mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-v9pp-h525-vwm9 GHSA-8xr9-89pc-8wcx GHSA-c274-3m34-wwp8 GHSA-868q-j7qx-m3gf GHSA-pvhv-2w8w-pf3x GHSA-pxw4-6qw4-jp6w GHSA-vf7h-r8hg-75jj GHSA-vpj9-v2pp-24wp GHSA-x9mq-h652-rw6x GHSA-24v2-mrj2-4wpc GHSA-3wv8-q6g7-7frh GHSA-5wmg-fqv9-w9qf GHSA-7x7r-gpvw-q53f GHSA-9w8w-fgjg-w972 GHSA-c286-9hvr-9fmm GHSA-fh3v-99xx-v7cw GHSA-fv2q-p9cw-m9w5 GHSA-h6vm-3gjm-rw54 GHSA-mjf9-4pcv-vfg7 GHSA-vh28-f7wh-hg42 GHSA-vw56-cch3-67cp GHSA-wgc3-34qh-3h44
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-v9pp-h525-vwm9",
|
||||
"modified": "2023-11-25T12:30:22Z",
|
||||
"modified": "2025-01-08T15:31:06Z",
|
||||
"published": "2023-06-07T21:30:18Z",
|
||||
"aliases": [
|
||||
"CVE-2023-33863"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-8xr9-89pc-8wcx",
|
||||
"modified": "2024-04-20T00:31:52Z",
|
||||
"modified": "2025-01-08T15:31:06Z",
|
||||
"published": "2024-04-04T18:30:33Z",
|
||||
"aliases": [
|
||||
"CVE-2024-25690"
|
||||
@@ -30,6 +30,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-79",
|
||||
"CWE-80"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
|
||||
@@ -26,6 +26,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-203",
|
||||
"CWE-416"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
|
||||
@@ -26,6 +26,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-362",
|
||||
"CWE-416"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
|
||||
@@ -26,6 +26,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-362",
|
||||
"CWE-416"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
|
||||
@@ -26,6 +26,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-362",
|
||||
"CWE-415"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-vf7h-r8hg-75jj",
|
||||
"modified": "2025-01-06T18:31:01Z",
|
||||
"modified": "2025-01-08T15:31:09Z",
|
||||
"published": "2024-12-31T12:30:44Z",
|
||||
"aliases": [
|
||||
"CVE-2024-12105"
|
||||
@@ -22,6 +22,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.progress.com/network-monitoring"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2089"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -26,6 +26,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-362",
|
||||
"CWE-416"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
|
||||
@@ -26,6 +26,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-362",
|
||||
"CWE-59"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
|
||||
@@ -1,13 +1,18 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-24v2-mrj2-4wpc",
|
||||
"modified": "2025-01-07T18:30:50Z",
|
||||
"modified": "2025-01-08T15:31:09Z",
|
||||
"published": "2025-01-07T18:30:50Z",
|
||||
"aliases": [
|
||||
"CVE-2025-0247"
|
||||
],
|
||||
"details": "Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 134.",
|
||||
"severity": [],
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
@@ -25,7 +30,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-01-07T16:15:39Z"
|
||||
|
||||
@@ -1,13 +1,18 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-3wv8-q6g7-7frh",
|
||||
"modified": "2025-01-07T21:30:55Z",
|
||||
"modified": "2025-01-08T15:31:10Z",
|
||||
"published": "2025-01-07T21:30:55Z",
|
||||
"aliases": [
|
||||
"CVE-2022-41572"
|
||||
],
|
||||
"details": "An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Privilege escalation can be accomplished on the server because nmap can be run as root. The attacker achieves total control over the server.",
|
||||
"severity": [],
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
@@ -24,8 +29,10 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"cwe_ids": [
|
||||
"CWE-276"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-01-07T20:15:27Z"
|
||||
|
||||
@@ -1,13 +1,18 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-5wmg-fqv9-w9qf",
|
||||
"modified": "2025-01-07T18:30:52Z",
|
||||
"modified": "2025-01-08T15:31:09Z",
|
||||
"published": "2025-01-07T18:30:51Z",
|
||||
"aliases": [
|
||||
"CVE-2024-40748"
|
||||
],
|
||||
"details": "Lack of output escaping in the id attribute of menu lists.",
|
||||
"severity": [],
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
@@ -23,7 +28,7 @@
|
||||
"cwe_ids": [
|
||||
"CWE-79"
|
||||
],
|
||||
"severity": null,
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-01-07T17:15:23Z"
|
||||
|
||||
@@ -1,13 +1,18 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-7x7r-gpvw-q53f",
|
||||
"modified": "2025-01-07T21:30:55Z",
|
||||
"modified": "2025-01-08T15:31:10Z",
|
||||
"published": "2025-01-07T21:30:55Z",
|
||||
"aliases": [
|
||||
"CVE-2024-55218"
|
||||
],
|
||||
"details": "IceWarp Server 10.2.1 is vulnerable to Cross Site Scripting (XSS) via the meta parameter.",
|
||||
"severity": [],
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
@@ -24,8 +29,10 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"cwe_ids": [
|
||||
"CWE-79"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-01-07T20:15:30Z"
|
||||
|
||||
@@ -1,13 +1,18 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-9w8w-fgjg-w972",
|
||||
