diff --git a/advisories/unreviewed/2024/03/GHSA-2cw3-g6hp-3xj8/GHSA-2cw3-g6hp-3xj8.json b/advisories/unreviewed/2024/03/GHSA-2cw3-g6hp-3xj8/GHSA-2cw3-g6hp-3xj8.json new file mode 100644 index 00000000000..e573dcd1ac1 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-2cw3-g6hp-3xj8/GHSA-2cw3-g6hp-3xj8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cw3-g6hp-3xj8", + "modified": "2024-03-21T15:31:54Z", + "published": "2024-03-21T15:31:54Z", + "aliases": [ + "CVE-2024-29880" + ], + "details": "In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent process", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29880" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-749" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-2vwx-x49m-q6hr/GHSA-2vwx-x49m-q6hr.json b/advisories/unreviewed/2024/03/GHSA-2vwx-x49m-q6hr/GHSA-2vwx-x49m-q6hr.json new file mode 100644 index 00000000000..72d621bf8ae --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-2vwx-x49m-q6hr/GHSA-2vwx-x49m-q6hr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2vwx-x49m-q6hr", + "modified": "2024-03-21T15:31:54Z", + "published": "2024-03-21T15:31:54Z", + "aliases": [ + "CVE-2024-29878" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/sitepreference/add, 'description' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29878" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-sentrifugo" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-329g-rg28-m8qv/GHSA-329g-rg28-m8qv.json b/advisories/unreviewed/2024/03/GHSA-329g-rg28-m8qv/GHSA-329g-rg28-m8qv.json new file mode 100644 index 00000000000..9fd448d032a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-329g-rg28-m8qv/GHSA-329g-rg28-m8qv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-329g-rg28-m8qv", + "modified": "2024-03-21T15:31:55Z", + "published": "2024-03-21T15:31:55Z", + "aliases": [ + "CVE-2024-27995" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Repute Infosystems ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup allows Stored XSS.This issue affects ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup: from n/a through 4.0.23.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27995" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/armember-membership/wordpress-armember-plugin-4-0-23-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T15:16:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-3525-gmp6-g5m5/GHSA-3525-gmp6-g5m5.json b/advisories/unreviewed/2024/03/GHSA-3525-gmp6-g5m5/GHSA-3525-gmp6-g5m5.json new file mode 100644 index 00000000000..6a8dea779d3 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-3525-gmp6-g5m5/GHSA-3525-gmp6-g5m5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3525-gmp6-g5m5", + "modified": "2024-03-21T15:31:52Z", + "published": "2024-03-21T15:31:52Z", + "aliases": [ + "CVE-2024-29874" + ], + "details": "SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/default/reports/activeuserrptpdf, 'sort_name' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29874" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-sentrifugo" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-44mc-ggjv-3xj6/GHSA-44mc-ggjv-3xj6.json b/advisories/unreviewed/2024/03/GHSA-44mc-ggjv-3xj6/GHSA-44mc-ggjv-3xj6.json new file mode 100644 index 00000000000..608e9a0907f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-44mc-ggjv-3xj6/GHSA-44mc-ggjv-3xj6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44mc-ggjv-3xj6", + "modified": "2024-03-21T15:31:52Z", + "published": "2024-03-21T15:31:52Z", + "aliases": [ + "CVE-2024-29875" + ], + "details": "SQL injection vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/default/reports/exportactiveuserrpt, 'sort_name' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29875" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-sentrifugo" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-49fx-mg36-mm4r/GHSA-49fx-mg36-mm4r.json b/advisories/unreviewed/2024/03/GHSA-49fx-mg36-mm4r/GHSA-49fx-mg36-mm4r.json new file mode 100644 index 00000000000..32c56ccc9b2 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-49fx-mg36-mm4r/GHSA-49fx-mg36-mm4r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49fx-mg36-mm4r", + "modified": "2024-03-21T15:31:55Z", + "published": "2024-03-21T15:31:55Z", + "aliases": [ + "CVE-2024-27994" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YITH YITH WooCommerce Product Add-Ons allows Reflected XSS.This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.5.