diff --git a/advisories/unreviewed/2022/03/GHSA-fvpm-fmhh-c8qc/GHSA-fvpm-fmhh-c8qc.json b/advisories/unreviewed/2022/03/GHSA-fvpm-fmhh-c8qc/GHSA-fvpm-fmhh-c8qc.json
index 885944001e5..7f2287da6dc 100644
--- a/advisories/unreviewed/2022/03/GHSA-fvpm-fmhh-c8qc/GHSA-fvpm-fmhh-c8qc.json
+++ b/advisories/unreviewed/2022/03/GHSA-fvpm-fmhh-c8qc/GHSA-fvpm-fmhh-c8qc.json
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-77"
+ "CWE-77",
+ "CWE-78"
],
"severity": "CRITICAL",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2022/03/GHSA-pjh3-v4fw-6w59/GHSA-pjh3-v4fw-6w59.json b/advisories/unreviewed/2022/03/GHSA-pjh3-v4fw-6w59/GHSA-pjh3-v4fw-6w59.json
index 6a50cecfca9..38b842fd4b7 100644
--- a/advisories/unreviewed/2022/03/GHSA-pjh3-v4fw-6w59/GHSA-pjh3-v4fw-6w59.json
+++ b/advisories/unreviewed/2022/03/GHSA-pjh3-v4fw-6w59/GHSA-pjh3-v4fw-6w59.json
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-77"
+ "CWE-77",
+ "CWE-78"
],
"severity": "CRITICAL",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2022/03/GHSA-wpvg-rwm7-w52r/GHSA-wpvg-rwm7-w52r.json b/advisories/unreviewed/2022/03/GHSA-wpvg-rwm7-w52r/GHSA-wpvg-rwm7-w52r.json
index 7057326b7b7..b0778f569a9 100644
--- a/advisories/unreviewed/2022/03/GHSA-wpvg-rwm7-w52r/GHSA-wpvg-rwm7-w52r.json
+++ b/advisories/unreviewed/2022/03/GHSA-wpvg-rwm7-w52r/GHSA-wpvg-rwm7-w52r.json
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-77"
+ "CWE-77",
+ "CWE-78"
],
"severity": "CRITICAL",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2023/10/GHSA-7xp8-vhxc-29v9/GHSA-7xp8-vhxc-29v9.json b/advisories/unreviewed/2023/10/GHSA-7xp8-vhxc-29v9/GHSA-7xp8-vhxc-29v9.json
index 6f91b6c913c..5c58eba2195 100644
--- a/advisories/unreviewed/2023/10/GHSA-7xp8-vhxc-29v9/GHSA-7xp8-vhxc-29v9.json
+++ b/advisories/unreviewed/2023/10/GHSA-7xp8-vhxc-29v9/GHSA-7xp8-vhxc-29v9.json
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
+ "CWE-121",
"CWE-787"
],
"severity": "CRITICAL",
diff --git a/advisories/unreviewed/2023/10/GHSA-g55h-gq76-w8v9/GHSA-g55h-gq76-w8v9.json b/advisories/unreviewed/2023/10/GHSA-g55h-gq76-w8v9/GHSA-g55h-gq76-w8v9.json
index 78cdd0d7093..a5110578598 100644
--- a/advisories/unreviewed/2023/10/GHSA-g55h-gq76-w8v9/GHSA-g55h-gq76-w8v9.json
+++ b/advisories/unreviewed/2023/10/GHSA-g55h-gq76-w8v9/GHSA-g55h-gq76-w8v9.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-204"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2023/10/GHSA-m3gg-5v93-qrhg/GHSA-m3gg-5v93-qrhg.json b/advisories/unreviewed/2023/10/GHSA-m3gg-5v93-qrhg/GHSA-m3gg-5v93-qrhg.json
index 40c165d3e78..dea962ce31a 100644
--- a/advisories/unreviewed/2023/10/GHSA-m3gg-5v93-qrhg/GHSA-m3gg-5v93-qrhg.json
+++ b/advisories/unreviewed/2023/10/GHSA-m3gg-5v93-qrhg/GHSA-m3gg-5v93-qrhg.json
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
+ "CWE-121",
"CWE-787"
],
"severity": "CRITICAL",
diff --git a/advisories/unreviewed/2023/10/GHSA-v5x7-5rc8-h4m4/GHSA-v5x7-5rc8-h4m4.json b/advisories/unreviewed/2023/10/GHSA-v5x7-5rc8-h4m4/GHSA-v5x7-5rc8-h4m4.json
index 18afa2f6dca..64aed565091 100644
--- a/advisories/unreviewed/2023/10/GHSA-v5x7-5rc8-h4m4/GHSA-v5x7-5rc8-h4m4.json
+++ b/advisories/unreviewed/2023/10/GHSA-v5x7-5rc8-h4m4/GHSA-v5x7-5rc8-h4m4.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-269"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2023/10/GHSA-xf6j-84wr-6vq4/GHSA-xf6j-84wr-6vq4.json b/advisories/unreviewed/2023/10/GHSA-xf6j-84wr-6vq4/GHSA-xf6j-84wr-6vq4.json
index 524f88da80b..ac1e4a3f4bf 100644
--- a/advisories/unreviewed/2023/10/GHSA-xf6j-84wr-6vq4/GHSA-xf6j-84wr-6vq4.json
+++ b/advisories/unreviewed/2023/10/GHSA-xf6j-84wr-6vq4/GHSA-xf6j-84wr-6vq4.json
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
+ "CWE-121",
"CWE-787"
],
"severity": "CRITICAL",
diff --git a/advisories/unreviewed/2023/12/GHSA-5m24-g5mr-69cj/GHSA-5m24-g5mr-69cj.json b/advisories/unreviewed/2023/12/GHSA-5m24-g5mr-69cj/GHSA-5m24-g5mr-69cj.json
index c446dfe5f99..f3749b1ca6e 100644
--- a/advisories/unreviewed/2023/12/GHSA-5m24-g5mr-69cj/GHSA-5m24-g5mr-69cj.json
+++ b/advisories/unreviewed/2023/12/GHSA-5m24-g5mr-69cj/GHSA-5m24-g5mr-69cj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5m24-g5mr-69cj",
- "modified": "2023-12-27T21:31:00Z",
+ "modified": "2024-09-12T15:32:58Z",
"published": "2023-12-22T21:30:23Z",
"aliases": [
"CVE-2023-51014"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-77"
],
"severity": "CRITICAL",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2023/12/GHSA-9v85-6x2c-c4m4/GHSA-9v85-6x2c-c4m4.json b/advisories/unreviewed/2023/12/GHSA-9v85-6x2c-c4m4/GHSA-9v85-6x2c-c4m4.json
index c47b6f4d42e..ac664a42c24 100644
--- a/advisories/unreviewed/2023/12/GHSA-9v85-6x2c-c4m4/GHSA-9v85-6x2c-c4m4.json
+++ b/advisories/unreviewed/2023/12/GHSA-9v85-6x2c-c4m4/GHSA-9v85-6x2c-c4m4.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9v85-6x2c-c4m4",
- "modified": "2023-12-27T21:31:00Z",
+ "modified": "2024-09-12T15:32:58Z",
"published": "2023-12-22T18:30:31Z",
"aliases": [
"CVE-2023-51025"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-77"
],
"severity": "CRITICAL",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/07/GHSA-c77m-wh63-vhch/GHSA-c77m-wh63-vhch.json b/advisories/unreviewed/2024/07/GHSA-c77m-wh63-vhch/GHSA-c77m-wh63-vhch.json
index a4e0a1993b3..e060ed2e31f 100644
--- a/advisories/unreviewed/2024/07/GHSA-c77m-wh63-vhch/GHSA-c77m-wh63-vhch.json
+++ b/advisories/unreviewed/2024/07/GHSA-c77m-wh63-vhch/GHSA-c77m-wh63-vhch.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c77m-wh63-vhch",
- "modified": "2024-07-29T09:36:14Z",
+ "modified": "2024-09-12T15:32:58Z",
"published": "2024-07-23T09:30:39Z",
"aliases": [
"CVE-2024-41012"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfilelock: Remove locks reliably when fcntl/close race is detected\n\nWhen fcntl_setlk() races with close(), it removes the created lock with\ndo_lock_file_wait().\nHowever, LSMs can allow the first do_lock_file_wait() that created the lock\nwhile denying the second do_lock_file_wait() that tries to remove the lock.\nSeparately, posix_lock_file() could also fail to\nremove a lock due to GFP_KERNEL allocation failure (when splitting a range\nin the middle).\n\nAfter the bug has been triggered, use-after-free reads will occur in\nlock_get_status() when userspace reads /proc/locks. This can likely be used\nto read arbitrary kernel memory, but can't corrupt kernel memory.\n\nFix it by calling locks_remove_posix() instead, which is designed to\nreliably get rid of POSIX locks associated with the given file and\nfiles_struct and is also used by filp_flush().",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H"
+ }
],
"affected": [
@@ -53,9 +56,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-416"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-23T08:15:01Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-23g6-fhm7-588p/GHSA-23g6-fhm7-588p.json b/advisories/unreviewed/2024/08/GHSA-23g6-fhm7-588p/GHSA-23g6-fhm7-588p.json
index ee00a06e10b..046823f135b 100644
--- a/advisories/unreviewed/2024/08/GHSA-23g6-fhm7-588p/GHSA-23g6-fhm7-588p.json
+++ b/advisories/unreviewed/2024/08/GHSA-23g6-fhm7-588p/GHSA-23g6-fhm7-588p.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-23g6-fhm7-588p",
- "modified": "2024-08-22T03:31:34Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-22T03:31:34Z",
"aliases": [
"CVE-2022-48910"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ipv6: ensure we call ipv6_mc_down() at most once\n\nThere are two reasons for addrconf_notify() to be called with NETDEV_DOWN:\neither the network device is actually going down, or IPv6 was disabled\non the interface.\n\nIf either of them stays down while the other is toggled, we repeatedly\ncall the code for NETDEV_DOWN, including ipv6_mc_down(), while never\ncalling the corresponding ipv6_mc_up() in between. This will cause a\nnew entry in idev->mc_tomb to be allocated for each multicast group\nthe interface is subscribed to, which in turn leaks one struct ifmcaddr6\nper nontrivial multicast group the interface is subscribed to.\n\nThe following reproducer will leak at least $n objects:\n\nip addr add ff2e::4242/32 dev eth0 autojoin\nsysctl -w net.ipv6.conf.eth0.disable_ipv6=1\nfor i in $(seq 1 $n); do\n\tip link set up eth0; ip link set down eth0\ndone\n\nJoining groups with IPV6_ADD_MEMBERSHIP (unprivileged) or setting the\nsysctl net.ipv6.conf.eth0.forwarding to 1 (=> subscribing to ff02::2)\ncan also be used to create a nontrivial idev->mc_list, which will the\nleak objects with the right up-down-sequence.\n\nBased on both sources for NETDEV_DOWN events the interface IPv6 state\nshould be considered:\n\n - not ready if the network interface is not ready OR IPv6 is disabled\n for it\n - ready if the network interface is ready AND IPv6 is enabled for it\n\nThe functions ipv6_mc_up() and ipv6_down() should only be run when this\nstate changes.\n\nImplement this by remembering when the IPv6 state is ready, and only\nrun ipv6_mc_down() if it actually changed from ready to not ready.\n\nThe other direction (not ready -> ready) already works correctly, as:\n\n - the interface notification triggered codepath for NETDEV_UP /\n NETDEV_CHANGE returns early if ipv6 is disabled, and\n - the disable_ipv6=0 triggered codepath skips fully initializing the\n interface as long as addrconf_link_ready(dev) returns false\n - calling ipv6_mc_up() repeatedly does not leak anything",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -51,7 +54,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-22T02:15:05Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-26rc-mj52-pcf5/GHSA-26rc-mj52-pcf5.json b/advisories/unreviewed/2024/08/GHSA-26rc-mj52-pcf5/GHSA-26rc-mj52-pcf5.json
index de3509912ca..4b003ec9c4a 100644
--- a/advisories/unreviewed/2024/08/GHSA-26rc-mj52-pcf5/GHSA-26rc-mj52-pcf5.json
+++ b/advisories/unreviewed/2024/08/GHSA-26rc-mj52-pcf5/GHSA-26rc-mj52-pcf5.json
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-26rc-mj52-pcf5",
- "modified": "2024-09-06T15:32:56Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-28T12:30:33Z",
"aliases": [
"CVE-2024-6449"
],
"details": "HyperView Geoportal Toolkit in versions though 8.2.4 does not restrict cross-domain requests when fetching remote content pointed by one of GET request parameters.\nAn unauthenticated remote attacker can prepare links, which upon opening will load scripts from a remote location controlled by the attacker and execute them in the user space.\nBy manipulating this parameter it is also possible to enumerate some of the devices in Local Area Network in which the server resides.",
"severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
+ },
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
diff --git a/advisories/unreviewed/2024/08/GHSA-2fx8-5w8c-86ff/GHSA-2fx8-5w8c-86ff.json b/advisories/unreviewed/2024/08/GHSA-2fx8-5w8c-86ff/GHSA-2fx8-5w8c-86ff.json
index c193cb0e93a..f6b550ef079 100644
--- a/advisories/unreviewed/2024/08/GHSA-2fx8-5w8c-86ff/GHSA-2fx8-5w8c-86ff.json
+++ b/advisories/unreviewed/2024/08/GHSA-2fx8-5w8c-86ff/GHSA-2fx8-5w8c-86ff.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2fx8-5w8c-86ff",
- "modified": "2024-08-27T09:30:44Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-27T09:30:44Z",
"aliases": [
"CVE-2024-41176"
diff --git a/advisories/unreviewed/2024/08/GHSA-3mqr-vvf3-23jj/GHSA-3mqr-vvf3-23jj.json b/advisories/unreviewed/2024/08/GHSA-3mqr-vvf3-23jj/GHSA-3mqr-vvf3-23jj.json
index 6afb9129346..197ba7263d1 100644
--- a/advisories/unreviewed/2024/08/GHSA-3mqr-vvf3-23jj/GHSA-3mqr-vvf3-23jj.json
+++ b/advisories/unreviewed/2024/08/GHSA-3mqr-vvf3-23jj/GHSA-3mqr-vvf3-23jj.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3mqr-vvf3-23jj",
- "modified": "2024-08-29T18:31:35Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-26T12:31:20Z",
"aliases": [
"CVE-2024-44940"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfou: remove warn in gue_gro_receive on unsupported protocol\n\nDrop the WARN_ON_ONCE inn gue_gro_receive if the encapsulated type is\nnot known or does not have a GRO handler.\n\nSuch a packet is easily constructed. Syzbot generates them and sets\noff this warning.\n\nRemove the warning as it is expected and not actionable.\n\nThe warning was previously reduced from WARN_ON to WARN_ON_ONCE in\ncommit 270136613bf7 (\"fou: Do WARN_ON_ONCE in gue_gro_receive for bad\nproto callbacks\").",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -39,7 +42,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-26T12:15:06Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-46h9-pp48-mv2m/GHSA-46h9-pp48-mv2m.json b/advisories/unreviewed/2024/08/GHSA-46h9-pp48-mv2m/GHSA-46h9-pp48-mv2m.json
index 469cedba597..b4b0a469835 100644
--- a/advisories/unreviewed/2024/08/GHSA-46h9-pp48-mv2m/GHSA-46h9-pp48-mv2m.json
+++ b/advisories/unreviewed/2024/08/GHSA-46h9-pp48-mv2m/GHSA-46h9-pp48-mv2m.json
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-20"
+ "CWE-20",
+ "CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/08/GHSA-482j-q2mw-67xq/GHSA-482j-q2mw-67xq.json b/advisories/unreviewed/2024/08/GHSA-482j-q2mw-67xq/GHSA-482j-q2mw-67xq.json
index 80f1a64ff40..e1f1610d745 100644
--- a/advisories/unreviewed/2024/08/GHSA-482j-q2mw-67xq/GHSA-482j-q2mw-67xq.json
+++ b/advisories/unreviewed/2024/08/GHSA-482j-q2mw-67xq/GHSA-482j-q2mw-67xq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-482j-q2mw-67xq",
- "modified": "2024-08-28T09:30:34Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-28T09:30:34Z",
"aliases": [
"CVE-2024-4555"
diff --git a/advisories/unreviewed/2024/08/GHSA-4j2g-pw4f-5hg9/GHSA-4j2g-pw4f-5hg9.json b/advisories/unreviewed/2024/08/GHSA-4j2g-pw4f-5hg9/GHSA-4j2g-pw4f-5hg9.json
index 186cd03f782..167fc189d54 100644
--- a/advisories/unreviewed/2024/08/GHSA-4j2g-pw4f-5hg9/GHSA-4j2g-pw4f-5hg9.json
+++ b/advisories/unreviewed/2024/08/GHSA-4j2g-pw4f-5hg9/GHSA-4j2g-pw4f-5hg9.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4j2g-pw4f-5hg9",
- "modified": "2024-08-22T03:31:34Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-22T03:31:34Z",
"aliases": [
"CVE-2022-48916"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Fix double list_add when enabling VMD in scalable mode\n\nWhen enabling VMD and IOMMU scalable mode, the following kernel panic\ncall trace/kernel log is shown in Eagle Stream platform (Sapphire Rapids\nCPU) during booting:\n\npci 0000:59:00.5: Adding to iommu group 42\n...\nvmd 0000:59:00.5: PCI host bridge to bus 10000:80\npci 10000:80:01.0: [8086:352a] type 01 class 0x060400\npci 10000:80:01.0: reg 0x10: [mem 0x00000000-0x0001ffff 64bit]\npci 10000:80:01.0: enabling Extended Tags\npci 10000:80:01.0: PME# supported from D0 D3hot D3cold\npci 10000:80:01.0: DMAR: Setup RID2PASID failed\npci 10000:80:01.0: Failed to add to iommu group 42: -16\npci 10000:80:03.0: [8086:352b] type 01 class 0x060400\npci 10000:80:03.0: reg 0x10: [mem 0x00000000-0x0001ffff 64bit]\npci 10000:80:03.0: enabling Extended Tags\npci 10000:80:03.0: PME# supported from D0 D3hot D3cold\n------------[ cut here ]------------\nkernel BUG at lib/list_debug.c:29!\ninvalid opcode: 0000 [#1] PREEMPT SMP NOPTI\nCPU: 0 PID: 7 Comm: kworker/0:1 Not tainted 5.17.0-rc3+ #7\nHardware name: Lenovo ThinkSystem SR650V3/SB27A86647, BIOS ESE101Y-1.00 01/13/2022\nWorkqueue: events work_for_cpu_fn\nRIP: 0010:__list_add_valid.cold+0x26/0x3f\nCode: 9a 4a ab ff 4c 89 c1 48 c7 c7 40 0c d9 9e e8 b9 b1 fe ff 0f\n 0b 48 89 f2 4c 89 c1 48 89 fe 48 c7 c7 f0 0c d9 9e e8 a2 b1\n fe ff <0f> 0b 48 89 d1 4c 89 c6 4c 89 ca 48 c7 c7 98 0c d9\n 9e e8 8b b1 fe\nRSP: 0000:ff5ad434865b3a40 EFLAGS: 00010246\nRAX: 0000000000000058 RBX: ff4d61160b74b880 RCX: ff4d61255e1fffa8\nRDX: 0000000000000000 RSI: 00000000fffeffff RDI: ffffffff9fd34f20\nRBP: ff4d611d8e245c00 R08: 0000000000000000 R09: ff5ad434865b3888\nR10: ff5ad434865b3880 R11: ff4d61257fdc6fe8 R12: ff4d61160b74b8a0\nR13: ff4d61160b74b8a0 R14: ff4d611d8e245c10 R15: ff4d611d8001ba70\nFS: 0000000000000000(0000) GS:ff4d611d5ea00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: ff4d611fa1401000 CR3: 0000000aa0210001 CR4: 0000000000771ef0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe07f0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n \n intel_pasid_alloc_table+0x9c/0x1d0\n dmar_insert_one_dev_info+0x423/0x540\n ? device_to_iommu+0x12d/0x2f0\n intel_iommu_attach_device+0x116/0x290\n __iommu_attach_device+0x1a/0x90\n iommu_group_add_device+0x190/0x2c0\n __iommu_probe_device+0x13e/0x250\n iommu_probe_device+0x24/0x150\n iommu_bus_notifier+0x69/0x90\n blocking_notifier_call_chain+0x5a/0x80\n device_add+0x3db/0x7b0\n ? arch_memremap_can_ram_remap+0x19/0x50\n ? memremap+0x75/0x140\n pci_device_add+0x193/0x1d0\n pci_scan_single_device+0xb9/0xf0\n pci_scan_slot+0x4c/0x110\n pci_scan_child_bus_extend+0x3a/0x290\n vmd_enable_domain.constprop.0+0x63e/0x820\n vmd_probe+0x163/0x190\n local_pci_probe+0x42/0x80\n work_for_cpu_fn+0x13/0x20\n process_one_work+0x1e2/0x3b0\n worker_thread+0x1c4/0x3a0\n ? rescuer_thread+0x370/0x370\n kthread+0xc7/0xf0\n ? kthread_complete_and_exit+0x20/0x20\n ret_from_fork+0x1f/0x30\n \nModules linked in:\n---[ end trace 0000000000000000 ]---\n...\nKernel panic - not syncing: Fatal exception\nKernel Offset: 0x1ca00000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff)\n---[ end Kernel panic - not syncing: Fatal exception ]---\n\nThe following 'lspci' output shows devices '10000:80:*' are subdevices of\nthe VMD device 0000:59:00.5:\n\n $ lspci\n ...\n 0000:59:00.5 RAID bus controller: Intel Corporation Volume Management Device NVMe RAID Controller (rev 20)\n ...\n 10000:80:01.0 PCI bridge: Intel Corporation Device 352a (rev 03)\n 10000:80:03.0 PCI bridge: Intel Corporation Device 352b (rev 03)\n 10000:80:05.0 PCI bridge: Intel Corporation Device 352c (rev 03)\n 10000:80:07.0 PCI bridge: Intel Corporation Device 352d (rev 03)\n 10000:81:00.0 Non-Volatile memory controller: Intel Corporation NVMe Datacenter SSD [3DNAND, Beta Rock Controller]\n 10000:82:00\n---truncated---",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -35,7 +38,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-22T02:15:05Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-57m4-x9jr-6j53/GHSA-57m4-x9jr-6j53.json b/advisories/unreviewed/2024/08/GHSA-57m4-x9jr-6j53/GHSA-57m4-x9jr-6j53.json
