From 88893362d003c64c6e03950dd3f35709d8a42bfe Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 26 Jul 2024 15:33:27 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-4mm4-33wm-56jr.json | 6 ++- .../GHSA-vhhq-fxg5-hvp8.json | 6 ++- .../GHSA-7c32-qxxc-879m.json | 11 +++-- .../GHSA-9cv8-f6m9-rm59.json | 2 +- .../GHSA-9wh8-7hw4-wc5g.json | 11 +++-- .../GHSA-h362-fq3p-pqgm.json | 11 +++-- .../GHSA-wc5f-w959-5pxw.json | 2 +- .../GHSA-xhhx-8x4v-2374.json | 2 +- .../GHSA-34x5-w6rv-c97v.json | 11 +++-- .../GHSA-4298-7v99-63c5.json | 2 +- .../GHSA-47mr-2899-hh6f.json | 2 +- .../GHSA-4r38-rqh5-3fvr.json | 11 +++-- .../GHSA-6572-8r92-7fjf.json | 38 +++++++++++++++++ .../GHSA-8wc4-v9cf-9rcc.json | 11 +++-- .../GHSA-9354-p3xr-gqw5.json | 2 +- .../GHSA-cc7x-v8jj-qg95.json | 11 +++-- .../GHSA-g2m5-6x74-9mv6.json | 2 +- .../GHSA-ggqv-qggh-5p8q.json | 42 +++++++++++++++++++ .../GHSA-gwr6-5fvh-8v7r.json | 42 +++++++++++++++++++ .../GHSA-hww2-2qgh-frpq.json | 11 +++-- .../GHSA-j9jr-cfvj-wm74.json | 11 +++-- .../GHSA-jm9w-pgx2-583g.json | 11 +++-- .../GHSA-jq7x-5g7j-c2g9.json | 2 +- .../GHSA-jr7f-r978-2hmw.json | 11 +++-- .../GHSA-pvrp-53vr-r883.json | 11 +++-- .../GHSA-rjfq-p48j-h96h.json | 3 +- .../GHSA-rqq7-hjc5-3h3v.json | 1 + .../GHSA-whhx-238v-wr87.json | 6 ++- .../GHSA-whww-hhj9-9f35.json | 6 ++- .../GHSA-wj8j-4972-pm4v.json | 11 +++-- .../GHSA-wwxv-fvxx-vp4c.json | 38 +++++++++++++++++ .../GHSA-xf72-gh36-pgmj.json | 11 +++-- .../GHSA-xqhh-5j5h-pqfc.json | 2 +- 33 files changed, 290 insertions(+), 70 deletions(-) create mode 100644 advisories/unreviewed/2024/07/GHSA-6572-8r92-7fjf/GHSA-6572-8r92-7fjf.json create mode 100644 advisories/unreviewed/2024/07/GHSA-ggqv-qggh-5p8q/GHSA-ggqv-qggh-5p8q.json create mode 100644 advisories/unreviewed/2024/07/GHSA-gwr6-5fvh-8v7r/GHSA-gwr6-5fvh-8v7r.json create mode 100644 advisories/unreviewed/2024/07/GHSA-wwxv-fvxx-vp4c/GHSA-wwxv-fvxx-vp4c.json diff --git a/advisories/unreviewed/2024/04/GHSA-4mm4-33wm-56jr/GHSA-4mm4-33wm-56jr.json b/advisories/unreviewed/2024/04/GHSA-4mm4-33wm-56jr/GHSA-4mm4-33wm-56jr.json index 6908409bfd9..63c2075b9c5 100644 --- a/advisories/unreviewed/2024/04/GHSA-4mm4-33wm-56jr/GHSA-4mm4-33wm-56jr.json +++ b/advisories/unreviewed/2024/04/GHSA-4mm4-33wm-56jr/GHSA-4mm4-33wm-56jr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4mm4-33wm-56jr", - "modified": "2024-07-25T21:31:19Z", + "modified": "2024-07-26T15:31:48Z", "published": "2024-04-02T00:30:47Z", "aliases": [ "CVE-2024-3165" @@ -36,6 +36,10 @@ { "type": "WEB", "url": "https://auth.dotcms.com/security/SI-70?token=563ec927-3190-4478-bd77-0d6f8c6fc676" + }, + { + "type": "WEB", + "url": "https://www.dotcms.com/security/SI-70" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/04/GHSA-vhhq-fxg5-hvp8/GHSA-vhhq-fxg5-hvp8.json b/advisories/unreviewed/2024/04/GHSA-vhhq-fxg5-hvp8/GHSA-vhhq-fxg5-hvp8.json index 30528c22ca4..dc44e2cac09 100644 --- a/advisories/unreviewed/2024/04/GHSA-vhhq-fxg5-hvp8/GHSA-vhhq-fxg5-hvp8.json +++ b/advisories/unreviewed/2024/04/GHSA-vhhq-fxg5-hvp8/GHSA-vhhq-fxg5-hvp8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vhhq-fxg5-hvp8", - "modified": "2024-07-25T21:31:19Z", + "modified": "2024-07-26T15:31:48Z", "published": "2024-04-02T00:30:46Z", "aliases": [ "CVE-2024-3164" @@ -36,6 +36,10 @@ { "type": "WEB", "url": "https://auth.dotcms.com/security/SI-69?token=dc1f0241-b697-41dd-8140-154658e90c54" + }, + { + "type": "WEB", + "url": "https://www.dotcms.com/security/SI-69" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-7c32-qxxc-879m/GHSA-7c32-qxxc-879m.json b/advisories/unreviewed/2024/06/GHSA-7c32-qxxc-879m/GHSA-7c32-qxxc-879m.json index 4514caa287d..4589ce2e027 100644 --- a/advisories/unreviewed/2024/06/GHSA-7c32-qxxc-879m/GHSA-7c32-qxxc-879m.json +++ b/advisories/unreviewed/2024/06/GHSA-7c32-qxxc-879m/GHSA-7c32-qxxc-879m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7c32-qxxc-879m", - "modified": "2024-07-16T21:30:49Z", + "modified": "2024-07-26T15:31:49Z", "published": "2024-06-16T15:30:44Z", "aliases": [ "CVE-2024-38458" ], "details": "Xenforo before 2.2.16 allows code injection.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-16T15:15:51Z" diff --git a/advisories/unreviewed/2024/06/GHSA-9cv8-f6m9-rm59/GHSA-9cv8-f6m9-rm59.json b/advisories/unreviewed/2024/06/GHSA-9cv8-f6m9-rm59/GHSA-9cv8-f6m9-rm59.json index e2d83f9d986..ea9289c918c 100644 --- a/advisories/unreviewed/2024/06/GHSA-9cv8-f6m9-rm59/GHSA-9cv8-f6m9-rm59.json +++ b/advisories/unreviewed/2024/06/GHSA-9cv8-f6m9-rm59/GHSA-9cv8-f6m9-rm59.json @@ -48,7 +48,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-9wh8-7hw4-wc5g/GHSA-9wh8-7hw4-wc5g.json b/advisories/unreviewed/2024/06/GHSA-9wh8-7hw4-wc5g/GHSA-9wh8-7hw4-wc5g.json index 7f92eec6a35..52a7a6408a4 100644 --- a/advisories/unreviewed/2024/06/GHSA-9wh8-7hw4-wc5g/GHSA-9wh8-7hw4-wc5g.json +++ b/advisories/unreviewed/2024/06/GHSA-9wh8-7hw4-wc5g/GHSA-9wh8-7hw4-wc5g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9wh8-7hw4-wc5g", - "modified": "2024-06-16T15:30:44Z", + "modified": "2024-07-26T15:31:49Z", "published": "2024-06-16T15:30:44Z", "aliases": [ "CVE-2024-38454" ], "details": "ExpressionEngine before 7.4.11 allows XSS.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-16T15:15:51Z" diff --git a/advisories/unreviewed/2024/06/GHSA-h362-fq3p-pqgm/GHSA-h362-fq3p-pqgm.json b/advisories/unreviewed/2024/06/GHSA-h362-fq3p-pqgm/GHSA-h362-fq3p-pqgm.json index 64a740032cf..bad3d4a39c3 100644 --- a/advisories/unreviewed/2024/06/GHSA-h362-fq3p-pqgm/GHSA-h362-fq3p-pqgm.json +++ b/advisories/unreviewed/2024/06/GHSA-h362-fq3p-pqgm/GHSA-h362-fq3p-pqgm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h362-fq3p-pqgm", - "modified": "2024-07-16T21:30:49Z", + "modified": "2024-07-26T15:31:49Z", "published": "2024-06-16T15:30:44Z", "aliases": [ "CVE-2024-38457" ], "details": "Xenforo before 2.2.16 allows CSRF.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-16T15:15:51Z" diff --git a/advisories/unreviewed/2024/06/GHSA-wc5f-w959-5pxw/GHSA-wc5f-w959-5pxw.json b/advisories/unreviewed/2024/06/GHSA-wc5f-w959-5pxw/GHSA-wc5f-w959-5pxw.json index 7feaea717f8..e7b599bb8ea 100644 --- a/advisories/unreviewed/2024/06/GHSA-wc5f-w959-5pxw/GHSA-wc5f-w959-5pxw.json +++ b/advisories/unreviewed/2024/06/GHSA-wc5f-w959-5pxw/GHSA-wc5f-w959-5pxw.