From 88e86a00965b4478305778101736270b5c64dec1 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 23 Aug 2024 21:32:06 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-8c2v-657f-h9r7.json | 2 +- .../GHSA-62vc-2f72-vcj3.json | 9 ++-- .../GHSA-9jmq-68m9-2x2j.json | 11 +++-- .../GHSA-f8vf-5cvf-jr22.json | 11 +++-- .../GHSA-9xr6-qf7m-2jv5.json | 11 +++-- .../GHSA-r7wm-jrf5-83qv.json | 11 +++-- .../GHSA-v2vx-hcgc-qcvc.json | 11 +++-- .../GHSA-v6qj-65jf-4qvc.json | 9 ++-- .../GHSA-w4j4-p425-4fwc.json | 11 +++-- .../GHSA-q2xc-6c48-r5px.json | 11 +++-- .../GHSA-6qmp-435x-jm84.json | 11 +++-- .../GHSA-27rm-pvpp-228f.json | 35 +++++++++++++++ .../GHSA-44mp-qrwc-xm4x.json | 11 +++-- .../GHSA-4mrc-w7jh-hx4j.json | 38 ++++++++++++++++ .../GHSA-58cw-gjp7-8mm7.json | 11 +++-- .../GHSA-6v83-ppjw-wp84.json | 11 +++-- .../GHSA-723q-4x66-vrf2.json | 11 +++-- .../GHSA-c9r7-wpw8-xc67.json | 11 +++-- .../GHSA-cgxv-795x-3vqr.json | 38 ++++++++++++++++ .../GHSA-g3jm-x33w-9q5w.json | 11 +++-- .../GHSA-g6mg-qmxh-mv93.json | 11 +++-- .../GHSA-g8h2-j9pm-4xx2.json | 39 +++++++++++++++++ .../GHSA-jg95-r9xh-xw9c.json | 38 ++++++++++++++++ .../GHSA-jj85-4qm9-xvwg.json | 11 +++-- .../GHSA-pr2m-hg7m-28mp.json | 39 +++++++++++++++++ .../GHSA-pwhp-4qxf-7ff6.json | 1 + .../GHSA-r6rr-3664-gq2w.json | 11 +++-- .../GHSA-v9wr-8wrm-h6p7.json | 38 ++++++++++++++++ .../GHSA-vq36-rf43-jmh7.json | 11 +++-- .../GHSA-wqgx-27v7-cr9h.json | 11 +++-- .../GHSA-x34v-6wh4-m93r.json | 43 +++++++++++++++++++ 31 files changed, 455 insertions(+), 83 deletions(-) create mode 100644 advisories/unreviewed/2024/08/GHSA-27rm-pvpp-228f/GHSA-27rm-pvpp-228f.json create mode 100644 advisories/unreviewed/2024/08/GHSA-4mrc-w7jh-hx4j/GHSA-4mrc-w7jh-hx4j.json create mode 100644 advisories/unreviewed/2024/08/GHSA-cgxv-795x-3vqr/GHSA-cgxv-795x-3vqr.json create mode 100644 advisories/unreviewed/2024/08/GHSA-g8h2-j9pm-4xx2/GHSA-g8h2-j9pm-4xx2.json create mode 100644 advisories/unreviewed/2024/08/GHSA-jg95-r9xh-xw9c/GHSA-jg95-r9xh-xw9c.json create mode 100644 advisories/unreviewed/2024/08/GHSA-pr2m-hg7m-28mp/GHSA-pr2m-hg7m-28mp.json create mode 100644 advisories/unreviewed/2024/08/GHSA-v9wr-8wrm-h6p7/GHSA-v9wr-8wrm-h6p7.json create mode 100644 advisories/unreviewed/2024/08/GHSA-x34v-6wh4-m93r/GHSA-x34v-6wh4-m93r.json diff --git a/advisories/unreviewed/2024/01/GHSA-8c2v-657f-h9r7/GHSA-8c2v-657f-h9r7.json b/advisories/unreviewed/2024/01/GHSA-8c2v-657f-h9r7/GHSA-8c2v-657f-h9r7.json index 39be488994e..9d404069720 100644 --- a/advisories/unreviewed/2024/01/GHSA-8c2v-657f-h9r7/GHSA-8c2v-657f-h9r7.json +++ b/advisories/unreviewed/2024/01/GHSA-8c2v-657f-h9r7/GHSA-8c2v-657f-h9r7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8c2v-657f-h9r7", - "modified": "2024-02-03T00:31:33Z", + "modified": "2024-08-23T21:30:41Z", "published": "2024-01-29T21:30:27Z", "aliases": [ "CVE-2024-24139" diff --git a/advisories/unreviewed/2024/02/GHSA-62vc-2f72-vcj3/GHSA-62vc-2f72-vcj3.json b/advisories/unreviewed/2024/02/GHSA-62vc-2f72-vcj3/GHSA-62vc-2f72-vcj3.json index d317c369dfc..4134e9bd109 100644 --- a/advisories/unreviewed/2024/02/GHSA-62vc-2f72-vcj3/GHSA-62vc-2f72-vcj3.json +++ b/advisories/unreviewed/2024/02/GHSA-62vc-2f72-vcj3/GHSA-62vc-2f72-vcj3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-62vc-2f72-vcj3", - "modified": "2024-03-04T09:30:29Z", + "modified": "2024-08-23T21:30:41Z", "published": "2024-02-20T15:31:05Z", "aliases": [ "CVE-2024-1553" ], "details": "Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-20T14:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-9jmq-68m9-2x2j/GHSA-9jmq-68m9-2x2j.json