Publish Advisories

GHSA-5f4g-m368-xv75
GHSA-23wx-6wm2-v53g
GHSA-74j3-65q6-x5h9
GHSA-9f2j-hwhw-8fxw
GHSA-jw3g-fq47-7q3j
GHSA-57g7-92mv-gwwp
GHSA-xx3p-5m4j-rhw8
GHSA-xxxw-3j6h-q7h6
This commit is contained in:
advisory-database[bot]
2024-09-19 12:33:02 +00:00
parent 14fced448e
commit 99760bfef5
8 changed files with 103 additions and 10 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5f4g-m368-xv75",
"modified": "2022-04-16T00:01:13Z",
"modified": "2024-09-19T12:31:20Z",
"published": "2022-04-12T00:00:38Z",
"aliases": [
"CVE-2022-1252"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-23wx-6wm2-v53g",
"modified": "2022-05-24T19:06:07Z",
"modified": "2024-09-19T12:31:20Z",
"published": "2022-05-24T19:06:07Z",
"aliases": [
"CVE-2020-18662"
],
"details": "SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-74j3-65q6-x5h9",
"modified": "2022-05-24T17:00:37Z",
"modified": "2024-09-19T12:31:20Z",
"published": "2022-05-24T17:00:37Z",
"aliases": [
"CVE-2018-18674"
],
"details": "GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the \"board tail contents\" parameter, aka the adm/board_form_update.php bo_content_tail parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -33,7 +36,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9f2j-hwhw-8fxw",
"modified": "2022-05-24T19:06:07Z",
"modified": "2024-09-19T12:31:20Z",
"published": "2022-05-24T19:06:07Z",
"aliases": [
"CVE-2020-18663"
],
"details": "Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the act parameter in bbs/move_update.php.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jw3g-fq47-7q3j",
"modified": "2022-05-24T19:06:08Z",
"modified": "2024-09-19T12:31:20Z",
"published": "2022-05-24T19:06:08Z",
"aliases": [
"CVE-2020-18661"
],
"details": "Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the url parameter to bbs/login.php.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -32,6 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-707",
"CWE-79"
],
"severity": "MODERATE",
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xx3p-5m4j-rhw8",
"modified": "2024-09-19T12:31:20Z",
"published": "2024-09-19T12:31:20Z",
"aliases": [
"CVE-2024-8354"
],
"details": "A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivileged guest user to crash the QEMU process on the host and cause a denial of service condition.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8354"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-8354"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2313497"
}
],
"database_specific": {
"cwe_ids": [
"CWE-617"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-19T11:15:10Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xxxw-3j6h-q7h6",
"modified": "2024-09-19T12:31:20Z",
"published": "2024-09-19T12:31:20Z",
"aliases": [
"CVE-2024-8986"
],
"details": "The grafana plugin SDK bundles build metadata into the binaries it compiles; this metadata includes the repository URI for the plugin being built, as retrieved by running `git remote get-url origin`.\n \nIf credentials are included in the repository URI (for instance, to allow for fetching of private dependencies), the final binary will contain the full URI, including said credentials.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:L/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8986"
},
{
"type": "WEB",
"url": "https://grafana.com/security/security-advisories/cve-2024-8986"
}
],
"database_specific": {
"cwe_ids": [
"CWE-522"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-19T11:15:10Z"
}
}