Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-11-26 21:33:25 +00:00
parent a39463db36
commit 871d8ea9bc
53 changed files with 1092 additions and 56 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vvf8-2h68-9475",
"modified": "2024-11-05T06:30:33Z",
"modified": "2024-11-26T21:32:22Z",
"published": "2024-09-19T18:30:52Z",
"aliases": [
"CVE-2024-8883"
@@ -111,6 +111,14 @@
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:6878"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:10386"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:10385"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fhqq-8f65-5xfc",
"modified": "2024-11-21T21:33:31Z",
"modified": "2024-11-26T21:32:22Z",
"published": "2024-10-01T21:31:35Z",
"aliases": [
"CVE-2024-9407"
@@ -161,6 +161,10 @@
"type": "WEB",
"url": "https://github.com/containers/buildah/commit/e4e2ad5ca2088d7c388109394135ead7aaf1f4f4"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:10147"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:8846"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mc76-5925-c5p6",
"modified": "2024-11-22T22:26:57Z",
"modified": "2024-11-26T21:32:22Z",
"published": "2024-10-01T21:31:34Z",
"aliases": [
"CVE-2024-9341"
@@ -111,6 +111,10 @@
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:7925"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:10147"
}
],
"database_specific": {
@@ -36,7 +36,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-290"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-640"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-640"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-59"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-863"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-787"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qjx2-rcx8-qr2r",
"modified": "2024-09-10T21:31:40Z",
"modified": "2024-11-26T21:32:22Z",
"published": "2024-09-10T21:31:40Z",
"aliases": [
"CVE-2024-8190"
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Service-Appliance-CSA-CVE-2024-8190"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/alerts/2024/09/13/ivanti-releases-security-update-cloud-services-appliance"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hm3j-qgpw-pj98",
"modified": "2024-11-18T21:30:43Z",
"modified": "2024-11-26T21:32:22Z",
"published": "2024-10-09T15:32:18Z",
"aliases": [
"CVE-2024-9680"
@@ -21,10 +21,18 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9680"
},
{
"type": "WEB",
"url": "https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=281992"
},
{
"type": "WEB",
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1923344"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/10/msg00005.html"
},
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-49039"
@@ -0,0 +1,58 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2f2j-v2q5-34f3",
"modified": "2024-11-26T21:32:25Z",
"published": "2024-11-26T21:32:25Z",
"aliases": [
"CVE-2024-11745"
],
"details": "A vulnerability was found in Tenda AC8 16.03.34.09 and classified as critical. Affected by this issue is the function route_static_check of the file /goform/SetStaticRouteCfg. The manipulation of the argument list leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11745"
},
{
"type": "WEB",
"url": "https://tasty-foxtrot-3a8.notion.site/Tenda-AC8v4-route_static_check-stack-overflow-1460448e6195803087a5d39755d2bb6b?pvs=74"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.286142"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.286142"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.449893"
},
{
"type": "WEB",
"url": "https://www.tenda.com.cn"
}
],
"database_specific": {
"cwe_ids": [
"CWE-119"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-26T21:15:06Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3f8f-56cp-m994",
"modified": "2024-11-26T18:38:52Z",
"modified": "2024-11-26T21:32:24Z",
"published": "2024-11-26T18:38:52Z",
"aliases": [
"CVE-2024-53555"
],
"details": "A CSV injection vulnerability in Taiga v6.8.1 allows attackers to execute arbitrary code via uploading a crafted CSV file.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-1236"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-26T17:15:26Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4696-66c4-2gvx",
"modified": "2024-11-19T18:31:06Z",
"modified": "2024-11-26T21:32:23Z",
"published": "2024-11-19T18:31:06Z",
"aliases": [
"CVE-2024-48991"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48991"
},
{
"type": "WEB",
"url": "https://github.com/liske/needrestart/commit/42af5d328901287a4f79d1f5861ac827a53fd56d"
},
{
"type": "WEB",
"url": "https://github.com/liske/needrestart/commit/6ce6136cccc307c6b8a0f8cae12f9a22ac2aad59"
@@ -0,0 +1,58 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4f47-wxrx-fmj7",
"modified": "2024-11-26T21:32:24Z",
"published": "2024-11-26T21:32:24Z",
"aliases": [
"CVE-2024-11742"
],
"details": "A vulnerability, which was classified as problematic, has been found in SourceCodester Best House Rental Management System 1.0. This issue affects some unknown processing of the file /rental/ajax.php?action=save_tenant. The manipulation of the argument lastname/firstname/middlename leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11742"
},
{
"type": "WEB",
"url": "https://github.com/YasserREED/YasserREED-CVEs/blob/main/Best%20house%20rental%20management%20system%20project%20in%20php/Stored%20Cross-Site%20Scripting%20(XSS).md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.286139"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.286139"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.449683"
},
{
"type": "WEB",
"url": "https://www.sourcecodester.com"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-26T20:15:25Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4q69-rp52-xhqw",
"modified": "2024-11-26T21:32:24Z",
"published": "2024-11-26T21:32:24Z",
"aliases": [
"CVE-2024-53619"
],
"details": "An authenticated arbitrary file upload vulnerability in the Documents module of SPIP v4.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53619"
},
{
"type": "WEB",
"url": "https://grimthereaperteam.medium.com/spip-4-3-3-malicious-file-upload-xss-in-pdf-526c03bb1776"
}
],
"database_specific": {
"cwe_ids": [
"CWE-434"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-26T19:15:30Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4vvm-5cw4-4q22",
"modified": "2024-11-26T21:32:25Z",
"published": "2024-11-26T21:32:25Z",
"aliases": [
"CVE-2024-49052"
],
"details": "Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49052"
},
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49052"
}
],
"database_specific": {
"cwe_ids": [
"CWE-306"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-26T20:15:32Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5mv2-m792-g4pg",
"modified": "2024-11-26T21:32:24Z",
"published": "2024-11-26T21:32:24Z",
"aliases": [
"CVE-2019-17082"
],
"details": "Missing Authentication for Critical Function vulnerability in OpenText™ AccuRev for LDAP Integration allows Authentication Bypass. The vulnerability could allow \n\na valid AccuRev username to gain access to AccuRev source control without knowing the users password.\n\nThis issue affects AccuRev for LDAP Integration: 2017.1.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:I/V:C/RE:M/U:Red"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2019-17082"
},
{
"type": "WEB",
"url": "https://support.microfocus.com/kb/kmdoc.php?id=KM03544106"
}
],
"database_specific": {
"cwe_ids": [
"CWE-306"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-26T20:15:19Z"
}
}

Some files were not shown because too many files have changed in this diff Show More