b/advisories/unreviewed/2024/02/GHSA-9jmq-68m9-2x2j/GHSA-9jmq-68m9-2x2j.json index 930612a2eb2..d4b5a02710b 100644 --- a/advisories/unreviewed/2024/02/GHSA-9jmq-68m9-2x2j/GHSA-9jmq-68m9-2x2j.json +++ b/advisories/unreviewed/2024/02/GHSA-9jmq-68m9-2x2j/GHSA-9jmq-68m9-2x2j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9jmq-68m9-2x2j", - "modified": "2024-02-27T18:31:02Z", + "modified": "2024-08-23T21:30:41Z", "published": "2024-02-27T18:31:02Z", "aliases": [ "CVE-2024-25840" ], "details": "In the module \"Account Manager | Sales Representative & Dealers | CRM\" (prestasalesmanager) up to 9.0 from Presta World for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-31" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T17:15:12Z" diff --git a/advisories/unreviewed/2024/02/GHSA-f8vf-5cvf-jr22/GHSA-f8vf-5cvf-jr22.json b/advisories/unreviewed/2024/02/GHSA-f8vf-5cvf-jr22/GHSA-f8vf-5cvf-jr22.json index 8cbcb952fef..8f685b1d2be 100644 --- a/advisories/unreviewed/2024/02/GHSA-f8vf-5cvf-jr22/GHSA-f8vf-5cvf-jr22.json +++ b/advisories/unreviewed/2024/02/GHSA-f8vf-5cvf-jr22/GHSA-f8vf-5cvf-jr22.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f8vf-5cvf-jr22", - "modified": "2024-02-29T03:33:12Z", + "modified": "2024-08-23T21:30:41Z", "published": "2024-02-29T03:33:12Z", "aliases": [ "CVE-2023-27151" ], "details": "openCRX 5.2.0 was discovered to contain an HTML injection vulnerability for Search Criteria-Activity Number (in the Saved Search Activity) via the Name, Description, or Activity Number field.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T01:38:30Z" diff --git a/advisories/unreviewed/2024/03/GHSA-9xr6-qf7m-2jv5/GHSA-9xr6-qf7m-2jv5.json b/advisories/unreviewed/2024/03/GHSA-9xr6-qf7m-2jv5/GHSA-9xr6-qf7m-2jv5.json index cd7fa12d39f..7fe54591d28 100644 --- a/advisories/unreviewed/2024/03/GHSA-9xr6-qf7m-2jv5/GHSA-9xr6-qf7m-2jv5.json +++ b/advisories/unreviewed/2024/03/GHSA-9xr6-qf7m-2jv5/GHSA-9xr6-qf7m-2jv5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9xr6-qf7m-2jv5", - "modified": "2024-07-30T03:30:51Z", + "modified": "2024-08-23T21:30:41Z", "published": "2024-03-27T09:30:41Z", "aliases": [ "CVE-2024-2466" ], "details": "libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address, therefore completely skipping the certificate check. This affects all uses of TLS protocols (HTTPS, FTPS, IMAPS, POPS3, SMTPS, etc).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -65,9 +68,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-297" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-27T08:15:41Z" diff --git a/advisories/unreviewed/2024/03/GHSA-r7wm-jrf5-83qv/GHSA-r7wm-jrf5-83qv.json b/advisories/unreviewed/2024/03/GHSA-r7wm-jrf5-83qv/GHSA-r7wm-jrf5-83qv.json index c19acb9fc58..6c9e35ba10b 100644 --- a/advisories/unreviewed/2024/03/GHSA-r7wm-jrf5-83qv/GHSA-r7wm-jrf5-83qv.json +++ b/advisories/unreviewed/2024/03/GHSA-r7wm-jrf5-83qv/GHSA-r7wm-jrf5-83qv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r7wm-jrf5-83qv", - "modified": "2024-03-04T03:30:26Z", + "modified": "2024-08-23T21:30:41Z", "published": "2024-03-04T03:30:26Z", "aliases": [ "CVE-2024-20032" ], "details": "In aee, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08487630; Issue ID: MSV-1020.