From 871d8ea9bc734f2eaf9e4ca5eac28a0dd21a55ef Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 26 Nov 2024 21:33:25 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-vvf8-2h68-9475.json | 10 +++- .../GHSA-fhqq-8f65-5xfc.json | 6 +- .../GHSA-mc76-5925-c5p6.json | 6 +- .../GHSA-f5vv-hcgf-xvxq.json | 2 +- .../GHSA-jx37-m37q-v7c2.json | 2 +- .../GHSA-pmmp-296p-3p5g.json | 2 +- .../GHSA-v5mf-vjw2-x655.json | 2 +- .../GHSA-x3q7-hmmp-xprv.json | 2 +- .../GHSA-9chj-jjcm-3mr7.json | 2 +- .../GHSA-q9j5-9g8p-5h5q.json | 3 +- .../GHSA-x6rx-7w39-qpg5.json | 3 +- .../GHSA-qjx2-rcx8-qr2r.json | 6 +- .../GHSA-hm3j-qgpw-pj98.json | 10 +++- .../GHSA-2f2j-v2q5-34f3.json | 58 +++++++++++++++++++ .../GHSA-3f8f-56cp-m994.json | 11 ++-- .../GHSA-4696-66c4-2gvx.json | 6 +- .../GHSA-4f47-wxrx-fmj7.json | 58 +++++++++++++++++++ .../GHSA-4q69-rp52-xhqw.json | 38 ++++++++++++ .../GHSA-4vvm-5cw4-4q22.json | 38 ++++++++++++ .../GHSA-5mv2-m792-g4pg.json | 38 ++++++++++++ .../GHSA-69hg-2xq4-4m8v.json | 11 ++-- .../GHSA-6cqf-gqr3-8cr4.json | 43 ++++++++++++++ .../GHSA-8c3c-gvf8-p7v2.json | 10 +++- .../GHSA-8cwc-g9gg-qp9w.json | 46 +++++++++++++++ .../GHSA-94xw-8rg2-4fmc.json | 42 ++++++++++++++ .../GHSA-9g7f-8r42-f32m.json | 9 ++- .../GHSA-9qqr-v783-v57r.json | 38 ++++++++++++ .../GHSA-9vv4-rwwg-wc6h.json | 11 ++-- .../GHSA-cfjc-m7fv-63xj.json | 6 +- .../GHSA-cgcp-gvp8-4fpv.json | 42 ++++++++++++++ .../GHSA-cwgj-pq49-6x66.json | 3 +- .../GHSA-f5r5-77wf-xx6h.json | 42 ++++++++++++++ .../GHSA-f82f-w24c-j3ww.json | 42 ++++++++++++++ .../GHSA-g446-rqm3-4h89.json | 9 ++- .../GHSA-g797-r4r7-wp94.json | 38 ++++++++++++ .../GHSA-g7hv-g729-xq68.json | 3 +- .../GHSA-g863-pp98-8m8m.json | 2 +- .../GHSA-hx7r-qwxv-w9j9.json | 9 ++- .../GHSA-j27h-7c89-c3c6.json | 6 +- .../GHSA-m22p-g7xv-5j93.json | 58 +++++++++++++++++++ .../GHSA-p972-2fg6-pw4j.json | 11 ++-- .../GHSA-pvxj-chgv-3rj7.json | 38 ++++++++++++ .../GHSA-qcjh-2fxc-73fr.json | 38 ++++++++++++ .../GHSA-r3mm-qxv5-x23h.json | 42 ++++++++++++++ .../GHSA-r642-x62f-jqhp.json | 9 ++- .../GHSA-rfmc-j4j9-f2cc.json | 38 ++++++++++++ .../GHSA-rmhm-cwgp-268p.json | 42 ++++++++++++++ .../GHSA-rmv2-8jjc-23xw.json | 11 ++-- .../GHSA-v84c-53c6-xmmp.json | 38 ++++++++++++ .../GHSA-vhvx-3f4j-g64m.json | 58 +++++++++++++++++++ .../GHSA-w69p-wm6c-5486.json | 38 ++++++++++++ .../GHSA-wh54-vv47-2265.json | 3 +- .../GHSA-xxc6-q6r3-h584.json | 9 ++- 53 files changed, 1092 insertions(+), 56 deletions(-) create mode 100644 advisories/unreviewed/2024/11/GHSA-2f2j-v2q5-34f3/GHSA-2f2j-v2q5-34f3.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4f47-wxrx-fmj7/GHSA-4f47-wxrx-fmj7.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4q69-rp52-xhqw/GHSA-4q69-rp52-xhqw.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4vvm-5cw4-4q22/GHSA-4vvm-5cw4-4q22.json create mode 100644 advisories/unreviewed/2024/11/GHSA-5mv2-m792-g4pg/GHSA-5mv2-m792-g4pg.json create mode 100644 advisories/unreviewed/2024/11/GHSA-6cqf-gqr3-8cr4/GHSA-6cqf-gqr3-8cr4.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8cwc-g9gg-qp9w/GHSA-8cwc-g9gg-qp9w.json create mode 100644 advisories/unreviewed/2024/11/GHSA-94xw-8rg2-4fmc/GHSA-94xw-8rg2-4fmc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9qqr-v783-v57r/GHSA-9qqr-v783-v57r.json create mode 100644 advisories/unreviewed/2024/11/GHSA-cgcp-gvp8-4fpv/GHSA-cgcp-gvp8-4fpv.json create mode 100644 advisories/unreviewed/2024/11/GHSA-f5r5-77wf-xx6h/GHSA-f5r5-77wf-xx6h.json create mode 100644 advisories/unreviewed/2024/11/GHSA-f82f-w24c-j3ww/GHSA-f82f-w24c-j3ww.json create mode 100644 advisories/unreviewed/2024/11/GHSA-g797-r4r7-wp94/GHSA-g797-r4r7-wp94.json create mode 100644 advisories/unreviewed/2024/11/GHSA-m22p-g7xv-5j93/GHSA-m22p-g7xv-5j93.json create mode 100644 advisories/unreviewed/2024/11/GHSA-pvxj-chgv-3rj7/GHSA-pvxj-chgv-3rj7.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qcjh-2fxc-73fr/GHSA-qcjh-2fxc-73fr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-r3mm-qxv5-x23h/GHSA-r3mm-qxv5-x23h.json create mode 100644 advisories/unreviewed/2024/11/GHSA-rfmc-j4j9-f2cc/GHSA-rfmc-j4j9-f2cc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-rmhm-cwgp-268p/GHSA-rmhm-cwgp-268p.json create mode 100644 advisories/unreviewed/2024/11/GHSA-v84c-53c6-xmmp/GHSA-v84c-53c6-xmmp.json create mode 100644 advisories/unreviewed/2024/11/GHSA-vhvx-3f4j-g64m/GHSA-vhvx-3f4j-g64m.json create mode 100644 advisories/unreviewed/2024/11/GHSA-w69p-wm6c-5486/GHSA-w69p-wm6c-5486.json diff --git a/advisories/github-reviewed/2024/09/GHSA-vvf8-2h68-9475/GHSA-vvf8-2h68-9475.json b/advisories/github-reviewed/2024/09/GHSA-vvf8-2h68-9475/GHSA-vvf8-2h68-9475.json index e99477b8d0a..5b0478841e1 100644 --- a/advisories/github-reviewed/2024/09/GHSA-vvf8-2h68-9475/GHSA-vvf8-2h68-9475.json +++ b/advisories/github-reviewed/2024/09/GHSA-vvf8-2h68-9475/GHSA-vvf8-2h68-9475.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vvf8-2h68-9475", - "modified": "2024-11-05T06:30:33Z", + "modified": "2024-11-26T21:32:22Z", "published": "2024-09-19T18:30:52Z", "aliases": [ "CVE-2024-8883" @@ -111,6 +111,14 @@ { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:6878" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:10386" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:10385" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/10/GHSA-fhqq-8f65-5xfc/GHSA-fhqq-8f65-5xfc.json b/advisories/github-reviewed/2024/10/GHSA-fhqq-8f65-5xfc/GHSA-fhqq-8f65-5xfc.json index 5871ffce847..9540641bb58 100644 --- a/advisories/github-reviewed/2024/10/GHSA-fhqq-8f65-5xfc/GHSA-fhqq-8f65-5xfc.json +++ b/advisories/github-reviewed/2024/10/GHSA-fhqq-8f65-5xfc/GHSA-fhqq-8f65-5xfc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fhqq-8f65-5xfc", - "modified": "2024-11-21T21:33:31Z", + "modified": "2024-11-26T21:32:22Z", "published": "2024-10-01T21:31:35Z", "aliases": [ "CVE-2024-9407" @@ -161,6 +161,10 @@ "type": "WEB", "url": "https://github.com/containers/buildah/commit/e4e2ad5ca2088d7c388109394135ead7aaf1f4f4" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:10147" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:8846" diff --git a/advisories/github-reviewed/2024/10/GHSA-mc76-5925-c5p6/GHSA-mc76-5925-c5p6.json b/advisories/github-reviewed/2024/10/GHSA-mc76-5925-c5p6/GHSA-mc76-5925-c5p6.json index 5dc9aaf5959..ec41fae40d4 100644 --- a/advisories/github-reviewed/2024/10/GHSA-mc76-5925-c5p6/GHSA-mc76-5925-c5p6.json +++ b/advisories/github-reviewed/2024/10/GHSA-mc76-5925-c5p6/GHSA-mc76-5925-c5p6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mc76-5925-c5p6", - "modified": "2024-11-22T22:26:57Z", + "modified": "2024-11-26T21:32:22Z", "published": "2024-10-01T21:31:34Z", "aliases": [ "CVE-2024-9341" @@ -111,6 +111,10 @@ { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:7925" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:10147" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/06/GHSA-f5vv-hcgf-xvxq/GHSA-f5vv-hcgf-xvxq.json b/advisories/unreviewed/2023/06/GHSA-f5vv-hcgf-xvxq/GHSA-f5vv-hcgf-xvxq.json index 8251269183d..8d2d88d039d 100644 --- a/advisories/unreviewed/2023/06/GHSA-f5vv-hcgf-xvxq/GHSA-f5vv-hcgf-xvxq.json +++ b/advisories/unreviewed/2023/06/GHSA-f5vv-hcgf-xvxq/GHSA-f5vv-hcgf-xvxq.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-jx37-m37q-v7c2/GHSA-jx37-m37q-v7c2.json b/advisories/unreviewed/2023/06/GHSA-jx37-m37q-v7c2/GHSA-jx37-m37q-v7c2.json index 9db50b80202..982ebff6d13 100644 --- a/advisories/unreviewed/2023/06/GHSA-jx37-m37q-v7c2/GHSA-jx37-m37q-v7c2.json +++ b/advisories/unreviewed/2023/06/GHSA-jx37-m37q-v7c2/GHSA-jx37-m37q-v7c2.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-290" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-pmmp-296p-3p5g/GHSA-pmmp-296p-3p5g.json b/advisories/unreviewed/2023/06/GHSA-pmmp-296p-3p5g/GHSA-pmmp-296p-3p5g.json index a08731b6476..e20f4bb751a 100644 --- a/advisories/unreviewed/2023/06/GHSA-pmmp-296p-3p5g/GHSA-pmmp-296p-3p5g.json +++ b/advisories/unreviewed/2023/06/GHSA-pmmp-296p-3p5g/GHSA-pmmp-296p-3p5g.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-640" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-v5mf-vjw2-x655/GHSA-v5mf-vjw2-x655.json b/advisories/unreviewed/2023/06/GHSA-v5mf-vjw2-x655/GHSA-v5mf-vjw2-x655.json index 53225e92092..9eebe7120c7 100644 --- a/advisories/unreviewed/2023/06/GHSA-v5mf-vjw2-x655/GHSA-v5mf-vjw2-x655.json +++ b/advisories/unreviewed/2023/06/GHSA-v5mf-vjw2-x655/GHSA-v5mf-vjw2-x655.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-640" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-x3q7-hmmp-xprv/GHSA-x3q7-hmmp-xprv.json b/advisories/unreviewed/2023/06/GHSA-x3q7-hmmp-xprv/GHSA-x3q7-hmmp-xprv.json index c655e11af07..14624571418 100644 --- a/advisories/unreviewed/2023/06/GHSA-x3q7-hmmp-xprv/GHSA-x3q7-hmmp-xprv.json +++ b/advisories/unreviewed/2023/06/GHSA-x3q7-hmmp-xprv/GHSA-x3q7-hmmp-xprv.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-9chj-jjcm-3mr7/GHSA-9chj-jjcm-3mr7.json b/advisories/unreviewed/2023/07/GHSA-9chj-jjcm-3mr7/GHSA-9chj-jjcm-3mr7.json index a274fb1069f..91a0eba8bd6 100644 --- a/advisories/unreviewed/2023/07/GHSA-9chj-jjcm-3mr7/GHSA-9chj-jjcm-3mr7.json +++ b/advisories/unreviewed/2023/07/GHSA-9chj-jjcm-3mr7/GHSA-9chj-jjcm-3mr7.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-q9j5-9g8p-5h5q/GHSA-q9j5-9g8p-5h5q.json b/advisories/unreviewed/2024/08/GHSA-q9j5-9g8p-5h5q/GHSA-q9j5-9g8p-5h5q.json index d2fca9dfff8..1804fa9d83e 100644 --- a/advisories/unreviewed/2024/08/GHSA-q9j5-9g8p-5h5q/GHSA-q9j5-9g8p-5h5q.json +++ b/advisories/unreviewed/2024/08/GHSA-q9j5-9g8p-5h5q/GHSA-q9j5-9g8p-5h5q.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-x6rx-7w39-qpg5/GHSA-x6rx-7w39-qpg5.json b/advisories/unreviewed/2024/08/GHSA-x6rx-7w39-qpg5/GHSA-x6rx-7w39-qpg5.json index 2f05645d87c..108ca3fa5b6 100644 --- a/advisories/unreviewed/2024/08/GHSA-x6rx-7w39-qpg5/GHSA-x6rx-7w39-qpg5.json +++ b/advisories/unreviewed/2024/08/GHSA-x6rx-7w39-qpg5/GHSA-x6rx-7w39-qpg5.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-qjx2-rcx8-qr2r/GHSA-qjx2-rcx8-qr2r.json b/advisories/unreviewed/2024/09/GHSA-qjx2-rcx8-qr2r/GHSA-qjx2-rcx8-qr2r.json index b0a1fba71d5..3a6cd230abb 100644 --- a/advisories/unreviewed/2024/09/GHSA-qjx2-rcx8-qr2r/GHSA-qjx2-rcx8-qr2r.json +++ b/advisories/unreviewed/2024/09/GHSA-qjx2-rcx8-qr2r/GHSA-qjx2-rcx8-qr2r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qjx2-rcx8-qr2r", - "modified": "2024-09-10T21:31:40Z", + "modified": "2024-11-26T21:32:22Z", "published": "2024-09-10T21:31:40Z", "aliases": [ "CVE-2024-8190" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Service-Appliance-CSA-CVE-2024-8190" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/alerts/2024/09/13/ivanti-releases-security-update-cloud-services-appliance" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-hm3j-qgpw-pj98/GHSA-hm3j-qgpw-pj98.json b/advisories/unreviewed/2024/10/GHSA-hm3j-qgpw-pj98/GHSA-hm3j-qgpw-pj98.json index 0d3ba6ead49..48ad73524e9 100644 --- a/advisories/unreviewed/2024/10/GHSA-hm3j-qgpw-pj98/GHSA-hm3j-qgpw-pj98.json +++ b/advisories/unreviewed/2024/10/GHSA-hm3j-qgpw-pj98/GHSA-hm3j-qgpw-pj98.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hm3j-qgpw-pj98", - "modified": "2024-11-18T21:30:43Z", + "modified": "2024-11-26T21:32:22Z", "published": "2024-10-09T15:32:18Z", "aliases": [ "CVE-2024-9680" @@ -21,10 +21,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9680" }, + { + "type": "WEB", + "url": "https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=281992" + }, { "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1923344" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/10/msg00005.html" + }, { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-49039" diff --git a/advisories/unreviewed/2024/11/GHSA-2f2j-v2q5-34f3/GHSA-2f2j-v2q5-34f3.json b/advisories/unreviewed/2024/11/GHSA-2f2j-v2q5-34f3/GHSA-2f2j-v2q5-34f3.json new file mode 100644 index 00000000000..a032341a67d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2f2j-v2q5-34f3/GHSA-2f2j-v2q5-34f3.