From 9099526b4efca4afad0de242a618296f28337702 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 26 Apr 2024 09:32:15 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-qppj-fm5r-hxr3.json | 260 +++++++++--------- .../GHSA-874v-pj72-92f3.json | 14 +- .../GHSA-x5m7-63c6-fx79.json | 6 +- .../GHSA-2gpj-6wgq-8636.json | 17 +- .../GHSA-5pqr-9wpj-5m82.json | 6 +- .../GHSA-5w8c-g2pj-65rx.json | 6 +- .../GHSA-9f7v-8m4p-pv76.json | 6 +- .../GHSA-2hcr-79rm-r8rp.json | 6 +- .../GHSA-8jhw-fpw9-r227.json | 6 +- .../GHSA-c9xj-rf55-c64g.json | 6 +- .../GHSA-rj8q-prqp-jwfg.json | 10 +- .../GHSA-697h-9h25-w4fm.json | 6 +- .../GHSA-v5qp-mx94-j49v.json | 6 +- .../GHSA-x57x-3c65-5f3j.json | 6 +- .../GHSA-26mf-52p6-23pq.json | 6 +- .../GHSA-273j-fjrx-gf2f.json | 6 +- .../GHSA-2mpf-fq5j-4hgp.json | 6 +- .../GHSA-3jpw-p5mr-c3q9.json | 6 +- .../GHSA-3q47-w545-wgfv.json | 46 ++++ .../GHSA-3v95-qw2c-cq5p.json | 38 +++ .../GHSA-3vx9-2ch5-m6r6.json | 6 +- .../GHSA-4cjh-m2w7-xg99.json | 10 +- .../GHSA-55g5-m7rx-jf99.json | 6 +- .../GHSA-5fh7-7mw7-mmx5.json | 38 +++ .../GHSA-5qx9-9ffj-5r8f.json | 38 +++ .../GHSA-5v68-73xh-wcgw.json | 6 +- .../GHSA-5wrr-m725-w8jw.json | 6 +- .../GHSA-5xq9-rcpj-p52v.json | 6 +- .../GHSA-63p9-g7fv-6cvr.json | 6 +- .../GHSA-6pwq-2vrc-6rr6.json | 6 +- .../GHSA-6qf6-cmc3-h6x2.json | 6 +- .../GHSA-7jxx-p3jr-r2x9.json | 6 +- .../GHSA-7pmg-vmj4-qjp4.json | 6 +- .../GHSA-7qqv-8pwc-x4xc.json | 6 +- .../GHSA-88h4-jw57-85v9.json | 6 +- .../GHSA-8cpf-fxr6-4wpq.json | 6 +- .../GHSA-8f99-g2pj-x8w3.json | 38 +++ .../GHSA-8x4w-7h9g-pg2q.json | 6 +- .../GHSA-975v-wj6r-fgj8.json | 6 +- .../GHSA-9cw3-8wpf-rpmg.json | 6 +- .../GHSA-9x55-44vc-363x.json | 38 +++ .../GHSA-ccmh-gwpx-35xj.json | 6 +- .../GHSA-g3wm-f7gr-3fwh.json | 6 +- .../GHSA-gj63-qcjc-2fcw.json | 6 +- .../GHSA-hcf3-w2q6-29cf.json | 42 +++ .../GHSA-hcm7-xw9m-99cx.json | 6 +- .../GHSA-hqqq-4jv4-jmj5.json | 46 ++++ .../GHSA-hv7f-m7x4-mc78.json | 6 +- .../GHSA-j2hp-jqgm-85pf.json | 38 +++ .../GHSA-jfv3-gh3j-c5r7.json | 6 +- .../GHSA-jmgx-64x4-v838.json | 6 +- .../GHSA-p2wq-4ggp-45f3.json | 38 +++ .../GHSA-pfc3-5g8j-v982.json | 38 +++ .../GHSA-pj4r-r8f8-qmcc.json | 38 +++ .../GHSA-pprv-m73j-58qg.json | 42 +++ .../GHSA-q4c6-w389-xqq6.json | 6 +- .../GHSA-q4p9-39fv-h479.json | 38 +++ .../GHSA-r27r-5fwh-vxqw.json | 6 +- .../GHSA-r345-8c48-x279.json | 6 +- .../GHSA-r5cc-f7pr-5v73.json | 6 +- .../GHSA-v98m-62r5-hvcm.json | 6 +- .../GHSA-vx97-8q8q-qgq5.json | 38 +++ .../GHSA-w8q4-gvf3-wvfq.json | 38 +++ .../GHSA-wg7v-w4x5-xvmx.json | 6 +- .../GHSA-wh99-p93p-g825.json | 6 +- .../GHSA-wj37-mpq9-xrcm.json | 38 +++ .../GHSA-x78r-qrp5-rmmf.json | 38 +++ .../GHSA-xg8r-x2wg-m4m7.json | 38 +++ .../GHSA-xhvg-2jp2-9c4h.json | 42 +++ 69 files changed, 1185 insertions(+), 178 deletions(-) create mode 100644 advisories/unreviewed/2024/04/GHSA-3q47-w545-wgfv/GHSA-3q47-w545-wgfv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3v95-qw2c-cq5p/GHSA-3v95-qw2c-cq5p.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5fh7-7mw7-mmx5/GHSA-5fh7-7mw7-mmx5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5qx9-9ffj-5r8f/GHSA-5qx9-9ffj-5r8f.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8f99-g2pj-x8w3/GHSA-8f99-g2pj-x8w3.json create mode 100644 advisories/unreviewed/2024/04/GHSA-9x55-44vc-363x/GHSA-9x55-44vc-363x.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hcf3-w2q6-29cf/GHSA-hcf3-w2q6-29cf.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hqqq-4jv4-jmj5/GHSA-hqqq-4jv4-jmj5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-j2hp-jqgm-85pf/GHSA-j2hp-jqgm-85pf.json create mode 100644 advisories/unreviewed/2024/04/GHSA-p2wq-4ggp-45f3/GHSA-p2wq-4ggp-45f3.json create mode 100644 advisories/unreviewed/2024/04/GHSA-pfc3-5g8j-v982/GHSA-pfc3-5g8j-v982.json create mode 100644 advisories/unreviewed/2024/04/GHSA-pj4r-r8f8-qmcc/GHSA-pj4r-r8f8-qmcc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-pprv-m73j-58qg/GHSA-pprv-m73j-58qg.json create mode 100644 advisories/unreviewed/2024/04/GHSA-q4p9-39fv-h479/GHSA-q4p9-39fv-h479.json create mode 100644 advisories/unreviewed/2024/04/GHSA-vx97-8q8q-qgq5/GHSA-vx97-8q8q-qgq5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-w8q4-gvf3-wvfq/GHSA-w8q4-gvf3-wvfq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wj37-mpq9-xrcm/GHSA-wj37-mpq9-xrcm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-x78r-qrp5-rmmf/GHSA-x78r-qrp5-rmmf.json create mode 100644 advisories/unreviewed/2024/04/GHSA-xg8r-x2wg-m4m7/GHSA-xg8r-x2wg-m4m7.json create mode 100644 advisories/unreviewed/2024/04/GHSA-xhvg-2jp2-9c4h/GHSA-xhvg-2jp2-9c4h.json diff --git a/advisories/github-reviewed/2023/10/GHSA-qppj-fm5r-hxr3/GHSA-qppj-fm5r-hxr3.json b/advisories/github-reviewed/2023/10/GHSA-qppj-fm5r-hxr3/GHSA-qppj-fm5r-hxr3.json index e8361fbb6de..b34bcf07b6d 100644 --- a/advisories/github-reviewed/2023/10/GHSA-qppj-fm5r-hxr3/GHSA-qppj-fm5r-hxr3.json +++ b/advisories/github-reviewed/2023/10/GHSA-qppj-fm5r-hxr3/GHSA-qppj-fm5r-hxr3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qppj-fm5r-hxr3", - "modified": "2024-04-01T16:13:51Z", + "modified": "2024-04-26T09:30:36Z", "published": "2023-10-10T21:28:24Z", "aliases": [ "CVE-2023-44487" @@ -508,34 +508,6 @@ "type": "WEB", "url": "https://github.com/Azure/AKS/issues/3947" }, - { - "type": "WEB", - "url": "https://github.com/akka/akka-http/issues/4323" - }, - { - "type": "WEB", - "url": "https://github.com/alibaba/tengine/issues/1872" - }, - { - "type": "WEB", - "url": "https://github.com/apache/apisix/issues/10320" - }, - { - "type": "WEB", - "url": "https://github.com/varnishcache/varnish-cache/issues/3996" - }, - { - "type": "WEB", - "url": "https://github.com/caddyserver/caddy/issues/5877" - }, - { - "type": "WEB", - "url": "https://github.com/tempesta-tech/tempesta/issues/1986" - }, - { - "type": "WEB", - "url": "https://github.com/dotnet/announcements/issues/277" - }, { "type": "WEB", "url": "https://github.com/eclipse/jetty.project/issues/10679" @@ -544,10 +516,26 @@ "type": "WEB", "url": "https://github.com/etcd-io/etcd/issues/16740" }, + { + "type": "WEB", + "url": "https://github.com/tempesta-tech/tempesta/issues/1986" + }, { "type": "WEB", "url": "https://github.com/golang/go/issues/63417" }, + { + "type": "WEB", + "url": "https://github.com/dotnet/announcements/issues/277" + }, + { + "type": "WEB", + "url": "https://github.com/varnishcache/varnish-cache/issues/3996" + }, + { + "type": "WEB", + "url": "https://github.com/akka/akka-http/issues/4323" + }, { "type": "WEB", "url": "https://github.com/haproxy/haproxy/issues/2312" @@ -556,10 +544,6 @@ "type": "WEB", "url": "https://github.com/hyperium/hyper/issues/3337" }, - { - "type": "WEB", - "url": "https://github.com/opensearch-project/data-prepper/issues/3474" - }, { "type": "WEB", "url": "https://github.com/junkurihara/rust-rpxy/issues/97" @@ -568,6 +552,22 @@ "type": "WEB", "url": "https://github.com/kazu-yamamoto/http2/issues/93" }, + { + "type": "WEB", + "url": "https://github.com/caddyserver/caddy/issues/5877" + }, + { + "type": "WEB", + "url": "https://github.com/alibaba/tengine/issues/1872" + }, + { + "type": "WEB", + "url": "https://github.com/opensearch-project/data-prepper/issues/3474" + }, + { + "type": "WEB", + "url": "https://github.com/apache/apisix/issues/10320" + }, { "type": "WEB", "url": "https://github.com/openresty/openresty/issues/930" @@ -576,6 +576,22 @@ "type": "WEB", "url": "https://github.com/ninenines/cowboy/issues/1615" }, + { + "type": "WEB", + "url": "https://github.com/apache/trafficserver/pull/10564" + }, + { + "type": "WEB", + "url": "https://github.com/envoyproxy/envoy/pull/30055" + }, + { + "type": "WEB", + "url": "https://github.com/facebook/proxygen/pull/466" + }, + { + "type": "WEB", + "url": "https://github.com/grpc/grpc-go/pull/6703" + }, { "type": "WEB", "url": "https://github.com/projectcontour/contour/pull/5826" @@ -584,26 +600,10 @@ "type": "WEB", "url": "https://github.com/h2o/h2o/pull/3291" }, - { - "type": "WEB", - "url": "https://github.com/envoyproxy/envoy/pull/30055" - }, - { - "type": "WEB", - "url": "https://github.com/apache/trafficserver/pull/10564" - }, - { - "type": "WEB", - "url": "https://github.com/grpc/grpc-go/pull/6703" - }, { "type": "WEB", "url": "https://github.com/kubernetes/kubernetes/pull/121120" }, - { - "type": "WEB", - "url": "https://github.com/apache/httpd-site/pull/10" - }, { "type": "WEB", "url": "https://github.com/line/armeria/pull/5232" @@ -612,18 +612,6 @@ "type": "WEB", "url": "https://github.com/linkerd/website/pull/1695/commits/4b9c6836471bc8270ab48aae6fd2181bc73fd632" }, - { - "type": "WEB", - "url": "https://github.com/akka/akka-http/pull/4325" - }, - { - "type": "WEB", - "url": "https://github.com/akka/akka-http/pull/4324" - }, - { - "type": "WEB", - "url": "https://github.com/facebook/proxygen/pull/466" - }, { "type": "WEB", "url": "https://github.com/microsoft/CBL-Mariner/pull/6381" @@ -636,6 +624,18 @@ "type": "WEB", "url": "https://github.com/nodejs/node/pull/50121" }, + { + "type": "WEB", + "url": "https://github.com/apache/httpd-site/pull/10" + }, + { + "type": "WEB", + "url": "https://github.com/akka/akka-http/pull/4325" + }, + { + "type": "WEB", + "url": "https://github.com/akka/akka-http/pull/4324" + }, { "type": "WEB", "url": "https://github.com/netty/netty/commit/58f75f665aa81a8cbcf6ffa74820042a285c5e61" @@ -644,18 +644,34 @@ "type": "WEB", "url": "https://github.com/kazu-yamamoto/http2/commit/f61d41a502bd0f60eb24e1ce14edc7b6df6722a1" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5" + }, + { + "type": "WEB", + "url": "https://martinthomson.github.io/h2-stream-limits/draft-thomson-httpbis-h2-stream-limits.html" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4" }, - { - "type": "WEB", - "url": "https://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLPRSSSYR4PCMWILK.html" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK" - }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3" @@ -682,7 +698,39 @@ }, { "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK" + "url": "https://access.redhat.com/security/cve/cve-2023-44487" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK" }, { "type": "WEB", @@ -702,31 +750,7 @@ }, { "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY" + "url": "https://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLPRSSSYR4PCMWILK.html" }, { "type": "WEB", @@ -734,35 +758,15 @@ }, { "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ" + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3" }, { "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ" + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4" }, { "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A" - }, - { - "type": "WEB", - "url": "https://martinthomson.github.io/h2-stream-limits/draft-thomson-httpbis-h2-stream-limits.html" + "url": "https://msrc.microsoft.com/blog/2023/10/microsoft-response-to-distributed-denial-of-service-ddos-attacks-against-http/2" }, { "type": "WEB", @@ -832,10 +836,6 @@ "type": "WEB", "url": "https://www.theregister.com/2023/10/10/http2_rapid_reset_zeroday" }, - { - "type": "WEB", - "url": "https://msrc.microsoft.com/blog/2023/10/microsoft-response-to-distributed-denial-of-service-ddos-attacks-against-http/2" - }, { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-44487" @@ -880,6 +880,10 @@ "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20231016-0001" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0007" + }, { "type": "WEB", "url": "https://security.paloaltonetworks.com/CVE-2023-44487" @@ -900,10 +904,6 @@ "type": "WEB", "url": "https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.81" }, - { - "type": "WEB", - "url": "https://access.redhat.com/security/cve/cve-2023-44487" - }, { "type": "WEB", "url": "https://discuss.hashicorp.com/t/hcsec-2023-32-vault-consul-and-boundary-affected-by-http-2-rapid-reset-denial-of-service-vulnerability-cve-2023-44487/59715" @@ -1034,7 +1034,7 @@ }, { "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00047.html" + "url": "https://github.com/icing/mod_h2/blob/0a864782af0a942aa2ad4ed960a6b32cd35bcf0a/mod_http2/README.md?plain=1#L239-L244" }, { "type": "WEB", @@ -1098,7 +1098,7 @@ }, { "type": "WEB", - "url": "https://github.com/icing/mod_h2/blob/0a864782af0a942aa2ad4ed960a6b32cd35bcf0a/mod_http2/README.md?plain=1#L239-L244" + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK" }, { "type": "WEB", @@ -1160,6 +1160,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00045.html" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00047.html" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2023/10/13/4" diff --git a/advisories/github-reviewed/2024/03/GHSA-874v-pj72-92f3/GHSA-874v-pj72-92f3.json b/advisories/github-reviewed/2024/03/GHSA-874v-pj72-92f3/GHSA-874v-pj72-92f3.json index 81684a1c8b4..1adc1336af6 100644 --- a/advisories/github-reviewed/2024/03/GHSA-874v-pj72-92f3/GHSA-874v-pj72-92f3.json +++ b/advisories/github-reviewed/2024/03/GHSA-874v-pj72-92f3/GHSA-874v-pj72-92f3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-874v-pj72-92f3", - "modified": "2024-04-03T03:30:29Z", + "modified": "2024-04-26T09:30:33Z", "published": "2024-03-28T17:53:52Z", "aliases": [ "CVE-2024-1753" @@ -67,6 +67,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1753" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:2055" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:2064" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:2066" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-1753" diff --git a/advisories/github-reviewed/2024/04/GHSA-x5m7-63c6-fx79/GHSA-x5m7-63c6-fx79.json b/advisories/github-reviewed/2024/04/GHSA-x5m7-63c6-fx79/GHSA-x5m7-63c6-fx79.json index fc4e5ac8a9d..f002b87e2ca 100644 --- a/advisories/github-reviewed/2024/04/GHSA-x5m7-63c6-fx79/GHSA-x5m7-63c6-fx79.json +++ b/advisories/github-reviewed/2024/04/GHSA-x5m7-63c6-fx79/GHSA-x5m7-63c6-fx79.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x5m7-63c6-fx79", - "modified": "2024-04-25T19:57:06Z", + "modified": "2024-04-26T09:30:34Z", "published": "2024-04-25T18:30:39Z", "aliases": [ "CVE-2024-1139" @@ -48,6 +48,10 @@ "type": "WEB", "url": "https://github.com/openshift/cluster-monitoring-operator/commit/1cfbe9ffafe1e43f8f87a451b72fddf5d76fa4e3" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1887" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-1139" diff --git a/advisories/unreviewed/2022/05/GHSA-2gpj-6wgq-8636/GHSA-2gpj-6wgq-8636.json b/advisories/unreviewed/2022/05/GHSA-2gpj-6wgq-8636/GHSA-2gpj-6wgq-8636.json index 4b0ccab4451..f404d378b58 100644 --- a/advisories/unreviewed/2022/05/GHSA-2gpj-6wgq-8636/GHSA-2gpj-6wgq-8636.json +++ b/advisories/unreviewed/2022/05/GHSA-2gpj-6wgq-8636/GHSA-2gpj-6wgq-8636.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2gpj-6wgq-8636", - "modified": "2022-05-24T17:18:08Z", + "modified": "2024-04-26T09:30:33Z", "published": "2022-05-24T17:18:08Z", "aliases": [ "CVE-2020-12667" ], "details": "Knot Resolver before 5.1.1 allows traffic amplification via a crafted DNS answer from an attacker-controlled server, aka an \"NXNSAttack\" issue. This is triggered by random subdomains in the NSDNAME in NS records.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -22,6 +25,14 @@ "type": "WEB", "url": "https://en.blog.nic.cz/2020/05/19/nxnsattack-upgrade-resolvers-to-stop-new-kind-of-random-subdomain-attack" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00017.html" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/76Y4FITMOH6RVPWAANGV7NB2ZHPJJGDQ" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/76Y4FITMOH6RVPWAANGV7NB2ZHPJJGDQ" @@ -45,7 +56,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-5pqr-9wpj-5m82/GHSA-5pqr-9wpj-5m82.json b/advisories/unreviewed/2022/05/GHSA-5pqr-9wpj-5m82/GHSA-5pqr-9wpj-5m82.json index 84548fae05d..f2d2dbaf4ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-5pqr-9wpj-5m82/GHSA-5pqr-9wpj-5m82.json +++ b/advisories/unreviewed/2022/05/GHSA-5pqr-9wpj-5m82/GHSA-5pqr-9wpj-5m82.