Publish Advisories

GHSA-45x7-px36-x8w8
GHSA-9fg2-hvwm-63r7
GHSA-f25w-hjcw-x829
GHSA-wccm-6vx2-7p8c
GHSA-6c5p-j8vq-pqhj
GHSA-6cm9-r25c-5778
GHSA-cjwg-qfpm-7377
GHSA-f24j-hhmv-5ccv
GHSA-fh99-9gvw-rw3c
GHSA-r8hh-gm8p-9j5x
GHSA-rvpg-mqjj-6hqp
This commit is contained in:
advisory-database[bot]
2024-04-26 00:31:39 +00:00
parent 8e25235138
commit 90eaccfda2
11 changed files with 300 additions and 8 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-45x7-px36-x8w8",
"modified": "2024-03-14T21:48:09Z",
"modified": "2024-04-26T00:30:36Z",
"published": "2023-12-18T19:22:09Z",
"aliases": [
"CVE-2023-48795"
@@ -350,6 +350,10 @@
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202312-17"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F7EYCFQCTSGJXWO3ZZ44MGKFC5HA7G3Y"
},
{
"type": "WEB",
"url": "https://github.com/rapier1/hpn-ssh/releases"
@@ -446,10 +450,6 @@
"type": "WEB",
"url": "https://access.redhat.com/security/cve/cve-2023-48795"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F7EYCFQCTSGJXWO3ZZ44MGKFC5HA7G3Y"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CHHITS4PUOZAKFIUBQAQZC7JWXMOYE4B"
@@ -486,6 +486,10 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/33XHJUB6ROFUOH2OQNENFROTVH6MHSHA"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00016.html"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/01/msg00014.html"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9fg2-hvwm-63r7",
"modified": "2022-05-24T16:57:31Z",
"modified": "2024-04-26T00:30:34Z",
"published": "2022-05-24T16:57:31Z",
"aliases": [
"CVE-2019-17069"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2019-17069"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00016.html"
},
{
"type": "WEB",
"url": "https://lists.tartarus.org/pipermail/putty-announce/2019/000029.html"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f25w-hjcw-x829",
"modified": "2022-05-24T17:22:01Z",
"modified": "2024-04-26T00:30:35Z",
"published": "2022-05-24T17:22:01Z",
"aliases": [
"CVE-2020-14002"
@@ -21,6 +21,18 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-14002"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00016.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/26TACCSQYYCPWAJYNAUIXJGZ5RGORJZV"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JPV4A77EDCT4BTFO5BE26ZH72BG4E5IJ"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/26TACCSQYYCPWAJYNAUIXJGZ5RGORJZV"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wccm-6vx2-7p8c",
"modified": "2023-12-24T18:30:21Z",
"modified": "2024-04-26T00:30:35Z",
"published": "2022-05-24T19:07:19Z",
"aliases": [
"CVE-2021-36367"
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://git.tartarus.org/?p=simon/putty.git;a=commit;h=1dc5659aa62848f0aeb5de7bd3839fecc7debefa"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00016.html"
},
{
"type": "WEB",
"url": "https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6c5p-j8vq-pqhj",
"modified": "2024-04-26T00:30:35Z",
"published": "2024-04-26T00:30:35Z",
"aliases": [
"CVE-2024-33663"
],
"details": "python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33663"
},
{
"type": "WEB",
"url": "https://github.com/mpdavis/python-jose/issues/346"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-26T00:15:09Z"
}
}
@@ -0,0 +1,47 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6cm9-r25c-5778",
"modified": "2024-04-26T00:30:35Z",
"published": "2024-04-26T00:30:35Z",
"aliases": [
"CVE-2024-33661"
],
"details": "Portainer before 2.20.0 allows redirects when the target is not index.yaml.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33661"
},
{
"type": "WEB",
"url": "https://github.com/portainer/portainer/pull/11233"
},
{
"type": "WEB",
"url": "https://github.com/portainer/portainer/pull/11236"
},
{
"type": "WEB",
"url": "https://github.com/portainer/portainer/compare/2.19.4...2.20.0"
},
{
"type": "WEB",
"url": "https://www.portainer.io"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-26T00:15:08Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cjwg-qfpm-7377",
"modified": "2024-04-26T00:30:35Z",
"published": "2024-04-26T00:30:35Z",
"aliases": [
"CVE-2024-33664"
],
"details": "python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a \"JWT bomb.\" This is similar to CVE-2024-21319.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33664"
},
{
"type": "WEB",
"url": "https://github.com/mpdavis/python-jose/issues/344"
},
{
"type": "WEB",
"url": "https://github.com/mpdavis/python-jose/pull/345"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-26T00:15:09Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f24j-hhmv-5ccv",
"modified": "2024-04-26T00:30:35Z",
"published": "2024-04-26T00:30:35Z",
"aliases": [
"CVE-2024-31609"
],
"details": "Cross Site Scripting (XSS) vulnerability in BOSSCMS v3.10 allows attackers to run arbitrary code via the header code and footer code fields in code configuration.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31609"
},
{
"type": "WEB",
"url": "https://github.com/ss122-0ss/BOSSCMS/blob/main/readme.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-25T22:15:08Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fh99-9gvw-rw3c",
"modified": "2024-04-26T00:30:35Z",
"published": "2024-04-26T00:30:35Z",
"aliases": [
"CVE-2024-3265"
],
"details": "The Advanced Search WordPress plugin through 1.1.6 does not properly escape parameters appended to an SQL query, making it possible for users with the administrator role to conduct SQL Injection attacks in the context of a multisite WordPress configurations.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3265"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/ecb74622-eeed-48b6-a944-4e3494d6594d"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-25T22:15:09Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r8hh-gm8p-9j5x",
"modified": "2024-04-26T00:30:35Z",
"published": "2024-04-26T00:30:35Z",
"aliases": [
"CVE-2024-31610"
],
"details": "File Upload vulnerability in the function for employees to upload avatars in Code-Projects Simple School Management System v1.0 allows attackers to run arbitrary code via upload of crafted file.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31610"
},
{
"type": "WEB",
"url": "https://github.com/ss122-0ss/School/blob/main/readme.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-25T22:15:08Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rvpg-mqjj-6hqp",
"modified": "2024-04-26T00:30:35Z",
"published": "2024-04-26T00:30:35Z",
"aliases": [
"CVE-2024-0916"
],
"details": "Unauthenticated file upload allows remote code execution.\nThis issue affects UvDesk Community: from 1.0.0 through 1.1.3.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0916"
},
{
"type": "WEB",
"url": "https://github.com/uvdesk/core-framework/pull/706"
},
{
"type": "WEB",
"url": "https://pentraze.com/vulnerability-reports"
}
],
"database_specific": {
"cwe_ids": [
"CWE-434"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-25T23:15:46Z"
}
}