diff --git a/advisories/github-reviewed/2018/12/GHSA-www2-v7xj-xrc6/GHSA-www2-v7xj-xrc6.json b/advisories/github-reviewed/2018/12/GHSA-www2-v7xj-xrc6/GHSA-www2-v7xj-xrc6.json index ac03d1efb1a..50abbdb1511 100644 --- a/advisories/github-reviewed/2018/12/GHSA-www2-v7xj-xrc6/GHSA-www2-v7xj-xrc6.json +++ b/advisories/github-reviewed/2018/12/GHSA-www2-v7xj-xrc6/GHSA-www2-v7xj-xrc6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-www2-v7xj-xrc6", - "modified": "2024-11-18T22:31:17Z", + "modified": "2024-12-27T18:30:25Z", "published": "2018-12-12T15:52:07Z", "aliases": [ "CVE-2018-20060" @@ -58,35 +58,11 @@ }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2019:2272" + "url": "https://usn.ubuntu.com/3990-1" }, { "type": "WEB", - "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1649153" - }, - { - "type": "WEB", - "url": "https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2018-32.yaml" - }, - { - "type": "PACKAGE", - "url": "https://github.com/urllib3/urllib3" - }, - { - "type": "WEB", - "url": "https://github.com/urllib3/urllib3/blob/master/CHANGES.rst" - }, - { - "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2021/06/msg00015.html" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5SJERZEJDSUYQP7BNBXMBHRHGY26HRZD" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BXLAXHM3Z6DUCXZ7ZXZ2EAYJXWDCZFCT" + "url": "https://security.netapp.com/advisory/ntap-20241227-0010" }, { "type": "WEB", @@ -94,7 +70,47 @@ }, { "type": "WEB", - "url": "https://usn.ubuntu.com/3990-1" + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BXLAXHM3Z6DUCXZ7ZXZ2EAYJXWDCZFCT" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5SJERZEJDSUYQP7BNBXMBHRHGY26HRZD" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWP36YW3KSVLXDBY3QJKDYEPCIMN3VQZ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BXLAXHM3Z6DUCXZ7ZXZ2EAYJXWDCZFCT" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5SJERZEJDSUYQP7BNBXMBHRHGY26HRZD" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2021/06/msg00015.html" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/blob/master/CHANGES.rst" + }, + { + "type": "PACKAGE", + "url": "https://github.com/urllib3/urllib3" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2018-32.yaml" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1649153" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2019:2272" }, { "type": "WEB", diff --git a/advisories/github-reviewed/2024/08/GHSA-r55c-59qm-vjw6/GHSA-r55c-59qm-vjw6.json b/advisories/github-reviewed/2024/08/GHSA-r55c-59qm-vjw6/GHSA-r55c-59qm-vjw6.json index f01b9b0655d..d30950c750b 100644 --- a/advisories/github-reviewed/2024/08/GHSA-r55c-59qm-vjw6/GHSA-r55c-59qm-vjw6.json +++ b/advisories/github-reviewed/2024/08/GHSA-r55c-59qm-vjw6/GHSA-r55c-59qm-vjw6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r55c-59qm-vjw6", - "modified": "2024-09-05T18:38:26Z", + "modified": "2024-12-27T18:30:26Z", "published": "2024-08-01T22:05:10Z", "aliases": [ "CVE-2024-41123" @@ -64,6 +64,10 @@ "type": "WEB", "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rexml/CVE-2024-41123.yml" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241227-0005" + }, { "type": "WEB", "url": "https://www.ruby-lang.org/en/news/2024/08/01/dos-rexml-cve-2024-41123" diff --git a/advisories/github-reviewed/2024/08/GHSA-rpcc-p8xm-rc6p/GHSA-rpcc-p8xm-rc6p.json b/advisories/github-reviewed/2024/08/GHSA-rpcc-p8xm-rc6p/GHSA-rpcc-p8xm-rc6p.json index 8bf1cec8554..f8450ee4890 100644 --- a/advisories/github-reviewed/2024/08/GHSA-rpcc-p8xm-rc6p/GHSA-rpcc-p8xm-rc6p.json +++ b/advisories/github-reviewed/2024/08/GHSA-rpcc-p8xm-rc6p/GHSA-rpcc-p8xm-rc6p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rpcc-p8xm-rc6p", - "modified": "2024-10-16T17:05:02Z", + "modified": "2024-12-27T18:30:26Z", "published": "2024-08-02T21:31:34Z", "aliases": [ "CVE-2024-3056" @@ -135,6 +135,10 @@ { "type": "WEB", "url": "https://pkg.go.dev/vuln/GO-2024-3042" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241227-0002" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/09/GHSA-cx7f-g6mp-7hqm/GHSA-cx7f-g6mp-7hqm.json b/advisories/github-reviewed/2024/09/GHSA-cx7f-g6mp-7hqm/GHSA-cx7f-g6mp-7hqm.json index df52f61cd07..fc6b90ce25f 100644 --- a/advisories/github-reviewed/2024/09/GHSA-cx7f-g6mp-7hqm/GHSA-cx7f-g6mp-7hqm.json +++ b/advisories/github-reviewed/2024/09/GHSA-cx7f-g6mp-7hqm/GHSA-cx7f-g6mp-7hqm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cx7f-g6mp-7hqm", - "modified": "2024-12-10T19:47:12Z", + "modified": "2024-12-27T18:30:26Z", "published": "2024-09-13T06:30:42Z", "aliases": [ "CVE-2024-38816" @@ -143,6 +143,10 @@ "type": "PACKAGE", "url": "https://github.com/spring-projects/spring-framework" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241227-0001" + }, { "type": "WEB", "url": "https://spring.io/security/cve-2024-38816" diff --git a/advisories/github-reviewed/2024/10/GHSA-2rxp-v6pw-ch6m/GHSA-2rxp-v6pw-ch6m.json b/advisories/github-reviewed/2024/10/GHSA-2rxp-v6pw-ch6m/GHSA-2rxp-v6pw-ch6m.json index 81abdc6b4c2..5138205f748 100644 --- a/advisories/github-reviewed/2024/10/GHSA-2rxp-v6pw-ch6m/GHSA-2rxp-v6pw-ch6m.json +++ b/advisories/github-reviewed/2024/10/GHSA-2rxp-v6pw-ch6m/GHSA-2rxp-v6pw-ch6m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2rxp-v6pw-ch6m", - "modified": "2024-10-29T14:59:27Z", + "modified": "2024-12-27T18:30:26Z", "published": "2024-10-28T14:10:18Z", "aliases": [ "CVE-2024-49761" @@ -60,6 +60,10 @@ "type": "WEB", "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rexml/CVE-2024-49761.yml" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241227-0004" + }, { "type": "WEB", "url": "https://www.ruby-lang.org/en/news/2024/10/28/redos-rexml-cve-2024-49761" diff --git a/advisories/github-reviewed/2024/10/GHSA-434g-2637-qmqr/GHSA-434g-2637-qmqr.json b/advisories/github-reviewed/2024/10/GHSA-434g-2637-qmqr/GHSA-434g-2637-qmqr.json index 48fd90fb8ae..0735a7c2aa3 100644 --- a/advisories/github-reviewed/2024/10/GHSA-434g-2637-qmqr/GHSA-434g-2637-qmqr.json +++ b/advisories/github-reviewed/2024/10/GHSA-434g-2637-qmqr/GHSA-434g-2637-qmqr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-434g-2637-qmqr", - "modified": "2024-10-15T17:14:02Z", + "modified": "2024-12-27T18:30:26Z", "published": "2024-10-10T03:30:44Z", "aliases": [ "CVE-2024-48949" @@ -55,6 +55,10 @@ { "type": "WEB", "url": "https://github.com/indutny/elliptic/compare/v6.5.5...v6.5.6" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241227-0003" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/01/GHSA-jh7h-6j93-vqwx/GHSA-jh7h-6j93-vqwx.json b/advisories/unreviewed/2022/01/GHSA-jh7h-6j93-vqwx/GHSA-jh7h-6j93-vqwx.json index 9047cb3d3a5..b430d4e9bf7 100644 --- a/advisories/unreviewed/2022/01/GHSA-jh7h-6j93-vqwx/GHSA-jh7h-6j93-vqwx.json +++ b/advisories/unreviewed/2022/01/GHSA-jh7h-6j93-vqwx/GHSA-jh7h-6j93-vqwx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jh7h-6j93-vqwx", - "modified": "2022-01-28T00:03:35Z", + "modified": "2024-12-27T18:30:25Z", "published": "2022-01-22T00:00:42Z", "aliases": [ "CVE-2021-46200" ], "details": "An SQL Injection vulnerability exists in Sourcecodester Simple Music Clour Community System 1.0 via the email parameter in /music/ajax.