From 9431ad34c7737fd2ede9d6d0bce3a4a8cf0ed6b1 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 27 Sep 2024 18:34:10 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-25x7-989g-366h.json | 1 + .../GHSA-36qx-fccg-6873.json | 3 +- .../GHSA-6jw3-xmj9-qvcw.json | 1 + .../GHSA-c948-477j-77c3.json | 1 + .../GHSA-32h2-7245-4mh4.json | 1 + .../GHSA-c467-vf3v-2g2q.json | 3 +- .../GHSA-q8rx-w8h7-j8xw.json | 3 +- .../GHSA-qfrv-fmc5-hmmh.json | 1 + .../GHSA-xhg6-78jc-3cwf.json | 1 + .../GHSA-q4mq-w4v3-mv77.json | 3 +- .../GHSA-345m-8c2p-v3fj.json | 1 + .../GHSA-cp7v-2p64-673r.json | 3 +- .../GHSA-hx98-fgmp-472p.json | 3 +- .../GHSA-75w9-x6cm-hvwg.json | 6 +- .../GHSA-qq8g-mc9v-7pv4.json | 1 + .../GHSA-w49g-9f3f-c384.json | 6 +- .../GHSA-2wpc-6fxg-xpcf.json | 11 ++-- .../GHSA-2wr3-8g8v-wc39.json | 9 ++- .../GHSA-36xh-276f-w5j9.json | 2 +- .../GHSA-3gv3-rgph-2cgp.json | 11 ++-- .../GHSA-3mp4-p7x2-73pw.json | 2 +- .../GHSA-42m7-33x8-mvrh.json | 38 ++++++++++++ .../GHSA-459r-mr42-wfpg.json | 11 ++-- .../GHSA-4f5w-x884-92x8.json | 11 ++-- .../GHSA-5rqg-4vpc-fpm2.json | 43 ++++++++++++++ .../GHSA-64jg-5jxr-f8cr.json | 42 ++++++++++++++ .../GHSA-653g-mc33-gq3r.json | 2 +- .../GHSA-6jxj-6j73-7fgm.json | 39 +++++++++++++ .../GHSA-7jwq-r5r6-rxq7.json | 11 ++-- .../GHSA-7pcw-cjv4-c788.json | 42 ++++++++++++++ .../GHSA-7w3c-jwh7-4486.json | 11 ++-- .../GHSA-7wfr-5f4h-3mw7.json | 2 +- .../GHSA-8hrr-r493-96vh.json | 42 ++++++++++++++ .../GHSA-8mgj-fhf8-9275.json | 42 ++++++++++++++ .../GHSA-8xf3-x93c-2ch6.json | 50 ++++++++++++++++ .../GHSA-92rj-4rqf-4mg5.json | 3 +- .../GHSA-9q57-6634-5vrw.json | 2 +- .../GHSA-9xg3-36cq-7vr7.json | 42 ++++++++++++++ .../GHSA-chwj-xj8v-386c.json | 2 +- .../GHSA-crxf-g2j7-6h5p.json | 58 +++++++++++++++++++ .../GHSA-f3pj-vwf5-5vr3.json | 2 +- .../GHSA-g9g7-rmqc-4q4p.json | 43 ++++++++++++++ .../GHSA-gq5m-j7gp-3x7q.json | 2 +- .../GHSA-gvfm-hc65-h2hv.json | 11 ++-- .../GHSA-h4fw-fxpw-rrgp.json | 38 ++++++++++++ .../GHSA-j9h3-rgr4-jg83.json | 42 ++++++++++++++ .../GHSA-jr3c-32f2-p7wg.json | 2 +- .../GHSA-jwxr-qpg5-2pj9.json | 35 +++++++++++ .../GHSA-m7hg-9c63-f5hm.json | 11 ++-- .../GHSA-m8mp-83qq-7j4f.json | 2 +- .../GHSA-mhxx-5693-798f.json | 43 ++++++++++++++ .../GHSA-p52v-vcvw-fcmg.json | 42 ++++++++++++++ .../GHSA-pcj5-c4v2-hq4g.json | 1 + .../GHSA-pq82-r7vq-hfqh.json | 42 ++++++++++++++ .../GHSA-r29x-667c-gv4v.json | 42 ++++++++++++++ .../GHSA-r2gp-x2mf-c5p8.json | 11 ++-- .../GHSA-rr53-gjvx-gr2c.json | 11 ++-- .../GHSA-v6qv-c78w-ff25.json | 42 ++++++++++++++ .../GHSA-vww8-5r8j-mrcr.json | 9 ++- .../GHSA-wj7r-74h6-3r6w.json | 11 ++-- .../GHSA-wqc2-gwgp-9p7w.json | 35 +++++++++++ .../GHSA-wwq9-rfhf-r6h9.json | 35 +++++++++++ .../GHSA-xfx4-9q4j-5v3q.json | 9 ++- .../GHSA-xjwr-gx3m-j7pj.json | 11 ++-- .../GHSA-xwc4-p3cg-mmq4.json | 2 +- 65 files changed, 1023 insertions(+), 77 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-42m7-33x8-mvrh/GHSA-42m7-33x8-mvrh.json create mode 100644 advisories/unreviewed/2024/09/GHSA-5rqg-4vpc-fpm2/GHSA-5rqg-4vpc-fpm2.json create mode 100644 advisories/unreviewed/2024/09/GHSA-64jg-5jxr-f8cr/GHSA-64jg-5jxr-f8cr.json create mode 100644 advisories/unreviewed/2024/09/GHSA-6jxj-6j73-7fgm/GHSA-6jxj-6j73-7fgm.json create mode 100644 advisories/unreviewed/2024/09/GHSA-7pcw-cjv4-c788/GHSA-7pcw-cjv4-c788.json create mode 100644 advisories/unreviewed/2024/09/GHSA-8hrr-r493-96vh/GHSA-8hrr-r493-96vh.json create mode 100644 advisories/unreviewed/2024/09/GHSA-8mgj-fhf8-9275/GHSA-8mgj-fhf8-9275.json create mode 100644 advisories/unreviewed/2024/09/GHSA-8xf3-x93c-2ch6/GHSA-8xf3-x93c-2ch6.json create mode 100644 advisories/unreviewed/2024/09/GHSA-9xg3-36cq-7vr7/GHSA-9xg3-36cq-7vr7.json create mode 100644 advisories/unreviewed/2024/09/GHSA-crxf-g2j7-6h5p/GHSA-crxf-g2j7-6h5p.json create mode 100644 advisories/unreviewed/2024/09/GHSA-g9g7-rmqc-4q4p/GHSA-g9g7-rmqc-4q4p.json create mode 100644 advisories/unreviewed/2024/09/GHSA-h4fw-fxpw-rrgp/GHSA-h4fw-fxpw-rrgp.json create mode 100644 advisories/unreviewed/2024/09/GHSA-j9h3-rgr4-jg83/GHSA-j9h3-rgr4-jg83.json create mode 100644 advisories/unreviewed/2024/09/GHSA-jwxr-qpg5-2pj9/GHSA-jwxr-qpg5-2pj9.json create mode 100644 advisories/unreviewed/2024/09/GHSA-mhxx-5693-798f/GHSA-mhxx-5693-798f.json create mode 100644 advisories/unreviewed/2024/09/GHSA-p52v-vcvw-fcmg/GHSA-p52v-vcvw-fcmg.json create mode 100644 advisories/unreviewed/2024/09/GHSA-pq82-r7vq-hfqh/GHSA-pq82-r7vq-hfqh.json create mode 100644 advisories/unreviewed/2024/09/GHSA-r29x-667c-gv4v/GHSA-r29x-667c-gv4v.json create mode 100644 advisories/unreviewed/2024/09/GHSA-v6qv-c78w-ff25/GHSA-v6qv-c78w-ff25.json create mode 100644 advisories/unreviewed/2024/09/GHSA-wqc2-gwgp-9p7w/GHSA-wqc2-gwgp-9p7w.json create mode 100644 advisories/unreviewed/2024/09/GHSA-wwq9-rfhf-r6h9/GHSA-wwq9-rfhf-r6h9.json diff --git a/advisories/unreviewed/2023/06/GHSA-25x7-989g-366h/GHSA-25x7-989g-366h.json b/advisories/unreviewed/2023/06/GHSA-25x7-989g-366h/GHSA-25x7-989g-366h.json index b75b296dba5..bc45ce08cf8 100644 --- a/advisories/unreviewed/2023/06/GHSA-25x7-989g-366h/GHSA-25x7-989g-366h.json +++ b/advisories/unreviewed/2023/06/GHSA-25x7-989g-366h/GHSA-25x7-989g-366h.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-268", "CWE-269", "CWE-863" ], diff --git a/advisories/unreviewed/2023/06/GHSA-36qx-fccg-6873/GHSA-36qx-fccg-6873.json b/advisories/unreviewed/2023/06/GHSA-36qx-fccg-6873/GHSA-36qx-fccg-6873.json index 52cf9667cc6..7b6454651cd 100644 --- a/advisories/unreviewed/2023/06/GHSA-36qx-fccg-6873/GHSA-36qx-fccg-6873.json +++ b/advisories/unreviewed/2023/06/GHSA-36qx-fccg-6873/GHSA-36qx-fccg-6873.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-36qx-fccg-6873", - "modified": "2024-04-04T04:53:11Z", + "modified": "2024-09-27T18:32:20Z", "published": "2023-06-15T21:30:25Z", "aliases": [ "CVE-2023-2747" @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1204", "CWE-908" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/12/GHSA-6jw3-xmj9-qvcw/GHSA-6jw3-xmj9-qvcw.json b/advisories/unreviewed/2023/12/GHSA-6jw3-xmj9-qvcw/GHSA-6jw3-xmj9-qvcw.json index a8f16eb9d20..599db9f3d97 100644 --- a/advisories/unreviewed/2023/12/GHSA-6jw3-xmj9-qvcw/GHSA-6jw3-xmj9-qvcw.json +++ b/advisories/unreviewed/2023/12/GHSA-6jw3-xmj9-qvcw/GHSA-6jw3-xmj9-qvcw.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1279", "CWE-908" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/12/GHSA-c948-477j-77c3/GHSA-c948-477j-77c3.json b/advisories/unreviewed/2023/12/GHSA-c948-477j-77c3/GHSA-c948-477j-77c3.json index dc49df4b5c4..bbe50bb40d9 100644 --- a/advisories/unreviewed/2023/12/GHSA-c948-477j-77c3/GHSA-c948-477j-77c3.json +++ b/advisories/unreviewed/2023/12/GHSA-c948-477j-77c3/GHSA-c948-477j-77c3.