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5pqr-9wpj-5m82", - "modified": "2023-02-13T00:30:59Z", + "modified": "2024-04-26T09:30:33Z", "published": "2022-05-24T16:50:26Z", "aliases": [ "CVE-2019-10190" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10190" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00017.html" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TMSSWBHINIX4WE6UDXWM66L7JYEK6XS6" diff --git a/advisories/unreviewed/2022/05/GHSA-5w8c-g2pj-65rx/GHSA-5w8c-g2pj-65rx.json b/advisories/unreviewed/2022/05/GHSA-5w8c-g2pj-65rx/GHSA-5w8c-g2pj-65rx.json index a107ab96f28..9de64a53c75 100644 --- a/advisories/unreviewed/2022/05/GHSA-5w8c-g2pj-65rx/GHSA-5w8c-g2pj-65rx.json +++ b/advisories/unreviewed/2022/05/GHSA-5w8c-g2pj-65rx/GHSA-5w8c-g2pj-65rx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5w8c-g2pj-65rx", - "modified": "2023-02-13T00:30:59Z", + "modified": "2024-04-26T09:30:33Z", "published": "2022-05-24T16:50:27Z", "aliases": [ "CVE-2019-10191" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10191" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00017.html" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TMSSWBHINIX4WE6UDXWM66L7JYEK6XS6" diff --git a/advisories/unreviewed/2022/05/GHSA-9f7v-8m4p-pv76/GHSA-9f7v-8m4p-pv76.json b/advisories/unreviewed/2022/05/GHSA-9f7v-8m4p-pv76/GHSA-9f7v-8m4p-pv76.json index e166ef809e3..1cefad20e20 100644 --- a/advisories/unreviewed/2022/05/GHSA-9f7v-8m4p-pv76/GHSA-9f7v-8m4p-pv76.json +++ b/advisories/unreviewed/2022/05/GHSA-9f7v-8m4p-pv76/GHSA-9f7v-8m4p-pv76.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9f7v-8m4p-pv76", - "modified": "2024-04-04T02:43:50Z", + "modified": "2024-04-26T09:30:33Z", "published": "2022-05-24T17:03:44Z", "aliases": [ "CVE-2019-19331" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-19331" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00017.html" + }, { "type": "WEB", "url": "https://www.knot-resolver.cz/2019-12-04-knot-resolver-4.3.0.html" diff --git a/advisories/unreviewed/2023/09/GHSA-2hcr-79rm-r8rp/GHSA-2hcr-79rm-r8rp.json b/advisories/unreviewed/2023/09/GHSA-2hcr-79rm-r8rp/GHSA-2hcr-79rm-r8rp.json index e6f9b2db5af..8eb4d623a0b 100644 --- a/advisories/unreviewed/2023/09/GHSA-2hcr-79rm-r8rp/GHSA-2hcr-79rm-r8rp.json +++ b/advisories/unreviewed/2023/09/GHSA-2hcr-79rm-r8rp/GHSA-2hcr-79rm-r8rp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2hcr-79rm-r8rp", - "modified": "2023-11-16T03:30:19Z", + "modified": "2024-04-26T09:30:33Z", "published": "2023-09-21T21:31:00Z", "aliases": [ "CVE-2023-41993" @@ -37,6 +37,10 @@ "type": "WEB", "url": "https://security.gentoo.org/glsa/202401-33" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0004" + }, { "type": "WEB", "url": "https://support.apple.com/en-us/HT213926" diff --git a/advisories/unreviewed/2023/09/GHSA-8jhw-fpw9-r227/GHSA-8jhw-fpw9-r227.json b/advisories/unreviewed/2023/09/GHSA-8jhw-fpw9-r227/GHSA-8jhw-fpw9-r227.json index 9b36edace1f..665dc528c36 100644 --- a/advisories/unreviewed/2023/09/GHSA-8jhw-fpw9-r227/GHSA-8jhw-fpw9-r227.json +++ b/advisories/unreviewed/2023/09/GHSA-8jhw-fpw9-r227/GHSA-8jhw-fpw9-r227.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8jhw-fpw9-r227", - "modified": "2024-04-04T07:41:03Z", + "modified": "2024-04-26T09:30:33Z", "published": "2023-09-14T21:30:26Z", "aliases": [ "CVE-2023-32643" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://https://discourse.gnome.org/t/multiple-fixes-for-gvariant-normalisation-issues-in-glib/12835" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0005" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/09/GHSA-c9xj-rf55-c64g/GHSA-c9xj-rf55-c64g.json b/advisories/unreviewed/2023/09/GHSA-c9xj-rf55-c64g/GHSA-c9xj-rf55-c64g.json index e514fd0eefe..5792fb7d1bf 100644 --- a/advisories/unreviewed/2023/09/GHSA-c9xj-rf55-c64g/GHSA-c9xj-rf55-c64g.json +++ b/advisories/unreviewed/2023/09/GHSA-c9xj-rf55-c64g/GHSA-c9xj-rf55-c64g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c9xj-rf55-c64g", - "modified": "2023-11-27T15:30:55Z", + "modified": "2024-04-26T09:30:33Z", "published": "2023-09-14T21:30:26Z", "aliases": [ "CVE-2023-32665" @@ -40,6 +40,10 @@ { "type": "WEB", "url": "https://security.gentoo.org/glsa/202311-18" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0006" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-rj8q-prqp-jwfg/GHSA-rj8q-prqp-jwfg.json b/advisories/unreviewed/2024/01/GHSA-rj8q-prqp-jwfg/GHSA-rj8q-prqp-jwfg.json index 5e2852a2761..fe53f8deb24 100644 --- a/advisories/unreviewed/2024/01/GHSA-rj8q-prqp-jwfg/GHSA-rj8q-prqp-jwfg.json +++ b/advisories/unreviewed/2024/01/GHSA-rj8q-prqp-jwfg/GHSA-rj8q-prqp-jwfg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rj8q-prqp-jwfg", - "modified": "2024-02-16T15:30:26Z", + "modified": "2024-04-26T09:30:33Z", "published": "2024-01-09T18:30:27Z", "aliases": [ "CVE-2023-6129" @@ -37,6 +37,14 @@ "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20240216-0009" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0008" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0013" + }, { "type": "WEB", "url": "https://www.openssl.org/news/secadv/20240109.txt" diff --git a/advisories/unreviewed/2024/02/GHSA-697h-9h25-w4fm/GHSA-697h-9h25-w4fm.json b/advisories/unreviewed/2024/02/GHSA-697h-9h25-w4fm/GHSA-697h-9h25-w4fm.json index f6a07dc23a6..d49f48494c6 100644 --- a/advisories/unreviewed/2024/02/GHSA-697h-9h25-w4fm/GHSA-697h-9h25-w4fm.json +++ b/advisories/unreviewed/2024/02/GHSA-697h-9h25-w4fm/GHSA-697h-9h25-w4fm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-697h-9h25-w4fm", - "modified": "2024-03-07T18:30:27Z", + "modified": "2024-04-26T09:30:33Z", "published": "2024-02-03T15:30:28Z", "aliases": [ "CVE-2024-0853" @@ -36,6 +36,10 @@ { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20240307-0004" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0009" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-v5qp-mx94-j49v/GHSA-v5qp-mx94-j49v.json b/advisories/unreviewed/2024/02/GHSA-v5qp-mx94-j49v/GHSA-v5qp-mx94-j49v.json index e0a3f11ffb6..3f4fd6543ac 100644 --- a/advisories/unreviewed/2024/02/GHSA-v5qp-mx94-j49v/GHSA-v5qp-mx94-j49v.json +++ b/advisories/unreviewed/2024/02/GHSA-v5qp-mx94-j49v/GHSA-v5qp-mx94-j49v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v5qp-mx94-j49v", - "modified": "2024-03-04T03:30:25Z", + "modified": "2024-04-26T09:30:33Z", "published": "2024-02-13T15:31:12Z", "aliases": [ "CVE-2023-5679" @@ -41,6 +41,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZDZFMEKQTZ4L7RY46FCENWFB5MDT263R" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0002" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/02/13/1" diff --git a/advisories/unreviewed/2024/02/GHSA-x57x-3c65-5f3j/GHSA-x57x-3c65-5f3j.json b/advisories/unreviewed/2024/02/GHSA-x57x-3c65-5f3j/GHSA-x57x-3c65-5f3j.json index d7a0faafd82..f5c2ed8d25b 100644 --- a/advisories/unreviewed/2024/02/GHSA-x57x-3c65-5f3j/GHSA-x57x-3c65-5f3j.json +++ b/advisories/unreviewed/2024/02/GHSA-x57x-3c65-5f3j/GHSA-x57x-3c65-5f3j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x57x-3c65-5f3j", - "modified": "2024-03-04T03:30:25Z", + "modified": "2024-04-26T09:30:33Z", "published": "2024-02-13T15:31:12Z", "aliases": [ "CVE-2023-4408" @@ -41,6 +41,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZDZFMEKQTZ4L7RY46FCENWFB5MDT263R" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0001" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/02/13/1" diff --git a/advisories/unreviewed/2024/04/GHSA-26mf-52p6-23pq/GHSA-26mf-52p6-23pq.json b/advisories/unreviewed/2024/04/GHSA-26mf-52p6-23pq/GHSA-26mf-52p6-23pq.json index 32f231e138d..c30651aa15d 100644 --- a/advisories/unreviewed/2024/04/GHSA-26mf-52p6-23pq/GHSA-26mf-52p6-23pq.json +++ b/advisories/unreviewed/2024/04/GHSA-26mf-52p6-23pq/GHSA-26mf-52p6-23pq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-26mf-52p6-23pq", - "modified": "2024-04-17T00:30:53Z", + "modified": "2024-04-26T09:30:33Z", "published": "2024-04-17T00:30:53Z", "aliases": [ "CVE-2024-20994" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20994" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0013" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-273j-fjrx-gf2f/GHSA-273j-fjrx-gf2f.json b/advisories/unreviewed/2024/04/GHSA-273j-fjrx-gf2f/GHSA-273j-fjrx-gf2f.json index 64cf53001ca..e7b5270e0b9 100644 --- a/advisories/unreviewed/2024/04/GHSA-273j-fjrx-gf2f/GHSA-273j-fjrx-gf2f.json +++ b/advisories/unreviewed/2024/04/GHSA-273j-fjrx-gf2f/GHSA-273j-fjrx-gf2f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-273j-fjrx-gf2f", - "modified": "2024-04-22T15:30:40Z", + "modified": "2024-04-26T09:30:34Z", "published": "2024-04-17T00:30:56Z", "aliases": [ "CVE-2024-21085" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00014.html" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0004" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-2mpf-fq5j-4hgp/GHSA-2mpf-fq5j-4hgp.json