From 90eaccfda2c7adfa64ce055f8a084b02bcabb1ab Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 26 Apr 2024 00:31:39 +0000 Subject: [PATCH] Publish Advisories GHSA-45x7-px36-x8w8 GHSA-9fg2-hvwm-63r7 GHSA-f25w-hjcw-x829 GHSA-wccm-6vx2-7p8c GHSA-6c5p-j8vq-pqhj GHSA-6cm9-r25c-5778 GHSA-cjwg-qfpm-7377 GHSA-f24j-hhmv-5ccv GHSA-fh99-9gvw-rw3c GHSA-r8hh-gm8p-9j5x GHSA-rvpg-mqjj-6hqp --- .../GHSA-45x7-px36-x8w8.json | 14 ++++-- .../GHSA-9fg2-hvwm-63r7.json | 6 ++- .../GHSA-f25w-hjcw-x829.json | 14 +++++- .../GHSA-wccm-6vx2-7p8c.json | 6 ++- .../GHSA-6c5p-j8vq-pqhj.json | 35 ++++++++++++++ .../GHSA-6cm9-r25c-5778.json | 47 +++++++++++++++++++ .../GHSA-cjwg-qfpm-7377.json | 39 +++++++++++++++ .../GHSA-f24j-hhmv-5ccv.json | 35 ++++++++++++++ .../GHSA-fh99-9gvw-rw3c.json | 35 ++++++++++++++ .../GHSA-r8hh-gm8p-9j5x.json | 35 ++++++++++++++ .../GHSA-rvpg-mqjj-6hqp.json | 42 +++++++++++++++++ 11 files changed, 300 insertions(+), 8 deletions(-) create mode 100644 advisories/unreviewed/2024/04/GHSA-6c5p-j8vq-pqhj/GHSA-6c5p-j8vq-pqhj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6cm9-r25c-5778/GHSA-6cm9-r25c-5778.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cjwg-qfpm-7377/GHSA-cjwg-qfpm-7377.json create mode 100644 advisories/unreviewed/2024/04/GHSA-f24j-hhmv-5ccv/GHSA-f24j-hhmv-5ccv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-fh99-9gvw-rw3c/GHSA-fh99-9gvw-rw3c.json create mode 100644 advisories/unreviewed/2024/04/GHSA-r8hh-gm8p-9j5x/GHSA-r8hh-gm8p-9j5x.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rvpg-mqjj-6hqp/GHSA-rvpg-mqjj-6hqp.json diff --git a/advisories/github-reviewed/2023/12/GHSA-45x7-px36-x8w8/GHSA-45x7-px36-x8w8.json b/advisories/github-reviewed/2023/12/GHSA-45x7-px36-x8w8/GHSA-45x7-px36-x8w8.json index df8c9c94d3c..bd6391dfc43 100644 --- a/advisories/github-reviewed/2023/12/GHSA-45x7-px36-x8w8/GHSA-45x7-px36-x8w8.json +++ b/advisories/github-reviewed/2023/12/GHSA-45x7-px36-x8w8/GHSA-45x7-px36-x8w8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-45x7-px36-x8w8", - "modified": "2024-03-14T21:48:09Z", + "modified": "2024-04-26T00:30:36Z", "published": "2023-12-18T19:22:09Z", "aliases": [ "CVE-2023-48795" @@ -350,6 +350,10 @@ "type": "WEB", "url": "https://security.gentoo.org/glsa/202312-17" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F7EYCFQCTSGJXWO3ZZ44MGKFC5HA7G3Y" + }, { "type": "WEB", "url": "https://github.com/rapier1/hpn-ssh/releases" @@ -446,10 +450,6 @@ "type": "WEB", "url": "https://access.redhat.com/security/cve/cve-2023-48795" }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F7EYCFQCTSGJXWO3ZZ44MGKFC5HA7G3Y" - }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CHHITS4PUOZAKFIUBQAQZC7JWXMOYE4B" @@ -486,6 +486,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/33XHJUB6ROFUOH2OQNENFROTVH6MHSHA" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00016.html" + }, { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2024/01/msg00014.html" diff --git a/advisories/unreviewed/2022/05/GHSA-9fg2-hvwm-63r7/GHSA-9fg2-hvwm-63r7.json b/advisories/unreviewed/2022/05/GHSA-9fg2-hvwm-63r7/GHSA-9fg2-hvwm-63r7.json index ebdaa395cfe..d221c8be69b 100644 --- a/advisories/unreviewed/2022/05/GHSA-9fg2-hvwm-63r7/GHSA-9fg2-hvwm-63r7.json +++ b/advisories/unreviewed/2022/05/GHSA-9fg2-hvwm-63r7/GHSA-9fg2-hvwm-63r7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9fg2-hvwm-63r7", - "modified": "2022-05-24T16:57:31Z", + "modified": "2024-04-26T00:30:34Z", "published": "2022-05-24T16:57:31Z", "aliases": [ "CVE-2019-17069" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-17069" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00016.html" + }, { "type": "WEB", "url": "https://lists.tartarus.org/pipermail/putty-announce/2019/000029.html" diff --git a/advisories/unreviewed/2022/05/GHSA-f25w-hjcw-x829/GHSA-f25w-hjcw-x829.json b/advisories/unreviewed/2022/05/GHSA-f25w-hjcw-x829/GHSA-f25w-hjcw-x829.json index 4e3d7b5a2ae..adffce3ca6b 100644 --- a/advisories/unreviewed/2022/05/GHSA-f25w-hjcw-x829/GHSA-f25w-hjcw-x829.json +++ b/advisories/unreviewed/2022/05/GHSA-f25w-hjcw-x829/GHSA-f25w-hjcw-x829.