From 982e2b9570e90655565adadf3b56bac156ffa3c3 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 19 Dec 2024 15:32:43 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-22c5-cpvr-cfvq.json | 6 +- .../GHSA-hwvf-grj2-9364.json | 9 ++- .../GHSA-vmh3-rhm9-223f.json | 9 ++- .../GHSA-gxh7-r3qj-jmff.json | 3 +- .../GHSA-jf9g-42gm-v87w.json | 4 +- .../GHSA-r8fc-3gvg-wxxf.json | 3 +- .../GHSA-2gmr-g5v4-9cch.json | 52 +++++++++++++++++ .../GHSA-5h2c-fvjp-2wmx.json | 3 +- .../GHSA-5mvx-j4j8-xv4p.json | 36 ++++++++++++ .../GHSA-5pvq-85hg-5rww.json | 56 +++++++++++++++++++ .../GHSA-62jh-qwjh-cgr7.json | 3 +- .../GHSA-6mpf-h5jc-fvrw.json | 48 ++++++++++++++++ .../GHSA-77c2-c35q-254w.json | 48 ++++++++++++++++ .../GHSA-g2mr-f5hm-6x69.json | 3 +- .../GHSA-hjr5-pr64-8mc2.json | 3 +- .../GHSA-p8hv-f2qg-cxvv.json | 44 +++++++++++++++ .../GHSA-q73v-pp5w-q5mq.json | 3 +- .../GHSA-qf32-jmjm-hhgw.json | 29 ++++++++++ .../GHSA-rrjw-vh74-2hwv.json | 3 +- .../GHSA-wh36-w27p-cfw8.json | 36 ++++++++++++ .../GHSA-wq8r-q99m-pp5x.json | 56 +++++++++++++++++++ .../GHSA-wwq6-xmjh-4f52.json | 36 ++++++++++++ .../GHSA-x5mp-q3w8-grg7.json | 56 +++++++++++++++++++ .../GHSA-xc5w-rmjg-qwhh.json | 44 +++++++++++++++ .../GHSA-xf4j-mpgp-536j.json | 3 +- .../GHSA-xmrx-vg29-jh4h.json | 52 +++++++++++++++++ 26 files changed, 633 insertions(+), 15 deletions(-) create mode 100644 advisories/unreviewed/2024/12/GHSA-2gmr-g5v4-9cch/GHSA-2gmr-g5v4-9cch.json create mode 100644 advisories/unreviewed/2024/12/GHSA-5mvx-j4j8-xv4p/GHSA-5mvx-j4j8-xv4p.json create mode 100644 advisories/unreviewed/2024/12/GHSA-5pvq-85hg-5rww/GHSA-5pvq-85hg-5rww.json create mode 100644 advisories/unreviewed/2024/12/GHSA-6mpf-h5jc-fvrw/GHSA-6mpf-h5jc-fvrw.json create mode 100644 advisories/unreviewed/2024/12/GHSA-77c2-c35q-254w/GHSA-77c2-c35q-254w.json create mode 100644 advisories/unreviewed/2024/12/GHSA-p8hv-f2qg-cxvv/GHSA-p8hv-f2qg-cxvv.json create mode 100644 advisories/unreviewed/2024/12/GHSA-qf32-jmjm-hhgw/GHSA-qf32-jmjm-hhgw.json create mode 100644 advisories/unreviewed/2024/12/GHSA-wh36-w27p-cfw8/GHSA-wh36-w27p-cfw8.json create mode 100644 advisories/unreviewed/2024/12/GHSA-wq8r-q99m-pp5x/GHSA-wq8r-q99m-pp5x.json create mode 100644 advisories/unreviewed/2024/12/GHSA-wwq6-xmjh-4f52/GHSA-wwq6-xmjh-4f52.json create mode 100644 advisories/unreviewed/2024/12/GHSA-x5mp-q3w8-grg7/GHSA-x5mp-q3w8-grg7.json create mode 100644 advisories/unreviewed/2024/12/GHSA-xc5w-rmjg-qwhh/GHSA-xc5w-rmjg-qwhh.json create mode 100644 advisories/unreviewed/2024/12/GHSA-xmrx-vg29-jh4h/GHSA-xmrx-vg29-jh4h.json diff --git a/advisories/github-reviewed/2024/12/GHSA-22c5-cpvr-cfvq/GHSA-22c5-cpvr-cfvq.json b/advisories/github-reviewed/2024/12/GHSA-22c5-cpvr-cfvq/GHSA-22c5-cpvr-cfvq.json index 454fc03bd44..b0ea25c5856 100644 --- a/advisories/github-reviewed/2024/12/GHSA-22c5-cpvr-cfvq/GHSA-22c5-cpvr-cfvq.json +++ b/advisories/github-reviewed/2024/12/GHSA-22c5-cpvr-cfvq/GHSA-22c5-cpvr-cfvq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-22c5-cpvr-cfvq", - "modified": "2024-12-17T12:31:38Z", + "modified": "2024-12-19T15:31:11Z", "published": "2024-12-12T09:31:36Z", "aliases": [ "CVE-2024-4109" @@ -56,6 +56,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:10933" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:11559" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-4109" diff --git a/advisories/unreviewed/2022/05/GHSA-hwvf-grj2-9364/GHSA-hwvf-grj2-9364.json b/advisories/unreviewed/2022/05/GHSA-hwvf-grj2-9364/GHSA-hwvf-grj2-9364.json index 4bc6269699f..91c7c4d98e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-hwvf-grj2-9364/GHSA-hwvf-grj2-9364.json +++ b/advisories/unreviewed/2022/05/GHSA-hwvf-grj2-9364/GHSA-hwvf-grj2-9364.