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-248", "CWE-754" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/01/GHSA-32h2-7245-4mh4/GHSA-32h2-7245-4mh4.json b/advisories/unreviewed/2024/01/GHSA-32h2-7245-4mh4/GHSA-32h2-7245-4mh4.json index 451cd799356..e9ec549c986 100644 --- a/advisories/unreviewed/2024/01/GHSA-32h2-7245-4mh4/GHSA-32h2-7245-4mh4.json +++ b/advisories/unreviewed/2024/01/GHSA-32h2-7245-4mh4/GHSA-32h2-7245-4mh4.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1319", "CWE-909" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/02/GHSA-c467-vf3v-2g2q/GHSA-c467-vf3v-2g2q.json b/advisories/unreviewed/2024/02/GHSA-c467-vf3v-2g2q/GHSA-c467-vf3v-2g2q.json index ff374492561..ce9026d537a 100644 --- a/advisories/unreviewed/2024/02/GHSA-c467-vf3v-2g2q/GHSA-c467-vf3v-2g2q.json +++ b/advisories/unreviewed/2024/02/GHSA-c467-vf3v-2g2q/GHSA-c467-vf3v-2g2q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c467-vf3v-2g2q", - "modified": "2024-02-21T21:30:25Z", + "modified": "2024-09-27T18:32:20Z", "published": "2024-02-21T21:30:25Z", "aliases": [ "CVE-2023-6533" @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-248", "CWE-345" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/02/GHSA-q8rx-w8h7-j8xw/GHSA-q8rx-w8h7-j8xw.json b/advisories/unreviewed/2024/02/GHSA-q8rx-w8h7-j8xw/GHSA-q8rx-w8h7-j8xw.json index 9ca9abf7179..cd24a8fb246 100644 --- a/advisories/unreviewed/2024/02/GHSA-q8rx-w8h7-j8xw/GHSA-q8rx-w8h7-j8xw.json +++ b/advisories/unreviewed/2024/02/GHSA-q8rx-w8h7-j8xw/GHSA-q8rx-w8h7-j8xw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q8rx-w8h7-j8xw", - "modified": "2024-02-21T21:30:25Z", + "modified": "2024-09-27T18:32:20Z", "published": "2024-02-21T21:30:25Z", "aliases": [ "CVE-2023-6640" @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-248", "CWE-754" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/02/GHSA-qfrv-fmc5-hmmh/GHSA-qfrv-fmc5-hmmh.json b/advisories/unreviewed/2024/02/GHSA-qfrv-fmc5-hmmh/GHSA-qfrv-fmc5-hmmh.json index f7ec9095013..aa392fc87da 100644 --- a/advisories/unreviewed/2024/02/GHSA-qfrv-fmc5-hmmh/GHSA-qfrv-fmc5-hmmh.json +++ b/advisories/unreviewed/2024/02/GHSA-qfrv-fmc5-hmmh/GHSA-qfrv-fmc5-hmmh.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1240", "CWE-327" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/02/GHSA-xhg6-78jc-3cwf/GHSA-xhg6-78jc-3cwf.json b/advisories/unreviewed/2024/02/GHSA-xhg6-78jc-3cwf/GHSA-xhg6-78jc-3cwf.json index 9311a179c8e..0ee491916fd 100644 --- a/advisories/unreviewed/2024/02/GHSA-xhg6-78jc-3cwf/GHSA-xhg6-78jc-3cwf.json +++ b/advisories/unreviewed/2024/02/GHSA-xhg6-78jc-3cwf/GHSA-xhg6-78jc-3cwf.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1279", "CWE-330" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/03/GHSA-q4mq-w4v3-mv77/GHSA-q4mq-w4v3-mv77.json b/advisories/unreviewed/2024/03/GHSA-q4mq-w4v3-mv77/GHSA-q4mq-w4v3-mv77.json index 4abd688d34b..80b78845028 100644 --- a/advisories/unreviewed/2024/03/GHSA-q4mq-w4v3-mv77/GHSA-q4mq-w4v3-mv77.json +++ b/advisories/unreviewed/2024/03/GHSA-q4mq-w4v3-mv77/GHSA-q4mq-w4v3-mv77.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-204" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-345m-8c2p-v3fj/GHSA-345m-8c2p-v3fj.json b/advisories/unreviewed/2024/04/GHSA-345m-8c2p-v3fj/GHSA-345m-8c2p-v3fj.json index e2f28d55ca6..690134d7360 100644 --- a/advisories/unreviewed/2024/04/GHSA-345m-8c2p-v3fj/GHSA-345m-8c2p-v3fj.json +++ b/advisories/unreviewed/2024/04/GHSA-345m-8c2p-v3fj/GHSA-345m-8c2p-v3fj.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-248", "CWE-754" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/04/GHSA-cp7v-2p64-673r/GHSA-cp7v-2p64-673r.json b/advisories/unreviewed/2024/04/GHSA-cp7v-2p64-673r/GHSA-cp7v-2p64-673r.json index ad306ac1ba1..40affb195f9 100644 --- a/advisories/unreviewed/2024/04/GHSA-cp7v-2p64-673r/GHSA-cp7v-2p64-673r.json +++ b/advisories/unreviewed/2024/04/GHSA-cp7v-2p64-673r/GHSA-cp7v-2p64-673r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cp7v-2p64-673r", - "modified": "2024-04-27T00:30:38Z", + "modified": "2024-09-27T18:32:21Z", "published": "2024-04-27T00:30:37Z", "aliases": [ "CVE-2024-3051" @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-248", "CWE-345" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/07/GHSA-hx98-fgmp-472p/GHSA-hx98-fgmp-472p.json b/advisories/unreviewed/2024/07/GHSA-hx98-fgmp-472p/GHSA-hx98-fgmp-472p.json index 3fec2f22fef..76fc0ec503c 100644 --- a/advisories/unreviewed/2024/07/GHSA-hx98-fgmp-472p/GHSA-hx98-fgmp-472p.json +++ b/advisories/unreviewed/2024/07/GHSA-hx98-fgmp-472p/GHSA-hx98-fgmp-472p.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-489" + "CWE-489", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-75w9-x6cm-hvwg/GHSA-75w9-x6cm-hvwg.json b/advisories/unreviewed/2024/08/GHSA-75w9-x6cm-hvwg/GHSA-75w9-x6cm-hvwg.json index 22b4a2bbaed..e0a9281d05d 100644 --- a/advisories/unreviewed/2024/08/GHSA-75w9-x6cm-hvwg/GHSA-75w9-x6cm-hvwg.json +++ b/advisories/unreviewed/2024/08/GHSA-75w9-x6cm-hvwg/GHSA-75w9-x6cm-hvwg.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-75w9-x6cm-hvwg", - "modified": "2024-08-20T21:30:35Z", + "modified": "2024-09-27T18:32:21Z", "published": "2024-08-20T21:30:35Z", "aliases": [ "CVE-2024-6337" ], "details": "An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a GitHub App with only content: read and pull_request_write: write permissions to read issue content inside a private repository. This was only exploitable via user access token and installation access token was not impacted. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in versions 3.13.3, 3.12.8, 3.11.14 and 3.10.16. This vulnerability was reported via the GitHub Bug Bounty program.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/08/GHSA-qq8g-mc9v-7pv4/GHSA-qq8g-mc9v-7pv4.json b/advisories/unreviewed/2024/08/GHSA-qq8g-mc9v-7pv4/GHSA-qq8g-mc9v-7pv4.json index 184b80c9de1..ed379b87621 100644 --- a/advisories/unreviewed/2024/08/GHSA-qq8g-mc9v-7pv4/GHSA-qq8g-mc9v-7pv4.json +++ b/advisories/unreviewed/2024/08/GHSA-qq8g-mc9v-7pv4/GHSA-qq8g-mc9v-7pv4.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-80" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/08/GHSA-w49g-9f3f-c384/GHSA-w49g-9f3f-c384.json b/advisories/unreviewed/2024/08/GHSA-w49g-9f3f-c384/GHSA-w49g-9f3f-c384.json index 7c6e2ec66e5..f721729a432 100644 --- a/advisories/unreviewed/2024/08/GHSA-w49g-9f3f-c384/GHSA-w49g-9f3f-c384.json +++ b/advisories/unreviewed/2024/08/GHSA-w49g-9f3f-c384/GHSA-w49g-9f3f-c384.