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2f2j-v2q5-34f3", + "modified": "2024-11-26T21:32:25Z", + "published": "2024-11-26T21:32:25Z", + "aliases": [ + "CVE-2024-11745" + ], + "details": "A vulnerability was found in Tenda AC8 16.03.34.09 and classified as critical. Affected by this issue is the function route_static_check of the file /goform/SetStaticRouteCfg. The manipulation of the argument list leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11745" + }, + { + "type": "WEB", + "url": "https://tasty-foxtrot-3a8.notion.site/Tenda-AC8v4-route_static_check-stack-overflow-1460448e6195803087a5d39755d2bb6b?pvs=74" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.286142" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.286142" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.449893" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T21:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3f8f-56cp-m994/GHSA-3f8f-56cp-m994.json b/advisories/unreviewed/2024/11/GHSA-3f8f-56cp-m994/GHSA-3f8f-56cp-m994.json index c9a22e45ad5..cde34ae1f08 100644 --- a/advisories/unreviewed/2024/11/GHSA-3f8f-56cp-m994/GHSA-3f8f-56cp-m994.json +++ b/advisories/unreviewed/2024/11/GHSA-3f8f-56cp-m994/GHSA-3f8f-56cp-m994.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3f8f-56cp-m994", - "modified": "2024-11-26T18:38:52Z", + "modified": "2024-11-26T21:32:24Z", "published": "2024-11-26T18:38:52Z", "aliases": [ "CVE-2024-53555" ], "details": "A CSV injection vulnerability in Taiga v6.8.1 allows attackers to execute arbitrary code via uploading a crafted CSV file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1236" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-26T17:15:26Z" diff --git a/advisories/unreviewed/2024/11/GHSA-4696-66c4-2gvx/GHSA-4696-66c4-2gvx.json b/advisories/unreviewed/2024/11/GHSA-4696-66c4-2gvx/GHSA-4696-66c4-2gvx.json index 0e3942115c9..a4753602a1a 100644 --- a/advisories/unreviewed/2024/11/GHSA-4696-66c4-2gvx/GHSA-4696-66c4-2gvx.json +++ b/advisories/unreviewed/2024/11/GHSA-4696-66c4-2gvx/GHSA-4696-66c4-2gvx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4696-66c4-2gvx", - "modified": "2024-11-19T18:31:06Z", + "modified": "2024-11-26T21:32:23Z", "published": "2024-11-19T18:31:06Z", "aliases": [ "CVE-2024-48991" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48991" }, + { + "type": "WEB", + "url": "https://github.com/liske/needrestart/commit/42af5d328901287a4f79d1f5861ac827a53fd56d" + }, { "type": "WEB", "url": "https://github.com/liske/needrestart/commit/6ce6136cccc307c6b8a0f8cae12f9a22ac2aad59" diff --git a/advisories/unreviewed/2024/11/GHSA-4f47-wxrx-fmj7/GHSA-4f47-wxrx-fmj7.json b/advisories/unreviewed/2024/11/GHSA-4f47-wxrx-fmj7/GHSA-4f47-wxrx-fmj7.json new file mode 100644 index 00000000000..caf42a14853 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4f47-wxrx-fmj7/GHSA-4f47-wxrx-fmj7.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4f47-wxrx-fmj7", + "modified": "2024-11-26T21:32:24Z", + "published": "2024-11-26T21:32:24Z", + "aliases": [ + "CVE-2024-11742" + ], + "details": "A vulnerability, which was classified as problematic, has been found in SourceCodester Best House Rental Management System 1.0. This issue affects some unknown processing of the file /rental/ajax.php?action=save_tenant. The manipulation of the argument lastname/firstname/middlename leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11742" + }, + { + "type": "WEB", + "url": "https://github.com/YasserREED/YasserREED-CVEs/blob/main/Best%20house%20rental%20management%20system%20project%20in%20php/Stored%20Cross-Site%20Scripting%20(XSS).md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.286139" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.286139" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.449683" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T20:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4q69-rp52-xhqw/GHSA-4q69-rp52-xhqw.json b/advisories/unreviewed/2024/11/GHSA-4q69-rp52-xhqw/GHSA-4q69-rp52-xhqw.json new file mode 100644 index 00000000000..0f32627e158 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4q69-rp52-xhqw/GHSA-4q69-rp52-xhqw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4q69-rp52-xhqw", + "modified": "2024-11-26T21:32:24Z", + "published": "2024-11-26T21:32:24Z", + "aliases": [ + "CVE-2024-53619" + ], + "details": "An authenticated arbitrary file upload vulnerability in the Documents module of SPIP v4.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53619" + }, + { + "type": "WEB", + "url": "https://grimthereaperteam.medium.com/spip-4-3-3-malicious-file-upload-xss-in-pdf-526c03bb1776" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T19:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4vvm-5cw4-4q22/GHSA-4vvm-5cw4-4q22.json b/advisories/unreviewed/2024/11/GHSA-4vvm-5cw4-4q22/GHSA-4vvm-5cw4-4q22.json new file mode 100644 index 00000000000..4ea75e8a28c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4vvm-5cw4-4q22/GHSA-4vvm-5cw4-4q22.