From 7fc539afcbfbbef7777c073b140e5100ebbc3550 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 16 Aug 2024 15:32:47 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-9cp8-pr92-vg9q.json | 3 +- .../GHSA-xhxm-p3qv-qprc.json | 9 ++-- .../GHSA-2c9f-7jg2-vp9c.json | 9 ++-- .../GHSA-m35v-jxg3-p887.json | 9 ++-- .../GHSA-qcq9-h9hg-5pq2.json | 9 ++-- .../GHSA-25rw-wcg9-79jh.json | 38 +++++++++++++++ .../GHSA-33vq-3m9c-jf8p.json | 38 +++++++++++++++ .../GHSA-3p4h-pcqj-f7fx.json | 11 +++-- .../GHSA-52g6-2pfv-hfcq.json | 38 +++++++++++++++ .../GHSA-54xp-779j-4c34.json | 1 + .../GHSA-58p8-qp66-2jq2.json | 42 +++++++++++++++++ .../GHSA-5cv5-pc9w-5hgp.json | 38 +++++++++++++++ .../GHSA-5jw4-r8w6-r7mq.json | 42 +++++++++++++++++ .../GHSA-5wq9-96x8-3hq5.json | 11 +++-- .../GHSA-6cg9-52c8-r76r.json | 9 ++-- .../GHSA-6g7p-7w92-r3v3.json | 3 +- .../GHSA-6pr8-g9pq-xmj3.json | 11 +++-- .../GHSA-75q5-8jhm-6829.json | 38 +++++++++++++++ .../GHSA-7h3f-p2xx-rhqq.json | 38 +++++++++++++++ .../GHSA-9xhm-rcrp-wq9j.json | 38 +++++++++++++++ .../GHSA-c75r-v5wg-3gmj.json | 11 +++-- .../GHSA-c856-w373-jm6c.json | 38 +++++++++++++++ .../GHSA-cprr-85rg-mjvr.json | 11 +++-- .../GHSA-f994-q776-gghm.json | 11 +++-- .../GHSA-fhxh-jfcp-fmv9.json | 38 +++++++++++++++ .../GHSA-fj4q-r9h6-xhrg.json | 9 ++-- .../GHSA-g8gg-jvrh-m6c2.json | 11 +++-- .../GHSA-gh9v-q4wx-5m5c.json | 3 +- .../GHSA-h44r-v8c9-8pmx.json | 38 +++++++++++++++ .../GHSA-h7cf-jrwx-94cj.json | 12 +++-- .../GHSA-mccv-36h3-rfv5.json | 11 +++-- .../GHSA-mcqx-pmh8-v9cr.json | 9 ++-- .../GHSA-mqj4-jxhw-766g.json | 38 +++++++++++++++ .../GHSA-p332-vhv3-xv9m.json | 9 ++-- .../GHSA-p3f9-2qr4-24wj.json | 38 +++++++++++++++ .../GHSA-p736-fp6q-qr5j.json | 6 ++- .../GHSA-p8f2-24c3-9gc6.json | 38 +++++++++++++++ .../GHSA-q967-hxp7-f2rc.json | 11 +++-- .../GHSA-qffp-wwcx-j425.json | 11 +++-- .../GHSA-qm84-v26j-7pch.json | 6 ++- .../GHSA-v2r6-5xjh-fr9c.json | 38 +++++++++++++++ .../GHSA-w2rc-qg2j-54hv.json | 46 +++++++++++++++++++ .../GHSA-w2ww-w274-8rxv.json | 38 +++++++++++++++ .../GHSA-w9fr-xv2x-w94q.json | 1 + .../GHSA-wm2h-r2j5-8pjc.json | 38 +++++++++++++++ .../GHSA-wxwq-v4jc-6x96.json | 9 ++-- .../GHSA-xw3h-6c4j-mqhw.json | 11 +++-- .../GHSA-xx3f-44rh-4g76.json | 6 ++- 48 files changed, 900 insertions(+), 81 deletions(-) create mode 100644 advisories/unreviewed/2024/08/GHSA-25rw-wcg9-79jh/GHSA-25rw-wcg9-79jh.json create mode 100644 advisories/unreviewed/2024/08/GHSA-33vq-3m9c-jf8p/GHSA-33vq-3m9c-jf8p.json create mode 100644 advisories/unreviewed/2024/08/GHSA-52g6-2pfv-hfcq/GHSA-52g6-2pfv-hfcq.json create mode 100644 advisories/unreviewed/2024/08/GHSA-58p8-qp66-2jq2/GHSA-58p8-qp66-2jq2.json create mode 100644 advisories/unreviewed/2024/08/GHSA-5cv5-pc9w-5hgp/GHSA-5cv5-pc9w-5hgp.json create mode 100644 advisories/unreviewed/2024/08/GHSA-5jw4-r8w6-r7mq/GHSA-5jw4-r8w6-r7mq.json create mode 100644 advisories/unreviewed/2024/08/GHSA-75q5-8jhm-6829/GHSA-75q5-8jhm-6829.json create mode 100644 advisories/unreviewed/2024/08/GHSA-7h3f-p2xx-rhqq/GHSA-7h3f-p2xx-rhqq.json create mode 100644 advisories/unreviewed/2024/08/GHSA-9xhm-rcrp-wq9j/GHSA-9xhm-rcrp-wq9j.json create mode 100644 advisories/unreviewed/2024/08/GHSA-c856-w373-jm6c/GHSA-c856-w373-jm6c.json create mode 100644 advisories/unreviewed/2024/08/GHSA-fhxh-jfcp-fmv9/GHSA-fhxh-jfcp-fmv9.json create mode 100644 advisories/unreviewed/2024/08/GHSA-h44r-v8c9-8pmx/GHSA-h44r-v8c9-8pmx.json create mode 100644 advisories/unreviewed/2024/08/GHSA-mqj4-jxhw-766g/GHSA-mqj4-jxhw-766g.json create mode 100644 advisories/unreviewed/2024/08/GHSA-p3f9-2qr4-24wj/GHSA-p3f9-2qr4-24wj.json create mode 100644 advisories/unreviewed/2024/08/GHSA-p8f2-24c3-9gc6/GHSA-p8f2-24c3-9gc6.json create mode 100644 advisories/unreviewed/2024/08/GHSA-v2r6-5xjh-fr9c/GHSA-v2r6-5xjh-fr9c.json create mode 100644 advisories/unreviewed/2024/08/GHSA-w2rc-qg2j-54hv/GHSA-w2rc-qg2j-54hv.json create mode 100644 advisories/unreviewed/2024/08/GHSA-w2ww-w274-8rxv/GHSA-w2ww-w274-8rxv.json create mode 100644 advisories/unreviewed/2024/08/GHSA-wm2h-r2j5-8pjc/GHSA-wm2h-r2j5-8pjc.json diff --git a/advisories/unreviewed/2024/06/GHSA-9cp8-pr92-vg9q/GHSA-9cp8-pr92-vg9q.json b/advisories/unreviewed/2024/06/GHSA-9cp8-pr92-vg9q/GHSA-9cp8-pr92-vg9q.json index 2592897663c..1d74b2ea65b 100644 --- a/advisories/unreviewed/2024/06/GHSA-9cp8-pr92-vg9q/GHSA-9cp8-pr92-vg9q.json +++ b/advisories/unreviewed/2024/06/GHSA-9cp8-pr92-vg9q/GHSA-9cp8-pr92-vg9q.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-xhxm-p3qv-qprc/GHSA-xhxm-p3qv-qprc.json b/advisories/unreviewed/2024/06/GHSA-xhxm-p3qv-qprc/GHSA-xhxm-p3qv-qprc.json index d435a8624f3..5ac33d81aa0 100644 --- a/advisories/unreviewed/2024/06/GHSA-xhxm-p3qv-qprc/GHSA-xhxm-p3qv-qprc.json +++ b/advisories/unreviewed/2024/06/GHSA-xhxm-p3qv-qprc/GHSA-xhxm-p3qv-qprc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xhxm-p3qv-qprc", - "modified": "2024-06-19T12:31:21Z", + "modified": "2024-08-16T15:31:40Z", "published": "2024-06-11T15:31:13Z", "aliases": [ "CVE-2024-5691" ], "details": "By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions to open a new window. This vulnerability affects Firefox < 127 and Firefox ESR < 115.12.