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-xhhx-8x4v-2374/GHSA-xhhx-8x4v-2374.json b/advisories/unreviewed/2024/06/GHSA-xhhx-8x4v-2374/GHSA-xhhx-8x4v-2374.json index 1a598c887dc..49785e88b9e 100644 --- a/advisories/unreviewed/2024/06/GHSA-xhhx-8x4v-2374/GHSA-xhhx-8x4v-2374.json +++ b/advisories/unreviewed/2024/06/GHSA-xhhx-8x4v-2374/GHSA-xhhx-8x4v-2374.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-34x5-w6rv-c97v/GHSA-34x5-w6rv-c97v.json b/advisories/unreviewed/2024/07/GHSA-34x5-w6rv-c97v/GHSA-34x5-w6rv-c97v.json index 0d21b61392f..2771577e2c2 100644 --- a/advisories/unreviewed/2024/07/GHSA-34x5-w6rv-c97v/GHSA-34x5-w6rv-c97v.json +++ b/advisories/unreviewed/2024/07/GHSA-34x5-w6rv-c97v/GHSA-34x5-w6rv-c97v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-34x5-w6rv-c97v", - "modified": "2024-07-24T21:31:31Z", + "modified": "2024-07-26T15:31:50Z", "published": "2024-07-24T21:31:31Z", "aliases": [ "CVE-2024-41551" ], "details": "CampCodes Supplier Management System v1.0 is vulnerable to SQL injection via Supply_Management_System/admin/view_order_items.php?id= .", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-24T20:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-4298-7v99-63c5/GHSA-4298-7v99-63c5.json b/advisories/unreviewed/2024/07/GHSA-4298-7v99-63c5/GHSA-4298-7v99-63c5.json index 2e49331ca58..b962d2e46d5 100644 --- a/advisories/unreviewed/2024/07/GHSA-4298-7v99-63c5/GHSA-4298-7v99-63c5.json +++ b/advisories/unreviewed/2024/07/GHSA-4298-7v99-63c5/GHSA-4298-7v99-63c5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4298-7v99-63c5", - "modified": "2024-07-22T12:30:35Z", + "modified": "2024-07-26T15:31:50Z", "published": "2024-07-22T12:30:35Z", "aliases": [ "CVE-2024-33933" diff --git a/advisories/unreviewed/2024/07/GHSA-47mr-2899-hh6f/GHSA-47mr-2899-hh6f.json b/advisories/unreviewed/2024/07/GHSA-47mr-2899-hh6f/GHSA-47mr-2899-hh6f.json index a6a8c011594..5d9c481ea1c 100644 --- a/advisories/unreviewed/2024/07/GHSA-47mr-2899-hh6f/GHSA-47mr-2899-hh6f.json +++ b/advisories/unreviewed/2024/07/GHSA-47mr-2899-hh6f/GHSA-47mr-2899-hh6f.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-4r38-rqh5-3fvr/GHSA-4r38-rqh5-3fvr.json b/advisories/unreviewed/2024/07/GHSA-4r38-rqh5-3fvr/GHSA-4r38-rqh5-3fvr.json index 3211da2ca9e..eb665db0a4c 100644 --- a/advisories/unreviewed/2024/07/GHSA-4r38-rqh5-3fvr/GHSA-4r38-rqh5-3fvr.json +++ b/advisories/unreviewed/2024/07/GHSA-4r38-rqh5-3fvr/GHSA-4r38-rqh5-3fvr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4r38-rqh5-3fvr", - "modified": "2024-07-24T15:31:28Z", + "modified": "2024-07-26T15:31:50Z", "published": "2024-07-24T15:31:28Z", "aliases": [ "CVE-2024-31977" ], "details": "Adtran 834-5 11.1.0.101-202106231430, and fixed as of SmartOS Version 12.5.5.1, devices allow OS Command Injection via shell metacharacters to the Ping or Traceroute utility.