From 80798a5de627e17072b878e91e02cb4e74616929 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 19 Sep 2024 18:32:25 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-qhgj-ghq2-5hjh.json | 1 + .../GHSA-rgjp-37vj-5h44.json | 5 +- .../GHSA-784r-2wg6-39wc.json | 2 +- .../GHSA-gfh7-3mx2-9p35.json | 2 +- .../GHSA-j97x-4gxg-7x49.json | 2 +- .../GHSA-v994-7f87-hh83.json | 3 +- .../GHSA-j3c9-h64h-gwp9.json | 1 + .../GHSA-f982-vxqp-wp2r.json | 3 +- .../GHSA-3m77-f49c-p58r.json | 7 ++- .../GHSA-7p4c-c4rq-7g98.json | 9 ++-- .../GHSA-7r5r-ffqc-9254.json | 3 +- .../GHSA-c45h-95rf-26qw.json | 6 ++- .../GHSA-pg6p-3hcc-49g7.json | 6 ++- .../GHSA-rgxg-wcwm-pqg6.json | 6 ++- .../GHSA-vfp8-2c95-8f3h.json | 3 +- .../GHSA-5mh8-xjgp-m345.json | 2 +- .../GHSA-6qpq-4383-4c38.json | 2 +- .../GHSA-c77r-fh37-x2px.json | 2 +- .../GHSA-cxj4-mqwg-88f8.json | 2 +- .../GHSA-v323-q9x3-gg6h.json | 2 +- .../GHSA-23p2-2jrp-5wcp.json | 38 +++++++++++++++ .../GHSA-245x-752w-r292.json | 2 +- .../GHSA-48xg-h5xm-jxr5.json | 38 +++++++++++++++ .../GHSA-4xx7-2cx3-x473.json | 46 +++++++++++++++++++ .../GHSA-5mq7-93mw-h965.json | 9 ++-- .../GHSA-6ffr-69v4-q8xm.json | 42 +++++++++++++++++ .../GHSA-6g58-3572-wc68.json | 38 +++++++++++++++ .../GHSA-6gcw-xcpf-vr88.json | 38 +++++++++++++++ .../GHSA-8w47-g5wh-386w.json | 38 +++++++++++++++ .../GHSA-94j8-54mg-394v.json | 11 +++-- .../GHSA-94r8-x6vr-vvc4.json | 11 +++-- .../GHSA-c4jq-v98x-5qm2.json | 39 ++++++++++++++++ .../GHSA-cr54-4mf7-rg5v.json | 11 +++-- .../GHSA-g35q-hm7c-4v7x.json | 9 ++-- .../GHSA-gggx-8wfw-w6jx.json | 9 ++-- .../GHSA-hrvw-rfgx-8g4m.json | 11 +++-- .../GHSA-j57f-xm3w-v49f.json | 11 +++-- .../GHSA-m6g3-ch98-vrmr.json | 38 +++++++++++++++ .../GHSA-mhpj-hp73-2h88.json | 11 +++-- .../GHSA-p594-vh26-gh4w.json | 11 +++-- .../GHSA-p8g8-q26r-2q2r.json | 11 +++-- .../GHSA-prj2-h762-9j59.json | 11 +++-- .../GHSA-pwh3-mj55-39cv.json | 38 +++++++++++++++ .../GHSA-q7w8-3gcx-6f5g.json | 38 +++++++++++++++ .../GHSA-qchx-h2pq-fhfp.json | 38 +++++++++++++++ .../GHSA-r7hv-2fgc-3qj2.json | 38 +++++++++++++++ .../GHSA-rcj3-r74w-96hp.json | 2 +- .../GHSA-rq26-5593-xpg9.json | 3 +- .../GHSA-vvf8-2h68-9475.json | 46 +++++++++++++++++++ .../GHSA-w599-hr6x-f9qv.json | 11 +++-- .../GHSA-w69q-w4h4-2fx8.json | 42 +++++++++++++++++ .../GHSA-w7rx-cmpf-jrpp.json | 38 +++++++++++++++ .../GHSA-w9g7-h647-wg7j.json | 38 +++++++++++++++ 53 files changed, 811 insertions(+), 73 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-23p2-2jrp-5wcp/GHSA-23p2-2jrp-5wcp.json create mode 100644 advisories/unreviewed/2024/09/GHSA-48xg-h5xm-jxr5/GHSA-48xg-h5xm-jxr5.json create mode 100644 advisories/unreviewed/2024/09/GHSA-4xx7-2cx3-x473/GHSA-4xx7-2cx3-x473.json create mode 100644 advisories/unreviewed/2024/09/GHSA-6ffr-69v4-q8xm/GHSA-6ffr-69v4-q8xm.json create mode 100644 advisories/unreviewed/2024/09/GHSA-6g58-3572-wc68/GHSA-6g58-3572-wc68.json create mode 100644 advisories/unreviewed/2024/09/GHSA-6gcw-xcpf-vr88/GHSA-6gcw-xcpf-vr88.json create mode 100644 advisories/unreviewed/2024/09/GHSA-8w47-g5wh-386w/GHSA-8w47-g5wh-386w.json create mode 100644 advisories/unreviewed/2024/09/GHSA-c4jq-v98x-5qm2/GHSA-c4jq-v98x-5qm2.json create mode 100644 advisories/unreviewed/2024/09/GHSA-m6g3-ch98-vrmr/GHSA-m6g3-ch98-vrmr.json create mode 100644 advisories/unreviewed/2024/09/GHSA-pwh3-mj55-39cv/GHSA-pwh3-mj55-39cv.json create mode 100644 advisories/unreviewed/2024/09/GHSA-q7w8-3gcx-6f5g/GHSA-q7w8-3gcx-6f5g.json create mode 100644 advisories/unreviewed/2024/09/GHSA-qchx-h2pq-fhfp/GHSA-qchx-h2pq-fhfp.json create mode 100644 advisories/unreviewed/2024/09/GHSA-r7hv-2fgc-3qj2/GHSA-r7hv-2fgc-3qj2.json create mode 100644 advisories/unreviewed/2024/09/GHSA-vvf8-2h68-9475/GHSA-vvf8-2h68-9475.json create mode 100644 advisories/unreviewed/2024/09/GHSA-w69q-w4h4-2fx8/GHSA-w69q-w4h4-2fx8.json create mode 100644 advisories/unreviewed/2024/09/GHSA-w7rx-cmpf-jrpp/GHSA-w7rx-cmpf-jrpp.json create mode 100644 advisories/unreviewed/2024/09/GHSA-w9g7-h647-wg7j/GHSA-w9g7-h647-wg7j.json diff --git a/advisories/unreviewed/2023/07/GHSA-qhgj-ghq2-5hjh/GHSA-qhgj-ghq2-5hjh.json b/advisories/unreviewed/2023/07/GHSA-qhgj-ghq2-5hjh/GHSA-qhgj-ghq2-5hjh.json index 243d643cff6..fb2a32cfab0 100644 --- a/advisories/unreviewed/2023/07/GHSA-qhgj-ghq2-5hjh/GHSA-qhgj-ghq2-5hjh.json +++ b/advisories/unreviewed/2023/07/GHSA-qhgj-ghq2-5hjh/GHSA-qhgj-ghq2-5hjh.json @@ -37,6 +37,7 @@ "database_specific": { "cwe_ids": [ "CWE-119", + "CWE-121", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/07/GHSA-rgjp-37vj-5h44/GHSA-rgjp-37vj-5h44.json b/advisories/unreviewed/2023/07/GHSA-rgjp-37vj-5h44/GHSA-rgjp-37vj-5h44.json index fbd626ca144..8434fce54ae 100644 --- a/advisories/unreviewed/2023/07/GHSA-rgjp-37vj-5h44/GHSA-rgjp-37vj-5h44.json +++ b/advisories/unreviewed/2023/07/GHSA-rgjp-37vj-5h44/GHSA-rgjp-37vj-5h44.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rgjp-37vj-5h44", - "modified": "2024-04-04T05:48:54Z", + "modified": "2024-09-19T18:30:48Z", "published": "2023-07-06T21:15:07Z", "aliases": [ "CVE-2023-0636" @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-77" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-784r-2wg6-39wc/GHSA-784r-2wg6-39wc.json b/advisories/unreviewed/2023/10/GHSA-784r-2wg6-39wc/GHSA-784r-2wg6-39wc.json index 97d67bc9bdf..8e9b1d1afc0 100644 --- a/advisories/unreviewed/2023/10/GHSA-784r-2wg6-39wc/GHSA-784r-2wg6-39wc.json +++ b/advisories/unreviewed/2023/10/GHSA-784r-2wg6-39wc/GHSA-784r-2wg6-39wc.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-gfh7-3mx2-9p35/GHSA-gfh7-3mx2-9p35.json b/advisories/unreviewed/2023/10/GHSA-gfh7-3mx2-9p35/GHSA-gfh7-3mx2-9p35.json index fd78d05c2e8..1bdea7afc78 100644 --- a/advisories/unreviewed/2023/10/GHSA-gfh7-3mx2-9p35/GHSA-gfh7-3mx2-9p35.json +++ b/advisories/unreviewed/2023/10/GHSA-gfh7-3mx2-9p35/GHSA-gfh7-3mx2-9p35.