Publish Advisories

GHSA-58jw-58x8-342p
GHSA-37x3-hqf8-5w7p
GHSA-3wjc-g785-xjp8
GHSA-6fc3-8g79-3f39
GHSA-87qp-7cw8-8q9c
GHSA-8jm2-4r4f-748v
GHSA-m653-rf8h-79j3
GHSA-p8fm-626m-mf8v
GHSA-q7m5-4xhc-7xfr
GHSA-qjrx-78jp-x72f
GHSA-rqhc-7mvg-jchq
GHSA-rx84-4w3q-488h
GHSA-w97v-hmpc-3m55
GHSA-wvw8-hcw4-jwqp
GHSA-x3j5-x3h2-frf6
This commit is contained in:
advisory-database[bot]
2024-03-25 06:31:44 +00:00
parent 4c631496be
commit 862b9c31d9
15 changed files with 541 additions and 1 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-58jw-58x8-342p",
"modified": "2023-03-16T18:30:31Z",
"modified": "2024-03-25T06:30:23Z",
"published": "2023-03-10T21:30:22Z",
"aliases": [
"CVE-2022-40540"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40540"
},
{
"type": "WEB",
"url": "https://bugzilla.suse.com/show_bug.cgi?id=1209597"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230616-0001"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-37x3-hqf8-5w7p",
"modified": "2024-03-25T06:30:24Z",
"published": "2024-03-25T06:30:24Z",
"aliases": [
"CVE-2024-1232"
],
"details": "The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins delete downloads via a CSRF attack",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1232"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/2a29b509-4cd5-43c8-84f4-f86251dd28f8"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T05:15:50Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3wjc-g785-xjp8",
"modified": "2024-03-25T06:30:24Z",
"published": "2024-03-25T06:30:24Z",
"aliases": [
"CVE-2023-37885"
],
"details": "Missing Authorization vulnerability in InspiryThemes RealHomes.This issue affects RealHomes: from n/a through 4.0.2.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37885"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/realhomes/wordpress-realhomes-theme-4-0-2-broken-access-control-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T05:15:50Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6fc3-8g79-3f39",
"modified": "2024-03-25T06:30:24Z",
"published": "2024-03-25T06:30:24Z",
"aliases": [
"CVE-2024-1962"
],
"details": "The CM Download Manager WordPress plugin before 2.9.1 does not have CSRF checks in some places, which could allow attackers to make logged in admins edit downloads via a CSRF attack",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1962"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/469486d4-7677-4d66-83c0-a6b9ac7c503b"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T05:15:50Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-87qp-7cw8-8q9c",
"modified": "2024-03-25T06:30:24Z",
"published": "2024-03-25T06:30:24Z",
"aliases": [
"CVE-2024-21505"
],
"details": "Versions of the package web3-utils before 4.2.1 are vulnerable to Prototype Pollution via the utility functions format and mergeDeep, due to insecure recursive merge.\nAn attacker can manipulate an object's prototype, potentially leading to the alteration of the behavior of all objects inheriting from the affected prototype by passing specially crafted input to these functions.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21505"
},
{
"type": "WEB",
"url": "https://github.com/web3/web3.js/commit/8ed041c6635d807b3da8960ad49e125e3d1b0e80"
},
{
"type": "WEB",
"url": "https://security.snyk.io/vuln/SNYK-JS-WEB3UTILS-6229337"
}
],
"database_specific": {
"cwe_ids": [
"CWE-1321"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T05:15:50Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8jm2-4r4f-748v",
"modified": "2024-03-25T06:30:23Z",
"published": "2024-03-25T06:30:23Z",
"aliases": [
"CVE-2024-29071"
],
"details": "HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may change the system settings.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29071"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/vu/JVNVU93546510"
},
{
"type": "WEB",
"url": "https://www.au.com/support/service/internet/guide/modem/bl1500hm/firmware"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T04:15:09Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m653-rf8h-79j3",
"modified": "2024-03-25T06:30:24Z",
"published": "2024-03-25T06:30:24Z",
"aliases": [
"CVE-2024-29009"
],
"details": "Cross-site request forgery (CSRF) vulnerability in easy-popup-show all versions allows a remote unauthenticated attacker to hijack the authentication of the administrator and to perform unintended operations if the administrator views a malicious page while logged in.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29009"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/jp/JVN86206017"