index 19d453dfe33..010f65fd6ca 100644
--- a/advisories/unreviewed/2024/08/GHSA-57m4-x9jr-6j53/GHSA-57m4-x9jr-6j53.json
+++ b/advisories/unreviewed/2024/08/GHSA-57m4-x9jr-6j53/GHSA-57m4-x9jr-6j53.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-57m4-x9jr-6j53",
- "modified": "2024-08-21T09:31:32Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-21T09:31:32Z",
"aliases": [
"CVE-2023-52914"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/poll: add hash if ready poll request can't complete inline\n\nIf we don't, then we may lose access to it completely, leading to a\nrequest leak. This will eventually stall the ring exit process as\nwell.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-401"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-21T07:15:07Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-59c7-3fh8-7mq3/GHSA-59c7-3fh8-7mq3.json b/advisories/unreviewed/2024/08/GHSA-59c7-3fh8-7mq3/GHSA-59c7-3fh8-7mq3.json
index dde0629e0a4..f55aea7119a 100644
--- a/advisories/unreviewed/2024/08/GHSA-59c7-3fh8-7mq3/GHSA-59c7-3fh8-7mq3.json
+++ b/advisories/unreviewed/2024/08/GHSA-59c7-3fh8-7mq3/GHSA-59c7-3fh8-7mq3.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-59c7-3fh8-7mq3",
- "modified": "2024-08-21T09:31:32Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-21T09:31:32Z",
"aliases": [
"CVE-2023-52911"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm: another fix for the headless Adreno GPU\n\nFix another oops reproducible when rebooting the board with the Adreno\nGPU working in the headless mode (e.g. iMX platforms).\n\nUnable to handle kernel NULL pointer dereference at virtual address 00000000 when read\n[00000000] *pgd=74936831, *pte=00000000, *ppte=00000000\nInternal error: Oops: 17 [#1] ARM\nCPU: 0 PID: 51 Comm: reboot Not tainted 6.2.0-rc1-dirty #11\nHardware name: Freescale i.MX53 (Device Tree Support)\nPC is at msm_atomic_commit_tail+0x50/0x970\nLR is at commit_tail+0x9c/0x188\npc : [] lr : [] psr: 600e0013\nsp : e0851d30 ip : ee4eb7eb fp : 00090acc\nr10: 00000058 r9 : c2193014 r8 : c4310000\nr7 : c4759380 r6 : 07bef61d r5 : 00000000 r4 : 00000000\nr3 : c44cc440 r2 : 00000000 r1 : 00000000 r0 : 00000000\nFlags: nZCv IRQs on FIQs on Mode SVC_32 ISA ARM Segment none\nControl: 10c5387d Table: 74910019 DAC: 00000051\nRegister r0 information: NULL pointer\nRegister r1 information: NULL pointer\nRegister r2 information: NULL pointer\nRegister r3 information: slab kmalloc-1k start c44cc400 pointer offset 64 size 1024\nRegister r4 information: NULL pointer\nRegister r5 information: NULL pointer\nRegister r6 information: non-paged memory\nRegister r7 information: slab kmalloc-128 start c4759380 pointer offset 0 size 128\nRegister r8 information: slab kmalloc-2k start c4310000 pointer offset 0 size 2048\nRegister r9 information: non-slab/vmalloc memory\nRegister r10 information: non-paged memory\nRegister r11 information: non-paged memory\nRegister r12 information: non-paged memory\nProcess reboot (pid: 51, stack limit = 0xc80046d9)\nStack: (0xe0851d30 to 0xe0852000)\n1d20: c4759380 fbd77200 000005ff 002b9c70\n1d40: c4759380 c4759380 00000000 07bef61d 00000600 c0d6fe7c c2193014 00000058\n1d60: 00090acc c067a214 00000000 c4759380 c4310000 00000000 c44cc854 c067a89c\n1d80: 00000000 00000000 00000000 c4310468 00000000 c4759380 c4310000 c4310468\n1da0: c4310470 c0643258 c4759380 00000000 00000000 c0c4ee24 00000000 c44cc810\n1dc0: 00000000 c0c4ee24 00000000 c44cc810 00000000 0347d2a8 e0851e00 e0851e00\n1de0: c4759380 c067ad20 c4310000 00000000 c44cc810 c27f8718 c44cc854 c067adb8\n1e00: c4933000 00000002 00000001 00000000 00000000 c2130850 00000000 c2130854\n1e20: c25fc488 00000000 c0ff162c 00000000 00000001 00000002 00000000 00000000\n1e40: c43102c0 c43102c0 00000000 0347d2a8 c44cc810 c44cc814 c2133da8 c06d1a60\n1e60: 00000000 00000000 00079028 c2012f24 fee1dead c4933000 00000058 c01431e4\n1e80: 01234567 c0143a20 00000000 00000000 00000000 00000000 00000000 00000000\n1ea0: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000\n1ec0: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000\n1ee0: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000\n1f00: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000\n1f20: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000\n1f40: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000\n1f60: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000\n1f80: 00000000 00000000 00000000 0347d2a8 00000002 00000004 00000078 00000058\n1fa0: c010028c c0100060 00000002 00000004 fee1dead 28121969 01234567 00079028\n1fc0: 00000002 00000004 00000078 00000058 0002fdc5 00000000 00000000 00090acc\n1fe0: 00000058 becc9c64 b6e97e05 b6e0e5f6 600e0030 fee1dead 00000000 00000000\n msm_atomic_commit_tail from commit_tail+0x9c/0x188\n commit_tail from drm_atomic_helper_commit+0x160/0x188\n drm_atomic_helper_commit from drm_atomic_commit+0xac/0xe0\n drm_atomic_commit from drm_atomic_helper_disable_all+0x1b0/0x1c0\n drm_atomic_helper_disable_all from drm_atomic_helper_shutdown+0x88/0x140\n drm_atomic_helper_shutdown from device_shutdown+0x16c/0x240\n device_shutdown from kernel_restart+0x38/0x90\n kernel_restart from __do_sys_reboot+0x\n---truncated---",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-476"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-21T07:15:06Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-6wp2-34q6-2gfj/GHSA-6wp2-34q6-2gfj.json b/advisories/unreviewed/2024/08/GHSA-6wp2-34q6-2gfj/GHSA-6wp2-34q6-2gfj.json
index b9bf14fe297..017fda24c3c 100644
--- a/advisories/unreviewed/2024/08/GHSA-6wp2-34q6-2gfj/GHSA-6wp2-34q6-2gfj.json
+++ b/advisories/unreviewed/2024/08/GHSA-6wp2-34q6-2gfj/GHSA-6wp2-34q6-2gfj.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6wp2-34q6-2gfj",
- "modified": "2024-08-21T09:31:32Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-21T09:31:32Z",
"aliases": [
"CVE-2023-52913"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915: Fix potential context UAFs\n\ngem_context_register() makes the context visible to userspace, and which\npoint a separate thread can trigger the I915_GEM_CONTEXT_DESTROY ioctl.\nSo we need to ensure that nothing uses the ctx ptr after this. And we\nneed to ensure that adding the ctx to the xarray is the *last* thing\nthat gem_context_register() does with the ctx pointer.\n\n[tursulin: Stable and fixes tags add/tidy.]\n(cherry picked from commit bed4b455cf5374e68879be56971c1da563bcd90c)",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-416"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-21T07:15:07Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-7vcc-f42v-gv2x/GHSA-7vcc-f42v-gv2x.json b/advisories/unreviewed/2024/08/GHSA-7vcc-f42v-gv2x/GHSA-7vcc-f42v-gv2x.json
index 3f541c2673a..c6aadcafa6c 100644
--- a/advisories/unreviewed/2024/08/GHSA-7vcc-f42v-gv2x/GHSA-7vcc-f42v-gv2x.json
+++ b/advisories/unreviewed/2024/08/GHSA-7vcc-f42v-gv2x/GHSA-7vcc-f42v-gv2x.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7vcc-f42v-gv2x",
- "modified": "2024-08-22T03:31:34Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-22T03:31:34Z",
"aliases": [
"CVE-2022-48911"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_queue: fix possible use-after-free\n\nEric Dumazet says:\n The sock_hold() side seems suspect, because there is no guarantee\n that sk_refcnt is not already 0.\n\nOn failure, we cannot queue the packet and need to indicate an\nerror. The packet will be dropped by the caller.\n\nv2: split skb prefetch hunk into separate change",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -53,9 +56,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-416"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-22T02:15:05Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-8332-m7c6-g7c2/GHSA-8332-m7c6-g7c2.json b/advisories/unreviewed/2024/08/GHSA-8332-m7c6-g7c2/GHSA-8332-m7c6-g7c2.json
index 10bc5c8c35c..8c6cfc2ecad 100644
--- a/advisories/unreviewed/2024/08/GHSA-8332-m7c6-g7c2/GHSA-8332-m7c6-g7c2.json
+++ b/advisories/unreviewed/2024/08/GHSA-8332-m7c6-g7c2/GHSA-8332-m7c6-g7c2.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8332-m7c6-g7c2",
- "modified": "2024-08-21T09:31:32Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-21T09:31:32Z",
"aliases": [
"CVE-2023-52908"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix potential NULL dereference\n\nFix potential NULL dereference, in the case when \"man\", the resource manager\nmight be NULL, when/if we print debug information.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-476"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-21T07:15:06Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-8f4h-jjh9-fxrx/GHSA-8f4h-jjh9-fxrx.json b/advisories/unreviewed/2024/08/GHSA-8f4h-jjh9-fxrx/GHSA-8f4h-jjh9-fxrx.json
index 3e3851c3df9..b4493f5a6df 100644
--- a/advisories/unreviewed/2024/08/GHSA-8f4h-jjh9-fxrx/GHSA-8f4h-jjh9-fxrx.json
+++ b/advisories/unreviewed/2024/08/GHSA-8f4h-jjh9-fxrx/GHSA-8f4h-jjh9-fxrx.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8f4h-jjh9-fxrx",
- "modified": "2024-08-29T18:31:35Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-26T12:31:20Z",
"aliases": [
"CVE-2024-44938"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\njfs: Fix shift-out-of-bounds in dbDiscardAG\n\nWhen searching for the next smaller log2 block, BLKSTOL2() returned 0,\ncausing shift exponent -1 to be negative.\n\nThis patch fixes the issue by exiting the loop directly when negative\nshift is found.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-787"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-26T12:15:05Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-8qr8-pjqc-9jxp/GHSA-8qr8-pjqc-9jxp.json b/advisories/unreviewed/2024/08/GHSA-8qr8-pjqc-9jxp/GHSA-8qr8-pjqc-9jxp.json
index 378efa82fa0..9f4c02fc94f 100644
--- a/advisories/unreviewed/2024/08/GHSA-8qr8-pjqc-9jxp/GHSA-8qr8-pjqc-9jxp.json
+++ b/advisories/unreviewed/2024/08/GHSA-8qr8-pjqc-9jxp/GHSA-8qr8-pjqc-9jxp.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8qr8-pjqc-9jxp",
- "modified": "2024-08-22T03:31:34Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-22T03:31:34Z",
"aliases": [
"CVE-2022-48923"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: prevent copying too big compressed lzo segment\n\nCompressed length can be corrupted to be a lot larger than memory\nwe have allocated for buffer.\nThis will cause memcpy in copy_compressed_segment to write outside\nof allocated memory.\n\nThis mostly results in stuck read syscall but sometimes when using\nbtrfs send can get #GP\n\n kernel: general protection fault, probably for non-canonical address 0x841551d5c1000: 0000 [#1] PREEMPT SMP NOPTI\n kernel: CPU: 17 PID: 264 Comm: kworker/u256:7 Tainted: P OE 5.17.0-rc2-1 #12\n kernel: Workqueue: btrfs-endio btrfs_work_helper [btrfs]\n kernel: RIP: 0010:lzo_decompress_bio (./include/linux/fortify-string.h:225 fs/btrfs/lzo.c:322 fs/btrfs/lzo.c:394) btrfs\n Code starting with the faulting instruction\n ===========================================\n 0:* 48 8b 06 mov (%rsi),%rax <-- trapping instruction\n 3: 48 8d 79 08 lea 0x8(%rcx),%rdi\n 7: 48 83 e7 f8 and $0xfffffffffffffff8,%rdi\n b: 48 89 01 mov %rax,(%rcx)\n e: 44 89 f0 mov %r14d,%eax\n 11: 48 8b 54 06 f8 mov -0x8(%rsi,%rax,1),%rdx\n kernel: RSP: 0018:ffffb110812efd50 EFLAGS: 00010212\n kernel: RAX: 0000000000001000 RBX: 000000009ca264c8 RCX: ffff98996e6d8ff8\n kernel: RDX: 0000000000000064 RSI: 000841551d5c1000 RDI: ffffffff9500435d\n kernel: RBP: ffff989a3be856c0 R08: 0000000000000000 R09: 0000000000000000\n kernel: R10: 0000000000000000 R11: 0000000000001000 R12: ffff98996e6d8000\n kernel: R13: 0000000000000008 R14: 0000000000001000 R15: 000841551d5c1000\n kernel: FS: 0000000000000000(0000) GS:ffff98a09d640000(0000) knlGS:0000000000000000\n kernel: CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n kernel: CR2: 00001e9f984d9ea8 CR3: 000000014971a000 CR4: 00000000003506e0\n kernel: Call Trace:\n kernel: \n kernel: end_compressed_bio_read (fs/btrfs/compression.c:104 fs/btrfs/compression.c:1363 fs/btrfs/compression.c:323) btrfs\n kernel: end_workqueue_fn (fs/btrfs/disk-io.c:1923) btrfs\n kernel: btrfs_work_helper (fs/btrfs/async-thread.c:326) btrfs\n kernel: process_one_work (./arch/x86/include/asm/jump_label.h:27 ./include/linux/jump_label.h:212 ./include/trace/events/workqueue.h:108 kernel/workqueue.c:2312)\n kernel: worker_thread (./include/linux/list.h:292 kernel/workqueue.c:2455)\n kernel: ? process_one_work (kernel/workqueue.c:2397)\n kernel: kthread (kernel/kthread.c:377)\n kernel: ? kthread_complete_and_exit (kernel/kthread.c:332)\n kernel: ret_from_fork (arch/x86/entry/entry_64.S:301)\n kernel: ",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-787"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-22T02:15:08Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-cp24-c7w4-6gh4/GHSA-cp24-c7w4-6gh4.json b/advisories/unreviewed/2024/08/GHSA-cp24-c7w4-6gh4/GHSA-cp24-c7w4-6gh4.json
index 24803713429..a4dadd2473d 100644
--- a/advisories/unreviewed/2024/08/GHSA-cp24-c7w4-6gh4/GHSA-cp24-c7w4-6gh4.json
+++ b/advisories/unreviewed/2024/08/GHSA-cp24-c7w4-6gh4/GHSA-cp24-c7w4-6gh4.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cp24-c7w4-6gh4",
- "modified": "2024-08-22T03:31:34Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-22T03:31:34Z",
"aliases": [
"CVE-2022-48908"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: arcnet: com20020: Fix null-ptr-deref in com20020pci_probe()\n\nDuring driver initialization, the pointer of card info, i.e. the\nvariable 'ci' is required. However, the definition of\n'com20020pci_id_table' reveals that this field is empty for some\ndevices, which will cause null pointer dereference when initializing\nthese devices.\n\nThe following log reveals it:\n\n[ 3.973806] KASAN: null-ptr-deref in range [0x0000000000000028-0x000000000000002f]\n[ 3.973819] RIP: 0010:com20020pci_probe+0x18d/0x13e0 [com20020_pci]\n[ 3.975181] Call Trace:\n[ 3.976208] local_pci_probe+0x13f/0x210\n[ 3.977248] pci_device_probe+0x34c/0x6d0\n[ 3.977255] ? pci_uevent+0x470/0x470\n[ 3.978265] really_probe+0x24c/0x8d0\n[ 3.978273] __driver_probe_device+0x1b3/0x280\n[ 3.979288] driver_probe_device+0x50/0x370\n\nFix this by checking whether the 'ci' is a null pointer first.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -53,9 +56,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-476"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-22T02:15:05Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-cp82-8q86-pm99/GHSA-cp82-8q86-pm99.json b/advisories/unreviewed/2024/08/GHSA-cp82-8q86-pm99/GHSA-cp82-8q86-pm99.json