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w49g-9f3f-c384", - "modified": "2024-08-20T21:30:35Z", + "modified": "2024-09-27T18:32:21Z", "published": "2024-08-20T21:30:35Z", "aliases": [ "CVE-2024-7711" ], "details": "An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the title, assignees, and labels of any issue inside a public repository. This was only exploitable inside a public repository. This vulnerability affected GitHub Enterprise Server versions before 3.14 and was fixed in versions 3.13.3, 3.12.8, and 3.11.14. Versions 3.10 of GitHub Enterprise Server are not affected. This vulnerability was reported via the GitHub Bug Bounty program.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:D/RE:L/U:Amber" diff --git a/advisories/unreviewed/2024/09/GHSA-2wpc-6fxg-xpcf/GHSA-2wpc-6fxg-xpcf.json b/advisories/unreviewed/2024/09/GHSA-2wpc-6fxg-xpcf/GHSA-2wpc-6fxg-xpcf.json index 9a574dbcc05..1f329a09be9 100644 --- a/advisories/unreviewed/2024/09/GHSA-2wpc-6fxg-xpcf/GHSA-2wpc-6fxg-xpcf.json +++ b/advisories/unreviewed/2024/09/GHSA-2wpc-6fxg-xpcf/GHSA-2wpc-6fxg-xpcf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2wpc-6fxg-xpcf", - "modified": "2024-09-27T15:30:35Z", + "modified": "2024-09-27T18:32:25Z", "published": "2024-09-27T15:30:35Z", "aliases": [ "CVE-2024-46470" ], "details": "Cross Site Scripting vulnerability in CodeAstro Membership Management System 1.0 allows attackers to run malicious JavaScript via the membership_type field in the edit-type.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T15:15:15Z" diff --git a/advisories/unreviewed/2024/09/GHSA-2wr3-8g8v-wc39/GHSA-2wr3-8g8v-wc39.json b/advisories/unreviewed/2024/09/GHSA-2wr3-8g8v-wc39/GHSA-2wr3-8g8v-wc39.json index 549e25e2447..fb2f611821b 100644 --- a/advisories/unreviewed/2024/09/GHSA-2wr3-8g8v-wc39/GHSA-2wr3-8g8v-wc39.json +++ b/advisories/unreviewed/2024/09/GHSA-2wr3-8g8v-wc39/GHSA-2wr3-8g8v-wc39.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2wr3-8g8v-wc39", - "modified": "2024-09-27T15:30:35Z", + "modified": "2024-09-27T18:32:25Z", "published": "2024-09-27T15:30:35Z", "aliases": [ "CVE-2024-45863" ], "details": "A null-dereference vulnerability involving parsing requests specifying invalid protocols can cause the application to crash or potentially result in other undesirable effects. This issue affects Facebook Thrift from v2024.09.09.00 until v2024.09.23.00.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T14:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-36xh-276f-w5j9/GHSA-36xh-276f-w5j9.json b/advisories/unreviewed/2024/09/GHSA-36xh-276f-w5j9/GHSA-36xh-276f-w5j9.json index ddcb20cbe49..0a71bdbe25e 100644 --- a/advisories/unreviewed/2024/09/GHSA-36xh-276f-w5j9/GHSA-36xh-276f-w5j9.json +++ b/advisories/unreviewed/2024/09/GHSA-36xh-276f-w5j9/GHSA-36xh-276f-w5j9.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-3gv3-rgph-2cgp/GHSA-3gv3-rgph-2cgp.json b/advisories/unreviewed/2024/09/GHSA-3gv3-rgph-2cgp/GHSA-3gv3-rgph-2cgp.json index da866f19911..726aba785df 100644 --- a/advisories/unreviewed/2024/09/GHSA-3gv3-rgph-2cgp/GHSA-3gv3-rgph-2cgp.json +++ b/advisories/unreviewed/2024/09/GHSA-3gv3-rgph-2cgp/GHSA-3gv3-rgph-2cgp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3gv3-rgph-2cgp", - "modified": "2024-09-27T15:30:35Z", + "modified": "2024-09-27T18:32:25Z", "published": "2024-09-27T15:30:35Z", "aliases": [ "CVE-2024-46331" ], "details": "ModStartCMS v8.8.0 was discovered to contain an open redirect vulnerability in the redirect parameter at /admin/login. This vulnerability allows attackers to redirect users to an arbitrary website via a crafted URL.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-601" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T15:15:15Z" diff --git a/advisories/unreviewed/2024/09/GHSA-3mp4-p7x2-73pw/GHSA-3mp4-p7x2-73pw.json b/advisories/unreviewed/2024/09/GHSA-3mp4-p7x2-73pw/GHSA-3mp4-p7x2-73pw.json index 5af7edd7705..0c7c8769be2 100644 --- a/advisories/unreviewed/2024/09/GHSA-3mp4-p7x2-73pw/GHSA-3mp4-p7x2-73pw.json +++ b/advisories/unreviewed/2024/09/GHSA-3mp4-p7x2-73pw/GHSA-3mp4-p7x2-73pw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3mp4-p7x2-73pw", - "modified": "2024-09-13T09:30:33Z", + "modified": "2024-09-27T18:32:21Z", "published": "2024-09-13T09:30:33Z", "aliases": [ "CVE-2024-8742" diff --git a/advisories/unreviewed/2024/09/GHSA-42m7-33x8-mvrh/GHSA-42m7-33x8-mvrh.json b/advisories/unreviewed/2024/09/GHSA-42m7-33x8-mvrh/GHSA-42m7-33x8-mvrh.json new file mode 100644 index 00000000000..60ec8dd318c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-42m7-33x8-mvrh/GHSA-42m7-33x8-mvrh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42m7-33x8-mvrh", + "modified": "2024-09-27T18:32:26Z", + "published": "2024-09-27T18:32:26Z", + "aliases": [ + "CVE-2024-8310" + ], + "details": "OPW Fuel Management Systems SiteSentinel \ncould allow an attacker to bypass authentication to the server and obtain full admin privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8310" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-268-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-27T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-459r-mr42-wfpg/GHSA-459r-mr42-wfpg.json b/advisories/unreviewed/2024/09/GHSA-459r-mr42-wfpg/GHSA-459r-mr42-wfpg.json index 61cb129a09b..bf66d525a95 100644 --- a/advisories/unreviewed/2024/09/GHSA-459r-mr42-wfpg/GHSA-459r-mr42-wfpg.json +++ b/advisories/unreviewed/2024/09/GHSA-459r-mr42-wfpg/GHSA-459r-mr42-wfpg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-459r-mr42-wfpg", - "modified": "2024-09-27T15:30:33Z", + "modified": "2024-09-27T18:32:25Z", "published": "2024-09-27T15:30:33Z", "aliases": [ "CVE-2024-46441" ], "details": "An arbitrary file upload vulnerability in YPay 1.2.0 allows attackers to execute arbitrary code via a ZIP archive to themePutFile in app/common/util/Upload.php (called from app/admin/controller/ypay/Home.php). The file extension of an uncompressed file is not checked.