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-j97x-4gxg-7x49/GHSA-j97x-4gxg-7x49.json b/advisories/unreviewed/2023/10/GHSA-j97x-4gxg-7x49/GHSA-j97x-4gxg-7x49.json index c61b0bc239c..65d493a4b9d 100644 --- a/advisories/unreviewed/2023/10/GHSA-j97x-4gxg-7x49/GHSA-j97x-4gxg-7x49.json +++ b/advisories/unreviewed/2023/10/GHSA-j97x-4gxg-7x49/GHSA-j97x-4gxg-7x49.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-v994-7f87-hh83/GHSA-v994-7f87-hh83.json b/advisories/unreviewed/2023/10/GHSA-v994-7f87-hh83/GHSA-v994-7f87-hh83.json index 74d94da6735..49b9c498876 100644 --- a/advisories/unreviewed/2023/10/GHSA-v994-7f87-hh83/GHSA-v994-7f87-hh83.json +++ b/advisories/unreviewed/2023/10/GHSA-v994-7f87-hh83/GHSA-v994-7f87-hh83.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-311" + "CWE-311", + "CWE-319" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-j3c9-h64h-gwp9/GHSA-j3c9-h64h-gwp9.json b/advisories/unreviewed/2024/02/GHSA-j3c9-h64h-gwp9/GHSA-j3c9-h64h-gwp9.json index b43ab4e8a96..cd3ad327b2f 100644 --- a/advisories/unreviewed/2024/02/GHSA-j3c9-h64h-gwp9/GHSA-j3c9-h64h-gwp9.json +++ b/advisories/unreviewed/2024/02/GHSA-j3c9-h64h-gwp9/GHSA-j3c9-h64h-gwp9.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1240", "CWE-311" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/04/GHSA-f982-vxqp-wp2r/GHSA-f982-vxqp-wp2r.json b/advisories/unreviewed/2024/04/GHSA-f982-vxqp-wp2r/GHSA-f982-vxqp-wp2r.json index 5950e3eccdb..a9b245ea433 100644 --- a/advisories/unreviewed/2024/04/GHSA-f982-vxqp-wp2r/GHSA-f982-vxqp-wp2r.json +++ b/advisories/unreviewed/2024/04/GHSA-f982-vxqp-wp2r/GHSA-f982-vxqp-wp2r.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-23" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-3m77-f49c-p58r/GHSA-3m77-f49c-p58r.json b/advisories/unreviewed/2024/06/GHSA-3m77-f49c-p58r/GHSA-3m77-f49c-p58r.json index 1c68ab4b854..4928e097cf5 100644 --- a/advisories/unreviewed/2024/06/GHSA-3m77-f49c-p58r/GHSA-3m77-f49c-p58r.json +++ b/advisories/unreviewed/2024/06/GHSA-3m77-f49c-p58r/GHSA-3m77-f49c-p58r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3m77-f49c-p58r", - "modified": "2024-06-22T12:30:37Z", + "modified": "2024-09-19T18:30:49Z", "published": "2024-06-22T12:30:37Z", "aliases": [ "CVE-2024-6251" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ @@ -36,6 +40,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-80" ], "severity": "LOW", diff --git a/advisories/unreviewed/2024/06/GHSA-7p4c-c4rq-7g98/GHSA-7p4c-c4rq-7g98.json b/advisories/unreviewed/2024/06/GHSA-7p4c-c4rq-7g98/GHSA-7p4c-c4rq-7g98.json index d35a09eca2b..1c18e270a32 100644 --- a/advisories/unreviewed/2024/06/GHSA-7p4c-c4rq-7g98/GHSA-7p4c-c4rq-7g98.json +++ b/advisories/unreviewed/2024/06/GHSA-7p4c-c4rq-7g98/GHSA-7p4c-c4rq-7g98.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7p4c-c4rq-7g98", - "modified": "2024-06-22T09:30:51Z", + "modified": "2024-09-19T18:30:49Z", "published": "2024-06-22T09:30:51Z", "aliases": [ "CVE-2024-38379" ], "details": "Apache Allura's neighborhood settings are vulnerable to a stored XSS attack.  Only neighborhood admins can access these settings, so the scope of risk is limited to configurations where neighborhood admins are not fully trusted.\n\nThis issue affects Apache Allura: from 1.4.0 through 1.17.0.\n\nUsers are recommended to upgrade to version 1.17.1, which fixes the issue.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-22T09:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-7r5r-ffqc-9254/GHSA-7r5r-ffqc-9254.json b/advisories/unreviewed/2024/06/GHSA-7r5r-ffqc-9254/GHSA-7r5r-ffqc-9254.json index 2f472b955ae..c7801758477 100644 --- a/advisories/unreviewed/2024/06/GHSA-7r5r-ffqc-9254/GHSA-7r5r-ffqc-9254.json +++ b/advisories/unreviewed/2024/06/GHSA-7r5r-ffqc-9254/GHSA-7r5r-ffqc-9254.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-c45h-95rf-26qw/GHSA-c45h-95rf-26qw.json b/advisories/unreviewed/2024/06/GHSA-c45h-95rf-26qw/GHSA-c45h-95rf-26qw.json index 75581a658e3..4e3b8060759 100644 --- a/advisories/unreviewed/2024/06/GHSA-c45h-95rf-26qw/GHSA-c45h-95rf-26qw.json +++ b/advisories/unreviewed/2024/06/GHSA-c45h-95rf-26qw/GHSA-c45h-95rf-26qw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c45h-95rf-26qw", - "modified": "2024-06-22T12:30:38Z", + "modified": "2024-09-19T18:30:49Z", "published": "2024-06-22T12:30:37Z", "aliases": [ "CVE-2024-6252" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-pg6p-3hcc-49g7/GHSA-pg6p-3hcc-49g7.json b/advisories/unreviewed/2024/06/GHSA-pg6p-3hcc-49g7/GHSA-pg6p-3hcc-49g7.json index 54406a92b85..7bad9d61162 100644 --- a/advisories/unreviewed/2024/06/GHSA-pg6p-3hcc-49g7/GHSA-pg6p-3hcc-49g7.json +++ b/advisories/unreviewed/2024/06/GHSA-pg6p-3hcc-49g7/GHSA-pg6p-3hcc-49g7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pg6p-3hcc-49g7", - "modified": "2024-06-23T03:30:35Z", + "modified": "2024-09-19T18:30:49Z", "published": "2024-06-23T03:30:35Z", "aliases": [ "CVE-2024-6266" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-rgxg-wcwm-pqg6/GHSA-rgxg-wcwm-pqg6.json b/advisories/unreviewed/2024/06/GHSA-rgxg-wcwm-pqg6/GHSA-rgxg-wcwm-pqg6.json index b4c4d3965bb..64da2d6da4f 100644 --- a/advisories/unreviewed/2024/06/GHSA-rgxg-wcwm-pqg6/GHSA-rgxg-wcwm-pqg6.json +++ b/advisories/unreviewed/2024/06/GHSA-rgxg-wcwm-pqg6/GHSA-rgxg-wcwm-pqg6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rgxg-wcwm-pqg6", - "modified": "2024-06-23T12:30:35Z", + "modified": "2024-09-19T18:30:49Z", "published": "2024-06-23T12:30:35Z", "aliases": [ "CVE-2024-6268" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-vfp8-2c95-8f3h/GHSA-vfp8-2c95-8f3h.json b/advisories/unreviewed/2024/06/GHSA-vfp8-2c95-8f3h/GHSA-vfp8-2c95-8f3h.json index 5d05cd5515f..41b2b0a40b4 100644 --- a/advisories/unreviewed/2024/06/GHSA-vfp8-2c95-8f3h/GHSA-vfp8-2c95-8f3h.json +++ b/advisories/unreviewed/2024/06/GHSA-vfp8-2c95-8f3h/GHSA-vfp8-2c95-8f3h.