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vvm-5cw4-4q22", + "modified": "2024-11-26T21:32:25Z", + "published": "2024-11-26T21:32:25Z", + "aliases": [ + "CVE-2024-49052" + ], + "details": "Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49052" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49052" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T20:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5mv2-m792-g4pg/GHSA-5mv2-m792-g4pg.json b/advisories/unreviewed/2024/11/GHSA-5mv2-m792-g4pg/GHSA-5mv2-m792-g4pg.json new file mode 100644 index 00000000000..2d7995cab53 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5mv2-m792-g4pg/GHSA-5mv2-m792-g4pg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mv2-m792-g4pg", + "modified": "2024-11-26T21:32:24Z", + "published": "2024-11-26T21:32:24Z", + "aliases": [ + "CVE-2019-17082" + ], + "details": "Missing Authentication for Critical Function vulnerability in OpenText™ AccuRev for LDAP Integration allows Authentication Bypass. The vulnerability could allow \n\na valid AccuRev username to gain access to AccuRev source control without knowing the user’s password.\n\nThis issue affects AccuRev for LDAP Integration: 2017.1.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:I/V:C/RE:M/U:Red" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-17082" + }, + { + "type": "WEB", + "url": "https://support.microfocus.com/kb/kmdoc.php?id=KM03544106" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T20:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-69hg-2xq4-4m8v/GHSA-69hg-2xq4-4m8v.json b/advisories/unreviewed/2024/11/GHSA-69hg-2xq4-4m8v/GHSA-69hg-2xq4-4m8v.json index ff24a6e2eca..188f93cbdc6 100644 --- a/advisories/unreviewed/2024/11/GHSA-69hg-2xq4-4m8v/GHSA-69hg-2xq4-4m8v.json +++ b/advisories/unreviewed/2024/11/GHSA-69hg-2xq4-4m8v/GHSA-69hg-2xq4-4m8v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-69hg-2xq4-4m8v", - "modified": "2024-11-15T18:30:51Z", + "modified": "2024-11-26T21:32:23Z", "published": "2024-11-15T18:30:51Z", "aliases": [ "CVE-2024-24449" ], "details": "An uninitialized pointer dereference in the NasPdu::NasPdu component of OpenAirInterface CN5G AMF up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted InitialUEMessage message sent to the AMF.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-824" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T18:15:27Z" diff --git a/advisories/unreviewed/2024/11/GHSA-6cqf-gqr3-8cr4/GHSA-6cqf-gqr3-8cr4.json b/advisories/unreviewed/2024/11/GHSA-6cqf-gqr3-8cr4/GHSA-6cqf-gqr3-8cr4.json new file mode 100644 index 00000000000..c24d35992c6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6cqf-gqr3-8cr4/GHSA-6cqf-gqr3-8cr4.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cqf-gqr3-8cr4", + "modified": "2024-11-26T21:32:25Z", + "published": "2024-11-26T21:32:25Z", + "aliases": [ + "CVE-2024-50942" + ], + "details": "qiwen-file v1.4.0 was discovered to contain a SQL injection vulnerability via the component /mapper/NoticeMapper.xml.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50942" + }, + { + "type": "WEB", + "url": "https://gist.github.com/3xsh0re/4253401806bc35b2f95dcea12a4310fc" + }, + { + "type": "WEB", + "url": "https://www.qiwenshare.com" + }, + { + "type": "WEB", + "url": "http://qiwen-file.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8c3c-gvf8-p7v2/GHSA-8c3c-gvf8-p7v2.json b/advisories/unreviewed/2024/11/GHSA-8c3c-gvf8-p7v2/GHSA-8c3c-gvf8-p7v2.json index f2db57b8d6e..aeeace17a55 100644 --- a/advisories/unreviewed/2024/11/GHSA-8c3c-gvf8-p7v2/GHSA-8c3c-gvf8-p7v2.json +++ b/advisories/unreviewed/2024/11/GHSA-8c3c-gvf8-p7v2/GHSA-8c3c-gvf8-p7v2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8c3c-gvf8-p7v2", - "modified": "2024-11-26T18:38:52Z", + "modified": "2024-11-26T21:32:24Z", "published": "2024-11-26T18:38:52Z", "aliases": [ "CVE-2024-52337" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52337" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:10381" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:10384" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-52337" diff --git a/advisories/unreviewed/2024/11/GHSA-8cwc-g9gg-qp9w/GHSA-8cwc-g9gg-qp9w.json b/advisories/unreviewed/2024/11/GHSA-8cwc-g9gg-qp9w/GHSA-8cwc-g9gg-qp9w.json new file mode 100644 index 00000000000..3d99148ec28 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8cwc-g9gg-qp9w/GHSA-8cwc-g9gg-qp9w.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8cwc-g9gg-qp9w", + "modified": "2024-11-26T21:32:24Z", + "published": "2024-11-26T21:32:24Z", + "aliases": [ + "CVE-2024-11145" + ], + "details": "Valor Apps Easy Folder Listing Pro has a deserialization vulnerability that allows an unauthenticated, remote attacker to execute arbitrary code with the privileges of the Joomla! application. Fixed in versions 3.8 and 4.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11145" + }, + { + "type": "WEB", + "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/IT/white/2024/va-24-331-01.json" + }, + { + "type": "WEB", + "url": "https://www.valorapps.com/web-products/easy-folder-listing-pro.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T20:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-94xw-8rg2-4fmc/GHSA-94xw-8rg2-4fmc.json b/advisories/unreviewed/2024/11/GHSA-94xw-8rg2-4fmc/GHSA-94xw-8rg2-4fmc.json new file mode 100644 index 00000000000..f530cdbf8f9 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-94xw-8rg2-4fmc/GHSA-94xw-8rg2-4fmc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94xw-8rg2-4fmc", + "modified": "2024-11-26T21:32:24Z", + "published": "2024-11-26T21:32:24Z", + "aliases": [ + "CVE-2024-8177" + ], + "details": "An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.4.5, starting from 17.5 prior to 17.5.3, starting from 17.6 prior to 17.6.1 which could cause Denial of Service via integrating a malicious harbor registry.