From 9df02a36d4ce601bae68fc9d51eb0700fcef2851 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 10 Jul 2024 15:31:32 +0000 Subject: [PATCH] Publish Advisories GHSA-5gp6-9w92-5752 GHSA-c4mp-wp8f-qrg6 GHSA-cw5c-xm7f-wx63 GHSA-63fx-4x42-65f2 GHSA-79hg-h6r6-64mm GHSA-gx86-j6ch-gp6g GHSA-hxwp-wpwp-65p6 GHSA-p9qx-gfwc-8q38 GHSA-q4qc-g79m-gvh2 GHSA-qfm4-xx8x-452f GHSA-rxq5-6v7m-86hq GHSA-v458-23rq-7r33 GHSA-vjcf-4947-pvqf GHSA-x6fc-g9vq-7q2g --- .../GHSA-5gp6-9w92-5752.json | 2 +- .../GHSA-c4mp-wp8f-qrg6.json | 1 + .../GHSA-cw5c-xm7f-wx63.json | 3 +- .../GHSA-63fx-4x42-65f2.json | 35 +++++++++++++++++ .../GHSA-79hg-h6r6-64mm.json | 14 ++++++- .../GHSA-gx86-j6ch-gp6g.json | 35 +++++++++++++++++ .../GHSA-hxwp-wpwp-65p6.json | 38 +++++++++++++++++++ .../GHSA-p9qx-gfwc-8q38.json | 35 +++++++++++++++++ .../GHSA-q4qc-g79m-gvh2.json | 35 +++++++++++++++++ .../GHSA-qfm4-xx8x-452f.json | 38 +++++++++++++++++++ .../GHSA-rxq5-6v7m-86hq.json | 35 +++++++++++++++++ .../GHSA-v458-23rq-7r33.json | 35 +++++++++++++++++ .../GHSA-vjcf-4947-pvqf.json | 31 +++++++++++++++ .../GHSA-x6fc-g9vq-7q2g.json | 35 +++++++++++++++++ 14 files changed, 369 insertions(+), 3 deletions(-) create mode 100644 advisories/unreviewed/2024/07/GHSA-63fx-4x42-65f2/GHSA-63fx-4x42-65f2.json create mode 100644 advisories/unreviewed/2024/07/GHSA-gx86-j6ch-gp6g/GHSA-gx86-j6ch-gp6g.json create mode 100644 advisories/unreviewed/2024/07/GHSA-hxwp-wpwp-65p6/GHSA-hxwp-wpwp-65p6.json create mode 100644 advisories/unreviewed/2024/07/GHSA-p9qx-gfwc-8q38/GHSA-p9qx-gfwc-8q38.json create mode 100644 advisories/unreviewed/2024/07/GHSA-q4qc-g79m-gvh2/GHSA-q4qc-g79m-gvh2.json create mode 100644 advisories/unreviewed/2024/07/GHSA-qfm4-xx8x-452f/GHSA-qfm4-xx8x-452f.json create mode 100644 advisories/unreviewed/2024/07/GHSA-rxq5-6v7m-86hq/GHSA-rxq5-6v7m-86hq.json create mode 100644 advisories/unreviewed/2024/07/GHSA-v458-23rq-7r33/GHSA-v458-23rq-7r33.json create mode 100644 advisories/unreviewed/2024/07/GHSA-vjcf-4947-pvqf/GHSA-vjcf-4947-pvqf.json create mode 100644 advisories/unreviewed/2024/07/GHSA-x6fc-g9vq-7q2g/GHSA-x6fc-g9vq-7q2g.json diff --git a/advisories/unreviewed/2023/05/GHSA-5gp6-9w92-5752/GHSA-5gp6-9w92-5752.json b/advisories/unreviewed/2023/05/GHSA-5gp6-9w92-5752/GHSA-5gp6-9w92-5752.json index 20e5becbf0d..93cd578a810 100644 --- a/advisories/unreviewed/2023/05/GHSA-5gp6-9w92-5752/GHSA-5gp6-9w92-5752.json +++ b/advisories/unreviewed/2023/05/GHSA-5gp6-9w92-5752/GHSA-5gp6-9w92-5752.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5gp6-9w92-5752", - "modified": "2023-12-22T15:30:26Z", + "modified": "2024-07-10T15:30:27Z", "published": "2023-05-16T00:30:16Z", "aliases": [ "CVE-2023-1729" diff --git a/advisories/unreviewed/2023/08/GHSA-c4mp-wp8f-qrg6/GHSA-c4mp-wp8f-qrg6.json b/advisories/unreviewed/2023/08/GHSA-c4mp-wp8f-qrg6/GHSA-c4mp-wp8f-qrg6.json index b7cdc5a4839..4494248788e 100644 --- a/advisories/unreviewed/2023/08/GHSA-c4mp-wp8f-qrg6/GHSA-c4mp-wp8f-qrg6.json +++ b/advisories/unreviewed/2023/08/GHSA-c4mp-wp8f-qrg6/GHSA-c4mp-wp8f-qrg6.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-125" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/05/GHSA-cw5c-xm7f-wx63/GHSA-cw5c-xm7f-wx63.json b/advisories/unreviewed/2024/05/GHSA-cw5c-xm7f-wx63/GHSA-cw5c-xm7f-wx63.json index 92b46ad77fa..cf631251f04 100644 --- a/advisories/unreviewed/2024/05/GHSA-cw5c-xm7f-wx63/GHSA-cw5c-xm7f-wx63.json +++ b/advisories/unreviewed/2024/05/GHSA-cw5c-xm7f-wx63/GHSA-cw5c-xm7f-wx63.