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-5mh8-xjgp-m345/GHSA-5mh8-xjgp-m345.json b/advisories/unreviewed/2024/08/GHSA-5mh8-xjgp-m345/GHSA-5mh8-xjgp-m345.json index ee33f9f7a59..55927d5b9f8 100644 --- a/advisories/unreviewed/2024/08/GHSA-5mh8-xjgp-m345/GHSA-5mh8-xjgp-m345.json +++ b/advisories/unreviewed/2024/08/GHSA-5mh8-xjgp-m345/GHSA-5mh8-xjgp-m345.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-129" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-6qpq-4383-4c38/GHSA-6qpq-4383-4c38.json b/advisories/unreviewed/2024/08/GHSA-6qpq-4383-4c38/GHSA-6qpq-4383-4c38.json index 3863f3200bf..3b880b5697d 100644 --- a/advisories/unreviewed/2024/08/GHSA-6qpq-4383-4c38/GHSA-6qpq-4383-4c38.json +++ b/advisories/unreviewed/2024/08/GHSA-6qpq-4383-4c38/GHSA-6qpq-4383-4c38.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-129" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-c77r-fh37-x2px/GHSA-c77r-fh37-x2px.json b/advisories/unreviewed/2024/08/GHSA-c77r-fh37-x2px/GHSA-c77r-fh37-x2px.json index f93d56d9ae3..e967045faa7 100644 --- a/advisories/unreviewed/2024/08/GHSA-c77r-fh37-x2px/GHSA-c77r-fh37-x2px.json +++ b/advisories/unreviewed/2024/08/GHSA-c77r-fh37-x2px/GHSA-c77r-fh37-x2px.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c77r-fh37-x2px", - "modified": "2024-08-30T15:31:30Z", + "modified": "2024-09-19T18:30:50Z", "published": "2024-08-30T15:31:30Z", "aliases": [ "CVE-2024-8260" diff --git a/advisories/unreviewed/2024/08/GHSA-cxj4-mqwg-88f8/GHSA-cxj4-mqwg-88f8.json b/advisories/unreviewed/2024/08/GHSA-cxj4-mqwg-88f8/GHSA-cxj4-mqwg-88f8.json index ce368d84f3d..a49f0512a87 100644 --- a/advisories/unreviewed/2024/08/GHSA-cxj4-mqwg-88f8/GHSA-cxj4-mqwg-88f8.json +++ b/advisories/unreviewed/2024/08/GHSA-cxj4-mqwg-88f8/GHSA-cxj4-mqwg-88f8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cxj4-mqwg-88f8", - "modified": "2024-09-12T15:32:59Z", + "modified": "2024-09-19T18:30:50Z", "published": "2024-08-28T09:30:34Z", "aliases": [ "CVE-2024-4554" diff --git a/advisories/unreviewed/2024/08/GHSA-v323-q9x3-gg6h/GHSA-v323-q9x3-gg6h.json b/advisories/unreviewed/2024/08/GHSA-v323-q9x3-gg6h/GHSA-v323-q9x3-gg6h.json index f81a4f55511..430089e2680 100644 --- a/advisories/unreviewed/2024/08/GHSA-v323-q9x3-gg6h/GHSA-v323-q9x3-gg6h.json +++ b/advisories/unreviewed/2024/08/GHSA-v323-q9x3-gg6h/GHSA-v323-q9x3-gg6h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v323-q9x3-gg6h", - "modified": "2024-08-30T18:30:40Z", + "modified": "2024-09-19T18:30:50Z", "published": "2024-08-30T18:30:40Z", "aliases": [ "CVE-2024-6204" diff --git a/advisories/unreviewed/2024/09/GHSA-23p2-2jrp-5wcp/GHSA-23p2-2jrp-5wcp.json b/advisories/unreviewed/2024/09/GHSA-23p2-2jrp-5wcp/GHSA-23p2-2jrp-5wcp.json new file mode 100644 index 00000000000..e6403977122 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-23p2-2jrp-5wcp/GHSA-23p2-2jrp-5wcp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23p2-2jrp-5wcp", + "modified": "2024-09-19T18:30:53Z", + "published": "2024-09-19T18:30:53Z", + "aliases": [ + "CVE-2024-47160" + ], + "details": "In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47160" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-19T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-245x-752w-r292/GHSA-245x-752w-r292.json b/advisories/unreviewed/2024/09/GHSA-245x-752w-r292/GHSA-245x-752w-r292.json index 5330ea91477..11151c92876 100644 --- a/advisories/unreviewed/2024/09/GHSA-245x-752w-r292/GHSA-245x-752w-r292.json +++ b/advisories/unreviewed/2024/09/GHSA-245x-752w-r292/GHSA-245x-752w-r292.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-245x-752w-r292", - "modified": "2024-09-10T09:31:11Z", + "modified": "2024-09-19T18:30:51Z", "published": "2024-09-10T09:31:11Z", "aliases": [ "CVE-2024-7618" diff --git a/advisories/unreviewed/2024/09/GHSA-48xg-h5xm-jxr5/GHSA-48xg-h5xm-jxr5.json b/advisories/unreviewed/2024/09/GHSA-48xg-h5xm-jxr5/GHSA-48xg-h5xm-jxr5.json new file mode 100644 index 00000000000..cb9878dd382 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-48xg-h5xm-jxr5/GHSA-48xg-h5xm-jxr5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-48xg-h5xm-jxr5", + "modified": "2024-09-19T18:30:52Z", + "published": "2024-09-19T18:30:52Z", + "aliases": [ + "CVE-2024-7737" + ], + "details": "A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7737" + }, + { + "type": "WEB", + "url": "https://www.3ds.com/vulnerability/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-19T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-4xx7-2cx3-x473/GHSA-4xx7-2cx3-x473.json b/advisories/unreviewed/2024/09/GHSA-4xx7-2cx3-x473/GHSA-4xx7-2cx3-x473.json new file mode 100644 index 00000000000..4bc0762b61a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-4xx7-2cx3-x473/GHSA-4xx7-2cx3-x473.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xx7-2cx3-x473", + "modified": "2024-09-19T18:30:52Z", + "published": "2024-09-19T18:30:52Z", + "aliases": [ + "CVE-2024-8698" + ], + "details": "A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly determines whether a SAML signature is for the full document or only for specific assertions based on the position of the signature in the XML document, rather than the Reference element used to specify the signed element. This flaw allows attackers to create crafted responses that can bypass the validation, potentially leading to privilege escalation or impersonation attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8698" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-8698" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2311641" + }, + { + "type": "WEB", + "url": "https://github.com/keycloak/keycloak/blob/main/saml-core/src/main/java/org/keycloak/saml/processing/core/util/XMLSignatureUtil.java#L415" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-347" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-19T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-5mq7-93mw-h965/GHSA-5mq7-93mw-h965.json b/advisories/unreviewed/2024/09/GHSA-5mq7-93mw-h965/GHSA-5mq7-93mw-h965.json index 44531e064ec..6a0f71dd978 100644 --- a/advisories/unreviewed/2024/09/GHSA-5mq7-93mw-h965/GHSA-5mq7-93mw-h965.json +++ b/advisories/unreviewed/2024/09/GHSA-5mq7-93mw-h965/GHSA-5mq7-93mw-h965.