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8177" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2637996" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/480706" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-407" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T19:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9g7f-8r42-f32m/GHSA-9g7f-8r42-f32m.json b/advisories/unreviewed/2024/11/GHSA-9g7f-8r42-f32m/GHSA-9g7f-8r42-f32m.json index e466c4a04e1..8d0134075e8 100644 --- a/advisories/unreviewed/2024/11/GHSA-9g7f-8r42-f32m/GHSA-9g7f-8r42-f32m.json +++ b/advisories/unreviewed/2024/11/GHSA-9g7f-8r42-f32m/GHSA-9g7f-8r42-f32m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9g7f-8r42-f32m", - "modified": "2024-11-12T15:30:43Z", + "modified": "2024-11-26T21:32:22Z", "published": "2024-11-12T15:30:43Z", "aliases": [ "CVE-2024-51562" ], "details": "The NVMe driver function nvme_opc_get_log_page is vulnerable to a buffer over-read from a guest-controlled value.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-12T15:15:10Z" diff --git a/advisories/unreviewed/2024/11/GHSA-9qqr-v783-v57r/GHSA-9qqr-v783-v57r.json b/advisories/unreviewed/2024/11/GHSA-9qqr-v783-v57r/GHSA-9qqr-v783-v57r.json new file mode 100644 index 00000000000..34d020f11ef --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9qqr-v783-v57r/GHSA-9qqr-v783-v57r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qqr-v783-v57r", + "modified": "2024-11-26T21:32:24Z", + "published": "2024-11-26T21:32:24Z", + "aliases": [ + "CVE-2024-49038" + ], + "details": "Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation of privilege over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49038" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49038" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T20:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9vv4-rwwg-wc6h/GHSA-9vv4-rwwg-wc6h.json b/advisories/unreviewed/2024/11/GHSA-9vv4-rwwg-wc6h/GHSA-9vv4-rwwg-wc6h.json index 2c89a20e21b..ea4ced79a4e 100644 --- a/advisories/unreviewed/2024/11/GHSA-9vv4-rwwg-wc6h/GHSA-9vv4-rwwg-wc6h.json +++ b/advisories/unreviewed/2024/11/GHSA-9vv4-rwwg-wc6h/GHSA-9vv4-rwwg-wc6h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9vv4-rwwg-wc6h", - "modified": "2024-11-26T18:38:52Z", + "modified": "2024-11-26T21:32:24Z", "published": "2024-11-26T18:38:52Z", "aliases": [ "CVE-2024-53365" ], "details": "A stored cross-site scripting (XSS) vulnerability was identified in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/profile.php. This vulnerability allows authenticated users to inject malicious XSS scripts into the profile name field.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-26T17:15:26Z" diff --git a/advisories/unreviewed/2024/11/GHSA-cfjc-m7fv-63xj/GHSA-cfjc-m7fv-63xj.json b/advisories/unreviewed/2024/11/GHSA-cfjc-m7fv-63xj/GHSA-cfjc-m7fv-63xj.json index 5d571a0cc71..4cc6f7ae24c 100644 --- a/advisories/unreviewed/2024/11/GHSA-cfjc-m7fv-63xj/GHSA-cfjc-m7fv-63xj.json +++ b/advisories/unreviewed/2024/11/GHSA-cfjc-m7fv-63xj/GHSA-cfjc-m7fv-63xj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cfjc-m7fv-63xj", - "modified": "2024-11-26T18:38:52Z", + "modified": "2024-11-26T21:32:24Z", "published": "2024-11-26T18:38:52Z", "aliases": [ "CVE-2024-52336" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52336" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:10384" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-52336" diff --git a/advisories/unreviewed/2024/11/GHSA-cgcp-gvp8-4fpv/GHSA-cgcp-gvp8-4fpv.json b/advisories/unreviewed/2024/11/GHSA-cgcp-gvp8-4fpv/GHSA-cgcp-gvp8-4fpv.json new file mode 100644 index 00000000000..9f502826ca6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cgcp-gvp8-4fpv/GHSA-cgcp-gvp8-4fpv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cgcp-gvp8-4fpv", + "modified": "2024-11-26T21:32:23Z", + "published": "2024-11-26T21:32:23Z", + "aliases": [ + "CVE-2024-10898" + ], + "details": "The Contact Form 7 Email Add on plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9 via the cf7_email_add_on_add_admin_template() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php files can be uploaded and included.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10898" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/cf7-email-add-on/trunk/include/class-cf7-email.php#L110" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d82efaa3-ea61-476c-ad1a-60585450c63a?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-21T11:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cwgj-pq49-6x66/GHSA-cwgj-pq49-6x66.json b/advisories/unreviewed/2024/11/GHSA-cwgj-pq49-6x66/GHSA-cwgj-pq49-6x66.json index c77d2ed9904..2f7613aae21 100644 --- a/advisories/unreviewed/2024/11/GHSA-cwgj-pq49-6x66/GHSA-cwgj-pq49-6x66.json +++ b/advisories/unreviewed/2024/11/GHSA-cwgj-pq49-6x66/GHSA-cwgj-pq49-6x66.json @@ -40,7 +40,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-f5r5-77wf-xx6h/GHSA-f5r5-77wf-xx6h.json b/advisories/unreviewed/2024/11/GHSA-f5r5-77wf-xx6h/GHSA-f5r5-77wf-xx6h.json new file mode 100644 index 00000000000..9d6e40618d2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f5r5-77wf-xx6h/GHSA-f5r5-77wf-xx6h.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5r5-77wf-xx6h", + "modified": "2024-11-26T21:32:24Z", + "published": "2024-11-26T21:32:24Z", + "aliases": [ + "CVE-2024-8114" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. This issue allows an attacker with access to a victim's Personal Access Token (PAT) to escalate privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8114" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2649822" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/480494" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T19:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f82f-w24c-j3ww/GHSA-f82f-w24c-j3ww.json b/advisories/unreviewed/2024/11/GHSA-f82f-w24c-j3ww/GHSA-f82f-w24c-j3ww.json new file mode 100644 index 00000000000..26120c43e60 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f82f-w24c-j3ww/GHSA-f82f-w24c-j3ww.