Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-11-06 21:32:07 +00:00
parent a96d66c373
commit 7f2cf9283b
51 changed files with 341 additions and 126 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jpxc-vmjf-9fcj",
"modified": "2024-09-16T22:55:00Z",
"modified": "2024-11-06T21:30:54Z",
"published": "2024-09-16T14:37:26Z",
"aliases": [
"CVE-2024-8775"
@@ -44,6 +44,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8775"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:8969"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-8775"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-586p-749j-fhwp",
"modified": "2024-11-06T12:31:32Z",
"modified": "2024-11-06T21:30:54Z",
"published": "2024-10-09T15:32:21Z",
"aliases": [
"CVE-2024-9675"
@@ -64,6 +64,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:8686"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:8690"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:8703"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mc76-5925-c5p6",
"modified": "2024-11-05T09:30:36Z",
"modified": "2024-11-06T21:30:54Z",
"published": "2024-10-01T21:31:34Z",
"aliases": [
"CVE-2024-9341"
@@ -72,6 +72,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:8428"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:8690"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:8846"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-32p4-gm2c-wmch",
"modified": "2024-11-06T15:37:19Z",
"modified": "2024-11-06T21:30:55Z",
"published": "2024-11-06T12:31:32Z",
"aliases": [
"CVE-2024-9902"
@@ -140,6 +140,10 @@
"type": "WEB",
"url": "https://github.com/ansible/ansible/commit/f7be90626da3035c697623dcf9c90b7a0bc91c92"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:8969"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-9902"
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-863"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -36,7 +36,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-922"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -32,6 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-273",
"CWE-754"
],
"severity": "LOW",
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": "LOW",
"github_reviewed": false,
@@ -40,7 +40,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2c83-rhjj-cjg4",
"modified": "2024-02-16T00:30:28Z",
"modified": "2024-11-06T21:30:53Z",
"published": "2024-02-16T00:30:28Z",
"aliases": [
"CVE-2024-23674"
],
"details": "The Online-Ausweis-Funktion eID scheme in the German National Identity card through 2024-02-15 allows authentication bypass by spoofing. A man-in-the-middle attacker can assume a victim's identify for access to government, medical, and financial resources, and can also extract personal data from the card, aka the \"sPACE (Spoofing Password Authenticated Connection Establishment)\" issue. This occurs because of a combination of factors, such as insecure PIN entry (for basic readers) and eid:// deeplinking. The victim must be using a modified eID kernel, which may occur if the victim is tricked into installing a fake version of an official app. NOTE: the BSI position is \"ensuring a secure operational environment at the client side is an obligation of the ID card owner.\"",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
}
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-290"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-15T23:15:08Z"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-404"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vr4j-34fw-6v8v",
"modified": "2024-02-16T03:30:51Z",
"modified": "2024-11-06T21:30:53Z",
"published": "2024-02-16T03:30:51Z",
"aliases": [
"CVE-2024-0030"
],
"details": "In btif_to_bta_response of btif_gatt_util.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-125"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-16T02:15:50Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6hr8-534p-8986",
"modified": "2024-06-26T00:31:35Z",
"modified": "2024-11-06T21:30:53Z",
"published": "2024-03-11T18:31:09Z",
"aliases": [
"CVE-2023-52492"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: fix NULL pointer in channel unregistration function\n\n__dma_async_device_channel_register() can fail. In case of failure,\nchan->local is freed (with free_percpu()), and chan->local is nullified.\nWhen dma_async_device_unregister() is called (because of managed API or\nintentionally by DMA controller driver), channels are unconditionally\nunregistered, leading to this NULL pointer:\n[ 1.318693] Unable to handle kernel NULL pointer dereference at virtual address 00000000000000d0\n[...]\n[ 1.484499] Call trace:\n[ 1.486930] device_del+0x40/0x394\n[ 1.490314] device_unregister+0x20/0x7c\n[ 1.494220] __dma_async_device_channel_unregister+0x68/0xc0\n\nLook at dma_async_device_register() function error path, channel device\nunregistration is done only if chan->local is not NULL.\n\nThen add the same condition at the beginning of\n__dma_async_device_channel_unregister() function, to avoid NULL pointer\nissue whatever the API used to reach this function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -49,9 +52,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-476"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-11T18:15:16Z"
@@ -25,7 +25,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-276"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9mq8-5h36-frr5",
"modified": "2024-06-27T12:30:44Z",
"modified": "2024-11-06T21:30:54Z",
"published": "2024-03-21T12:31:56Z",
"aliases": [
"CVE-2023-52620"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: disallow timeout for anonymous sets\n\nNever used from userspace, disallow these parameters.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
}
],
"affected": [
@@ -55,7 +58,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-21T11:15:28Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9prw-2r97-97f6",
"modified": "2024-03-03T00:30:31Z",
"modified": "2024-11-06T21:30:53Z",
"published": "2024-03-03T00:30:31Z",
"aliases": [
"CVE-2023-52511"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: sun6i: reduce DMA RX transfer width to single byte\n\nThrough empirical testing it has been determined that sometimes RX SPI\ntransfers with DMA enabled return corrupted data. This is down to single\nor even multiple bytes lost during DMA transfer from SPI peripheral to\nmemory. It seems the RX FIFO within the SPI peripheral can become\nconfused when performing bus read accesses wider than a single byte to it\nduring an active SPI transfer.\n\nThis patch reduces the width of individual DMA read accesses to the\nRX FIFO to a single byte to mitigate that issue.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
}
],
"affected": [
@@ -39,7 +42,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-02T22:15:47Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cpxg-8g4c-4mhp",
"modified": "2024-03-11T21:31:24Z",
"modified": "2024-11-06T21:30:53Z",
"published": "2024-03-11T21:31:24Z",
"aliases": [
"CVE-2024-22006"
],
"details": "Android kernel allows Information disclosure.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-11T19:15:47Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f4j7-jf79-wp46",
"modified": "2024-03-16T00:30:32Z",
"modified": "2024-11-06T21:30:53Z",
"published": "2024-03-16T00:30:32Z",
"aliases": [
"CVE-2024-23298"
],
"details": "A logic issue was addressed with improved state management.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-15T23:15:07Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f8jx-pmvg-jgfh",
"modified": "2024-03-03T00:30:32Z",
"modified": "2024-11-06T21:30:53Z",
"published": "2024-03-03T00:30:32Z",
"aliases": [
"CVE-2023-52522"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix possible store tearing in neigh_periodic_work()\n\nWhile looking at a related syzbot report involving neigh_periodic_work(),\nI found that I forgot to add an annotation when deleting an\nRCU protected item from a list.\n\nReaders use rcu_deference(*np), we need to use either\nrcu_assign_pointer() or WRITE_ONCE() on writer side\nto prevent store tearing.\n\nI use rcu_assign_pointer() to have lockdep support,\nthis was the choice made in neigh_flush_dev().",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -47,7 +50,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-02T22:15:48Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wf6g-6473-wm39",
"modified": "2024-03-02T00:31:31Z",
"modified": "2024-11-06T21:30:53Z",
"published": "2024-03-02T00:31:31Z",
"aliases": [
"CVE-2023-49539"
],
"details": "Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/category. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the category parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-01T22:15:47Z"

Some files were not shown because too many files have changed in this diff Show More