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-24T15:15:11Z" diff --git a/advisories/unreviewed/2024/07/GHSA-6572-8r92-7fjf/GHSA-6572-8r92-7fjf.json b/advisories/unreviewed/2024/07/GHSA-6572-8r92-7fjf/GHSA-6572-8r92-7fjf.json new file mode 100644 index 00000000000..b5581cfad49 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-6572-8r92-7fjf/GHSA-6572-8r92-7fjf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6572-8r92-7fjf", + "modified": "2024-07-26T15:31:51Z", + "published": "2024-07-26T15:31:51Z", + "aliases": [ + "CVE-2024-41692" + ], + "details": "This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to presence of root terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by accessing the root shell on the vulnerable system.\n\nSuccessful exploitation of this vulnerability could allow the attacker to execute arbitrary commands with root privileges on the targeted system.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41692" + }, + { + "type": "WEB", + "url": "https://cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1191" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-26T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-8wc4-v9cf-9rcc/GHSA-8wc4-v9cf-9rcc.json b/advisories/unreviewed/2024/07/GHSA-8wc4-v9cf-9rcc/GHSA-8wc4-v9cf-9rcc.json index e3626078f14..0a23ac0900a 100644 --- a/advisories/unreviewed/2024/07/GHSA-8wc4-v9cf-9rcc/GHSA-8wc4-v9cf-9rcc.json +++ b/advisories/unreviewed/2024/07/GHSA-8wc4-v9cf-9rcc/GHSA-8wc4-v9cf-9rcc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8wc4-v9cf-9rcc", - "modified": "2024-07-24T21:31:31Z", + "modified": "2024-07-26T15:31:50Z", "published": "2024-07-24T21:31:31Z", "aliases": [ "CVE-2024-41460" ], "details": "Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter at ip/goform/RouteStatic.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-24T21:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-9354-p3xr-gqw5/GHSA-9354-p3xr-gqw5.json b/advisories/unreviewed/2024/07/GHSA-9354-p3xr-gqw5/GHSA-9354-p3xr-gqw5.json index 053748cb245..ea3ae993210 100644 --- a/advisories/unreviewed/2024/07/GHSA-9354-p3xr-gqw5/GHSA-9354-p3xr-gqw5.json +++ b/advisories/unreviewed/2024/07/GHSA-9354-p3xr-gqw5/GHSA-9354-p3xr-gqw5.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1321" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-cc7x-v8jj-qg95/GHSA-cc7x-v8jj-qg95.json b/advisories/unreviewed/2024/07/GHSA-cc7x-v8jj-qg95/GHSA-cc7x-v8jj-qg95.json index 9320f2cc2c4..d60431ce921 100644 --- a/advisories/unreviewed/2024/07/GHSA-cc7x-v8jj-qg95/GHSA-cc7x-v8jj-qg95.json +++ b/advisories/unreviewed/2024/07/GHSA-cc7x-v8jj-qg95/GHSA-cc7x-v8jj-qg95.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cc7x-v8jj-qg95", - "modified": "2024-07-24T21:31:31Z", + "modified": "2024-07-26T15:31:50Z", "published": "2024-07-24T21:31:31Z", "aliases": [ "CVE-2024-41462" ], "details": "Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/DhcpListClient.