"modified": "2025-01-07T21:30:55Z",
|
||||
"modified": "2025-01-08T15:31:10Z",
|
||||
"published": "2025-01-07T21:30:55Z",
|
||||
"aliases": [
|
||||
"CVE-2024-54819"
|
||||
],
|
||||
"details": "I, Librarian before and including 5.11.1 is vulnerable to Server-Side Request Forgery (SSRF) due to improper input validation in classes/security/validation.php",
|
||||
"severity": [],
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
@@ -24,8 +29,10 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"cwe_ids": [
|
||||
"CWE-918"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-01-07T20:15:30Z"
|
||||
|
||||
@@ -1,13 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-c286-9hvr-9fmm",
|
||||
"modified": "2025-01-08T09:30:38Z",
|
||||
"modified": "2025-01-08T15:31:11Z",
|
||||
"published": "2025-01-08T09:30:38Z",
|
||||
"aliases": [
|
||||
"CVE-2024-13173"
|
||||
],
|
||||
"details": "The health module has insufficient restrictions on loading URLs, which may lead to some information leakage.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
|
||||
},
|
||||
{
|
||||
"type": "CVSS_V4",
|
||||
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
|
||||
|
||||
@@ -1,13 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-fh3v-99xx-v7cw",
|
||||
"modified": "2025-01-08T09:30:38Z",
|
||||
"modified": "2025-01-08T15:31:11Z",
|
||||
"published": "2025-01-08T09:30:38Z",
|
||||
"aliases": [
|
||||
"CVE-2024-13186"
|
||||
],
|
||||
"details": "The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
|
||||
},
|
||||
{
|
||||
"type": "CVSS_V4",
|
||||
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
|
||||
|
||||
@@ -1,13 +1,18 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-fv2q-p9cw-m9w5",
|
||||
"modified": "2025-01-07T21:30:55Z",
|
||||
"modified": "2025-01-08T15:31:10Z",
|
||||
"published": "2025-01-07T21:30:55Z",
|
||||
"aliases": [
|
||||
"CVE-2024-35532"
|
||||
],
|
||||
"details": "An XML External Entity (XXE) injection vulnerability in Intersec Geosafe-ea 2022.12, 2022.13, and 2022.14 allows attackers to perform arbitrary file reading under the privileges of the running process, make SSRF requests, or cause a Denial of Service (DoS) via unspecified vectors.",
|
||||
"severity": [],
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
@@ -24,8 +29,10 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"cwe_ids": [
|
||||
"CWE-125"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-01-07T20:15:29Z"
|
||||
|
||||
@@ -1,13 +1,18 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-h6vm-3gjm-rw54",
|
||||
"modified": "2025-01-07T18:30:52Z",
|
||||
"modified": "2025-01-08T15:31:09Z",
|
||||
"published": "2025-01-07T18:30:52Z",
|
||||
"aliases": [
|
||||
"CVE-2024-40749"
|
||||
],
|
||||
"details": "Improper Access Controls allows access to protected views.",
|
||||
"severity": [],
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
@@ -23,7 +28,7 @@
|
||||
"cwe_ids": [
|
||||
"CWE-284"
|
||||
],
|
||||
"severity": null,
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-01-07T17:15:23Z"
|
||||
|
||||
@@ -1,13 +1,18 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-mjf9-4pcv-vfg7",
|
||||
"modified": "2025-01-08T09:30:39Z",
|
||||
"modified": "2025-01-08T15:31:11Z",
|
||||
"published": "2025-01-08T09:30:39Z",
|
||||
"aliases": [
|
||||
"CVE-2024-54676"
|
||||
],
|
||||
"details": "Vendor: The Apache Software Foundation\n\nVersions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0\n\nDescription: Default clustering instructions at https://openmeetings.apache.org/Clustering.html doesn't specify white/black lists for OpenJPA this leads to possible deserialisation of untrusted data.\nUsers are recommended to upgrade to version 8.0.0 and update their startup scripts to include the relevant 'openjpa.serialization.class.blacklist' and 'openjpa.serialization.class.whitelist' configurations as shown in the documentation.",
|
||||
"severity": [],
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
@@ -27,7 +32,7 @@
|
||||
"cwe_ids": [
|
||||
"CWE-502"
|
||||
],
|
||||
"severity": null,
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-01-08T09:15:07Z"
|
||||
|
||||
@@ -1,13 +1,18 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-vh28-f7wh-hg42",
|
||||
"modified": "2025-01-07T21:30:55Z",
|
||||
"modified": "2025-01-08T15:31:10Z",
|
||||
"published": "2025-01-07T21:30:55Z",
|
||||
"aliases": [
|
||||
"CVE-2022-41573"
|
||||
],
|
||||
"details": "An issue was discovered in Ovidentia 8.3. The file upload feature does not prevent the uploading of executable files. A user can upload a .png file containing PHP code and then rename it to have the .php extension. It will then be accessible at an images/common/ URI for remote code execution.",
|
||||
"severity": [],
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
@@ -28,8 +33,10 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"cwe_ids": [
|
||||
"CWE-434"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-01-07T20:15:28Z"
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user