From 9c8ab38287ce9a1f29d99ca064f21f8e23ede2c9 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 12 Jun 2024 15:33:31 +0000 Subject: [PATCH] Publish Advisories GHSA-27fw-99r5-fg9c GHSA-2x84-5cch-m2hj GHSA-4c7q-m7hc-pc92 GHSA-59h3-wp7j-68gw GHSA-6577-hj74-984x GHSA-65c3-6x9j-29cg GHSA-68j3-86cc-wp27 GHSA-6q97-8v3g-rpxw GHSA-9g8p-86c3-9596 GHSA-cmgh-j7wm-g8fg GHSA-cqx6-vqmj-2pph GHSA-jw5j-hq8v-39jg GHSA-jwcg-wv5x-vg3g GHSA-jww8-w6cf-vwpg GHSA-qjqw-554m-3g9j GHSA-qjv8-6g62-8v6m GHSA-qwvx-pmh3-3mjv GHSA-r3w6-p6hr-rww6 GHSA-rv3r-wr97-qfj7 GHSA-v74c-qc46-9gg9 GHSA-w3vp-r637-3fhj --- .../GHSA-27fw-99r5-fg9c.json | 47 ++++++++++++++++ .../GHSA-2x84-5cch-m2hj.json | 50 +++++++++++++++++ .../GHSA-4c7q-m7hc-pc92.json | 38 +++++++++++++ .../GHSA-59h3-wp7j-68gw.json | 55 +++++++++++++++++++ .../GHSA-6577-hj74-984x.json | 47 ++++++++++++++++ .../GHSA-65c3-6x9j-29cg.json | 35 ++++++++++++ .../GHSA-68j3-86cc-wp27.json | 35 ++++++++++++ .../GHSA-6q97-8v3g-rpxw.json | 35 ++++++++++++ .../GHSA-9g8p-86c3-9596.json | 47 ++++++++++++++++ .../GHSA-cmgh-j7wm-g8fg.json | 47 ++++++++++++++++ .../GHSA-cqx6-vqmj-2pph.json | 2 +- .../GHSA-jw5j-hq8v-39jg.json | 2 +- .../GHSA-jwcg-wv5x-vg3g.json | 39 +++++++++++++ .../GHSA-jww8-w6cf-vwpg.json | 38 +++++++++++++ .../GHSA-qjqw-554m-3g9j.json | 2 +- .../GHSA-qjv8-6g62-8v6m.json | 50 +++++++++++++++++ .../GHSA-qwvx-pmh3-3mjv.json | 42 ++++++++++++++ .../GHSA-r3w6-p6hr-rww6.json | 38 +++++++++++++ .../GHSA-rv3r-wr97-qfj7.json | 50 +++++++++++++++++ .../GHSA-v74c-qc46-9gg9.json | 39 +++++++++++++ .../GHSA-w3vp-r637-3fhj.json | 38 +++++++++++++ 21 files changed, 773 insertions(+), 3 deletions(-) create mode 100644 advisories/unreviewed/2024/06/GHSA-27fw-99r5-fg9c/GHSA-27fw-99r5-fg9c.json create mode 100644 advisories/unreviewed/2024/06/GHSA-2x84-5cch-m2hj/GHSA-2x84-5cch-m2hj.json create mode 100644 advisories/unreviewed/2024/06/GHSA-4c7q-m7hc-pc92/GHSA-4c7q-m7hc-pc92.json create mode 100644 advisories/unreviewed/2024/06/GHSA-59h3-wp7j-68gw/GHSA-59h3-wp7j-68gw.json create mode 100644 advisories/unreviewed/2024/06/GHSA-6577-hj74-984x/GHSA-6577-hj74-984x.json create mode 100644 advisories/unreviewed/2024/06/GHSA-65c3-6x9j-29cg/GHSA-65c3-6x9j-29cg.json create mode 100644 advisories/unreviewed/2024/06/GHSA-68j3-86cc-wp27/GHSA-68j3-86cc-wp27.json create mode 100644 advisories/unreviewed/2024/06/GHSA-6q97-8v3g-rpxw/GHSA-6q97-8v3g-rpxw.json create mode 100644 advisories/unreviewed/2024/06/GHSA-9g8p-86c3-9596/GHSA-9g8p-86c3-9596.json create mode 100644 advisories/unreviewed/2024/06/GHSA-cmgh-j7wm-g8fg/GHSA-cmgh-j7wm-g8fg.json create mode 100644 advisories/unreviewed/2024/06/GHSA-jwcg-wv5x-vg3g/GHSA-jwcg-wv5x-vg3g.json create mode 100644 advisories/unreviewed/2024/06/GHSA-jww8-w6cf-vwpg/GHSA-jww8-w6cf-vwpg.json create mode 100644 advisories/unreviewed/2024/06/GHSA-qjv8-6g62-8v6m/GHSA-qjv8-6g62-8v6m.json create mode 100644 advisories/unreviewed/2024/06/GHSA-qwvx-pmh3-3mjv/GHSA-qwvx-pmh3-3mjv.json create mode 100644 advisories/unreviewed/2024/06/GHSA-r3w6-p6hr-rww6/GHSA-r3w6-p6hr-rww6.json create mode 100644 advisories/unreviewed/2024/06/GHSA-rv3r-wr97-qfj7/GHSA-rv3r-wr97-qfj7.json create mode 100644 advisories/unreviewed/2024/06/GHSA-v74c-qc46-9gg9/GHSA-v74c-qc46-9gg9.json create mode 100644 advisories/unreviewed/2024/06/GHSA-w3vp-r637-3fhj/GHSA-w3vp-r637-3fhj.json diff --git a/advisories/unreviewed/2024/06/GHSA-27fw-99r5-fg9c/GHSA-27fw-99r5-fg9c.json b/advisories/unreviewed/2024/06/GHSA-27fw-99r5-fg9c/GHSA-27fw-99r5-fg9c.json new file mode 100644 index 00000000000..908fae0750a --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-27fw-99r5-fg9c/GHSA-27fw-99r5-fg9c.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-27fw-99r5-fg9c", + "modified": "2024-06-12T15:31:44Z", + "published": "2024-06-12T15:31:44Z", + "aliases": [ + "CVE-2024-1576" + ], + "details": "SQL Injection vulnerability in MegaBIP software allows attacker to obtain site administrator privileges, including access to the administration panel and the ability to change the administrator password. This issue affects MegaBIP software versions through 5.09.