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hwvf-grj2-9364", - "modified": "2022-05-24T17:29:25Z", + "modified": "2024-12-19T15:31:07Z", "published": "2022-05-24T17:29:25Z", "aliases": [ "CVE-2020-3390" ], "details": "A vulnerability in Simple Network Management Protocol (SNMP) trap generation for wireless clients of the Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family could allow an unauthenticated, adjacent attacker to cause the device to unexpectedly reload, causing a denial of service (DoS) condition on an affected device. The vulnerability is due to the lack of input validation of the information used to generate an SNMP trap in relation to a wireless client connection. An attacker could exploit this vulnerability by sending an 802.1x packet with crafted parameters during the wireless authentication setup phase of a connection. A successful exploit could allow the attacker to cause the device to reload, causing a DoS condition.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-vmh3-rhm9-223f/GHSA-vmh3-rhm9-223f.json b/advisories/unreviewed/2022/05/GHSA-vmh3-rhm9-223f/GHSA-vmh3-rhm9-223f.json index d58bfc47a01..6facab39af3 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmh3-rhm9-223f/GHSA-vmh3-rhm9-223f.json +++ b/advisories/unreviewed/2022/05/GHSA-vmh3-rhm9-223f/GHSA-vmh3-rhm9-223f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vmh3-rhm9-223f", - "modified": "2022-05-24T17:29:25Z", + "modified": "2024-12-19T15:31:07Z", "published": "2022-05-24T17:29:25Z", "aliases": [ "CVE-2020-3359" ], "details": "A vulnerability in the multicast DNS (mDNS) feature of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper validation of mDNS packets. An attacker could exploit this vulnerability by sending a crafted mDNS packet to an affected device. A successful exploit could cause a device to reload, resulting in a DoS condition.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2024/04/GHSA-gxh7-r3qj-jmff/GHSA-gxh7-r3qj-jmff.json b/advisories/unreviewed/2024/04/GHSA-gxh7-r3qj-jmff/GHSA-gxh7-r3qj-jmff.json index 21a9363fe25..c475fac240b 100644 --- a/advisories/unreviewed/2024/04/GHSA-gxh7-r3qj-jmff/GHSA-gxh7-r3qj-jmff.json +++ b/advisories/unreviewed/2024/04/GHSA-gxh7-r3qj-jmff/GHSA-gxh7-r3qj-jmff.json @@ -54,7 +54,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-79" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-jf9g-42gm-v87w/GHSA-jf9g-42gm-v87w.json b/advisories/unreviewed/2024/04/GHSA-jf9g-42gm-v87w/GHSA-jf9g-42gm-v87w.json index da01814b800..f84d8d8a630 100644 --- a/advisories/unreviewed/2024/04/GHSA-jf9g-42gm-v87w/GHSA-jf9g-42gm-v87w.json +++ b/advisories/unreviewed/2024/04/GHSA-jf9g-42gm-v87w/GHSA-jf9g-42gm-v87w.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-r8fc-3gvg-wxxf/GHSA-r8fc-3gvg-wxxf.json b/advisories/unreviewed/2024/04/GHSA-r8fc-3gvg-wxxf/GHSA-r8fc-3gvg-wxxf.json index 3457f143dac..09141975b57 100644 --- a/advisories/unreviewed/2024/04/GHSA-r8fc-3gvg-wxxf/GHSA-r8fc-3gvg-wxxf.json +++ b/advisories/unreviewed/2024/04/GHSA-r8fc-3gvg-wxxf/GHSA-r8fc-3gvg-wxxf.json @@ -54,7 +54,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-305" + "CWE-305", + "CWE-79" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-2gmr-g5v4-9cch/GHSA-2gmr-g5v4-9cch.json b/advisories/unreviewed/2024/12/GHSA-2gmr-g5v4-9cch/GHSA-2gmr-g5v4-9cch.json new file mode 100644 index 00000000000..65b4dad97c6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2gmr-g5v4-9cch/GHSA-2gmr-g5v4-9cch.