diff --git a/advisories/unreviewed/2023/09/GHSA-8hxx-8cjf-cxvg/GHSA-8hxx-8cjf-cxvg.json b/advisories/unreviewed/2023/09/GHSA-8hxx-8cjf-cxvg/GHSA-8hxx-8cjf-cxvg.json index 437cf42ca1c..5058a7bf166 100644 --- a/advisories/unreviewed/2023/09/GHSA-8hxx-8cjf-cxvg/GHSA-8hxx-8cjf-cxvg.json +++ b/advisories/unreviewed/2023/09/GHSA-8hxx-8cjf-cxvg/GHSA-8hxx-8cjf-cxvg.json @@ -44,7 +44,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-3wqv-582c-6cpc/GHSA-3wqv-582c-6cpc.json b/advisories/unreviewed/2024/07/GHSA-3wqv-582c-6cpc/GHSA-3wqv-582c-6cpc.json index f5b608f4664..57a7e35104c 100644 --- a/advisories/unreviewed/2024/07/GHSA-3wqv-582c-6cpc/GHSA-3wqv-582c-6cpc.json +++ b/advisories/unreviewed/2024/07/GHSA-3wqv-582c-6cpc/GHSA-3wqv-582c-6cpc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3wqv-582c-6cpc", - "modified": "2024-07-30T21:31:27Z", + "modified": "2024-09-30T21:02:12Z", "published": "2024-07-30T21:31:27Z", "aliases": [ "CVE-2024-3930" diff --git a/advisories/unreviewed/2024/08/GHSA-5wm9-5344-qrrj/GHSA-5wm9-5344-qrrj.json b/advisories/unreviewed/2024/08/GHSA-5wm9-5344-qrrj/GHSA-5wm9-5344-qrrj.json index 760d0da5549..6be9efe8531 100644 --- a/advisories/unreviewed/2024/08/GHSA-5wm9-5344-qrrj/GHSA-5wm9-5344-qrrj.json +++ b/advisories/unreviewed/2024/08/GHSA-5wm9-5344-qrrj/GHSA-5wm9-5344-qrrj.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5wm9-5344-qrrj", - "modified": "2024-08-22T15:31:18Z", + "modified": "2024-09-30T21:02:12Z", "published": "2024-08-20T21:30:35Z", "aliases": [ "CVE-2024-6800" ], "details": "An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when utilizing SAML authentication with specific identity providers. This vulnerability allowed an attacker with direct network access to GitHub Enterprise Server to forge a SAML response to provision and/or gain access to a user with site administrator privileges. Exploitation of this vulnerability would allow unauthorized access to the instance without requiring prior authentication. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in versions 3.13.3, 3.12.8, 3.11.14, and 3.10.16. This vulnerability was reported via the GitHub Bug Bounty program.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:C/RE:H/U:Red" diff --git a/advisories/unreviewed/2024/09/GHSA-26q7-27mp-g4qj/GHSA-26q7-27mp-g4qj.json b/advisories/unreviewed/2024/09/GHSA-26q7-27mp-g4qj/GHSA-26q7-27mp-g4qj.json index 882c98ac798..4c45dc9c48d 100644 --- a/advisories/unreviewed/2024/09/GHSA-26q7-27mp-g4qj/GHSA-26q7-27mp-g4qj.json +++ b/advisories/unreviewed/2024/09/GHSA-26q7-27mp-g4qj/GHSA-26q7-27mp-g4qj.json @@ -36,6 +36,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-24" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/09/GHSA-354q-9jjr-5vm7/GHSA-354q-9jjr-5vm7.json b/advisories/unreviewed/2024/09/GHSA-354q-9jjr-5vm7/GHSA-354q-9jjr-5vm7.json new file mode 100644 index 00000000000..9807700914c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-354q-9jjr-5vm7/GHSA-354q-9jjr-5vm7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-354q-9jjr-5vm7", + "modified": "2024-09-30T21:02:13Z", + "published": "2024-09-30T21:02:13Z", + "aliases": [ + "CVE-2024-28811" + ], + "details": "An issue was discovered in Infinera hiT 7300 5.60.50. A web application allows a remote privileged attacker to execute applications contained in a specific OS directory via HTTP invocations.