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1576" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/06/CVE-2024-1576" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2024/06/CVE-2024-1576" + }, + { + "type": "WEB", + "url": "https://megabip.pl" + }, + { + "type": "WEB", + "url": "https://www.gov.pl/web/cyfryzacja/rekomendacja-pelnomocnika-rzadu-ds-cyberbezpieczenstwa-dotyczaca-biuletynow-informacji-publicznej" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-2x84-5cch-m2hj/GHSA-2x84-5cch-m2hj.json b/advisories/unreviewed/2024/06/GHSA-2x84-5cch-m2hj/GHSA-2x84-5cch-m2hj.json new file mode 100644 index 00000000000..fb2899f3619 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-2x84-5cch-m2hj/GHSA-2x84-5cch-m2hj.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2x84-5cch-m2hj", + "modified": "2024-06-12T15:31:46Z", + "published": "2024-06-12T15:31:46Z", + "aliases": [ + "CVE-2024-5895" + ], + "details": "A vulnerability, which was classified as critical, has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. This issue affects the function delete_users of the file /classes/Users.php?f=delete. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-268139.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5895" + }, + { + "type": "WEB", + "url": "https://github.com/Hefei-Coffee/cve/blob/main/sql11.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.268139" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.268139" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.354915" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-4c7q-m7hc-pc92/GHSA-4c7q-m7hc-pc92.json b/advisories/unreviewed/2024/06/GHSA-4c7q-m7hc-pc92/GHSA-4c7q-m7hc-pc92.json new file mode 100644 index 00000000000..0c825465b8f --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-4c7q-m7hc-pc92/GHSA-4c7q-m7hc-pc92.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4c7q-m7hc-pc92", + "modified": "2024-06-12T15:31:44Z", + "published": "2024-06-12T15:31:44Z", + "aliases": [ + "CVE-2024-23445" + ], + "details": "It was identified that if a cross-cluster API key https://www.elastic.co/guide/en/elasticsearch/reference/8.14/security-api-create-cross-cluster-api-key.html#security-api-create-cross-cluster-api-key-request-body  restricts search for a given index using the query or the field_security parameter, and the same cross-cluster API key also grants replication for the same index, the search restrictions are not enforced during cross cluster search operations and search results may include documents and terms that should not be returned.\n\nThis issue only affects the API key based security model for remote clusters https://www.elastic.co/guide/en/elasticsearch/reference/8.14/remote-clusters.html#remote-clusters-security-models  that was previously a beta feature and is released as GA with 8.14.0", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23445" + }, + { + "type": "WEB", + "url": "https://discuss.elastic.co/t/elasticsearch-8-14-0-security-update-esa-2024-13/360898" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-59h3-wp7j-68gw/GHSA-59h3-wp7j-68gw.json b/advisories/unreviewed/2024/06/GHSA-59h3-wp7j-68gw/GHSA-59h3-wp7j-68gw.json new file mode 100644 index 00000000000..3d5273207ba --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-59h3-wp7j-68gw/GHSA-59h3-wp7j-68gw.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59h3-wp7j-68gw", + "modified": "2024-06-12T15:31:45Z", + "published": "2024-06-12T15:31:45Z", + "aliases": [ + "CVE-2024-36840" + ], + "details": "SQL Injection vulnerability in Boelter Blue System Management v.1.3 allows a remote attacker to execute arbitrary code and obtain sensitive information via the id parameter to news_details.php and location_details.php; and the section parameter to services.