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T13:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-4f5w-x884-92x8/GHSA-4f5w-x884-92x8.json b/advisories/unreviewed/2024/09/GHSA-4f5w-x884-92x8/GHSA-4f5w-x884-92x8.json index 33834b1decb..c613fa0f830 100644 --- a/advisories/unreviewed/2024/09/GHSA-4f5w-x884-92x8/GHSA-4f5w-x884-92x8.json +++ b/advisories/unreviewed/2024/09/GHSA-4f5w-x884-92x8/GHSA-4f5w-x884-92x8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4f5w-x884-92x8", - "modified": "2024-09-27T15:30:34Z", + "modified": "2024-09-27T18:32:25Z", "published": "2024-09-27T15:30:34Z", "aliases": [ "CVE-2024-40511" ], "details": "Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMServerAdmin.asmx function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T14:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-5rqg-4vpc-fpm2/GHSA-5rqg-4vpc-fpm2.json b/advisories/unreviewed/2024/09/GHSA-5rqg-4vpc-fpm2/GHSA-5rqg-4vpc-fpm2.json new file mode 100644 index 00000000000..6e7efc0eb03 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5rqg-4vpc-fpm2/GHSA-5rqg-4vpc-fpm2.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rqg-4vpc-fpm2", + "modified": "2024-09-27T18:32:27Z", + "published": "2024-09-27T18:32:27Z", + "aliases": [ + "CVE-2024-46257" + ], + "details": "A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve remote code execution via Add Let's Encrypt Certificate. NOTE: this is not part of any NGINX software shipped by F5.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46257" + }, + { + "type": "WEB", + "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/commit/99cce7e2b0da2978411cedd7cac5fffbe15bc466" + }, + { + "type": "WEB", + "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.11.3/backend/internal/certificate.js#L870" + }, + { + "type": "WEB", + "url": "https://github.com/barttran2k/POC_CVE-2024-46256" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-27T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-64jg-5jxr-f8cr/GHSA-64jg-5jxr-f8cr.json b/advisories/unreviewed/2024/09/GHSA-64jg-5jxr-f8cr/GHSA-64jg-5jxr-f8cr.json new file mode 100644 index 00000000000..ef4cf6ddf32 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-64jg-5jxr-f8cr/GHSA-64jg-5jxr-f8cr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-64jg-5jxr-f8cr", + "modified": "2024-09-27T18:32:26Z", + "published": "2024-09-27T18:32:26Z", + "aliases": [ + "CVE-2024-28948" + ], + "details": "Advantech ADAM-5630 contains a cross-site request forgery (CSRF) vulnerability. It allows an attacker to partly circumvent the same \norigin policy, which is designed to prevent different websites from \ninterfering with each other.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28948" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-02" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-27T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-653g-mc33-gq3r/GHSA-653g-mc33-gq3r.json b/advisories/unreviewed/2024/09/GHSA-653g-mc33-gq3r/GHSA-653g-mc33-gq3r.json index 4a502dfd5d6..50b40298854 100644 --- a/advisories/unreviewed/2024/09/GHSA-653g-mc33-gq3r/GHSA-653g-mc33-gq3r.json +++ b/advisories/unreviewed/2024/09/GHSA-653g-mc33-gq3r/GHSA-653g-mc33-gq3r.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-6jxj-6j73-7fgm/GHSA-6jxj-6j73-7fgm.json b/advisories/unreviewed/2024/09/GHSA-6jxj-6j73-7fgm/GHSA-6jxj-6j73-7fgm.json new file mode 100644 index 00000000000..8aaf7fb5204 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6jxj-6j73-7fgm/GHSA-6jxj-6j73-7fgm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jxj-6j73-7fgm", + "modified": "2024-09-27T18:32:26Z", + "published": "2024-09-27T18:32:26Z", + "aliases": [ + "CVE-2024-25412" + ], + "details": "A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email field.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25412" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1GBL-iY5ZRaxRqLVqpBe1w6dVgEfywAG7/view?usp=sharing" + }, + { + "type": "WEB", + "url": "https://github.com/paragbagul111/CVE-2024-25412" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-27T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-7jwq-r5r6-rxq7/GHSA-7jwq-r5r6-rxq7.json b/advisories/unreviewed/2024/09/GHSA-7jwq-r5r6-rxq7/GHSA-7jwq-r5r6-rxq7.json index 7e3b83a167a..cd89abb7241 100644 --- a/advisories/unreviewed/2024/09/GHSA-7jwq-r5r6-rxq7/GHSA-7jwq-r5r6-rxq7.json +++ b/advisories/unreviewed/2024/09/GHSA-7jwq-r5r6-rxq7/GHSA-7jwq-r5r6-rxq7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7jwq-r5r6-rxq7", - "modified": "2024-09-27T15:30:35Z", + "modified": "2024-09-27T18:32:25Z", "published": "2024-09-27T15:30:35Z", "aliases": [ "CVE-2024-46471" ], "details": "The Directory Listing in /uploads/ Folder in CodeAstro Membership Management System 1.0 exposes the structure and contents of directories, potentially revealing sensitive information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T15:15:15Z" diff --git a/advisories/unreviewed/2024/09/GHSA-7pcw-cjv4-c788/GHSA-7pcw-cjv4-c788.json b/advisories/unreviewed/2024/09/GHSA-7pcw-cjv4-c788/GHSA-7pcw-cjv4-c788.json new file mode 100644 index 00000000000..ac996612b65 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-7pcw-cjv4-c788/GHSA-7pcw-cjv4-c788.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pcw-cjv4-c788", + "modified": "2024-09-27T18:32:26Z", + "published": "2024-09-27T18:32:26Z", + "aliases": [ + "CVE-2024-39364" + ], + "details": "Advantech ADAM-5630 \nhas built-in commands that can be executed without authenticating the \nuser. These commands allow for restarting the operating system, \nrebooting the hardware, and stopping the execution. The commands can be \nsent to a simple HTTP request and are executed by the device \nautomatically, without discrimination of origin or level of privileges \nof the user sending the commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39364" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-02" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-27T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-7w3c-jwh7-4486/GHSA-7w3c-jwh7-4486.json b/advisories/unreviewed/2024/09/GHSA-7w3c-jwh7-4486/GHSA-7w3c-jwh7-4486.json index 308471149ef..b929454db88 100644 --- a/advisories/unreviewed/2024/09/GHSA-7w3c-jwh7-4486/GHSA-7w3c-jwh7-4486.json +++ b/advisories/unreviewed/2024/09/GHSA-7w3c-jwh7-4486/GHSA-7w3c-jwh7-4486.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7w3c-jwh7-4486", - "modified": "2024-09-26T18:31:45Z", + "modified": "2024-09-27T18:32:25Z", "published": "2024-09-26T18:31:45Z", "aliases": [ "CVE-2024-45989" ], "details": "Monica AI Assistant desktop application v2.3.0 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor. A prompt injection allows an attacker to modify chatbot answer with an unloaded image that exfiltrates the user's sensitive chat data of the current session to a malicious third-party or attacker-controlled server.