From 8a1401307fa203713818b0cb1976a03af738dc41 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 24 Jun 2024 06:32:40 +0000 Subject: [PATCH] Publish Advisories GHSA-8rmm-gm28-pj8q GHSA-m6q9-p373-g5q8 GHSA-8925-jp4p-j7g9 GHSA-c87f-rj58-gx9p GHSA-g4hp-vh46-5gw6 GHSA-rvm7-rc5g-c98q GHSA-vjx7-hf5r-chv4 --- .../GHSA-8rmm-gm28-pj8q.json | 6 +++- .../GHSA-m6q9-p373-g5q8.json | 6 +++- .../GHSA-8925-jp4p-j7g9.json | 35 +++++++++++++++++++ .../GHSA-c87f-rj58-gx9p.json | 6 +++- .../GHSA-g4hp-vh46-5gw6.json | 6 +++- .../GHSA-rvm7-rc5g-c98q.json | 6 +++- .../GHSA-vjx7-hf5r-chv4.json | 35 +++++++++++++++++++ 7 files changed, 95 insertions(+), 5 deletions(-) create mode 100644 advisories/unreviewed/2024/06/GHSA-8925-jp4p-j7g9/GHSA-8925-jp4p-j7g9.json create mode 100644 advisories/unreviewed/2024/06/GHSA-vjx7-hf5r-chv4/GHSA-vjx7-hf5r-chv4.json diff --git a/advisories/github-reviewed/2024/04/GHSA-8rmm-gm28-pj8q/GHSA-8rmm-gm28-pj8q.json b/advisories/github-reviewed/2024/04/GHSA-8rmm-gm28-pj8q/GHSA-8rmm-gm28-pj8q.json index 4f53e9a5aaf..3da99e260e9 100644 --- a/advisories/github-reviewed/2024/04/GHSA-8rmm-gm28-pj8q/GHSA-8rmm-gm28-pj8q.json +++ b/advisories/github-reviewed/2024/04/GHSA-8rmm-gm28-pj8q/GHSA-8rmm-gm28-pj8q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8rmm-gm28-pj8q", - "modified": "2024-05-21T18:31:14Z", + "modified": "2024-06-24T06:30:54Z", "published": "2024-04-17T17:33:04Z", "aliases": [ "CVE-2023-6717" @@ -75,6 +75,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:2945" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4057" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-6717" diff --git a/advisories/github-reviewed/2024/04/GHSA-m6q9-p373-g5q8/GHSA-m6q9-p373-g5q8.json b/advisories/github-reviewed/2024/04/GHSA-m6q9-p373-g5q8/GHSA-m6q9-p373-g5q8.json index 79704ba2c95..95340b14194 100644 --- a/advisories/github-reviewed/2024/04/GHSA-m6q9-p373-g5q8/GHSA-m6q9-p373-g5q8.json +++ b/advisories/github-reviewed/2024/04/GHSA-m6q9-p373-g5q8/GHSA-m6q9-p373-g5q8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m6q9-p373-g5q8", - "modified": "2024-05-21T18:31:14Z", + "modified": "2024-06-24T06:30:54Z", "published": "2024-04-17T18:24:38Z", "aliases": [ "CVE-2024-1249" @@ -95,6 +95,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:2945" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4057" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-1249" diff --git a/advisories/unreviewed/2024/06/GHSA-8925-jp4p-j7g9/GHSA-8925-jp4p-j7g9.json b/advisories/unreviewed/2024/06/GHSA-8925-jp4p-j7g9/GHSA-8925-jp4p-j7g9.json new file mode 100644 index 00000000000..0f8d8642f9e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-8925-jp4p-j7g9/GHSA-8925-jp4p-j7g9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8925-jp4p-j7g9", + "modified": "2024-06-24T06:30:55Z", + "published": "2024-06-24T06:30:55Z", + "aliases": [ + "CVE-2024-4899" + ], + "details": "The SEOPress WordPress plugin before 7.8 does not sanitise and escape some of its Post settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4899" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/15346ae9-9a29-4968-a6a9-81d1116ac448" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-24T06:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-c87f-rj58-gx9p/GHSA-c87f-rj58-gx9p.json b/advisories/unreviewed/2024/06/GHSA-c87f-rj58-gx9p/GHSA-c87f-rj58-gx9p.json index d542c8fab14..021d7d22d86 100644 --- a/advisories/unreviewed/2024/06/GHSA-c87f-rj58-gx9p/GHSA-c87f-rj58-gx9p.json +++ b/advisories/unreviewed/2024/06/GHSA-c87f-rj58-gx9p/GHSA-c87f-rj58-gx9p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c87f-rj58-gx9p", - "modified": "2024-06-20T12:31:20Z", + "modified": "2024-06-24T06:30:55Z", "published": "2024-06-20T12:31:20Z", "aliases": [ "CVE-2024-28147" @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://r.sec-consult.com/metaventis" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jun/11" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-g4hp-vh46-5gw6/GHSA-g4hp-vh46-5gw6.json b/advisories/unreviewed/2024/06/GHSA-g4hp-vh46-5gw6/GHSA-g4hp-vh46-5gw6.json index 215f89e88f9..fbf9426de2e 100644 --- a/advisories/unreviewed/2024/06/GHSA-g4hp-vh46-5gw6/GHSA-g4hp-vh46-5gw6.json +++ b/advisories/unreviewed/2024/06/GHSA-g4hp-vh46-5gw6/GHSA-g4hp-vh46-5gw6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g4hp-vh46-5gw6", - "modified": "2024-06-19T12:31:21Z", + "modified": "2024-06-24T06:30:55Z", "published": "2024-06-19T12:31:21Z", "aliases": [ "CVE-2024-5676" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://www.paradox.com/Products/default.asp?CATID=3&SUBCATID=38&PRD=563" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jun/8" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-rvm7-rc5g-c98q/GHSA-rvm7-rc5g-c98q.json b/advisories/unreviewed/2024/06/GHSA-rvm7-rc5g-c98q/GHSA-rvm7-rc5g-c98q.json index 30b9c76898a..cd049c2b8a4 100644 --- a/advisories/unreviewed/2024/06/GHSA-rvm7-rc5g-c98q/GHSA-rvm7-rc5g-c98q.json +++ b/advisories/unreviewed/2024/06/GHSA-rvm7-rc5g-c98q/GHSA-rvm7-rc5g-c98q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rvm7-rc5g-c98q", - "modified": "2024-06-11T21:32:17Z", + "modified": "2024-06-24T06:30:54Z", "published": "2024-06-11T21:32:17Z", "aliases": [ "CVE-2023-4727" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4727" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4051" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-4727" diff --git a/advisories/unreviewed/2024/06/GHSA-vjx7-hf5r-chv4/GHSA-vjx7-hf5r-chv4.json b/advisories/unreviewed/2024/06/GHSA-vjx7-hf5r-chv4/GHSA-vjx7-hf5r-chv4.json new file mode 100644 index 00000000000..43e12ab1f56 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-vjx7-hf5r-chv4/GHSA-vjx7-hf5r-chv4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjx7-hf5r-chv4", + "modified": "2024-06-24T06:30:55Z", + "published": "2024-06-24T06:30:55Z", + "aliases": [ + "CVE-2024-4900" + ], + "details": "The SEOPress WordPress plugin before 7.8 does not validate and escape one of its Post settings, which could allow contributor and above role to perform Open redirect attacks against any user viewing a malicious post", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4900" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/a56ad272-e2ed-4064-9b5d-114a834dd8b3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-24T06:15:11Z" + } +} \ No newline at end of file