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-24T21:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-g2m5-6x74-9mv6/GHSA-g2m5-6x74-9mv6.json b/advisories/unreviewed/2024/07/GHSA-g2m5-6x74-9mv6/GHSA-g2m5-6x74-9mv6.json index 49d80912c64..a343e2c1f6f 100644 --- a/advisories/unreviewed/2024/07/GHSA-g2m5-6x74-9mv6/GHSA-g2m5-6x74-9mv6.json +++ b/advisories/unreviewed/2024/07/GHSA-g2m5-6x74-9mv6/GHSA-g2m5-6x74-9mv6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g2m5-6x74-9mv6", - "modified": "2024-07-24T15:31:27Z", + "modified": "2024-07-26T15:31:50Z", "published": "2024-07-24T15:31:27Z", "aliases": [ "CVE-2024-6096" diff --git a/advisories/unreviewed/2024/07/GHSA-ggqv-qggh-5p8q/GHSA-ggqv-qggh-5p8q.json b/advisories/unreviewed/2024/07/GHSA-ggqv-qggh-5p8q/GHSA-ggqv-qggh-5p8q.json new file mode 100644 index 00000000000..f26e6ffd850 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-ggqv-qggh-5p8q/GHSA-ggqv-qggh-5p8q.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggqv-qggh-5p8q", + "modified": "2024-07-26T15:31:51Z", + "published": "2024-07-26T15:31:51Z", + "aliases": [ + "CVE-2024-40689" + ], + "details": "IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. IBM X-Force ID: 297719.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40689" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/297719" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7160579" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-26T14:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-gwr6-5fvh-8v7r/GHSA-gwr6-5fvh-8v7r.json b/advisories/unreviewed/2024/07/GHSA-gwr6-5fvh-8v7r/GHSA-gwr6-5fvh-8v7r.json new file mode 100644 index 00000000000..e7ae324670e --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-gwr6-5fvh-8v7r/GHSA-gwr6-5fvh-8v7r.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwr6-5fvh-8v7r", + "modified": "2024-07-26T15:31:51Z", + "published": "2024-07-26T15:31:51Z", + "aliases": [ + "CVE-2024-7128" + ], + "details": "A flaw was found in the Openshift console. Several endpoints in the application use the authHandler() and authHandlerWithUser() middleware functions. When the default authentication provider (\"openShiftAuth\") is set, these functions do not perform any authentication checks, relying instead on the targeted service to handle authentication and authorization. This issue leads to various degrees of data exposure due to a lack of proper credential verification.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7128" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-7128" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2300037" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-26T14:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-hww2-2qgh-frpq/GHSA-hww2-2qgh-frpq.json b/advisories/unreviewed/2024/07/GHSA-hww2-2qgh-frpq/GHSA-hww2-2qgh-frpq.json index fe1aff67b5b..6ea9a09917a 100644 --- a/advisories/unreviewed/2024/07/GHSA-hww2-2qgh-frpq/GHSA-hww2-2qgh-frpq.json +++ b/advisories/unreviewed/2024/07/GHSA-hww2-2qgh-frpq/GHSA-hww2-2qgh-frpq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hww2-2qgh-frpq", - "modified": "2024-07-24T21:31:31Z", + "modified": "2024-07-26T15:31:50Z", "published": "2024-07-24T21:31:31Z", "aliases": [ "CVE-2024-41463" ], "details": "Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter at ip/goform/addressNat.