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5mq7-93mw-h965", - "modified": "2024-09-13T06:30:42Z", + "modified": "2024-09-19T18:30:51Z", "published": "2024-09-13T06:30:42Z", "aliases": [ "CVE-2024-46681" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npktgen: use cpus_read_lock() in pg_net_init()\n\nI have seen the WARN_ON(smp_processor_id() != cpu) firing\nin pktgen_thread_worker() during tests.\n\nWe must use cpus_read_lock()/cpus_read_unlock()\naround the for_each_online_cpu(cpu) loop.\n\nWhile we are at it use WARN_ON_ONCE() to avoid a possible syslog flood.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:12Z" diff --git a/advisories/unreviewed/2024/09/GHSA-6ffr-69v4-q8xm/GHSA-6ffr-69v4-q8xm.json b/advisories/unreviewed/2024/09/GHSA-6ffr-69v4-q8xm/GHSA-6ffr-69v4-q8xm.json new file mode 100644 index 00000000000..66c178886ff --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6ffr-69v4-q8xm/GHSA-6ffr-69v4-q8xm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6ffr-69v4-q8xm", + "modified": "2024-09-19T18:30:51Z", + "published": "2024-09-19T18:30:51Z", + "aliases": [ + "CVE-2024-45752" + ], + "details": "logiops through 0.3.4, in its default configuration, allows any unprivileged user to configure its logid daemon via an unrestricted D-Bus service, including setting malicious keyboard macros. This allows for privilege escalation with minimal user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45752" + }, + { + "type": "WEB", + "url": "https://bugzilla.suse.com/show_bug.cgi?id=1226598" + }, + { + "type": "WEB", + "url": "https://github.com/PixlOne/logiops/releases" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-19T16:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6g58-3572-wc68/GHSA-6g58-3572-wc68.json b/advisories/unreviewed/2024/09/GHSA-6g58-3572-wc68/GHSA-6g58-3572-wc68.json new file mode 100644 index 00000000000..404e90014c8 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6g58-3572-wc68/GHSA-6g58-3572-wc68.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6g58-3572-wc68", + "modified": "2024-09-19T18:30:51Z", + "published": "2024-09-19T18:30:51Z", + "aliases": [ + "CVE-2024-7736" + ], + "details": "A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7736" + }, + { + "type": "WEB", + "url": "https://www.3ds.com/vulnerability/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-19T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6gcw-xcpf-vr88/GHSA-6gcw-xcpf-vr88.json b/advisories/unreviewed/2024/09/GHSA-6gcw-xcpf-vr88/GHSA-6gcw-xcpf-vr88.json new file mode 100644 index 00000000000..9e2adf7f253 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6gcw-xcpf-vr88/GHSA-6gcw-xcpf-vr88.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gcw-xcpf-vr88", + "modified": "2024-09-19T18:30:52Z", + "published": "2024-09-19T18:30:52Z", + "aliases": [ + "CVE-2024-8651" + ], + "details": "A vulnerability in NetCat CMS allows an attacker to send a specially crafted http request that can be used to check whether a user exists in the system, which could be a basis for further attacks.\nThis issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others.\n\nApply patch from vendor https://netcat.ru/ https://netcat.ru/] . Versions 6.4.0.24248 and on have the patch.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8651" + }, + { + "type": "WEB", + "url": "https://github.com/klsecservices/Advisories/blob/master/K-NetCat-2024-001.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-204" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-19T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8w47-g5wh-386w/GHSA-8w47-g5wh-386w.json b/advisories/unreviewed/2024/09/GHSA-8w47-g5wh-386w/GHSA-8w47-g5wh-386w.json new file mode 100644 index 00000000000..e3b22e24263 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8w47-g5wh-386w/GHSA-8w47-g5wh-386w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8w47-g5wh-386w", + "modified": "2024-09-19T18:30:53Z", + "published": "2024-09-19T18:30:53Z", + "aliases": [ + "CVE-2024-47162" + ], + "details": "In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47162" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-19T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-94j8-54mg-394v/GHSA-94j8-54mg-394v.json b/advisories/unreviewed/2024/09/GHSA-94j8-54mg-394v/GHSA-94j8-54mg-394v.json index e05cc269ca5..1e97bb9a229 100644 --- a/advisories/unreviewed/2024/09/GHSA-94j8-54mg-394v/GHSA-94j8-54mg-394v.json +++ b/advisories/unreviewed/2024/09/GHSA-94j8-54mg-394v/GHSA-94j8-54mg-394v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-94j8-54mg-394v", - "modified": "2024-09-18T21:30:48Z", + "modified": "2024-09-19T18:30:51Z", "published": "2024-09-18T21:30:48Z", "aliases": [ "CVE-2024-34057" ], "details": "Triangle Microworks TMW IEC 61850 Client source code libraries before 12.2.0 lack a buffer size check when processing received messages. The resulting buffer overflow can cause a crash, resulting in a denial of service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T19:15:40Z" diff --git a/advisories/unreviewed/2024/09/GHSA-94r8-x6vr-vvc4/GHSA-94r8-x6vr-vvc4.json b/advisories/unreviewed/2024/09/GHSA-94r8-x6vr-vvc4/GHSA-94r8-x6vr-vvc4.json index b91d7ea027e..543bd40c643 100644 --- a/advisories/unreviewed/2024/09/GHSA-94r8-x6vr-vvc4/GHSA-94r8-x6vr-vvc4.json +++ b/advisories/unreviewed/2024/09/GHSA-94r8-x6vr-vvc4/GHSA-94r8-x6vr-vvc4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-94r8-x6vr-vvc4", - "modified": "2024-09-18T21:30:48Z", + "modified": "2024-09-19T18:30:51Z", "published": "2024-09-18T21:30:48Z", "aliases": [ "CVE-2024-46377" ], "details": "Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the save_settings() function of the file rental/admin_class.