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1336" + "CWE-1336", + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-63fx-4x42-65f2/GHSA-63fx-4x42-65f2.json b/advisories/unreviewed/2024/07/GHSA-63fx-4x42-65f2/GHSA-63fx-4x42-65f2.json new file mode 100644 index 00000000000..29e2d8e0dc0 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-63fx-4x42-65f2/GHSA-63fx-4x42-65f2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63fx-4x42-65f2", + "modified": "2024-07-10T15:30:28Z", + "published": "2024-07-10T15:30:28Z", + "aliases": [ + "CVE-2024-40331" + ], + "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/dbBakMySQL_deal.php?mudi=backup", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40331" + }, + { + "type": "WEB", + "url": "https://github.com/Tank992/cms/blob/main/66/csrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-79hg-h6r6-64mm/GHSA-79hg-h6r6-64mm.json b/advisories/unreviewed/2024/07/GHSA-79hg-h6r6-64mm/GHSA-79hg-h6r6-64mm.json index e50e01d7363..9ab573a5412 100644 --- a/advisories/unreviewed/2024/07/GHSA-79hg-h6r6-64mm/GHSA-79hg-h6r6-64mm.json +++ b/advisories/unreviewed/2024/07/GHSA-79hg-h6r6-64mm/GHSA-79hg-h6r6-64mm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-79hg-h6r6-64mm", - "modified": "2024-07-10T03:30:35Z", + "modified": "2024-07-10T15:30:27Z", "published": "2024-07-08T18:31:18Z", "aliases": [ "CVE-2024-6409" @@ -25,10 +25,18 @@ "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-6409" }, + { + "type": "WEB", + "url": "https://almalinux.org/blog/2024-07-09-cve-2024-6409" + }, { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2295085" }, + { + "type": "WEB", + "url": "https://bugzilla.suse.com/show_bug.cgi?id=1227217" + }, { "type": "WEB", "url": "https://explore.alas.aws.amazon.com/CVE-2024-6409.html" @@ -45,6 +53,10 @@ "type": "WEB", "url": "https://ubuntu.com/security/CVE-2024-6409" }, + { + "type": "WEB", + "url": "https://www.suse.com/security/cve/CVE-2024-6409.html" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/07/08/2" diff --git a/advisories/unreviewed/2024/07/GHSA-gx86-j6ch-gp6g/GHSA-gx86-j6ch-gp6g.json b/advisories/unreviewed/2024/07/GHSA-gx86-j6ch-gp6g/GHSA-gx86-j6ch-gp6g.json new file mode 100644 index 00000000000..af20d96bc8b --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-gx86-j6ch-gp6g/GHSA-gx86-j6ch-gp6g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gx86-j6ch-gp6g", + "modified": "2024-07-10T15:30:28Z", + "published": "2024-07-10T15:30:28Z", + "aliases": [ + "CVE-2024-40329" + ], + "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/softBak_deal.php?mudi=backup", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40329" + }, + { + "type": "WEB", + "url": "https://github.com/Tank992/cms/blob/main/67/csrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T13:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-hxwp-wpwp-65p6/GHSA-hxwp-wpwp-65p6.json b/advisories/unreviewed/2024/07/GHSA-hxwp-wpwp-65p6/GHSA-hxwp-wpwp-65p6.json new file mode 100644 index 00000000000..e47964b1836 