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-24T21:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-j9jr-cfvj-wm74/GHSA-j9jr-cfvj-wm74.json b/advisories/unreviewed/2024/07/GHSA-j9jr-cfvj-wm74/GHSA-j9jr-cfvj-wm74.json index c4b3e6ecdcc..219ef74474e 100644 --- a/advisories/unreviewed/2024/07/GHSA-j9jr-cfvj-wm74/GHSA-j9jr-cfvj-wm74.json +++ b/advisories/unreviewed/2024/07/GHSA-j9jr-cfvj-wm74/GHSA-j9jr-cfvj-wm74.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j9jr-cfvj-wm74", - "modified": "2024-07-24T21:31:31Z", + "modified": "2024-07-26T15:31:51Z", "published": "2024-07-24T21:31:31Z", "aliases": [ "CVE-2024-41466" ], "details": "Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/NatStaticSetting.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-24T21:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-jm9w-pgx2-583g/GHSA-jm9w-pgx2-583g.json b/advisories/unreviewed/2024/07/GHSA-jm9w-pgx2-583g/GHSA-jm9w-pgx2-583g.json index 1a7a4521d10..4699098b7cb 100644 --- a/advisories/unreviewed/2024/07/GHSA-jm9w-pgx2-583g/GHSA-jm9w-pgx2-583g.json +++ b/advisories/unreviewed/2024/07/GHSA-jm9w-pgx2-583g/GHSA-jm9w-pgx2-583g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jm9w-pgx2-583g", - "modified": "2024-07-24T15:31:28Z", + "modified": "2024-07-26T15:31:50Z", "published": "2024-07-24T15:31:28Z", "aliases": [ "CVE-2024-31971" ], "details": "Multiple stored cross-site scripting (XSS) vulnerabilities on AdTran NetVanta 3120 18.01.01.00.E devices allow remote attackers to inject arbitrary JavaScript, as demonstrated by /mainPassword.html, /processIdentity.html, /public.html, /dhcp.html, /private.html, /hostname.html, /connectivity.html, /NetworkMonitor.html, /trafficMonitoringConfig.html, and /wizardMain.html.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-24T15:15:11Z" diff --git a/advisories/unreviewed/2024/07/GHSA-jq7x-5g7j-c2g9/GHSA-jq7x-5g7j-c2g9.json b/advisories/unreviewed/2024/07/GHSA-jq7x-5g7j-c2g9/GHSA-jq7x-5g7j-c2g9.json index c17e0ecaf39..dc892bcff15 100644 --- a/advisories/unreviewed/2024/07/GHSA-jq7x-5g7j-c2g9/GHSA-jq7x-5g7j-c2g9.json +++ b/advisories/unreviewed/2024/07/GHSA-jq7x-5g7j-c2g9/GHSA-jq7x-5g7j-c2g9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jq7x-5g7j-c2g9", - "modified": "2024-07-22T09:31:56Z", + "modified": "2024-07-26T15:31:49Z", "published": "2024-07-22T09:31:56Z", "aliases": [ "CVE-2024-37429" diff --git a/advisories/unreviewed/2024/07/GHSA-jr7f-r978-2hmw/GHSA-jr7f-r978-2hmw.json b/advisories/unreviewed/2024/07/GHSA-jr7f-r978-2hmw/GHSA-jr7f-r978-2hmw.json index 3278408fa57..0651b98c6c7 100644 --- a/advisories/unreviewed/2024/07/GHSA-jr7f-r978-2hmw/GHSA-jr7f-r978-2hmw.json +++ b/advisories/unreviewed/2024/07/GHSA-jr7f-r978-2hmw/GHSA-jr7f-r978-2hmw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jr7f-r978-2hmw", - "modified": "2024-07-24T21:31:31Z", + "modified": "2024-07-26T15:31:51Z", "published": "2024-07-24T21:31:31Z", "aliases": [ "CVE-2024-41465" ], "details": "Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 parameter at ip/goform/setcfm.