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T21:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-c4jq-v98x-5qm2/GHSA-c4jq-v98x-5qm2.json b/advisories/unreviewed/2024/09/GHSA-c4jq-v98x-5qm2/GHSA-c4jq-v98x-5qm2.json new file mode 100644 index 00000000000..1c09ee6e233 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-c4jq-v98x-5qm2/GHSA-c4jq-v98x-5qm2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4jq-v98x-5qm2", + "modified": "2024-09-19T18:30:52Z", + "published": "2024-09-19T18:30:52Z", + "aliases": [ + "CVE-2024-31570" + ], + "details": "libfreeimage in FreeImage 3.4.0 through 3.18.0 has a stack-based buffer overflow in the PluginXPM.cpp Load function via an XPM file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31570" + }, + { + "type": "WEB", + "url": "https://sourceforge.net/p/freeimage/bugs/355" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/04/11/10" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-19T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-cr54-4mf7-rg5v/GHSA-cr54-4mf7-rg5v.json b/advisories/unreviewed/2024/09/GHSA-cr54-4mf7-rg5v/GHSA-cr54-4mf7-rg5v.json index edfeadb0ae1..b9513be1e89 100644 --- a/advisories/unreviewed/2024/09/GHSA-cr54-4mf7-rg5v/GHSA-cr54-4mf7-rg5v.json +++ b/advisories/unreviewed/2024/09/GHSA-cr54-4mf7-rg5v/GHSA-cr54-4mf7-rg5v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cr54-4mf7-rg5v", - "modified": "2024-09-05T21:31:34Z", + "modified": "2024-09-19T18:30:51Z", "published": "2024-09-05T21:31:34Z", "aliases": [ "CVE-2024-45159" ], "details": "An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the client, if the client-provided certificate does not have appropriate values in if keyUsage or extKeyUsage extensions, then the return value of mbedtls_ssl_get_verify_result() would incorrectly have the MBEDTLS_X509_BADCERT_KEY_USAGE and MBEDTLS_X509_BADCERT_KEY_USAGE bits clear. As a result, an attacker that had a certificate valid for uses other than TLS client authentication would nonetheless be able to use it for TLS client authentication. Only TLS 1.3 servers were affected, and only with optional authentication (with required authentication, the handshake would be aborted with a fatal alert).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-295" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-05T19:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-g35q-hm7c-4v7x/GHSA-g35q-hm7c-4v7x.json b/advisories/unreviewed/2024/09/GHSA-g35q-hm7c-4v7x/GHSA-g35q-hm7c-4v7x.json index 5cb045604f7..eaf126676cc 100644 --- a/advisories/unreviewed/2024/09/GHSA-g35q-hm7c-4v7x/GHSA-g35q-hm7c-4v7x.json +++ b/advisories/unreviewed/2024/09/GHSA-g35q-hm7c-4v7x/GHSA-g35q-hm7c-4v7x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g35q-hm7c-4v7x", - "modified": "2024-09-06T03:31:29Z", + "modified": "2024-09-19T18:30:51Z", "published": "2024-09-06T03:31:29Z", "aliases": [ "CVE-2024-40865" ], "details": "The issue was addressed by suspending Persona when the virtual keyboard is active. This issue is fixed in visionOS 1.3. Inputs to the virtual keyboard may be inferred from Persona.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-06T02:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-gggx-8wfw-w6jx/GHSA-gggx-8wfw-w6jx.json b/advisories/unreviewed/2024/09/GHSA-gggx-8wfw-w6jx/GHSA-gggx-8wfw-w6jx.json index e9196ec1bd0..b0ed70f35ff 100644 --- a/advisories/unreviewed/2024/09/GHSA-gggx-8wfw-w6jx/GHSA-gggx-8wfw-w6jx.json +++ b/advisories/unreviewed/2024/09/GHSA-gggx-8wfw-w6jx/GHSA-gggx-8wfw-w6jx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gggx-8wfw-w6jx", - "modified": "2024-09-13T09:30:32Z", + "modified": "2024-09-19T18:30:51Z", "published": "2024-09-13T09:30:32Z", "aliases": [ "CVE-2024-46706" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntty: serial: fsl_lpuart: mark last busy before uart_add_one_port\n\nWith \"earlycon initcall_debug=1 loglevel=8\" in bootargs, kernel\nsometimes boot hang. It is because normal console still is not ready,\nbut runtime suspend is called, so early console putchar will hang\nin waiting TRDE set in UARTSTAT.\n\nThe lpuart driver has auto suspend delay set to 3000ms, but during\nuart_add_one_port, a child device serial ctrl will added and probed with\nits pm runtime enabled(see serial_ctrl.c).\nThe runtime suspend call path is:\ndevice_add\n |-> bus_probe_device\n |->device_initial_probe\n\t |->__device_attach\n |-> pm_runtime_get_sync(dev->parent);\n\t\t\t |-> pm_request_idle(dev);\n\t\t\t |-> pm_runtime_put(dev->parent);\n\nSo in the end, before normal console ready, the lpuart get runtime\nsuspended. And earlycon putchar will hang.\n\nTo address the issue, mark last busy just after pm_runtime_enable,\nthree seconds is long enough to switch from bootconsole to normal\nconsole.