b/advisories/unreviewed/2024/04/GHSA-2mpf-fq5j-4hgp/GHSA-2mpf-fq5j-4hgp.json index e16dc4918cc..e5b9e90a8a4 100644 --- a/advisories/unreviewed/2024/04/GHSA-2mpf-fq5j-4hgp/GHSA-2mpf-fq5j-4hgp.json +++ b/advisories/unreviewed/2024/04/GHSA-2mpf-fq5j-4hgp/GHSA-2mpf-fq5j-4hgp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2mpf-fq5j-4hgp", - "modified": "2024-04-17T00:30:56Z", + "modified": "2024-04-26T09:30:34Z", "published": "2024-04-17T00:30:56Z", "aliases": [ "CVE-2024-21087" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21087" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0013" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-3jpw-p5mr-c3q9/GHSA-3jpw-p5mr-c3q9.json b/advisories/unreviewed/2024/04/GHSA-3jpw-p5mr-c3q9/GHSA-3jpw-p5mr-c3q9.json index 1a2b2b0a691..449bcde4f43 100644 --- a/advisories/unreviewed/2024/04/GHSA-3jpw-p5mr-c3q9/GHSA-3jpw-p5mr-c3q9.json +++ b/advisories/unreviewed/2024/04/GHSA-3jpw-p5mr-c3q9/GHSA-3jpw-p5mr-c3q9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3jpw-p5mr-c3q9", - "modified": "2024-04-17T00:30:55Z", + "modified": "2024-04-26T09:30:34Z", "published": "2024-04-17T00:30:55Z", "aliases": [ "CVE-2024-21052" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21052" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0012" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-3q47-w545-wgfv/GHSA-3q47-w545-wgfv.json b/advisories/unreviewed/2024/04/GHSA-3q47-w545-wgfv/GHSA-3q47-w545-wgfv.json new file mode 100644 index 00000000000..0823a7f1df0 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3q47-w545-wgfv/GHSA-3q47-w545-wgfv.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3q47-w545-wgfv", + "modified": "2024-04-26T09:30:34Z", + "published": "2024-04-26T09:30:34Z", + "aliases": [ + "CVE-2024-3962" + ], + "details": "The Product Addons & Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ppom_upload_file function in all versions up to, and including, 32.0.18. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Successful exploitation requires the PPOM Pro plugin to be installed along with a WooCommerce product that contains a file upload field to retrieve the correct nonce.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3962" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3075669/woocommerce-product-addon" + }, + { + "type": "WEB", + "url": "https://themeisle.com/plugins/ppom-pro" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4f95bcc3-354e-4016-9a17-945569b076b6?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T09:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3v95-qw2c-cq5p/GHSA-3v95-qw2c-cq5p.json b/advisories/unreviewed/2024/04/GHSA-3v95-qw2c-cq5p/GHSA-3v95-qw2c-cq5p.json new file mode 100644 index 00000000000..ad445e54bce --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3v95-qw2c-cq5p/GHSA-3v95-qw2c-cq5p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3v95-qw2c-cq5p", + "modified": "2024-04-26T09:30:34Z", + "published": "2024-04-26T09:30:34Z", + "aliases": [ + "CVE-2024-33642" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EkoJR Advanced Post List allows Stored XSS.This issue affects Advanced Post List: from n/a through 0.5.6.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33642" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/advanced-post-list/wordpress-advanced-post-list-plugin-0-5-6-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T08:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3vx9-2ch5-m6r6/GHSA-3vx9-2ch5-m6r6.json b/advisories/unreviewed/2024/04/GHSA-3vx9-2ch5-m6r6/GHSA-3vx9-2ch5-m6r6.json index a16c69154f3..eeeabe7c2e1 100644 --- a/advisories/unreviewed/2024/04/GHSA-3vx9-2ch5-m6r6/GHSA-3vx9-2ch5-m6r6.json +++ b/advisories/unreviewed/2024/04/GHSA-3vx9-2ch5-m6r6/GHSA-3vx9-2ch5-m6r6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3vx9-2ch5-m6r6", - "modified": "2024-04-17T00:30:56Z", + "modified": "2024-04-26T09:30:34Z", "published": "2024-04-17T00:30:56Z", "aliases": [ "CVE-2024-21096" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21096" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0013" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-4cjh-m2w7-xg99/GHSA-4cjh-m2w7-xg99.json b/advisories/unreviewed/2024/04/GHSA-4cjh-m2w7-xg99/GHSA-4cjh-m2w7-xg99.json index b9347124c33..44f84646507 100644 --- a/advisories/unreviewed/2024/04/GHSA-4cjh-m2w7-xg99/GHSA-4cjh-m2w7-xg99.json +++ b/advisories/unreviewed/2024/04/GHSA-4cjh-m2w7-xg99/GHSA-4cjh-m2w7-xg99.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4cjh-m2w7-xg99", - "modified": "2024-04-17T00:30:56Z", + "modified": "2024-04-26T09:30:34Z", "published": "2024-04-17T00:30:56Z", "aliases": [ "CVE-2024-21102" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21102" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0013" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0015" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-55g5-m7rx-jf99/GHSA-55g5-m7rx-jf99.json b/advisories/unreviewed/2024/04/GHSA-55g5-m7rx-jf99/GHSA-55g5-m7rx-jf99.json index a4a8ea04633..1224ff694b6 100644 --- a/advisories/unreviewed/2024/04/GHSA-55g5-m7rx-jf99/GHSA-55g5-m7rx-jf99.json +++ b/advisories/unreviewed/2024/04/GHSA-55g5-m7rx-jf99/GHSA-55g5-m7rx-jf99.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-55g5-m7rx-jf99", - "modified": "2024-04-17T00:30:54Z", + "modified": "2024-04-26T09:30:33Z", "published": "2024-04-17T00:30:54Z", "aliases": [ "CVE-2024-21005" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21005" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0004" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-5fh7-7mw7-mmx5/GHSA-5fh7-7mw7-mmx5.json b/advisories/unreviewed/2024/04/GHSA-5fh7-7mw7-mmx5/GHSA-5fh7-7mw7-mmx5.json new file mode 100644 index 00000000000..bee1c7fcb62 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5fh7-7mw7-mmx5/GHSA-5fh7-7mw7-mmx5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fh7-7mw7-mmx5", + "modified": "2024-04-26T09:30:35Z", + "published": "2024-04-26T09:30:35Z", + "aliases": [ + "CVE-2024-4195" + ], + "details": "Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes, which allows an attacker authenticated as a team admin to promote guests to team admins via crafted HTTP requests.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4195" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T09:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5qx9-9ffj-5r8f/GHSA-5qx9-9ffj-5r8f.json b/advisories/unreviewed/2024/04/GHSA-5qx9-9ffj-5r8f/GHSA-5qx9-9ffj-5r8f.json new file mode 100644 index 00000000000..c702dff33ea --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5qx9-9ffj-5r8f/GHSA-5qx9-9ffj-5r8f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qx9-9ffj-5r8f", + "modified": "2024-04-26T09:30:35Z", + "published": "2024-04-26T09:30:34Z", + "aliases": [ + "CVE-2024-4198" + ], + "details": "Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes which allows an attacker authenticated as team admin to demote users to guest via crafted HTTP requests.