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gmr-g5v4-9cch", + "modified": "2024-12-19T15:31:11Z", + "published": "2024-12-19T15:31:11Z", + "aliases": [ + "CVE-2024-12786" + ], + "details": "A vulnerability, which was classified as critical, was found in X1a0He Adobe Downloader up to 1.3.1 on macOS. Affected is the function shouldAcceptNewConnection of the file com.x1a0he.macOS.Adobe-Downloader.helper of the component XPC Service. The manipulation leads to improper privilege management. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. This product is not affiliated with the company Adobe.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12786" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.288966" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.288966" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.464685" + }, + { + "type": "WEB", + "url": "https://winslow1984.com/books/cve-collection/page/adobe-downloader-131-local-privilege-escalation" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T15:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5h2c-fvjp-2wmx/GHSA-5h2c-fvjp-2wmx.json b/advisories/unreviewed/2024/12/GHSA-5h2c-fvjp-2wmx/GHSA-5h2c-fvjp-2wmx.json index 6877153bafd..43364959814 100644 --- a/advisories/unreviewed/2024/12/GHSA-5h2c-fvjp-2wmx/GHSA-5h2c-fvjp-2wmx.json +++ b/advisories/unreviewed/2024/12/GHSA-5h2c-fvjp-2wmx/GHSA-5h2c-fvjp-2wmx.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-404" + "CWE-404", + "CWE-476" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-5mvx-j4j8-xv4p/GHSA-5mvx-j4j8-xv4p.json b/advisories/unreviewed/2024/12/GHSA-5mvx-j4j8-xv4p/GHSA-5mvx-j4j8-xv4p.json new file mode 100644 index 00000000000..c11d541e36e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5mvx-j4j8-xv4p/GHSA-5mvx-j4j8-xv4p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mvx-j4j8-xv4p", + "modified": "2024-12-19T15:31:11Z", + "published": "2024-12-19T15:31:11Z", + "aliases": [ + "CVE-2021-32589" + ], + "details": "A use after free in Fortinet FortiManager, FortiAnalyzer allows attacker to execute unauthorized code or commands via ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-32589" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-21-067" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T13:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5pvq-85hg-5rww/GHSA-5pvq-85hg-5rww.json b/advisories/unreviewed/2024/12/GHSA-5pvq-85hg-5rww/GHSA-5pvq-85hg-5rww.json new file mode 100644 index 00000000000..ff7830b802c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5pvq-85hg-5rww/GHSA-5pvq-85hg-5rww.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5pvq-85hg-5rww", + "modified": "2024-12-19T15:31:11Z", + "published": "2024-12-19T15:31:11Z", + "aliases": [ + "CVE-2024-12784" + ], + "details": "A vulnerability was found in itsourcecode Vehicle Management System 1.0. It has been classified as critical. Affected is an unknown function of the file editbill.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12784" + }, + { + "type": "WEB", + "url": "https://github.com/FinleyTang/Vehicle-Management-System/blob/main/Vehicle%20Management%20System%20editbill.php%20has%20Sqlinjection.pdf" + }, + { + "type": "WEB", + "url": "https://itsourcecode.