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-24T21:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-pvrp-53vr-r883/GHSA-pvrp-53vr-r883.json b/advisories/unreviewed/2024/07/GHSA-pvrp-53vr-r883/GHSA-pvrp-53vr-r883.json index dc51784feff..c1d8ca204f4 100644 --- a/advisories/unreviewed/2024/07/GHSA-pvrp-53vr-r883/GHSA-pvrp-53vr-r883.json +++ b/advisories/unreviewed/2024/07/GHSA-pvrp-53vr-r883/GHSA-pvrp-53vr-r883.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pvrp-53vr-r883", - "modified": "2024-07-24T21:31:31Z", + "modified": "2024-07-26T15:31:50Z", "published": "2024-07-24T21:31:31Z", "aliases": [ "CVE-2024-41461" ], "details": "Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the list1 parameter at ip/goform/DhcpListClient.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-24T21:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-rjfq-p48j-h96h/GHSA-rjfq-p48j-h96h.json b/advisories/unreviewed/2024/07/GHSA-rjfq-p48j-h96h/GHSA-rjfq-p48j-h96h.json index d87919b768e..0053dc54e3e 100644 --- a/advisories/unreviewed/2024/07/GHSA-rjfq-p48j-h96h/GHSA-rjfq-p48j-h96h.json +++ b/advisories/unreviewed/2024/07/GHSA-rjfq-p48j-h96h/GHSA-rjfq-p48j-h96h.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1393" + "CWE-1393", + "CWE-287" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-rqq7-hjc5-3h3v/GHSA-rqq7-hjc5-3h3v.json b/advisories/unreviewed/2024/07/GHSA-rqq7-hjc5-3h3v/GHSA-rqq7-hjc5-3h3v.json index 6756a775944..c5a02ac33f0 100644 --- a/advisories/unreviewed/2024/07/GHSA-rqq7-hjc5-3h3v/GHSA-rqq7-hjc5-3h3v.json +++ b/advisories/unreviewed/2024/07/GHSA-rqq7-hjc5-3h3v/GHSA-rqq7-hjc5-3h3v.json @@ -44,6 +44,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-425" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/07/GHSA-whhx-238v-wr87/GHSA-whhx-238v-wr87.json b/advisories/unreviewed/2024/07/GHSA-whhx-238v-wr87/GHSA-whhx-238v-wr87.json index 6740ee0e661..992c7275863 100644 --- a/advisories/unreviewed/2024/07/GHSA-whhx-238v-wr87/GHSA-whhx-238v-wr87.json +++ b/advisories/unreviewed/2024/07/GHSA-whhx-238v-wr87/GHSA-whhx-238v-wr87.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-whhx-238v-wr87", - "modified": "2024-07-26T03:30:46Z", + "modified": "2024-07-26T15:31:51Z", "published": "2024-07-26T03:30:46Z", "aliases": [ "CVE-2024-4447" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://auth.dotcms.com/security/SI-72" + }, + { + "type": "WEB", + "url": "https://www.dotcms.com/security/SI-72" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-whww-hhj9-9f35/GHSA-whww-hhj9-9f35.json b/advisories/unreviewed/2024/07/GHSA-whww-hhj9-9f35/GHSA-whww-hhj9-9f35.json index cd3a9dd7a59..6facc787147 100644 --- a/advisories/unreviewed/2024/07/GHSA-whww-hhj9-9f35/GHSA-whww-hhj9-9f35.json +++ b/advisories/unreviewed/2024/07/GHSA-whww-hhj9-9f35/GHSA-whww-hhj9-9f35.