Publish Advisories

GHSA-7jpg-h873-5g68
GHSA-3cpq-rw36-cppv
GHSA-3pp9-5jvj-qcv4
GHSA-549r-m25h-hvpx
GHSA-6pfp-pc86-29qj
GHSA-9pc7-h97p-m6xj
GHSA-gw84-qf63-55gw
GHSA-j67r-3cm4-272w
GHSA-pc6r-5rpf-rh32
GHSA-qf8r-gmh3-q7x2
GHSA-qr6m-fxwf-qgc5
GHSA-r2pp-5j58-wrhj
GHSA-rjfp-3rm3-gx89
GHSA-vhhg-73hp-mrc2
GHSA-vqjg-5pqm-q7ph
GHSA-w65f-4h2f-cpj2
GHSA-x8mf-jcmf-r79f
GHSA-xfx3-cr74-x3cv
This commit is contained in:
advisory-database[bot]
2024-06-26 18:32:00 +00:00
parent fb7446606d
commit 995f208dfa
18 changed files with 313 additions and 25 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7jpg-h873-5g68",
"modified": "2023-11-02T03:30:25Z",
"modified": "2024-06-26T18:30:27Z",
"published": "2023-06-16T21:30:27Z",
"aliases": [
"CVE-2023-35788"
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3cpq-rw36-cppv",
"modified": "2024-06-26T18:30:28Z",
"published": "2024-06-26T18:30:28Z",
"aliases": [
"CVE-2024-39459"
],
"details": "In rare cases Jenkins Plain Credentials Plugin 182.v468b_97b_9dcb_8 and earlier stores secret file credentials unencrypted (only Base64 encoded) on the Jenkins controller file system, where they can be viewed by users with access to the Jenkins controller file system (global credentials) or with Item/Extended Read permission (folder-scoped credentials).",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39459"
},
{
"type": "WEB",
"url": "https://www.jenkins.io/security/advisory/2024-06-26/#SECURITY-2495"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/06/26/2"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-26T17:15:27Z"
}
}
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-451"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-549r-m25h-hvpx",
"modified": "2024-06-24T21:33:21Z",
"modified": "2024-06-26T18:30:27Z",
"published": "2024-06-24T21:33:20Z",
"aliases": [
"CVE-2024-37677"
],
"details": "An issue in Shenzhen Weitillage Industrial Co., Ltd the access management specialist V6.62.51215 allows a remote attacker to obtain sensitive information.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-24T19:15:15Z"
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6pfp-pc86-29qj",
"modified": "2024-06-26T18:30:28Z",
"published": "2024-06-26T18:30:28Z",
"aliases": [
"CVE-2024-38271"
],
"details": "There exists a vulnerability in Quickshare/Nearby where an attacker can force the a victim to stay connected to a temporary hotspot created for the share. As part of the sequence of packets in a QuickShare connection over Bluetooth, the attacker forces the victim to connect to the attackers WiFi network and then sends an OfflineFrame that crashes Quick Share.\nThis makes the Wifi connection to the attackers network last instead of returning to the old network when the Quick Share session is done allowing the attacker to be a MiTM. We recommend upgrading to version 1.0.1724.0 of Quickshare or above",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38271"
},
{
"type": "WEB",
"url": "https://github.com/google/nearby/pull/2433"
},
{
"type": "WEB",
"url": "https://github.com/google/nearby/pull/2435"
}
],
"database_specific": {
"cwe_ids": [
"CWE-404"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-26T16:15:11Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9pc7-h97p-m6xj",
"modified": "2024-06-24T21:33:21Z",
"modified": "2024-06-26T18:30:27Z",
"published": "2024-06-24T21:33:21Z",
"aliases": [
"CVE-2024-37679"
],
"details": "Cross Site Scripting vulnerability in Hangzhou Meisoft Information Technology Co., Ltd. Finesoft v.8.0 and before allows a remote attacker to execute arbitrary code via a crafted script to the login.jsp parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-24T19:15:15Z"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gw84-qf63-55gw",
"modified": "2024-06-26T18:30:28Z",
"published": "2024-06-26T18:30:28Z",
"aliases": [
"CVE-2024-6354"
],
"details": "Improper access control in PAM dashboard in Devolutions Remote Desktop Manager 2024.2.11 and earlier on Windows allows an authenticated user to bypass the execute permission via the use of the PAM dashboard.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6354"
},
{
"type": "WEB",
"url": "https://devolutions.net/security/advisories/DEVO-2024-0010"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-26T17:15:27Z"
}
}
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-357"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-356"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qf8r-gmh3-q7x2",
"modified": "2024-06-26T18:30:28Z",
"published": "2024-06-26T18:30:28Z",
"aliases": [
"CVE-2024-38272"
],