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-11T13:15:50Z" diff --git a/advisories/unreviewed/2024/07/GHSA-2c9f-7jg2-vp9c/GHSA-2c9f-7jg2-vp9c.json b/advisories/unreviewed/2024/07/GHSA-2c9f-7jg2-vp9c/GHSA-2c9f-7jg2-vp9c.json index 5d683cebec4..3a9d940d5d0 100644 --- a/advisories/unreviewed/2024/07/GHSA-2c9f-7jg2-vp9c/GHSA-2c9f-7jg2-vp9c.json +++ b/advisories/unreviewed/2024/07/GHSA-2c9f-7jg2-vp9c/GHSA-2c9f-7jg2-vp9c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2c9f-7jg2-vp9c", - "modified": "2024-07-09T18:30:49Z", + "modified": "2024-08-16T15:31:40Z", "published": "2024-07-09T18:30:49Z", "aliases": [ "CVE-2024-21729" ], "details": "Inadequate input validation leads to XSS vulnerabilities in the accessiblemedia field.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-09T17:15:14Z" diff --git a/advisories/unreviewed/2024/07/GHSA-m35v-jxg3-p887/GHSA-m35v-jxg3-p887.json b/advisories/unreviewed/2024/07/GHSA-m35v-jxg3-p887/GHSA-m35v-jxg3-p887.json index ec10349610a..d004cce3fc5 100644 --- a/advisories/unreviewed/2024/07/GHSA-m35v-jxg3-p887/GHSA-m35v-jxg3-p887.json +++ b/advisories/unreviewed/2024/07/GHSA-m35v-jxg3-p887/GHSA-m35v-jxg3-p887.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m35v-jxg3-p887", - "modified": "2024-07-09T18:30:49Z", + "modified": "2024-08-16T15:31:40Z", "published": "2024-07-09T18:30:49Z", "aliases": [ "CVE-2024-21731" ], "details": "Improper handling of input could lead to an XSS vector in the StringHelper::truncate method.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-09T17:15:14Z" diff --git a/advisories/unreviewed/2024/07/GHSA-qcq9-h9hg-5pq2/GHSA-qcq9-h9hg-5pq2.json b/advisories/unreviewed/2024/07/GHSA-qcq9-h9hg-5pq2/GHSA-qcq9-h9hg-5pq2.json index 4d04df2c55c..b08b3620794 100644 --- a/advisories/unreviewed/2024/07/GHSA-qcq9-h9hg-5pq2/GHSA-qcq9-h9hg-5pq2.json +++ b/advisories/unreviewed/2024/07/GHSA-qcq9-h9hg-5pq2/GHSA-qcq9-h9hg-5pq2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qcq9-h9hg-5pq2", - "modified": "2024-07-09T18:30:49Z", + "modified": "2024-08-16T15:31:40Z", "published": "2024-07-09T18:30:49Z", "aliases": [ "CVE-2024-21730" ], "details": "The fancyselect list field layout does not correctly escape inputs, leading to a self-XSS vector.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-09T17:15:14Z" diff --git a/advisories/unreviewed/2024/08/GHSA-25rw-wcg9-79jh/GHSA-25rw-wcg9-79jh.json b/advisories/unreviewed/2024/08/GHSA-25rw-wcg9-79jh/GHSA-25rw-wcg9-79jh.json new file mode 100644 index 00000000000..be5600a9e5f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-25rw-wcg9-79jh/GHSA-25rw-wcg9-79jh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25rw-wcg9-79jh", + "modified": "2024-08-16T15:31:42Z", + "published": "2024-08-16T15:31:42Z", + "aliases": [ + "CVE-2024-43808" + ], + "details": "In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43808" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-33vq-3m9c-jf8p/GHSA-33vq-3m9c-jf8p.json b/advisories/unreviewed/2024/08/GHSA-33vq-3m9c-jf8p/GHSA-33vq-3m9c-jf8p.json new file mode 100644 index 00000000000..195a69f10f8 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-33vq-3m9c-jf8p/GHSA-33vq-3m9c-jf8p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33vq-3m9c-jf8p", + "modified": "2024-08-16T15:31:42Z", + "published": "2024-08-16T15:31:42Z", + "aliases": [ + "CVE-2024-6004" + ], + "details": "A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to deny printer connections until the system is rebooted.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6004" + }, + { + "type": "WEB", + "url": "https://iknow.lenovo.com.cn/detail/422688" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T15:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3p4h-pcqj-f7fx/GHSA-3p4h-pcqj-f7fx.json b/advisories/unreviewed/2024/08/GHSA-3p4h-pcqj-f7fx/GHSA-3p4h-pcqj-f7fx.json index afa20714333..b63986e7930 100644 --- a/advisories/unreviewed/2024/08/GHSA-3p4h-pcqj-f7fx/GHSA-3p4h-pcqj-f7fx.json +++ b/advisories/unreviewed/2024/08/GHSA-3p4h-pcqj-f7fx/GHSA-3p4h-pcqj-f7fx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3p4h-pcqj-f7fx", - "modified": "2024-08-15T18:31:52Z", + "modified": "2024-08-16T15:31:41Z", "published": "2024-08-15T18:31:52Z", "aliases": [ "CVE-2024-42987" ], "details": "Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the modino parameter in the fromPptpUserAdd function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:21Z" diff --git a/advisories/unreviewed/2024/08/GHSA-52g6-2pfv-hfcq/GHSA-52g6-2pfv-hfcq.json b/advisories/unreviewed/2024/08/GHSA-52g6-2pfv-hfcq/GHSA-52g6-2pfv-hfcq.json new file mode 100644 index 00000000000..264284deb0e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-52g6-2pfv-hfcq/GHSA-52g6-2pfv-hfcq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52g6-2pfv-hfcq", + "modified": "2024-08-16T15:31:41Z", + "published": "2024-08-16T15:31:41Z", + "aliases": [ + "CVE-2024-42465" + ], + "details": "Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Abuse.This issue affects upKeeper Manager: through 5.1.9.