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-26T18:15:08Z" diff --git a/advisories/unreviewed/2024/09/GHSA-7wfr-5f4h-3mw7/GHSA-7wfr-5f4h-3mw7.json b/advisories/unreviewed/2024/09/GHSA-7wfr-5f4h-3mw7/GHSA-7wfr-5f4h-3mw7.json index ed494d93967..291c068b6fc 100644 --- a/advisories/unreviewed/2024/09/GHSA-7wfr-5f4h-3mw7/GHSA-7wfr-5f4h-3mw7.json +++ b/advisories/unreviewed/2024/09/GHSA-7wfr-5f4h-3mw7/GHSA-7wfr-5f4h-3mw7.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-8hrr-r493-96vh/GHSA-8hrr-r493-96vh.json b/advisories/unreviewed/2024/09/GHSA-8hrr-r493-96vh/GHSA-8hrr-r493-96vh.json new file mode 100644 index 00000000000..7e87204d3af --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8hrr-r493-96vh/GHSA-8hrr-r493-96vh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hrr-r493-96vh", + "modified": "2024-09-27T18:32:26Z", + "published": "2024-09-27T18:32:26Z", + "aliases": [ + "CVE-2024-37187" + ], + "details": "Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37187" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-261" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-27T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8mgj-fhf8-9275/GHSA-8mgj-fhf8-9275.json b/advisories/unreviewed/2024/09/GHSA-8mgj-fhf8-9275/GHSA-8mgj-fhf8-9275.json new file mode 100644 index 00000000000..5ab299d14d6 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8mgj-fhf8-9275/GHSA-8mgj-fhf8-9275.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8mgj-fhf8-9275", + "modified": "2024-09-27T18:32:26Z", + "published": "2024-09-27T18:32:26Z", + "aliases": [ + "CVE-2024-34542" + ], + "details": "Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34542" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-02" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-261" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-27T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8xf3-x93c-2ch6/GHSA-8xf3-x93c-2ch6.json b/advisories/unreviewed/2024/09/GHSA-8xf3-x93c-2ch6/GHSA-8xf3-x93c-2ch6.json new file mode 100644 index 00000000000..6fc1448431f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8xf3-x93c-2ch6/GHSA-8xf3-x93c-2ch6.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xf3-x93c-2ch6", + "modified": "2024-09-27T18:32:26Z", + "published": "2024-09-27T18:32:25Z", + "aliases": [ + "CVE-2024-45744" + ], + "details": "TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authenticated attacker could gain file system access using a separate vulnerability such as CVE-2024-45745. At least version 7.1.3 is affected. Version 7.3 adds HashiCorp Vault integration that does not store external passwords locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45744" + }, + { + "type": "WEB", + "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-254-02.json" + }, + { + "type": "WEB", + "url": "https://www.topquadrant.com/doc/latest/administrator_guide/edg_installation_and_authentication/hashicorp_integration.html" + }, + { + "type": "WEB", + "url": "https://www.topquadrant.com/doc/latest/reference/PasswordManagementAdminPage.html" + }, + { + "type": "WEB", + "url": "https://www.topquadrant.com/release-note/7-3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-257" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-27T16:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-92rj-4rqf-4mg5/GHSA-92rj-4rqf-4mg5.json b/advisories/unreviewed/2024/09/GHSA-92rj-4rqf-4mg5/GHSA-92rj-4rqf-4mg5.json index 231a72da023..a1265bd3046 100644 --- a/advisories/unreviewed/2024/09/GHSA-92rj-4rqf-4mg5/GHSA-92rj-4rqf-4mg5.json +++ b/advisories/unreviewed/2024/09/GHSA-92rj-4rqf-4mg5/GHSA-92rj-4rqf-4mg5.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-285" + "CWE-285", + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-9q57-6634-5vrw/GHSA-9q57-6634-5vrw.json b/advisories/unreviewed/2024/09/GHSA-9q57-6634-5vrw/GHSA-9q57-6634-5vrw.json index e80a2251efd..8cbb3f854ac 100644 --- a/advisories/unreviewed/2024/09/GHSA-9q57-6634-5vrw/GHSA-9q57-6634-5vrw.json +++ b/advisories/unreviewed/2024/09/GHSA-9q57-6634-5vrw/GHSA-9q57-6634-5vrw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9q57-6634-5vrw", - "modified": "2024-09-16T14:37:27Z", + "modified": "2024-09-27T18:32:21Z", "published": "2024-09-16T14:37:26Z", "aliases": [ "CVE-2024-8669" diff --git a/advisories/unreviewed/2024/09/GHSA-9xg3-36cq-7vr7/GHSA-9xg3-36cq-7vr7.json b/advisories/unreviewed/2024/09/GHSA-9xg3-36cq-7vr7/GHSA-9xg3-36cq-7vr7.json new file mode 100644 index 00000000000..58c352f83f1 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-9xg3-36cq-7vr7/GHSA-9xg3-36cq-7vr7.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xg3-36cq-7vr7", + "modified": "2024-09-27T18:32:26Z", + "published": "2024-09-27T18:32:26Z", + "aliases": [ + "CVE-2024-38308" + ], + "details": "Advantech ADAM 5550's web application includes a \"logs\" page where all \nthe HTTP requests received are displayed to the user. The device doesn't\n correctly neutralize malicious code when parsing HTTP requests to \ngenerate page output.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38308" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-27T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-chwj-xj8v-386c/GHSA-chwj-xj8v-386c.json b/advisories/unreviewed/2024/09/GHSA-chwj-xj8v-386c/GHSA-chwj-xj8v-386c.json index 3b90e9110ac..62aa5defb7d 100644 --- a/advisories/unreviewed/2024/09/GHSA-chwj-xj8v-386c/GHSA-chwj-xj8v-386c.json +++ b/advisories/unreviewed/2024/09/GHSA-chwj-xj8v-386c/GHSA-chwj-xj8v-386c.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-crxf-g2j7-6h5p/GHSA-crxf-g2j7-6h5p.json b/advisories/unreviewed/2024/09/GHSA-crxf-g2j7-6h5p/GHSA-crxf-g2j7-6h5p.json new file mode 100644 index 00000000000..9efb97f9c43 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-crxf-g2j7-6h5p/GHSA-crxf-g2j7-6h5p.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crxf-g2j7-6h5p", + "modified": "2024-09-27T18:32:26Z", + "published": "2024-09-27T18:32:26Z", + "aliases": [ + "CVE-2024-9284" + ], + "details": "A vulnerability was found in TP-LINK TL-WR841ND up to 20240920. It has been rated as critical. Affected by this issue is some unknown functionality of the file /userRpm/popupSiteSurveyRpm.htm. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9284" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/TP-LINK/WR-841ND/popupSiteSurveyRpm.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.278684" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.278684" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.411526" + }, + { + "type": "WEB", + "url": "https://www.tp-link.