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-whww-hhj9-9f35", - "modified": "2024-07-26T00:32:10Z", + "modified": "2024-07-26T15:31:51Z", "published": "2024-07-26T00:32:10Z", "aliases": [ "CVE-2024-3938" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://auth.dotcms.com/security/SI-71" + }, + { + "type": "WEB", + "url": "https://www.dotcms.com/security/SI-71" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-wj8j-4972-pm4v/GHSA-wj8j-4972-pm4v.json b/advisories/unreviewed/2024/07/GHSA-wj8j-4972-pm4v/GHSA-wj8j-4972-pm4v.json index 6239886dc1f..fcb62c79b68 100644 --- a/advisories/unreviewed/2024/07/GHSA-wj8j-4972-pm4v/GHSA-wj8j-4972-pm4v.json +++ b/advisories/unreviewed/2024/07/GHSA-wj8j-4972-pm4v/GHSA-wj8j-4972-pm4v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wj8j-4972-pm4v", - "modified": "2024-07-24T21:31:31Z", + "modified": "2024-07-26T15:31:51Z", "published": "2024-07-24T21:31:31Z", "aliases": [ "CVE-2024-41464" ], "details": "Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goform/RouteStatic", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-24T21:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-wwxv-fvxx-vp4c/GHSA-wwxv-fvxx-vp4c.json b/advisories/unreviewed/2024/07/GHSA-wwxv-fvxx-vp4c/GHSA-wwxv-fvxx-vp4c.json new file mode 100644 index 00000000000..78d408d7e1c --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-wwxv-fvxx-vp4c/GHSA-wwxv-fvxx-vp4c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wwxv-fvxx-vp4c", + "modified": "2024-07-26T15:31:51Z", + "published": "2024-07-26T15:31:51Z", + "aliases": [ + "CVE-2024-6922" + ], + "details": "Automation Anywhere Automation 360 v21-v32 is vulnerable to Server-Side Request Forgery in a web API component. An attacker with unauthenticated access to the Automation 360 Control Room HTTPS service (port 443) or HTTP service (port 80) can trigger arbitrary web requests from the server.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6922" + }, + { + "type": "WEB", + "url": "https://www.automationanywhere.com/products/automation-360" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-26T14:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-xf72-gh36-pgmj/GHSA-xf72-gh36-pgmj.json b/advisories/unreviewed/2024/07/GHSA-xf72-gh36-pgmj/GHSA-xf72-gh36-pgmj.json index ae3f1598c6d..17265134493 100644 --- a/advisories/unreviewed/2024/07/GHSA-xf72-gh36-pgmj/GHSA-xf72-gh36-pgmj.json +++ b/advisories/unreviewed/2024/07/GHSA-xf72-gh36-pgmj/GHSA-xf72-gh36-pgmj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xf72-gh36-pgmj", - "modified": "2024-07-24T21:31:31Z", + "modified": "2024-07-26T15:31:50Z", "published": "2024-07-24T21:31:31Z", "aliases": [ "CVE-2024-41459" ], "details": "Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the PPPOEPassword parameter at ip/goform/QuickIndex.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-24T21:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-xqhh-5j5h-pqfc/GHSA-xqhh-5j5h-pqfc.json b/advisories/unreviewed/2024/07/GHSA-xqhh-5j5h-pqfc/GHSA-xqhh-5j5h-pqfc.json index 1ec09f1a78b..8453fdc25d7 100644 --- a/advisories/unreviewed/2024/07/GHSA-xqhh-5j5h-pqfc/GHSA-xqhh-5j5h-pqfc.json +++ b/advisories/unreviewed/2024/07/GHSA-xqhh-5j5h-pqfc/GHSA-xqhh-5j5h-pqfc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xqhh-5j5h-pqfc", - "modified": "2024-07-24T15:31:27Z", + "modified": "2024-07-26T15:31:50Z", "published": "2024-07-24T15:31:27Z", "aliases": [ "CVE-2024-6327"