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T07:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-hrvw-rfgx-8g4m/GHSA-hrvw-rfgx-8g4m.json b/advisories/unreviewed/2024/09/GHSA-hrvw-rfgx-8g4m/GHSA-hrvw-rfgx-8g4m.json index 6eaa1b3be2a..dfee6434aa1 100644 --- a/advisories/unreviewed/2024/09/GHSA-hrvw-rfgx-8g4m/GHSA-hrvw-rfgx-8g4m.json +++ b/advisories/unreviewed/2024/09/GHSA-hrvw-rfgx-8g4m/GHSA-hrvw-rfgx-8g4m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hrvw-rfgx-8g4m", - "modified": "2024-09-13T06:30:43Z", + "modified": "2024-09-19T18:30:51Z", "published": "2024-09-13T06:30:43Z", "aliases": [ "CVE-2024-46688" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: fix out-of-bound access when z_erofs_gbuf_growsize() partially fails\n\nIf z_erofs_gbuf_growsize() partially fails on a global buffer due to\nmemory allocation failure or fault injection (as reported by syzbot [1]),\nnew pages need to be freed by comparing to the existing pages to avoid\nmemory leaks.\n\nHowever, the old gbuf->pages[] array may not be large enough, which can\nlead to null-ptr-deref or out-of-bound access.\n\nFix this by checking against gbuf->nrpages in advance.\n\n[1] https://lore.kernel.org/r/000000000000f7b96e062018c6e3@google.com", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-j57f-xm3w-v49f/GHSA-j57f-xm3w-v49f.json b/advisories/unreviewed/2024/09/GHSA-j57f-xm3w-v49f/GHSA-j57f-xm3w-v49f.json index bde8646bc23..39d3ed9cb7f 100644 --- a/advisories/unreviewed/2024/09/GHSA-j57f-xm3w-v49f/GHSA-j57f-xm3w-v49f.json +++ b/advisories/unreviewed/2024/09/GHSA-j57f-xm3w-v49f/GHSA-j57f-xm3w-v49f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j57f-xm3w-v49f", - "modified": "2024-09-13T06:30:43Z", + "modified": "2024-09-19T18:30:51Z", "published": "2024-09-13T06:30:43Z", "aliases": [ "CVE-2024-46694" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: avoid using null object of framebuffer\n\nInstead of using state->fb->obj[0] directly, get object from framebuffer\nby calling drm_gem_fb_get_obj() and return error code when object is\nnull to avoid using null object of framebuffer.\n\n(cherry picked from commit 73dd0ad9e5dad53766ea3e631303430116f834b3)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-m6g3-ch98-vrmr/GHSA-m6g3-ch98-vrmr.json b/advisories/unreviewed/2024/09/GHSA-m6g3-ch98-vrmr/GHSA-m6g3-ch98-vrmr.json new file mode 100644 index 00000000000..5b0e77bcd6c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-m6g3-ch98-vrmr/GHSA-m6g3-ch98-vrmr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6g3-ch98-vrmr", + "modified": "2024-09-19T18:30:51Z", + "published": "2024-09-19T18:30:51Z", + "aliases": [ + "CVE-2024-45861" + ], + "details": "Kastle Systems firmware prior to May 1, 2024, contained a hard-coded credential, which if accessed may allow an attacker to access sensitive information.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45861" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-263-05" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-19T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mhpj-hp73-2h88/GHSA-mhpj-hp73-2h88.json b/advisories/unreviewed/2024/09/GHSA-mhpj-hp73-2h88/GHSA-mhpj-hp73-2h88.json index 5c850a2b395..32617eed4ba 100644 --- a/advisories/unreviewed/2024/09/GHSA-mhpj-hp73-2h88/GHSA-mhpj-hp73-2h88.json +++ b/advisories/unreviewed/2024/09/GHSA-mhpj-hp73-2h88/GHSA-mhpj-hp73-2h88.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mhpj-hp73-2h88", - "modified": "2024-09-05T18:30:56Z", + "modified": "2024-09-19T18:30:50Z", "published": "2024-09-05T18:30:56Z", "aliases": [ "CVE-2024-45176" ], "details": "An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper input validation, the C-MOR web interface is vulnerable to reflected cross-site scripting (XSS) attacks. It was found out that different functions are prone to reflected cross-site scripting attacks due to insufficient user input validation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-05T16:15:08Z" diff --git a/advisories/unreviewed/2024/09/GHSA-p594-vh26-gh4w/GHSA-p594-vh26-gh4w.json b/advisories/unreviewed/2024/09/GHSA-p594-vh26-gh4w/GHSA-p594-vh26-gh4w.json index 0a9e80e7165..452a8db6188 100644 --- a/advisories/unreviewed/2024/09/GHSA-p594-vh26-gh4w/GHSA-p594-vh26-gh4w.json +++ b/advisories/unreviewed/2024/09/GHSA-p594-vh26-gh4w/GHSA-p594-vh26-gh4w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p594-vh26-gh4w", - "modified": "2024-09-13T06:30:43Z", + "modified": "2024-09-19T18:30:51Z", "published": "2024-09-13T06:30:43Z", "aliases": [ "CVE-2024-46695" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nselinux,smack: don't bypass permissions check in inode_setsecctx hook\n\nMarek Gresko reports that the root user on an NFS client is able to\nchange the security labels on files on an NFS filesystem that is\nexported with root squashing enabled.\n\nThe end of the kerneldoc comment for __vfs_setxattr_noperm() states:\n\n * This function requires the caller to lock the inode's i_mutex before it\n * is executed. It also assumes that the caller will make the appropriate\n * permission checks.\n\nnfsd_setattr() does do permissions checking via fh_verify() and\nnfsd_permission(), but those don't do all the same permissions checks\nthat are done by security_inode_setxattr() and its related LSM hooks do.\n\nSince nfsd_setattr() is the only consumer of security_inode_setsecctx(),\nsimplest solution appears to be to replace the call to\n__vfs_setxattr_noperm() with a call to __vfs_setxattr_locked(). This\nfixes the above issue and has the added benefit of causing nfsd to\nrecall conflicting delegations on a file when a client tries to change\nits security label.