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-2p2c-vwq7-7vg6/GHSA-2p2c-vwq7-7vg6.json b/advisories/unreviewed/2022/05/GHSA-2p2c-vwq7-7vg6/GHSA-2p2c-vwq7-7vg6.json index 3f120aba4bf..c2f57afb332 100644 --- a/advisories/unreviewed/2022/05/GHSA-2p2c-vwq7-7vg6/GHSA-2p2c-vwq7-7vg6.json +++ b/advisories/unreviewed/2022/05/GHSA-2p2c-vwq7-7vg6/GHSA-2p2c-vwq7-7vg6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2p2c-vwq7-7vg6", - "modified": "2022-05-13T01:27:48Z", + "modified": "2024-12-27T18:30:25Z", "published": "2022-05-13T01:27:48Z", "aliases": [ "CVE-2018-12121" @@ -39,6 +39,10 @@ "type": "WEB", "url": "https://security.gentoo.org/glsa/202003-48" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241227-0008" + }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/106043" diff --git a/advisories/unreviewed/2022/05/GHSA-cr4g-c387-95hx/GHSA-cr4g-c387-95hx.json b/advisories/unreviewed/2022/05/GHSA-cr4g-c387-95hx/GHSA-cr4g-c387-95hx.json index a06d1cc980a..33307d01a4f 100644 --- a/advisories/unreviewed/2022/05/GHSA-cr4g-c387-95hx/GHSA-cr4g-c387-95hx.json +++ b/advisories/unreviewed/2022/05/GHSA-cr4g-c387-95hx/GHSA-cr4g-c387-95hx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cr4g-c387-95hx", - "modified": "2022-05-24T17:34:25Z", + "modified": "2024-12-27T18:30:25Z", "published": "2022-05-24T17:34:25Z", "aliases": [ "CVE-2020-24723" ], "details": "Cross Site Scripting (XSS) vulnerability in the Registration page of the admin panel in PHPGurukul User Registration & Login and User Management System With admin panel 2.1.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-f39p-m8r2-p6f6/GHSA-f39p-m8r2-p6f6.json b/advisories/unreviewed/2022/05/GHSA-f39p-m8r2-p6f6/GHSA-f39p-m8r2-p6f6.json index 8509a373651..24545e19c03 100644 --- a/advisories/unreviewed/2022/05/GHSA-f39p-m8r2-p6f6/GHSA-f39p-m8r2-p6f6.json +++ b/advisories/unreviewed/2022/05/GHSA-f39p-m8r2-p6f6/GHSA-f39p-m8r2-p6f6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f39p-m8r2-p6f6", - "modified": "2022-05-17T02:14:13Z", + "modified": "2024-12-27T18:30:25Z", "published": "2022-05-17T02:14:13Z", "aliases": [ "CVE-2017-12588" @@ -30,6 +30,10 @@ { "type": "WEB", "url": "https://github.com/rsyslog/rsyslog/blob/master/ChangeLog" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241227-0009" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-q23g-5crp-275m/GHSA-q23g-5crp-275m.json b/advisories/unreviewed/2022/05/GHSA-q23g-5crp-275m/GHSA-q23g-5crp-275m.json index 5989bd93553..a5affb3893f 100644 --- a/advisories/unreviewed/2022/05/GHSA-q23g-5crp-275m/GHSA-q23g-5crp-275m.json +++ b/advisories/unreviewed/2022/05/GHSA-q23g-5crp-275m/GHSA-q23g-5crp-275m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q23g-5crp-275m", - "modified": "2022-05-24T17:34:16Z", + "modified": "2024-12-27T18:30:25Z", "published": "2022-05-24T17:34:16Z", "aliases": [ "CVE-2020-25952" ], "details": "SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System With admin panel 2.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-wrc8-jp87-rq8j/GHSA-wrc8-jp87-rq8j.json b/advisories/unreviewed/2022/05/GHSA-wrc8-jp87-rq8j/GHSA-wrc8-jp87-rq8j.json index b1fd562861e..e33e2b44ff2 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrc8-jp87-rq8j/GHSA-wrc8-jp87-rq8j.json +++ b/advisories/unreviewed/2022/05/GHSA-wrc8-jp87-rq8j/GHSA-wrc8-jp87-rq8j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wrc8-jp87-rq8j", - "modified": "2022-05-14T01:09:55Z", + "modified": "2024-12-27T18:30:25Z", "published": "2022-05-14T01:09:55Z", "aliases": [ "CVE-2017-8923" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://bugs.php.net/bug.php?id=74577" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241227-0007" + }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/98518" diff --git a/advisories/unreviewed/2024/02/GHSA-7gq6-cq6r-rrpx/GHSA-7gq6-cq6r-rrpx.json b/advisories/unreviewed/2024/02/GHSA-7gq6-cq6r-rrpx/GHSA-7gq6-cq6r-rrpx.json