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-27T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-f3pj-vwf5-5vr3/GHSA-f3pj-vwf5-5vr3.json b/advisories/unreviewed/2024/09/GHSA-f3pj-vwf5-5vr3/GHSA-f3pj-vwf5-5vr3.json index bbb82642ec3..2089592138e 100644 --- a/advisories/unreviewed/2024/09/GHSA-f3pj-vwf5-5vr3/GHSA-f3pj-vwf5-5vr3.json +++ b/advisories/unreviewed/2024/09/GHSA-f3pj-vwf5-5vr3/GHSA-f3pj-vwf5-5vr3.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-g9g7-rmqc-4q4p/GHSA-g9g7-rmqc-4q4p.json b/advisories/unreviewed/2024/09/GHSA-g9g7-rmqc-4q4p/GHSA-g9g7-rmqc-4q4p.json new file mode 100644 index 00000000000..4a32de7db66 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g9g7-rmqc-4q4p/GHSA-g9g7-rmqc-4q4p.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9g7-rmqc-4q4p", + "modified": "2024-09-27T18:32:26Z", + "published": "2024-09-27T18:32:26Z", + "aliases": [ + "CVE-2024-25411" + ], + "details": "A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter in setup.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25411" + }, + { + "type": "WEB", + "url": "https://github.com/flatpressblog/flatpress/pull/261" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1GBL-iY5ZRaxRqLVqpBe1w6dVgEfywAG7/view?usp=sharing" + }, + { + "type": "WEB", + "url": "https://github.com/paragbagul111/CVE-2024-25411" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-27T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gq5m-j7gp-3x7q/GHSA-gq5m-j7gp-3x7q.json b/advisories/unreviewed/2024/09/GHSA-gq5m-j7gp-3x7q/GHSA-gq5m-j7gp-3x7q.json index 78c4a735424..fd9af3a3a3b 100644 --- a/advisories/unreviewed/2024/09/GHSA-gq5m-j7gp-3x7q/GHSA-gq5m-j7gp-3x7q.json +++ b/advisories/unreviewed/2024/09/GHSA-gq5m-j7gp-3x7q/GHSA-gq5m-j7gp-3x7q.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-gvfm-hc65-h2hv/GHSA-gvfm-hc65-h2hv.json b/advisories/unreviewed/2024/09/GHSA-gvfm-hc65-h2hv/GHSA-gvfm-hc65-h2hv.json index 5b7a0c9ccbe..9f502ab505b 100644 --- a/advisories/unreviewed/2024/09/GHSA-gvfm-hc65-h2hv/GHSA-gvfm-hc65-h2hv.json +++ b/advisories/unreviewed/2024/09/GHSA-gvfm-hc65-h2hv/GHSA-gvfm-hc65-h2hv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gvfm-hc65-h2hv", - "modified": "2024-09-26T18:31:44Z", + "modified": "2024-09-27T18:32:25Z", "published": "2024-09-26T18:31:44Z", "aliases": [ "CVE-2024-46627" ], "details": "Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-26T17:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-h4fw-fxpw-rrgp/GHSA-h4fw-fxpw-rrgp.json b/advisories/unreviewed/2024/09/GHSA-h4fw-fxpw-rrgp/GHSA-h4fw-fxpw-rrgp.json new file mode 100644 index 00000000000..6c2a35acae3 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-h4fw-fxpw-rrgp/GHSA-h4fw-fxpw-rrgp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4fw-fxpw-rrgp", + "modified": "2024-09-27T18:32:26Z", + "published": "2024-09-27T18:32:26Z", + "aliases": [ + "CVE-2024-22170" + ], + "details": "Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Western Digital My Cloud ddns-start on Linux allows Overflow Buffers.This issue affects My Cloud: before 5.29.102.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22170" + }, + { + "type": "WEB", + "url": "https://www.westerndigital.com/support/product-security/wdc-24005-western-digital-my-cloud-os-5-firmware-5-29-102" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-27T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-j9h3-rgr4-jg83/GHSA-j9h3-rgr4-jg83.json b/advisories/unreviewed/2024/09/GHSA-j9h3-rgr4-jg83/GHSA-j9h3-rgr4-jg83.json new file mode 100644 index 00000000000..1b74ded12c1 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-j9h3-rgr4-jg83/GHSA-j9h3-rgr4-jg83.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9h3-rgr4-jg83", + "modified": "2024-09-27T18:32:26Z", + "published": "2024-09-27T18:32:26Z", + "aliases": [ + "CVE-2024-8630" + ], + "details": "Alisonic Sibylla devices are vulnerable to SQL injection attacks, which could allow complete access to the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8630" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-268-02" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-27T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-jr3c-32f2-p7wg/GHSA-jr3c-32f2-p7wg.json b/advisories/unreviewed/2024/09/GHSA-jr3c-32f2-p7wg/GHSA-jr3c-32f2-p7wg.json index 6fe592bc1b7..2bfe5282d28 100644 --- a/advisories/unreviewed/2024/09/GHSA-jr3c-32f2-p7wg/GHSA-jr3c-32f2-p7wg.json +++ b/advisories/unreviewed/2024/09/GHSA-jr3c-32f2-p7wg/GHSA-jr3c-32f2-p7wg.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-jwxr-qpg5-2pj9/GHSA-jwxr-qpg5-2pj9.json b/advisories/unreviewed/2024/09/GHSA-jwxr-qpg5-2pj9/GHSA-jwxr-qpg5-2pj9.json new file mode 100644 index 00000000000..f607a8f09ba --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-jwxr-qpg5-2pj9/GHSA-jwxr-qpg5-2pj9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwxr-qpg5-2pj9", + "modified": "2024-09-27T18:32:26Z", + "published": "2024-09-27T18:32:26Z", + "aliases": [ + "CVE-2024-46367" + ], + "details": "A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submitting a malicious payload within the username field. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the CRM system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46367" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Tommywarren/4ac0c8f6e5d8584accd31b8277e55749" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-27T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-m7hg-9c63-f5hm/GHSA-m7hg-9c63-f5hm.json b/advisories/unreviewed/2024/09/GHSA-m7hg-9c63-f5hm/GHSA-m7hg-9c63-f5hm.json index 1e13d9bc1fa..d0abb8e11f3 100644 --- a/advisories/unreviewed/2024/09/GHSA-m7hg-9c63-f5hm/GHSA-m7hg-9c63-f5hm.json +++ b/advisories/unreviewed/2024/09/GHSA-m7hg-9c63-f5hm/GHSA-m7hg-9c63-f5hm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m7hg-9c63-f5hm", - "modified": "2024-09-27T15:30:35Z", + "modified": "2024-09-27T18:32:25Z", "published": "2024-09-27T15:30:35Z", "aliases": [ "CVE-2024-40512" ], "details": "Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMReporting.asmx function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T14:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-m8mp-83qq-7j4f/GHSA-m8mp-83qq-7j4f.json b/advisories/unreviewed/2024/09/GHSA-m8mp-83qq-7j4f/GHSA-m8mp-83qq-7j4f.json index cc62f6f43ef..9f13d16790c 100644 --- a/advisories/unreviewed/2024/09/GHSA-m8mp-83qq-7j4f/GHSA-m8mp-83qq-7j4f.json +++ b/advisories/unreviewed/2024/09/GHSA-m8mp-83qq-7j4f/GHSA-m8mp-83qq-7j4f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m8mp-83qq-7j4f", - "modified": "2024-09-13T15:31:33Z", + "modified": "2024-09-27T18:32:21Z", "published": "2024-09-13T06:30:43Z", "aliases": [ "CVE-2024-7129" diff --git a/advisories/unreviewed/2024/09/GHSA-mhxx-5693-798f/GHSA-mhxx-5693-798f.json b/advisories/unreviewed/2024/09/GHSA-mhxx-5693-798f/GHSA-mhxx-5693-798f.json new file mode 100644 index 00000000000..f8fc3ab1c5c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mhxx-5693-798f/GHSA-mhxx-5693-798f.