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42465" + }, + { + "type": "WEB", + "url": "https://support.upkeeper.se/hc/en-us/articles/15432332385564-CVE-2024-42465-Lack-of-resources-and-rate-limiting-two-factor-authentication" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-54xp-779j-4c34/GHSA-54xp-779j-4c34.json b/advisories/unreviewed/2024/08/GHSA-54xp-779j-4c34/GHSA-54xp-779j-4c34.json index 6a19d6d4338..dea746a6896 100644 --- a/advisories/unreviewed/2024/08/GHSA-54xp-779j-4c34/GHSA-54xp-779j-4c34.json +++ b/advisories/unreviewed/2024/08/GHSA-54xp-779j-4c34/GHSA-54xp-779j-4c34.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-416" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-58p8-qp66-2jq2/GHSA-58p8-qp66-2jq2.json b/advisories/unreviewed/2024/08/GHSA-58p8-qp66-2jq2/GHSA-58p8-qp66-2jq2.json new file mode 100644 index 00000000000..b6c954e7060 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-58p8-qp66-2jq2/GHSA-58p8-qp66-2jq2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58p8-qp66-2jq2", + "modified": "2024-08-16T15:31:41Z", + "published": "2024-08-16T15:31:41Z", + "aliases": [ + "CVE-2024-7145" + ], + "details": "The JetElements plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.6.20 via the 'progress_type' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7145" + }, + { + "type": "WEB", + "url": "https://crocoblock.com/plugins/jetelements" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/793f27ec-a3bb-4273-a41c-cc5b04c8e8fc?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5cv5-pc9w-5hgp/GHSA-5cv5-pc9w-5hgp.json b/advisories/unreviewed/2024/08/GHSA-5cv5-pc9w-5hgp/GHSA-5cv5-pc9w-5hgp.json new file mode 100644 index 00000000000..e478b6a946a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5cv5-pc9w-5hgp/GHSA-5cv5-pc9w-5hgp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5cv5-pc9w-5hgp", + "modified": "2024-08-16T15:31:42Z", + "published": "2024-08-16T15:31:42Z", + "aliases": [ + "CVE-2024-4763" + ], + "details": "An insecure driver vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM)\n\n that could allow a local attacker to escalate privileges to kernel.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4763" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-155486" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T15:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5jw4-r8w6-r7mq/GHSA-5jw4-r8w6-r7mq.json b/advisories/unreviewed/2024/08/GHSA-5jw4-r8w6-r7mq/GHSA-5jw4-r8w6-r7mq.json new file mode 100644 index 00000000000..6828471430d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5jw4-r8w6-r7mq/GHSA-5jw4-r8w6-r7mq.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5jw4-r8w6-r7mq", + "modified": "2024-08-16T15:31:41Z", + "published": "2024-08-16T15:31:41Z", + "aliases": [ + "CVE-2024-7144" + ], + "details": "The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and 'slide_id' parameters in all versions up to, and including, 2.6.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7144" + }, + { + "type": "WEB", + "url": "https://crocoblock.com/plugins/jetelements" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c5e64adf-49b3-4e85-8dc1-918f7e92965b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5wq9-96x8-3hq5/GHSA-5wq9-96x8-3hq5.json b/advisories/unreviewed/2024/08/GHSA-5wq9-96x8-3hq5/GHSA-5wq9-96x8-3hq5.json index b66f1aa45c5..93322540771 100644 --- a/advisories/unreviewed/2024/08/GHSA-5wq9-96x8-3hq5/GHSA-5wq9-96x8-3hq5.json +++ b/advisories/unreviewed/2024/08/GHSA-5wq9-96x8-3hq5/GHSA-5wq9-96x8-3hq5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5wq9-96x8-3hq5", - "modified": "2024-08-15T18:31:52Z", + "modified": "2024-08-16T15:31:41Z", "published": "2024-08-15T18:31:52Z", "aliases": [ "CVE-2024-42981" ], "details": "Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the delno parameter in the fromPptpUserSetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:21Z" diff --git a/advisories/unreviewed/2024/08/GHSA-6cg9-52c8-r76r/GHSA-6cg9-52c8-r76r.json b/advisories/unreviewed/2024/08/GHSA-6cg9-52c8-r76r/GHSA-6cg9-52c8-r76r.json index 8db7011bee4..6d144847982 100644 --- a/advisories/unreviewed/2024/08/GHSA-6cg9-52c8-r76r/GHSA-6cg9-52c8-r76r.json +++ b/advisories/unreviewed/2024/08/GHSA-6cg9-52c8-r76r/GHSA-6cg9-52c8-r76r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6cg9-52c8-r76r", - "modified": "2024-08-15T18:31:51Z", + "modified": "2024-08-16T15:31:41Z", "published": "2024-08-15T18:31:51Z", "aliases": [ "CVE-2024-42967" ], "details": "Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:20Z" diff --git a/advisories/unreviewed/2024/08/GHSA-6g7p-7w92-r3v3/GHSA-6g7p-7w92-r3v3.json b/advisories/unreviewed/2024/08/GHSA-6g7p-7w92-r3v3/GHSA-6g7p-7w92-r3v3.json index 1931f660c80..e92a823094a 100644 --- a/advisories/unreviewed/2024/08/GHSA-6g7p-7w92-r3v3/GHSA-6g7p-7w92-r3v3.json +++ b/advisories/unreviewed/2024/08/GHSA-6g7p-7w92-r3v3/GHSA-6g7p-7w92-r3v3.