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36840" + }, + { + "type": "WEB", + "url": "https://infosec-db.github.io/CyberDepot/vuln_boelter_blue" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/178978/Boelter-Blue-System-Management-1.3-SQL-Injection.html" + }, + { + "type": "WEB", + "url": "https://play.google.com/store/apps/details?id=com.anchor5digital.anchor5adminapp&hl=en_US" + }, + { + "type": "WEB", + "url": "https://sploitus.com/exploit?id=PACKETSTORM:178978" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.267594" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jun/0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T15:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-6577-hj74-984x/GHSA-6577-hj74-984x.json b/advisories/unreviewed/2024/06/GHSA-6577-hj74-984x/GHSA-6577-hj74-984x.json new file mode 100644 index 00000000000..86485d87ad5 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-6577-hj74-984x/GHSA-6577-hj74-984x.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6577-hj74-984x", + "modified": "2024-06-12T15:31:44Z", + "published": "2024-06-12T15:31:44Z", + "aliases": [ + "CVE-2024-1577" + ], + "details": "Remote Code Execution vulnerability in MegaBIP software allows to execute arbitrary code on the server without requiring authentication by saving crafted by the attacker PHP code to one of the website files. This issue affects all versions of MegaBIP software.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1577" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/06/CVE-2024-1576" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2024/06/CVE-2024-1576" + }, + { + "type": "WEB", + "url": "https://megabip.pl" + }, + { + "type": "WEB", + "url": "https://www.gov.pl/web/cyfryzacja/rekomendacja-pelnomocnika-rzadu-ds-cyberbezpieczenstwa-dotyczaca-biuletynow-informacji-publicznej" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-65c3-6x9j-29cg/GHSA-65c3-6x9j-29cg.json b/advisories/unreviewed/2024/06/GHSA-65c3-6x9j-29cg/GHSA-65c3-6x9j-29cg.json new file mode 100644 index 00000000000..69036d24647 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-65c3-6x9j-29cg/GHSA-65c3-6x9j-29cg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65c3-6x9j-29cg", + "modified": "2024-06-12T15:31:45Z", + "published": "2024-06-12T15:31:45Z", + "aliases": [ + "CVE-2024-2300" + ], + "details": "HP Advance Mobile Applications for iOS and Android are potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2300" + }, + { + "type": "WEB", + "url": "https://support.hp.com/us-en/document/ish_10737234-10737262-16/hpsbgn03921" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T15:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-68j3-86cc-wp27/GHSA-68j3-86cc-wp27.json b/advisories/unreviewed/2024/06/GHSA-68j3-86cc-wp27/GHSA-68j3-86cc-wp27.json new file mode 100644 index 00000000000..5c8aece2db2 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-68j3-86cc-wp27/GHSA-68j3-86cc-wp27.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68j3-86cc-wp27", + "modified": "2024-06-12T15:31:45Z", + "published": "2024-06-12T15:31:45Z", + "aliases": [ + "CVE-2024-36691" + ], + "details": "Insecure permissions in the AdminController.AjaxSave() method of PPGo_Jobs v2.8.0 allows authenticated attackers to arbitrarily modify users' account information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36691" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/beimi-tb0gl/yrgtbp/wi8bg26o3wlfqdaf?singleDoc" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T15:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-6q97-8v3g-rpxw/GHSA-6q97-8v3g-rpxw.json b/advisories/unreviewed/2024/06/GHSA-6q97-8v3g-rpxw/GHSA-6q97-8v3g-rpxw.json new file mode 100644 index 00000000000..1746dee6998 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-6q97-8v3g-rpxw/GHSA-6q97-8v3g-rpxw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6q97-8v3g-rpxw", + "modified": "2024-06-12T15:31:45Z", + "published": "2024-06-12T15:31:45Z", + "aliases": [ + "CVE-2024-36265" + ], + "details": "** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core.\n\nThis issue affects Apache Submarine Server Core: from 0.8.0.\n\nAs this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.