From 89d1e32549d2f7cbd41bbcdf81600cdd11ed2ced Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 25 Sep 2024 09:32:30 +0000 Subject: [PATCH] Publish Advisories GHSA-9m5v-m5wp-xcm2 GHSA-2wgv-mm5j-3gx2 GHSA-48cr-j2cx-mcr8 GHSA-6wvp-rh8p-4q7q GHSA-8g6h-p8fh-f429 GHSA-f5fw-25gw-5m92 GHSA-h68x-49ww-wvpx GHSA-hj6g-33gj-29m6 GHSA-qjwg-5c9j-xqcm GHSA-v6p4-r397-q442 --- .../GHSA-9m5v-m5wp-xcm2.json | 6 ++- .../GHSA-2wgv-mm5j-3gx2.json | 42 +++++++++++++++++ .../GHSA-48cr-j2cx-mcr8.json | 35 ++++++++++++++ .../GHSA-6wvp-rh8p-4q7q.json | 46 +++++++++++++++++++ .../GHSA-8g6h-p8fh-f429.json | 42 +++++++++++++++++ .../GHSA-f5fw-25gw-5m92.json | 39 ++++++++++++++++ .../GHSA-h68x-49ww-wvpx.json | 38 +++++++++++++++ .../GHSA-hj6g-33gj-29m6.json | 42 +++++++++++++++++ .../GHSA-qjwg-5c9j-xqcm.json | 42 +++++++++++++++++ .../GHSA-v6p4-r397-q442.json | 38 +++++++++++++++ 10 files changed, 369 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-2wgv-mm5j-3gx2/GHSA-2wgv-mm5j-3gx2.json create mode 100644 advisories/unreviewed/2024/09/GHSA-48cr-j2cx-mcr8/GHSA-48cr-j2cx-mcr8.json create mode 100644 advisories/unreviewed/2024/09/GHSA-6wvp-rh8p-4q7q/GHSA-6wvp-rh8p-4q7q.json create mode 100644 advisories/unreviewed/2024/09/GHSA-8g6h-p8fh-f429/GHSA-8g6h-p8fh-f429.json create mode 100644 advisories/unreviewed/2024/09/GHSA-f5fw-25gw-5m92/GHSA-f5fw-25gw-5m92.json create mode 100644 advisories/unreviewed/2024/09/GHSA-h68x-49ww-wvpx/GHSA-h68x-49ww-wvpx.json create mode 100644 advisories/unreviewed/2024/09/GHSA-hj6g-33gj-29m6/GHSA-hj6g-33gj-29m6.json create mode 100644 advisories/unreviewed/2024/09/GHSA-qjwg-5c9j-xqcm/GHSA-qjwg-5c9j-xqcm.json create mode 100644 advisories/unreviewed/2024/09/GHSA-v6p4-r397-q442/GHSA-v6p4-r397-q442.json diff --git a/advisories/unreviewed/2022/05/GHSA-9m5v-m5wp-xcm2/GHSA-9m5v-m5wp-xcm2.json b/advisories/unreviewed/2022/05/GHSA-9m5v-m5wp-xcm2/GHSA-9m5v-m5wp-xcm2.json index 9505114f6cc..a0088c43017 100644 --- a/advisories/unreviewed/2022/05/GHSA-9m5v-m5wp-xcm2/GHSA-9m5v-m5wp-xcm2.json +++ b/advisories/unreviewed/2022/05/GHSA-9m5v-m5wp-xcm2/GHSA-9m5v-m5wp-xcm2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9m5v-m5wp-xcm2", - "modified": "2022-05-13T00:01:14Z", + "modified": "2024-09-25T09:30:46Z", "published": "2022-05-03T00:00:36Z", "aliases": [ "CVE-2022-28613" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28613" }, + { + "type": "WEB", + "url": "https://publisher.hitachienergy.com/preview?DocumentID=8DBD000103&LanguageCode=en&DocumentPartId=&Action=Launch" + }, { "type": "WEB", "url": "https://search.abb.com/library/Download.aspx?DocumentID=8DBD000103&LanguageCode=en&DocumentPartId=&Action=Launch" diff --git a/advisories/unreviewed/2024/09/GHSA-2wgv-mm5j-3gx2/GHSA-2wgv-mm5j-3gx2.json b/advisories/unreviewed/2024/09/GHSA-2wgv-mm5j-3gx2/GHSA-2wgv-mm5j-3gx2.json new file mode 100644 index 00000000000..b742536bb1d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-2wgv-mm5j-3gx2/GHSA-2wgv-mm5j-3gx2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2wgv-mm5j-3gx2", + "modified": "2024-09-25T09:30:46Z", + "published": "2024-09-25T09:30:46Z", + "aliases": [ + "CVE-2024-8678" + ], + "details": "The Revolut Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wc/v3/revolut REST API endpoint in all versions up to, and including, 4.17.3. This makes it possible for unauthenticated attackers to mark orders as completed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8678" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3153063" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/74dad6f0-0760-4420-b8cc-dc84cafd9b0d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T07:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-48cr-j2cx-mcr8/GHSA-48cr-j2cx-mcr8.json b/advisories/unreviewed/2024/09/GHSA-48cr-j2cx-mcr8/GHSA-48cr-j2cx-mcr8.json new file mode 100644 index 00000000000..2b6d64bd54c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-48cr-j2cx-mcr8/GHSA-48cr-j2cx-mcr8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-48cr-j2cx-mcr8", + "modified": "2024-09-25T09:30:46Z", + "published": "2024-09-25T09:30:46Z", + "aliases": [ + "CVE-2024-40761" + ], + "details": "Inadequate Encryption Strength vulnerability in Apache Answer.