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-259" + "CWE-259", + "CWE-798" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-6pr8-g9pq-xmj3/GHSA-6pr8-g9pq-xmj3.json b/advisories/unreviewed/2024/08/GHSA-6pr8-g9pq-xmj3/GHSA-6pr8-g9pq-xmj3.json index ad3275b05c9..ed59278735d 100644 --- a/advisories/unreviewed/2024/08/GHSA-6pr8-g9pq-xmj3/GHSA-6pr8-g9pq-xmj3.json +++ b/advisories/unreviewed/2024/08/GHSA-6pr8-g9pq-xmj3/GHSA-6pr8-g9pq-xmj3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6pr8-g9pq-xmj3", - "modified": "2024-08-15T18:31:51Z", + "modified": "2024-08-16T15:31:41Z", "published": "2024-08-15T18:31:51Z", "aliases": [ "CVE-2024-42969" ], "details": "Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSafeUrlFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:20Z" diff --git a/advisories/unreviewed/2024/08/GHSA-75q5-8jhm-6829/GHSA-75q5-8jhm-6829.json b/advisories/unreviewed/2024/08/GHSA-75q5-8jhm-6829/GHSA-75q5-8jhm-6829.json new file mode 100644 index 00000000000..d6b2b70582b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-75q5-8jhm-6829/GHSA-75q5-8jhm-6829.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75q5-8jhm-6829", + "modified": "2024-08-16T15:31:41Z", + "published": "2024-08-16T15:31:41Z", + "aliases": [ + "CVE-2024-42464" + ], + "details": "Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Utilizing REST's Trust in the System Resource to Obtain Sensitive Data.This issue affects upKeeper Manager: through 5.1.9.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42464" + }, + { + "type": "WEB", + "url": "https://support.upkeeper.se/hc/en-us/articles/15432275702044-CVE-2024-42464-Leak-of-user-Information" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7h3f-p2xx-rhqq/GHSA-7h3f-p2xx-rhqq.json b/advisories/unreviewed/2024/08/GHSA-7h3f-p2xx-rhqq/GHSA-7h3f-p2xx-rhqq.json new file mode 100644 index 00000000000..d78e26c8570 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7h3f-p2xx-rhqq/GHSA-7h3f-p2xx-rhqq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7h3f-p2xx-rhqq", + "modified": "2024-08-16T15:31:42Z", + "published": "2024-08-16T15:31:42Z", + "aliases": [ + "CVE-2024-5210" + ], + "details": "A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to prevent printer services from being reachable until the system is rebooted.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5210" + }, + { + "type": "WEB", + "url": "https://iknow.lenovo.com.cn/detail/422688" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T15:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9xhm-rcrp-wq9j/GHSA-9xhm-rcrp-wq9j.json b/advisories/unreviewed/2024/08/GHSA-9xhm-rcrp-wq9j/GHSA-9xhm-rcrp-wq9j.json new file mode 100644 index 00000000000..83a148721bd --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9xhm-rcrp-wq9j/GHSA-9xhm-rcrp-wq9j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xhm-rcrp-wq9j", + "modified": "2024-08-16T15:31:42Z", + "published": "2024-08-16T15:31:42Z", + "aliases": [ + "CVE-2024-4781" + ], + "details": "A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to crash printer communications until the system is rebooted.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4781" + }, + { + "type": "WEB", + "url": "https://iknow.lenovo.com.cn/detail/422688" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T15:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c75r-v5wg-3gmj/GHSA-c75r-v5wg-3gmj.json b/advisories/unreviewed/2024/08/GHSA-c75r-v5wg-3gmj/GHSA-c75r-v5wg-3gmj.json index 3bcebd5ebc1..072b11b86f5 100644 --- a/advisories/unreviewed/2024/08/GHSA-c75r-v5wg-3gmj/GHSA-c75r-v5wg-3gmj.json +++ b/advisories/unreviewed/2024/08/GHSA-c75r-v5wg-3gmj/GHSA-c75r-v5wg-3gmj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c75r-v5wg-3gmj", - "modified": "2024-08-15T18:31:51Z", + "modified": "2024-08-16T15:31:41Z", "published": "2024-08-15T18:31:51Z", "aliases": [ "CVE-2024-42976" ], "details": "Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSafeClientFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:20Z" diff --git a/advisories/unreviewed/2024/08/GHSA-c856-w373-jm6c/GHSA-c856-w373-jm6c.json b/advisories/unreviewed/2024/08/GHSA-c856-w373-jm6c/GHSA-c856-w373-jm6c.json new file mode 100644 index 00000000000..4cce94279f0 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c856-w373-jm6c/GHSA-c856-w373-jm6c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c856-w373-jm6c", + "modified": "2024-08-16T15:31:42Z", + "published": "2024-08-16T15:31:42Z", + "aliases": [ + "CVE-2024-43807" + ], + "details": "In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43807" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cprr-85rg-mjvr/GHSA-cprr-85rg-mjvr.json b/advisories/unreviewed/2024/08/GHSA-cprr-85rg-mjvr/GHSA-cprr-85rg-mjvr.json index 3eade713ff5..97611485971 100644 --- a/advisories/unreviewed/2024/08/GHSA-cprr-85rg-mjvr/GHSA-cprr-85rg-mjvr.json +++ b/advisories/unreviewed/2024/08/GHSA-cprr-85rg-mjvr/GHSA-cprr-85rg-mjvr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cprr-85rg-mjvr", - "modified": "2024-08-15T18:31:52Z", + "modified": "2024-08-16T15:31:41Z", "published": "2024-08-15T18:31:52Z", "aliases": [ "CVE-2024-42985" ], "details": "Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromNatlimit function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:21Z" diff --git a/advisories/unreviewed/2024/08/GHSA-f994-q776-gghm/GHSA-f994-q776-gghm.json b/advisories/unreviewed/2024/08/GHSA-f994-q776-gghm/GHSA-f994-q776-gghm.json index 1530b21c41f..cf5732d72d5 100644 --- a/advisories/unreviewed/2024/08/GHSA-f994-q776-gghm/GHSA-f994-q776-gghm.json +++ b/advisories/unreviewed/2024/08/GHSA-f994-q776-gghm/GHSA-f994-q776-gghm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f994-q776-gghm", - "modified": "2024-08-15T18:31:52Z", + "modified": "2024-08-16T15:31:41Z", "published": "2024-08-15T18:31:52Z", "aliases": [ "CVE-2024-42980" ], "details": "Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the frmL7ImForm function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:21Z" diff --git a/advisories/unreviewed/2024/08/GHSA-fhxh-jfcp-fmv9/GHSA-fhxh-jfcp-fmv9.json b/advisories/unreviewed/2024/08/GHSA-fhxh-jfcp-fmv9/GHSA-fhxh-jfcp-fmv9.json new file mode 100644 index 00000000000..f1e080e8587 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fhxh-jfcp-fmv9/GHSA-fhxh-jfcp-fmv9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhxh-jfcp-fmv9", + "modified": "2024-08-16T15:31:41Z", + "published": "2024-08-16T15:31:41Z", + "aliases": [ + "CVE-2024-42463" + ], + "details": "Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Utilizing REST's Trust in the System Resource to Obtain Sensitive Data.This issue affects upKeeper Manager: through 5.1.9.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42463" + }, + { + "type": "WEB", + "url": "https://support.upkeeper.se/hc/en-us/articles/15432241822620-CVE-2024-42463-Leak-of-organizations-messages" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fj4q-r9h6-xhrg/GHSA-fj4q-r9h6-xhrg.json b/advisories/unreviewed/2024/08/GHSA-fj4q-r9h6-xhrg/GHSA-fj4q-r9h6-xhrg.json index 60dc5d5f8ee..bb67f5eb25d 100644 --- a/advisories/unreviewed/2024/08/GHSA-fj4q-r9h6-xhrg/GHSA-fj4q-r9h6-xhrg.json +++ b/advisories/unreviewed/2024/08/GHSA-fj4q-r9h6-xhrg/GHSA-fj4q-r9h6-xhrg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fj4q-r9h6-xhrg", - "modified": "2024-08-15T18:31:52Z", + "modified": "2024-08-16T15:31:41Z", "published": "2024-08-15T18:31:52Z", "aliases": [ "CVE-2024-42978" ], "details": "An issue in the handler function in /goform/telnet of Tenda FH1206 v02.03.01.35 allows attackers to execute arbitrary commands via a crafted HTTP request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:20Z" diff --git a/advisories/unreviewed/2024/08/GHSA-g8gg-jvrh-m6c2/GHSA-g8gg-jvrh-m6c2.json b/advisories/unreviewed/2024/08/GHSA-g8gg-jvrh-m6c2/GHSA-g8gg-jvrh-m6c2.json index 47cbd75d6e5..af6c0d386f4 100644 --- a/advisories/unreviewed/2024/08/GHSA-g8gg-jvrh-m6c2/GHSA-g8gg-jvrh-m6c2.json +++ b/advisories/unreviewed/2024/08/GHSA-g8gg-jvrh-m6c2/GHSA-g8gg-jvrh-m6c2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g8gg-jvrh-m6c2", - "modified": "2024-08-16T00:32:05Z", + "modified": "2024-08-16T15:31:41Z", "published": "2024-08-16T00:32:05Z", "aliases": [ "CVE-2024-34740" ], "details": "In attributeBytesBase64 and attributeBytesHex of BinaryXmlSerializer.java, there is a possible arbitrary XML injection due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T22:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-gh9v-q4wx-5m5c/GHSA-gh9v-q4wx-5m5c.json b/advisories/unreviewed/2024/08/GHSA-gh9v-q4wx-5m5c/GHSA-gh9v-q4wx-5m5c.json index 23df17c54fb..46a7f0f5c5c 100644 --- a/advisories/unreviewed/2024/08/GHSA-gh9v-q4wx-5m5c/GHSA-gh9v-q4wx-5m5c.json +++ b/advisories/unreviewed/2024/08/GHSA-gh9v-q4wx-5m5c/GHSA-gh9v-q4wx-5m5c.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-457" + "CWE-457", + "CWE-908" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-h44r-v8c9-8pmx/GHSA-h44r-v8c9-8pmx.json b/advisories/unreviewed/2024/08/GHSA-h44r-v8c9-8pmx/GHSA-h44r-v8c9-8pmx.json new file mode 100644 index 00000000000..96df9882c38 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-h44r-v8c9-8pmx/GHSA-h44r-v8c9-8pmx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h44r-v8c9-8pmx", + "modified": "2024-08-16T15:31:42Z", + "published": "2024-08-16T15:31:42Z", + "aliases": [ + "CVE-2024-5209" + ], + "details": "A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to deny printing capabilities until the system is rebooted.