30Z", + "aliases": [ + "CVE-2024-1876" + ], + "details": "A vulnerability was found in SourceCodester Employee Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /psubmit.php. The manipulation of the argument pid with the input '+or+1%3d1%23 leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-254724.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1876" + }, + { + "type": "WEB", + "url": "https://github.com/skid-nochizplz/skid-nochizplz/blob/main/TrashBin/CVE/SOURCECODESTER%20EMPLOYEE%20MANAGEMENT%20SYSTEM/Employee%20Project%20SQL%20Injection%20Update.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.254724" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.254724" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-v8vj-cv27-hjv8/GHSA-v8vj-cv27-hjv8.json b/advisories/unreviewed/2024/02/GHSA-v8vj-cv27-hjv8/GHSA-v8vj-cv27-hjv8.json new file mode 100644 index 00000000000..a873004c54b --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-v8vj-cv27-hjv8/GHSA-v8vj-cv27-hjv8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8vj-cv27-hjv8", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-27444" + ], + "details": "langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-44467 fix and execute arbitrary code via the __import__, __subclasses__, __builtins__, __globals__, __getattribute__, __bases__, __mro__, or __base__ attribute in Python code. These are not prohibited by pal_chain/base.py.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27444" + }, + { + "type": "WEB", + "url": "https://github.com/langchain-ai/langchain/commit/de9a6cdf163ed00adaf2e559203ed0a9ca2f1de7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:28:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-vmr3-wr3f-xmpw/GHSA-vmr3-wr3f-xmpw.json b/advisories/unreviewed/2024/02/GHSA-vmr3-wr3f-xmpw/GHSA-vmr3-wr3f-xmpw.json new file mode 100644 index 00000000000..44fe327d6e1 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-vmr3-wr3f-xmpw/GHSA-vmr3-wr3f-xmpw.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vmr3-wr3f-xmpw", + "modified": "2024-02-26T18:30:29Z", + "published": "2024-02-26T18:30:29Z", + "aliases": [ + "CVE-2024-0439" + ], + "details": "As a manager, you should not be able to modify a series of settings. In the UI this is indeed hidden as a convenience for the role since most managers would not be savvy enough to modify these settings. They can use their token to still modify those settings though through a standard HTTP request\n\nWhile this is not a critical vulnerability, it does indeed need to be patched to enforce the expected permission level.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0439" + }, + { + "type": "WEB", + "url": "https://github.com/mintplex-labs/anything-llm/commit/7200a06ef07d92eef5f3c4c8be29824aa001d688" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/7fc1b78e-7faf-4f40-961d-61e53dac81ce" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-vqx3-p34h-gjh5/GHSA-vqx3-p34h-gjh5.json b/advisories/unreviewed/2024/02/GHSA-vqx3-p34h-gjh5/GHSA-vqx3-p34h-gjh5.json new file mode 100644 index 00000000000..699acf891d6 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-vqx3-p34h-gjh5/GHSA-vqx3-p34h-gjh5.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vqx3-p34h-gjh5", + "modified": "2024-02-26T18:30:29Z", + "published": "2024-02-26T18:30:29Z", + "aliases": [ + "CVE-2023-5775" + ], + "details": "The BackWPup plugin for WordPress is vulnerable to Plaintext Storage of Backup Destination Password in all versions up to, and including, 4.0.2. This is due to to the plugin improperly storing backup destination passwords in plaintext. This makes it possible for authenticated attackers, with administrator-level access, to retrieve the password from the password input field in the UI or from the options table where the password is stored.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5775" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3039678/backwpup" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4bce4f04-e622-468a-ac7e-5903ad50cc13?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-w4wv-vq5v-xp26/GHSA-w4wv-vq5v-xp26.json b/advisories/unreviewed/2024/02/GHSA-w4wv-vq5v-xp26/GHSA-w4wv-vq5v-xp26.json new file mode 100644 index 00000000000..2a2704862d7 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-w4wv-vq5v-xp26/GHSA-w4wv-vq5v-xp26.