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27994" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/yith-woocommerce-product-add-ons/wordpress-yith-woocommerce-product-add-ons-plugin-4-5-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T15:16:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-4pmx-x3px-qgrr/GHSA-4pmx-x3px-qgrr.json b/advisories/unreviewed/2024/03/GHSA-4pmx-x3px-qgrr/GHSA-4pmx-x3px-qgrr.json new file mode 100644 index 00000000000..70d50828cf3 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-4pmx-x3px-qgrr/GHSA-4pmx-x3px-qgrr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pmx-x3px-qgrr", + "modified": "2024-03-21T15:31:54Z", + "published": "2024-03-21T15:31:54Z", + "aliases": [ + "CVE-2023-47715" + ], + "details": "IBM Storage Protect Plus Server 10.1.0 through 10.1.16 could allow an authenticated user with read-only permissions to add or delete entries from an existing HyperVisor configuration. IBM X-Force ID: 271538.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47715" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/271538" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7144861" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-5444-vc88-hfjh/GHSA-5444-vc88-hfjh.json b/advisories/unreviewed/2024/03/GHSA-5444-vc88-hfjh/GHSA-5444-vc88-hfjh.json new file mode 100644 index 00000000000..8e937388da8 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-5444-vc88-hfjh/GHSA-5444-vc88-hfjh.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5444-vc88-hfjh", + "modified": "2024-03-21T15:31:55Z", + "published": "2024-03-21T15:31:55Z", + "aliases": [ + "CVE-2024-2463" + ], + "details": "Weak password recovery mechanism in CDeX application allows to retrieve password reset token.This issue affects CDeX application versions through 5.7.1.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2463" + }, + { + "type": "WEB", + "url": "https://cdex.cloud" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/03/CVE-2024-2463" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2024/03/CVE-2024-2463" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-640" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T15:16:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-6243-94gq-j27f/GHSA-6243-94gq-j27f.json b/advisories/unreviewed/2024/03/GHSA-6243-94gq-j27f/GHSA-6243-94gq-j27f.json new file mode 100644 index 00000000000..ed049f7465b --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-6243-94gq-j27f/GHSA-6243-94gq-j27f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6243-94gq-j27f", + "modified": "2024-03-21T15:31:55Z", + "published": "2024-03-21T15:31:55Z", + "aliases": [ + "CVE-2024-27993" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Typps Calendarista Basic Edition.This issue affects Calendarista Basic Edition: from n/a through 3.0.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27993" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/calendarista-basic-edition/wordpress-calendarista-basic-edition-plugin-3-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T15:16:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-6qxg-84xw-6m8w/GHSA-6qxg-84xw-6m8w.json b/advisories/unreviewed/2024/03/GHSA-6qxg-84xw-6m8w/GHSA-6qxg-84xw-6m8w.json new file mode 100644 index 00000000000..100c9d23d82 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-6qxg-84xw-6m8w/GHSA-6qxg-84xw-6m8w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6qxg-84xw-6m8w", + "modified": "2024-03-21T15:31:54Z", + "published": "2024-03-21T15:31:54Z", + "aliases": [ + "CVE-2024-29879" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29879" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-sentrifugo" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-7359-w9jh-qr2r/GHSA-7359-w9jh-qr2r.json b/advisories/unreviewed/2024/03/GHSA-7359-w9jh-qr2r/GHSA-7359-w9jh-qr2r.json new file mode 100644 index 00000000000..d7ad85b50d3 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-7359-w9jh-qr2r/GHSA-7359-w9jh-qr2r.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7359-w9jh-qr2r", + "modified": "2024-03-21T15:31:55Z", + "published": "2024-03-21T15:31:55Z", + "aliases": [ + "CVE-2024-2465" + ], + "details": "Open redirection vulnerability in CDeX application allows to redirect users to arbitrary websites via a specially crafted URL.This issue affects CDeX application versions through 5.7.1.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2465" + }, + { + "type": "WEB", + "url": "https://cdex.cloud" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/03/CVE-2024-2463" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2024/03/CVE-2024-2463" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T15:16:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-7cgx-cf5v-j5v2/GHSA-7cgx-cf5v-j5v2.json b/advisories/unreviewed/2024/03/GHSA-7cgx-cf5v-j5v2/GHSA-7cgx-cf5v-j5v2.json new file mode 100644 index 00000000000..6426f908892 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-7cgx-cf5v-j5v2/GHSA-7cgx-cf5v-j5v2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7cgx-cf5v-j5v2", + "modified": "2024-03-21T15:31:51Z", + "published": "2024-03-21T15:31:51Z", + "aliases": [ + "CVE-2024-29866" + ], + "details": "Datalust Seq before 2023.4.11151 and 2024 before 2024.1.11146 has Incorrect Access Control because a Project Owner or Organization Owner can escalate to System privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29866" + }, + { + "type": "WEB", + "url": "https://github.com/datalust/seq-tickets/issues/2127" + }, + { + "type": "WEB", + "url": "https://datalust.co" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-8x54-9cjv-7vch/GHSA-8x54-9cjv-7vch.json b/advisories/unreviewed/2024/03/GHSA-8x54-9cjv-7vch/GHSA-8x54-9cjv-7vch.json new file mode 100644 index 00000000000..f00ed8c0697 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-8x54-9cjv-7vch/GHSA-8x54-9cjv-7vch.