index 86da7c55243..995f67d8d74 100644
--- a/advisories/unreviewed/2024/08/GHSA-cp82-8q86-pm99/GHSA-cp82-8q86-pm99.json
+++ b/advisories/unreviewed/2024/08/GHSA-cp82-8q86-pm99/GHSA-cp82-8q86-pm99.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cp82-8q86-pm99",
- "modified": "2024-08-22T03:31:34Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-22T03:31:34Z",
"aliases": [
"CVE-2022-48922"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: fix oops caused by irqsoff latency tracer\n\nThe trace_hardirqs_{on,off}() require the caller to setup frame pointer\nproperly. This because these two functions use macro 'CALLER_ADDR1' (aka.\n__builtin_return_address(1)) to acquire caller info. If the $fp is used\nfor other purpose, the code generated this macro (as below) could trigger\nmemory access fault.\n\n 0xffffffff8011510e <+80>: ld a1,-16(s0)\n 0xffffffff80115112 <+84>: ld s2,-8(a1) # <-- paging fault here\n\nThe oops message during booting if compiled with 'irqoff' tracer enabled:\n[ 0.039615][ T0] Unable to handle kernel NULL pointer dereference at virtual address 00000000000000f8\n[ 0.041925][ T0] Oops [#1]\n[ 0.042063][ T0] Modules linked in:\n[ 0.042864][ T0] CPU: 0 PID: 0 Comm: swapper/0 Not tainted 5.17.0-rc1-00233-g9a20c48d1ed2 #29\n[ 0.043568][ T0] Hardware name: riscv-virtio,qemu (DT)\n[ 0.044343][ T0] epc : trace_hardirqs_on+0x56/0xe2\n[ 0.044601][ T0] ra : restore_all+0x12/0x6e\n[ 0.044721][ T0] epc : ffffffff80126a5c ra : ffffffff80003b94 sp : ffffffff81403db0\n[ 0.044801][ T0] gp : ffffffff8163acd8 tp : ffffffff81414880 t0 : 0000000000000020\n[ 0.044882][ T0] t1 : 0098968000000000 t2 : 0000000000000000 s0 : ffffffff81403de0\n[ 0.044967][ T0] s1 : 0000000000000000 a0 : 0000000000000001 a1 : 0000000000000100\n[ 0.045046][ T0] a2 : 0000000000000000 a3 : 0000000000000000 a4 : 0000000000000000\n[ 0.045124][ T0] a5 : 0000000000000000 a6 : 0000000000000000 a7 : 0000000054494d45\n[ 0.045210][ T0] s2 : ffffffff80003b94 s3 : ffffffff81a8f1b0 s4 : ffffffff80e27b50\n[ 0.045289][ T0] s5 : ffffffff81414880 s6 : ffffffff8160fa00 s7 : 00000000800120e8\n[ 0.045389][ T0] s8 : 0000000080013100 s9 : 000000000000007f s10: 0000000000000000\n[ 0.045474][ T0] s11: 0000000000000000 t3 : 7fffffffffffffff t4 : 0000000000000000\n[ 0.045548][ T0] t5 : 0000000000000000 t6 : ffffffff814aa368\n[ 0.045620][ T0] status: 0000000200000100 badaddr: 00000000000000f8 cause: 000000000000000d\n[ 0.046402][ T0] [] restore_all+0x12/0x6e\n\nThis because the $fp(aka. $s0) register is not used as frame pointer in the\nassembly entry code.\n\n\tresume_kernel:\n\t\tREG_L s0, TASK_TI_PREEMPT_COUNT(tp)\n\t\tbnez s0, restore_all\n\t\tREG_L s0, TASK_TI_FLAGS(tp)\n andi s0, s0, _TIF_NEED_RESCHED\n beqz s0, restore_all\n call preempt_schedule_irq\n j restore_all\n\nTo fix above issue, here we add one extra level wrapper for function\ntrace_hardirqs_{on,off}() so they can be safely called by low level entry\ncode.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-476"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-22T02:15:08Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-cvq3-56r9-hh2h/GHSA-cvq3-56r9-hh2h.json b/advisories/unreviewed/2024/08/GHSA-cvq3-56r9-hh2h/GHSA-cvq3-56r9-hh2h.json
index 4059e605b87..af5a5ca1e7e 100644
--- a/advisories/unreviewed/2024/08/GHSA-cvq3-56r9-hh2h/GHSA-cvq3-56r9-hh2h.json
+++ b/advisories/unreviewed/2024/08/GHSA-cvq3-56r9-hh2h/GHSA-cvq3-56r9-hh2h.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cvq3-56r9-hh2h",
- "modified": "2024-08-22T03:31:34Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-22T03:31:33Z",
"aliases": [
"CVE-2022-48907"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nauxdisplay: lcd2s: Fix memory leak in ->remove()\n\nOnce allocated the struct lcd2s_data is never freed.\nFix the memory leak by switching to devm_kzalloc().",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-401"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-22T02:15:05Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-cxj4-mqwg-88f8/GHSA-cxj4-mqwg-88f8.json b/advisories/unreviewed/2024/08/GHSA-cxj4-mqwg-88f8/GHSA-cxj4-mqwg-88f8.json
index 77492d95e47..ce368d84f3d 100644
--- a/advisories/unreviewed/2024/08/GHSA-cxj4-mqwg-88f8/GHSA-cxj4-mqwg-88f8.json
+++ b/advisories/unreviewed/2024/08/GHSA-cxj4-mqwg-88f8/GHSA-cxj4-mqwg-88f8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cxj4-mqwg-88f8",
- "modified": "2024-08-28T09:30:34Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-28T09:30:34Z",
"aliases": [
"CVE-2024-4554"
@@ -32,7 +32,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-20"
+ "CWE-20",
+ "CWE-79"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/08/GHSA-f5pw-c669-x4x7/GHSA-f5pw-c669-x4x7.json b/advisories/unreviewed/2024/08/GHSA-f5pw-c669-x4x7/GHSA-f5pw-c669-x4x7.json
index b706ceb38b1..42eed320431 100644
--- a/advisories/unreviewed/2024/08/GHSA-f5pw-c669-x4x7/GHSA-f5pw-c669-x4x7.json
+++ b/advisories/unreviewed/2024/08/GHSA-f5pw-c669-x4x7/GHSA-f5pw-c669-x4x7.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f5pw-c669-x4x7",
- "modified": "2024-08-21T09:31:32Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-21T09:31:32Z",
"aliases": [
"CVE-2023-52910"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/iova: Fix alloc iova overflows issue\n\nIn __alloc_and_insert_iova_range, there is an issue that retry_pfn\noverflows. The value of iovad->anchor.pfn_hi is ~0UL, then when\niovad->cached_node is iovad->anchor, curr_iova->pfn_hi + 1 will\noverflow. As a result, if the retry logic is executed, low_pfn is\nupdated to 0, and then new_pfn < low_pfn returns false to make the\nallocation successful.\n\nThis issue occurs in the following two situations:\n1. The first iova size exceeds the domain size. When initializing\niova domain, iovad->cached_node is assigned as iovad->anchor. For\nexample, the iova domain size is 10M, start_pfn is 0x1_F000_0000,\nand the iova size allocated for the first time is 11M. The\nfollowing is the log information, new->pfn_lo is smaller than\niovad->cached_node.\n\nExample log as follows:\n[ 223.798112][T1705487] sh: [name:iova&]__alloc_and_insert_iova_range\nstart_pfn:0x1f0000,retry_pfn:0x0,size:0xb00,limit_pfn:0x1f0a00\n[ 223.799590][T1705487] sh: [name:iova&]__alloc_and_insert_iova_range\nsuccess start_pfn:0x1f0000,new->pfn_lo:0x1efe00,new->pfn_hi:0x1f08ff\n\n2. The node with the largest iova->pfn_lo value in the iova domain\nis deleted, iovad->cached_node will be updated to iovad->anchor,\nand then the alloc iova size exceeds the maximum iova size that can\nbe allocated in the domain.\n\nAfter judging that retry_pfn is less than limit_pfn, call retry_pfn+1\nto fix the overflow issue.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -35,7 +38,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-21T07:15:06Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-h5r9-xw9c-j3f7/GHSA-h5r9-xw9c-j3f7.json b/advisories/unreviewed/2024/08/GHSA-h5r9-xw9c-j3f7/GHSA-h5r9-xw9c-j3f7.json
index 7cce59d6144..f71d50ba23d 100644
--- a/advisories/unreviewed/2024/08/GHSA-h5r9-xw9c-j3f7/GHSA-h5r9-xw9c-j3f7.json
+++ b/advisories/unreviewed/2024/08/GHSA-h5r9-xw9c-j3f7/GHSA-h5r9-xw9c-j3f7.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h5r9-xw9c-j3f7",
- "modified": "2024-08-22T03:31:34Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-22T03:31:33Z",
"aliases": [
"CVE-2022-48903"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix relocation crash due to premature return from btrfs_commit_transaction()\n\nWe are seeing crashes similar to the following trace:\n\n[38.969182] WARNING: CPU: 20 PID: 2105 at fs/btrfs/relocation.c:4070 btrfs_relocate_block_group+0x2dc/0x340 [btrfs]\n[38.973556] CPU: 20 PID: 2105 Comm: btrfs Not tainted 5.17.0-rc4 #54\n[38.974580] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.12.0-59-gc9ba5276e321-prebuilt.qemu.org 04/01/2014\n[38.976539] RIP: 0010:btrfs_relocate_block_group+0x2dc/0x340 [btrfs]\n[38.980336] RSP: 0000:ffffb0dd42e03c20 EFLAGS: 00010206\n[38.981218] RAX: ffff96cfc4ede800 RBX: ffff96cfc3ce0000 RCX: 000000000002ca14\n[38.982560] RDX: 0000000000000000 RSI: 4cfd109a0bcb5d7f RDI: ffff96cfc3ce0360\n[38.983619] RBP: ffff96cfc309c000 R08: 0000000000000000 R09: 0000000000000000\n[38.984678] R10: ffff96cec0000001 R11: ffffe84c80000000 R12: ffff96cfc4ede800\n[38.985735] R13: 0000000000000000 R14: 0000000000000000 R15: ffff96cfc3ce0360\n[38.987146] FS: 00007f11c15218c0(0000) GS:ffff96d6dfb00000(0000) knlGS:0000000000000000\n[38.988662] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[38.989398] CR2: 00007ffc922c8e60 CR3: 00000001147a6001 CR4: 0000000000370ee0\n[38.990279] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[38.991219] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[38.992528] Call Trace:\n[38.992854] \n[38.993148] btrfs_relocate_chunk+0x27/0xe0 [btrfs]\n[38.993941] btrfs_balance+0x78e/0xea0 [btrfs]\n[38.994801] ? vsnprintf+0x33c/0x520\n[38.995368] ? __kmalloc_track_caller+0x351/0x440\n[38.996198] btrfs_ioctl_balance+0x2b9/0x3a0 [btrfs]\n[38.997084] btrfs_ioctl+0x11b0/0x2da0 [btrfs]\n[38.997867] ? mod_objcg_state+0xee/0x340\n[38.998552] ? seq_release+0x24/0x30\n[38.999184] ? proc_nr_files+0x30/0x30\n[38.999654] ? call_rcu+0xc8/0x2f0\n[39.000228] ? __x64_sys_ioctl+0x84/0xc0\n[39.000872] ? btrfs_ioctl_get_supported_features+0x30/0x30 [btrfs]\n[39.001973] __x64_sys_ioctl+0x84/0xc0\n[39.002566] do_syscall_64+0x3a/0x80\n[39.003011] entry_SYSCALL_64_after_hwframe+0x44/0xae\n[39.003735] RIP: 0033:0x7f11c166959b\n[39.007324] RSP: 002b:00007fff2543e998 EFLAGS: 00000246 ORIG_RAX: 0000000000000010\n[39.008521] RAX: ffffffffffffffda RBX: 00007f11c1521698 RCX: 00007f11c166959b\n[39.009833] RDX: 00007fff2543ea40 RSI: 00000000c4009420 RDI: 0000000000000003\n[39.011270] RBP: 0000000000000003 R08: 0000000000000013 R09: 00007f11c16f94e0\n[39.012581] R10: 0000000000000000 R11: 0000000000000246 R12: 00007fff25440df3\n[39.014046] R13: 0000000000000000 R14: 00007fff2543ea40 R15: 0000000000000001\n[39.015040] \n[39.015418] ---[ end trace 0000000000000000 ]---\n[43.131559] ------------[ cut here ]------------\n[43.132234] kernel BUG at fs/btrfs/extent-tree.c:2717!\n[43.133031] invalid opcode: 0000 [#1] PREEMPT SMP PTI\n[43.133702] CPU: 1 PID: 1839 Comm: btrfs Tainted: G W 5.17.0-rc4 #54\n[43.134863] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.12.0-59-gc9ba5276e321-prebuilt.qemu.org 04/01/2014\n[43.136426] RIP: 0010:unpin_extent_range+0x37a/0x4f0 [btrfs]\n[43.139913] RSP: 0000:ffffb0dd4216bc70 EFLAGS: 00010246\n[43.140629] RAX: 0000000000000000 RBX: ffff96cfc34490f8 RCX: 0000000000000001\n[43.141604] RDX: 0000000080000001 RSI: 0000000051d00000 RDI: 00000000ffffffff\n[43.142645] RBP: 0000000000000000 R08: 0000000000000000 R09: ffff96cfd07dca50\n[43.143669] R10: ffff96cfc46e8a00 R11: fffffffffffec000 R12: 0000000041d00000\n[43.144657] R13: ffff96cfc3ce0000 R14: ffffb0dd4216bd08 R15: 0000000000000000\n[43.145686] FS: 00007f7657dd68c0(0000) GS:ffff96d6df640000(0000) knlGS:0000000000000000\n[43.146808] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[43.147584] CR2: 00007f7fe81bf5b0 CR3: 00000001093ee004 CR4: 0000000000370ee0\n[43.148589] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[43.149581] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 00000000000\n---truncated---",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -35,7 +38,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-22T02:15:04Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-hq36-r5x9-pmq2/GHSA-hq36-r5x9-pmq2.json b/advisories/unreviewed/2024/08/GHSA-hq36-r5x9-pmq2/GHSA-hq36-r5x9-pmq2.json
index 95b85574a16..e6d11d0724e 100644
--- a/advisories/unreviewed/2024/08/GHSA-hq36-r5x9-pmq2/GHSA-hq36-r5x9-pmq2.json
+++ b/advisories/unreviewed/2024/08/GHSA-hq36-r5x9-pmq2/GHSA-hq36-r5x9-pmq2.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hq36-r5x9-pmq2",
- "modified": "2024-08-22T03:31:33Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-22T03:31:33Z",
"aliases": [
"CVE-2022-48901"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: do not start relocation until in progress drops are done\n\nWe hit a bug with a recovering relocation on mount for one of our file\nsystems in production. I reproduced this locally by injecting errors\ninto snapshot delete with balance running at the same time. This\npresented as an error while looking up an extent item\n\n WARNING: CPU: 5 PID: 1501 at fs/btrfs/extent-tree.c:866 lookup_inline_extent_backref+0x647/0x680\n CPU: 5 PID: 1501 Comm: btrfs-balance Not tainted 5.16.0-rc8+ #8\n RIP: 0010:lookup_inline_extent_backref+0x647/0x680\n RSP: 0018:ffffae0a023ab960 EFLAGS: 00010202\n RAX: 0000000000000001 RBX: 0000000000000000 RCX: 0000000000000000\n RDX: 0000000000000000 RSI: 000000000000000c RDI: 0000000000000000\n RBP: ffff943fd2a39b60 R08: 0000000000000000 R09: 0000000000000001\n R10: 0001434088152de0 R11: 0000000000000000 R12: 0000000001d05000\n R13: ffff943fd2a39b60 R14: ffff943fdb96f2a0 R15: ffff9442fc923000\n FS: 0000000000000000(0000) GS:ffff944e9eb40000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007f1157b1fca8 CR3: 000000010f092000 CR4: 0000000000350ee0\n Call Trace:\n \n insert_inline_extent_backref+0x46/0xd0\n __btrfs_inc_extent_ref.isra.0+0x5f/0x200\n ? btrfs_merge_delayed_refs+0x164/0x190\n __btrfs_run_delayed_refs+0x561/0xfa0\n ? btrfs_search_slot+0x7b4/0xb30\n ? btrfs_update_root+0x1a9/0x2c0\n btrfs_run_delayed_refs+0x73/0x1f0\n ? btrfs_update_root+0x1a9/0x2c0\n btrfs_commit_transaction+0x50/0xa50\n ? btrfs_update_reloc_root+0x122/0x220\n prepare_to_merge+0x29f/0x320\n relocate_block_group+0x2b8/0x550\n btrfs_relocate_block_group+0x1a6/0x350\n btrfs_relocate_chunk+0x27/0xe0\n btrfs_balance+0x777/0xe60\n balance_kthread+0x35/0x50\n ? btrfs_balance+0xe60/0xe60\n kthread+0x16b/0x190\n ? set_kthread_struct+0x40/0x40\n ret_from_fork+0x22/0x30\n \n\nNormally snapshot deletion and relocation are excluded from running at\nthe same time by the fs_info->cleaner_mutex. However if we had a\npending balance waiting to get the ->cleaner_mutex, and a snapshot\ndeletion was running, and then the box crashed, we would come up in a\nstate where we have a half deleted snapshot.\n\nAgain, in the normal case the snapshot deletion needs to complete before\nrelocation can start, but in this case relocation could very well start\nbefore the snapshot deletion completes, as we simply add the root to the\ndead roots list and wait for the next time the cleaner runs to clean up\nthe snapshot.\n\nFix this by setting a bit on the fs_info if we have any DEAD_ROOT's that\nhad a pending drop_progress key. If they do then we know we were in the\nmiddle of the drop operation and set a flag on the fs_info. Then\nbalance can wait until this flag is cleared to start up again.\n\nIf there are DEAD_ROOT's that don't have a drop_progress set then we're\nsafe to start balance right away as we'll be properly protected by the\ncleaner_mutex.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -35,7 +38,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-22T02:15:04Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-jch5-qv3h-cm6v/GHSA-jch5-qv3h-cm6v.json b/advisories/unreviewed/2024/08/GHSA-jch5-qv3h-cm6v/GHSA-jch5-qv3h-cm6v.json
index a84afa9e662..b44a05ec85c 100644
--- a/advisories/unreviewed/2024/08/GHSA-jch5-qv3h-cm6v/GHSA-jch5-qv3h-cm6v.json
+++ b/advisories/unreviewed/2024/08/GHSA-jch5-qv3h-cm6v/GHSA-jch5-qv3h-cm6v.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jch5-qv3h-cm6v",
- "modified": "2024-08-22T03:31:33Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-22T03:31:33Z",
"aliases": [