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28811" + }, + { + "type": "WEB", + "url": "https://www.cvcn.gov.it/cvcn/cve/CVE-2024-28811" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-30T19:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3hc5-r53w-6ph8/GHSA-3hc5-r53w-6ph8.json b/advisories/unreviewed/2024/09/GHSA-3hc5-r53w-6ph8/GHSA-3hc5-r53w-6ph8.json index 5988f6db7b5..08d7e0351a1 100644 --- a/advisories/unreviewed/2024/09/GHSA-3hc5-r53w-6ph8/GHSA-3hc5-r53w-6ph8.json +++ b/advisories/unreviewed/2024/09/GHSA-3hc5-r53w-6ph8/GHSA-3hc5-r53w-6ph8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3hc5-r53w-6ph8", - "modified": "2024-09-25T03:30:36Z", + "modified": "2024-09-30T21:02:12Z", "published": "2024-09-25T03:30:36Z", "aliases": [ "CVE-2024-8941" diff --git a/advisories/unreviewed/2024/09/GHSA-3vv9-hcm7-cvjm/GHSA-3vv9-hcm7-cvjm.json b/advisories/unreviewed/2024/09/GHSA-3vv9-hcm7-cvjm/GHSA-3vv9-hcm7-cvjm.json index a62a276b02b..f63cb2ac1b2 100644 --- a/advisories/unreviewed/2024/09/GHSA-3vv9-hcm7-cvjm/GHSA-3vv9-hcm7-cvjm.json +++ b/advisories/unreviewed/2024/09/GHSA-3vv9-hcm7-cvjm/GHSA-3vv9-hcm7-cvjm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3vv9-hcm7-cvjm", - "modified": "2024-09-30T18:31:36Z", + "modified": "2024-09-30T21:02:12Z", "published": "2024-09-30T18:31:36Z", "aliases": [ "CVE-2024-46475" ], "details": "A reflected cross-site scripting (XSS) vulnerability on the homepage of Metronic Admin Dashboard Template v2.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-30T16:15:09Z" diff --git a/advisories/unreviewed/2024/09/GHSA-486w-gh7g-6cf2/GHSA-486w-gh7g-6cf2.json b/advisories/unreviewed/2024/09/GHSA-486w-gh7g-6cf2/GHSA-486w-gh7g-6cf2.json new file mode 100644 index 00000000000..1fa22902359 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-486w-gh7g-6cf2/GHSA-486w-gh7g-6cf2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-486w-gh7g-6cf2", + "modified": "2024-09-30T21:02:13Z", + "published": "2024-09-30T21:02:13Z", + "aliases": [ + "CVE-2024-28813" + ], + "details": "An issue was discovered in Infinera hiT 7300 5.60.50. Undocumented privileged functions in the @CT management application allow an attacker to activate remote SSH access to the appliance via an unexpected network interface.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28813" + }, + { + "type": "WEB", + "url": "https://www.cvcn.gov.it/cvcn/cve/CVE-2024-28813" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-30T19:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-57m6-hpvh-pg7p/GHSA-57m6-hpvh-pg7p.json b/advisories/unreviewed/2024/09/GHSA-57m6-hpvh-pg7p/GHSA-57m6-hpvh-pg7p.json index ddb424c5fe9..30ec0634a22 100644 --- a/advisories/unreviewed/2024/09/GHSA-57m6-hpvh-pg7p/GHSA-57m6-hpvh-pg7p.json +++ b/advisories/unreviewed/2024/09/GHSA-57m6-hpvh-pg7p/GHSA-57m6-hpvh-pg7p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-57m6-hpvh-pg7p", - "modified": "2024-09-30T15:30:49Z", + "modified": "2024-09-30T21:02:12Z", "published": "2024-09-30T15:30:49Z", "aliases": [ "CVE-2024-46313" ], "details": "TP-Link WR941ND V6 has a stack overflow vulnerability in the ssid parameter in /userRpm/popupSiteSurveyRpm.htm.