index 4a6a64b47b5..02d5415dcc5 100644 --- a/advisories/unreviewed/2024/02/GHSA-7gq6-cq6r-rrpx/GHSA-7gq6-cq6r-rrpx.json +++ b/advisories/unreviewed/2024/02/GHSA-7gq6-cq6r-rrpx/GHSA-7gq6-cq6r-rrpx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7gq6-cq6r-rrpx", - "modified": "2024-06-27T12:30:43Z", + "modified": "2024-12-27T18:30:25Z", "published": "2024-02-20T21:30:26Z", "aliases": [ "CVE-2023-52439" @@ -58,6 +58,10 @@ { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241227-0006" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-gp33-9vvc-fgq2/GHSA-gp33-9vvc-fgq2.json b/advisories/unreviewed/2024/02/GHSA-gp33-9vvc-fgq2/GHSA-gp33-9vvc-fgq2.json index 91a0d6f9464..e41cc85d95a 100644 --- a/advisories/unreviewed/2024/02/GHSA-gp33-9vvc-fgq2/GHSA-gp33-9vvc-fgq2.json +++ b/advisories/unreviewed/2024/02/GHSA-gp33-9vvc-fgq2/GHSA-gp33-9vvc-fgq2.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-hc38-9v2x-99qg/GHSA-hc38-9v2x-99qg.json b/advisories/unreviewed/2024/02/GHSA-hc38-9v2x-99qg/GHSA-hc38-9v2x-99qg.json index c6544edf7c9..1dcc2a4e9cc 100644 --- a/advisories/unreviewed/2024/02/GHSA-hc38-9v2x-99qg/GHSA-hc38-9v2x-99qg.json +++ b/advisories/unreviewed/2024/02/GHSA-hc38-9v2x-99qg/GHSA-hc38-9v2x-99qg.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-j9vj-p8vp-6j8q/GHSA-j9vj-p8vp-6j8q.json b/advisories/unreviewed/2024/02/GHSA-j9vj-p8vp-6j8q/GHSA-j9vj-p8vp-6j8q.json index b2e867e8892..bdaae64fa66 100644 --- a/advisories/unreviewed/2024/02/GHSA-j9vj-p8vp-6j8q/GHSA-j9vj-p8vp-6j8q.json +++ b/advisories/unreviewed/2024/02/GHSA-j9vj-p8vp-6j8q/GHSA-j9vj-p8vp-6j8q.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-mcf7-8x34-3jf9/GHSA-mcf7-8x34-3jf9.json b/advisories/unreviewed/2024/02/GHSA-mcf7-8x34-3jf9/GHSA-mcf7-8x34-3jf9.json index 6f860c39e83..70260fdfe71 100644 --- a/advisories/unreviewed/2024/02/GHSA-mcf7-8x34-3jf9/GHSA-mcf7-8x34-3jf9.json +++ b/advisories/unreviewed/2024/02/GHSA-mcf7-8x34-3jf9/GHSA-mcf7-8x34-3jf9.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-pg9v-m7q9-3r6p/GHSA-pg9v-m7q9-3r6p.json b/advisories/unreviewed/2024/02/GHSA-pg9v-m7q9-3r6p/GHSA-pg9v-m7q9-3r6p.json index ea3ac7c23cb..d0f2cabf43e 100644 --- a/advisories/unreviewed/2024/02/GHSA-pg9v-m7q9-3r6p/GHSA-pg9v-m7q9-3r6p.json +++ b/advisories/unreviewed/2024/02/GHSA-pg9v-m7q9-3r6p/GHSA-pg9v-m7q9-3r6p.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-rmjj-8r22-rwhv/GHSA-rmjj-8r22-rwhv.json b/advisories/unreviewed/2024/02/GHSA-rmjj-8r22-rwhv/GHSA-rmjj-8r22-rwhv.json index e16d4b2d9c4..67dd3086cc8 100644 --- a/advisories/unreviewed/2024/02/GHSA-rmjj-8r22-rwhv/GHSA-rmjj-8r22-rwhv.json +++ b/advisories/unreviewed/2024/02/GHSA-rmjj-8r22-rwhv/GHSA-rmjj-8r22-rwhv.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-6m8c-mx2x-w4pf/GHSA-6m8c-mx2x-w4pf.json b/advisories/unreviewed/2024/03/GHSA-6m8c-mx2x-w4pf/GHSA-6m8c-mx2x-w4pf.json index e818ce3a41e..d1d4b5d5295 100644 --- a/advisories/unreviewed/2024/03/GHSA-6m8c-mx2x-w4pf/GHSA-6m8c-mx2x-w4pf.json +++ b/advisories/unreviewed/2024/03/GHSA-6m8c-mx2x-w4pf/GHSA-6m8c-mx2x-w4pf.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-m74x-wfqr-f768/GHSA-m74x-wfqr-f768.json b/advisories/unreviewed/2024/03/GHSA-m74x-wfqr-f768/GHSA-m74x-wfqr-f768.json index a401f01795e..a70c00a6df6 100644 --- a/advisories/unreviewed/2024/03/GHSA-m74x-wfqr-f768/GHSA-m74x-wfqr-f768.json +++ b/advisories/unreviewed/2024/03/GHSA-m74x-wfqr-f768/GHSA-m74x-wfqr-f768.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-416" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/03/GHSA-x2qr-244g-56q9/GHSA-x2qr-244g-56q9.json b/advisories/unreviewed/2024/03/GHSA-x2qr-244g-56q9/GHSA-x2qr-244g-56q9.json index fbaaec732d3..dbccd9db157 100644 --- a/advisories/unreviewed/2024/03/GHSA-x2qr-244g-56q9/GHSA-x2qr-244g-56q9.json +++ b/advisories/unreviewed/2024/03/GHSA-x2qr-244g-56q9/GHSA-x2qr-244g-56q9.