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-04T03:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-v2vx-hcgc-qcvc/GHSA-v2vx-hcgc-qcvc.json b/advisories/unreviewed/2024/03/GHSA-v2vx-hcgc-qcvc/GHSA-v2vx-hcgc-qcvc.json index 33f1b6117c7..05cc5a5271b 100644 --- a/advisories/unreviewed/2024/03/GHSA-v2vx-hcgc-qcvc/GHSA-v2vx-hcgc-qcvc.json +++ b/advisories/unreviewed/2024/03/GHSA-v2vx-hcgc-qcvc/GHSA-v2vx-hcgc-qcvc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v2vx-hcgc-qcvc", - "modified": "2024-03-22T12:30:46Z", + "modified": "2024-08-23T21:30:41Z", "published": "2024-03-22T12:30:46Z", "aliases": [ "CVE-2024-28560" ], "details": "SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the deleteArea() function of the Address.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-22T12:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-v6qj-65jf-4qvc/GHSA-v6qj-65jf-4qvc.json b/advisories/unreviewed/2024/03/GHSA-v6qj-65jf-4qvc/GHSA-v6qj-65jf-4qvc.json index 8bd3662613b..2a78100ef95 100644 --- a/advisories/unreviewed/2024/03/GHSA-v6qj-65jf-4qvc/GHSA-v6qj-65jf-4qvc.json +++ b/advisories/unreviewed/2024/03/GHSA-v6qj-65jf-4qvc/GHSA-v6qj-65jf-4qvc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v6qj-65jf-4qvc", - "modified": "2024-03-28T03:30:59Z", + "modified": "2024-08-23T21:30:41Z", "published": "2024-03-28T03:30:59Z", "aliases": [ "CVE-2024-28014" ], "details": "Stack-based Buffer Overflow vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN and MR02LN all versions allows a attacker to execute an arbitrary command via the internet.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T01:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-w4j4-p425-4fwc/GHSA-w4j4-p425-4fwc.json b/advisories/unreviewed/2024/03/GHSA-w4j4-p425-4fwc/GHSA-w4j4-p425-4fwc.json index 8c546a6885e..7f220de48c1 100644 --- a/advisories/unreviewed/2024/03/GHSA-w4j4-p425-4fwc/GHSA-w4j4-p425-4fwc.json +++ b/advisories/unreviewed/2024/03/GHSA-w4j4-p425-4fwc/GHSA-w4j4-p425-4fwc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w4j4-p425-4fwc", - "modified": "2024-03-22T18:30:31Z", + "modified": "2024-08-23T21:30:41Z", "published": "2024-03-22T18:30:31Z", "aliases": [ "CVE-2024-29385" ], "details": "DIR-845L router <= v1.01KRb03 has an Unauthenticated remote code execution vulnerability in the cgibin binary via soapcgi_main function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-22T17:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-q2xc-6c48-r5px/GHSA-q2xc-6c48-r5px.json b/advisories/unreviewed/2024/05/GHSA-q2xc-6c48-r5px/GHSA-q2xc-6c48-r5px.json index 7e6236c02a5..80831d095f2 100644 --- a/advisories/unreviewed/2024/05/GHSA-q2xc-6c48-r5px/GHSA-q2xc-6c48-r5px.json +++ b/advisories/unreviewed/2024/05/GHSA-q2xc-6c48-r5px/GHSA-q2xc-6c48-r5px.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q2xc-6c48-r5px", - "modified": "2024-05-14T21:34:44Z", + "modified": "2024-08-23T21:30:41Z", "published": "2024-05-14T21:34:44Z", "aliases": [ "CVE-2022-28132" ], "details": "The T-Soft E-Commerce 4 web application is susceptible to SQL injection (SQLi) attacks when authenticated as an admin or privileged user. This vulnerability allows attackers to access and manipulate the database through crafted requests. By exploiting this flaw, attackers can bypass authentication mechanisms, view sensitive information stored in the database, and potentially exfiltrate data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T21:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-6qmp-435x-jm84/GHSA-6qmp-435x-jm84.json b/advisories/unreviewed/2024/06/GHSA-6qmp-435x-jm84/GHSA-6qmp-435x-jm84.json index 65dfc5173b2..9c9ee6d43fd 100644 --- a/advisories/unreviewed/2024/06/GHSA-6qmp-435x-jm84/GHSA-6qmp-435x-jm84.json +++ b/advisories/unreviewed/2024/06/GHSA-6qmp-435x-jm84/GHSA-6qmp-435x-jm84.