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f82f-w24c-j3ww", + "modified": "2024-11-26T21:32:24Z", + "published": "2024-11-26T21:32:24Z", + "aliases": [ + "CVE-2024-10240" + ], + "details": "An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting from 17.4 before 17.4.4, all versions starting from 17.5 before 17.5.2 in which an unauthenticated user may be able to read some information about an MR in a private project, under certain circumstances.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10240" + }, + { + "type": "WEB", + "url": "https://about.gitlab.com/releases/2024/11/13/patch-release-gitlab-17-5-2-released/#information-disclosure-through-an-api-endpoint" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/493188" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T20:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-g446-rqm3-4h89/GHSA-g446-rqm3-4h89.json b/advisories/unreviewed/2024/11/GHSA-g446-rqm3-4h89/GHSA-g446-rqm3-4h89.json index f23f8d0158e..292b4420357 100644 --- a/advisories/unreviewed/2024/11/GHSA-g446-rqm3-4h89/GHSA-g446-rqm3-4h89.json +++ b/advisories/unreviewed/2024/11/GHSA-g446-rqm3-4h89/GHSA-g446-rqm3-4h89.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g446-rqm3-4h89", - "modified": "2024-11-12T15:30:43Z", + "modified": "2024-11-26T21:32:22Z", "published": "2024-11-12T15:30:43Z", "aliases": [ "CVE-2024-39281" ], "details": "The command ctl_persistent_reserve_out allows the caller to specify an arbitrary size which will be passed to the kernel's memory allocator.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-20" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-12T15:15:09Z" diff --git a/advisories/unreviewed/2024/11/GHSA-g797-r4r7-wp94/GHSA-g797-r4r7-wp94.json b/advisories/unreviewed/2024/11/GHSA-g797-r4r7-wp94/GHSA-g797-r4r7-wp94.json new file mode 100644 index 00000000000..209d06a5b7d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g797-r4r7-wp94/GHSA-g797-r4r7-wp94.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g797-r4r7-wp94", + "modified": "2024-11-26T21:32:24Z", + "published": "2024-11-26T21:32:24Z", + "aliases": [ + "CVE-2024-11668" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Long-lived connections could potentially bypass authentication controls, allowing unauthorized access to streaming results.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11668" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/456922" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-613" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T19:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-g7hv-g729-xq68/GHSA-g7hv-g729-xq68.json b/advisories/unreviewed/2024/11/GHSA-g7hv-g729-xq68/GHSA-g7hv-g729-xq68.json index 9bc41d1f5f5..fc1d7d59bbb 100644 --- a/advisories/unreviewed/2024/11/GHSA-g7hv-g729-xq68/GHSA-g7hv-g729-xq68.json +++ b/advisories/unreviewed/2024/11/GHSA-g7hv-g729-xq68/GHSA-g7hv-g729-xq68.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-g863-pp98-8m8m/GHSA-g863-pp98-8m8m.json b/advisories/unreviewed/2024/11/GHSA-g863-pp98-8m8m/GHSA-g863-pp98-8m8m.json index 0f7e3814bda..1adb586b3ec 100644 --- a/advisories/unreviewed/2024/11/GHSA-g863-pp98-8m8m/GHSA-g863-pp98-8m8m.json +++ b/advisories/unreviewed/2024/11/GHSA-g863-pp98-8m8m/GHSA-g863-pp98-8m8m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g863-pp98-8m8m", - "modified": "2024-11-23T15:32:28Z", + "modified": "2024-11-26T21:32:24Z", "published": "2024-11-23T15:32:28Z", "aliases": [ "CVE-2024-35160" diff --git a/advisories/unreviewed/2024/11/GHSA-hx7r-qwxv-w9j9/GHSA-hx7r-qwxv-w9j9.json b/advisories/unreviewed/2024/11/GHSA-hx7r-qwxv-w9j9/GHSA-hx7r-qwxv-w9j9.json index 8c04c6a7c96..5558a90baaf 100644 --- a/advisories/unreviewed/2024/11/GHSA-hx7r-qwxv-w9j9/GHSA-hx7r-qwxv-w9j9.json +++ b/advisories/unreviewed/2024/11/GHSA-hx7r-qwxv-w9j9/GHSA-hx7r-qwxv-w9j9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hx7r-qwxv-w9j9", - "modified": "2024-11-12T15:30:44Z", + "modified": "2024-11-26T21:32:22Z", "published": "2024-11-12T15:30:44Z", "aliases": [ "CVE-2024-51565" ], "details": "The hda driver is vulnerable to a buffer over-read from a guest-controlled value.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-12T15:15:11Z" diff --git a/advisories/unreviewed/2024/11/GHSA-j27h-7c89-c3c6/GHSA-j27h-7c89-c3c6.json b/advisories/unreviewed/2024/11/GHSA-j27h-7c89-c3c6/GHSA-j27h-7c89-c3c6.json index 69db10106c3..0669b74a380 100644 --- a/advisories/unreviewed/2024/11/GHSA-j27h-7c89-c3c6/GHSA-j27h-7c89-c3c6.json +++ b/advisories/unreviewed/2024/11/GHSA-j27h-7c89-c3c6/GHSA-j27h-7c89-c3c6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j27h-7c89-c3c6", - "modified": "2024-11-22T21:32:13Z", + "modified": "2024-11-26T21:32:23Z", "published": "2024-11-20T21:30:50Z", "aliases": [ "CVE-2024-52677" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://github.com/J-0k3r/test/blob/main/upload.pdf" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/ghsa-j27h-7c89-c3c6" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/11/GHSA-m22p-g7xv-5j93/GHSA-m22p-g7xv-5j93.json b/advisories/unreviewed/2024/11/GHSA-m22p-g7xv-5j93/GHSA-m22p-g7xv-5j93.json new file mode 100644 index 00000000000..af2454dacc0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-m22p-g7xv-5j93/GHSA-m22p-g7xv-5j93.