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4198" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T09:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5v68-73xh-wcgw/GHSA-5v68-73xh-wcgw.json b/advisories/unreviewed/2024/04/GHSA-5v68-73xh-wcgw/GHSA-5v68-73xh-wcgw.json index 149994d847e..5b0b219ef4a 100644 --- a/advisories/unreviewed/2024/04/GHSA-5v68-73xh-wcgw/GHSA-5v68-73xh-wcgw.json +++ b/advisories/unreviewed/2024/04/GHSA-5v68-73xh-wcgw/GHSA-5v68-73xh-wcgw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5v68-73xh-wcgw", - "modified": "2024-04-17T00:30:54Z", + "modified": "2024-04-26T09:30:33Z", "published": "2024-04-17T00:30:54Z", "aliases": [ "CVE-2024-20998" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20998" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0013" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-5wrr-m725-w8jw/GHSA-5wrr-m725-w8jw.json b/advisories/unreviewed/2024/04/GHSA-5wrr-m725-w8jw/GHSA-5wrr-m725-w8jw.json index f78b2e15053..db8ed2dd344 100644 --- a/advisories/unreviewed/2024/04/GHSA-5wrr-m725-w8jw/GHSA-5wrr-m725-w8jw.json +++ b/advisories/unreviewed/2024/04/GHSA-5wrr-m725-w8jw/GHSA-5wrr-m725-w8jw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5wrr-m725-w8jw", - "modified": "2024-04-17T00:30:54Z", + "modified": "2024-04-26T09:30:33Z", "published": "2024-04-17T00:30:54Z", "aliases": [ "CVE-2024-21002" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21002" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0004" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-5xq9-rcpj-p52v/GHSA-5xq9-rcpj-p52v.json b/advisories/unreviewed/2024/04/GHSA-5xq9-rcpj-p52v/GHSA-5xq9-rcpj-p52v.json index be41a292163..af4eebc4350 100644 --- a/advisories/unreviewed/2024/04/GHSA-5xq9-rcpj-p52v/GHSA-5xq9-rcpj-p52v.json +++ b/advisories/unreviewed/2024/04/GHSA-5xq9-rcpj-p52v/GHSA-5xq9-rcpj-p52v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5xq9-rcpj-p52v", - "modified": "2024-04-17T00:30:54Z", + "modified": "2024-04-26T09:30:34Z", "published": "2024-04-17T00:30:54Z", "aliases": [ "CVE-2024-21013" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21013" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0013" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-63p9-g7fv-6cvr/GHSA-63p9-g7fv-6cvr.json b/advisories/unreviewed/2024/04/GHSA-63p9-g7fv-6cvr/GHSA-63p9-g7fv-6cvr.json index d2eaf1f3abd..084dc593693 100644 --- a/advisories/unreviewed/2024/04/GHSA-63p9-g7fv-6cvr/GHSA-63p9-g7fv-6cvr.json +++ b/advisories/unreviewed/2024/04/GHSA-63p9-g7fv-6cvr/GHSA-63p9-g7fv-6cvr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-63p9-g7fv-6cvr", - "modified": "2024-04-17T00:30:55Z", + "modified": "2024-04-26T09:30:34Z", "published": "2024-04-17T00:30:55Z", "aliases": [ "CVE-2024-21050" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21050" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0012" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-6pwq-2vrc-6rr6/GHSA-6pwq-2vrc-6rr6.json b/advisories/unreviewed/2024/04/GHSA-6pwq-2vrc-6rr6/GHSA-6pwq-2vrc-6rr6.json index 0084f3cc5c7..5b6b6a50298 100644 --- a/advisories/unreviewed/2024/04/GHSA-6pwq-2vrc-6rr6/GHSA-6pwq-2vrc-6rr6.json +++ b/advisories/unreviewed/2024/04/GHSA-6pwq-2vrc-6rr6/GHSA-6pwq-2vrc-6rr6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6pwq-2vrc-6rr6", - "modified": "2024-04-17T00:30:55Z", + "modified": "2024-04-26T09:30:34Z", "published": "2024-04-17T00:30:55Z", "aliases": [ "CVE-2024-21061" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21061" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0014" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-6qf6-cmc3-h6x2/GHSA-6qf6-cmc3-h6x2.json b/advisories/unreviewed/2024/04/GHSA-6qf6-cmc3-h6x2/GHSA-6qf6-cmc3-h6x2.json index fa4ad467403..ae8a9810349 100644 --- a/advisories/unreviewed/2024/04/GHSA-6qf6-cmc3-h6x2/GHSA-6qf6-cmc3-h6x2.json +++ b/advisories/unreviewed/2024/04/GHSA-6qf6-cmc3-h6x2/GHSA-6qf6-cmc3-h6x2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6qf6-cmc3-h6x2", - "modified": "2024-04-17T00:30:53Z", + "modified": "2024-04-26T09:30:33Z", "published": "2024-04-17T00:30:53Z", "aliases": [ "CVE-2024-20993" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20993" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0014" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-7jxx-p3jr-r2x9/GHSA-7jxx-p3jr-r2x9.json b/advisories/unreviewed/2024/04/GHSA-7jxx-p3jr-r2x9/GHSA-7jxx-p3jr-r2x9.json index b091775bd0b..95b03a9f2f7 100644 --- a/advisories/unreviewed/2024/04/GHSA-7jxx-p3jr-r2x9/GHSA-7jxx-p3jr-r2x9.json +++ b/advisories/unreviewed/2024/04/GHSA-7jxx-p3jr-r2x9/GHSA-7jxx-p3jr-r2x9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7jxx-p3jr-r2x9", - "modified": "2024-04-17T00:30:54Z", + "modified": "2024-04-26T09:30:33Z", "published": "2024-04-17T00:30:54Z", "aliases": [ "CVE-2024-21009" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21009" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0013" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-7pmg-vmj4-qjp4/GHSA-7pmg-vmj4-qjp4.json b/advisories/unreviewed/2024/04/GHSA-7pmg-vmj4-qjp4/GHSA-7pmg-vmj4-qjp4.json index dc6ec21bf1e..5efc18873de 100644 --- a/advisories/unreviewed/2024/04/GHSA-7pmg-vmj4-qjp4/GHSA-7pmg-vmj4-qjp4.json +++ b/advisories/unreviewed/2024/04/GHSA-7pmg-vmj4-qjp4/GHSA-7pmg-vmj4-qjp4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7pmg-vmj4-qjp4", - "modified": "2024-04-17T00:30:55Z", + "modified": "2024-04-26T09:30:34Z", "published": "2024-04-17T00:30:55Z", "aliases": [ "CVE-2024-21053" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21053" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0012" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-7qqv-8pwc-x4xc/GHSA-7qqv-8pwc-x4xc.json b/advisories/unreviewed/2024/04/GHSA-7qqv-8pwc-x4xc/GHSA-7qqv-8pwc-x4xc.json index 85de8cdb585..0cf855d25cd 100644 --- a/advisories/unreviewed/2024/04/GHSA-7qqv-8pwc-x4xc/GHSA-7qqv-8pwc-x4xc.json +++ b/advisories/unreviewed/2024/04/GHSA-7qqv-8pwc-x4xc/GHSA-7qqv-8pwc-x4xc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7qqv-8pwc-x4xc", - "modified": "2024-04-22T15:30:40Z", + "modified": "2024-04-26T09:30:33Z", "published": "2024-04-17T00:30:54Z", "aliases": [ "CVE-2024-21011" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00014.html" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0004" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-88h4-jw57-85v9/GHSA-88h4-jw57-85v9.json b/advisories/unreviewed/2024/04/GHSA-88h4-jw57-85v9/GHSA-88h4-jw57-85v9.json index 9ae3680b6d4..c8f740da492 100644 --- a/advisories/unreviewed/2024/04/GHSA-88h4-jw57-85v9/GHSA-88h4-jw57-85v9.json +++ b/advisories/unreviewed/2024/04/GHSA-88h4-jw57-85v9/GHSA-88h4-jw57-85v9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-88h4-jw57-85v9", - "modified": "2024-04-17T00:30:55Z", + "modified": "2024-04-26T09:30:34Z", "published": "2024-04-17T00:30:55Z", "aliases": [ "CVE-2024-21060" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21060" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0013" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-8cpf-fxr6-4wpq/GHSA-8cpf-fxr6-4wpq.json b/advisories/unreviewed/2024/04/GHSA-8cpf-fxr6-4wpq/GHSA-8cpf-fxr6-4wpq.json index 62b4eee9a42..8e007d1c38a 100644 --- a/advisories/unreviewed/2024/04/GHSA-8cpf-fxr6-4wpq/GHSA-8cpf-fxr6-4wpq.json +++ b/advisories/unreviewed/2024/04/GHSA-8cpf-fxr6-4wpq/GHSA-8cpf-fxr6-4wpq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8cpf-fxr6-4wpq", - "modified": "2024-04-17T00:30:54Z", + "modified": "2024-04-26T09:30:33Z", "published": "2024-04-17T00:30:54Z", "aliases": [ "CVE-2024-21008" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21008" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0013" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-8f99-g2pj-x8w3/GHSA-8f99-g2pj-x8w3.json b/advisories/unreviewed/2024/04/GHSA-8f99-g2pj-x8w3/GHSA-8f99-g2pj-x8w3.json new file mode 100644 index 00000000000..46a4df9258f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8f99-g2pj-x8w3/GHSA-8f99-g2pj-x8w3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8f99-g2pj-x8w3", + "modified": "2024-04-26T09:30:34Z", + "published": "2024-04-26T09:30:34Z", + "aliases": [ + "CVE-2024-4182" + ], + "details": "Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing errors in custom status values, which allows an authenticated attacker to crash other users' web clients via a malformed custom status.