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhxx-5693-798f", + "modified": "2024-09-27T18:32:27Z", + "published": "2024-09-27T18:32:27Z", + "aliases": [ + "CVE-2024-46256" + ], + "details": "A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46256" + }, + { + "type": "WEB", + "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/commit/99cce7e2b0da2978411cedd7cac5fffbe15bc466" + }, + { + "type": "WEB", + "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.11.3/backend/internal/certificate.js#L830" + }, + { + "type": "WEB", + "url": "https://github.com/barttran2k/POC_CVE-2024-46256" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-27T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-p52v-vcvw-fcmg/GHSA-p52v-vcvw-fcmg.json b/advisories/unreviewed/2024/09/GHSA-p52v-vcvw-fcmg/GHSA-p52v-vcvw-fcmg.json new file mode 100644 index 00000000000..9c7442590c3 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-p52v-vcvw-fcmg/GHSA-p52v-vcvw-fcmg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p52v-vcvw-fcmg", + "modified": "2024-09-27T18:32:25Z", + "published": "2024-09-27T18:32:25Z", + "aliases": [ + "CVE-2024-45745" + ], + "details": "TopQuadrant TopBraid EDG before version 8.0.1 allows an authenticated attacker to upload an XML DTD file and execute JavaScript to read local files or access URLs (XXE). Fixed in 8.0.1 (bug fix: TBS-6721).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45745" + }, + { + "type": "WEB", + "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-254-02.json" + }, + { + "type": "WEB", + "url": "https://www.topquadrant.com/wp-content/uploads/2024/06/changelog-8.0.1.txt" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-27T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-pcj5-c4v2-hq4g/GHSA-pcj5-c4v2-hq4g.json b/advisories/unreviewed/2024/09/GHSA-pcj5-c4v2-hq4g/GHSA-pcj5-c4v2-hq4g.json index fc0c870fdf5..ea68eed7866 100644 --- a/advisories/unreviewed/2024/09/GHSA-pcj5-c4v2-hq4g/GHSA-pcj5-c4v2-hq4g.json +++ b/advisories/unreviewed/2024/09/GHSA-pcj5-c4v2-hq4g/GHSA-pcj5-c4v2-hq4g.json @@ -40,6 +40,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-312", "CWE-313" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/09/GHSA-pq82-r7vq-hfqh/GHSA-pq82-r7vq-hfqh.json b/advisories/unreviewed/2024/09/GHSA-pq82-r7vq-hfqh/GHSA-pq82-r7vq-hfqh.json new file mode 100644 index 00000000000..0724374df9f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pq82-r7vq-hfqh/GHSA-pq82-r7vq-hfqh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pq82-r7vq-hfqh", + "modified": "2024-09-27T18:32:26Z", + "published": "2024-09-27T18:32:26Z", + "aliases": [ + "CVE-2024-6981" + ], + "details": "OMNTEC Proteus Tank Monitoring OEL8000III Series\n\n\ncould allow an attacker to perform administrative actions without proper authentication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6981" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-268-06" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-27T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-r29x-667c-gv4v/GHSA-r29x-667c-gv4v.json b/advisories/unreviewed/2024/09/GHSA-r29x-667c-gv4v/GHSA-r29x-667c-gv4v.json new file mode 100644 index 00000000000..456139bac5a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-r29x-667c-gv4v/GHSA-r29x-667c-gv4v.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r29x-667c-gv4v", + "modified": "2024-09-27T18:32:26Z", + "published": "2024-09-27T18:32:26Z", + "aliases": [ + "CVE-2024-39275" + ], + "details": "Cookies of authenticated Advantech ADAM-5630 users remain as active valid cookies when a \nsession is closed. Forging requests with a legitimate cookie, even if \nthe session was terminated, allows an unauthorized attacker to act with \nthe same level of privileges of the legitimate user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39275" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-02" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-539" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-27T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-r2gp-x2mf-c5p8/GHSA-r2gp-x2mf-c5p8.json b/advisories/unreviewed/2024/09/GHSA-r2gp-x2mf-c5p8/GHSA-r2gp-x2mf-c5p8.json index 3046b887055..3a4b165bf64 100644 --- a/advisories/unreviewed/2024/09/GHSA-r2gp-x2mf-c5p8/GHSA-r2gp-x2mf-c5p8.json +++ b/advisories/unreviewed/2024/09/GHSA-r2gp-x2mf-c5p8/GHSA-r2gp-x2mf-c5p8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r2gp-x2mf-c5p8", - "modified": "2024-09-27T15:30:35Z", + "modified": "2024-09-27T18:32:25Z", "published": "2024-09-27T15:30:35Z", "aliases": [ "CVE-2024-40509" ], "details": "Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMFinDev.asmx function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T15:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-rr53-gjvx-gr2c/GHSA-rr53-gjvx-gr2c.json b/advisories/unreviewed/2024/09/GHSA-rr53-gjvx-gr2c/GHSA-rr53-gjvx-gr2c.json index 12b82ac0ba2..afa3704848e 100644 --- a/advisories/unreviewed/2024/09/GHSA-rr53-gjvx-gr2c/GHSA-rr53-gjvx-gr2c.json +++ b/advisories/unreviewed/2024/09/GHSA-rr53-gjvx-gr2c/GHSA-rr53-gjvx-gr2c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rr53-gjvx-gr2c", - "modified": "2024-09-27T15:30:35Z", + "modified": "2024-09-27T18:32:25Z", "published": "2024-09-27T15:30:35Z", "aliases": [ "CVE-2024-46333" ], "details": "An authenticated cross-site scripting (XSS) vulnerability in Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Album Name parameter under the Add Album function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T15:15:15Z" diff --git a/advisories/unreviewed/2024/09/GHSA-v6qv-c78w-ff25/GHSA-v6qv-c78w-ff25.json b/advisories/unreviewed/2024/09/GHSA-v6qv-c78w-ff25/GHSA-v6qv-c78w-ff25.json new file mode 100644 index 00000000000..4c6b115ef15 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-v6qv-c78w-ff25/GHSA-v6qv-c78w-ff25.