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-30T15:15:06Z" diff --git a/advisories/unreviewed/2024/09/GHSA-6399-3x37-fjv2/GHSA-6399-3x37-fjv2.json b/advisories/unreviewed/2024/09/GHSA-6399-3x37-fjv2/GHSA-6399-3x37-fjv2.json index 4db283e0118..760e0096f56 100644 --- a/advisories/unreviewed/2024/09/GHSA-6399-3x37-fjv2/GHSA-6399-3x37-fjv2.json +++ b/advisories/unreviewed/2024/09/GHSA-6399-3x37-fjv2/GHSA-6399-3x37-fjv2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6399-3x37-fjv2", - "modified": "2024-09-30T15:30:49Z", + "modified": "2024-09-30T21:02:12Z", "published": "2024-09-30T15:30:49Z", "aliases": [ "CVE-2024-45920" ], "details": "A Stored Cross-Site Scripting (XSS) vulnerability in Solvait 24.4.2 allows remote attackers to inject malicious scripts into the application. This issue arises due to insufficient input validation and sanitization in \"Intrest\" feature.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-30T13:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-7p9w-p89x-5ghq/GHSA-7p9w-p89x-5ghq.json b/advisories/unreviewed/2024/09/GHSA-7p9w-p89x-5ghq/GHSA-7p9w-p89x-5ghq.json index 6210021b134..11ece89fe85 100644 --- a/advisories/unreviewed/2024/09/GHSA-7p9w-p89x-5ghq/GHSA-7p9w-p89x-5ghq.json +++ b/advisories/unreviewed/2024/09/GHSA-7p9w-p89x-5ghq/GHSA-7p9w-p89x-5ghq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7p9w-p89x-5ghq", - "modified": "2024-09-30T09:30:46Z", + "modified": "2024-09-30T21:02:12Z", "published": "2024-09-30T09:30:46Z", "aliases": [ "CVE-2024-45200" ], "details": "In Nintendo Mario Kart 8 Deluxe before 3.0.3, the LAN/LDN local multiplayer implementation allows a remote attacker to exploit a stack-based buffer overflow upon deserialization of session information via a malformed browse-reply packet, aka KartLANPwn. The victim is not required to join a game session with an attacker. The victim must open the \"Wireless Play\" (or \"LAN Play\") menu from the game's title screen, and an attacker nearby (LDN) or on the same LAN network as the victim can send a crafted reply packet to the victim's console. This enables a remote attacker to obtain complete denial-of-service on the game's process, or potentially, remote code execution on the victim's console. The issue is caused by incorrect use of the Nintendo Pia library,", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-30T08:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-cmwc-rx53-qx3h/GHSA-cmwc-rx53-qx3h.json b/advisories/unreviewed/2024/09/GHSA-cmwc-rx53-qx3h/GHSA-cmwc-rx53-qx3h.json new file mode 100644 index 00000000000..fb3659c3af5 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-cmwc-rx53-qx3h/GHSA-cmwc-rx53-qx3h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmwc-rx53-qx3h", + "modified": "2024-09-30T21:02:13Z", + "published": "2024-09-30T21:02:13Z", + "aliases": [ + "CVE-2024-28810" + ], + "details": "An issue was discovered in Infinera hiT 7300 5.60.50. Sensitive information inside diagnostic files (exported by the @CT application) allows an attacker to achieve loss of confidentiality by analyzing these files.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28810" + }, + { + "type": "WEB", + "url": "https://www.cvcn.gov.it/cvcn/cve/CVE-2024-28810" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-30T19:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-f4fp-grgf-crcx/GHSA-f4fp-grgf-crcx.json b/advisories/unreviewed/2024/09/GHSA-f4fp-grgf-crcx/GHSA-f4fp-grgf-crcx.json new file mode 100644 index 00000000000..4b8ef4a2816 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-f4fp-grgf-crcx/GHSA-f4fp-grgf-crcx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4fp-grgf-crcx", + "modified": "2024-09-30T21:02:13Z", + "published": "2024-09-30T21:02:13Z", + "aliases": [ + "CVE-2024-28812" + ], + "details": "An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) with hardcoded credentials allows attackers to access the appliance operating system (with highest privileges) via an SSH connection.