Publish Advisories

GHSA-78hx-gp6g-7mj6
GHSA-9mhc-h3vf-83fw
GHSA-76p4-frhc-q2c5
GHSA-h65f-46fv-r349
GHSA-mcpx-wv4g-3hg5
This commit is contained in:
advisory-database[bot]
2024-06-26 12:33:22 +00:00
parent a3a4a0d8d0
commit 985547a5bc
5 changed files with 152 additions and 7 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-78hx-gp6g-7mj6",
"modified": "2024-05-23T00:30:37Z",
"modified": "2024-06-26T12:32:06Z",
"published": "2024-03-20T18:10:36Z",
"aliases": [
"CVE-2024-1394"
@@ -134,10 +134,6 @@
"type": "WEB",
"url": "https://github.com/golang-fips/openssl/commit/85d31d0d257ce842c8a1e63c4d230ae850348136"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1462"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2569"
@@ -158,6 +154,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:3265"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:3352"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-1394"
@@ -186,6 +186,10 @@
"type": "WEB",
"url": "https://vuln.go.dev/ID/GO-2024-2660.json"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1462"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1468"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9mhc-h3vf-83fw",
"modified": "2022-05-24T17:03:59Z",
"modified": "2024-06-26T12:32:03Z",
"published": "2022-05-24T17:03:59Z",
"aliases": [
"CVE-2019-1387"
],
"details": "An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are currently affected by a vulnerability that is caused by too-lax validation of submodule names, allowing very targeted attacks via remote code execution in recursive clones.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -38,14 +41,30 @@
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2020/01/msg00019.html"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00018.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N6UGTEOXWIYSM5KDZL74QD2GK6YQNQCP"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N6UGTEOXWIYSM5KDZL74QD2GK6YQNQCP"
},
{
"type": "WEB",
"url": "https://lore.kernel.org/git/xmqqr21cqcn9.fsf%40gitster-ct.c.googlers.com/T/#u"
},
{
"type": "WEB",
"url": "https://lore.kernel.org/git/xmqqr21cqcn9.fsf@gitster-ct.c.googlers.com/T/#u"
},
{
"type": "WEB",
"url": "https://public-inbox.org/git/xmqqr21cqcn9.fsf%40gitster-ct.c.googlers.com"
},
{
"type": "WEB",
"url": "https://public-inbox.org/git/xmqqr21cqcn9.fsf@gitster-ct.c.googlers.com"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-76p4-frhc-q2c5",
"modified": "2024-06-26T12:32:05Z",
"published": "2024-06-26T12:32:05Z",
"aliases": [
"CVE-2024-37252"
],
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Icegram Email Subscribers & Newsletters allows SQL Injection.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.25.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37252"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/email-subscribers/wordpress-email-subscribers-by-icegram-express-plugin-5-7-25-sql-injection-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-26T11:15:51Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h65f-46fv-r349",
"modified": "2024-06-26T12:32:05Z",
"published": "2024-06-26T12:32:05Z",
"aliases": [
"CVE-2024-37098"
],
"details": "Server-Side Request Forgery (SSRF) vulnerability in Blossom Themes BlossomThemes Email Newsletter.This issue affects BlossomThemes Email Newsletter: from n/a through 2.2.6.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37098"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/blossomthemes-email-newsletter/wordpress-blossomthemes-email-newsletter-plugin-2-2-7-server-side-request-forgery-ssrf-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-918"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-26T11:15:51Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mcpx-wv4g-3hg5",
"modified": "2024-06-26T12:32:05Z",
"published": "2024-06-26T12:32:05Z",
"aliases": [
"CVE-2024-6344"
],
"details": "A vulnerability, which was classified as problematic, was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. This affects an unknown part of the component Push Configuration Section. The manipulation of the argument Configuration Name leads to cross site scripting. It is possible to initiate the attack remotely. The identifier VDB-269733 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6344"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.269733"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.269733"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.358596"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-26T11:15:52Z"
}
}