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4wv-vq5v-xp26", + "modified": "2024-02-26T18:30:30Z", + "published": "2024-02-26T18:30:30Z", + "aliases": [ + "CVE-2024-23496" + ], + "details": "A heap-based buffer overflow vulnerability exists in the GGUF library gguf_fread_str functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23496" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1913" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-w6r8-2m56-2cwg/GHSA-w6r8-2m56-2cwg.json b/advisories/unreviewed/2024/02/GHSA-w6r8-2m56-2cwg/GHSA-w6r8-2m56-2cwg.json new file mode 100644 index 00000000000..e6aa6e845e4 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-w6r8-2m56-2cwg/GHSA-w6r8-2m56-2cwg.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6r8-2m56-2cwg", + "modified": "2024-02-26T18:30:30Z", + "published": "2024-02-26T18:30:30Z", + "aliases": [ + "CVE-2024-1758" + ], + "details": "The SuperFaktura WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.40.3 via the wc_sf_url_check function. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1758" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/woocommerce-superfaktura/trunk/class-wc-superfaktura.php#L3418" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3040372%40woocommerce-superfaktura&new=3040372%40woocommerce-superfaktura&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/520598d7-863f-4bf3-ba74-fa9b2cc32767?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-w98j-8492-h547/GHSA-w98j-8492-h547.json b/advisories/unreviewed/2024/02/GHSA-w98j-8492-h547/GHSA-w98j-8492-h547.json new file mode 100644 index 00000000000..f66f0324642 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-w98j-8492-h547/GHSA-w98j-8492-h547.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w98j-8492-h547", + "modified": "2024-02-26T18:30:30Z", + "published": "2024-02-26T18:30:30Z", + "aliases": [ + "CVE-2024-1871" + ], + "details": "A vulnerability, which was classified as problematic, was found in SourceCodester Employee Management System 1.0. Affected is an unknown function of the file /process/assignp.php of the component Project Assignment Report. The manipulation of the argument pname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-254694 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1871" + }, + { + "type": "WEB", + "url": "https://github.com/skid-nochizplz/skid-nochizplz/blob/main/TrashBin/CVE/SOURCECODESTER%20EMPLOYEE%20MANAGEMENT%20SYSTEM/XSS%20Vulnerability%20in%20Project%20Assignment%20Report.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.254694" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.254694" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-wjv4-j3hc-gxvv/GHSA-wjv4-j3hc-gxvv.json b/advisories/unreviewed/2024/02/GHSA-wjv4-j3hc-gxvv/GHSA-wjv4-j3hc-gxvv.json index 813e0cd959a..2307bb9401e 100644 --- a/advisories/unreviewed/2024/02/GHSA-wjv4-j3hc-gxvv/GHSA-wjv4-j3hc-gxvv.json +++ b/advisories/unreviewed/2024/02/GHSA-wjv4-j3hc-gxvv/GHSA-wjv4-j3hc-gxvv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wjv4-j3hc-gxvv", - "modified": "2024-02-23T03:30:39Z", + "modified": "2024-02-26T18:30:28Z", "published": "2024-02-21T06:30:32Z", "aliases": [ "CVE-2024-1670" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://issues.chromium.org/issues/41481374" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PWWBMVQTSERVBXSXCZVUKIMEDNQUQ7O3" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QDCMYQ3J45NHQ4EJREM3BJNNKB5BK4Y7" diff --git a/advisories/unreviewed/2024/02/GHSA-wmmx-6x56-w87j/GHSA-wmmx-6x56-w87j.json b/advisories/unreviewed/2024/02/GHSA-wmmx-6x56-w87j/GHSA-wmmx-6x56-w87j.json new file mode 100644 index 00000000000..5e7cb30d7aa --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-wmmx-6x56-w87j/GHSA-wmmx-6x56-w87j.