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6qmp-435x-jm84", - "modified": "2024-06-07T00:30:37Z", + "modified": "2024-08-23T21:30:41Z", "published": "2024-06-07T00:30:37Z", "aliases": [ "CVE-2024-24194" ], "details": "robdns commit d76d2e6 was discovered to contain a NULL pointer dereference via the item->tokens component at /src/conf-parse.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-06T22:15:10Z" diff --git a/advisories/unreviewed/2024/08/GHSA-27rm-pvpp-228f/GHSA-27rm-pvpp-228f.json b/advisories/unreviewed/2024/08/GHSA-27rm-pvpp-228f/GHSA-27rm-pvpp-228f.json new file mode 100644 index 00000000000..b42d76bd28d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-27rm-pvpp-228f/GHSA-27rm-pvpp-228f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-27rm-pvpp-228f", + "modified": "2024-08-23T21:30:42Z", + "published": "2024-08-23T21:30:42Z", + "aliases": [ + "CVE-2024-37392" + ], + "details": "A stored Cross-Site Scripting (XSS) vulnerability has been identified in SMSEagle software version < 6.0. The vulnerability arises because the application did not properly sanitize user input in the SMS messages in the inbox. This could allow an attacker to inject malicious JavaScript code into an SMS message, which gets executed when the SMS is viewed and specially interacted in web-GUI.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37392" + }, + { + "type": "WEB", + "url": "https://www.smseagle.eu/2024/08/21/resolved-xss-in-smseagle-software-cve-2024-37392" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-44mp-qrwc-xm4x/GHSA-44mp-qrwc-xm4x.json b/advisories/unreviewed/2024/08/GHSA-44mp-qrwc-xm4x/GHSA-44mp-qrwc-xm4x.json index 90535f99bdd..dbd82a4664f 100644 --- a/advisories/unreviewed/2024/08/GHSA-44mp-qrwc-xm4x/GHSA-44mp-qrwc-xm4x.json +++ b/advisories/unreviewed/2024/08/GHSA-44mp-qrwc-xm4x/GHSA-44mp-qrwc-xm4x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-44mp-qrwc-xm4x", - "modified": "2024-08-23T18:33:03Z", + "modified": "2024-08-23T21:30:42Z", "published": "2024-08-23T18:33:03Z", "aliases": [ "CVE-2024-42852" ], "details": "Cross Site Scripting vulnerability in AcuToWeb server v.10.5.0.7577C8b allows a remote attacker to execute arbitrary code via the index.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-23T18:15:07Z" diff --git a/advisories/unreviewed/2024/08/GHSA-4mrc-w7jh-hx4j/GHSA-4mrc-w7jh-hx4j.json b/advisories/unreviewed/2024/08/GHSA-4mrc-w7jh-hx4j/GHSA-4mrc-w7jh-hx4j.json new file mode 100644 index 00000000000..c78022db41d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4mrc-w7jh-hx4j/GHSA-4mrc-w7jh-hx4j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mrc-w7jh-hx4j", + "modified": "2024-08-23T21:30:42Z", + "published": "2024-08-23T21:30:42Z", + "aliases": [ + "CVE-2024-45190" + ], + "details": "Mage AI allows remote users with the \"Viewer\" role to leak arbitrary files from the Mage server due to a path traversal in the \"Pipeline Interaction\" request", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45190" + }, + { + "type": "WEB", + "url": "https://research.jfrog.com/vulnerabilities/mage-ai-pipeline-interaction-request-remote-arbitrary-file-leak-jfsa-2024-001039605" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-58cw-gjp7-8mm7/GHSA-58cw-gjp7-8mm7.json b/advisories/unreviewed/2024/08/GHSA-58cw-gjp7-8mm7/GHSA-58cw-gjp7-8mm7.json index a8a0070a005..99f00f4ca69 100644 --- a/advisories/unreviewed/2024/08/GHSA-58cw-gjp7-8mm7/GHSA-58cw-gjp7-8mm7.json +++ b/advisories/unreviewed/2024/08/GHSA-58cw-gjp7-8mm7/GHSA-58cw-gjp7-8mm7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-58cw-gjp7-8mm7", - "modified": "2024-08-23T18:33:02Z", + "modified": "2024-08-23T21:30:42Z", "published": "2024-08-23T18:33:02Z", "aliases": [ "CVE-2024-39841" ], "details": "A SQL Injection vulnerability exists in the service configuration functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-23T17:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-6v83-ppjw-wp84/GHSA-6v83-ppjw-wp84.json b/advisories/unreviewed/2024/08/GHSA-6v83-ppjw-wp84/GHSA-6v83-ppjw-wp84.json index 3fbf8961bef..0ffcd94b5d8 100644 --- a/advisories/unreviewed/2024/08/GHSA-6v83-ppjw-wp84/GHSA-6v83-ppjw-wp84.json +++ b/advisories/unreviewed/2024/08/GHSA-6v83-ppjw-wp84/GHSA-6v83-ppjw-wp84.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6v83-ppjw-wp84", - "modified": "2024-08-23T18:33:01Z", + "modified": "2024-08-23T21:30:42Z", "published": "2024-08-23T18:33:01Z", "aliases": [ "CVE-2024-42636" ], "details": "DedeCMS V5.7.115 has a command execution vulnerability via file_manage_view.php?fmdo=newfile&activepath.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-23T16:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-723q-4x66-vrf2/GHSA-723q-4x66-vrf2.json b/advisories/unreviewed/2024/08/GHSA-723q-4x66-vrf2/GHSA-723q-4x66-vrf2.json index 0ab80220bc5..2211eb9db3c 100644 --- a/advisories/unreviewed/2024/08/GHSA-723q-4x66-vrf2/GHSA-723q-4x66-vrf2.json +++ b/advisories/unreviewed/2024/08/GHSA-723q-4x66-vrf2/GHSA-723q-4x66-vrf2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-723q-4x66-vrf2", - "modified": "2024-08-23T18:33:02Z", + "modified": "2024-08-23T21:30:42Z", "published": "2024-08-23T18:33:02Z", "aliases": [ "CVE-2024-44381" ], "details": "D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in jhttpd msp_info_htm function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-23T16:15:07Z" diff --git a/advisories/unreviewed/2024/08/GHSA-c9r7-wpw8-xc67/GHSA-c9r7-wpw8-xc67.json b/advisories/unreviewed/2024/08/GHSA-c9r7-wpw8-xc67/GHSA-c9r7-wpw8-xc67.json index d20b949c293..f9c5ac60334 100644 --- a/advisories/unreviewed/2024/08/GHSA-c9r7-wpw8-xc67/GHSA-c9r7-wpw8-xc67.json +++ b/advisories/unreviewed/2024/08/GHSA-c9r7-wpw8-xc67/GHSA-c9r7-wpw8-xc67.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c9r7-wpw8-xc67", - "modified": "2024-08-23T15:30:34Z", + "modified": "2024-08-23T21:30:42Z", "published": "2024-08-23T15:30:34Z", "aliases": [ "CVE-2024-42915" ], "details": "A host header injection vulnerability in Staff Appraisal System v1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This will allow attackers to arbitrarily reset other users' passwords and compromise their accounts.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-640" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-23T15:15:16Z" diff --git a/advisories/unreviewed/2024/08/GHSA-cgxv-795x-3vqr/GHSA-cgxv-795x-3vqr.json b/advisories/unreviewed/2024/08/GHSA-cgxv-795x-3vqr/GHSA-cgxv-795x-3vqr.json new file mode 100644 index 00000000000..a02c70952f0 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cgxv-795x-3vqr/GHSA-cgxv-795x-3vqr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cgxv-795x-3vqr", + "modified": "2024-08-23T21:30:42Z", + "published": "2024-08-23T21:30:42Z", + "aliases": [ + "CVE-2024-45189" + ], + "details": "Mage AI allows remote users with the \"Viewer\" role to leak arbitrary files from the Mage server due to a path traversal in the \"Git