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5209" + }, + { + "type": "WEB", + "url": "https://iknow.lenovo.com.cn/detail/422688" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T15:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-h7cf-jrwx-94cj/GHSA-h7cf-jrwx-94cj.json b/advisories/unreviewed/2024/08/GHSA-h7cf-jrwx-94cj/GHSA-h7cf-jrwx-94cj.json index 6dc8c0311ce..75b1fdf978f 100644 --- a/advisories/unreviewed/2024/08/GHSA-h7cf-jrwx-94cj/GHSA-h7cf-jrwx-94cj.json +++ b/advisories/unreviewed/2024/08/GHSA-h7cf-jrwx-94cj/GHSA-h7cf-jrwx-94cj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h7cf-jrwx-94cj", - "modified": "2024-08-15T18:31:52Z", + "modified": "2024-08-16T15:31:41Z", "published": "2024-08-15T18:31:52Z", "aliases": [ "CVE-2024-42982" ], "details": "Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,10 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121", + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:21Z" diff --git a/advisories/unreviewed/2024/08/GHSA-mccv-36h3-rfv5/GHSA-mccv-36h3-rfv5.json b/advisories/unreviewed/2024/08/GHSA-mccv-36h3-rfv5/GHSA-mccv-36h3-rfv5.json index 6e5bbcf565c..99782040605 100644 --- a/advisories/unreviewed/2024/08/GHSA-mccv-36h3-rfv5/GHSA-mccv-36h3-rfv5.json +++ b/advisories/unreviewed/2024/08/GHSA-mccv-36h3-rfv5/GHSA-mccv-36h3-rfv5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mccv-36h3-rfv5", - "modified": "2024-08-15T18:31:51Z", + "modified": "2024-08-16T15:31:40Z", "published": "2024-08-15T18:31:51Z", "aliases": [ "CVE-2024-31799" ], "details": "Information Disclosure in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to read the WiFi passphrase via the UART Debugging Port.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-319" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:17Z" diff --git a/advisories/unreviewed/2024/08/GHSA-mcqx-pmh8-v9cr/GHSA-mcqx-pmh8-v9cr.json b/advisories/unreviewed/2024/08/GHSA-mcqx-pmh8-v9cr/GHSA-mcqx-pmh8-v9cr.json index 09bebabd78b..65e7701a72f 100644 --- a/advisories/unreviewed/2024/08/GHSA-mcqx-pmh8-v9cr/GHSA-mcqx-pmh8-v9cr.json +++ b/advisories/unreviewed/2024/08/GHSA-mcqx-pmh8-v9cr/GHSA-mcqx-pmh8-v9cr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mcqx-pmh8-v9cr", - "modified": "2024-08-01T18:32:50Z", + "modified": "2024-08-16T15:31:40Z", "published": "2024-08-01T18:32:50Z", "aliases": [ "CVE-2024-7255" ], "details": "Out of bounds read in WebTransport in Google Chrome prior to 127.0.6533.88 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-01T18:15:26Z" diff --git a/advisories/unreviewed/2024/08/GHSA-mqj4-jxhw-766g/GHSA-mqj4-jxhw-766g.json b/advisories/unreviewed/2024/08/GHSA-mqj4-jxhw-766g/GHSA-mqj4-jxhw-766g.json new file mode 100644 index 00000000000..7f3f7149998 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mqj4-jxhw-766g/GHSA-mqj4-jxhw-766g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqj4-jxhw-766g", + "modified": "2024-08-16T15:31:41Z", + "published": "2024-08-16T15:31:41Z", + "aliases": [ + "CVE-2024-42462" + ], + "details": "Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This issue affects upKeeper Manager: through 5.1.9.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42462" + }, + { + "type": "WEB", + "url": "https://support.upkeeper.se/hc/en-us/articles/15432045399452-CVE-2024-42462-Bypass-multifactor-authentication" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p332-vhv3-xv9m/GHSA-p332-vhv3-xv9m.json b/advisories/unreviewed/2024/08/GHSA-p332-vhv3-xv9m/GHSA-p332-vhv3-xv9m.json index 9089c05f9dc..288884eea08 100644 --- a/advisories/unreviewed/2024/08/GHSA-p332-vhv3-xv9m/GHSA-p332-vhv3-xv9m.json +++ b/advisories/unreviewed/2024/08/GHSA-p332-vhv3-xv9m/GHSA-p332-vhv3-xv9m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p332-vhv3-xv9m", - "modified": "2024-08-15T18:31:51Z", + "modified": "2024-08-16T15:31:41Z", "published": "2024-08-15T18:31:51Z", "aliases": [ "CVE-2024-42966" ], "details": "Incorrect access control in TOTOLINK N350RT V9.3.5u.6139_B20201216 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:20Z" diff --git a/advisories/unreviewed/2024/08/GHSA-p3f9-2qr4-24wj/GHSA-p3f9-2qr4-24wj.json b/advisories/unreviewed/2024/08/GHSA-p3f9-2qr4-24wj/GHSA-p3f9-2qr4-24wj.json new file mode 100644 index 00000000000..a3c07dfa936 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-p3f9-2qr4-24wj/GHSA-p3f9-2qr4-24wj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3f9-2qr4-24wj", + "modified": "2024-08-16T15:31:42Z", + "published": "2024-08-16T15:31:42Z", + "aliases": [ + "CVE-2024-4782" + ], + "details": "A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to disrupt the printer's functionality until a manual system reboot occurs.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4782" + }, + { + "type": "WEB", + "url": "https://iknow.lenovo.com.cn/detail/422688" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T15:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p736-fp6q-qr5j/GHSA-p736-fp6q-qr5j.json b/advisories/unreviewed/2024/08/GHSA-p736-fp6q-qr5j/GHSA-p736-fp6q-qr5j.json index 40c3fc74a3c..0545b284ea7 100644 --- a/advisories/unreviewed/2024/08/GHSA-p736-fp6q-qr5j/GHSA-p736-fp6q-qr5j.json +++ b/advisories/unreviewed/2024/08/GHSA-p736-fp6q-qr5j/GHSA-p736-fp6q-qr5j.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p736-fp6q-qr5j", - "modified": "2024-08-15T15:30:58Z", + "modified": "2024-08-16T15:31:40Z", "published": "2024-08-15T15:30:58Z", "aliases": [ "CVE-2024-7262" ], "details": "Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.13489 on Windows allows an attacker to load an arbitrary Windows library.