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.288960" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.288960" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.462629" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T14:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-62jh-qwjh-cgr7/GHSA-62jh-qwjh-cgr7.json b/advisories/unreviewed/2024/12/GHSA-62jh-qwjh-cgr7/GHSA-62jh-qwjh-cgr7.json index 18268d4485a..856bd35e10e 100644 --- a/advisories/unreviewed/2024/12/GHSA-62jh-qwjh-cgr7/GHSA-62jh-qwjh-cgr7.json +++ b/advisories/unreviewed/2024/12/GHSA-62jh-qwjh-cgr7/GHSA-62jh-qwjh-cgr7.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-404" + "CWE-404", + "CWE-476" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-6mpf-h5jc-fvrw/GHSA-6mpf-h5jc-fvrw.json b/advisories/unreviewed/2024/12/GHSA-6mpf-h5jc-fvrw/GHSA-6mpf-h5jc-fvrw.json new file mode 100644 index 00000000000..3cc696559db --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6mpf-h5jc-fvrw/GHSA-6mpf-h5jc-fvrw.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mpf-h5jc-fvrw", + "modified": "2024-12-19T15:31:11Z", + "published": "2024-12-19T15:31:11Z", + "aliases": [ + "CVE-2024-9101" + ], + "details": "A reflected cross-site scripting (XSS) vulnerability in the 'Entry Chooser' of phpLDAPadmin (version 1.2.1 through the latest version, 1.2.6.7) allows attackers to execute arbitrary JavaScript in the user's browser via the 'element' parameter, which is unsafely passed to the JavaScript 'eval' function. However, exploitation is limited to specific conditions where 'opener' is correctly set.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9101" + }, + { + "type": "WEB", + "url": "https://github.com/leenooks/phpLDAPadmin/commit/f713afc8d164169516c91b0988531f2accb9bce6#diff-c2d6d7678ada004e704ee055169395a58227aaec86a6f75fa74ca18ff49bca44R27" + }, + { + "type": "WEB", + "url": "https://github.com/leenooks/phpLDAPadmin/blob/master/htdocs/entry_chooser.php" + }, + { + "type": "WEB", + "url": "https://sourceforge.net/projects/phpldapadmin/files/phpldapadmin-php5/1.2.1" + }, + { + "type": "WEB", + "url": "https://www.redguard.ch/blog/2024/12/19/security-advisory-phpldapadmin" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-77c2-c35q-254w/GHSA-77c2-c35q-254w.json b/advisories/unreviewed/2024/12/GHSA-77c2-c35q-254w/GHSA-77c2-c35q-254w.json new file mode 100644 index 00000000000..7ed50b92e41 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-77c2-c35q-254w/GHSA-77c2-c35q-254w.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77c2-c35q-254w", + "modified": "2024-12-19T15:31:11Z", + "published": "2024-12-19T15:31:11Z", + "aliases": [ + "CVE-2024-25131" + ], + "details": "A flaw was found in the MustGather.managed.openshift.io Custom Defined Resource (CRD) of OpenShift Dedicated. A non-privileged user on the cluster can create a MustGather object with a specially crafted file and set the most privileged service account to run the job. This can allow a standard developer user to escalate their privileges to a cluster administrator and pivot to the AWS environment.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25131" + }, + { + "type": "WEB", + "url": "https://github.com/openshift/must-gather-operator/pull/135" + }, + { + "type": "WEB", + "url": "https://github.com/openshift/must-gather-operator/pull/138" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-25131" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258856" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-g2mr-f5hm-6x69/GHSA-g2mr-f5hm-6x69.json b/advisories/unreviewed/2024/12/GHSA-g2mr-f5hm-6x69/GHSA-g2mr-f5hm-6x69.json index f19fe0438db..255e5741799 100644 --- a/advisories/unreviewed/2024/12/GHSA-g2mr-f5hm-6x69/GHSA-g2mr-f5hm-6x69.json +++ b/advisories/unreviewed/2024/12/GHSA-g2mr-f5hm-6x69/GHSA-g2mr-f5hm-6x69.