\n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36265" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/prckhhst19qxof064hsm8cccxtofvflz" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T15:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-9g8p-86c3-9596/GHSA-9g8p-86c3-9596.json b/advisories/unreviewed/2024/06/GHSA-9g8p-86c3-9596/GHSA-9g8p-86c3-9596.json new file mode 100644 index 00000000000..3e0bc71e433 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-9g8p-86c3-9596/GHSA-9g8p-86c3-9596.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9g8p-86c3-9596", + "modified": "2024-06-12T15:31:45Z", + "published": "2024-06-12T15:31:44Z", + "aliases": [ + "CVE-2024-36699" + ], + "details": "GNU Debugger v8.2 to v14.2 was discovered to contain a buffer overflow via the component gdb.selected_inferior().read_memory at utils.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36699" + }, + { + "type": "WEB", + "url": "https://github.com/N1nEmAn/wp" + }, + { + "type": "WEB", + "url": "https://github.com/N1nEmAn/wp/19.html" + }, + { + "type": "WEB", + "url": "https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=06e967dbc9b75a4a3c1b15b54360cf1abbf9c2bd" + }, + { + "type": "WEB", + "url": "https://sourceware.orga/pipermail/gdb-patches/2024-April/2080" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-cmgh-j7wm-g8fg/GHSA-cmgh-j7wm-g8fg.json b/advisories/unreviewed/2024/06/GHSA-cmgh-j7wm-g8fg/GHSA-cmgh-j7wm-g8fg.json new file mode 100644 index 00000000000..7cf42cc663a --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-cmgh-j7wm-g8fg/GHSA-cmgh-j7wm-g8fg.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmgh-j7wm-g8fg", + "modified": "2024-06-12T15:31:44Z", + "published": "2024-06-12T15:31:44Z", + "aliases": [ + "CVE-2024-1659" + ], + "details": "Arbitrary File Upload vulnerability in MegaBIP software allows attacker to upload any file to the server (including a PHP code file) without an authentication. This issue affects MegaBIP software versions through 5.10.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1659" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/06/CVE-2024-1576" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2024/06/CVE-2024-1576" + }, + { + "type": "WEB", + "url": "https://megabip.pl" + }, + { + "type": "WEB", + "url": "https://www.gov.pl/web/cyfryzacja/rekomendacja-pelnomocnika-rzadu-ds-cyberbezpieczenstwa-dotyczaca-biuletynow-informacji-publicznej" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-cqx6-vqmj-2pph/GHSA-cqx6-vqmj-2pph.json b/advisories/unreviewed/2024/06/GHSA-cqx6-vqmj-2pph/GHSA-cqx6-vqmj-2pph.json index 0f5b6ec5975..13f95915683 100644 --- a/advisories/unreviewed/2024/06/GHSA-cqx6-vqmj-2pph/GHSA-cqx6-vqmj-2pph.json +++ b/advisories/unreviewed/2024/06/GHSA-cqx6-vqmj-2pph/GHSA-cqx6-vqmj-2pph.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1236" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-jw5j-hq8v-39jg/GHSA-jw5j-hq8v-39jg.json b/advisories/unreviewed/2024/06/GHSA-jw5j-hq8v-39jg/GHSA-jw5j-hq8v-39jg.json index 208aa4ec50f..092ec3360ca 100644 --- a/advisories/unreviewed/2024/06/GHSA-jw5j-hq8v-39jg/GHSA-jw5j-hq8v-39jg.json +++ b/advisories/unreviewed/2024/06/GHSA-jw5j-hq8v-39jg/GHSA-jw5j-hq8v-39jg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jw5j-hq8v-39jg", - "modified": "2024-06-09T21:30:33Z", + "modified": "2024-06-12T15:31:44Z", "published": "2024-06-09T21:30:33Z", "aliases": [ "CVE-2024-34802" diff --git a/advisories/unreviewed/2024/06/GHSA-jwcg-wv5x-vg3g/GHSA-jwcg-wv5x-vg3g.json b/advisories/unreviewed/2024/06/GHSA-jwcg-wv5x-vg3g/GHSA-jwcg-wv5x-vg3g.json new file mode 100644 index 00000000000..ed892288c89 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-jwcg-wv5x-vg3g/GHSA-jwcg-wv5x-vg3g.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwcg-wv5x-vg3g", + "modified": "2024-06-12T15:31:44Z", + "published": "2024-06-12T15:31:44Z", + "aliases": [ + "CVE-2024-36264" + ], + "details": "** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils.\n\nThis issue affects Apache Submarine Commons Utils: from 0.8.0.\n\nAs this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.