\nUsing the MHTML format allows an attacker to automatically deliver a malicious library on opening the document and a single user click on a crafted hyperlink leads to the execution of the library.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:L/U:X" diff --git a/advisories/unreviewed/2024/08/GHSA-p8f2-24c3-9gc6/GHSA-p8f2-24c3-9gc6.json b/advisories/unreviewed/2024/08/GHSA-p8f2-24c3-9gc6/GHSA-p8f2-24c3-9gc6.json new file mode 100644 index 00000000000..c0a2f77fe02 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-p8f2-24c3-9gc6/GHSA-p8f2-24c3-9gc6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8f2-24c3-9gc6", + "modified": "2024-08-16T15:31:41Z", + "published": "2024-08-16T15:31:41Z", + "aliases": [ + "CVE-2024-42466" + ], + "details": "Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Abuse.This issue affects upKeeper Manager: through 5.1.9.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42466" + }, + { + "type": "WEB", + "url": "https://support.upkeeper.se/hc/en-us/articles/15432408367260-CVE-2024-42466-Lack-of-resources-and-rate-limiting-login" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-q967-hxp7-f2rc/GHSA-q967-hxp7-f2rc.json b/advisories/unreviewed/2024/08/GHSA-q967-hxp7-f2rc/GHSA-q967-hxp7-f2rc.json index 9de1df9e81c..9bd4442473e 100644 --- a/advisories/unreviewed/2024/08/GHSA-q967-hxp7-f2rc/GHSA-q967-hxp7-f2rc.json +++ b/advisories/unreviewed/2024/08/GHSA-q967-hxp7-f2rc/GHSA-q967-hxp7-f2rc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q967-hxp7-f2rc", - "modified": "2024-08-15T18:31:51Z", + "modified": "2024-08-16T15:31:41Z", "published": "2024-08-15T18:31:51Z", "aliases": [ "CVE-2024-42977" ], "details": "Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the qos parameter in the fromqossetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:20Z" diff --git a/advisories/unreviewed/2024/08/GHSA-qffp-wwcx-j425/GHSA-qffp-wwcx-j425.json b/advisories/unreviewed/2024/08/GHSA-qffp-wwcx-j425/GHSA-qffp-wwcx-j425.json index e3489fc6a99..de53e7abdbc 100644 --- a/advisories/unreviewed/2024/08/GHSA-qffp-wwcx-j425/GHSA-qffp-wwcx-j425.json +++ b/advisories/unreviewed/2024/08/GHSA-qffp-wwcx-j425/GHSA-qffp-wwcx-j425.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qffp-wwcx-j425", - "modified": "2024-08-15T18:31:52Z", + "modified": "2024-08-16T15:31:41Z", "published": "2024-08-15T18:31:52Z", "aliases": [ "CVE-2024-42986" ], "details": "Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the PPPOEPassword parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:21Z" diff --git a/advisories/unreviewed/2024/08/GHSA-qm84-v26j-7pch/GHSA-qm84-v26j-7pch.json b/advisories/unreviewed/2024/08/GHSA-qm84-v26j-7pch/GHSA-qm84-v26j-7pch.json index 1d53e4dc986..f84bc46027a 100644 --- a/advisories/unreviewed/2024/08/GHSA-qm84-v26j-7pch/GHSA-qm84-v26j-7pch.json +++ b/advisories/unreviewed/2024/08/GHSA-qm84-v26j-7pch/GHSA-qm84-v26j-7pch.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qm84-v26j-7pch", - "modified": "2024-08-15T15:30:58Z", + "modified": "2024-08-16T15:31:40Z", "published": "2024-08-15T15:30:58Z", "aliases": [ "CVE-2024-6347" ], "details": "* Unprotected privileged mode access through UDS session in the Blind Spot Detection Sensor ECU firmware in Nissan Altima (2022) allows attackers to trigger denial-of-service (DoS) by unauthorized access to the ECU's programming session.\n * No preconditions implemented for ECU management functionality through UDS session in the Blind Spot Detection Sensor ECU in Nissan Altima (2022) allows attackers to disrupt normal ECU operations by triggering a control command without authentication.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:D/RE:H/U:X" diff --git a/advisories/unreviewed/2024/08/GHSA-v2r6-5xjh-fr9c/GHSA-v2r6-5xjh-fr9c.json b/advisories/unreviewed/2024/08/GHSA-v2r6-5xjh-fr9c/GHSA-v2r6-5xjh-fr9c.json new file mode 100644 index 00000000000..58e2a0b217b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v2r6-5xjh-fr9c/GHSA-v2r6-5xjh-fr9c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2r6-5xjh-fr9c", + "modified": "2024-08-16T15:31:41Z", + "published": "2024-08-16T15:31:41Z", + "aliases": [ + "CVE-2024-2175" + ], + "details": "An insecure permissions vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM)\n\n that could allow a local attacker to escalate privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2175" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-155486" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w2rc-qg2j-54hv/GHSA-w2rc-qg2j-54hv.json b/advisories/unreviewed/2024/08/GHSA-w2rc-qg2j-54hv/GHSA-w2rc-qg2j-54hv.json new file mode 100644 index 00000000000..2764cb2f2c1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w2rc-qg2j-54hv/GHSA-w2rc-qg2j-54hv.