"CVE-2022-48902"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: do not WARN_ON() if we have PageError set\n\nWhenever we do any extent buffer operations we call\nassert_eb_page_uptodate() to complain loudly if we're operating on an\nnon-uptodate page. Our overnight tests caught this warning earlier this\nweek\n\n WARNING: CPU: 1 PID: 553508 at fs/btrfs/extent_io.c:6849 assert_eb_page_uptodate+0x3f/0x50\n CPU: 1 PID: 553508 Comm: kworker/u4:13 Tainted: G W 5.17.0-rc3+ #564\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.13.0-2.fc32 04/01/2014\n Workqueue: btrfs-cache btrfs_work_helper\n RIP: 0010:assert_eb_page_uptodate+0x3f/0x50\n RSP: 0018:ffffa961440a7c68 EFLAGS: 00010246\n RAX: 0017ffffc0002112 RBX: ffffe6e74453f9c0 RCX: 0000000000001000\n RDX: ffffe6e74467c887 RSI: ffffe6e74453f9c0 RDI: ffff8d4c5efc2fc0\n RBP: 0000000000000d56 R08: ffff8d4d4a224000 R09: 0000000000000000\n R10: 00015817fa9d1ef0 R11: 000000000000000c R12: 00000000000007b1\n R13: ffff8d4c5efc2fc0 R14: 0000000001500000 R15: 0000000001cb1000\n FS: 0000000000000000(0000) GS:ffff8d4dbbd00000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007ff31d3448d8 CR3: 0000000118be8004 CR4: 0000000000370ee0\n Call Trace:\n\n extent_buffer_test_bit+0x3f/0x70\n free_space_test_bit+0xa6/0xc0\n load_free_space_tree+0x1f6/0x470\n caching_thread+0x454/0x630\n ? rcu_read_lock_sched_held+0x12/0x60\n ? rcu_read_lock_sched_held+0x12/0x60\n ? rcu_read_lock_sched_held+0x12/0x60\n ? lock_release+0x1f0/0x2d0\n btrfs_work_helper+0xf2/0x3e0\n ? lock_release+0x1f0/0x2d0\n ? finish_task_switch.isra.0+0xf9/0x3a0\n process_one_work+0x26d/0x580\n ? process_one_work+0x580/0x580\n worker_thread+0x55/0x3b0\n ? process_one_work+0x580/0x580\n kthread+0xf0/0x120\n ? kthread_complete_and_exit+0x20/0x20\n ret_from_fork+0x1f/0x30\n\nThis was partially fixed by c2e39305299f01 (\"btrfs: clear extent buffer\nuptodate when we fail to write it\"), however all that fix did was keep\nus from finding extent buffers after a failed writeout. It didn't keep\nus from continuing to use a buffer that we already had found.\n\nIn this case we're searching the commit root to cache the block group,\nso we can start committing the transaction and switch the commit root\nand then start writing. After the switch we can look up an extent\nbuffer that hasn't been written yet and start processing that block\ngroup. Then we fail to write that block out and clear Uptodate on the\npage, and then we start spewing these errors.\n\nNormally we're protected by the tree lock to a certain degree here. If\nwe read a block we have that block read locked, and we block the writer\nfrom locking the block before we submit it for the write. However this\nisn't necessarily fool proof because the read could happen before we do\nthe submit_bio and after we locked and unlocked the extent buffer.\n\nAlso in this particular case we have path->skip_locking set, so that\nwon't save us here. We'll simply get a block that was valid when we\nread it, but became invalid while we were using it.\n\nWhat we really want is to catch the case where we've \"read\" a block but\nit's not marked Uptodate. On read we ClearPageError(), so if we're\n!Uptodate and !Error we know we didn't do the right thing for reading\nthe page.\n\nFix this by checking !Uptodate && !Error, this way we will not complain\nif our buffer gets invalidated while we're using it, and we'll maintain\nthe spirit of the check which is to make sure we have a fully in-cache\nblock while we're messing with it.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -35,7 +38,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-22T02:15:04Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-m65f-mmqm-4fq6/GHSA-m65f-mmqm-4fq6.json b/advisories/unreviewed/2024/08/GHSA-m65f-mmqm-4fq6/GHSA-m65f-mmqm-4fq6.json
index d2456ae7b6a..e1e42297b21 100644
--- a/advisories/unreviewed/2024/08/GHSA-m65f-mmqm-4fq6/GHSA-m65f-mmqm-4fq6.json
+++ b/advisories/unreviewed/2024/08/GHSA-m65f-mmqm-4fq6/GHSA-m65f-mmqm-4fq6.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m65f-mmqm-4fq6",
- "modified": "2024-08-22T03:31:34Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-22T03:31:34Z",
"aliases": [
"CVE-2022-48920"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: get rid of warning on transaction commit when using flushoncommit\n\nWhen using the flushoncommit mount option, during almost every transaction\ncommit we trigger a warning from __writeback_inodes_sb_nr():\n\n $ cat fs/fs-writeback.c:\n (...)\n static void __writeback_inodes_sb_nr(struct super_block *sb, ...\n {\n (...)\n WARN_ON(!rwsem_is_locked(&sb->s_umount));\n (...)\n }\n (...)\n\nThe trace produced in dmesg looks like the following:\n\n [947.473890] WARNING: CPU: 5 PID: 930 at fs/fs-writeback.c:2610 __writeback_inodes_sb_nr+0x7e/0xb3\n [947.481623] Modules linked in: nfsd nls_cp437 cifs asn1_decoder cifs_arc4 fscache cifs_md4 ipmi_ssif\n [947.489571] CPU: 5 PID: 930 Comm: btrfs-transacti Not tainted 95.16.3-srb-asrock-00001-g36437ad63879 #186\n [947.497969] RIP: 0010:__writeback_inodes_sb_nr+0x7e/0xb3\n [947.502097] Code: 24 10 4c 89 44 24 18 c6 (...)\n [947.519760] RSP: 0018:ffffc90000777e10 EFLAGS: 00010246\n [947.523818] RAX: 0000000000000000 RBX: 0000000000963300 RCX: 0000000000000000\n [947.529765] RDX: 0000000000000000 RSI: 000000000000fa51 RDI: ffffc90000777e50\n [947.535740] RBP: ffff888101628a90 R08: ffff888100955800 R09: ffff888100956000\n [947.541701] R10: 0000000000000002 R11: 0000000000000001 R12: ffff888100963488\n [947.547645] R13: ffff888100963000 R14: ffff888112fb7200 R15: ffff888100963460\n [947.553621] FS: 0000000000000000(0000) GS:ffff88841fd40000(0000) knlGS:0000000000000000\n [947.560537] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n [947.565122] CR2: 0000000008be50c4 CR3: 000000000220c000 CR4: 00000000001006e0\n [947.571072] Call Trace:\n [947.572354] \n [947.573266] btrfs_commit_transaction+0x1f1/0x998\n [947.576785] ? start_transaction+0x3ab/0x44e\n [947.579867] ? schedule_timeout+0x8a/0xdd\n [947.582716] transaction_kthread+0xe9/0x156\n [947.585721] ? btrfs_cleanup_transaction.isra.0+0x407/0x407\n [947.590104] kthread+0x131/0x139\n [947.592168] ? set_kthread_struct+0x32/0x32\n [947.595174] ret_from_fork+0x22/0x30\n [947.597561] \n [947.598553] ---[ end trace 644721052755541c ]---\n\nThis is because we started using writeback_inodes_sb() to flush delalloc\nwhen committing a transaction (when using -o flushoncommit), in order to\navoid deadlocks with filesystem freeze operations. This change was made\nby commit ce8ea7cc6eb313 (\"btrfs: don't call btrfs_start_delalloc_roots\nin flushoncommit\"). After that change we started producing that warning,\nand every now and then a user reports this since the warning happens too\noften, it spams dmesg/syslog, and a user is unsure if this reflects any\nproblem that might compromise the filesystem's reliability.\n\nWe can not just lock the sb->s_umount semaphore before calling\nwriteback_inodes_sb(), because that would at least deadlock with\nfilesystem freezing, since at fs/super.c:freeze_super() sync_filesystem()\nis called while we are holding that semaphore in write mode, and that can\ntrigger a transaction commit, resulting in a deadlock. It would also\ntrigger the same type of deadlock in the unmount path. Possibly, it could\nalso introduce some other locking dependencies that lockdep would report.\n\nTo fix this call try_to_writeback_inodes_sb() instead of\nwriteback_inodes_sb(), because that will try to read lock sb->s_umount\nand then will only call writeback_inodes_sb() if it was able to lock it.\nThis is fine because the cases where it can't read lock sb->s_umount\nare during a filesystem unmount or during a filesystem freeze - in those\ncases sb->s_umount is write locked and sync_filesystem() is called, which\ncalls writeback_inodes_sb(). In other words, in all cases where we can't\ntake a read lock on sb->s_umount, writeback is already being triggered\nelsewhere.\n\nAn alternative would be to call btrfs_start_delalloc_roots() with a\nnumber of pages different from LONG_MAX, for example matching the number\nof delalloc bytes we currently have, in \n---truncated---",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-667"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-22T02:15:06Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-mprm-vjq4-3rh2/GHSA-mprm-vjq4-3rh2.json b/advisories/unreviewed/2024/08/GHSA-mprm-vjq4-3rh2/GHSA-mprm-vjq4-3rh2.json
index 2129c79afee..3f491dd7d58 100644
--- a/advisories/unreviewed/2024/08/GHSA-mprm-vjq4-3rh2/GHSA-mprm-vjq4-3rh2.json
+++ b/advisories/unreviewed/2024/08/GHSA-mprm-vjq4-3rh2/GHSA-mprm-vjq4-3rh2.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mprm-vjq4-3rh2",
- "modified": "2024-08-22T03:31:34Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-22T03:31:34Z",
"aliases": [
"CVE-2022-48917"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: ops: Shift tested values in snd_soc_put_volsw() by +min\n\nWhile the $val/$val2 values passed in from userspace are always >= 0\nintegers, the limits of the control can be signed integers and the $min\ncan be non-zero and less than zero. To correctly validate $val/$val2\nagainst platform_max, add the $min offset to val first.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -55,7 +58,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-22T02:15:05Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-q2w7-x8j6-5gxc/GHSA-q2w7-x8j6-5gxc.json b/advisories/unreviewed/2024/08/GHSA-q2w7-x8j6-5gxc/GHSA-q2w7-x8j6-5gxc.json
index b646af8db39..6551e516d4c 100644
--- a/advisories/unreviewed/2024/08/GHSA-q2w7-x8j6-5gxc/GHSA-q2w7-x8j6-5gxc.json
+++ b/advisories/unreviewed/2024/08/GHSA-q2w7-x8j6-5gxc/GHSA-q2w7-x8j6-5gxc.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q2w7-x8j6-5gxc",
- "modified": "2024-08-22T03:31:34Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-22T03:31:34Z",
"aliases": [
"CVE-2022-48909"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: fix connection leak\n\nThere's a potential leak issue under following execution sequence :\n\nsmc_release \t\t\t\tsmc_connect_work\nif (sk->sk_state == SMC_INIT)\n\t\t\t\t\tsend_clc_confirim\n\ttcp_abort();\n\t\t\t\t\t...\n\t\t\t\t\tsk.sk_state = SMC_ACTIVE\nsmc_close_active\nswitch(sk->sk_state) {\n...\ncase SMC_ACTIVE:\n\tsmc_close_final()\n\t// then wait peer closed\n\nUnfortunately, tcp_abort() may discard CLC CONFIRM messages that are\nstill in the tcp send buffer, in which case our connection token cannot\nbe delivered to the server side, which means that we cannot get a\npassive close message at all. Therefore, it is impossible for the to be\ndisconnected at all.\n\nThis patch tries a very simple way to avoid this issue, once the state\nhas changed to SMC_ACTIVE after tcp_abort(), we can actively abort the\nsmc connection, considering that the state is SMC_INIT before\ntcp_abort(), abandoning the complete disconnection process should not\ncause too much problem.\n\nIn fact, this problem may exist as long as the CLC CONFIRM message is\nnot received by the server. Whether a timer should be added after\nsmc_close_final() needs to be discussed in the future. But even so, this\npatch provides a faster release for connection in above case, it should\nalso be valuable.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-401"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-22T02:15:05Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-qjgq-7w73-7hvf/GHSA-qjgq-7w73-7hvf.json b/advisories/unreviewed/2024/08/GHSA-qjgq-7w73-7hvf/GHSA-qjgq-7w73-7hvf.json
index 200c2903c13..4e6acbd7a5f 100644
--- a/advisories/unreviewed/2024/08/GHSA-qjgq-7w73-7hvf/GHSA-qjgq-7w73-7hvf.json
+++ b/advisories/unreviewed/2024/08/GHSA-qjgq-7w73-7hvf/GHSA-qjgq-7w73-7hvf.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qjgq-7w73-7hvf",
- "modified": "2024-08-22T03:31:34Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-22T03:31:34Z",
"aliases": [
"CVE-2022-48914"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxen/netfront: destroy queues before real_num_tx_queues is zeroed\n\nxennet_destroy_queues() relies on info->netdev->real_num_tx_queues to\ndelete queues. Since d7dac083414eb5bb99a6d2ed53dc2c1b405224e5\n(\"net-sysfs: update the queue counts in the unregistration path\"),\nunregister_netdev() indirectly sets real_num_tx_queues to 0. Those two\nfacts together means, that xennet_destroy_queues() called from\nxennet_remove() cannot do its job, because it's called after\nunregister_netdev(). This results in kfree-ing queues that are still\nlinked in napi, which ultimately crashes:\n\n BUG: kernel NULL pointer dereference, address: 0000000000000000\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 [#1] PREEMPT SMP PTI\n CPU: 1 PID: 52 Comm: xenwatch Tainted: G W 5.16.10-1.32.fc32.qubes.x86_64+ #226\n RIP: 0010:free_netdev+0xa3/0x1a0\n Code: ff 48 89 df e8 2e e9 00 00 48 8b 43 50 48 8b 08 48 8d b8 a0 fe ff ff 48 8d a9 a0 fe ff ff 49 39 c4 75 26 eb 47 e8 ed c1 66 ff <48> 8b 85 60 01 00 00 48 8d 95 60 01 00 00 48 89 ef 48 2d 60 01 00\n RSP: 0000:ffffc90000bcfd00 EFLAGS: 00010286\n RAX: 0000000000000000 RBX: ffff88800edad000 RCX: 0000000000000000\n RDX: 0000000000000001 RSI: ffffc90000bcfc30 RDI: 00000000ffffffff\n RBP: fffffffffffffea0 R08: 0000000000000000 R09: 0000000000000000\n R10: 0000000000000000 R11: 0000000000000001 R12: ffff88800edad050\n R13: ffff8880065f8f88 R14: 0000000000000000 R15: ffff8880066c6680\n FS: 0000000000000000(0000) GS:ffff8880f3300000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000000000000000 CR3: 00000000e998c006 CR4: 00000000003706e0\n Call Trace:\n \n xennet_remove+0x13d/0x300 [xen_netfront]\n xenbus_dev_remove+0x6d/0xf0\n __device_release_driver+0x17a/0x240\n device_release_driver+0x24/0x30\n bus_remove_device+0xd8/0x140\n device_del+0x18b/0x410\n ? _raw_spin_unlock+0x16/0x30\n ? klist_iter_exit+0x14/0x20\n ? xenbus_dev_request_and_reply+0x80/0x80\n device_unregister+0x13/0x60\n xenbus_dev_changed+0x18e/0x1f0\n xenwatch_thread+0xc0/0x1a0\n ? do_wait_intr_irq+0xa0/0xa0\n kthread+0x16b/0x190\n ? set_kthread_struct+0x40/0x40\n ret_from_fork+0x22/0x30\n \n\nFix this by calling xennet_destroy_queues() from xennet_uninit(),\nwhen real_num_tx_queues is still available. This ensures that queues are\ndestroyed when real_num_tx_queues is set to 0, regardless of how\nunregister_netdev() was called.\n\nOriginally reported at\nhttps://github.com/QubesOS/qubes-issues/issues/7257",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -45,9 +48,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-476"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-22T02:15:05Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-qm4j-q6jh-qw3p/GHSA-qm4j-q6jh-qw3p.json b/advisories/unreviewed/2024/08/GHSA-qm4j-q6jh-qw3p/GHSA-qm4j-q6jh-qw3p.json
index 390089c90ac..a80e207dfde 100644
--- a/advisories/unreviewed/2024/08/GHSA-qm4j-q6jh-qw3p/GHSA-qm4j-q6jh-qw3p.json
+++ b/advisories/unreviewed/2024/08/GHSA-qm4j-q6jh-qw3p/GHSA-qm4j-q6jh-qw3p.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qm4j-q6jh-qw3p",
- "modified": "2024-08-22T03:31:33Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-22T03:31:33Z",
"aliases": [
"CVE-2022-48904"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/amd: Fix I/O page table memory leak\n\nThe current logic updates the I/O page table mode for the domain\nbefore calling the logic to free memory used for the page table.\nThis results in IOMMU page table memory leak, and can be observed\nwhen launching VM w/ pass-through devices.\n\nFix by freeing the memory used for page table before updating the mode.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-401"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-22T02:15:04Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-qw5v-wmjr-8fpc/GHSA-qw5v-wmjr-8fpc.json b/advisories/unreviewed/2024/08/GHSA-qw5v-wmjr-8fpc/GHSA-qw5v-wmjr-8fpc.json
index 8e634667b88..8f4064ddf92 100644
--- a/advisories/unreviewed/2024/08/GHSA-qw5v-wmjr-8fpc/GHSA-qw5v-wmjr-8fpc.json
+++ b/advisories/unreviewed/2024/08/GHSA-qw5v-wmjr-8fpc/GHSA-qw5v-wmjr-8fpc.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qw5v-wmjr-8fpc",
- "modified": "2024-08-21T09:31:32Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-21T09:31:32Z",
"aliases": [