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-404" + "CWE-404", + "CWE-476" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-hjr5-pr64-8mc2/GHSA-hjr5-pr64-8mc2.json b/advisories/unreviewed/2024/12/GHSA-hjr5-pr64-8mc2/GHSA-hjr5-pr64-8mc2.json index 65b5ff3f73c..786f033bc1b 100644 --- a/advisories/unreviewed/2024/12/GHSA-hjr5-pr64-8mc2/GHSA-hjr5-pr64-8mc2.json +++ b/advisories/unreviewed/2024/12/GHSA-hjr5-pr64-8mc2/GHSA-hjr5-pr64-8mc2.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-404" + "CWE-404", + "CWE-476" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-p8hv-f2qg-cxvv/GHSA-p8hv-f2qg-cxvv.json b/advisories/unreviewed/2024/12/GHSA-p8hv-f2qg-cxvv/GHSA-p8hv-f2qg-cxvv.json new file mode 100644 index 00000000000..31aadf9e0fd --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p8hv-f2qg-cxvv/GHSA-p8hv-f2qg-cxvv.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8hv-f2qg-cxvv", + "modified": "2024-12-19T15:31:11Z", + "published": "2024-12-19T15:31:11Z", + "aliases": [ + "CVE-2024-9102" + ], + "details": "phpLDAPadmin since at least version 1.2.0 through the latest version 1.2.6.7 allows users to export elements from the LDAP directory into a Comma-Separated Value (CSV) file, but it does not neutralize special elements that could be interpreted as a command when the file is opened by a spreadsheet product. Thus, this could lead to CSV Formula Injection.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9102" + }, + { + "type": "WEB", + "url": "https://github.com/leenooks/phpLDAPadmin/commit/ea17aadef46fd29850160987fe7740ceed1381ad#diff-93b9f3e6d4c5bdacf469ea0ec74c1e9217ca6272da9be5a1bfd711f7da16f9e3R240" + }, + { + "type": "WEB", + "url": "https://sourceforge.net/projects/phpldapadmin/files/phpldapadmin-php5/1.2.0" + }, + { + "type": "WEB", + "url": "https://www.redguard.ch/blog/2024/12/19/security-advisory-phpldapadmin" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1236" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-q73v-pp5w-q5mq/GHSA-q73v-pp5w-q5mq.json b/advisories/unreviewed/2024/12/GHSA-q73v-pp5w-q5mq/GHSA-q73v-pp5w-q5mq.json index fe6ea720a92..a2abcf81c8e 100644 --- a/advisories/unreviewed/2024/12/GHSA-q73v-pp5w-q5mq/GHSA-q73v-pp5w-q5mq.json +++ b/advisories/unreviewed/2024/12/GHSA-q73v-pp5w-q5mq/GHSA-q73v-pp5w-q5mq.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-404" + "CWE-404", + "CWE-476" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-qf32-jmjm-hhgw/GHSA-qf32-jmjm-hhgw.json b/advisories/unreviewed/2024/12/GHSA-qf32-jmjm-hhgw/GHSA-qf32-jmjm-hhgw.json new file mode 100644 index 00000000000..5464fc130f9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qf32-jmjm-hhgw/GHSA-qf32-jmjm-hhgw.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qf32-jmjm-hhgw", + "modified": "2024-12-19T15:31:11Z", + "published": "2024-12-19T15:31:11Z", + "aliases": [ + "CVE-2024-54790" + ], + "details": "A SQL Injection vulnerability was found in /index.php in PHPGurukul Pre-School Enrollment System v1.0, which allows remote attackers to execute arbitrary code via the visittime parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54790" + }, + { + "type": "WEB", + "url": "https://github.com/Santoshcyber1/CVE-wirteup/blob/main/Phpgurukul/Pre-School%20Enrollment/SQL%20Injection%20pr-school%20i.