Content\" request", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45189" + }, + { + "type": "WEB", + "url": "https://research.jfrog.com/vulnerabilities/mage-ai-git-content-request-remote-arbitrary-file-leak-jfsa-2024-001039604" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g3jm-x33w-9q5w/GHSA-g3jm-x33w-9q5w.json b/advisories/unreviewed/2024/08/GHSA-g3jm-x33w-9q5w/GHSA-g3jm-x33w-9q5w.json index 90658c58af8..eed8051f7b5 100644 --- a/advisories/unreviewed/2024/08/GHSA-g3jm-x33w-9q5w/GHSA-g3jm-x33w-9q5w.json +++ b/advisories/unreviewed/2024/08/GHSA-g3jm-x33w-9q5w/GHSA-g3jm-x33w-9q5w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g3jm-x33w-9q5w", - "modified": "2024-08-23T18:33:02Z", + "modified": "2024-08-23T21:30:42Z", "published": "2024-08-23T18:33:02Z", "aliases": [ "CVE-2024-44386" ], "details": "Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function fromSetIpBind.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-23T16:15:07Z" diff --git a/advisories/unreviewed/2024/08/GHSA-g6mg-qmxh-mv93/GHSA-g6mg-qmxh-mv93.json b/advisories/unreviewed/2024/08/GHSA-g6mg-qmxh-mv93/GHSA-g6mg-qmxh-mv93.json index d63fcc9e9e6..2ec69201776 100644 --- a/advisories/unreviewed/2024/08/GHSA-g6mg-qmxh-mv93/GHSA-g6mg-qmxh-mv93.json +++ b/advisories/unreviewed/2024/08/GHSA-g6mg-qmxh-mv93/GHSA-g6mg-qmxh-mv93.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g6mg-qmxh-mv93", - "modified": "2024-08-21T18:31:27Z", + "modified": "2024-08-23T21:30:42Z", "published": "2024-08-21T18:31:27Z", "aliases": [ "CVE-2024-43027" ], "details": "DrayTek Vigor 3900 before v1.5.1.5_Beta, DrayTek Vigor 2960 before v1.5.1.5_Beta and DrayTek Vigor 300B before v1.5.1.5_Beta were discovered to contain a command injection vulnerability via the action parameter at cgi-bin/mainfunction.cgi.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-21T16:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-g8h2-j9pm-4xx2/GHSA-g8h2-j9pm-4xx2.json b/advisories/unreviewed/2024/08/GHSA-g8h2-j9pm-4xx2/GHSA-g8h2-j9pm-4xx2.json new file mode 100644 index 00000000000..642cadfc65a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-g8h2-j9pm-4xx2/GHSA-g8h2-j9pm-4xx2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8h2-j9pm-4xx2", + "modified": "2024-08-23T21:30:42Z", + "published": "2024-08-23T21:30:42Z", + "aliases": [ + "CVE-2024-40111" + ], + "details": "A persistent (stored) cross-site scripting (XSS) vulnerability has been identified in Automad 2.0.0-alpha.4. This vulnerability enables an attacker to inject malicious JavaScript code into the template body. The injected code is stored within the flat file CMS and is executed in the browser of any user visiting the forum.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40111" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/10BVQKYo2H1-Nx3FOGteL2xww4lbZ3xlS/view?usp=sharing" + }, + { + "type": "WEB", + "url": "https://github.com/w3bn00b3r/Stored-Cross-Site-Scripting-XSS---Automad-2.0.0-alpha.4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jg95-r9xh-xw9c/GHSA-jg95-r9xh-xw9c.json b/advisories/unreviewed/2024/08/GHSA-jg95-r9xh-xw9c/GHSA-jg95-r9xh-xw9c.json new file mode 100644 index 00000000000..b67e16f3bc4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jg95-r9xh-xw9c/GHSA-jg95-r9xh-xw9c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jg95-r9xh-xw9c", + "modified": "2024-08-23T21:30:42Z", + "published": "2024-08-23T21:30:42Z", + "aliases": [ + "CVE-2024-45187" + ], + "details": "Guest users in the Mage AI framework that remain logged in after their accounts are deleted, are mistakenly given high privileges and specifically given access to remotely execute arbitrary code