diff --git a/advisories/unreviewed/2022/04/GHSA-5f4g-m368-xv75/GHSA-5f4g-m368-xv75.json b/advisories/unreviewed/2022/04/GHSA-5f4g-m368-xv75/GHSA-5f4g-m368-xv75.json index 8612645fe70..e05a87f357a 100644 --- a/advisories/unreviewed/2022/04/GHSA-5f4g-m368-xv75/GHSA-5f4g-m368-xv75.json +++ b/advisories/unreviewed/2022/04/GHSA-5f4g-m368-xv75/GHSA-5f4g-m368-xv75.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5f4g-m368-xv75", - "modified": "2022-04-16T00:01:13Z", + "modified": "2024-09-19T12:31:20Z", "published": "2022-04-12T00:00:38Z", "aliases": [ "CVE-2022-1252" diff --git a/advisories/unreviewed/2022/05/GHSA-23wx-6wm2-v53g/GHSA-23wx-6wm2-v53g.json b/advisories/unreviewed/2022/05/GHSA-23wx-6wm2-v53g/GHSA-23wx-6wm2-v53g.json index 65672947c1c..ad9e7720cc2 100644 --- a/advisories/unreviewed/2022/05/GHSA-23wx-6wm2-v53g/GHSA-23wx-6wm2-v53g.json +++ b/advisories/unreviewed/2022/05/GHSA-23wx-6wm2-v53g/GHSA-23wx-6wm2-v53g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-23wx-6wm2-v53g", - "modified": "2022-05-24T19:06:07Z", + "modified": "2024-09-19T12:31:20Z", "published": "2022-05-24T19:06:07Z", "aliases": [ "CVE-2020-18662" ], "details": "SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-74j3-65q6-x5h9/GHSA-74j3-65q6-x5h9.json b/advisories/unreviewed/2022/05/GHSA-74j3-65q6-x5h9/GHSA-74j3-65q6-x5h9.json index c42945e4a59..f1a75d6a5d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-74j3-65q6-x5h9/GHSA-74j3-65q6-x5h9.json +++ b/advisories/unreviewed/2022/05/GHSA-74j3-65q6-x5h9/GHSA-74j3-65q6-x5h9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-74j3-65q6-x5h9", - "modified": "2022-05-24T17:00:37Z", + "modified": "2024-09-19T12:31:20Z", "published": "2022-05-24T17:00:37Z", "aliases": [ "CVE-2018-18674" ], "details": "GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the \"board tail contents\" parameter, aka the adm/board_form_update.php bo_content_tail parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-9f2j-hwhw-8fxw/GHSA-9f2j-hwhw-8fxw.json b/advisories/unreviewed/2022/05/GHSA-9f2j-hwhw-8fxw/GHSA-9f2j-hwhw-8fxw.json index e301db39aef..44a7160d1bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-9f2j-hwhw-8fxw/GHSA-9f2j-hwhw-8fxw.json +++ b/advisories/unreviewed/2022/05/GHSA-9f2j-hwhw-8fxw/GHSA-9f2j-hwhw-8fxw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9f2j-hwhw-8fxw", - "modified": "2022-05-24T19:06:07Z", + "modified": "2024-09-19T12:31:20Z", "published": "2022-05-24T19:06:07Z", "aliases": [ "CVE-2020-18663" ], "details": "Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the act parameter in bbs/move_update.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-jw3g-fq47-7q3j/GHSA-jw3g-fq47-7q3j.json b/advisories/unreviewed/2022/05/GHSA-jw3g-fq47-7q3j/GHSA-jw3g-fq47-7q3j.json index b4ea0ccc65c..ef2c7ec9fda 100644 --- a/advisories/unreviewed/2022/05/GHSA-jw3g-fq47-7q3j/GHSA-jw3g-fq47-7q3j.json +++ b/advisories/unreviewed/2022/05/GHSA-jw3g-fq47-7q3j/GHSA-jw3g-fq47-7q3j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jw3g-fq47-7q3j", - "modified": "2022-05-24T19:06:08Z", + "modified": "2024-09-19T12:31:20Z", "published": "2022-05-24T19:06:08Z", "aliases": [ "CVE-2020-18661" ], "details": "Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the url parameter to bbs/login.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/11/GHSA-57g7-92mv-gwwp/GHSA-57g7-92mv-gwwp.json b/advisories/unreviewed/2022/11/GHSA-57g7-92mv-gwwp/GHSA-57g7-92mv-gwwp.json index fb6a1438b91..dac3c0e9c2d 100644 --- a/advisories/unreviewed/2022/11/GHSA-57g7-92mv-gwwp/GHSA-57g7-92mv-gwwp.json +++ b/advisories/unreviewed/2022/11/GHSA-57g7-92mv-gwwp/GHSA-57g7-92mv-gwwp.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-707", "CWE-79" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/09/GHSA-xx3p-5m4j-rhw8/GHSA-xx3p-5m4j-rhw8.json b/advisories/unreviewed/2024/09/GHSA-xx3p-5m4j-rhw8/GHSA-xx3p-5m4j-rhw8.json new file mode 100644 index 00000000000..8ff2b9ce28e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xx3p-5m4j-rhw8/GHSA-xx3p-5m4j-rhw8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xx3p-5m4j-rhw8", + "modified": "2024-09-19T12:31:20Z", + "published": "2024-09-19T12:31:20Z", + "aliases": [ + "CVE-2024-8354" + ], + "details": "A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivileged guest user to crash the QEMU process on the host and cause a denial of service condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8354" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-8354" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2313497" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-617" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-19T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xxxw-3j6h-q7h6/GHSA-xxxw-3j6h-q7h6.json b/advisories/unreviewed/2024/09/GHSA-xxxw-3j6h-q7h6/GHSA-xxxw-3j6h-q7h6.json new file mode 100644 index 00000000000..34884584e43 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xxxw-3j6h-q7h6/GHSA-xxxw-3j6h-q7h6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxxw-3j6h-q7h6", + "modified": "2024-09-19T12:31:20Z", + "published": "2024-09-19T12:31:20Z", + "aliases": [ + "CVE-2024-8986" + ], + "details": "The grafana plugin SDK bundles build metadata into the binaries it compiles; this metadata includes the repository URI for the plugin being built, as retrieved by running `git remote get-url origin`.\n \nIf credentials are included in the repository URI (for instance, to allow for fetching of private dependencies), the final binary will contain the full URI, including said credentials.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:L/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8986" + }, + { + "type": "WEB", + "url": "https://grafana.com/security/security-advisories/cve-2024-8986" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-19T11:15:10Z" + } +} \ No newline at end of file