Publish Advisories

GHSA-3vp4-9c6g-mcq2
GHSA-8q5c-h63v-v869
GHSA-gc8p-39g7-4mhp
GHSA-p9h5-83v6-32fq
GHSA-pfmv-h3cf-mr72
This commit is contained in:
advisory-database[bot]
2024-05-08 06:32:45 +00:00
parent eab4740bc6
commit 935df55252
5 changed files with 192 additions and 0 deletions
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3vp4-9c6g-mcq2",
"modified": "2024-05-08T06:30:48Z",
"published": "2024-05-08T06:30:48Z",
"aliases": [
"CVE-2024-32674"
],
"details": "Heateor Social Login WordPress prior to 1.1.32 contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32674"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/jp/JVN87694318"
},
{
"type": "WEB",
"url": "https://wordpress.org/plugins/heateor-social-login"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-08T04:15:09Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8q5c-h63v-v869",
"modified": "2024-05-08T06:30:48Z",
"published": "2024-05-08T06:30:48Z",
"aliases": [
"CVE-2024-1076"
],
"details": "The SSL Zen WordPress plugin before 4.6.0 only relies on the use of .htaccess to prevent visitors from accessing the site's generated private keys, which allows an attacker to read them if the site runs on a server who doesn't support .htaccess files, like NGINX.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1076"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/9c3e9c72-3d6c-4e2c-bb8a-f4efce1371d5"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-08T06:15:06Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gc8p-39g7-4mhp",
"modified": "2024-05-08T06:30:48Z",
"published": "2024-05-08T06:30:48Z",
"aliases": [
"CVE-2024-3494"
],
"details": "The Mesmerize Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mesmerize_contact_form' shortcode in all versions up to, and including, 1.6.148 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3494"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3078422/mesmerize-companion/trunk/theme-data/mesmerize/functions.php"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/521bb5a3-0a0c-4693-a87d-fabb64f1ad4f?source=cve"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-08T06:15:07Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p9h5-83v6-32fq",
"modified": "2024-05-08T06:30:48Z",
"published": "2024-05-08T06:30:48Z",
"aliases": [
"CVE-2024-22266"
],
"details": " VMware Avi Load Balancer contains an information disclosure vulnerability. A malicious actor with access to the system logs can view cloud connection credentials in plaintext.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22266"
},
{
"type": "WEB",
"url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24219"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-08T04:15:09Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pfmv-h3cf-mr72",
"modified": "2024-05-08T06:30:48Z",
"published": "2024-05-08T06:30:48Z",
"aliases": [
"CVE-2024-22264"
],
"details": "VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious actor with admin privileges on VMware Avi Load Balancer can create, modify, execute and delete files as a root user on the host system.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22264"
},
{
"type": "WEB",
"url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24219"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-08T04:15:08Z"
}
}