through the Mage AI terminal server", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45187" + }, + { + "type": "WEB", + "url": "https://research.jfrog.com/vulnerabilities/mage-ai-deleted-users-rce-jfsa-2024-001039602" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T19:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jj85-4qm9-xvwg/GHSA-jj85-4qm9-xvwg.json b/advisories/unreviewed/2024/08/GHSA-jj85-4qm9-xvwg/GHSA-jj85-4qm9-xvwg.json index 869d1c22544..1e1202beb2f 100644 --- a/advisories/unreviewed/2024/08/GHSA-jj85-4qm9-xvwg/GHSA-jj85-4qm9-xvwg.json +++ b/advisories/unreviewed/2024/08/GHSA-jj85-4qm9-xvwg/GHSA-jj85-4qm9-xvwg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jj85-4qm9-xvwg", - "modified": "2024-08-23T18:33:01Z", + "modified": "2024-08-23T21:30:42Z", "published": "2024-08-23T18:33:01Z", "aliases": [ "CVE-2024-42523" ], "details": "publiccms V4.0.202302.e and before is vulnerable to Any File Upload via publiccms/admin/cmsTemplate/saveMetaData", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-23T16:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-pr2m-hg7m-28mp/GHSA-pr2m-hg7m-28mp.json b/advisories/unreviewed/2024/08/GHSA-pr2m-hg7m-28mp/GHSA-pr2m-hg7m-28mp.json new file mode 100644 index 00000000000..8c62e86e85d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-pr2m-hg7m-28mp/GHSA-pr2m-hg7m-28mp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pr2m-hg7m-28mp", + "modified": "2024-08-23T21:30:42Z", + "published": "2024-08-23T21:30:42Z", + "aliases": [ + "CVE-2024-42914" + ], + "details": "A host header injection vulnerability exists in the forgot password functionality of ArrowCMS version 1.0.0. By sending a specially crafted host header in the forgot password request, it is possible to send password reset links to users which, once clicked, lead to an attacker-controlled server and thus leak the password reset token. This may allow an attacker to reset other users' passwords.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42914" + }, + { + "type": "WEB", + "url": "https://github.com/soursec/CVEs/tree/main/CVE-2024-42914" + }, + { + "type": "WEB", + "url": "https://github.com/trquoccuong/ArrowCMS" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T19:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pwhp-4qxf-7ff6/GHSA-pwhp-4qxf-7ff6.json b/advisories/unreviewed/2024/08/GHSA-pwhp-4qxf-7ff6/GHSA-pwhp-4qxf-7ff6.json index 7b3173e9237..a895b1a110f 100644 --- a/advisories/unreviewed/2024/08/GHSA-pwhp-4qxf-7ff6/GHSA-pwhp-4qxf-7ff6.json +++ b/advisories/unreviewed/2024/08/GHSA-pwhp-4qxf-7ff6/GHSA-pwhp-4qxf-7ff6.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-74", "CWE-943" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/08/GHSA-r6rr-3664-gq2w/GHSA-r6rr-3664-gq2w.json b/advisories/unreviewed/2024/08/GHSA-r6rr-3664-gq2w/GHSA-r6rr-3664-gq2w.json index bb36ad92e1e..de5042bb363 100644 --- a/advisories/unreviewed/2024/08/GHSA-r6rr-3664-gq2w/GHSA-r6rr-3664-gq2w.json +++ b/advisories/unreviewed/2024/08/GHSA-r6rr-3664-gq2w/GHSA-r6rr-3664-gq2w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r6rr-3664-gq2w", - "modified": "2024-08-23T18:33:02Z", + "modified": "2024-08-23T21:30:42Z", "published": "2024-08-23T18:33:02Z", "aliases": [ "CVE-2024-44382" ], "details": "D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in the jhttpd upgrade_filter_asp function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-23T16:15:07Z" diff --git a/advisories/unreviewed/2024/08/GHSA-v9wr-8wrm-h6p7/GHSA-v9wr-8wrm-h6p7.json