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f25w-hjcw-x829", - "modified": "2022-05-24T17:22:01Z", + "modified": "2024-04-26T00:30:35Z", "published": "2022-05-24T17:22:01Z", "aliases": [ "CVE-2020-14002" @@ -21,6 +21,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-14002" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00016.html" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/26TACCSQYYCPWAJYNAUIXJGZ5RGORJZV" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JPV4A77EDCT4BTFO5BE26ZH72BG4E5IJ" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/26TACCSQYYCPWAJYNAUIXJGZ5RGORJZV" diff --git a/advisories/unreviewed/2022/05/GHSA-wccm-6vx2-7p8c/GHSA-wccm-6vx2-7p8c.json b/advisories/unreviewed/2022/05/GHSA-wccm-6vx2-7p8c/GHSA-wccm-6vx2-7p8c.json index 70e74198d18..a8c1042daaa 100644 --- a/advisories/unreviewed/2022/05/GHSA-wccm-6vx2-7p8c/GHSA-wccm-6vx2-7p8c.json +++ b/advisories/unreviewed/2022/05/GHSA-wccm-6vx2-7p8c/GHSA-wccm-6vx2-7p8c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wccm-6vx2-7p8c", - "modified": "2023-12-24T18:30:21Z", + "modified": "2024-04-26T00:30:35Z", "published": "2022-05-24T19:07:19Z", "aliases": [ "CVE-2021-36367" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://git.tartarus.org/?p=simon/putty.git;a=commit;h=1dc5659aa62848f0aeb5de7bd3839fecc7debefa" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00016.html" + }, { "type": "WEB", "url": "https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html" diff --git a/advisories/unreviewed/2024/04/GHSA-6c5p-j8vq-pqhj/GHSA-6c5p-j8vq-pqhj.json b/advisories/unreviewed/2024/04/GHSA-6c5p-j8vq-pqhj/GHSA-6c5p-j8vq-pqhj.json new file mode 100644 index 00000000000..77583efbf8b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6c5p-j8vq-pqhj/GHSA-6c5p-j8vq-pqhj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6c5p-j8vq-pqhj", + "modified": "2024-04-26T00:30:35Z", + "published": "2024-04-26T00:30:35Z", + "aliases": [ + "CVE-2024-33663" + ], + "details": "python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33663" + }, + { + "type": "WEB", + "url": "https://github.com/mpdavis/python-jose/issues/346" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T00:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6cm9-r25c-5778/GHSA-6cm9-r25c-5778.json b/advisories/unreviewed/2024/04/GHSA-6cm9-r25c-5778/GHSA-6cm9-r25c-5778.json new file mode 100644 index 00000000000..5a8e41af3ef --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6cm9-r25c-5778/GHSA-6cm9-r25c-5778.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cm9-r25c-5778", + "modified": "2024-04-26T00:30:35Z", + "published": "2024-04-26T00:30:35Z", + "aliases": [ + "CVE-2024-33661" + ], + "details": "Portainer before 2.20.0 allows redirects when the target is not index.yaml.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33661" + }, + { + "type": "WEB", + "url": "https://github.com/portainer/portainer/pull/11233" + }, + { + "type": "WEB", + "url": "https://github.com/portainer/portainer/pull/11236" + }, + { + "type": "WEB", + "url": "https://github.com/portainer/portainer/compare/2.19.4...2.20.0" + }, + { + "type": "WEB", + "url": "https://www.portainer.io" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T00:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cjwg-qfpm-7377/GHSA-cjwg-qfpm-7377.json b/advisories/unreviewed/2024/04/GHSA-cjwg-qfpm-7377/GHSA-cjwg-qfpm-7377.json new file mode 100644 index 00000000000..658d7e49362 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cjwg-qfpm-7377/GHSA-cjwg-qfpm-7377.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjwg-qfpm-7377", + "modified": "2024-04-26T00:30:35Z", + "published": "2024-04-26T00:30:35Z", + "aliases": [ + "CVE-2024-33664" + ], + "details": "python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a \"JWT bomb.\" This is similar to CVE-2024-21319.