From 9b3eff4c71965e9839c6b26a0789c70833b97aa3 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 24 Jul 2024 00:32:45 +0000 Subject: [PATCH] Publish Advisories GHSA-78hx-gp6g-7mj6 GHSA-v727-f437-6cxx GHSA-q262-3hfr-f5q4 GHSA-2x8c-95vh-gfv4 GHSA-67gf-x3r4-p4fq GHSA-g5qj-pfmg-p3jp GHSA-wg3w-75pp-j436 --- .../GHSA-78hx-gp6g-7mj6.json | 18 ++++++--- .../GHSA-v727-f437-6cxx.json | 10 ++++- .../GHSA-q262-3hfr-f5q4.json | 6 ++- .../GHSA-2x8c-95vh-gfv4.json | 6 ++- .../GHSA-67gf-x3r4-p4fq.json | 38 +++++++++++++++++++ .../GHSA-g5qj-pfmg-p3jp.json | 6 ++- .../GHSA-wg3w-75pp-j436.json | 38 +++++++++++++++++++ 7 files changed, 113 insertions(+), 9 deletions(-) create mode 100644 advisories/unreviewed/2024/07/GHSA-67gf-x3r4-p4fq/GHSA-67gf-x3r4-p4fq.json create mode 100644 advisories/unreviewed/2024/07/GHSA-wg3w-75pp-j436/GHSA-wg3w-75pp-j436.json diff --git a/advisories/github-reviewed/2024/03/GHSA-78hx-gp6g-7mj6/GHSA-78hx-gp6g-7mj6.json b/advisories/github-reviewed/2024/03/GHSA-78hx-gp6g-7mj6/GHSA-78hx-gp6g-7mj6.json index 69644307d8d..d7c3f0e9184 100644 --- a/advisories/github-reviewed/2024/03/GHSA-78hx-gp6g-7mj6/GHSA-78hx-gp6g-7mj6.json +++ b/advisories/github-reviewed/2024/03/GHSA-78hx-gp6g-7mj6/GHSA-78hx-gp6g-7mj6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-78hx-gp6g-7mj6", - "modified": "2024-07-22T06:31:08Z", + "modified": "2024-07-24T00:31:18Z", "published": "2024-03-20T18:10:36Z", "aliases": [ "CVE-2024-1394" @@ -134,10 +134,6 @@ "type": "WEB", "url": "https://github.com/golang-fips/openssl/commit/85d31d0d257ce842c8a1e63c4d230ae850348136" }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:3265" - }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:3352" @@ -174,6 +170,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:4672" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4761" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4762" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-1394" @@ -285,6 +289,10 @@ { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:2767" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:3265" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/12/GHSA-v727-f437-6cxx/GHSA-v727-f437-6cxx.json b/advisories/unreviewed/2023/12/GHSA-v727-f437-6cxx/GHSA-v727-f437-6cxx.json index b3dbd5ea6ed..6c9edecdf79 100644 --- a/advisories/unreviewed/2023/12/GHSA-v727-f437-6cxx/GHSA-v727-f437-6cxx.json +++ b/advisories/unreviewed/2023/12/GHSA-v727-f437-6cxx/GHSA-v727-f437-6cxx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v727-f437-6cxx", - "modified": "2024-07-17T00:32:52Z", + "modified": "2024-07-24T00:31:18Z", "published": "2023-12-21T21:30:31Z", "aliases": [ "CVE-2023-6546" @@ -37,6 +37,14 @@ "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-6546" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4731" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4729" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:4577" diff --git a/advisories/unreviewed/2024/05/GHSA-q262-3hfr-f5q4/GHSA-q262-3hfr-f5q4.json b/advisories/unreviewed/2024/05/GHSA-q262-3hfr-f5q4/GHSA-q262-3hfr-f5q4.json index 36adcf62b34..3a1e9ab7aeb 100644 --- a/advisories/unreviewed/2024/05/GHSA-q262-3hfr-f5q4/GHSA-q262-3hfr-f5q4.json +++ b/advisories/unreviewed/2024/05/GHSA-q262-3hfr-f5q4/GHSA-q262-3hfr-f5q4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q262-3hfr-f5q4", - "modified": "2024-07-09T18:30:42Z", + "modified": "2024-07-24T00:31:17Z", "published": "2024-05-08T03:30:37Z", "aliases": [ "CVE-2024-4418" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:4432" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4757" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-4418" diff --git a/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json b/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json index d064c5eda5f..f5d52144db5 100644 --- a/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json +++ b/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2x8c-95vh-gfv4", - "modified": "2024-07-23T21:31:37Z", + "modified": "2024-07-24T00:31:18Z", "published": "2024-07-01T15:32:33Z", "aliases": [ "CVE-2024-6387" @@ -284,6 +284,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/07/23/4" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/23/6" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-67gf-x3r4-p4fq/GHSA-67gf-x3r4-p4fq.json b/advisories/unreviewed/2024/07/GHSA-67gf-x3r4-p4fq/GHSA-67gf-x3r4-p4fq.json new file mode 100644 index 00000000000..c73849ad9bc --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-67gf-x3r4-p4fq/GHSA-67gf-x3r4-p4fq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67gf-x3r4-p4fq", + "modified": "2024-07-24T00:31:17Z", + "published": "2024-07-24T00:31:17Z", + "aliases": [ + "CVE-2024-38176" + ], + "details": "An improper restriction of excessive authentication attempts in GroupMe allows a unauthenticated attacker to elevate privileges over a network.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38176" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38176" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-23T22:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-g5qj-pfmg-p3jp/GHSA-g5qj-pfmg-p3jp.json b/advisories/unreviewed/2024/07/GHSA-g5qj-pfmg-p3jp/GHSA-g5qj-pfmg-p3jp.json index c7dd107d843..46f71fae01a 100644 --- a/advisories/unreviewed/2024/07/GHSA-g5qj-pfmg-p3jp/GHSA-g5qj-pfmg-p3jp.json +++ b/advisories/unreviewed/2024/07/GHSA-g5qj-pfmg-p3jp/GHSA-g5qj-pfmg-p3jp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g5qj-pfmg-p3jp", - "modified": "2024-07-23T21:31:37Z", + "modified": "2024-07-24T00:31:17Z", "published": "2024-07-02T21:32:15Z", "aliases": [ "CVE-2024-39894" @@ -44,6 +44,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/07/23/4" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/23/6" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-wg3w-75pp-j436/GHSA-wg3w-75pp-j436.json b/advisories/unreviewed/2024/07/GHSA-wg3w-75pp-j436/GHSA-wg3w-75pp-j436.json new file mode 100644 index 00000000000..614c69575ab --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-wg3w-75pp-j436/GHSA-wg3w-75pp-j436.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wg3w-75pp-j436", + "modified": "2024-07-24T00:31:17Z", + "published": "2024-07-24T00:31:17Z", + "aliases": [ + "CVE-2024-38164" + ], + "details": "An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to click on a malicious link.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38164" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38164" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-23T22:15:08Z" + } +} \ No newline at end of file