\n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36264" + }, + { + "type": "WEB", + "url": "https://github.com/apache/submarine/pull/1125" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/7mo0c7vbhpo8thvybl8wwvb0bccrg7r4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-jww8-w6cf-vwpg/GHSA-jww8-w6cf-vwpg.json b/advisories/unreviewed/2024/06/GHSA-jww8-w6cf-vwpg/GHSA-jww8-w6cf-vwpg.json new file mode 100644 index 00000000000..7b4f1682f46 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-jww8-w6cf-vwpg/GHSA-jww8-w6cf-vwpg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jww8-w6cf-vwpg", + "modified": "2024-06-12T15:31:45Z", + "published": "2024-06-12T15:31:45Z", + "aliases": [ + "CVE-2024-28964" + ], + "details": "Dell Common Event Enabler, version 8.9.10.0 and prior, contain an insecure deserialization vulnerability in CAVATools. A local unauthenticated attacker could potentially exploit this vulnerability, leading to arbitrary code execution in the context of the logged in user. Exploitation of this issue requires a victim to open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28964" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000224987/dsa-2024-179-security-update-for-dell-emc-common-event-enabler-windows-for-cavatools-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T15:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-qjqw-554m-3g9j/GHSA-qjqw-554m-3g9j.json b/advisories/unreviewed/2024/06/GHSA-qjqw-554m-3g9j/GHSA-qjqw-554m-3g9j.json index b5ba1000985..f97e211bbf7 100644 --- a/advisories/unreviewed/2024/06/GHSA-qjqw-554m-3g9j/GHSA-qjqw-554m-3g9j.json +++ b/advisories/unreviewed/2024/06/GHSA-qjqw-554m-3g9j/GHSA-qjqw-554m-3g9j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qjqw-554m-3g9j", - "modified": "2024-06-11T15:31:14Z", + "modified": "2024-06-12T15:31:44Z", "published": "2024-06-11T15:31:14Z", "aliases": [ "CVE-2024-28021" diff --git a/advisories/unreviewed/2024/06/GHSA-qjv8-6g62-8v6m/GHSA-qjv8-6g62-8v6m.json b/advisories/unreviewed/2024/06/GHSA-qjv8-6g62-8v6m/GHSA-qjv8-6g62-8v6m.json new file mode 100644 index 00000000000..e4d05fcaa7c --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-qjv8-6g62-8v6m/GHSA-qjv8-6g62-8v6m.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjv8-6g62-8v6m", + "modified": "2024-06-12T15:31:46Z", + "published": "2024-06-12T15:31:46Z", + "aliases": [ + "CVE-2024-5893" + ], + "details": "A vulnerability classified as critical has been found in SourceCodester Cab Management System 1.0. This affects an unknown part of the file /cms/classes/Users.php?f=delete_client. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-268137 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5893" + }, + { + "type": "WEB", + "url": "https://github.com/Hefei-Coffee/cve/blob/main/sql9.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.268137" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.268137" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.354910" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-qwvx-pmh3-3mjv/GHSA-qwvx-pmh3-3mjv.json b/advisories/unreviewed/2024/06/GHSA-qwvx-pmh3-3mjv/GHSA-qwvx-pmh3-3mjv.json new file mode 100644 index 00000000000..23e5d26add7 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-qwvx-pmh3-3mjv/GHSA-qwvx-pmh3-3mjv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qwvx-pmh3-3mjv", + "modified": "2024-06-12T15:31:45Z", + "published": "2024-06-12T15:31:45Z", + "aliases": [ + "CVE-2024-5891" + ], + "details": "A vulnerability was found in Quay. If an attacker can obtain the client ID for an application, they can use an OAuth token to authenticate despite not having access to the organization from which the application was created. This issue is limited to authentication and not authorization. However, in configurations where endpoints rely only on authentication, a user may authenticate to applications they otherwise have no access to.