diff --git a/advisories/github-reviewed/2024/03/GHSA-78hx-gp6g-7mj6/GHSA-78hx-gp6g-7mj6.json b/advisories/github-reviewed/2024/03/GHSA-78hx-gp6g-7mj6/GHSA-78hx-gp6g-7mj6.json index 671e8b5480c..c4164b5544c 100644 --- a/advisories/github-reviewed/2024/03/GHSA-78hx-gp6g-7mj6/GHSA-78hx-gp6g-7mj6.json +++ b/advisories/github-reviewed/2024/03/GHSA-78hx-gp6g-7mj6/GHSA-78hx-gp6g-7mj6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-78hx-gp6g-7mj6", - "modified": "2024-05-23T00:30:37Z", + "modified": "2024-06-26T12:32:06Z", "published": "2024-03-20T18:10:36Z", "aliases": [ "CVE-2024-1394" @@ -134,10 +134,6 @@ "type": "WEB", "url": "https://github.com/golang-fips/openssl/commit/85d31d0d257ce842c8a1e63c4d230ae850348136" }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:1462" - }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:2569" @@ -158,6 +154,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:3265" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:3352" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-1394" @@ -186,6 +186,10 @@ "type": "WEB", "url": "https://vuln.go.dev/ID/GO-2024-2660.json" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1462" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:1468" diff --git a/advisories/unreviewed/2022/05/GHSA-9mhc-h3vf-83fw/GHSA-9mhc-h3vf-83fw.json b/advisories/unreviewed/2022/05/GHSA-9mhc-h3vf-83fw/GHSA-9mhc-h3vf-83fw.json index 90a0943320b..65de21e18d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-9mhc-h3vf-83fw/GHSA-9mhc-h3vf-83fw.json +++ b/advisories/unreviewed/2022/05/GHSA-9mhc-h3vf-83fw/GHSA-9mhc-h3vf-83fw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9mhc-h3vf-83fw", - "modified": "2022-05-24T17:03:59Z", + "modified": "2024-06-26T12:32:03Z", "published": "2022-05-24T17:03:59Z", "aliases": [ "CVE-2019-1387" ], "details": "An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are currently affected by a vulnerability that is caused by too-lax validation of submodule names, allowing very targeted attacks via remote code execution in recursive clones.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -38,14 +41,30 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2020/01/msg00019.html" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00018.html" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N6UGTEOXWIYSM5KDZL74QD2GK6YQNQCP" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N6UGTEOXWIYSM5KDZL74QD2GK6YQNQCP" }, + { + "type": "WEB", + "url": "https://lore.kernel.org/git/xmqqr21cqcn9.fsf%40gitster-ct.c.googlers.com/T/#u" + }, { "type": "WEB", "url": "https://lore.kernel.org/git/xmqqr21cqcn9.fsf@gitster-ct.c.googlers.com/T/#u" }, + { + "type": "WEB", + "url": "https://public-inbox.org/git/xmqqr21cqcn9.fsf%40gitster-ct.c.googlers.com" + }, { "type": "WEB", "url": "https://public-inbox.org/git/xmqqr21cqcn9.fsf@gitster-ct.c.googlers.com" diff --git a/advisories/unreviewed/2024/06/GHSA-76p4-frhc-q2c5/GHSA-76p4-frhc-q2c5.json b/advisories/unreviewed/2024/06/GHSA-76p4-frhc-q2c5/GHSA-76p4-frhc-q2c5.json new file mode 100644 index 00000000000..005256e1caa --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-76p4-frhc-q2c5/GHSA-76p4-frhc-q2c5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76p4-frhc-q2c5", + "modified": "2024-06-26T12:32:05Z", + "published": "2024-06-26T12:32:05Z", + "aliases": [ + "CVE-2024-37252" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Icegram Email Subscribers & Newsletters allows SQL Injection.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.25.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37252" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/email-subscribers/wordpress-email-subscribers-by-icegram-express-plugin-5-7-25-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T11:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-h65f-46fv-r349/GHSA-h65f-46fv-r349.json b/advisories/unreviewed/2024/06/GHSA-h65f-46fv-r349/GHSA-h65f-46fv-r349.json new file mode 100644 index 00000000000..3d7587059d7 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-h65f-46fv-r349/GHSA-h65f-46fv-r349.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h65f-46fv-r349", + "modified": "2024-06-26T12:32:05Z", + "published": "2024-06-26T12:32:05Z", + "aliases": [ + "CVE-2024-37098" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in Blossom Themes BlossomThemes Email Newsletter.This issue affects BlossomThemes Email Newsletter: from n/a through 2.2.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37098" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/blossomthemes-email-newsletter/wordpress-blossomthemes-email-newsletter-plugin-2-2-7-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T11:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-mcpx-wv4g-3hg5/GHSA-mcpx-wv4g-3hg5.json b/advisories/unreviewed/2024/06/GHSA-mcpx-wv4g-3hg5/GHSA-mcpx-wv4g-3hg5.json new file mode 100644 index 00000000000..7dc97999e37 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-mcpx-wv4g-3hg5/GHSA-mcpx-wv4g-3hg5.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcpx-wv4g-3hg5", + "modified": "2024-06-26T12:32:05Z", + "published": "2024-06-26T12:32:05Z", + "aliases": [ + "CVE-2024-6344" + ], + "details": "A vulnerability, which was classified as problematic, was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. This affects an unknown part of the component Push Configuration Section. The manipulation of the argument Configuration Name leads to cross site scripting. It is possible to initiate the attack remotely. The identifier VDB-269733 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6344" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.269733" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.269733" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.358596" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T11:15:52Z" + } +} \ No newline at end of file