"CVE-2023-52909"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: fix handling of cached open files in nfsd4_open codepath\n\nCommit fb70bf124b05 (\"NFSD: Instantiate a struct file when creating a\nregular NFSv4 file\") added the ability to cache an open fd over a\ncompound. There are a couple of problems with the way this currently\nworks:\n\nIt's racy, as a newly-created nfsd_file can end up with its PENDING bit\ncleared while the nf is hashed, and the nf_file pointer is still zeroed\nout. Other tasks can find it in this state and they expect to see a\nvalid nf_file, and can oops if nf_file is NULL.\n\nAlso, there is no guarantee that we'll end up creating a new nfsd_file\nif one is already in the hash. If an extant entry is in the hash with a\nvalid nf_file, nfs4_get_vfs_file will clobber its nf_file pointer with\nthe value of op_file and the old nf_file will leak.\n\nFix both issues by making a new nfsd_file_acquirei_opened variant that\ntakes an optional file pointer. If one is present when this is called,\nwe'll take a new reference to it instead of trying to open the file. If\nthe nfsd_file already has a valid nf_file, we'll just ignore the\noptional file and pass the nfsd_file back as-is.\n\nAlso rework the tracepoints a bit to allow for an \"opened\" variant and\ndon't try to avoid counting acquisitions in the case where we already\nhave a cached open file.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-476"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-21T07:15:06Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-vc85-hxq3-m586/GHSA-vc85-hxq3-m586.json b/advisories/unreviewed/2024/08/GHSA-vc85-hxq3-m586/GHSA-vc85-hxq3-m586.json
index 7a56992830a..c6e3e16b774 100644
--- a/advisories/unreviewed/2024/08/GHSA-vc85-hxq3-m586/GHSA-vc85-hxq3-m586.json
+++ b/advisories/unreviewed/2024/08/GHSA-vc85-hxq3-m586/GHSA-vc85-hxq3-m586.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vc85-hxq3-m586",
- "modified": "2024-08-21T09:31:32Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-21T09:31:32Z",
"aliases": [
"CVE-2023-52912"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fixed bug on error when unloading amdgpu\n\nFixed bug on error when unloading amdgpu.\n\nThe error message is as follows:\n[ 377.706202] kernel BUG at drivers/gpu/drm/drm_buddy.c:278!\n[ 377.706215] invalid opcode: 0000 [#1] PREEMPT SMP NOPTI\n[ 377.706222] CPU: 4 PID: 8610 Comm: modprobe Tainted: G IOE 6.0.0-thomas #1\n[ 377.706231] Hardware name: ASUS System Product Name/PRIME Z390-A, BIOS 2004 11/02/2021\n[ 377.706238] RIP: 0010:drm_buddy_free_block+0x26/0x30 [drm_buddy]\n[ 377.706264] Code: 00 00 00 90 0f 1f 44 00 00 48 8b 0e 89 c8 25 00 0c 00 00 3d 00 04 00 00 75 10 48 8b 47 18 48 d3 e0 48 01 47 28 e9 fa fe ff ff <0f> 0b 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 41 54 55 48 89 f5 53\n[ 377.706282] RSP: 0018:ffffad2dc4683cb8 EFLAGS: 00010287\n[ 377.706289] RAX: 0000000000000000 RBX: ffff8b1743bd5138 RCX: 0000000000000000\n[ 377.706297] RDX: ffff8b1743bd5160 RSI: ffff8b1743bd5c78 RDI: ffff8b16d1b25f70\n[ 377.706304] RBP: ffff8b1743bd59e0 R08: 0000000000000001 R09: 0000000000000001\n[ 377.706311] R10: ffff8b16c8572400 R11: ffffad2dc4683cf0 R12: ffff8b16d1b25f70\n[ 377.706318] R13: ffff8b16d1b25fd0 R14: ffff8b1743bd59c0 R15: ffff8b16d1b25f70\n[ 377.706325] FS: 00007fec56c72c40(0000) GS:ffff8b1836500000(0000) knlGS:0000000000000000\n[ 377.706334] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 377.706340] CR2: 00007f9b88c1ba50 CR3: 0000000110450004 CR4: 00000000003706e0\n[ 377.706347] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 377.706354] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[ 377.706361] Call Trace:\n[ 377.706365] \n[ 377.706369] drm_buddy_free_list+0x2a/0x60 [drm_buddy]\n[ 377.706376] amdgpu_vram_mgr_fini+0xea/0x180 [amdgpu]\n[ 377.706572] amdgpu_ttm_fini+0x12e/0x1a0 [amdgpu]\n[ 377.706650] amdgpu_bo_fini+0x22/0x90 [amdgpu]\n[ 377.706727] gmc_v11_0_sw_fini+0x26/0x30 [amdgpu]\n[ 377.706821] amdgpu_device_fini_sw+0xa1/0x3c0 [amdgpu]\n[ 377.706897] amdgpu_driver_release_kms+0x12/0x30 [amdgpu]\n[ 377.706975] drm_dev_release+0x20/0x40 [drm]\n[ 377.707006] release_nodes+0x35/0xb0\n[ 377.707014] devres_release_all+0x8b/0xc0\n[ 377.707020] device_unbind_cleanup+0xe/0x70\n[ 377.707027] device_release_driver_internal+0xee/0x160\n[ 377.707033] driver_detach+0x44/0x90\n[ 377.707039] bus_remove_driver+0x55/0xe0\n[ 377.707045] pci_unregister_driver+0x3b/0x90\n[ 377.707052] amdgpu_exit+0x11/0x6c [amdgpu]\n[ 377.707194] __x64_sys_delete_module+0x142/0x2b0\n[ 377.707201] ? fpregs_assert_state_consistent+0x22/0x50\n[ 377.707208] ? exit_to_user_mode_prepare+0x3e/0x190\n[ 377.707215] do_syscall_64+0x38/0x90\n[ 377.707221] entry_SYSCALL_64_after_hwframe+0x63/0xcd",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-21T07:15:07Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-w39w-j699-c6w4/GHSA-w39w-j699-c6w4.json b/advisories/unreviewed/2024/08/GHSA-w39w-j699-c6w4/GHSA-w39w-j699-c6w4.json
index 97af7cb4981..4b515216589 100644
--- a/advisories/unreviewed/2024/08/GHSA-w39w-j699-c6w4/GHSA-w39w-j699-c6w4.json
+++ b/advisories/unreviewed/2024/08/GHSA-w39w-j699-c6w4/GHSA-w39w-j699-c6w4.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w39w-j699-c6w4",
- "modified": "2024-08-22T03:31:34Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-22T03:31:34Z",
"aliases": [
"CVE-2022-48921"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched/fair: Fix fault in reweight_entity\n\nSyzbot found a GPF in reweight_entity. This has been bisected to\ncommit 4ef0c5c6b5ba (\"kernel/sched: Fix sched_fork() access an invalid\nsched_task_group\")\n\nThere is a race between sched_post_fork() and setpriority(PRIO_PGRP)\nwithin a thread group that causes a null-ptr-deref in\nreweight_entity() in CFS. The scenario is that the main process spawns\nnumber of new threads, which then call setpriority(PRIO_PGRP, 0, -20),\nwait, and exit. For each of the new threads the copy_process() gets\ninvoked, which adds the new task_struct and calls sched_post_fork()\nfor it.\n\nIn the above scenario there is a possibility that\nsetpriority(PRIO_PGRP) and set_one_prio() will be called for a thread\nin the group that is just being created by copy_process(), and for\nwhich the sched_post_fork() has not been executed yet. This will\ntrigger a null pointer dereference in reweight_entity(), as it will\ntry to access the run queue pointer, which hasn't been set.\n\nBefore the mentioned change the cfs_rq pointer for the task has been\nset in sched_fork(), which is called much earlier in copy_process(),\nbefore the new task is added to the thread_group. Now it is done in\nthe sched_post_fork(), which is called after that. To fix the issue\nthe remove the update_load param from the update_load param() function\nand call reweight_task() only if the task flag doesn't have the\nTASK_NEW flag set.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-362"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-22T02:15:08Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-wh8g-pfmc-586j/GHSA-wh8g-pfmc-586j.json b/advisories/unreviewed/2024/08/GHSA-wh8g-pfmc-586j/GHSA-wh8g-pfmc-586j.json
index 26a0ae878d7..2cc152eb027 100644
--- a/advisories/unreviewed/2024/08/GHSA-wh8g-pfmc-586j/GHSA-wh8g-pfmc-586j.json
+++ b/advisories/unreviewed/2024/08/GHSA-wh8g-pfmc-586j/GHSA-wh8g-pfmc-586j.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wh8g-pfmc-586j",
- "modified": "2024-08-22T03:31:33Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-22T03:31:33Z",
"aliases": [
"CVE-2022-48905"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nibmvnic: free reset-work-item when flushing\n\nFix a tiny memory leak when flushing the reset work queue.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -45,9 +48,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-401"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-22T02:15:05Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-wq9p-m399-c79x/GHSA-wq9p-m399-c79x.json b/advisories/unreviewed/2024/08/GHSA-wq9p-m399-c79x/GHSA-wq9p-m399-c79x.json
index 5948385ec53..8ed0cdbc669 100644
--- a/advisories/unreviewed/2024/08/GHSA-wq9p-m399-c79x/GHSA-wq9p-m399-c79x.json
+++ b/advisories/unreviewed/2024/08/GHSA-wq9p-m399-c79x/GHSA-wq9p-m399-c79x.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wq9p-m399-c79x",
- "modified": "2024-08-28T09:30:34Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-28T09:30:34Z",
"aliases": [
"CVE-2024-4556"
diff --git a/advisories/unreviewed/2024/08/GHSA-wvmv-3h72-2xxc/GHSA-wvmv-3h72-2xxc.json b/advisories/unreviewed/2024/08/GHSA-wvmv-3h72-2xxc/GHSA-wvmv-3h72-2xxc.json
index a8cf85b06d9..10972a0fb8b 100644
--- a/advisories/unreviewed/2024/08/GHSA-wvmv-3h72-2xxc/GHSA-wvmv-3h72-2xxc.json
+++ b/advisories/unreviewed/2024/08/GHSA-wvmv-3h72-2xxc/GHSA-wvmv-3h72-2xxc.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wvmv-3h72-2xxc",
- "modified": "2024-08-22T03:31:34Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-08-22T03:31:34Z",
"aliases": [
"CVE-2022-48906"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: Correctly set DATA_FIN timeout when number of retransmits is large\n\nSyzkaller with UBSAN uncovered a scenario where a large number of\nDATA_FIN retransmits caused a shift-out-of-bounds in the DATA_FIN\ntimeout calculation:\n\n================================================================================\nUBSAN: shift-out-of-bounds in net/mptcp/protocol.c:470:29\nshift exponent 32 is too large for 32-bit type 'unsigned int'\nCPU: 1 PID: 13059 Comm: kworker/1:0 Not tainted 5.17.0-rc2-00630-g5fbf21c90c60 #1\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1.1 04/01/2014\nWorkqueue: events mptcp_worker\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0xcd/0x134 lib/dump_stack.c:106\n ubsan_epilogue+0xb/0x5a lib/ubsan.c:151\n __ubsan_handle_shift_out_of_bounds.cold+0xb2/0x20e lib/ubsan.c:330\n mptcp_set_datafin_timeout net/mptcp/protocol.c:470 [inline]\n __mptcp_retrans.cold+0x72/0x77 net/mptcp/protocol.c:2445\n mptcp_worker+0x58a/0xa70 net/mptcp/protocol.c:2528\n process_one_work+0x9df/0x16d0 kernel/workqueue.c:2307\n worker_thread+0x95/0xe10 kernel/workqueue.c:2454\n kthread+0x2f4/0x3b0 kernel/kthread.c:377\n ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295\n \n================================================================================\n\nThis change limits the maximum timeout by limiting the size of the\nshift, which keeps all intermediate values in-bounds.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -35,7 +38,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-22T02:15:05Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-2x3r-qhc4-2pjr/GHSA-2x3r-qhc4-2pjr.json b/advisories/unreviewed/2024/09/GHSA-2x3r-qhc4-2pjr/GHSA-2x3r-qhc4-2pjr.json
index 53d528c612b..528524898b3 100644
--- a/advisories/unreviewed/2024/09/GHSA-2x3r-qhc4-2pjr/GHSA-2x3r-qhc4-2pjr.json
+++ b/advisories/unreviewed/2024/09/GHSA-2x3r-qhc4-2pjr/GHSA-2x3r-qhc4-2pjr.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2x3r-qhc4-2pjr",
- "modified": "2024-09-12T06:30:22Z",
+ "modified": "2024-09-12T15:33:00Z",
"published": "2024-09-12T06:30:22Z",
"aliases": [
"CVE-2024-7859"
],
"details": "The Visual Sound WordPress plugin through 1.03 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-352"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-12T06:15:24Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-32fj-r8qw-r8w8/GHSA-32fj-r8qw-r8w8.json b/advisories/unreviewed/2024/09/GHSA-32fj-r8qw-r8w8/GHSA-32fj-r8qw-r8w8.json
new file mode 100644
index 00000000000..b5baa7c83db
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-32fj-r8qw-r8w8/GHSA-32fj-r8qw-r8w8.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-32fj-r8qw-r8w8",
+ "modified": "2024-09-12T15:33:01Z",
+ "published": "2024-09-12T15:33:01Z",
+ "aliases": [
+ "CVE-2024-45856"
+ ],
+ "details": "A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an ML Engine, database, project, or dataset containing arbitrary JavaScript code within the web UI.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45856"
+ },
+ {
+ "type": "WEB",
+ "url": "https://hiddenlayer.com/sai-security-advisory/2024-09-mindsdb"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "CRITICAL",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T13:15:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-375w-qxcp-h82p/GHSA-375w-qxcp-h82p.json b/advisories/unreviewed/2024/09/GHSA-375w-qxcp-h82p/GHSA-375w-qxcp-h82p.json
new file mode 100644
index 00000000000..f29ce5791e1
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-375w-qxcp-h82p/GHSA-375w-qxcp-h82p.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-375w-qxcp-h82p",
+ "modified": "2024-09-12T15:33:00Z",
+ "published": "2024-09-12T15:33:00Z",
+ "aliases": [
+ "CVE-2024-3305"
+ ],
+ "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Utarit Information SoliClub allows Retrieve Embedded Sensitive Data.This issue affects SoliClub: before 4.4.0 for iOS, before 5.2.1 for Android.",
+ "severity": [
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3305"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.usom.gov.tr/bildirim/tr-24-1457"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-200"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T13:15:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-3whw-wqrp-r5hq/GHSA-3whw-wqrp-r5hq.json b/advisories/unreviewed/2024/09/GHSA-3whw-wqrp-r5hq/GHSA-3whw-wqrp-r5hq.json
index ad8910a162d..349dacf50a1 100644
--- a/advisories/unreviewed/2024/09/GHSA-3whw-wqrp-r5hq/GHSA-3whw-wqrp-r5hq.json
+++ b/advisories/unreviewed/2024/09/GHSA-3whw-wqrp-r5hq/GHSA-3whw-wqrp-r5hq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3whw-wqrp-r5hq",
- "modified": "2024-09-06T09:32:30Z",
+ "modified": "2024-09-12T15:33:00Z",
"published": "2024-09-06T09:32:30Z",
"aliases": [
"CVE-2024-7349"
diff --git a/advisories/unreviewed/2024/09/GHSA-4fgp-7vvm-m4jf/GHSA-4fgp-7vvm-m4jf.json b/advisories/unreviewed/2024/09/GHSA-4fgp-7vvm-m4jf/GHSA-4fgp-7vvm-m4jf.json
new file mode 100644
index 00000000000..9003944e72b
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-4fgp-7vvm-m4jf/GHSA-4fgp-7vvm-m4jf.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4fgp-7vvm-m4jf",
+ "modified": "2024-09-12T15:33:00Z",
+ "published": "2024-09-12T15:33:00Z",
+ "aliases": [
+ "CVE-2024-27321"
+ ],
+ "details": "An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its multilabel classification tasks handle provided CSV files. If a user creates a multilabel classification task using a maliciously crafted CSV file containing Python code, the code will be passed to an eval function which executes it.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27321"
+ },
+ {
+ "type": "WEB",
+ "url": "https://hiddenlayer.com/sai-security-advisory/2024-09-autolabel"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-95"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T13:15:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-4hj6-28gf-vw7g/GHSA-4hj6-28gf-vw7g.json b/advisories/unreviewed/2024/09/GHSA-4hj6-28gf-vw7g/GHSA-4hj6-28gf-vw7g.json
index 55943047ee1..341b07dabb3 100644
--- a/advisories/unreviewed/2024/09/GHSA-4hj6-28gf-vw7g/GHSA-4hj6-28gf-vw7g.json
+++ b/advisories/unreviewed/2024/09/GHSA-4hj6-28gf-vw7g/GHSA-4hj6-28gf-vw7g.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4hj6-28gf-vw7g",
- "modified": "2024-09-10T21:31:39Z",
+ "modified": "2024-09-12T15:33:00Z",
"published": "2024-09-10T21:31:39Z",
"aliases": [
"CVE-2024-43040"
],
"details": "Renwoxing Enterprise Intelligent Management System before v3.0 was discovered to contain a SQL injection vulnerability via the parid parameter at /fx/baseinfo/SearchInfo.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-10T20:15:04Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-4qc3-9vcj-2gh8/GHSA-4qc3-9vcj-2gh8.json b/advisories/unreviewed/2024/09/GHSA-4qc3-9vcj-2gh8/GHSA-4qc3-9vcj-2gh8.json
new file mode 100644
index 00000000000..4ea66ea6b9e
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-4qc3-9vcj-2gh8/GHSA-4qc3-9vcj-2gh8.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4qc3-9vcj-2gh8",
+ "modified": "2024-09-12T15:33:01Z",
+ "published": "2024-09-12T15:33:01Z",
+ "aliases": [
+ "CVE-2024-6702"
+ ],
+ "details": "Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6702"