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-p8g8-q26r-2q2r/GHSA-p8g8-q26r-2q2r.json b/advisories/unreviewed/2024/09/GHSA-p8g8-q26r-2q2r/GHSA-p8g8-q26r-2q2r.json index ee68e58b25a..ad09f950b77 100644 --- a/advisories/unreviewed/2024/09/GHSA-p8g8-q26r-2q2r/GHSA-p8g8-q26r-2q2r.json +++ b/advisories/unreviewed/2024/09/GHSA-p8g8-q26r-2q2r/GHSA-p8g8-q26r-2q2r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p8g8-q26r-2q2r", - "modified": "2024-09-13T06:30:43Z", + "modified": "2024-09-19T18:30:51Z", "published": "2024-09-13T06:30:42Z", "aliases": [ "CVE-2024-46684" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbinfmt_elf_fdpic: fix AUXV size calculation when ELF_HWCAP2 is defined\n\ncreate_elf_fdpic_tables() does not correctly account the space for the\nAUX vector when an architecture has ELF_HWCAP2 defined. Prior to the\ncommit 10e29251be0e (\"binfmt_elf_fdpic: fix /proc//auxv\") it\nresulted in the last entry of the AUX vector being set to zero, but with\nthat change it results in a kernel BUG.\n\nFix that by adding one to the number of AUXV entries (nitems) when\nELF_HWCAP2 is defined.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-131" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-prj2-h762-9j59/GHSA-prj2-h762-9j59.json b/advisories/unreviewed/2024/09/GHSA-prj2-h762-9j59/GHSA-prj2-h762-9j59.json index d823183e96d..c2b73aa9ca9 100644 --- a/advisories/unreviewed/2024/09/GHSA-prj2-h762-9j59/GHSA-prj2-h762-9j59.json +++ b/advisories/unreviewed/2024/09/GHSA-prj2-h762-9j59/GHSA-prj2-h762-9j59.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-prj2-h762-9j59", - "modified": "2024-09-13T06:30:43Z", + "modified": "2024-09-19T18:30:51Z", "published": "2024-09-13T06:30:43Z", "aliases": [ "CVE-2024-46697" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: ensure that nfsd4_fattr_args.context is zeroed out\n\nIf nfsd4_encode_fattr4 ends up doing a \"goto out\" before we get to\nchecking for the security label, then args.context will be set to\nuninitialized junk on the stack, which we'll then try to free.\nInitialize it early.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-665" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-pwh3-mj55-39cv/GHSA-pwh3-mj55-39cv.json b/advisories/unreviewed/2024/09/GHSA-pwh3-mj55-39cv/GHSA-pwh3-mj55-39cv.json new file mode 100644 index 00000000000..86862ae7b31 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pwh3-mj55-39cv/GHSA-pwh3-mj55-39cv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwh3-mj55-39cv", + "modified": "2024-09-19T18:30:52Z", + "published": "2024-09-19T18:30:52Z", + "aliases": [ + "CVE-2024-8653" + ], + "details": "A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific paths on the site.\nThis issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others.\n\nApply patch from vendor https://netcat.ru/ https://netcat.ru/] . Versions 6.4.0.24248 and on have the patch.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8653" + }, + { + "type": "WEB", + "url": "https://github.com/klsecservices/Advisories/blob/master/K-NetCat-2024-003.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-19T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-q7w8-3gcx-6f5g/GHSA-q7w8-3gcx-6f5g.json b/advisories/unreviewed/2024/09/GHSA-q7w8-3gcx-6f5g/GHSA-q7w8-3gcx-6f5g.json new file mode 100644 index 00000000000..199cee8aaf7 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-q7w8-3gcx-6f5g/GHSA-q7w8-3gcx-6f5g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7w8-3gcx-6f5g", + "modified": "2024-09-19T18:30:52Z", + "published": "2024-09-19T18:30:52Z", + "aliases": [ + "CVE-2024-38016" + ], + "details": "Microsoft Office Visio Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38016" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38016" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-19T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-qchx-h2pq-fhfp/GHSA-qchx-h2pq-fhfp.json b/advisories/unreviewed/2024/09/GHSA-qchx-h2pq-fhfp/GHSA-qchx-h2pq-fhfp.json new file mode 100644 index 00000000000..376c81b19a2 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-qchx-h2pq-fhfp/GHSA-qchx-h2pq-fhfp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qchx-h2pq-fhfp", + "modified": "2024-09-19T18:30:52Z", + "published": "2024-09-19T18:30:52Z", + "aliases": [ + "CVE-2024-8652" + ], + "details": "A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific path on the site.\nThis issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others.\n\nApply patch from vendor https://netcat.ru/ https://netcat.ru/] . Versions 6.4.0.24248 and on have the patch.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8652" + }, + { + "type": "WEB", + "url": "https://github.com/klsecservices/Advisories/blob/master/K-NetCat-2024-002.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-19T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-r7hv-2fgc-3qj2/GHSA-r7hv-2fgc-3qj2.json b/advisories/unreviewed/2024/09/GHSA-r7hv-2fgc-3qj2/GHSA-r7hv-2fgc-3qj2.json new file mode 100644 index 00000000000..3c60ff8912c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-r7hv-2fgc-3qj2/GHSA-r7hv-2fgc-3qj2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7hv-2fgc-3qj2", + "modified": "2024-09-19T18:30:52Z", + "published": "2024-09-19T18:30:52Z", + "aliases": [ + "CVE-2024-47159" + ], + "details": "In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a project", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47159" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-19T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-rcj3-r74w-96hp/GHSA-rcj3-r74w-96hp.json b/advisories/unreviewed/2024/09/GHSA-rcj3-r74w-96hp/GHSA-rcj3-r74w-96hp.json index 6156dc6ce31..d20c0994bfb 100644 --- a/advisories/unreviewed/2024/09/GHSA-rcj3-r74w-96hp/GHSA-rcj3-r74w-96hp.json +++ b/advisories/unreviewed/2024/09/GHSA-rcj3-r74w-96hp/GHSA-rcj3-r74w-96hp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rcj3-r74w-96hp", - "modified": "2024-09-10T09:31:11Z", + "modified": "2024-09-19T18:30:51Z", "published": "2024-09-10T09:31:11Z", "aliases": [ "CVE-2024-7655" diff --git a/advisories/unreviewed/2024/09/GHSA-rq26-5593-xpg9/GHSA-rq26-5593-xpg9.json b/advisories/unreviewed/2024/09/GHSA-rq26-5593-xpg9/GHSA-rq26-5593-xpg9.json index 523cae8967d..7de9889b69a 100644 --- a/advisories/unreviewed/2024/09/GHSA-rq26-5593-xpg9/GHSA-rq26-5593-xpg9.json +++ b/advisories/unreviewed/2024/09/GHSA-rq26-5593-xpg9/GHSA-rq26-5593-xpg9.