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m22p-g7xv-5j93", + "modified": "2024-11-26T21:32:25Z", + "published": "2024-11-26T21:32:25Z", + "aliases": [ + "CVE-2024-11744" + ], + "details": "A vulnerability has been found in 1000 Projects Portfolio Management System MCA 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /register.php. The manipulation of the argument name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11744" + }, + { + "type": "WEB", + "url": "https://github.com/zdwf-klm/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://1000projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.286141" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.286141" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.449734" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T21:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-p972-2fg6-pw4j/GHSA-p972-2fg6-pw4j.json b/advisories/unreviewed/2024/11/GHSA-p972-2fg6-pw4j/GHSA-p972-2fg6-pw4j.json index e089895dcc6..33c1b1f36ab 100644 --- a/advisories/unreviewed/2024/11/GHSA-p972-2fg6-pw4j/GHSA-p972-2fg6-pw4j.json +++ b/advisories/unreviewed/2024/11/GHSA-p972-2fg6-pw4j/GHSA-p972-2fg6-pw4j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p972-2fg6-pw4j", - "modified": "2024-11-13T21:30:38Z", + "modified": "2024-11-26T21:32:23Z", "published": "2024-11-13T21:30:38Z", "aliases": [ "CVE-2024-45877" ], "details": "baltic-it TOPqw Webportal v1.35.283.2 is vulnerable to Incorrect Access Control in the User Management function in /Apps/TOPqw/BenutzerManagement.aspx. This allows a low privileged user to access all modules in the web portal, view and manipulate information and permissions of other users, lock other user or unlock the own account, change the password of other users, create new users or delete existing users and view, manipulate and delete reference data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-13T21:15:28Z" diff --git a/advisories/unreviewed/2024/11/GHSA-pvxj-chgv-3rj7/GHSA-pvxj-chgv-3rj7.json b/advisories/unreviewed/2024/11/GHSA-pvxj-chgv-3rj7/GHSA-pvxj-chgv-3rj7.json new file mode 100644 index 00000000000..389eb621b3b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pvxj-chgv-3rj7/GHSA-pvxj-chgv-3rj7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pvxj-chgv-3rj7", + "modified": "2024-11-26T21:32:24Z", + "published": "2024-11-26T21:32:24Z", + "aliases": [ + "CVE-2024-53620" + ], + "details": "A cross-site scripting (XSS) vulnerability in the Article module of SPIP v4.3.3 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Title parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53620" + }, + { + "type": "WEB", + "url": "https://grimthereaperteam.medium.com/ec1e8714c02e" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T19:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qcjh-2fxc-73fr/GHSA-qcjh-2fxc-73fr.json b/advisories/unreviewed/2024/11/GHSA-qcjh-2fxc-73fr/GHSA-qcjh-2fxc-73fr.json new file mode 100644 index 00000000000..fc9e94a46c8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qcjh-2fxc-73fr/GHSA-qcjh-2fxc-73fr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcjh-2fxc-73fr", + "modified": "2024-11-26T21:32:23Z", + "published": "2024-11-26T21:32:23Z", + "aliases": [ + "CVE-2024-48747" + ], + "details": "An issue in alist-tvbox v1.7.1 allows a remote attacker to execute arbitrary code via the /atv-cli file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48747" + }, + { + "type": "WEB", + "url": "https://github.com/6pc1/BugHub/blob/main/alist-tvbox%20command%20execution%20vulnerability.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-21T15:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-r3mm-qxv5-x23h/GHSA-r3mm-qxv5-x23h.json b/advisories/unreviewed/2024/11/GHSA-r3mm-qxv5-x23h/GHSA-r3mm-qxv5-x23h.json new file mode 100644 index 00000000000..c93073279eb --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-r3mm-qxv5-x23h/GHSA-r3mm-qxv5-x23h.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3mm-qxv5-x23h", + "modified": "2024-11-26T21:32:24Z", + "published": "2024-11-26T21:32:24Z", + "aliases": [ + "CVE-2024-8237" + ], + "details": "A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 12.6 prior to 17.4.5, 17.5 prior to 17.5.3, and 17.6 prior to 17.6.1. An attacker could cause a denial of service with a crafted cargo.toml file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8237" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2648665" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/480900" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-407" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T19:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-r642-x62f-jqhp/GHSA-r642-x62f-jqhp.json b/advisories/unreviewed/2024/11/GHSA-r642-x62f-jqhp/GHSA-r642-x62f-jqhp.json index 8c5ecd1ca9f..ed64757a1ab 100644 --- a/advisories/unreviewed/2024/11/GHSA-r642-x62f-jqhp/GHSA-r642-x62f-jqhp.json +++ b/advisories/unreviewed/2024/11/GHSA-r642-x62f-jqhp/GHSA-r642-x62f-jqhp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r642-x62f-jqhp", - "modified": "2024-11-12T15:30:44Z", + "modified": "2024-11-26T21:32:23Z", "published": "2024-11-12T15:30:44Z", "aliases": [ "CVE-2024-51566" ], "details": "The NVMe driver queue processing is vulernable to guest-induced infinite loops.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-1285" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-12T15:15:11Z" diff --git a/advisories/unreviewed/2024/11/GHSA-rfmc-j4j9-f2cc/GHSA-rfmc-j4j9-f2cc.json b/advisories/unreviewed/2024/11/GHSA-rfmc-j4j9-f2cc/GHSA-rfmc-j4j9-f2cc.json new file mode 100644 index 00000000000..46911adb0a9 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rfmc-j4j9-f2cc/GHSA-rfmc-j4j9-f2cc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfmc-j4j9-f2cc", + "modified": "2024-11-26T21:32:25Z", + "published": "2024-11-26T21:32:25Z", + "aliases": [ + "CVE-2024-49053" + ], + "details": "Microsoft Dynamics 365 Sales Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49053" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49053" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T20:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rmhm-cwgp-268p/GHSA-rmhm-cwgp-268p.json b/advisories/unreviewed/2024/11/GHSA-rmhm-cwgp-268p/GHSA-rmhm-cwgp-268p.json new file mode 100644 index 00000000000..e8977a96370 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rmhm-cwgp-268p/GHSA-rmhm-cwgp-268p.