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rrjw-vh74-2hwv/GHSA-rrjw-vh74-2hwv.json b/advisories/unreviewed/2024/12/GHSA-rrjw-vh74-2hwv/GHSA-rrjw-vh74-2hwv.json index 7a93006e96c..77506875a59 100644 --- a/advisories/unreviewed/2024/12/GHSA-rrjw-vh74-2hwv/GHSA-rrjw-vh74-2hwv.json +++ b/advisories/unreviewed/2024/12/GHSA-rrjw-vh74-2hwv/GHSA-rrjw-vh74-2hwv.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-404" + "CWE-404", + "CWE-476" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-wh36-w27p-cfw8/GHSA-wh36-w27p-cfw8.json b/advisories/unreviewed/2024/12/GHSA-wh36-w27p-cfw8/GHSA-wh36-w27p-cfw8.json new file mode 100644 index 00000000000..ea090e35cb3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wh36-w27p-cfw8/GHSA-wh36-w27p-cfw8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wh36-w27p-cfw8", + "modified": "2024-12-19T15:31:11Z", + "published": "2024-12-19T15:31:11Z", + "aliases": [ + "CVE-2024-10244" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ISDO Software Web Software allows SQL Injection.This issue affects Web Software: before 3.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10244" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1893" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T14:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wq8r-q99m-pp5x/GHSA-wq8r-q99m-pp5x.json b/advisories/unreviewed/2024/12/GHSA-wq8r-q99m-pp5x/GHSA-wq8r-q99m-pp5x.json new file mode 100644 index 00000000000..9a5db1bd732 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wq8r-q99m-pp5x/GHSA-wq8r-q99m-pp5x.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wq8r-q99m-pp5x", + "modified": "2024-12-19T15:31:11Z", + "published": "2024-12-19T15:31:11Z", + "aliases": [ + "CVE-2024-12783" + ], + "details": "A vulnerability was found in itsourcecode Vehicle Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /billaction.php. The manipulation of the argument extra-cost leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12783" + }, + { + "type": "WEB", + "url": "https://github.com/FinleyTang/Vehicle-Management-System/blob/main/Vehicle%20Management%20System%20billaction.php%20has%20Cross-site%20Scripting%20(XSS).pdf" + }, + { + "type": "WEB", + "url": "https://itsourcecode.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.288959" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.288959" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.462628" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wwq6-xmjh-4f52/GHSA-wwq6-xmjh-4f52.json b/advisories/unreviewed/2024/12/GHSA-wwq6-xmjh-4f52/GHSA-wwq6-xmjh-4f52.json new file mode 100644 index 00000000000..683a24e0ad7 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wwq6-xmjh-4f52/GHSA-wwq6-xmjh-4f52.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wwq6-xmjh-4f52", + "modified": "2024-12-19T15:31:11Z", + "published": "2024-12-19T15:31:11Z", + "aliases": [ + "CVE-2021-26102" + ], + "details": "A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated attacker to delete files on the system by sending a crafted POST request. In particular, deleting specific configuration files will reset the Admin password to its default value.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-26102" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-21-048" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-305" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T14:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-x5mp-q3w8-grg7/GHSA-x5mp-q3w8-grg7.json b/advisories/unreviewed/2024/12/GHSA-x5mp-q3w8-grg7/GHSA-x5mp-q3w8-grg7.json new file mode 100644 index 00000000000..3cb199b69f7 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-x5mp-q3w8-grg7/GHSA-x5mp-q3w8-grg7.