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-vvf8-2h68-9475/GHSA-vvf8-2h68-9475.json b/advisories/unreviewed/2024/09/GHSA-vvf8-2h68-9475/GHSA-vvf8-2h68-9475.json new file mode 100644 index 00000000000..537b70f581c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vvf8-2h68-9475/GHSA-vvf8-2h68-9475.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvf8-2h68-9475", + "modified": "2024-09-19T18:30:52Z", + "published": "2024-09-19T18:30:52Z", + "aliases": [ + "CVE-2024-8883" + ], + "details": "A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes to be exposed to the attacker, potentially leading to session hijacking.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8883" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-8883" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2312511" + }, + { + "type": "WEB", + "url": "https://github.com/keycloak/keycloak/blob/main/services/src/main/java/org/keycloak/protocol/oidc/utils/RedirectUtils.java" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-19T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-w599-hr6x-f9qv/GHSA-w599-hr6x-f9qv.json b/advisories/unreviewed/2024/09/GHSA-w599-hr6x-f9qv/GHSA-w599-hr6x-f9qv.json index 657b65bfbf6..7c6412a775c 100644 --- a/advisories/unreviewed/2024/09/GHSA-w599-hr6x-f9qv/GHSA-w599-hr6x-f9qv.json +++ b/advisories/unreviewed/2024/09/GHSA-w599-hr6x-f9qv/GHSA-w599-hr6x-f9qv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w599-hr6x-f9qv", - "modified": "2024-09-18T21:30:48Z", + "modified": "2024-09-19T18:30:51Z", "published": "2024-09-18T21:30:48Z", "aliases": [ "CVE-2024-44589" ], "details": "Stack overflow vulnerability in the Login function in the HNAP service in D-Link DCS-960L with firmware 1.09 allows attackers to execute of arbitrary code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T20:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-w69q-w4h4-2fx8/GHSA-w69q-w4h4-2fx8.json b/advisories/unreviewed/2024/09/GHSA-w69q-w4h4-2fx8/GHSA-w69q-w4h4-2fx8.json new file mode 100644 index 00000000000..ac210bf7c08 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-w69q-w4h4-2fx8/GHSA-w69q-w4h4-2fx8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w69q-w4h4-2fx8", + "modified": "2024-09-19T18:30:52Z", + "published": "2024-09-19T18:30:52Z", + "aliases": [ + "CVE-2024-8375" + ], + "details": "There exists a use after free vulnerability in Reverb. Reverb supports the VARIANT datatype, which is supposed to represent an arbitrary object in C++. When a tensor proto of type VARIANT is unpacked, memory is first allocated to store the entire tensor, and a ctor is called on each instance. Afterwards, Reverb copies the content in tensor_content to the previously mentioned pre-allocated memory, which results in the bytes in tensor_content overwriting the vtable pointers of all the objects which were previously allocated. Reverb exposes 2 relevant gRPC endpoints: InsertStream and SampleStream. The attacker can insert this stream into the server’s database, then when the client next calls SampleStream they will unpack the tensor into RAM, and when any method on that object is called (including its destructor) the attacker gains control of the Program Counter. We recommend upgrading past git commit  https://github.com/google-deepmind/reverb/commit/6a0dcf4c9e842b7f999912f792aaa6f6bd261a25", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8375" + }, + { + "type": "WEB", + "url": "https://github.com/google-deepmind/reverb/issues/141" + }, + { + "type": "WEB", + "url": "https://github.com/google-deepmind/reverb/commit/6a0dcf4c9e842b7f999912f792aaa6f6bd261a25" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-19T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-w7rx-cmpf-jrpp/GHSA-w7rx-cmpf-jrpp.json b/advisories/unreviewed/2024/09/GHSA-w7rx-cmpf-jrpp/GHSA-w7rx-cmpf-jrpp.json new file mode 100644 index 00000000000..ce2b40118ac --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-w7rx-cmpf-jrpp/GHSA-w7rx-cmpf-jrpp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7rx-cmpf-jrpp", + "modified": "2024-09-19T18:30:53Z", + "published": "2024-09-19T18:30:53Z", + "aliases": [ + "CVE-2024-8963" + ], + "details": "Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8963" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-CSA-4-6-Cloud-Services-Appliance-CVE-2024-8963" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-19T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-w9g7-h647-wg7j/GHSA-w9g7-h647-wg7j.json b/advisories/unreviewed/2024/09/GHSA-w9g7-h647-wg7j/GHSA-w9g7-h647-wg7j.json new file mode 100644 index 00000000000..1d03352820a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-w9g7-h647-wg7j/GHSA-w9g7-h647-wg7j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9g7-h647-wg7j", + "modified": "2024-09-19T18:30:51Z", + "published": "2024-09-19T18:30:51Z", + "aliases": [ + "CVE-2024-45862" + ], + "details": "Kastle Systems firmware prior to May 1, 2024, stored machine credentials in cleartext, which may allow an attacker to access sensitive information.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45862" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-263-05" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-312" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-19T16:15:05Z" + } +} \ No newline at end of file