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmmx-6x56-w87j", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2020-36775" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to avoid potential deadlock\n\nUsing f2fs_trylock_op() in f2fs_write_compressed_pages() to avoid potential\ndeadlock like we did in f2fs_write_single_data_page().", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-36775" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0478ccdc8ea016de1ebaf6fe6da0275c2b258c5b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8e8542437bb4070423c9754d5ba270ffdbae8c8d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/df77fbd8c5b222c680444801ffd20e8bbc90a56e" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-x57x-3c65-5f3j/GHSA-x57x-3c65-5f3j.json b/advisories/unreviewed/2024/02/GHSA-x57x-3c65-5f3j/GHSA-x57x-3c65-5f3j.json index c7b7bba4811..8806e1aed66 100644 --- a/advisories/unreviewed/2024/02/GHSA-x57x-3c65-5f3j/GHSA-x57x-3c65-5f3j.json +++ b/advisories/unreviewed/2024/02/GHSA-x57x-3c65-5f3j/GHSA-x57x-3c65-5f3j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x57x-3c65-5f3j", - "modified": "2024-02-19T03:30:24Z", + "modified": "2024-02-26T18:30:27Z", "published": "2024-02-13T15:31:12Z", "aliases": [ "CVE-2023-4408" @@ -25,10 +25,18 @@ "type": "WEB", "url": "https://kb.isc.org/docs/cve-2023-4408" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HVRDSJVZKMCXKKPP6PNR62T7RWZ3YSDZ" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PNNHZSZPG2E7NBMBNYPGHCFI4V4XRWNQ" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RGS7JN6FZXUSTC2XKQHH27574XOULYYJ" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/02/13/1" diff --git a/advisories/unreviewed/2024/02/GHSA-xcvq-77qq-2wpx/GHSA-xcvq-77qq-2wpx.json b/advisories/unreviewed/2024/02/GHSA-xcvq-77qq-2wpx/GHSA-xcvq-77qq-2wpx.json index 979fbf01412..1b7acdf99af 100644 --- a/advisories/unreviewed/2024/02/GHSA-xcvq-77qq-2wpx/GHSA-xcvq-77qq-2wpx.json +++ b/advisories/unreviewed/2024/02/GHSA-xcvq-77qq-2wpx/GHSA-xcvq-77qq-2wpx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xcvq-77qq-2wpx", - "modified": "2024-02-19T03:30:24Z", + "modified": "2024-02-26T18:30:27Z", "published": "2024-02-13T15:31:12Z", "aliases": [ "CVE-2023-5517" @@ -25,10 +25,18 @@ "type": "WEB", "url": "https://kb.isc.org/docs/cve-2023-5517" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HVRDSJVZKMCXKKPP6PNR62T7RWZ3YSDZ" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PNNHZSZPG2E7NBMBNYPGHCFI4V4XRWNQ" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RGS7JN6FZXUSTC2XKQHH27574XOULYYJ" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/02/13/1" diff --git a/advisories/unreviewed/2024/02/GHSA-xf63-228h-qhch/GHSA-xf63-228h-qhch.json b/advisories/unreviewed/2024/02/GHSA-xf63-228h-qhch/GHSA-xf63-228h-qhch.json new file mode 100644 index 00000000000..932e4bef712 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-xf63-228h-qhch/GHSA-xf63-228h-qhch.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xf63-228h-qhch", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-26604" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRevert \"kobject: Remove redundant checks for whether ktype is NULL\"\n\nThis reverts commit 1b28cb81dab7c1eedc6034206f4e8d644046ad31.\n\nIt is reported to cause problems, so revert it for now until the root\ncause can be found.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26604" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3ca8fbabcceb8bfe44f7f50640092fd8f1de375c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7f414d306320f837cc3df96cf52161cb8290fb1b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b746d52ce7bcac325a2fa264216ead85b7fbbfaa" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:28:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-xx6x-c9h6-h6fv/GHSA-xx6x-c9h6-h6fv.json b/advisories/unreviewed/2024/02/GHSA-xx6x-c9h6-h6fv/GHSA-xx6x-c9h6-h6fv.json new file mode 100644 index 00000000000..65727e6c5cf --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-xx6x-c9h6-h6fv/GHSA-xx6x-c9h6-h6fv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xx6x-c9h6-h6fv", + "modified": "2024-02-26T18:30:31Z", + "published": "2024-02-26T18:30:31Z", + "aliases": [ + "CVE-2024-26465" + ], + "details": "A DOM based cross-site scripting (XSS) vulnerability in the component /beep/Beep.Instrument.js of stewdio beep.js before commit ef22ad7 allows attackers to execute arbitrary Javascript via sending a crafted URL.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26465" + }, + { + "type": "WEB", + "url": "https://gist.github.com/cd80/89527424f733b2b82de876e02d163150" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-26T16:27:59Z" + } +} \ No newline at end of file