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5891" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-5891" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2283879" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1390" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-r3w6-p6hr-rww6/GHSA-r3w6-p6hr-rww6.json b/advisories/unreviewed/2024/06/GHSA-r3w6-p6hr-rww6/GHSA-r3w6-p6hr-rww6.json new file mode 100644 index 00000000000..11a4eae4938 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-r3w6-p6hr-rww6/GHSA-r3w6-p6hr-rww6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3w6-p6hr-rww6", + "modified": "2024-06-12T15:31:44Z", + "published": "2024-06-12T15:31:44Z", + "aliases": [ + "CVE-2024-25949" + ], + "details": "Dell OS10 Networking Switches, versions10.5.6.x, 10.5.5.x, 10.5.4.x and 10.5.3.x ,contain an improper authorization vulnerability. A remote authenticated attacker could potentially exploit this vulnerability leading to escalation of privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25949" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000225922/dsa-2024-087-security-update-for-dell-networking-os10-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T13:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-rv3r-wr97-qfj7/GHSA-rv3r-wr97-qfj7.json b/advisories/unreviewed/2024/06/GHSA-rv3r-wr97-qfj7/GHSA-rv3r-wr97-qfj7.json new file mode 100644 index 00000000000..5294b1be347 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-rv3r-wr97-qfj7/GHSA-rv3r-wr97-qfj7.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rv3r-wr97-qfj7", + "modified": "2024-06-12T15:31:46Z", + "published": "2024-06-12T15:31:46Z", + "aliases": [ + "CVE-2024-5894" + ], + "details": "A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects unknown code of the file manage_product.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-268138 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5894" + }, + { + "type": "WEB", + "url": "https://github.com/Hefei-Coffee/cve/blob/main/sql10.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.268138" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.268138" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.354912" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-v74c-qc46-9gg9/GHSA-v74c-qc46-9gg9.json b/advisories/unreviewed/2024/06/GHSA-v74c-qc46-9gg9/GHSA-v74c-qc46-9gg9.json new file mode 100644 index 00000000000..d42f8dd6bf9 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-v74c-qc46-9gg9/GHSA-v74c-qc46-9gg9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v74c-qc46-9gg9", + "modified": "2024-06-12T15:31:45Z", + "published": "2024-06-12T15:31:45Z", + "aliases": [ + "CVE-2024-36263" + ], + "details": "** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Submarine Server Core.\n\nThis issue affects Apache Submarine Server Core: all versions.\n\nAs this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.\n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36263" + }, + { + "type": "WEB", + "url": "https://github.com/apache/submarine/pull/1121" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/8q9kbdg9gk9kpz5p8x6t7q8709l3vrmt" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-w3vp-r637-3fhj/GHSA-w3vp-r637-3fhj.json b/advisories/unreviewed/2024/06/GHSA-w3vp-r637-3fhj/GHSA-w3vp-r637-3fhj.json new file mode 100644 index 00000000000..a8b78a93fea --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-w3vp-r637-3fhj/GHSA-w3vp-r637-3fhj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3vp-r637-3fhj", + "modified": "2024-06-12T15:31:44Z", + "published": "2024-06-12T15:31:44Z", + "aliases": [ + "CVE-2024-5313" + ], + "details": "CWE-668: Exposure of the Resource Wrong Sphere vulnerability exists that exposes a SSH\ninterface over the product network interface. This does not allow to directly exploit the product or\nmake any unintended operation as the SSH interface access is protected by an authentication\nmechanism. Impacts are limited to port scanning and fingerprinting activities as well as attempts\nto perform a potential denial of service attack on the exposed SSH interface.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5313" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-163-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-163-03.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-668" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T13:15:50Z" + } +} \ No newline at end of file