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x5mp-q3w8-grg7", + "modified": "2024-12-19T15:31:11Z", + "published": "2024-12-19T15:31:11Z", + "aliases": [ + "CVE-2024-12785" + ], + "details": "A vulnerability was found in itsourcecode Vehicle Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file sendmail.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12785" + }, + { + "type": "WEB", + "url": "https://github.com/FinleyTang/Vehicle-Management-System/blob/main/Vehicle%20Management%20System%20sendmail.php%20has%20Sqlinjection.pdf" + }, + { + "type": "WEB", + "url": "https://itsourcecode.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.288961" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.288961" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.462631" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T15:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xc5w-rmjg-qwhh/GHSA-xc5w-rmjg-qwhh.json b/advisories/unreviewed/2024/12/GHSA-xc5w-rmjg-qwhh/GHSA-xc5w-rmjg-qwhh.json new file mode 100644 index 00000000000..249d53d7472 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xc5w-rmjg-qwhh/GHSA-xc5w-rmjg-qwhh.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xc5w-rmjg-qwhh", + "modified": "2024-12-19T15:31:11Z", + "published": "2024-12-19T15:31:11Z", + "aliases": [ + "CVE-2024-47093" + ], + "details": "Improper neutralization of input in Nagvis before version 1.9.42 which can lead to XSS", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47093" + }, + { + "type": "WEB", + "url": "https://github.com/NagVis/nagvis/commit/30e71e8167d17a1828e7da71d6942f6fb36478cd" + }, + { + "type": "WEB", + "url": "https://github.com/NagVis/nagvis/commit/b5b1164007439de526df7d54d5c02d7732ba1c42" + }, + { + "type": "WEB", + "url": "https://www.nagvis.org/downloads/changelog/1.9.42" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xf4j-mpgp-536j/GHSA-xf4j-mpgp-536j.json b/advisories/unreviewed/2024/12/GHSA-xf4j-mpgp-536j/GHSA-xf4j-mpgp-536j.json index d45e869fa6f..38f0425c3c5 100644 --- a/advisories/unreviewed/2024/12/GHSA-xf4j-mpgp-536j/GHSA-xf4j-mpgp-536j.json +++ b/advisories/unreviewed/2024/12/GHSA-xf4j-mpgp-536j/GHSA-xf4j-mpgp-536j.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-404" + "CWE-404", + "CWE-476" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-xmrx-vg29-jh4h/GHSA-xmrx-vg29-jh4h.json b/advisories/unreviewed/2024/12/GHSA-xmrx-vg29-jh4h/GHSA-xmrx-vg29-jh4h.json new file mode 100644 index 00000000000..a09dc44b6b8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xmrx-vg29-jh4h/GHSA-xmrx-vg29-jh4h.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmrx-vg29-jh4h", + "modified": "2024-12-19T15:31:11Z", + "published": "2024-12-19T15:31:11Z", + "aliases": [ + "CVE-2024-12782" + ], + "details": "A vulnerability has been found in Fujifilm Apeos C3070, Apeos C5570 and Apeos C6580 up to 24.8.28 and classified as critical. This vulnerability affects unknown code of the file /home/index.html#hashHome of the component Web Interface. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12782" + }, + { + "type": "WEB", + "url": "https://github.com/dycccccccc/Fuji/blob/main/Fujifilm%20Business%20Innovation.docx" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.288958" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.288958" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.458897" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T13:15:05Z" + } +} \ No newline at end of file