"details": "There exists a vulnerability in Quickshare/Nearby where an attacker can bypass the accept file dialog on QuickShare Windows. Normally in QuickShare Windows app we can't send a file without the user accept from the receiving device if the visibility is set to everyone mode or contacts mode. We recommend upgrading to version 1.0.1724.0 of Quickshare or above",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38272"
},
{
"type": "WEB",
"url": "https://github.com/google/nearby/pull/2402"
},
{
"type": "WEB",
"url": "https://github.com/google/nearby/pull/2589"
}
],
"database_specific": {
"cwe_ids": [
"CWE-294"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-26T16:15:11Z"
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qr6m-fxwf-qgc5",
"modified": "2024-06-26T18:30:28Z",
"published": "2024-06-26T18:30:28Z",
"aliases": [
"CVE-2024-35545"
],
"details": "MAP-OS v4.45.0 and earlier was discovered to contain a cross-site scripting (XSS) vulnerability.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35545"
},
{
"type": "WEB",
"url": "https://github.com/RamonSilva20/mapos/commit/3559bae4782162faab94670f503fd35b0f331929"
},
{
"type": "WEB",
"url": "https://github.com/RamonSilva20/mapos/tree/master"
},
{
"type": "WEB",
"url": "https://portswigger.net/web-security/cross-site-scripting/stored"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-26T18:15:14Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r2pp-5j58-wrhj",
"modified": "2024-06-24T21:33:21Z",
"modified": "2024-06-26T18:30:27Z",
"published": "2024-06-24T21:33:20Z",
"aliases": [
"CVE-2024-37680"
],
"details": "Hangzhou Meisoft Information Technology Co., Ltd. FineSoft <=8.0 is affected by Cross Site Scripting (XSS) which allows remote attackers to execute arbitrary code. Enter any account and password, click Login, the page will report an error, and a controllable parameter will appear at the URL:weburl.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-24T19:15:15Z"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-449"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-451"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vqjg-5pqm-q7ph",
"modified": "2024-06-24T21:33:21Z",
"modified": "2024-06-26T18:30:27Z",
"published": "2024-06-24T21:33:20Z",
"aliases": [
"CVE-2024-37732"
],
"details": "Cross Site Scripting vulnerability in Anchor CMS v.0.12.7 allows a remote attacker to execute arbitrary code via a crafted .pdf file.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-24T19:15:15Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w65f-4h2f-cpj2",
"modified": "2024-06-24T21:33:21Z",
"modified": "2024-06-26T18:30:27Z",
"published": "2024-06-24T21:33:21Z",
"aliases": [
"CVE-2021-45785"
],
"details": "TruDesk Help Desk/Ticketing Solution v1.1.11 is vulnerable to a Cross-Site Request Forgery (CSRF) attack which would allow an attacker to restart the server, causing a DoS attack. The attacker must craft a webpage that would perform a GET request to the /api/v1/admin/restart endpoint, then the victim (who has sufficient privileges), would visit the page and the server restart would begin. The attacker must know the full URL that TruDesk is on in order to craft the webpage.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-24T19:15:11Z"
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x8mf-jcmf-r79f",
"modified": "2024-06-26T18:30:28Z",
"published": "2024-06-26T18:30:28Z",
"aliases": [
"CVE-2024-39460"
],
"details": "Jenkins Bitbucket Branch Source Plugin 886.v44cf5e4ecec5 and earlier prints the Bitbucket OAuth access token as part of the Bitbucket URL in the build log in some cases.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39460"
},
{
"type": "WEB",
"url": "https://www.jenkins.io/security/advisory/2024-06-26/#SECURITY-3363"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/06/26/2"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-26T17:15:27Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xfx3-cr74-x3cv",
"modified": "2024-06-26T18:30:28Z",
"published": "2024-06-26T18:30:28Z",
"aliases": [
"CVE-2024-39458"
],
"details": "When Jenkins Structs Plugin 337.v1b_04ea_4df7c8 and earlier fails to configure a build step, it logs a warning message containing diagnostic information that may contain secrets passed as step parameters, potentially resulting in accidental exposure of secrets through the default system log.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39458"
},
{
"type": "WEB",
"url": "https://www.jenkins.io/security/advisory/2024-06-26/#SECURITY-3371"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/06/26/2"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-26T17:15:27Z"
}
}