+ },
+ {
+ "type": "WEB",
+ "url": "https://support.pega.com/support-doc/pega-security-advisory-c24-vulnerability-remediation-note"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-74"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T15:18:27Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-52vm-8f6x-7r3p/GHSA-52vm-8f6x-7r3p.json b/advisories/unreviewed/2024/09/GHSA-52vm-8f6x-7r3p/GHSA-52vm-8f6x-7r3p.json
index b744959f5a2..c714febe5f5 100644
--- a/advisories/unreviewed/2024/09/GHSA-52vm-8f6x-7r3p/GHSA-52vm-8f6x-7r3p.json
+++ b/advisories/unreviewed/2024/09/GHSA-52vm-8f6x-7r3p/GHSA-52vm-8f6x-7r3p.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-52vm-8f6x-7r3p",
- "modified": "2024-09-12T06:30:22Z",
+ "modified": "2024-09-12T15:33:00Z",
"published": "2024-09-12T06:30:22Z",
"aliases": [
"CVE-2024-8054"
],
"details": "The MM-Breaking News WordPress plugin through 0.7.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-12T06:15:25Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-5jgh-5fp7-98p9/GHSA-5jgh-5fp7-98p9.json b/advisories/unreviewed/2024/09/GHSA-5jgh-5fp7-98p9/GHSA-5jgh-5fp7-98p9.json
index ca7e61c9b61..d38e3c9ce3f 100644
--- a/advisories/unreviewed/2024/09/GHSA-5jgh-5fp7-98p9/GHSA-5jgh-5fp7-98p9.json
+++ b/advisories/unreviewed/2024/09/GHSA-5jgh-5fp7-98p9/GHSA-5jgh-5fp7-98p9.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5jgh-5fp7-98p9",
- "modified": "2024-09-11T15:31:12Z",
+ "modified": "2024-09-12T15:33:00Z",
"published": "2024-09-11T15:31:12Z",
"aliases": [
"CVE-2024-8637"
],
"details": "Use after free in Media Router in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
"CWE-416"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-11T14:15:13Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-5jpg-grvp-4pr4/GHSA-5jpg-grvp-4pr4.json b/advisories/unreviewed/2024/09/GHSA-5jpg-grvp-4pr4/GHSA-5jpg-grvp-4pr4.json
new file mode 100644
index 00000000000..a96128ef1af
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-5jpg-grvp-4pr4/GHSA-5jpg-grvp-4pr4.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5jpg-grvp-4pr4",
+ "modified": "2024-09-12T15:33:01Z",
+ "published": "2024-09-12T15:33:01Z",
+ "aliases": [
+ "CVE-2024-6700"
+ ],
+ "details": "Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with App name.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6700"
+ },
+ {
+ "type": "WEB",
+ "url": "https://support.pega.com/support-doc/pega-security-advisory-c24-vulnerability-remediation-note"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T15:18:26Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-5jrh-c32g-j2q9/GHSA-5jrh-c32g-j2q9.json b/advisories/unreviewed/2024/09/GHSA-5jrh-c32g-j2q9/GHSA-5jrh-c32g-j2q9.json
new file mode 100644
index 00000000000..00ae38f3af0
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-5jrh-c32g-j2q9/GHSA-5jrh-c32g-j2q9.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5jrh-c32g-j2q9",
+ "modified": "2024-09-12T15:33:00Z",
+ "published": "2024-09-12T15:33:00Z",
+ "aliases": [
+ "CVE-2021-22503"
+ ],
+ "details": "Possible \nImproper Neutralization of Input During Web Page Generation Vulnerability\n\nin eDirectory has been discovered in\nOpenText™ eDirectory 9.2.3.0000.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-22503"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.netiq.com/documentation/edirectory-92/edirectory924_releasenotes/data/edirectory924_releasenotes.html"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T13:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-6r2v-725q-58ch/GHSA-6r2v-725q-58ch.json b/advisories/unreviewed/2024/09/GHSA-6r2v-725q-58ch/GHSA-6r2v-725q-58ch.json
new file mode 100644
index 00000000000..5e161a7b618
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-6r2v-725q-58ch/GHSA-6r2v-725q-58ch.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6r2v-725q-58ch",
+ "modified": "2024-09-12T15:33:01Z",
+ "published": "2024-09-12T15:33:01Z",
+ "aliases": [
+ "CVE-2024-6658"
+ ],
+ "details": "Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows OS Command Injection.This issue affects:\n\n\n\n Product \n\n\n\n\n\nAffected Versions \n\n\n\n\n\nLoadMaster \n\n\n\n\n\nFrom 7.2.55.0 to 7.2.60.0 (inclusive) \n\n\n\n\n\n \n\n\n\n\n\nFrom 7.2.49.0 to 7.2.54.11 (inclusive) \n\n\n\n\n\n \n\n\n\n\n\n7.2.48.12 and all prior versions \n\n\n\n\n\n\n\n\nMulti-Tenant Hypervisor \n\n\n\n\n\n7.1.35.11 and all prior versions \n\n\n\n\n\n\n\n\n\n\nECS\n\n\n\n\n\nAll prior versions to 7.2.60.0 (inclusive)",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6658"
+ },
+ {
+ "type": "WEB",
+ "url": "https://support.kemptechnologies.com/hc/en-us/articles/28910587250701"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-20"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T15:18:26Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-6v48-p2g5-g5g2/GHSA-6v48-p2g5-g5g2.json b/advisories/unreviewed/2024/09/GHSA-6v48-p2g5-g5g2/GHSA-6v48-p2g5-g5g2.json
new file mode 100644
index 00000000000..be42a7435a0
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-6v48-p2g5-g5g2/GHSA-6v48-p2g5-g5g2.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6v48-p2g5-g5g2",
+ "modified": "2024-09-12T15:33:01Z",
+ "published": "2024-09-12T15:33:01Z",
+ "aliases": [
+ "CVE-2024-40457"
+ ],
+ "details": "No-IP Dynamic Update Client (DUC) v3.x uses cleartext credentials that may occur on a command line or in a file. NOTE: the vendor's position is that cleartext in /etc/default/noip-duc is recommended and is the intentional behavior.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40457"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.noip.com/support/knowledgebase/install-linux-3-x-dynamic-update-client-duc"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.noip.com/support/knowledgebase/running-linux-duc-v3-0-startup-2"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T14:16:06Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-75jr-77wp-rpvh/GHSA-75jr-77wp-rpvh.json b/advisories/unreviewed/2024/09/GHSA-75jr-77wp-rpvh/GHSA-75jr-77wp-rpvh.json
index 60958a4f96b..fc4793e8efb 100644
--- a/advisories/unreviewed/2024/09/GHSA-75jr-77wp-rpvh/GHSA-75jr-77wp-rpvh.json
+++ b/advisories/unreviewed/2024/09/GHSA-75jr-77wp-rpvh/GHSA-75jr-77wp-rpvh.json
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-75jr-77wp-rpvh",
- "modified": "2024-09-11T15:31:12Z",
+ "modified": "2024-09-12T15:33:00Z",
"published": "2024-09-11T15:31:12Z",
"aliases": [
"CVE-2024-27114"
],
"details": "A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the public view setting is enabled, a attacker can upload a PHP-file that will be available for execution for a few milliseconds before it is removed, leading to execution of code on the underlying system. The vulnerability has been remediated in version 1.52.02.",
"severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ },
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:I/V:C/RE:M/U:Red"
diff --git a/advisories/unreviewed/2024/09/GHSA-76xg-73qg-phm7/GHSA-76xg-73qg-phm7.json b/advisories/unreviewed/2024/09/GHSA-76xg-73qg-phm7/GHSA-76xg-73qg-phm7.json
new file mode 100644
index 00000000000..775068a38bb
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-76xg-73qg-phm7/GHSA-76xg-73qg-phm7.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-76xg-73qg-phm7",
+ "modified": "2024-09-12T15:33:00Z",
+ "published": "2024-09-12T15:33:00Z",
+ "aliases": [
+ "CVE-2021-22518"
+ ],
+ "details": "A vulnerability identified in OpenText™ \nIdentity Manager AzureAD Driver that allows logging of sensitive information into log file. This impacts all versions before 5.1.4.0",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-22518"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.netiq.com/documentation/identity-manager-48-drivers/AzureADDriver514/data/AzureADDriver514.html"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-532"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T13:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-7p74-xwp9-69ww/GHSA-7p74-xwp9-69ww.json b/advisories/unreviewed/2024/09/GHSA-7p74-xwp9-69ww/GHSA-7p74-xwp9-69ww.json
new file mode 100644
index 00000000000..69e6f975d0d
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-7p74-xwp9-69ww/GHSA-7p74-xwp9-69ww.json
@@ -0,0 +1,42 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7p74-xwp9-69ww",
+ "modified": "2024-09-12T15:33:01Z",
+ "published": "2024-09-12T15:33:01Z",
+ "aliases": [
+ "CVE-2024-45825"
+ ],
+ "details": "CVE-2024-45825 IMPACT\nA denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a malformed CIP packet is sent over the network to the device and results in a major nonrecoverable fault causing a denial-of-service.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45825"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1699.html"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-20"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T15:18:23Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-7v38-xc68-49j2/GHSA-7v38-xc68-49j2.json b/advisories/unreviewed/2024/09/GHSA-7v38-xc68-49j2/GHSA-7v38-xc68-49j2.json
new file mode 100644
index 00000000000..731a213432c
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-7v38-xc68-49j2/GHSA-7v38-xc68-49j2.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7v38-xc68-49j2",
+ "modified": "2024-09-12T15:33:00Z",
+ "published": "2024-09-12T15:33:00Z",
+ "aliases": [
+ "CVE-2021-38132"
+ ],
+ "details": "Possible \nExternal Service Interaction attack\n\nin eDirectory has been discovered in\nOpenText™ eDirectory. This impact all version before 9.2.6.0000.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-38132"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.netiq.com/documentation/edirectory-92/edirectory926_releasenotes/data/edirectory926_releasenotes.html"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-918"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T13:15:10Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-7vhh-gfjc-x8rm/GHSA-7vhh-gfjc-x8rm.json b/advisories/unreviewed/2024/09/GHSA-7vhh-gfjc-x8rm/GHSA-7vhh-gfjc-x8rm.json
new file mode 100644
index 00000000000..a09e865d78f
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-7vhh-gfjc-x8rm/GHSA-7vhh-gfjc-x8rm.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7vhh-gfjc-x8rm",
+ "modified": "2024-09-12T15:33:01Z",
+ "published": "2024-09-12T15:33:01Z",
+ "aliases": [
+ "CVE-2024-45854"
+ ],
+ "details": "Deserialization of untrusted data can occur in versions 23.10.3.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when a ‘describe’ query is run on it.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45854"
+ },
+ {
+ "type": "WEB",
+ "url": "https://hiddenlayer.com/sai-security-advisory/2024-09-mindsdb"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-502"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T13:15:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-7vhj-pfwv-hx3w/GHSA-7vhj-pfwv-hx3w.json b/advisories/unreviewed/2024/09/GHSA-7vhj-pfwv-hx3w/GHSA-7vhj-pfwv-hx3w.json
new file mode 100644
index 00000000000..2bb898a7dba
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-7vhj-pfwv-hx3w/GHSA-7vhj-pfwv-hx3w.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7vhj-pfwv-hx3w",
+ "modified": "2024-09-12T15:33:01Z",
+ "published": "2024-09-12T15:33:01Z",
+ "aliases": [
+ "CVE-2024-45852"
+ ],
+ "details": "Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbitrary code on the server when interacted with.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45852"
+ },
+ {
+ "type": "WEB",
+ "url": "https://hiddenlayer.com/sai-security-advisory/2024-09-mindsdb"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-502"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T13:15:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-8cm9-rrgc-4pcj/GHSA-8cm9-rrgc-4pcj.json b/advisories/unreviewed/2024/09/GHSA-8cm9-rrgc-4pcj/GHSA-8cm9-rrgc-4pcj.json
new file mode 100644
index 00000000000..b647e62429f
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-8cm9-rrgc-4pcj/GHSA-8cm9-rrgc-4pcj.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8cm9-rrgc-4pcj",
+ "modified": "2024-09-12T15:33:01Z",
+ "published": "2024-09-12T15:33:01Z",
+ "aliases": [
+ "CVE-2024-45857"
+ ],
+ "details": "Deserialization of untrusted data can occur in versions 2.4.0 or newer of the Cleanlab project, enabling a maliciously crafted datalab.pkl file to run arbitrary code on an end user’s system when the data directory is loaded.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45857"
+ },
+ {
+ "type": "WEB",
+ "url": "https://hiddenlayer.com/sai-security-advisory/2024-09-cleanlab"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-502"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T13:15:16Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-97hh-35r9-2gfm/GHSA-97hh-35r9-2gfm.json b/advisories/unreviewed/2024/09/GHSA-97hh-35r9-2gfm/GHSA-97hh-35r9-2gfm.json
index b34d4a09d8f..666ef4aca0c 100644
--- a/advisories/unreviewed/2024/09/GHSA-97hh-35r9-2gfm/GHSA-97hh-35r9-2gfm.json
+++ b/advisories/unreviewed/2024/09/GHSA-97hh-35r9-2gfm/GHSA-97hh-35r9-2gfm.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-97hh-35r9-2gfm",
- "modified": "2024-09-05T12:31:16Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-09-05T12:31:16Z",
"aliases": [
"CVE-2024-6929"
diff --git a/advisories/unreviewed/2024/09/GHSA-9cxc-m8xm-7c7x/GHSA-9cxc-m8xm-7c7x.json b/advisories/unreviewed/2024/09/GHSA-9cxc-m8xm-7c7x/GHSA-9cxc-m8xm-7c7x.json
new file mode 100644
index 00000000000..a04577f241f
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-9cxc-m8xm-7c7x/GHSA-9cxc-m8xm-7c7x.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9cxc-m8xm-7c7x",
+ "modified": "2024-09-12T15:33:00Z",
+ "published": "2024-09-12T15:33:00Z",
+ "aliases": [
+ "CVE-2022-26322"
+ ],
+ "details": "Possible Insertion of Sensitive Information into Log File Vulnerability\n\nin Identity Manager has been discovered in\nOpenText™ \nIdentity Manager REST Driver. This impact version before 1.1.2.0200.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-26322"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.netiq.com/documentation/identity-manager-48-drivers/RESTDriver1.1.2.0300_readme/data/RESTDriver1.1.2.0300_readme.html"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-532"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T13:15:10Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-9gq6-6936-885w/GHSA-9gq6-6936-885w.json b/advisories/unreviewed/2024/09/GHSA-9gq6-6936-885w/GHSA-9gq6-6936-885w.json
new file mode 100644
index 00000000000..48cbe7f69f3
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-9gq6-6936-885w/GHSA-9gq6-6936-885w.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9gq6-6936-885w",
+ "modified": "2024-09-12T15:33:00Z",
+ "published": "2024-09-12T15:33:00Z",
+ "aliases": [
+ "CVE-2024-45848"
+ ],
+ "details": "An arbitrary code execution vulnerability exists in versions 23.12.4.0 up to 24.7.4.1 of the MindsDB platform, when the ChromaDB integration is installed on the server. If a specially crafted ‘INSERT’ query containing Python code is run against a database created with the ChromaDB engine, the code will be passed to an eval function and executed on the server.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45848"
+ },
+ {
+ "type": "WEB",
+ "url": "https://hiddenlayer.com/sai-security-advisory/2024-09-mindsdb"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-95"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T13:15:13Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-c85f-pcx6-2ghm/GHSA-c85f-pcx6-2ghm.json b/advisories/unreviewed/2024/09/GHSA-c85f-pcx6-2ghm/GHSA-c85f-pcx6-2ghm.json
new file mode 100644
index 00000000000..f77c211377d
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-c85f-pcx6-2ghm/GHSA-c85f-pcx6-2ghm.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-c85f-pcx6-2ghm",
+ "modified": "2024-09-12T15:33:00Z",
+ "published": "2024-09-12T15:33:00Z",
+ "aliases": [
+ "CVE-2024-45849"
+ ],
