diff --git a/advisories/unreviewed/2024/08/GHSA-9mmm-86g7-vp9g/GHSA-9mmm-86g7-vp9g.json b/advisories/unreviewed/2024/08/GHSA-9mmm-86g7-vp9g/GHSA-9mmm-86g7-vp9g.json new file mode 100644 index 00000000000..878405e243f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9mmm-86g7-vp9g/GHSA-9mmm-86g7-vp9g.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mmm-86g7-vp9g", + "modified": "2024-08-27T06:30:32Z", + "published": "2024-08-27T06:30:32Z", + "aliases": [ + "CVE-2024-45321" + ], + "details": "The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45321" + }, + { + "type": "WEB", + "url": "https://github.com/miyagawa/cpanminus/issues/611" + }, + { + "type": "WEB", + "url": "https://github.com/miyagawa/cpanminus/pull/674" + }, + { + "type": "WEB", + "url": "https://security.metacpan.org/2024/08/26/cpanminus-downloads-code-using-insecure-http.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T04:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-x4ww-7q5j-w77r/GHSA-x4ww-7q5j-w77r.json b/advisories/unreviewed/2024/08/GHSA-x4ww-7q5j-w77r/GHSA-x4ww-7q5j-w77r.json new file mode 100644 index 00000000000..b41ca80c41f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-x4ww-7q5j-w77r/GHSA-x4ww-7q5j-w77r.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x4ww-7q5j-w77r", + "modified": "2024-08-27T06:30:32Z", + "published": "2024-08-27T06:30:32Z", + "aliases": [ + "CVE-2024-6688" + ], + "details": "The Oxygen Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the oxy_save_css_from_admin AJAX action in all versions up to, and including, 4.8.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update stylesheets.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6688" + }, + { + "type": "WEB", + "url": "https://oxygenbuilder.com/oxygen-4-9-now-available" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/78c88402-52ca-44ff-8767-1f843fcb66fd?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T05:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-x7x8-w7fj-6xxc/GHSA-x7x8-w7fj-6xxc.json b/advisories/unreviewed/2024/08/GHSA-x7x8-w7fj-6xxc/GHSA-x7x8-w7fj-6xxc.json new file mode 100644 index 00000000000..fc140bebfdd --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-x7x8-w7fj-6xxc/GHSA-x7x8-w7fj-6xxc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7x8-w7fj-6xxc", + "modified": "2024-08-27T06:30:32Z", + "published": "2024-08-27T06:30:32Z", + "aliases": [ + "CVE-2024-7125" + ], + "details": "Authentication Bypass vulnerability in Hitachi Ops Center Common Services.This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before 11.0.2-01.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7125" + }, + { + "type": "WEB", + "url": "https://www.hitachi.com/products/it/software/security/info/vuls/hitachi-sec-2024-143/index.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T05:15:13Z" + } +} \ No newline at end of file