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28812" + }, + { + "type": "WEB", + "url": "https://www.cvcn.gov.it/cvcn/cve/CVE-2024-28812" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-30T19:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-hgwc-f2wf-xrf8/GHSA-hgwc-f2wf-xrf8.json b/advisories/unreviewed/2024/09/GHSA-hgwc-f2wf-xrf8/GHSA-hgwc-f2wf-xrf8.json index 82ab86947c5..505bfca223a 100644 --- a/advisories/unreviewed/2024/09/GHSA-hgwc-f2wf-xrf8/GHSA-hgwc-f2wf-xrf8.json +++ b/advisories/unreviewed/2024/09/GHSA-hgwc-f2wf-xrf8/GHSA-hgwc-f2wf-xrf8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hgwc-f2wf-xrf8", - "modified": "2024-09-30T18:31:36Z", + "modified": "2024-09-30T21:02:13Z", "published": "2024-09-30T18:31:36Z", "aliases": [ "CVE-2024-46540" ], "details": "A remote code execution (RCE) vulnerability in the component /admin/store.php of Emlog Pro before v2.3.15 allows attackers to use remote file downloads and self-extract fucntions to upload webshells to the target server, thereby obtaining system privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-266" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-30T17:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-m27f-2cq8-j66v/GHSA-m27f-2cq8-j66v.json b/advisories/unreviewed/2024/09/GHSA-m27f-2cq8-j66v/GHSA-m27f-2cq8-j66v.json index 347cc24757e..fe353115eea 100644 --- a/advisories/unreviewed/2024/09/GHSA-m27f-2cq8-j66v/GHSA-m27f-2cq8-j66v.json +++ b/advisories/unreviewed/2024/09/GHSA-m27f-2cq8-j66v/GHSA-m27f-2cq8-j66v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m27f-2cq8-j66v", - "modified": "2024-09-30T15:30:49Z", + "modified": "2024-09-30T21:02:12Z", "published": "2024-09-30T15:30:49Z", "aliases": [ "CVE-2024-46280" ], "details": "PIX-LINK LV-WR22 RE3002-P1-01_V117.0 is vulnerable to Improper Access Control. The TELNET service is enabled with weak credentials for a root-level account, without the possibility of changing them.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-30T15:15:06Z" diff --git a/advisories/unreviewed/2024/09/GHSA-m6g3-ch98-vrmr/GHSA-m6g3-ch98-vrmr.json b/advisories/unreviewed/2024/09/GHSA-m6g3-ch98-vrmr/GHSA-m6g3-ch98-vrmr.json index 5b0e77bcd6c..3f012e81625 100644 --- a/advisories/unreviewed/2024/09/GHSA-m6g3-ch98-vrmr/GHSA-m6g3-ch98-vrmr.json +++ b/advisories/unreviewed/2024/09/GHSA-m6g3-ch98-vrmr/GHSA-m6g3-ch98-vrmr.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m6g3-ch98-vrmr", - "modified": "2024-09-19T18:30:51Z", + "modified": "2024-09-30T21:02:12Z", "published": "2024-09-19T18:30:51Z", "aliases": [ "CVE-2024-45861" ], "details": "Kastle Systems firmware prior to May 1, 2024, contained a hard-coded credential, which if accessed may allow an attacker to access sensitive information.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-pp67-vh85-488h/GHSA-pp67-vh85-488h.json b/advisories/unreviewed/2024/09/GHSA-pp67-vh85-488h/GHSA-pp67-vh85-488h.json index 9f8bf8bdf76..8139e843c51 100644 --- a/advisories/unreviewed/2024/09/GHSA-pp67-vh85-488h/GHSA-pp67-vh85-488h.json +++ b/advisories/unreviewed/2024/09/GHSA-pp67-vh85-488h/GHSA-pp67-vh85-488h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pp67-vh85-488h", - "modified": "2024-09-30T18:31:36Z", + "modified": "2024-09-30T21:02:12Z", "published": "2024-09-30T18:31:36Z", "aliases": [ "CVE-2024-45993" ], "details": "Giflib Project v5.2.2 is vulnerable to a heap buffer overflow via gif2rgb.