+ "details": "An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases created with the SharePoint engine, an ‘INSERT’ query can be used for list creation. If such a query is specially crafted to contain Python code and is run against the database, the code will be passed to an eval function and executed on the server.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45849"
+ },
+ {
+ "type": "WEB",
+ "url": "https://hiddenlayer.com/sai-security-advisory/2024-09-mindsdb"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-95"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T13:15:13Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-c9h3-w54v-5g3j/GHSA-c9h3-w54v-5g3j.json b/advisories/unreviewed/2024/09/GHSA-c9h3-w54v-5g3j/GHSA-c9h3-w54v-5g3j.json
new file mode 100644
index 00000000000..892f01123ec
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-c9h3-w54v-5g3j/GHSA-c9h3-w54v-5g3j.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-c9h3-w54v-5g3j",
+ "modified": "2024-09-12T15:33:00Z",
+ "published": "2024-09-12T15:33:00Z",
+ "aliases": [
+ "CVE-2021-38131"
+ ],
+ "details": "Possible Cross-Site Scripting (XSS) Vulnerability\n\nin eDirectory has been discovered in\nOpenText™ eDirectory 9.2.5.0000.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-38131"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.netiq.com/documentation/edirectory-92/edirectory926_releasenotes/data/edirectory926_releasenotes.html"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T13:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-crmg-rp64-5cm3/GHSA-crmg-rp64-5cm3.json b/advisories/unreviewed/2024/09/GHSA-crmg-rp64-5cm3/GHSA-crmg-rp64-5cm3.json
new file mode 100644
index 00000000000..2bad0e0b2ac
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-crmg-rp64-5cm3/GHSA-crmg-rp64-5cm3.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-crmg-rp64-5cm3",
+ "modified": "2024-09-12T15:33:00Z",
+ "published": "2024-09-12T15:33:00Z",
+ "aliases": [
+ "CVE-2024-45847"
+ ],
+ "details": "An arbitrary code execution vulnerability exists in versions 23.11.4.2 up to 24.7.4.1 of the MindsDB platform, when one of several integrations is installed on the server. If a specially crafted ‘UPDATE’ query containing Python code is run against a database created with the specified integration engine, the code will be passed to an eval function and executed on the server.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45847"
+ },
+ {
+ "type": "WEB",
+ "url": "https://hiddenlayer.com/sai-security-advisory/2024-09-mindsdb"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-95"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T13:15:13Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-fr9q-rgwq-g5r5/GHSA-fr9q-rgwq-g5r5.json b/advisories/unreviewed/2024/09/GHSA-fr9q-rgwq-g5r5/GHSA-fr9q-rgwq-g5r5.json
new file mode 100644
index 00000000000..8e10c7a2d35
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-fr9q-rgwq-g5r5/GHSA-fr9q-rgwq-g5r5.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fr9q-rgwq-g5r5",
+ "modified": "2024-09-12T15:33:01Z",
+ "published": "2024-09-12T15:33:01Z",
+ "aliases": [
+ "CVE-2024-45855"
+ ],
+ "details": "Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when using ‘finetune’ on it.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45855"
+ },
+ {
+ "type": "WEB",
+ "url": "https://hiddenlayer.com/sai-security-advisory/2024-09-mindsdb"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-502"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T13:15:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-frqj-xr96-qh56/GHSA-frqj-xr96-qh56.json b/advisories/unreviewed/2024/09/GHSA-frqj-xr96-qh56/GHSA-frqj-xr96-qh56.json
index 17fea018008..bf28a9eef5a 100644
--- a/advisories/unreviewed/2024/09/GHSA-frqj-xr96-qh56/GHSA-frqj-xr96-qh56.json
+++ b/advisories/unreviewed/2024/09/GHSA-frqj-xr96-qh56/GHSA-frqj-xr96-qh56.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-frqj-xr96-qh56",
- "modified": "2024-09-05T12:31:15Z",
+ "modified": "2024-09-12T15:32:59Z",
"published": "2024-09-05T12:31:15Z",
"aliases": [
"CVE-2024-6332"
diff --git a/advisories/unreviewed/2024/09/GHSA-g2m8-f3x2-qprw/GHSA-g2m8-f3x2-qprw.json b/advisories/unreviewed/2024/09/GHSA-g2m8-f3x2-qprw/GHSA-g2m8-f3x2-qprw.json
new file mode 100644
index 00000000000..79e0a0c6997
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-g2m8-f3x2-qprw/GHSA-g2m8-f3x2-qprw.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-g2m8-f3x2-qprw",
+ "modified": "2024-09-12T15:33:00Z",
+ "published": "2024-09-12T15:33:00Z",
+ "aliases": [
+ "CVE-2024-27320"
+ ],
+ "details": "An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its classification tasks handle provided CSV files. If a victim user creates a classification task using a maliciously crafted CSV file containing Python code, the code will be passed to an eval function which executes it.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27320"
+ },
+ {
+ "type": "WEB",
+ "url": "https://hiddenlayer.com/sai-security-advisory/2024-09-autolabel"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-95"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T13:15:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-ggr8-prr7-mw8f/GHSA-ggr8-prr7-mw8f.json b/advisories/unreviewed/2024/09/GHSA-ggr8-prr7-mw8f/GHSA-ggr8-prr7-mw8f.json
new file mode 100644
index 00000000000..ea81f8dac95
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-ggr8-prr7-mw8f/GHSA-ggr8-prr7-mw8f.json
@@ -0,0 +1,42 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-ggr8-prr7-mw8f",
+ "modified": "2024-09-12T15:33:01Z",
+ "published": "2024-09-12T15:33:01Z",
+ "aliases": [
+ "CVE-2024-28990"
+ ],
+ "details": "SolarWinds Access Rights Manager (ARM) was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability would allow access to the RabbitMQ management console.\n\nWe thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28990"
+ },
+ {
+ "type": "WEB",
+ "url": "https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2024-3-1_release_notes.htm"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-28990"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-798"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T14:16:06Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-gmjh-p826-vp24/GHSA-gmjh-p826-vp24.json b/advisories/unreviewed/2024/09/GHSA-gmjh-p826-vp24/GHSA-gmjh-p826-vp24.json
new file mode 100644
index 00000000000..37cce0fc009
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-gmjh-p826-vp24/GHSA-gmjh-p826-vp24.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gmjh-p826-vp24",
+ "modified": "2024-09-12T15:33:00Z",
+ "published": "2024-09-12T15:33:00Z",
+ "aliases": [
+ "CVE-2021-22532"
+ ],
+ "details": "Possible NLDAP Denial of Service attack Vulnerability\n\nin eDirectory has been discovered in\nOpenText™ \neDirectory before 9.2.4.0000.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-22532"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.netiq.com/documentation/edirectory-92/edirectory925_releasenotes/data/edirectory925_releasenotes.html"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-770"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T13:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-gpxp-f9r6-4g34/GHSA-gpxp-f9r6-4g34.json b/advisories/unreviewed/2024/09/GHSA-gpxp-f9r6-4g34/GHSA-gpxp-f9r6-4g34.json
new file mode 100644
index 00000000000..0444c45a68f
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-gpxp-f9r6-4g34/GHSA-gpxp-f9r6-4g34.json
@@ -0,0 +1,42 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gpxp-f9r6-4g34",
+ "modified": "2024-09-12T15:33:01Z",
+ "published": "2024-09-12T15:33:01Z",
+ "aliases": [
+ "CVE-2024-45824"
+ ],
+ "details": "CVE-2024-45824 IMPACT\n\n\n\nA remote\ncode vulnerability exists in the affected products. The vulnerability occurs\nwhen chained with Path Traversal, Command Injection, and XSS Vulnerabilities\nand allows for full unauthenticated remote code execution. The link in the\nmitigations section below contains patches to fix this issue.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45824"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1696.html"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-77"
+ ],
+ "severity": "CRITICAL",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T14:16:06Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-gr7c-mhmf-p6jj/GHSA-gr7c-mhmf-p6jj.json b/advisories/unreviewed/2024/09/GHSA-gr7c-mhmf-p6jj/GHSA-gr7c-mhmf-p6jj.json
index 8f419989b05..cd8e5170654 100644
--- a/advisories/unreviewed/2024/09/GHSA-gr7c-mhmf-p6jj/GHSA-gr7c-mhmf-p6jj.json
+++ b/advisories/unreviewed/2024/09/GHSA-gr7c-mhmf-p6jj/GHSA-gr7c-mhmf-p6jj.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gr7c-mhmf-p6jj",
- "modified": "2024-09-12T06:30:22Z",
+ "modified": "2024-09-12T15:33:00Z",
"published": "2024-09-12T06:30:22Z",
"aliases": [
"CVE-2024-7861"
],
"details": "The Misiek Paypal WordPress plugin through 1.1.20090324 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-12T06:15:24Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-hh5f-w8h8-vh35/GHSA-hh5f-w8h8-vh35.json b/advisories/unreviewed/2024/09/GHSA-hh5f-w8h8-vh35/GHSA-hh5f-w8h8-vh35.json
index 34db0562c36..6b3e25e1149 100644
--- a/advisories/unreviewed/2024/09/GHSA-hh5f-w8h8-vh35/GHSA-hh5f-w8h8-vh35.json
+++ b/advisories/unreviewed/2024/09/GHSA-hh5f-w8h8-vh35/GHSA-hh5f-w8h8-vh35.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hh5f-w8h8-vh35",
- "modified": "2024-09-11T00:30:51Z",
+ "modified": "2024-09-12T15:33:00Z",
"published": "2024-09-11T00:30:51Z",
"aliases": [
"CVE-2024-40650"
],
"details": "In wifi_item_edit_content of styles.xml , there is a possible FRP bypass due to Missing check for FRP state. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-358"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-11T00:15:11Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-j4w6-9wmj-vfmv/GHSA-j4w6-9wmj-vfmv.json b/advisories/unreviewed/2024/09/GHSA-j4w6-9wmj-vfmv/GHSA-j4w6-9wmj-vfmv.json
new file mode 100644
index 00000000000..5b6f8e59604
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-j4w6-9wmj-vfmv/GHSA-j4w6-9wmj-vfmv.json
@@ -0,0 +1,42 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-j4w6-9wmj-vfmv",
+ "modified": "2024-09-12T15:33:01Z",
+ "published": "2024-09-12T15:33:01Z",
+ "aliases": [
+ "CVE-2024-28991"
+ ],
+ "details": "SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would allow an authenticated user to abuse the service, resulting in remote code execution.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28991"
+ },
+ {
+ "type": "WEB",
+ "url": "https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2024-3-1_release_notes.htm"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-28991"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-502"
+ ],
+ "severity": "CRITICAL",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T14:16:06Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-j75g-rhx3-9jfv/GHSA-j75g-rhx3-9jfv.json b/advisories/unreviewed/2024/09/GHSA-j75g-rhx3-9jfv/GHSA-j75g-rhx3-9jfv.json
index 01e2a02ab7b..c9744412138 100644
--- a/advisories/unreviewed/2024/09/GHSA-j75g-rhx3-9jfv/GHSA-j75g-rhx3-9jfv.json
+++ b/advisories/unreviewed/2024/09/GHSA-j75g-rhx3-9jfv/GHSA-j75g-rhx3-9jfv.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j75g-rhx3-9jfv",
- "modified": "2024-09-12T06:30:22Z",
+ "modified": "2024-09-12T15:33:00Z",
"published": "2024-09-12T06:30:22Z",
"aliases": [
"CVE-2024-7817"
],
"details": "The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF checks in some places, which could allow attackers to make logged in users delete arbitrary albums via a CSRF attack",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-352"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-12T06:15:24Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-jhg9-gwwm-6qw2/GHSA-jhg9-gwwm-6qw2.json b/advisories/unreviewed/2024/09/GHSA-jhg9-gwwm-6qw2/GHSA-jhg9-gwwm-6qw2.json
index 78096c52fd2..0760ad6a24f 100644
--- a/advisories/unreviewed/2024/09/GHSA-jhg9-gwwm-6qw2/GHSA-jhg9-gwwm-6qw2.json
+++ b/advisories/unreviewed/2024/09/GHSA-jhg9-gwwm-6qw2/GHSA-jhg9-gwwm-6qw2.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jhg9-gwwm-6qw2",
- "modified": "2024-09-11T15:31:12Z",
+ "modified": "2024-09-12T15:33:00Z",
"published": "2024-09-11T15:31:12Z",
"aliases": [
"CVE-2024-8639"
],
"details": "Use after free in Autofill in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
"CWE-416"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-11T14:15:14Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-jj2m-7f8j-222w/GHSA-jj2m-7f8j-222w.json b/advisories/unreviewed/2024/09/GHSA-jj2m-7f8j-222w/GHSA-jj2m-7f8j-222w.json
index 54b6c5a3d52..b39d9b6d865 100644
--- a/advisories/unreviewed/2024/09/GHSA-jj2m-7f8j-222w/GHSA-jj2m-7f8j-222w.json
+++ b/advisories/unreviewed/2024/09/GHSA-jj2m-7f8j-222w/GHSA-jj2m-7f8j-222w.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jj2m-7f8j-222w",
- "modified": "2024-09-12T06:30:22Z",
+ "modified": "2024-09-12T15:33:00Z",
"published": "2024-09-12T06:30:22Z",
"aliases": [
"CVE-2024-7822"
],
"details": "The Quick Code WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-12T06:15:24Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-jj65-79wr-35v9/GHSA-jj65-79wr-35v9.json b/advisories/unreviewed/2024/09/GHSA-jj65-79wr-35v9/GHSA-jj65-79wr-35v9.json
new file mode 100644
index 00000000000..ef582ef778a
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-jj65-79wr-35v9/GHSA-jj65-79wr-35v9.json
@@ -0,0 +1,42 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jj65-79wr-35v9",
+ "modified": "2024-09-12T15:33:01Z",
+ "published": "2024-09-12T15:33:01Z",
+ "aliases": [
+ "CVE-2024-45826"
+ ],
+ "details": "CVE-2024-45826 IMPACT\nDue to improper input validation, a path traversal and remote code execution vulnerability exists when the ThinManager® processes a crafted POST request. If exploited, a user can install an executable file.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45826"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1700.html"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-610"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T15:18:24Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-jq4w-q2w4-8qw3/GHSA-jq4w-q2w4-8qw3.json b/advisories/unreviewed/2024/09/GHSA-jq4w-q2w4-8qw3/GHSA-jq4w-q2w4-8qw3.json
index c27fe82c4ce..df040972c9f 100644
--- a/advisories/unreviewed/2024/09/GHSA-jq4w-q2w4-8qw3/GHSA-jq4w-q2w4-8qw3.json
+++ b/advisories/unreviewed/2024/09/GHSA-jq4w-q2w4-8qw3/GHSA-jq4w-q2w4-8qw3.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jq4w-q2w4-8qw3",
- "modified": "2024-09-12T06:30:22Z",
+ "modified": "2024-09-12T15:33:00Z",
"published": "2024-09-12T06:30:22Z",
"aliases": [
"CVE-2024-7818"
],
"details": "The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-12T06:15:24Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-jw76-x8jc-r725/GHSA-jw76-x8jc-r725.json b/advisories/unreviewed/2024/09/GHSA-jw76-x8jc-r725/GHSA-jw76-x8jc-r725.json
index b114901e530..1a7adbf46a7 100644
--- a/advisories/unreviewed/2024/09/GHSA-jw76-x8jc-r725/GHSA-jw76-x8jc-r725.json
+++ b/advisories/unreviewed/2024/09/GHSA-jw76-x8jc-r725/GHSA-jw76-x8jc-r725.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jw76-x8jc-r725",
- "modified": "2024-09-11T15:31:12Z",
+ "modified": "2024-09-12T15:33:00Z",
"published": "2024-09-11T15:31:12Z",
"aliases": [
"CVE-2024-8638"
],
"details": "Type Confusion in V8 in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
"CWE-843"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-11T14:15:14Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-m49g-89fj-x9pc/GHSA-m49g-89fj-x9pc.json b/advisories/unreviewed/2024/09/GHSA-m49g-89fj-x9pc/GHSA-m49g-89fj-x9pc.json
new file mode 100644
index 00000000000..78f2cf7d350
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-m49g-89fj-x9pc/GHSA-m49g-89fj-x9pc.json
@@ -0,0 +1,42 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-m49g-89fj-x9pc",
+ "modified": "2024-09-12T15:33:01Z",
+ "published": "2024-09-12T15:33:01Z",
+ "aliases": [
+ "CVE-2024-45823"
+ ],