},
{
"type": "WEB",
"url": "https://wordpress.org/plugins/easy-popup-show"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T05:15:50Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p8fm-626m-mf8v",
"modified": "2024-03-25T06:30:24Z",
"published": "2024-03-25T06:30:24Z",
"aliases": [
"CVE-2024-1564"
],
"details": "The wp-schema-pro WordPress plugin before 2.7.16 does not validate post access allowing a contributor user to access custom fields on any post regardless of post type or status via a shortcode",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1564"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/ecb1e36f-9c6e-4754-8878-03c97194644d"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T05:15:50Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q7m5-4xhc-7xfr",
"modified": "2024-03-25T06:30:24Z",
"published": "2024-03-25T06:30:24Z",
"aliases": [
"CVE-2024-21865"
],
"details": "HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may connect to the product via SSH and use a shell.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21865"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/vu/JVNVU93546510"
},
{
"type": "WEB",
"url": "https://www.au.com/support/service/internet/guide/modem/bl1500hm/firmware"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T05:15:50Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qjrx-78jp-x72f",
"modified": "2024-03-25T06:30:23Z",
"published": "2024-03-25T06:30:23Z",
"aliases": [
"CVE-2024-28041"
],
"details": "HGW BL1500HM Ver 002.001.013 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary command.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28041"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/vu/JVNVU93546510"
},
{
"type": "WEB",
"url": "https://www.au.com/support/service/internet/guide/modem/bl1500hm/firmware"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T04:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rqhc-7mvg-jchq",
"modified": "2024-03-25T06:30:24Z",
"published": "2024-03-25T06:30:24Z",
"aliases": [
"CVE-2023-37886"
],
"details": "Missing Authorization vulnerability in InspiryThemes RealHomes.This issue affects RealHomes: from n/a through 4.0.2.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37886"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/realhomes/wordpress-realhomes-theme-4-0-2-broken-access-control-vulnerability-2?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T05:15:50Z"
}
}
File diff suppressed because one or more lines are too long
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w97v-hmpc-3m55",
"modified": "2024-03-25T06:30:23Z",
"published": "2024-03-25T06:30:23Z",
"aliases": [
"CVE-2023-30480"
],
"details": "Missing Authorization vulnerability in Sparkle WP Educenter.This issue affects Educenter: from n/a through 1.5.5.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30480"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/educenter/wordpress-educenter-theme-1-5-1-broken-access-control?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T05:15:49Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wvw8-hcw4-jwqp",
"modified": "2024-03-25T06:30:24Z",
"published": "2024-03-25T06:30:24Z",
"aliases": [
"CVE-2024-1231"
],
"details": "The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins unpublish downloads via a CSRF attack",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1231"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/7d3968d9-61ed-4c00-8764-0360cf03255e"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T05:15:50Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x3j5-x3h2-frf6",
"modified": "2024-03-25T06:30:24Z",
"published": "2024-03-25T06:30:24Z",
"aliases": [
"CVE-2023-33923"
],
"details": "Missing Authorization vulnerability in HashThemes Viral News, HashThemes Viral, HashThemes HashOne.This issue affects Viral News: from n/a through 1.4.5; Viral: from n/a through 1.8.0; HashOne: from n/a through 1.3.0.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33923"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/hashone/wordpress-hashone-theme-1-3-0-broken-access-control-vulnerability?_s_id=cve"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/viral-news/wordpress-viral-news-theme-1-4-5-authenticated-arbitrary-plugin-activation-vulnerability?_s_id=cve"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/viral/wordpress-viral-theme-1-8-0-broken-access-control-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T05:15:49Z"
}
}