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4182" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-754" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T09:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8x4w-7h9g-pg2q/GHSA-8x4w-7h9g-pg2q.json b/advisories/unreviewed/2024/04/GHSA-8x4w-7h9g-pg2q/GHSA-8x4w-7h9g-pg2q.json index 5ba81852899..d2efe839703 100644 --- a/advisories/unreviewed/2024/04/GHSA-8x4w-7h9g-pg2q/GHSA-8x4w-7h9g-pg2q.json +++ b/advisories/unreviewed/2024/04/GHSA-8x4w-7h9g-pg2q/GHSA-8x4w-7h9g-pg2q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8x4w-7h9g-pg2q", - "modified": "2024-04-17T00:30:55Z", + "modified": "2024-04-26T09:30:34Z", "published": "2024-04-17T00:30:55Z", "aliases": [ "CVE-2024-21049" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21049" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0012" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-975v-wj6r-fgj8/GHSA-975v-wj6r-fgj8.json b/advisories/unreviewed/2024/04/GHSA-975v-wj6r-fgj8/GHSA-975v-wj6r-fgj8.json index 0fa7391465c..3e381f139f1 100644 --- a/advisories/unreviewed/2024/04/GHSA-975v-wj6r-fgj8/GHSA-975v-wj6r-fgj8.json +++ b/advisories/unreviewed/2024/04/GHSA-975v-wj6r-fgj8/GHSA-975v-wj6r-fgj8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-975v-wj6r-fgj8", - "modified": "2024-04-05T21:32:45Z", + "modified": "2024-04-26T09:30:33Z", "published": "2024-04-05T21:32:45Z", "aliases": [ "CVE-2024-2312" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2312" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0003" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/04/GHSA-9cw3-8wpf-rpmg/GHSA-9cw3-8wpf-rpmg.json b/advisories/unreviewed/2024/04/GHSA-9cw3-8wpf-rpmg/GHSA-9cw3-8wpf-rpmg.json index 629add1ddca..912adb0a0f8 100644 --- a/advisories/unreviewed/2024/04/GHSA-9cw3-8wpf-rpmg/GHSA-9cw3-8wpf-rpmg.json +++ b/advisories/unreviewed/2024/04/GHSA-9cw3-8wpf-rpmg/GHSA-9cw3-8wpf-rpmg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9cw3-8wpf-rpmg", - "modified": "2024-04-17T00:30:55Z", + "modified": "2024-04-26T09:30:34Z", "published": "2024-04-17T00:30:55Z", "aliases": [ "CVE-2024-21047" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21047" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0013" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-9x55-44vc-363x/GHSA-9x55-44vc-363x.json b/advisories/unreviewed/2024/04/GHSA-9x55-44vc-363x/GHSA-9x55-44vc-363x.json new file mode 100644 index 00000000000..04a3ea9911f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-9x55-44vc-363x/GHSA-9x55-44vc-363x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9x55-44vc-363x", + "modified": "2024-04-26T09:30:34Z", + "published": "2024-04-26T09:30:34Z", + "aliases": [ + "CVE-2024-33651" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Matthew Fries MF Gig Calendar.This issue affects MF Gig Calendar : from n/a through 1.2.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33651" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mf-gig-calendar/wordpress-mf-gig-calendar-plugin-1-2-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T08:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-ccmh-gwpx-35xj/GHSA-ccmh-gwpx-35xj.json b/advisories/unreviewed/2024/04/GHSA-ccmh-gwpx-35xj/GHSA-ccmh-gwpx-35xj.json index b2c1aa88518..23f6f7fbb82 100644 --- a/advisories/unreviewed/2024/04/GHSA-ccmh-gwpx-35xj/GHSA-ccmh-gwpx-35xj.json +++ b/advisories/unreviewed/2024/04/GHSA-ccmh-gwpx-35xj/GHSA-ccmh-gwpx-35xj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ccmh-gwpx-35xj", - "modified": "2024-04-22T15:30:40Z", + "modified": "2024-04-26T09:30:33Z", "published": "2024-04-17T00:30:54Z", "aliases": [ "CVE-2024-21012" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00014.html" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0004" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-g3wm-f7gr-3fwh/GHSA-g3wm-f7gr-3fwh.json b/advisories/unreviewed/2024/04/GHSA-g3wm-f7gr-3fwh/GHSA-g3wm-f7gr-3fwh.json index 249c78ce34f..b568346e9bf 100644 --- a/advisories/unreviewed/2024/04/GHSA-g3wm-f7gr-3fwh/GHSA-g3wm-f7gr-3fwh.json +++ b/advisories/unreviewed/2024/04/GHSA-g3wm-f7gr-3fwh/GHSA-g3wm-f7gr-3fwh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g3wm-f7gr-3fwh", - "modified": "2024-04-22T15:30:40Z", + "modified": "2024-04-26T09:30:34Z", "published": "2024-04-17T00:30:56Z", "aliases": [ "CVE-2024-21094" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00014.html" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0004" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-gj63-qcjc-2fcw/GHSA-gj63-qcjc-2fcw.json b/advisories/unreviewed/2024/04/GHSA-gj63-qcjc-2fcw/GHSA-gj63-qcjc-2fcw.json index 7e424c5aacb..62c4caa3e82 100644 --- a/advisories/unreviewed/2024/04/GHSA-gj63-qcjc-2fcw/GHSA-gj63-qcjc-2fcw.json +++ b/advisories/unreviewed/2024/04/GHSA-gj63-qcjc-2fcw/GHSA-gj63-qcjc-2fcw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gj63-qcjc-2fcw", - "modified": "2024-04-17T00:30:54Z", + "modified": "2024-04-26T09:30:34Z", "published": "2024-04-17T00:30:54Z", "aliases": [ "CVE-2024-21015" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21015" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0010" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-hcf3-w2q6-29cf/GHSA-hcf3-w2q6-29cf.json b/advisories/unreviewed/2024/04/GHSA-hcf3-w2q6-29cf/GHSA-hcf3-w2q6-29cf.json new file mode 100644 index 00000000000..ae699ce7195 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hcf3-w2q6-29cf/GHSA-hcf3-w2q6-29cf.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hcf3-w2q6-29cf", + "modified": "2024-04-26T09:30:34Z", + "published": "2024-04-26T09:30:34Z", + "aliases": [ + "CVE-2024-1789" + ], + "details": "The WP SMTP plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in versions 1.2 to 1.2.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1789" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3076663%40wp-smtp&new=3076663%40wp-smtp&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ee269bc7-2822-4a07-be91-6763c1cf6cf2?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hcm7-xw9m-99cx/GHSA-hcm7-xw9m-99cx.json b/advisories/unreviewed/2024/04/GHSA-hcm7-xw9m-99cx/GHSA-hcm7-xw9m-99cx.json index 4dacb2d726c..d6ebdb04ca9 100644 --- a/advisories/unreviewed/2024/04/GHSA-hcm7-xw9m-99cx/GHSA-hcm7-xw9m-99cx.json +++ b/advisories/unreviewed/2024/04/GHSA-hcm7-xw9m-99cx/GHSA-hcm7-xw9m-99cx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hcm7-xw9m-99cx", - "modified": "2024-04-17T00:30:55Z", + "modified": "2024-04-26T09:30:34Z", "published": "2024-04-17T00:30:55Z", "aliases": [ "CVE-2024-21055" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21055" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0011" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-hqqq-4jv4-jmj5/GHSA-hqqq-4jv4-jmj5.json b/advisories/unreviewed/2024/04/GHSA-hqqq-4jv4-jmj5/GHSA-hqqq-4jv4-jmj5.json new file mode 100644 index 00000000000..cc542f36623 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hqqq-4jv4-jmj5/GHSA-hqqq-4jv4-jmj5.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqqq-4jv4-jmj5", + "modified": "2024-04-26T09:30:34Z", + "published": "2024-04-26T09:30:34Z", + "aliases": [ + "CVE-2024-3678" + ], + "details": "The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.4.2. This makes it possible for unauthenticated attackers to view limited information from password protected posts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3678" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3069574/blog2social/trunk/includes/Meta.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3074883/blog2social/trunk/includes/Meta.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2dea1bcb-14c2-4ec9-8a4d-087bac2db486?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T08:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hv7f-m7x4-mc78/GHSA-hv7f-m7x4-mc78.json b/advisories/unreviewed/2024/04/GHSA-hv7f-m7x4-mc78/GHSA-hv7f-m7x4-mc78.json index ff9d7cf9f5b..52af5ecf8ee 100644 --- a/advisories/unreviewed/2024/04/GHSA-hv7f-m7x4-mc78/GHSA-hv7f-m7x4-mc78.json +++ b/advisories/unreviewed/2024/04/GHSA-hv7f-m7x4-mc78/GHSA-hv7f-m7x4-mc78.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hv7f-m7x4-mc78", - "modified": "2024-04-17T00:30:56Z", + "modified": "2024-04-26T09:30:34Z", "published": "2024-04-17T00:30:56Z", "aliases": [ "CVE-2024-21101" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21101" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0015" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-j2hp-jqgm-85pf/GHSA-j2hp-jqgm-85pf.json b/advisories/unreviewed/2024/04/GHSA-j2hp-jqgm-85pf/GHSA-j2hp-jqgm-85pf.json new file mode 100644 index 00000000000..78b24c2ca51 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-j2hp-jqgm-85pf/GHSA-j2hp-jqgm-85pf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2hp-jqgm-85pf", + "modified": "2024-04-26T09:30:34Z", + "published": "2024-04-26T09:30:34Z", + "aliases": [ + "CVE-2024-33639" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AccessAlly PopupAlly allows Stored XSS.This issue affects PopupAlly: from n/a through 2.1.