From 82b2d0bdfc89502877add721c5bfae89e26f4e6b Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 3 Jan 2025 15:32:03 +0000 Subject: [PATCH] Publish Advisories GHSA-cgc6-4xgf-5q5x GHSA-2mf6-q75m-3xr8 GHSA-973f-jfvh-694j GHSA-qrgc-v5hr-pjgw GHSA-xjpv-4c4j-wwp8 --- .../GHSA-cgc6-4xgf-5q5x.json | 11 ++++-- .../GHSA-2mf6-q75m-3xr8.json | 37 +++++++++++++++++++ .../GHSA-973f-jfvh-694j.json | 36 ++++++++++++++++++ .../GHSA-qrgc-v5hr-pjgw.json | 36 ++++++++++++++++++ .../GHSA-xjpv-4c4j-wwp8.json | 33 +++++++++++++++++ 5 files changed, 150 insertions(+), 3 deletions(-) create mode 100644 advisories/unreviewed/2025/01/GHSA-2mf6-q75m-3xr8/GHSA-2mf6-q75m-3xr8.json create mode 100644 advisories/unreviewed/2025/01/GHSA-973f-jfvh-694j/GHSA-973f-jfvh-694j.json create mode 100644 advisories/unreviewed/2025/01/GHSA-qrgc-v5hr-pjgw/GHSA-qrgc-v5hr-pjgw.json create mode 100644 advisories/unreviewed/2025/01/GHSA-xjpv-4c4j-wwp8/GHSA-xjpv-4c4j-wwp8.json diff --git a/advisories/unreviewed/2024/12/GHSA-cgc6-4xgf-5q5x/GHSA-cgc6-4xgf-5q5x.json b/advisories/unreviewed/2024/12/GHSA-cgc6-4xgf-5q5x/GHSA-cgc6-4xgf-5q5x.json index 8a581aa72d2..df99126a2dc 100644 --- a/advisories/unreviewed/2024/12/GHSA-cgc6-4xgf-5q5x/GHSA-cgc6-4xgf-5q5x.json +++ b/advisories/unreviewed/2024/12/GHSA-cgc6-4xgf-5q5x/GHSA-cgc6-4xgf-5q5x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cgc6-4xgf-5q5x", - "modified": "2024-12-19T00:37:35Z", + "modified": "2025-01-03T15:30:38Z", "published": "2024-12-19T00:37:35Z", "aliases": [ "CVE-2024-12694" ], "details": "Use after free in Compositing in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-18T22:15:06Z" diff --git a/advisories/unreviewed/2025/01/GHSA-2mf6-q75m-3xr8/GHSA-2mf6-q75m-3xr8.json b/advisories/unreviewed/2025/01/GHSA-2mf6-q75m-3xr8/GHSA-2mf6-q75m-3xr8.json new file mode 100644 index 00000000000..63abb916b93 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2mf6-q75m-3xr8/GHSA-2mf6-q75m-3xr8.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mf6-q75m-3xr8", + "modified": "2025-01-03T15:30:38Z", + "published": "2025-01-03T15:30:38Z", + "aliases": [ + "CVE-2024-48814" + ], + "details": "SQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via the ViewType parameter of the findbywhereclause function", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48814" + }, + { + "type": "WEB", + "url": "https://github.com/Silverpeas/Silverpeas-Components/pull/859" + }, + { + "type": "WEB", + "url": "https://github.com/Silverpeas/Silverpeas-Core/pull/1353" + }, + { + "type": "WEB", + "url": "https://gist.github.com/SubZ3r0-0x01/7150f7cbc3b7d810adb221cae3d08fc8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-03T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-973f-jfvh-694j/GHSA-973f-jfvh-694j.json b/advisories/unreviewed/2025/01/GHSA-973f-jfvh-694j/GHSA-973f-jfvh-694j.json new file mode 100644 index 00000000000..0900108b655 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-973f-jfvh-694j/GHSA-973f-jfvh-694j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-973f-jfvh-694j", + "modified": "2025-01-03T15:30:38Z", + "published": "2025-01-03T15:30:38Z", + "aliases": [ + "CVE-2024-41780" + ], + "details": "IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could \n\ncould allow a physical user to obtain sensitive information due to not masking passwords during entry.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41780" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7180119" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-359" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-03T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qrgc-v5hr-pjgw/GHSA-qrgc-v5hr-pjgw.json b/advisories/unreviewed/2025/01/GHSA-qrgc-v5hr-pjgw/GHSA-qrgc-v5hr-pjgw.json new file mode 100644 index 00000000000..c07babb170b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qrgc-v5hr-pjgw/GHSA-qrgc-v5hr-pjgw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrgc-v5hr-pjgw", + "modified": "2025-01-03T15:30:39Z", + "published": "2025-01-03T15:30:39Z", + "aliases": [ + "CVE-2024-5591" + ], + "details": "IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5591" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7180120" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-03T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xjpv-4c4j-wwp8/GHSA-xjpv-4c4j-wwp8.json b/advisories/unreviewed/2025/01/GHSA-xjpv-4c4j-wwp8/GHSA-xjpv-4c4j-wwp8.json new file mode 100644 index 00000000000..0dbf841de6f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xjpv-4c4j-wwp8/GHSA-xjpv-4c4j-wwp8.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjpv-4c4j-wwp8", + "modified": "2025-01-03T15:30:38Z", + "published": "2025-01-03T15:30:38Z", + "aliases": [ + "CVE-2024-55078" + ], + "details": "An arbitrary file upload vulnerability in the component /adminUser/updateImg of WukongCRM-11.0-JAVA v11.3.3 allows attackers to execute arbitrary code via uploading a crafted file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55078" + }, + { + "type": "WEB", + "url": "https://gist.github.com/summerxxoo/8a0c9905feda6e192c10b860888afd26" + }, + { + "type": "WEB", + "url": "https://github.com/summerxxoo/VulnPoc/blob/main/WukongCRM-11.0-JAVA%20-File%20upload%20across%20directories.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-03T15:15:10Z" + } +} \ No newline at end of file