Publish Advisories

GHSA-wv85-vm3v-v274
GHSA-54pm-mxvc-pw27
GHSA-634r-qhgm-h5w5
GHSA-63gw-9jw7-v975
GHSA-6v56-9m73-2rm4
GHSA-8582-mjhv-rmrr
GHSA-8pxv-x6jq-5vw9
GHSA-8qw7-q76p-7f4h
GHSA-9gq7-p5w9-w899
GHSA-ccff-2f27-4w8g
GHSA-cwqg-24rf-cjwq
GHSA-fg59-j242-rcj9
GHSA-j6w5-3xwm-qv7j
GHSA-j73p-gc9r-3pf8
GHSA-m88w-qcr5-cq82
GHSA-p742-rf2c-hvf6
GHSA-q47p-v5rw-v574
GHSA-r6f4-5657-3fp7
GHSA-rghf-m847-v399
GHSA-rp56-x26j-363p
GHSA-vq4q-wfv6-qgq8
GHSA-x3r6-ccvq-cf5v
GHSA-xwcg-xmmg-hh8r
This commit is contained in:
advisory-database[bot]
2024-07-22 15:33:40 +00:00
parent 2cc5fa9a7a
commit 8f816d6eff
23 changed files with 728 additions and 3 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wv85-vm3v-v274",
"modified": "2023-11-09T18:34:55Z",
"modified": "2024-07-22T15:32:35Z",
"published": "2023-11-09T18:34:55Z",
"aliases": [
"CVE-2023-47610"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-54pm-mxvc-pw27",
"modified": "2024-07-22T15:32:42Z",
"published": "2024-07-22T15:32:42Z",
"aliases": [
"CVE-2024-41828"
],
"details": "In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41828"
},
{
"type": "WEB",
"url": "https://www.jetbrains.com/privacy-security/issues-fixed"
}
],
"database_specific": {
"cwe_ids": [
"CWE-208"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-22T15:15:05Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-634r-qhgm-h5w5",
"modified": "2024-07-22T15:32:40Z",
"published": "2024-07-22T15:32:40Z",
"aliases": [
"CVE-2024-41315"
],
"details": "TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41315"
},
{
"type": "WEB",
"url": "https://github.com/yanggao017/vuln/blob/main/TOTOLINK/A6000R/CI_4_apcli_do_enr_pin_wps/README.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-22T14:15:06Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-63gw-9jw7-v975",
"modified": "2024-07-22T15:32:42Z",
"published": "2024-07-22T15:32:42Z",
"aliases": [
"CVE-2024-41827"
],
"details": "In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41827"
},
{
"type": "WEB",
"url": "https://www.jetbrains.com/privacy-security/issues-fixed"
}
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-22T15:15:05Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6v56-9m73-2rm4",
"modified": "2024-07-22T15:32:40Z",
"published": "2024-07-22T15:32:40Z",
"aliases": [
"CVE-2024-39601"
],
"details": "A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base system (All versions < V1.4.0). Affected devices allow a remote authenticated user or an unauthenticated user with physical access to downgrade the firmware of the device. This could allow an attacker to downgrade the device to older versions with known vulnerabilities.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39601"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/html/ssa-071402.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-306"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-22T14:15:06Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8582-mjhv-rmrr",
"modified": "2024-07-22T15:32:41Z",
"published": "2024-07-22T15:32:41Z",
"aliases": [
"CVE-2024-21552"
],
"details": "All versions of `SuperAGI` are vulnerable to Arbitrary Code Execution due to unsafe use of the eval function. An attacker could induce the LLM output to exploit this vulnerability and gain arbitrary code execution on the SuperAGI application server.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21552"
},
{
"type": "WEB",
"url": "https://github.com/TransformerOptimus/SuperAGI/blob/9361f0491716e56bd0c0ae2f3b49da201a18c58c/superagi/agent/output_handler.py#L149"
},
{
"type": "WEB",
"url": "https://github.com/TransformerOptimus/SuperAGI/blob/9361f0491716e56bd0c0ae2f3b49da201a18c58c/superagi/agent/output_handler.py#L180"
}
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-22T15:15:02Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8pxv-x6jq-5vw9",
"modified": "2024-07-22T12:30:37Z",
"modified": "2024-07-22T15:32:39Z",
"published": "2024-07-22T12:30:37Z",
"aliases": [
"CVE-2024-38503"
@@ -21,6 +21,10 @@
{
"type": "WEB",
"url": "https://syncope.apache.org/security#cve-2024-38503-html-tags-can-be-injected-into-console-or-enduser"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/07/22/3"
}
],
"database_specific": {
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8qw7-q76p-7f4h",
"modified": "2024-07-22T15:32:42Z",
"published": "2024-07-22T15:32:42Z",
"aliases": [
"CVE-2024-41829"
],
"details": "In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41829"
},
{
"type": "WEB",
"url": "https://www.jetbrains.com/privacy-security/issues-fixed"
}
],
"database_specific": {
"cwe_ids": [
"CWE-303"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-22T15:15:05Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9gq7-p5w9-w899",
"modified": "2024-07-22T15:32:41Z",
"published": "2024-07-22T15:32:41Z",
"aliases": [
"CVE-2024-26020"
],
"details": "An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted flashcard can lead to a arbitrary code execution. An attacker can send malicious flashcard to trigger this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26020"
},
{
"type": "WEB",
"url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1993"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-22T15:15:02Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ccff-2f27-4w8g",
"modified": "2024-07-22T15:32:41Z",
"published": "2024-07-22T15:32:41Z",
"aliases": [