+ "details": "CVE-2024-45823 IMPACT\n\n\n\nAn\nauthentication bypass vulnerability exists in the affected product. The\nvulnerability exists due to shared secrets across accounts and could allow a threat\nactor to impersonate a user if the threat actor is able to enumerate additional\ninformation required during authentication.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45823"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD%201698.html"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-287"
+ ],
+ "severity": "CRITICAL",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T15:18:22Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-mfqr-wp5f-9gj8/GHSA-mfqr-wp5f-9gj8.json b/advisories/unreviewed/2024/09/GHSA-mfqr-wp5f-9gj8/GHSA-mfqr-wp5f-9gj8.json
new file mode 100644
index 00000000000..2729eeebcce
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-mfqr-wp5f-9gj8/GHSA-mfqr-wp5f-9gj8.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mfqr-wp5f-9gj8",
+ "modified": "2024-09-12T15:33:00Z",
+ "published": "2024-09-12T15:33:00Z",
+ "aliases": [
+ "CVE-2021-22533"
+ ],
+ "details": "Possible Insertion of Sensitive Information into Log File Vulnerability\n\nin eDirectory has been discovered in\nOpenText™ eDirectory 9.2.4.0000.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-22533"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.netiq.com/documentation/edirectory-92/edirectory925_releasenotes/data/edirectory925_releasenotes.html"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-532"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T13:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-mmp2-p685-v76h/GHSA-mmp2-p685-v76h.json b/advisories/unreviewed/2024/09/GHSA-mmp2-p685-v76h/GHSA-mmp2-p685-v76h.json
index dd4b3a15aef..0299077d90e 100644
--- a/advisories/unreviewed/2024/09/GHSA-mmp2-p685-v76h/GHSA-mmp2-p685-v76h.json
+++ b/advisories/unreviewed/2024/09/GHSA-mmp2-p685-v76h/GHSA-mmp2-p685-v76h.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mmp2-p685-v76h",
- "modified": "2024-09-11T00:30:51Z",
+ "modified": "2024-09-12T15:33:00Z",
"published": "2024-09-11T00:30:51Z",
"aliases": [
"CVE-2024-23716"
],
"details": "In DevmemIntPFNotify of devicemem_server.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-416"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-11T00:15:10Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-mxxv-ww69-wr77/GHSA-mxxv-ww69-wr77.json b/advisories/unreviewed/2024/09/GHSA-mxxv-ww69-wr77/GHSA-mxxv-ww69-wr77.json
new file mode 100644
index 00000000000..c595b21dab8
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-mxxv-ww69-wr77/GHSA-mxxv-ww69-wr77.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mxxv-ww69-wr77",
+ "modified": "2024-09-12T15:33:01Z",
+ "published": "2024-09-12T15:33:01Z",
+ "aliases": [
+ "CVE-2024-6701"
+ ],
+ "details": "Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with case type.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6701"
+ },
+ {
+ "type": "WEB",
+ "url": "https://support.pega.com/support-doc/pega-security-advisory-c24-vulnerability-remediation-note"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T15:18:26Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-p5wh-m438-q8hr/GHSA-p5wh-m438-q8hr.json b/advisories/unreviewed/2024/09/GHSA-p5wh-m438-q8hr/GHSA-p5wh-m438-q8hr.json
index c0f66adab84..f2fcafc3df0 100644
--- a/advisories/unreviewed/2024/09/GHSA-p5wh-m438-q8hr/GHSA-p5wh-m438-q8hr.json
+++ b/advisories/unreviewed/2024/09/GHSA-p5wh-m438-q8hr/GHSA-p5wh-m438-q8hr.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p5wh-m438-q8hr",
- "modified": "2024-09-11T00:30:51Z",
+ "modified": "2024-09-12T15:33:00Z",
"published": "2024-09-11T00:30:51Z",
"aliases": [
"CVE-2024-31336"
],
"details": "N/A",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-787"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-11T00:15:11Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-q95f-jm6p-77wg/GHSA-q95f-jm6p-77wg.json b/advisories/unreviewed/2024/09/GHSA-q95f-jm6p-77wg/GHSA-q95f-jm6p-77wg.json
index c29cec0afee..8fd8e713fb5 100644
--- a/advisories/unreviewed/2024/09/GHSA-q95f-jm6p-77wg/GHSA-q95f-jm6p-77wg.json
+++ b/advisories/unreviewed/2024/09/GHSA-q95f-jm6p-77wg/GHSA-q95f-jm6p-77wg.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q95f-jm6p-77wg",
- "modified": "2024-09-12T06:30:22Z",
+ "modified": "2024-09-12T15:33:00Z",
"published": "2024-09-12T06:30:22Z",
"aliases": [
"CVE-2024-7860"
],
"details": "The Simple Headline Rotator WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-12T06:15:24Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-q9r8-89xr-4xv4/GHSA-q9r8-89xr-4xv4.json b/advisories/unreviewed/2024/09/GHSA-q9r8-89xr-4xv4/GHSA-q9r8-89xr-4xv4.json
new file mode 100644
index 00000000000..1f463b9e028
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-q9r8-89xr-4xv4/GHSA-q9r8-89xr-4xv4.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-q9r8-89xr-4xv4",
+ "modified": "2024-09-12T15:33:01Z",
+ "published": "2024-09-12T15:33:01Z",
+ "aliases": [
+ "CVE-2024-45853"
+ ],
+ "details": "Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when used for a prediction.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45853"
+ },
+ {
+ "type": "WEB",
+ "url": "https://hiddenlayer.com/sai-security-advisory/2024-09-mindsdb"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-502"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T13:15:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-qv98-75v6-5rhf/GHSA-qv98-75v6-5rhf.json b/advisories/unreviewed/2024/09/GHSA-qv98-75v6-5rhf/GHSA-qv98-75v6-5rhf.json
index 0d5bb2b1f93..2a4c373b41f 100644
--- a/advisories/unreviewed/2024/09/GHSA-qv98-75v6-5rhf/GHSA-qv98-75v6-5rhf.json
+++ b/advisories/unreviewed/2024/09/GHSA-qv98-75v6-5rhf/GHSA-qv98-75v6-5rhf.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qv98-75v6-5rhf",
- "modified": "2024-09-12T06:30:22Z",
+ "modified": "2024-09-12T15:33:00Z",
"published": "2024-09-12T06:30:22Z",
"aliases": [
"CVE-2024-8056"
],
"details": "The MM-Breaking News WordPress plugin through 0.7.9 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-12T06:15:25Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-r47m-g4vh-pxf6/GHSA-r47m-g4vh-pxf6.json b/advisories/unreviewed/2024/09/GHSA-r47m-g4vh-pxf6/GHSA-r47m-g4vh-pxf6.json
index b0a85809a57..e9a284b0b09 100644
--- a/advisories/unreviewed/2024/09/GHSA-r47m-g4vh-pxf6/GHSA-r47m-g4vh-pxf6.json
+++ b/advisories/unreviewed/2024/09/GHSA-r47m-g4vh-pxf6/GHSA-r47m-g4vh-pxf6.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r47m-g4vh-pxf6",
- "modified": "2024-09-10T21:31:39Z",
+ "modified": "2024-09-12T15:33:00Z",
"published": "2024-09-10T21:31:39Z",
"aliases": [
"CVE-2024-8504"
],
"details": "An attacker with authenticated access to VICIdial as an \"agent\" can execute arbitrary shell commands as the \"root\" user. This attack can be chained with CVE-2024-8503 to execute arbitrary shell commands starting from an unauthenticated perspective.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
"CWE-78"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-10T20:15:05Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-r4gm-mp4j-4fq7/GHSA-r4gm-mp4j-4fq7.json b/advisories/unreviewed/2024/09/GHSA-r4gm-mp4j-4fq7/GHSA-r4gm-mp4j-4fq7.json
index fafe4328a6a..a5e9d8b0454 100644
--- a/advisories/unreviewed/2024/09/GHSA-r4gm-mp4j-4fq7/GHSA-r4gm-mp4j-4fq7.json
+++ b/advisories/unreviewed/2024/09/GHSA-r4gm-mp4j-4fq7/GHSA-r4gm-mp4j-4fq7.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r4gm-mp4j-4fq7",
- "modified": "2024-09-12T06:30:22Z",
+ "modified": "2024-09-12T15:33:00Z",
"published": "2024-09-12T06:30:22Z",
"aliases": [
"CVE-2024-7820"
],
"details": "The ILC Thickbox WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-352"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-12T06:15:24Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-r4pj-228r-7758/GHSA-r4pj-228r-7758.json b/advisories/unreviewed/2024/09/GHSA-r4pj-228r-7758/GHSA-r4pj-228r-7758.json
new file mode 100644
index 00000000000..7538e696674
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-r4pj-228r-7758/GHSA-r4pj-228r-7758.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-r4pj-228r-7758",
+ "modified": "2024-09-12T15:33:01Z",
+ "published": "2024-09-12T15:33:01Z",
+ "aliases": [
+ "CVE-2024-6510"
+ ],
+ "details": "Local Privilege Escalation in AVG Internet Security v24 on Windows allows a local unprivileged user to escalate privileges to SYSTEM via COM-Hijacking.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6510"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.cirosec.de/sa/sa-2023-008"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-427"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T15:18:26Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-r53m-j46m-cw28/GHSA-r53m-j46m-cw28.json b/advisories/unreviewed/2024/09/GHSA-r53m-j46m-cw28/GHSA-r53m-j46m-cw28.json
index 670015fcabf..ccf16c20ac4 100644
--- a/advisories/unreviewed/2024/09/GHSA-r53m-j46m-cw28/GHSA-r53m-j46m-cw28.json
+++ b/advisories/unreviewed/2024/09/GHSA-r53m-j46m-cw28/GHSA-r53m-j46m-cw28.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r53m-j46m-cw28",
- "modified": "2024-09-12T06:30:22Z",
+ "modified": "2024-09-12T15:33:00Z",
"published": "2024-09-12T06:30:22Z",
"aliases": [
"CVE-2024-7862"
],
"details": "The blogintroduction-wordpress-plugin WordPress plugin through 0.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-352"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-12T06:15:25Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-r6cg-gw4p-5gmj/GHSA-r6cg-gw4p-5gmj.json b/advisories/unreviewed/2024/09/GHSA-r6cg-gw4p-5gmj/GHSA-r6cg-gw4p-5gmj.json
index af13b91d708..bc9975e5e90 100644
--- a/advisories/unreviewed/2024/09/GHSA-r6cg-gw4p-5gmj/GHSA-r6cg-gw4p-5gmj.json
+++ b/advisories/unreviewed/2024/09/GHSA-r6cg-gw4p-5gmj/GHSA-r6cg-gw4p-5gmj.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r6cg-gw4p-5gmj",
- "modified": "2024-09-11T15:31:12Z",
+ "modified": "2024-09-12T15:33:00Z",
"published": "2024-09-11T15:31:12Z",
"aliases": [
"CVE-2024-8636"
],
"details": "Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -29,9 +32,10 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-122"
+ "CWE-122",
+ "CWE-787"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-11T14:15:13Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-rccv-3qjv-c8h5/GHSA-rccv-3qjv-c8h5.json b/advisories/unreviewed/2024/09/GHSA-rccv-3qjv-c8h5/GHSA-rccv-3qjv-c8h5.json
index 0a7effd45d4..40dcd8d627e 100644
--- a/advisories/unreviewed/2024/09/GHSA-rccv-3qjv-c8h5/GHSA-rccv-3qjv-c8h5.json
+++ b/advisories/unreviewed/2024/09/GHSA-rccv-3qjv-c8h5/GHSA-rccv-3qjv-c8h5.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rccv-3qjv-c8h5",
- "modified": "2024-09-12T06:30:22Z",
+ "modified": "2024-09-12T15:33:00Z",
"published": "2024-09-12T06:30:22Z",
"aliases": [
"CVE-2024-7816"
],
"details": "The Gixaw Chat WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-12T06:15:24Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-rfvq-f6wq-mfhj/GHSA-rfvq-f6wq-mfhj.json b/advisories/unreviewed/2024/09/GHSA-rfvq-f6wq-mfhj/GHSA-rfvq-f6wq-mfhj.json
new file mode 100644
index 00000000000..5ffd26611d2
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-rfvq-f6wq-mfhj/GHSA-rfvq-f6wq-mfhj.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-rfvq-f6wq-mfhj",
+ "modified": "2024-09-12T15:33:00Z",
+ "published": "2024-09-12T15:33:00Z",
+ "aliases": [
+ "CVE-2024-3306"
+ ],
+ "details": "Authorization Bypass Through User-Controlled Key vulnerability in Utarit Information SoliClub allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SoliClub: before 4.4.0 for iOS, before 5.2.1 for Android.",
+ "severity": [
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3306"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.usom.gov.tr/bildirim/tr-24-1457"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-639"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T13:15:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-v6g6-3cm3-vf6c/GHSA-v6g6-3cm3-vf6c.json b/advisories/unreviewed/2024/09/GHSA-v6g6-3cm3-vf6c/GHSA-v6g6-3cm3-vf6c.json
new file mode 100644
index 00000000000..afeb701efbc
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-v6g6-3cm3-vf6c/GHSA-v6g6-3cm3-vf6c.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-v6g6-3cm3-vf6c",
+ "modified": "2024-09-12T15:33:00Z",
+ "published": "2024-09-12T15:33:00Z",
+ "aliases": [
+ "CVE-2024-45850"
+ ],
+ "details": "An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases created with the SharePoint engine, an ‘INSERT’ query can be used for site column creation. If such a query is specially crafted to contain Python code and is run against the database, the code will be passed to an eval function and executed on the server.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45850"
+ },
+ {
+ "type": "WEB",
+ "url": "https://hiddenlayer.com/sai-security-advisory/2024-09-mindsdb"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-95"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T13:15:13Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-wcjw-3v6p-4v3r/GHSA-wcjw-3v6p-4v3r.json b/advisories/unreviewed/2024/09/GHSA-wcjw-3v6p-4v3r/GHSA-wcjw-3v6p-4v3r.json
new file mode 100644
index 00000000000..0f2a5e603a7
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-wcjw-3v6p-4v3r/GHSA-wcjw-3v6p-4v3r.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wcjw-3v6p-4v3r",
+ "modified": "2024-09-12T15:33:00Z",
+ "published": "2024-09-12T15:33:00Z",
+ "aliases": [
+ "CVE-2024-45846"
+ ],
+ "details": "An arbitrary code execution vulnerability exists in versions 23.10.3.0 up to 24.7.4.1 of the MindsDB platform, when the Weaviate integration is installed on the server. If a specially crafted ‘SELECT WHERE’ clause containing Python code is run against a database created with the Weaviate engine, the code will be passed to an eval function and executed on the server.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45846"
+ },
+ {
+ "type": "WEB",
+ "url": "https://hiddenlayer.com/sai-security-advisory/2024-09-mindsdb"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-95"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T13:15:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-wf9g-c67g-h4ch/GHSA-wf9g-c67g-h4ch.json b/advisories/unreviewed/2024/09/GHSA-wf9g-c67g-h4ch/GHSA-wf9g-c67g-h4ch.json
new file mode 100644
index 00000000000..bc67311fd42
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-wf9g-c67g-h4ch/GHSA-wf9g-c67g-h4ch.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wf9g-c67g-h4ch",
+ "modified": "2024-09-12T15:33:01Z",
+ "published": "2024-09-12T15:33:01Z",
+ "aliases": [
+ "CVE-2024-45851"
+ ],
+ "details": "An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases created with the SharePoint engine, an ‘INSERT’ query can be used for list item creation. If such a query is specially crafted to contain Python code and is run against the database, the code will be passed to an eval function and executed on the server.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45851"
+ },
+ {
+ "type": "WEB",
+ "url": "https://hiddenlayer.com/sai-security-advisory/2024-09-mindsdb"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-95"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T13:15:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-x6xc-qv8r-frvx/GHSA-x6xc-qv8r-frvx.json b/advisories/unreviewed/2024/09/GHSA-x6xc-qv8r-frvx/GHSA-x6xc-qv8r-frvx.json
new file mode 100644
index 00000000000..fc4fbc78978
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-x6xc-qv8r-frvx/GHSA-x6xc-qv8r-frvx.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-x6xc-qv8r-frvx",
+ "modified": "2024-09-12T15:33:00Z",
+ "published": "2024-09-12T15:33:00Z",
+ "aliases": [
+ "CVE-2021-38133"
+ ],
+ "details": "Possible \nExternal Service Interaction attack\n\nin eDirectory has been discovered in\nOpenText™ eDirectory. This impact all version before 9.2.6.0000.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-38133"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.netiq.com/documentation/edirectory-92/edirectory926_releasenotes/data/edirectory926_releasenotes.html"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-521"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-12T13:15:10Z"
+ }
+}
\ No newline at end of file