\n\nThis issue affects Apache Answer: through 1.3.5.\n\nUsing the MD5 value of a user's email to access Gravatar is insecure and can lead to the leakage of user email. The official recommendation is to use SHA256 instead.\nUsers are recommended to upgrade to version 1.4.0, which fixes the issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40761" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/mmrhsfy16qwrw0pkv0p9kj40vy3sg08x" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-326" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T08:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6wvp-rh8p-4q7q/GHSA-6wvp-rh8p-4q7q.json b/advisories/unreviewed/2024/09/GHSA-6wvp-rh8p-4q7q/GHSA-6wvp-rh8p-4q7q.json new file mode 100644 index 00000000000..d725cbb69ac --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6wvp-rh8p-4q7q/GHSA-6wvp-rh8p-4q7q.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6wvp-rh8p-4q7q", + "modified": "2024-09-25T09:30:46Z", + "published": "2024-09-25T09:30:46Z", + "aliases": [ + "CVE-2024-8290" + ], + "details": "The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.12 via the WCFM_Customers_Manage_Controller::processing function due to missing validation on the ID user controlled key. This makes it possible for authenticated attackers, with subscriber/customer-level access and above, to change the email address of administrator user accounts which allows them to reset the password and access the administrator account.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8290" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.12/controllers/customers/wcfm-controller-customers-manage.php#L97" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3156433/wc-frontend-manager/trunk/controllers/customers/wcfm-controller-customers-manage.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/79172fe3-c0cf-48c4-8bc5-862c628c1a09?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T07:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8g6h-p8fh-f429/GHSA-8g6h-p8fh-f429.json b/advisories/unreviewed/2024/09/GHSA-8g6h-p8fh-f429/GHSA-8g6h-p8fh-f429.json new file mode 100644 index 00000000000..6a495a27bb6 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8g6h-p8fh-f429/GHSA-8g6h-p8fh-f429.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8g6h-p8fh-f429", + "modified": "2024-09-25T09:30:46Z", + "published": "2024-09-25T09:30:46Z", + "aliases": [ + "CVE-2024-8910" + ], + "details": "The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.5 via the render function in includes/widgets/htmega_accordion.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8910" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3156058/ht-mega-for-elementor" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/09fb88e4-4846-40d3-8a79-a6a867bfb59f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1230" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T07:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-f5fw-25gw-5m92/GHSA-f5fw-25gw-5m92.json b/advisories/unreviewed/2024/09/GHSA-f5fw-25gw-5m92/GHSA-f5fw-25gw-5m92.json new file mode 100644 index 00000000000..cfa5e7d82f3 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-f5fw-25gw-5m92/GHSA-f5fw-25gw-5m92.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5fw-25gw-5m92", + "modified": "2024-09-25T09:30:46Z", + "published": "2024-09-25T09:30:46Z", + "aliases": [ + "CVE-2024-23454" + ], + "details": "Apache Hadoop’s RunJar.run() does not set permissions for temporary directory by default. If sensitive data will be present in this file, all the other local users may be able to view the content.\nThis is because, on unix-like systems, the system temporary directory is\nshared between all local users. As such, files written in this directory,\nwithout setting the correct posix permissions explicitly, may be viewable\nby all other local users.