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33664" + }, + { + "type": "WEB", + "url": "https://github.com/mpdavis/python-jose/issues/344" + }, + { + "type": "WEB", + "url": "https://github.com/mpdavis/python-jose/pull/345" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-26T00:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-f24j-hhmv-5ccv/GHSA-f24j-hhmv-5ccv.json b/advisories/unreviewed/2024/04/GHSA-f24j-hhmv-5ccv/GHSA-f24j-hhmv-5ccv.json new file mode 100644 index 00000000000..0f293ffdefe --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-f24j-hhmv-5ccv/GHSA-f24j-hhmv-5ccv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f24j-hhmv-5ccv", + "modified": "2024-04-26T00:30:35Z", + "published": "2024-04-26T00:30:35Z", + "aliases": [ + "CVE-2024-31609" + ], + "details": "Cross Site Scripting (XSS) vulnerability in BOSSCMS v3.10 allows attackers to run arbitrary code via the header code and footer code fields in code configuration.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31609" + }, + { + "type": "WEB", + "url": "https://github.com/ss122-0ss/BOSSCMS/blob/main/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-25T22:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fh99-9gvw-rw3c/GHSA-fh99-9gvw-rw3c.json b/advisories/unreviewed/2024/04/GHSA-fh99-9gvw-rw3c/GHSA-fh99-9gvw-rw3c.json new file mode 100644 index 00000000000..1106573d212 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fh99-9gvw-rw3c/GHSA-fh99-9gvw-rw3c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fh99-9gvw-rw3c", + "modified": "2024-04-26T00:30:35Z", + "published": "2024-04-26T00:30:35Z", + "aliases": [ + "CVE-2024-3265" + ], + "details": "The Advanced Search WordPress plugin through 1.1.6 does not properly escape parameters appended to an SQL query, making it possible for users with the administrator role to conduct SQL Injection attacks in the context of a multisite WordPress configurations.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3265" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/ecb74622-eeed-48b6-a944-4e3494d6594d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-25T22:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-r8hh-gm8p-9j5x/GHSA-r8hh-gm8p-9j5x.json b/advisories/unreviewed/2024/04/GHSA-r8hh-gm8p-9j5x/GHSA-r8hh-gm8p-9j5x.json new file mode 100644 index 00000000000..12208ef882f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-r8hh-gm8p-9j5x/GHSA-r8hh-gm8p-9j5x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r8hh-gm8p-9j5x", + "modified": "2024-04-26T00:30:35Z", + "published": "2024-04-26T00:30:35Z", + "aliases": [ + "CVE-2024-31610" + ], + "details": "File Upload vulnerability in the function for employees to upload avatars in Code-Projects Simple School Management System v1.0 allows attackers to run arbitrary code via upload of crafted file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31610" + }, + { + "type": "WEB", + "url": "https://github.com/ss122-0ss/School/blob/main/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-25T22:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rvpg-mqjj-6hqp/GHSA-rvpg-mqjj-6hqp.json b/advisories/unreviewed/2024/04/GHSA-rvpg-mqjj-6hqp/GHSA-rvpg-mqjj-6hqp.json new file mode 100644 index 00000000000..39d28a23a12 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rvpg-mqjj-6hqp/GHSA-rvpg-mqjj-6hqp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvpg-mqjj-6hqp", + "modified": "2024-04-26T00:30:35Z", + "published": "2024-04-26T00:30:35Z", + "aliases": [ + "CVE-2024-0916" + ], + "details": "Unauthenticated file upload allows remote code execution.\nThis issue affects UvDesk Community: from 1.0.0 through 1.1.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0916" + }, + { + "type": "WEB", + "url": "https://github.com/uvdesk/core-framework/pull/706" + }, + { + "type": "WEB", + "url": "https://pentraze.com/vulnerability-reports" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-25T23:15:46Z" + } +} \ No newline at end of file