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33639" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/popupally/wordpress-popupally-plugin-2-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T08:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jfv3-gh3j-c5r7/GHSA-jfv3-gh3j-c5r7.json b/advisories/unreviewed/2024/04/GHSA-jfv3-gh3j-c5r7/GHSA-jfv3-gh3j-c5r7.json index aa821526b1c..1c94ee42e6f 100644 --- a/advisories/unreviewed/2024/04/GHSA-jfv3-gh3j-c5r7/GHSA-jfv3-gh3j-c5r7.json +++ b/advisories/unreviewed/2024/04/GHSA-jfv3-gh3j-c5r7/GHSA-jfv3-gh3j-c5r7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jfv3-gh3j-c5r7", - "modified": "2024-04-17T00:30:54Z", + "modified": "2024-04-26T09:30:33Z", "published": "2024-04-17T00:30:54Z", "aliases": [ "CVE-2024-21000" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21000" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0013" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-jmgx-64x4-v838/GHSA-jmgx-64x4-v838.json b/advisories/unreviewed/2024/04/GHSA-jmgx-64x4-v838/GHSA-jmgx-64x4-v838.json index e071eababc8..83114be2b4f 100644 --- a/advisories/unreviewed/2024/04/GHSA-jmgx-64x4-v838/GHSA-jmgx-64x4-v838.json +++ b/advisories/unreviewed/2024/04/GHSA-jmgx-64x4-v838/GHSA-jmgx-64x4-v838.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jmgx-64x4-v838", - "modified": "2024-04-17T00:30:55Z", + "modified": "2024-04-26T09:30:34Z", "published": "2024-04-17T00:30:55Z", "aliases": [ "CVE-2024-21056" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21056" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0012" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-p2wq-4ggp-45f3/GHSA-p2wq-4ggp-45f3.json b/advisories/unreviewed/2024/04/GHSA-p2wq-4ggp-45f3/GHSA-p2wq-4ggp-45f3.json new file mode 100644 index 00000000000..437d635b84f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-p2wq-4ggp-45f3/GHSA-p2wq-4ggp-45f3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2wq-4ggp-45f3", + "modified": "2024-04-26T09:30:34Z", + "published": "2024-04-26T09:30:34Z", + "aliases": [ + "CVE-2024-22091" + ], + "details": "Mattermost versions 8.1.x <= 8.1.10, 9.6.x <= 9.6.0, 9.5.x <= 9.5.2 and 8.1.x <= 8.1.11 fail to limit the size of a request path that includes user inputs which allows an attacker to cause excessive resource consumption, possibly leading to a DoS via sending large request paths\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22091" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T09:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pfc3-5g8j-v982/GHSA-pfc3-5g8j-v982.json b/advisories/unreviewed/2024/04/GHSA-pfc3-5g8j-v982/GHSA-pfc3-5g8j-v982.json new file mode 100644 index 00000000000..c9e369f332e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pfc3-5g8j-v982/GHSA-pfc3-5g8j-v982.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfc3-5g8j-v982", + "modified": "2024-04-26T09:30:34Z", + "published": "2024-04-26T09:30:34Z", + "aliases": [ + "CVE-2024-33598" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Twinpictures Annual Archive allows Stored XSS.This issue affects Annual Archive: from n/a through 1.6.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33598" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/anual-archive/wordpress-annual-archive-plugin-1-6-0-cross-site-scripting-xss-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T08:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pj4r-r8f8-qmcc/GHSA-pj4r-r8f8-qmcc.json b/advisories/unreviewed/2024/04/GHSA-pj4r-r8f8-qmcc/GHSA-pj4r-r8f8-qmcc.json new file mode 100644 index 00000000000..e208661dc72 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pj4r-r8f8-qmcc/GHSA-pj4r-r8f8-qmcc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pj4r-r8f8-qmcc", + "modified": "2024-04-26T09:30:34Z", + "published": "2024-04-26T09:30:34Z", + "aliases": [ + "CVE-2024-33650" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Cryout Creations Serious Slider.This issue affects Serious Slider: from n/a through 1.2.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33650" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cryout-serious-slider/wordpress-serious-slider-plugin-1-2-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T08:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pprv-m73j-58qg/GHSA-pprv-m73j-58qg.json b/advisories/unreviewed/2024/04/GHSA-pprv-m73j-58qg/GHSA-pprv-m73j-58qg.json new file mode 100644 index 00000000000..6ab25a63f11 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pprv-m73j-58qg/GHSA-pprv-m73j-58qg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pprv-m73j-58qg", + "modified": "2024-04-26T09:30:34Z", + "published": "2024-04-26T09:30:34Z", + "aliases": [ + "CVE-2024-2920" + ], + "details": "The WP-Members Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.4.9.3 due to the plugin uploading user supplied files to a publicly accessible directory in wp-content without any restrictions. This makes it possible for unauthenticated attackers to view files uploaded by other users which may contain sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2920" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3074215%40wp-members&new=3074215%40wp-members&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4319fa2e-8826-4100-9156-cbe80582367e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T08:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-q4c6-w389-xqq6/GHSA-q4c6-w389-xqq6.json b/advisories/unreviewed/2024/04/GHSA-q4c6-w389-xqq6/GHSA-q4c6-w389-xqq6.json index 957651fd204..8be5a4ef4aa 100644 --- a/advisories/unreviewed/2024/04/GHSA-q4c6-w389-xqq6/GHSA-q4c6-w389-xqq6.json +++ b/advisories/unreviewed/2024/04/GHSA-q4c6-w389-xqq6/GHSA-q4c6-w389-xqq6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q4c6-w389-xqq6", - "modified": "2024-04-22T15:30:40Z", + "modified": "2024-04-26T09:30:34Z", "published": "2024-04-17T00:30:56Z", "aliases": [ "CVE-2024-21068" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00014.html" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0004" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-q4p9-39fv-h479/GHSA-q4p9-39fv-h479.json b/advisories/unreviewed/2024/04/GHSA-q4p9-39fv-h479/GHSA-q4p9-39fv-h479.json new file mode 100644 index 00000000000..5c868cd50c5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-q4p9-39fv-h479/GHSA-q4p9-39fv-h479.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4p9-39fv-h479", + "modified": "2024-04-26T09:30:34Z", + "published": "2024-04-26T09:30:34Z", + "aliases": [ + "CVE-2023-6096" + ], + "details": "\nVladimir Kononovich, a Security Researcher has found a flaw that using a inappropriate encryption logic on the DVR. firmware encryption is broken and allows to decrypt. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6096" + }, + { + "type": "WEB", + "url": "https://www.hanwhavision.com/wp-content/uploads/2024/04/NVR-DVR-Vulnerability-Report-CVE-2023-6095-6096.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-668" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T08:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-r27r-5fwh-vxqw/GHSA-r27r-5fwh-vxqw.json b/advisories/unreviewed/2024/04/GHSA-r27r-5fwh-vxqw/GHSA-r27r-5fwh-vxqw.json index 91487888fd2..37d5eeea366 100644 --- a/advisories/unreviewed/2024/04/GHSA-r27r-5fwh-vxqw/GHSA-r27r-5fwh-vxqw.json +++ b/advisories/unreviewed/2024/04/GHSA-r27r-5fwh-vxqw/GHSA-r27r-5fwh-vxqw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r27r-5fwh-vxqw", - "modified": "2024-04-17T00:30:55Z", + "modified": "2024-04-26T09:30:34Z", "published": "2024-04-17T00:30:55Z", "aliases": [ "CVE-2024-21062" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21062" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0013" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-r345-8c48-x279/GHSA-r345-8c48-x279.json b/advisories/unreviewed/2024/04/GHSA-r345-8c48-x279/GHSA-r345-8c48-x279.json index f4d6414081b..ceba1eca9c6 100644 --- a/advisories/unreviewed/2024/04/GHSA-r345-8c48-x279/GHSA-r345-8c48-x279.json +++ b/advisories/unreviewed/2024/04/GHSA-r345-8c48-x279/GHSA-r345-8c48-x279.