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-415" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/12/GHSA-3gp8-m3mx-fm5q/GHSA-3gp8-m3mx-fm5q.json b/advisories/unreviewed/2024/12/GHSA-3gp8-m3mx-fm5q/GHSA-3gp8-m3mx-fm5q.json new file mode 100644 index 00000000000..190adc584fb --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3gp8-m3mx-fm5q/GHSA-3gp8-m3mx-fm5q.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gp8-m3mx-fm5q", + "modified": "2024-12-27T18:30:26Z", + "published": "2024-12-27T18:30:26Z", + "aliases": [ + "CVE-2024-12986" + ], + "details": "A vulnerability, which was classified as critical, has been found in DrayTek Vigor2960 and Vigor300B 1.5.1.3/1.5.1.4. This issue affects some unknown processing of the file /cgi-bin/mainfunction.cgi/apmcfgupptim of the component Web Management Interface. The manipulation of the argument session leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.1.5 is able to address this issue. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12986" + }, + { + "type": "WEB", + "url": "https://netsecfish.notion.site/Command-Injection-in-apmcfgupptim-endpoint-for-DrayTek-Gateway-Devices-1676b683e67c80b9ad8cc37b93273bf6?pvs=4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289379" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289379" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.468794" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3mp3-6fg3-7hxj/GHSA-3mp3-6fg3-7hxj.json b/advisories/unreviewed/2024/12/GHSA-3mp3-6fg3-7hxj/GHSA-3mp3-6fg3-7hxj.json new file mode 100644 index 00000000000..cd7d4aca2a4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3mp3-6fg3-7hxj/GHSA-3mp3-6fg3-7hxj.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3mp3-6fg3-7hxj", + "modified": "2024-12-27T18:30:26Z", + "published": "2024-12-27T18:30:26Z", + "aliases": [ + "CVE-2024-12987" + ], + "details": "A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. The manipulation of the argument session leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.1.5 is able to address this issue. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12987" + }, + { + "type": "WEB", + "url": "https://netsecfish.notion.site/Command-Injection-in-apmcfgupload-endpoint-for-DrayTek-Gateway-Devices-1676b683e67c8040b7f1f0ffe29ce18f?pvs=4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289380" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289380" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.468795" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5qv9-wh8x-pfpm/GHSA-5qv9-wh8x-pfpm.json b/advisories/unreviewed/2024/12/GHSA-5qv9-wh8x-pfpm/GHSA-5qv9-wh8x-pfpm.json new file mode 100644 index 00000000000..e6d016619b8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5qv9-wh8x-pfpm/GHSA-5qv9-wh8x-pfpm.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qv9-wh8x-pfpm", + "modified": "2024-12-27T18:30:26Z", + "published": "2024-12-27T18:30:26Z", + "aliases": [ + "CVE-2024-12856" + ], + "details": "The Four-Faith router models F3x24 and F3x36 are affected by an operating system (OS) command injection vulnerability. At least firmware version 2.0 allows authenticated and remote attackers to execute arbitrary OS commands over HTTP when modifying the system time via apply.cgi. Additionally, this firmware version has default credentials which, if not changed, would effectively change this vulnerability into an unauthenticated and remote OS command execution issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12856" + }, + { + "type": "WEB", + "url": "https://ducklingstudio.blog.fc2.com/blog-entry-392.html" + }, + { + "type": "WEB", + "url": "https://vulncheck.com/advisories/four-faith-time" + }, + { + "type": "WEB", + "url": "https://vulncheck.com/blog/four-faith-cve-2024-12856" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-67qp-qff2-ggpp/GHSA-67qp-qff2-ggpp.json b/advisories/unreviewed/2024/12/GHSA-67qp-qff2-ggpp/GHSA-67qp-qff2-ggpp.json new file mode 100644 index 00000000000..9e7f51d562f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-67qp-qff2-ggpp/GHSA-67qp-qff2-ggpp.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67qp-qff2-ggpp", + "modified": "2024-12-27T18:30:26Z", + "published": "2024-12-27T18:30:26Z", + "aliases": [ + "CVE-2024-12989" + ], + "details": "A vulnerability was found in WISI Tangram GT31 up to 20241214 and classified as problematic. Affected by this issue is some unknown functionality of the component HTTP Request Handler. The manipulation leads to server-side request forgery. The attack may be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12989" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289382" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289382" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.463798" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9jgq-4mjq-qcc9/GHSA-9jgq-4mjq-qcc9.json b/advisories/unreviewed/2024/12/GHSA-9jgq-4mjq-qcc9/GHSA-9jgq-4mjq-qcc9.json new file mode 100644 index 00000000000..58ea4cee09d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9jgq-4mjq-qcc9/GHSA-9jgq-4mjq-qcc9.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9jgq-4mjq-qcc9", + "modified": "2024-12-27T18:30:26Z", + "published": "2024-12-27T18:30:26Z", + "aliases": [ + "CVE-2024-12988" + ], + "details": "A vulnerability has been found in Netgear R6900P and R7000P 1.3.3.154 and classified as critical. Affected by this vulnerability is the function sub_16C4C of the component HTTP Header Handler. The manipulation of the argument Host leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12988" + }, + { + "type": "WEB", + "url": "https://github.com/physicszq/Routers/tree/main/Netgear/1.3.3.154" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289381" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289381" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.462781" + }, + { + "type": "WEB", + "url": "https://www.netgear.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w8vp-q672-4hxv/GHSA-w8vp-q672-4hxv.json b/advisories/unreviewed/2024/12/GHSA-w8vp-q672-4hxv/GHSA-w8vp-q672-4hxv.json new file mode 100644 index 00000000000..e66c035f40f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w8vp-q672-4hxv/GHSA-w8vp-q672-4hxv.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8vp-q672-4hxv", + "modified": "2024-12-27T18:30:26Z", + "published": "2024-12-27T18:30:26Z", + "aliases": [ + "CVE-2024-12990" + ], + "details": "A vulnerability was found in ruifang-tech Rebuild 3.8.6. It has been classified as problematic. This affects an unknown part of the file /user/admin-verify of the component Admin Verification Page. The manipulation of the argument nexturl with the input http://localhost/evil.html leads to open redirect. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12990" + }, + { + "type": "WEB", + "url": "https://github.com/cydtseng/Vulnerability-Research/blob/main/rebuild/OpenRedirect-AdminVerification.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289383" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289383" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.464029" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T18:15:25Z" + } +} \ No newline at end of file