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8x54-9cjv-7vch", + "modified": "2024-03-21T15:31:55Z", + "published": "2024-03-21T15:31:55Z", + "aliases": [ + "CVE-2024-2464" + ], + "details": "This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.This issue affects CDeX application versions through 5.7.1.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2464" + }, + { + "type": "WEB", + "url": "https://cdex.cloud" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/03/CVE-2024-2463" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2024/03/CVE-2024-2463" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-203" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T15:16:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-cxq6-hcg5-hcjv/GHSA-cxq6-hcg5-hcjv.json b/advisories/unreviewed/2024/03/GHSA-cxq6-hcg5-hcjv/GHSA-cxq6-hcg5-hcjv.json new file mode 100644 index 00000000000..c9a7a3d9154 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-cxq6-hcg5-hcjv/GHSA-cxq6-hcg5-hcjv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxq6-hcg5-hcjv", + "modified": "2024-03-21T15:31:52Z", + "published": "2024-03-21T15:31:52Z", + "aliases": [ + "CVE-2024-29873" + ], + "details": "SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/reports/businessunits/format/html, 'bunitname' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29873" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-sentrifugo" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-f64p-xgr6-r5f4/GHSA-f64p-xgr6-r5f4.json b/advisories/unreviewed/2024/03/GHSA-f64p-xgr6-r5f4/GHSA-f64p-xgr6-r5f4.json new file mode 100644 index 00000000000..7a241ab73c4 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-f64p-xgr6-r5f4/GHSA-f64p-xgr6-r5f4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f64p-xgr6-r5f4", + "modified": "2024-03-21T15:31:53Z", + "published": "2024-03-21T15:31:53Z", + "aliases": [ + "CVE-2024-29877" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/expenses/expensecategories/edit, 'expense_category_name' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29877" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-sentrifugo" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-frvc-6356-58xm/GHSA-frvc-6356-58xm.json b/advisories/unreviewed/2024/03/GHSA-frvc-6356-58xm/GHSA-frvc-6356-58xm.json new file mode 100644 index 00000000000..441ced1d26d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-frvc-6356-58xm/GHSA-frvc-6356-58xm.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frvc-6356-58xm", + "modified": "2024-03-21T15:31:51Z", + "published": "2024-03-21T15:31:51Z", + "aliases": [ + "CVE-2024-28834" + ], + "details": "A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to 512 bits, exposing a potential timing side-channel.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28834" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-28834" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2269228" + }, + { + "type": "WEB", + "url": "https://lists.gnupg.org/pipermail/gnutls-help/2024-March/004845.html" + }, + { + "type": "WEB", + "url": "https://people.redhat.com/~hkario/marvin" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-g7cx-2g6j-fpvq/GHSA-g7cx-2g6j-fpvq.json b/advisories/unreviewed/2024/03/GHSA-g7cx-2g6j-fpvq/GHSA-g7cx-2g6j-fpvq.json new file mode 100644 index 00000000000..ae5cfe5238a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-g7cx-2g6j-fpvq/GHSA-g7cx-2g6j-fpvq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7cx-2g6j-fpvq", + "modified": "2024-03-21T15:31:55Z", + "published": "2024-03-21T15:31:55Z", + "aliases": [ + "CVE-2024-29244" + ], + "details": "Shenzhen Libituo Technology Co., Ltd LBT-T300-mini v1.2.9 was discovered to contain a buffer overflow via the pin_code_3g parameter at /apply.cgi.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29244" + }, + { + "type": "WEB", + "url": "https://github.com/AdamRitz/lbtvul/blob/main/t300mini-2.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T15:16:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-h9fq-4hj4-g596/GHSA-h9fq-4hj4-g596.json b/advisories/unreviewed/2024/03/GHSA-h9fq-4hj4-g596/GHSA-h9fq-4hj4-g596.json new file mode 100644 index 00000000000..94ea809ef10 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-h9fq-4hj4-g596/GHSA-h9fq-4hj4-g596.