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2rc-qg2j-54hv", + "modified": "2024-08-16T15:31:42Z", + "published": "2024-08-16T15:31:42Z", + "aliases": [ + "CVE-2024-6098" + ], + "details": "When performing an online tag generation to devices which communicate \nusing the ControlLogix protocol, a machine-in-the-middle, or a device \nthat is not configured correctly, could deliver a response leading to \nunrestricted or unregulated resource allocation. This could cause a \ndenial-of-service condition and crash the Kepware application. By \ndefault, these functions are turned off, yet they remain accessible for \nusers who recognize and require their advantages.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6098" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-228-11" + }, + { + "type": "WEB", + "url": "https://www.ptc.com/en/support/article/CS423892" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T15:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w2ww-w274-8rxv/GHSA-w2ww-w274-8rxv.json b/advisories/unreviewed/2024/08/GHSA-w2ww-w274-8rxv/GHSA-w2ww-w274-8rxv.json new file mode 100644 index 00000000000..44f1649fa7f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w2ww-w274-8rxv/GHSA-w2ww-w274-8rxv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2ww-w274-8rxv", + "modified": "2024-08-16T15:31:42Z", + "published": "2024-08-16T15:31:42Z", + "aliases": [ + "CVE-2024-43809" + ], + "details": "In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43809" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w9fr-xv2x-w94q/GHSA-w9fr-xv2x-w94q.json b/advisories/unreviewed/2024/08/GHSA-w9fr-xv2x-w94q/GHSA-w9fr-xv2x-w94q.json index a0b45cd9bad..e0b5aa3765d 100644 --- a/advisories/unreviewed/2024/08/GHSA-w9fr-xv2x-w94q/GHSA-w9fr-xv2x-w94q.json +++ b/advisories/unreviewed/2024/08/GHSA-w9fr-xv2x-w94q/GHSA-w9fr-xv2x-w94q.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-416" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-wm2h-r2j5-8pjc/GHSA-wm2h-r2j5-8pjc.json b/advisories/unreviewed/2024/08/GHSA-wm2h-r2j5-8pjc/GHSA-wm2h-r2j5-8pjc.json new file mode 100644 index 00000000000..a2f22702845 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-wm2h-r2j5-8pjc/GHSA-wm2h-r2j5-8pjc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wm2h-r2j5-8pjc", + "modified": "2024-08-16T15:31:42Z", + "published": "2024-08-16T15:31:42Z", + "aliases": [ + "CVE-2024-43810" + ], + "details": "In JetBrains TeamCity before 2024.07.1 reflected XSS was possible in the AWS Core plugin", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43810" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wxwq-v4jc-6x96/GHSA-wxwq-v4jc-6x96.json b/advisories/unreviewed/2024/08/GHSA-wxwq-v4jc-6x96/GHSA-wxwq-v4jc-6x96.json index de182ed4a6f..12cc6df89aa 100644 --- a/advisories/unreviewed/2024/08/GHSA-wxwq-v4jc-6x96/GHSA-wxwq-v4jc-6x96.json +++ b/advisories/unreviewed/2024/08/GHSA-wxwq-v4jc-6x96/GHSA-wxwq-v4jc-6x96.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wxwq-v4jc-6x96", - "modified": "2024-08-15T18:31:51Z", + "modified": "2024-08-16T15:31:41Z", "published": "2024-08-15T18:31:51Z", "aliases": [ "CVE-2024-42947" ], "details": "An issue in the handler function in /goform/telnet of Tenda FH1201 v1.2.0.14 (408) allows attackers to execute arbitrary commands via a crafted HTTP request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:19Z" diff --git a/advisories/unreviewed/2024/08/GHSA-xw3h-6c4j-mqhw/GHSA-xw3h-6c4j-mqhw.json b/advisories/unreviewed/2024/08/GHSA-xw3h-6c4j-mqhw/GHSA-xw3h-6c4j-mqhw.json index 52e50c12fcd..670dc16dc80 100644 --- a/advisories/unreviewed/2024/08/GHSA-xw3h-6c4j-mqhw/GHSA-xw3h-6c4j-mqhw.json +++ b/advisories/unreviewed/2024/08/GHSA-xw3h-6c4j-mqhw/GHSA-xw3h-6c4j-mqhw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xw3h-6c4j-mqhw", - "modified": "2024-08-15T18:31:51Z", + "modified": "2024-08-16T15:31:41Z", "published": "2024-08-15T18:31:51Z", "aliases": [ "CVE-2024-31800" ], "details": "Authentication Bypass in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to gain a privileged command shell via the UART Debugging Port.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:17Z" diff --git a/advisories/unreviewed/2024/08/GHSA-xx3f-44rh-4g76/GHSA-xx3f-44rh-4g76.json b/advisories/unreviewed/2024/08/GHSA-xx3f-44rh-4g76/GHSA-xx3f-44rh-4g76.json index 07202f95e27..b800006c045 100644 --- a/advisories/unreviewed/2024/08/GHSA-xx3f-44rh-4g76/GHSA-xx3f-44rh-4g76.json +++ b/advisories/unreviewed/2024/08/GHSA-xx3f-44rh-4g76/GHSA-xx3f-44rh-4g76.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xx3f-44rh-4g76", - "modified": "2024-08-15T15:30:59Z", + "modified": "2024-08-16T15:31:40Z", "published": "2024-08-15T15:30:58Z", "aliases": [ "CVE-2024-7263" ], "details": "Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.13489 on Windows allows an attacker to load an arbitrary Windows library.\nThe patch released in version 12.2.0.16909 to mitigate CVE-2024-7262 was not restrictive enough. Another hyperlink parameter was not properly sanitized which leads to the execution of an arbitrary Windows library.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:X/U:X"