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6qv-c78w-ff25", + "modified": "2024-09-27T18:32:26Z", + "published": "2024-09-27T18:32:26Z", + "aliases": [ + "CVE-2024-6983" + ], + "details": "mudler/localai version 2.17.1 is vulnerable to remote code execution. The vulnerability arises because the localai backend receives inputs not only from the configuration file but also from other inputs, allowing an attacker to upload a binary file and execute malicious code. This can lead to the attacker gaining full control over the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6983" + }, + { + "type": "WEB", + "url": "https://github.com/mudler/localai/commit/d02a0f6f01d5c4a926a2d67190cb55d7aca23b66" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/f91fb287-412e-4c89-87df-9e4b6e609647" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-27T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vww8-5r8j-mrcr/GHSA-vww8-5r8j-mrcr.json b/advisories/unreviewed/2024/09/GHSA-vww8-5r8j-mrcr/GHSA-vww8-5r8j-mrcr.json index e749bcdf08a..d411800aebc 100644 --- a/advisories/unreviewed/2024/09/GHSA-vww8-5r8j-mrcr/GHSA-vww8-5r8j-mrcr.json +++ b/advisories/unreviewed/2024/09/GHSA-vww8-5r8j-mrcr/GHSA-vww8-5r8j-mrcr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vww8-5r8j-mrcr", - "modified": "2024-09-27T15:30:35Z", + "modified": "2024-09-27T18:32:25Z", "published": "2024-09-27T15:30:35Z", "aliases": [ "CVE-2024-45773" ], "details": "A use-after-free vulnerability involving upgradeToRocket requests can cause the application to crash or potentially result in code execution or other undesirable effects. This issue affects Facebook Thrift prior to v2024.09.09.00.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T14:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-wj7r-74h6-3r6w/GHSA-wj7r-74h6-3r6w.json b/advisories/unreviewed/2024/09/GHSA-wj7r-74h6-3r6w/GHSA-wj7r-74h6-3r6w.json index 2610851bb5f..43f68ac4bd1 100644 --- a/advisories/unreviewed/2024/09/GHSA-wj7r-74h6-3r6w/GHSA-wj7r-74h6-3r6w.json +++ b/advisories/unreviewed/2024/09/GHSA-wj7r-74h6-3r6w/GHSA-wj7r-74h6-3r6w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wj7r-74h6-3r6w", - "modified": "2024-09-23T06:30:41Z", + "modified": "2024-09-27T18:32:25Z", "published": "2024-09-23T06:30:41Z", "aliases": [ "CVE-2024-47227" ], "details": "iRedAdmin before 2.6 allows XSS, e.g., via order_name.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-23T04:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-wqc2-gwgp-9p7w/GHSA-wqc2-gwgp-9p7w.json b/advisories/unreviewed/2024/09/GHSA-wqc2-gwgp-9p7w/GHSA-wqc2-gwgp-9p7w.json new file mode 100644 index 00000000000..1287f26a9d4 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-wqc2-gwgp-9p7w/GHSA-wqc2-gwgp-9p7w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqc2-gwgp-9p7w", + "modified": "2024-09-27T18:32:26Z", + "published": "2024-09-27T18:32:26Z", + "aliases": [ + "CVE-2024-46366" + ], + "details": "A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side template code by injecting a malicious payload during the lead creation process. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the CRM system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46366" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Tommywarren/89cef7f876ee897a4ff40a8b71b6208e" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-27T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-wwq9-rfhf-r6h9/GHSA-wwq9-rfhf-r6h9.json b/advisories/unreviewed/2024/09/GHSA-wwq9-rfhf-r6h9/GHSA-wwq9-rfhf-r6h9.json new file mode 100644 index 00000000000..35ed3aaa13f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-wwq9-rfhf-r6h9/GHSA-wwq9-rfhf-r6h9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wwq9-rfhf-r6h9", + "modified": "2024-09-27T18:32:26Z", + "published": "2024-09-27T18:32:26Z", + "aliases": [ + "CVE-2024-46097" + ], + "details": "TestLink 1.9.20 is vulnerable to Incorrect Access Control in the TestPlan editing section. When a new TestPlan is created, an ID with an incremental value is automatically generated. Using the edit function you can change the tplan_id parameter to another ID. The application does not carry out a check on the user's permissions maing it possible to recover the IDs of all the TestPlans (even the administrative ones) and modify them even with minimal privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46097" + }, + { + "type": "WEB", + "url": "https://github.com/Alkatraz97/CVEs/blob/main/CVE-2024-46097.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-27T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xfx4-9q4j-5v3q/GHSA-xfx4-9q4j-5v3q.json b/advisories/unreviewed/2024/09/GHSA-xfx4-9q4j-5v3q/GHSA-xfx4-9q4j-5v3q.json index 5b1f7e00957..852c5cbc812 100644 --- a/advisories/unreviewed/2024/09/GHSA-xfx4-9q4j-5v3q/GHSA-xfx4-9q4j-5v3q.json +++ b/advisories/unreviewed/2024/09/GHSA-xfx4-9q4j-5v3q/GHSA-xfx4-9q4j-5v3q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xfx4-9q4j-5v3q", - "modified": "2024-09-27T06:30:43Z", + "modified": "2024-09-27T18:32:25Z", "published": "2024-09-27T06:30:43Z", "aliases": [ "CVE-2024-7714" ], "details": "The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 from OpenAI, thereby disabling the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0. Multiple actions are accessible: 'ays_chatgpt_disconnect', 'ays_chatgpt_connect', and 'ays_chatgpt_save_feedback'", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T06:15:12Z" diff --git a/advisories/unreviewed/2024/09/GHSA-xjwr-gx3m-j7pj/GHSA-xjwr-gx3m-j7pj.json b/advisories/unreviewed/2024/09/GHSA-xjwr-gx3m-j7pj/GHSA-xjwr-gx3m-j7pj.json index f4d9c90e72d..83c30bc97c6 100644 --- a/advisories/unreviewed/2024/09/GHSA-xjwr-gx3m-j7pj/GHSA-xjwr-gx3m-j7pj.json +++ b/advisories/unreviewed/2024/09/GHSA-xjwr-gx3m-j7pj/GHSA-xjwr-gx3m-j7pj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xjwr-gx3m-j7pj", - "modified": "2024-09-27T15:30:35Z", + "modified": "2024-09-27T18:32:25Z", "published": "2024-09-27T15:30:35Z", "aliases": [ "CVE-2024-46472" ], "details": "CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection via the parameter 'email' in the Login Page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T15:15:15Z" diff --git a/advisories/unreviewed/2024/09/GHSA-xwc4-p3cg-mmq4/GHSA-xwc4-p3cg-mmq4.json b/advisories/unreviewed/2024/09/GHSA-xwc4-p3cg-mmq4/GHSA-xwc4-p3cg-mmq4.json index 8292cffeb02..e3d551f04b3 100644 --- a/advisories/unreviewed/2024/09/GHSA-xwc4-p3cg-mmq4/GHSA-xwc4-p3cg-mmq4.json +++ b/advisories/unreviewed/2024/09/GHSA-xwc4-p3cg-mmq4/GHSA-xwc4-p3cg-mmq4.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": "MODERATE", "github_reviewed": false,