b/advisories/unreviewed/2024/08/GHSA-v9wr-8wrm-h6p7/GHSA-v9wr-8wrm-h6p7.json new file mode 100644 index 00000000000..7d05536f212 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v9wr-8wrm-h6p7/GHSA-v9wr-8wrm-h6p7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9wr-8wrm-h6p7", + "modified": "2024-08-23T21:30:42Z", + "published": "2024-08-23T21:30:42Z", + "aliases": [ + "CVE-2024-45188" + ], + "details": "Mage AI allows remote users with the \"Viewer\" role to leak arbitrary files from the Mage server due to a path traversal in the \"File Content\" request", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45188" + }, + { + "type": "WEB", + "url": "https://research.jfrog.com/vulnerabilities/mage-ai-file-content-request-remote-arbitrary-file-leak-jfsa-2024-001039603" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T20:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vq36-rf43-jmh7/GHSA-vq36-rf43-jmh7.json b/advisories/unreviewed/2024/08/GHSA-vq36-rf43-jmh7/GHSA-vq36-rf43-jmh7.json index 922bc7ef7d5..613873b1629 100644 --- a/advisories/unreviewed/2024/08/GHSA-vq36-rf43-jmh7/GHSA-vq36-rf43-jmh7.json +++ b/advisories/unreviewed/2024/08/GHSA-vq36-rf43-jmh7/GHSA-vq36-rf43-jmh7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vq36-rf43-jmh7", - "modified": "2024-08-23T18:33:03Z", + "modified": "2024-08-23T21:30:42Z", "published": "2024-08-23T18:33:03Z", "aliases": [ "CVE-2024-42992" ], "details": "Python Pip Pandas v2.2.2 was discovered to contain an arbitrary file read vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-23T18:15:07Z" diff --git a/advisories/unreviewed/2024/08/GHSA-wqgx-27v7-cr9h/GHSA-wqgx-27v7-cr9h.json b/advisories/unreviewed/2024/08/GHSA-wqgx-27v7-cr9h/GHSA-wqgx-27v7-cr9h.json index 30913bfecfd..86a79682a29 100644 --- a/advisories/unreviewed/2024/08/GHSA-wqgx-27v7-cr9h/GHSA-wqgx-27v7-cr9h.json +++ b/advisories/unreviewed/2024/08/GHSA-wqgx-27v7-cr9h/GHSA-wqgx-27v7-cr9h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wqgx-27v7-cr9h", - "modified": "2024-08-23T18:33:03Z", + "modified": "2024-08-23T21:30:42Z", "published": "2024-08-23T18:33:03Z", "aliases": [ "CVE-2024-42531" ], "details": "Ezviz Internet PT Camera CS-CV246 D15655150 allows an unauthenticated host to access its live video stream by crafting a set of RTSP packets with a specific set of URLs that can be used to redirect the camera feed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-23T17:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-x34v-6wh4-m93r/GHSA-x34v-6wh4-m93r.json b/advisories/unreviewed/2024/08/GHSA-x34v-6wh4-m93r/GHSA-x34v-6wh4-m93r.json new file mode 100644 index 00000000000..e86d7130dd3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-x34v-6wh4-m93r/GHSA-x34v-6wh4-m93r.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x34v-6wh4-m93r", + "modified": "2024-08-23T21:30:42Z", + "published": "2024-08-23T21:30:42Z", + "aliases": [ + "CVE-2024-42845" + ], + "details": "An eval Injection vulnerability in the component invesalius/reader/dicom.py of InVesalius 3.1.99991 through 3.1.99998 allows attackers to execute arbitrary code via loading a crafted DICOM file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42845" + }, + { + "type": "WEB", + "url": "https://github.com/invesalius/invesalius3" + }, + { + "type": "WEB", + "url": "https://github.com/invesalius/invesalius3/releases" + }, + { + "type": "WEB", + "url": "https://github.com/partywavesec/invesalius3_vulnerabilities/tree/main/CVE-2024-42845" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T19:15:06Z" + } +} \ No newline at end of file