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23454" + }, + { + "type": "WEB", + "url": "https://issues.apache.org/jira/browse/HADOOP-19031" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/xlo7q8kn4tsjvx059r789oz19hzgfkfs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T08:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-h68x-49ww-wvpx/GHSA-h68x-49ww-wvpx.json b/advisories/unreviewed/2024/09/GHSA-h68x-49ww-wvpx/GHSA-h68x-49ww-wvpx.json new file mode 100644 index 00000000000..f0f02562108 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-h68x-49ww-wvpx/GHSA-h68x-49ww-wvpx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h68x-49ww-wvpx", + "modified": "2024-09-25T09:30:46Z", + "published": "2024-09-25T09:30:46Z", + "aliases": [ + "CVE-2024-47303" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Livemesh Livemesh Addons for Elementor allows Stored XSS.This issue affects Livemesh Addons for Elementor: from n/a through 8.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47303" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/addons-for-elementor/wordpress-elementor-addons-by-livemesh-plugin-8-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T08:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-hj6g-33gj-29m6/GHSA-hj6g-33gj-29m6.json b/advisories/unreviewed/2024/09/GHSA-hj6g-33gj-29m6/GHSA-hj6g-33gj-29m6.json new file mode 100644 index 00000000000..ff2b3015b3f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-hj6g-33gj-29m6/GHSA-hj6g-33gj-29m6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hj6g-33gj-29m6", + "modified": "2024-09-25T09:30:46Z", + "published": "2024-09-25T09:30:46Z", + "aliases": [ + "CVE-2024-3866" + ], + "details": "The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Referer' header in all versions up to, and including, 3.8.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Successful exploitation of this vulnerability requires \"maintenance mode\" for a targeted form to be enabled. However, there is no setting available to the attacker or even an administrator-level user to enable this mode. The mode is only enabled during a required update, which is a very short window of time. Additionally, because of the self-based nature of this vulnerability, attackers would have to rely on additional techniques to execute a supplied payload in the context of targeted user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3866" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3153292/ninja-forms" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f6d6b82d-574d-4a56-9aef-42343c4b7c43?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T07:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-qjwg-5c9j-xqcm/GHSA-qjwg-5c9j-xqcm.json b/advisories/unreviewed/2024/09/GHSA-qjwg-5c9j-xqcm/GHSA-qjwg-5c9j-xqcm.json new file mode 100644 index 00000000000..5b2a6fb3373 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-qjwg-5c9j-xqcm/GHSA-qjwg-5c9j-xqcm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjwg-5c9j-xqcm", + "modified": "2024-09-25T09:30:46Z", + "published": "2024-09-25T09:30:46Z", + "aliases": [ + "CVE-2024-9169" + ], + "details": "The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin debug settings in all versions up to, and including, 6.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9169" + }, + { + "type": "WEB", + "url": "https://www.litespeedtech.com/products/cache-plugins/wordpress-acceleration" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/051a987a-944a-4898-872b-0456f0f59b27?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T09:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-v6p4-r397-q442/GHSA-v6p4-r397-q442.json b/advisories/unreviewed/2024/09/GHSA-v6p4-r397-q442/GHSA-v6p4-r397-q442.json new file mode 100644 index 00000000000..84801283439 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-v6p4-r397-q442/GHSA-v6p4-r397-q442.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6p4-r397-q442", + "modified": "2024-09-25T09:30:46Z", + "published": "2024-09-25T09:30:46Z", + "aliases": [ + "CVE-2024-8175" + ], + "details": "An unauthenticated remote attacker can causes the CODESYS web server to access invalid memory which results in a DoS.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8175" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-057" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-754" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T08:15:04Z" + } +} \ No newline at end of file