"CVE-2024-41318"
],
"details": "TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41318"
},
{
"type": "WEB",
"url": "https://github.com/yanggao017/vuln/blob/main/TOTOLINK/A6000R/CI_5_apcli_wps_gen_pincode/README.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-22T14:15:06Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cwqg-24rf-cjwq",
"modified": "2024-07-22T15:32:42Z",
"published": "2024-07-22T15:32:42Z",
"aliases": [
"CVE-2024-41826"
],
"details": "In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41826"
},
{
"type": "WEB",
"url": "https://www.jetbrains.com/privacy-security/issues-fixed"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-22T15:15:04Z"
}
}
@@ -32,6 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22",
"CWE-35"
],
"severity": "HIGH",
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j6w5-3xwm-qv7j",
"modified": "2024-07-22T15:32:40Z",
"published": "2024-07-22T15:32:40Z",
"aliases": [
"CVE-2024-41314"
],
"details": "TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41314"
},
{
"type": "WEB",
"url": "https://github.com/yanggao017/vuln/blob/main/TOTOLINK/A6000R/CI_1_vif_disable/README.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-22T14:15:06Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j73p-gc9r-3pf8",
"modified": "2024-07-22T12:30:36Z",
"modified": "2024-07-22T15:32:39Z",
"published": "2024-07-22T12:30:36Z",
"aliases": [
"CVE-2024-34457"
@@ -21,6 +21,10 @@
{
"type": "WEB",
"url": "https://lists.apache.org/thread/brlfrmvw9dcv38zoofmhxg7qookmwn7j"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/07/22/2"
}
],
"database_specific": {
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m88w-qcr5-cq82",
"modified": "2024-07-22T15:32:42Z",
"published": "2024-07-22T15:32:42Z",
"aliases": [
"CVE-2024-41824"
],
"details": "In JetBrains TeamCity before 2024.07 parameters of the \"password\" type could leak into the build log in some specific cases",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41824"
},
{
"type": "WEB",
"url": "https://www.jetbrains.com/privacy-security/issues-fixed"
}
],
"database_specific": {
"cwe_ids": [
"CWE-532"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-22T15:15:04Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p742-rf2c-hvf6",
"modified": "2024-07-22T15:32:40Z",
"published": "2024-07-22T15:32:40Z",
"aliases": [
"CVE-2024-41316"
],
"details": "TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41316"
},
{
"type": "WEB",
"url": "https://github.com/yanggao017/vuln/blob/main/TOTOLINK/A6000R/CI_2_apcli_cancel_wps/README.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-22T14:15:06Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q47p-v5rw-v574",
"modified": "2024-07-22T15:32:41Z",
"published": "2024-07-22T15:32:41Z",
"aliases": [
"CVE-2024-32152"
],
"details": "A blocklist bypass vulnerability exists in the LaTeX functionality of Ankitects Anki 24.04. A specially crafted malicious flashcard can lead to an arbitrary file creation at a fixed path. An attacker can share a malicious flashcard to trigger this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32152"
},
{
"type": "WEB",
"url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1994"
}
],
"database_specific": {
"cwe_ids": [
"CWE-184"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-22T15:15:03Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r6f4-5657-3fp7",
"modified": "2024-07-22T15:32:41Z",
"published": "2024-07-22T15:32:41Z",
"aliases": [
"CVE-2024-32484"
],
"details": "An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04. A specially crafted flashcard can lead to JavaScript code execution and result in an arbitrary file read. An attacker can share a malicious flashcard to trigger this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32484"
},
{
"type": "WEB",
"url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1995"
}
],
"database_specific": {
"cwe_ids": [
"CWE-80"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-22T15:15:03Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rghf-m847-v399",
"modified": "2024-07-22T15:32:41Z",
"published": "2024-07-22T15:32:41Z",
"aliases": [
"CVE-2024-41320"
],
"details": "TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the get_apcli_conn_info function.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41320"
},
{
"type": "WEB",
"url": "https://github.com/yanggao017/vuln/blob/main/TOTOLINK/A6000R/CI_6_get_apcli_conn_info/README.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-22T14:15:06Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rp56-x26j-363p",
"modified": "2024-07-22T15:32:40Z",
"published": "2024-07-22T15:32:40Z",
"aliases": [
"CVE-2024-37998"
],
"details": "A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base system (All versions < V1.4.0). The password of administrative accounts of the affected applications can be reset without requiring the knowledge of the current password, given the auto login is enabled. This could allow an unauthorized attacker to obtain administrative access of the affected applications.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37998"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/html/ssa-071402.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-620"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-22T14:15:05Z"
}
}

Some files were not shown because too many files have changed in this diff Show More