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9fq-4hj4-g596", + "modified": "2024-03-21T15:31:54Z", + "published": "2024-03-21T15:31:54Z", + "aliases": [ + "CVE-2024-2494" + ], + "details": "A flaw was found in the RPC library APIs of libvirt. The RPC server deserialization code allocates memory for arrays before the non-negative length check is performed by the C API entry points. Passing a negative length to the g_new0 function results in a crash due to the negative length being treated as a huge positive number. This flaw allows a local, unprivileged user to perform a denial of service attack by causing the libvirt daemon to crash.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2494" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-2494" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2270115" + }, + { + "type": "WEB", + "url": "https://lists.libvirt.org/archives/list/devel@lists.libvirt.org/thread/BKRQXPLPC6B7FLHJXSBQYW7HNDEBW6RJ" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-789" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-j67q-hvmw-6m2r/GHSA-j67q-hvmw-6m2r.json b/advisories/unreviewed/2024/03/GHSA-j67q-hvmw-6m2r/GHSA-j67q-hvmw-6m2r.json new file mode 100644 index 00000000000..37c6326e19b --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-j67q-hvmw-6m2r/GHSA-j67q-hvmw-6m2r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j67q-hvmw-6m2r", + "modified": "2024-03-21T15:31:52Z", + "published": "2024-03-21T15:31:52Z", + "aliases": [ + "CVE-2024-29871" + ], + "details": "SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/sentrifugo/index.php/index/updatecontactnumber, 'id' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29871" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-sentrifugo" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-j95q-fjjg-wf7f/GHSA-j95q-fjjg-wf7f.json b/advisories/unreviewed/2024/03/GHSA-j95q-fjjg-wf7f/GHSA-j95q-fjjg-wf7f.json new file mode 100644 index 00000000000..bc7b5767275 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-j95q-fjjg-wf7f/GHSA-j95q-fjjg-wf7f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j95q-fjjg-wf7f", + "modified": "2024-03-21T15:31:52Z", + "published": "2024-03-21T15:31:52Z", + "aliases": [ + "CVE-2024-29870" + ], + "details": "SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter./sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29870" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-sentrifugo" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-mgmq-g3mf-5h3g/GHSA-mgmq-g3mf-5h3g.json b/advisories/unreviewed/2024/03/GHSA-mgmq-g3mf-5h3g/GHSA-mgmq-g3mf-5h3g.json new file mode 100644 index 00000000000..988d72faefb --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-mgmq-g3mf-5h3g/GHSA-mgmq-g3mf-5h3g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgmq-g3mf-5h3g", + "modified": "2024-03-21T15:31:52Z", + "published": "2024-03-21T15:31:52Z", + "aliases": [ + "CVE-2024-29872" + ], + "details": "SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/empscreening/add, 'agencyids' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29872" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-sentrifugo" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-p9m7-r75h-rrfp/GHSA-p9m7-r75h-rrfp.json b/advisories/unreviewed/2024/03/GHSA-p9m7-r75h-rrfp/GHSA-p9m7-r75h-rrfp.json new file mode 100644 index 00000000000..5607f61d016 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-p9m7-r75h-rrfp/GHSA-p9m7-r75h-rrfp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9m7-r75h-rrfp", + "modified": "2024-03-21T15:31:55Z", + "published": "2024-03-21T15:31:55Z", + "aliases": [ + "CVE-2024-29243" + ], + "details": "Shenzhen Libituo Technology Co., Ltd LBT-T300-mini v1.2.9 was discovered to contain a buffer overflow via the vpn_client_ip parameter at /apply.cgi.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29243" + }, + { + "type": "WEB", + "url": "https://github.com/AdamRitz/lbtvul/blob/main/t300mini-2.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T15:16:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-qqp2-2gr9-622w/GHSA-qqp2-2gr9-622w.json b/advisories/unreviewed/2024/03/GHSA-qqp2-2gr9-622w/GHSA-qqp2-2gr9-622w.json new file mode 100644 index 00000000000..7ccba7308b2 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-qqp2-2gr9-622w/GHSA-qqp2-2gr9-622w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qqp2-2gr9-622w", + "modified": "2024-03-21T15:31:53Z", + "published": "2024-03-21T15:31:53Z", + "aliases": [ + "CVE-2024-29876" + ], + "details": "SQL injection vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/reports/activitylogreport, 'sortby' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29876" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-sentrifugo" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T14:15:09Z" + } +} \ No newline at end of file