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r345-8c48-x279", - "modified": "2024-04-17T00:30:55Z", + "modified": "2024-04-26T09:30:34Z", "published": "2024-04-17T00:30:55Z", "aliases": [ "CVE-2024-21054" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21054" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0013" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-r5cc-f7pr-5v73/GHSA-r5cc-f7pr-5v73.json b/advisories/unreviewed/2024/04/GHSA-r5cc-f7pr-5v73/GHSA-r5cc-f7pr-5v73.json index b29c51a099b..4f3bf87499d 100644 --- a/advisories/unreviewed/2024/04/GHSA-r5cc-f7pr-5v73/GHSA-r5cc-f7pr-5v73.json +++ b/advisories/unreviewed/2024/04/GHSA-r5cc-f7pr-5v73/GHSA-r5cc-f7pr-5v73.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r5cc-f7pr-5v73", - "modified": "2024-04-17T00:30:54Z", + "modified": "2024-04-26T09:30:33Z", "published": "2024-04-17T00:30:54Z", "aliases": [ "CVE-2024-21004" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21004" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0004" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-v98m-62r5-hvcm/GHSA-v98m-62r5-hvcm.json b/advisories/unreviewed/2024/04/GHSA-v98m-62r5-hvcm/GHSA-v98m-62r5-hvcm.json index f5ff081378b..dc53192dd83 100644 --- a/advisories/unreviewed/2024/04/GHSA-v98m-62r5-hvcm/GHSA-v98m-62r5-hvcm.json +++ b/advisories/unreviewed/2024/04/GHSA-v98m-62r5-hvcm/GHSA-v98m-62r5-hvcm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v98m-62r5-hvcm", - "modified": "2024-04-17T00:30:55Z", + "modified": "2024-04-26T09:30:34Z", "published": "2024-04-17T00:30:55Z", "aliases": [ "CVE-2024-21051" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21051" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0012" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-vx97-8q8q-qgq5/GHSA-vx97-8q8q-qgq5.json b/advisories/unreviewed/2024/04/GHSA-vx97-8q8q-qgq5/GHSA-vx97-8q8q-qgq5.json new file mode 100644 index 00000000000..8d9ef6d2954 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vx97-8q8q-qgq5/GHSA-vx97-8q8q-qgq5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vx97-8q8q-qgq5", + "modified": "2024-04-26T09:30:34Z", + "published": "2024-04-26T09:30:34Z", + "aliases": [ + "CVE-2024-32046" + ], + "details": "Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error messages in API requests even if the developer mode is off which allows an attacker to get information about the server such as the full path were files are stored\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32046" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T09:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-w8q4-gvf3-wvfq/GHSA-w8q4-gvf3-wvfq.json b/advisories/unreviewed/2024/04/GHSA-w8q4-gvf3-wvfq/GHSA-w8q4-gvf3-wvfq.json new file mode 100644 index 00000000000..cd80750350f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-w8q4-gvf3-wvfq/GHSA-w8q4-gvf3-wvfq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8q4-gvf3-wvfq", + "modified": "2024-04-26T09:30:34Z", + "published": "2024-04-26T09:30:34Z", + "aliases": [ + "CVE-2024-33638" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Brijesh Kothari Smart Maintenance Mode.This issue affects Smart Maintenance Mode: from n/a through 1.4.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33638" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/smart-maintenance-mode/wordpress-smart-maintenance-mode-plugin-1-4-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T08:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wg7v-w4x5-xvmx/GHSA-wg7v-w4x5-xvmx.json b/advisories/unreviewed/2024/04/GHSA-wg7v-w4x5-xvmx/GHSA-wg7v-w4x5-xvmx.json index 371532415df..eea5b68ca44 100644 --- a/advisories/unreviewed/2024/04/GHSA-wg7v-w4x5-xvmx/GHSA-wg7v-w4x5-xvmx.json +++ b/advisories/unreviewed/2024/04/GHSA-wg7v-w4x5-xvmx/GHSA-wg7v-w4x5-xvmx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wg7v-w4x5-xvmx", - "modified": "2024-04-17T00:30:54Z", + "modified": "2024-04-26T09:30:33Z", "published": "2024-04-17T00:30:54Z", "aliases": [ "CVE-2024-21003" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21003" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0004" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-wh99-p93p-g825/GHSA-wh99-p93p-g825.json b/advisories/unreviewed/2024/04/GHSA-wh99-p93p-g825/GHSA-wh99-p93p-g825.json index b136ed683c7..b07642d681d 100644 --- a/advisories/unreviewed/2024/04/GHSA-wh99-p93p-g825/GHSA-wh99-p93p-g825.json +++ b/advisories/unreviewed/2024/04/GHSA-wh99-p93p-g825/GHSA-wh99-p93p-g825.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wh99-p93p-g825", - "modified": "2024-04-17T00:30:56Z", + "modified": "2024-04-26T09:30:34Z", "published": "2024-04-17T00:30:56Z", "aliases": [ "CVE-2024-21069" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21069" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240426-0013" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/04/GHSA-wj37-mpq9-xrcm/GHSA-wj37-mpq9-xrcm.json b/advisories/unreviewed/2024/04/GHSA-wj37-mpq9-xrcm/GHSA-wj37-mpq9-xrcm.json new file mode 100644 index 00000000000..c1281d80387 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wj37-mpq9-xrcm/GHSA-wj37-mpq9-xrcm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wj37-mpq9-xrcm", + "modified": "2024-04-26T09:30:34Z", + "published": "2024-04-26T09:30:34Z", + "aliases": [ + "CVE-2024-4183" + ], + "details": "Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the number of active sessions, which allows an authenticated attacker to crash the server via repeated requests to the getSessions API after flooding the sessions table.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4183" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T09:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-x78r-qrp5-rmmf/GHSA-x78r-qrp5-rmmf.json b/advisories/unreviewed/2024/04/GHSA-x78r-qrp5-rmmf/GHSA-x78r-qrp5-rmmf.json new file mode 100644 index 00000000000..cd2c7114c8d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-x78r-qrp5-rmmf/GHSA-x78r-qrp5-rmmf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x78r-qrp5-rmmf", + "modified": "2024-04-26T09:30:34Z", + "published": "2024-04-26T09:30:34Z", + "aliases": [ + "CVE-2023-6116" + ], + "details": "\nTeam ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the camera. An attacker could inject malicious into http request packets to execute arbitrary code. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6116" + }, + { + "type": "WEB", + "url": "https://www.hanwhavision.com/wp-content/uploads/2024/04/NVR-DVR-Vulnerability-Report-CVE-2023-6116.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T08:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xg8r-x2wg-m4m7/GHSA-xg8r-x2wg-m4m7.json b/advisories/unreviewed/2024/04/GHSA-xg8r-x2wg-m4m7/GHSA-xg8r-x2wg-m4m7.json new file mode 100644 index 00000000000..d6c2397c7dc --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xg8r-x2wg-m4m7/GHSA-xg8r-x2wg-m4m7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xg8r-x2wg-m4m7", + "modified": "2024-04-26T09:30:34Z", + "published": "2024-04-26T09:30:34Z", + "aliases": [ + "CVE-2023-6095" + ], + "details": "\nVladimir Kononovich, a Security Researcher has found a flaw that allows for a remote code execution on the DVR. An attacker could inject malicious HTTP headers into request packets to execute arbitrary code. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6095" + }, + { + "type": "WEB", + "url": "https://www.hanwhavision.com/wp-content/uploads/2024/04/NVR-DVR-Vulnerability-Report-CVE-2023-6095-6096.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T08:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xhvg-2jp2-9c4h/GHSA-xhvg-2jp2-9c4h.json b/advisories/unreviewed/2024/04/GHSA-xhvg-2jp2-9c4h/GHSA-xhvg-2jp2-9c4h.json new file mode 100644 index 00000000000..18c0cfb574b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xhvg-2jp2-9c4h/GHSA-xhvg-2jp2-9c4h.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhvg-2jp2-9c4h", + "modified": "2024-04-26T09:30:34Z", + "published": "2024-04-26T09:30:34Z", + "aliases": [ + "CVE-2024-3890" + ], + "details": "The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Calendly widget in all versions up to, and including, 3.10.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3890" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3076871/happy-elementor-addons/trunk/widgets/calendly/widget.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/22e4eb2a-2c2b-4f4f-821e-8d2d7e558364?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T08:15:13Z" + } +} \ No newline at end of file