Publish Advisories

GHSA-5gp6-9w92-5752
GHSA-c4mp-wp8f-qrg6
GHSA-cw5c-xm7f-wx63
GHSA-63fx-4x42-65f2
GHSA-79hg-h6r6-64mm
GHSA-gx86-j6ch-gp6g
GHSA-hxwp-wpwp-65p6
GHSA-p9qx-gfwc-8q38
GHSA-q4qc-g79m-gvh2
GHSA-qfm4-xx8x-452f
GHSA-rxq5-6v7m-86hq
GHSA-v458-23rq-7r33
GHSA-vjcf-4947-pvqf
GHSA-x6fc-g9vq-7q2g
This commit is contained in:
advisory-database[bot]
2024-07-10 15:31:32 +00:00
parent 89b720b74d
commit 9df02a36d4
14 changed files with 369 additions and 3 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5gp6-9w92-5752",
"modified": "2023-12-22T15:30:26Z",
"modified": "2024-07-10T15:30:27Z",
"published": "2023-05-16T00:30:16Z",
"aliases": [
"CVE-2023-1729"
@@ -32,6 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120",
"CWE-125"
],
"severity": "MODERATE",
@@ -36,7 +36,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-1336"
"CWE-1336",
"CWE-94"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-63fx-4x42-65f2",
"modified": "2024-07-10T15:30:28Z",
"published": "2024-07-10T15:30:28Z",
"aliases": [
"CVE-2024-40331"
],
"details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/dbBakMySQL_deal.php?mudi=backup",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40331"
},
{
"type": "WEB",
"url": "https://github.com/Tank992/cms/blob/main/66/csrf.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-10T14:15:12Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-79hg-h6r6-64mm",
"modified": "2024-07-10T03:30:35Z",
"modified": "2024-07-10T15:30:27Z",
"published": "2024-07-08T18:31:18Z",
"aliases": [
"CVE-2024-6409"
@@ -25,10 +25,18 @@
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-6409"
},
{
"type": "WEB",
"url": "https://almalinux.org/blog/2024-07-09-cve-2024-6409"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2295085"
},
{
"type": "WEB",
"url": "https://bugzilla.suse.com/show_bug.cgi?id=1227217"
},
{
"type": "WEB",
"url": "https://explore.alas.aws.amazon.com/CVE-2024-6409.html"
@@ -45,6 +53,10 @@
"type": "WEB",
"url": "https://ubuntu.com/security/CVE-2024-6409"
},
{
"type": "WEB",
"url": "https://www.suse.com/security/cve/CVE-2024-6409.html"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/07/08/2"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gx86-j6ch-gp6g",
"modified": "2024-07-10T15:30:28Z",
"published": "2024-07-10T15:30:28Z",
"aliases": [
"CVE-2024-40329"
],
"details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/softBak_deal.php?mudi=backup",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40329"
},
{
"type": "WEB",
"url": "https://github.com/Tank992/cms/blob/main/67/csrf.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-10T13:15:10Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hxwp-wpwp-65p6",
"modified": "2024-07-10T15:30:27Z",
"published": "2024-07-10T15:30:27Z",
"aliases": [
"CVE-2024-28827"
],
"details": "Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <= 2.0.0p39 (EOL) allows a local attacker to gain SYSTEM privileges.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28827"
},
{
"type": "WEB",
"url": "https://checkmk.com/werk/16845"
}
],
"database_specific": {
"cwe_ids": [
"CWE-732"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-10T13:15:10Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p9qx-gfwc-8q38",
"modified": "2024-07-10T15:30:28Z",
"published": "2024-07-10T15:30:28Z",
"aliases": [
"CVE-2024-40334"
],
"details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/serverFile_deal.php?mudi=upFileDel&dataID=3",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40334"
},
{
"type": "WEB",
"url": "https://github.com/Tank992/cms/blob/main/69/csrf.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-10T13:15:10Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q4qc-g79m-gvh2",
"modified": "2024-07-10T15:30:28Z",
"published": "2024-07-10T15:30:28Z",
"aliases": [
"CVE-2024-40333"
],
"details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/softBak_deal.php?mudi=del&dataID=2",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40333"
},
{
"type": "WEB",
"url": "https://github.com/Tank992/cms/blob/main/68/csrf.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-10T13:15:10Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qfm4-xx8x-452f",
"modified": "2024-07-10T15:30:27Z",
"published": "2024-07-10T15:30:27Z",
"aliases": [
"CVE-2024-28828"
],
"details": "Cross-Site request forgery in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <= 2.0.0p39 (EOL) could lead to 1-click compromize of the site.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28828"
},
{
"type": "WEB",
"url": "https://checkmk.com/werk/17090"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-10T13:15:10Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rxq5-6v7m-86hq",
"modified": "2024-07-10T15:30:29Z",
"published": "2024-07-10T15:30:29Z",
"aliases": [
"CVE-2024-40336"
],
"details": "idccms v1.35 is vulnerable to Cross Site Scripting (XSS) within the 'Image Advertising Management.'",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40336"
},
{
"type": "WEB",
"url": "https://github.com/Tank992/cms/blob/main/73/readme.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-10T14:15:12Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v458-23rq-7r33",
"modified": "2024-07-10T15:30:28Z",
"published": "2024-07-10T15:30:28Z",
"aliases": [
"CVE-2024-40332"
],
"details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/moneyRecord_deal.php?mudi=delRecord",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40332"
},
{
"type": "WEB",
"url": "https://github.com/Tank992/cms/blob/main/65/csrf.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-10T14:15:12Z"
}
}
@@ -0,0 +1,31 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vjcf-4947-pvqf",
"modified": "2024-07-10T15:30:28Z",
"published": "2024-07-10T15:30:28Z",
"aliases": [
"CVE-2024-6642"
],
"details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6642"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-10T13:15:11Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x6fc-g9vq-7q2g",
"modified": "2024-07-10T15:30:27Z",
"published": "2024-07-10T15:30:27Z",
"aliases": [
"CVE-2024-40328"
],
"details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/memberOnline_deal.php?mudi=del&dataType=&dataID=6",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40328"
},
{
"type": "WEB",
"url": "https://github.com/Tank992/cms/blob/main/70/csrf.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-10T13:15:10Z"
}
}