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-30T17:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-qh4m-mqcp-x24m/GHSA-qh4m-mqcp-x24m.json b/advisories/unreviewed/2024/09/GHSA-qh4m-mqcp-x24m/GHSA-qh4m-mqcp-x24m.json index 127658d4167..ddb713b663c 100644 --- a/advisories/unreviewed/2024/09/GHSA-qh4m-mqcp-x24m/GHSA-qh4m-mqcp-x24m.json +++ b/advisories/unreviewed/2024/09/GHSA-qh4m-mqcp-x24m/GHSA-qh4m-mqcp-x24m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qh4m-mqcp-x24m", - "modified": "2024-09-17T00:31:06Z", + "modified": "2024-09-30T21:02:12Z", "published": "2024-09-17T00:31:06Z", "aliases": [ "CVE-2024-44170" ], "details": "A privacy issue was addressed by moving sensitive data to a more secure location. This issue is fixed in iOS 18 and iPadOS 18, watchOS 11, macOS Sequoia 15. An app may be able to access user-sensitive data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:51Z" diff --git a/advisories/unreviewed/2024/09/GHSA-rvmx-xw47-rh9g/GHSA-rvmx-xw47-rh9g.json b/advisories/unreviewed/2024/09/GHSA-rvmx-xw47-rh9g/GHSA-rvmx-xw47-rh9g.json index f59a439d01c..9752f5ad2d6 100644 --- a/advisories/unreviewed/2024/09/GHSA-rvmx-xw47-rh9g/GHSA-rvmx-xw47-rh9g.json +++ b/advisories/unreviewed/2024/09/GHSA-rvmx-xw47-rh9g/GHSA-rvmx-xw47-rh9g.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-209" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-v4f9-5946-4v4f/GHSA-v4f9-5946-4v4f.json b/advisories/unreviewed/2024/09/GHSA-v4f9-5946-4v4f/GHSA-v4f9-5946-4v4f.json index 5285610f3d7..974a87b092a 100644 --- a/advisories/unreviewed/2024/09/GHSA-v4f9-5946-4v4f/GHSA-v4f9-5946-4v4f.json +++ b/advisories/unreviewed/2024/09/GHSA-v4f9-5946-4v4f/GHSA-v4f9-5946-4v4f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v4f9-5946-4v4f", - "modified": "2024-09-30T15:30:49Z", + "modified": "2024-09-30T21:02:12Z", "published": "2024-09-30T15:30:49Z", "aliases": [ "CVE-2024-46293" ], "details": "Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authorization checks for admin operations. Specifically, an attacker can perform admin-level actions without possessing a valid session token. The application does not verify whether the user is logged in as an admin or even check for a session token at all.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-30T15:15:06Z" diff --git a/advisories/unreviewed/2024/09/GHSA-w9g7-h647-wg7j/GHSA-w9g7-h647-wg7j.json b/advisories/unreviewed/2024/09/GHSA-w9g7-h647-wg7j/GHSA-w9g7-h647-wg7j.json index 1d03352820a..389d08f97fe 100644 --- a/advisories/unreviewed/2024/09/GHSA-w9g7-h647-wg7j/GHSA-w9g7-h647-wg7j.json +++ b/advisories/unreviewed/2024/09/GHSA-w9g7-h647-wg7j/GHSA-w9g7-h647-wg7j.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w9g7-h647-wg7j", - "modified": "2024-09-19T18:30:51Z", + "modified": "2024-09-30T21:02:12Z", "published": "2024-09-19T18:30:51Z", "aliases": [ "CVE-2024-45862" ], "details": "Kastle Systems firmware prior to May 1, 2024, stored machine credentials in cleartext, which may allow an attacker to access sensitive information.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"