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmhm-cwgp-268p", + "modified": "2024-11-26T21:32:24Z", + "published": "2024-11-26T21:32:24Z", + "aliases": [ + "CVE-2024-11828" + ], + "details": "A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. By leveraging this vulnerability an attacker could create a DoS condition by sending crafted API calls. This was a regression of an earlier patch.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11828" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2380264" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/443559" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-407" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T19:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rmv2-8jjc-23xw/GHSA-rmv2-8jjc-23xw.json b/advisories/unreviewed/2024/11/GHSA-rmv2-8jjc-23xw/GHSA-rmv2-8jjc-23xw.json index 983aa2fa6ff..722b9e0b5c0 100644 --- a/advisories/unreviewed/2024/11/GHSA-rmv2-8jjc-23xw/GHSA-rmv2-8jjc-23xw.json +++ b/advisories/unreviewed/2024/11/GHSA-rmv2-8jjc-23xw/GHSA-rmv2-8jjc-23xw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rmv2-8jjc-23xw", - "modified": "2024-11-26T18:38:52Z", + "modified": "2024-11-26T21:32:24Z", "published": "2024-11-26T18:38:52Z", "aliases": [ "CVE-2024-51058" ], "details": "Local File Inclusion (LFI) vulnerability has been discovered in TCPDF 6.7.5. This vulnerability enables a user to read arbitrary files from the server's file system through src tag, potentially exposing sensitive information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-552" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-26T18:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-v84c-53c6-xmmp/GHSA-v84c-53c6-xmmp.json b/advisories/unreviewed/2024/11/GHSA-v84c-53c6-xmmp/GHSA-v84c-53c6-xmmp.json new file mode 100644 index 00000000000..6bcfdf78018 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-v84c-53c6-xmmp/GHSA-v84c-53c6-xmmp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v84c-53c6-xmmp", + "modified": "2024-11-26T21:32:24Z", + "published": "2024-11-26T21:32:24Z", + "aliases": [ + "CVE-2024-11669" + ], + "details": "An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Certain API endpoints could potentially allow unauthorized access to sensitive data due to overly broad application of token scopes.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11669" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/501528" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T19:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vhvx-3f4j-g64m/GHSA-vhvx-3f4j-g64m.json b/advisories/unreviewed/2024/11/GHSA-vhvx-3f4j-g64m/GHSA-vhvx-3f4j-g64m.json new file mode 100644 index 00000000000..15de92f4f6f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vhvx-3f4j-g64m/GHSA-vhvx-3f4j-g64m.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhvx-3f4j-g64m", + "modified": "2024-11-26T21:32:24Z", + "published": "2024-11-26T21:32:24Z", + "aliases": [ + "CVE-2024-11743" + ], + "details": "A vulnerability, which was classified as problematic, was found in SourceCodester Best House Rental Management System 1.0. Affected is an unknown function of the file /rental/ajax.php?action=delete_user of the component POST Request Handler. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11743" + }, + { + "type": "WEB", + "url": "https://github.com/YasserREED/YasserREED-CVEs/blob/main/Best%20house%20rental%20management%20system%20project%20in%20php/Cross-Site%20Request%20Forgery%20(CSRF).md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.286140" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.286140" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.449697" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T20:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w69p-wm6c-5486/GHSA-w69p-wm6c-5486.json b/advisories/unreviewed/2024/11/GHSA-w69p-wm6c-5486/GHSA-w69p-wm6c-5486.json new file mode 100644 index 00000000000..ce38fb7479b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-w69p-wm6c-5486/GHSA-w69p-wm6c-5486.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w69p-wm6c-5486", + "modified": "2024-11-26T21:32:24Z", + "published": "2024-11-26T21:32:24Z", + "aliases": [ + "CVE-2024-49035" + ], + "details": "An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49035" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49035" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T20:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wh54-vv47-2265/GHSA-wh54-vv47-2265.json b/advisories/unreviewed/2024/11/GHSA-wh54-vv47-2265/GHSA-wh54-vv47-2265.json index f1dc529fb67..5e980d634ff 100644 --- a/advisories/unreviewed/2024/11/GHSA-wh54-vv47-2265/GHSA-wh54-vv47-2265.json +++ b/advisories/unreviewed/2024/11/GHSA-wh54-vv47-2265/GHSA-wh54-vv47-2265.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-xxc6-q6r3-h584/GHSA-xxc6-q6r3-h584.json b/advisories/unreviewed/2024/11/GHSA-xxc6-q6r3-h584/GHSA-xxc6-q6r3-h584.json index 65f84e84fec..732b07b39b2 100644 --- a/advisories/unreviewed/2024/11/GHSA-xxc6-q6r3-h584/GHSA-xxc6-q6r3-h584.json +++ b/advisories/unreviewed/2024/11/GHSA-xxc6-q6r3-h584/GHSA-xxc6-q6r3-h584.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xxc6-q6r3-h584", - "modified": "2024-11-12T15:30:44Z", + "modified": "2024-11-26T21:32:22Z", "published": "2024-11-12T15:30:43Z", "aliases": [ "CVE-2024-51563" ], "details": "The virtio_vq_recordon function is subject to a time-of-check to time-of-use (TOCTOU) race condition.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-367" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-12T15:15:10Z"