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-hxwp-wpwp-65p6/GHSA-hxwp-wpwp-65p6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxwp-wpwp-65p6", + "modified": "2024-07-10T15:30:27Z", + "published": "2024-07-10T15:30:27Z", + "aliases": [ + "CVE-2024-28827" + ], + "details": "Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <= 2.0.0p39 (EOL) allows a local attacker to gain SYSTEM privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28827" + }, + { + "type": "WEB", + "url": "https://checkmk.com/werk/16845" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T13:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-p9qx-gfwc-8q38/GHSA-p9qx-gfwc-8q38.json b/advisories/unreviewed/2024/07/GHSA-p9qx-gfwc-8q38/GHSA-p9qx-gfwc-8q38.json new file mode 100644 index 00000000000..9e52e445cb4 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-p9qx-gfwc-8q38/GHSA-p9qx-gfwc-8q38.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9qx-gfwc-8q38", + "modified": "2024-07-10T15:30:28Z", + "published": "2024-07-10T15:30:28Z", + "aliases": [ + "CVE-2024-40334" + ], + "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/serverFile_deal.php?mudi=upFileDel&dataID=3", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40334" + }, + { + "type": "WEB", + "url": "https://github.com/Tank992/cms/blob/main/69/csrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T13:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-q4qc-g79m-gvh2/GHSA-q4qc-g79m-gvh2.json b/advisories/unreviewed/2024/07/GHSA-q4qc-g79m-gvh2/GHSA-q4qc-g79m-gvh2.json new file mode 100644 index 00000000000..69c7f0290da --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-q4qc-g79m-gvh2/GHSA-q4qc-g79m-gvh2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4qc-g79m-gvh2", + "modified": "2024-07-10T15:30:28Z", + "published": "2024-07-10T15:30:28Z", + "aliases": [ + "CVE-2024-40333" + ], + "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/softBak_deal.php?mudi=del&dataID=2", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40333" + }, + { + "type": "WEB", + "url": "https://github.com/Tank992/cms/blob/main/68/csrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T13:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-qfm4-xx8x-452f/GHSA-qfm4-xx8x-452f.json b/advisories/unreviewed/2024/07/GHSA-qfm4-xx8x-452f/GHSA-qfm4-xx8x-452f.json new file mode 100644 index 00000000000..1cc8bae68e0 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-qfm4-xx8x-452f/GHSA-qfm4-xx8x-452f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfm4-xx8x-452f", + "modified": "2024-07-10T15:30:27Z", + "published": "2024-07-10T15:30:27Z", + "aliases": [ + "CVE-2024-28828" + ], + "details": "Cross-Site request forgery in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <= 2.0.0p39 (EOL) could lead to 1-click compromize of the site.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28828" + }, + { + "type": "WEB", + "url": "https://checkmk.com/werk/17090" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T13:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-rxq5-6v7m-86hq/GHSA-rxq5-6v7m-86hq.json b/advisories/unreviewed/2024/07/GHSA-rxq5-6v7m-86hq/GHSA-rxq5-6v7m-86hq.json new file mode 100644 index 00000000000..9d831c6f407 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-rxq5-6v7m-86hq/GHSA-rxq5-6v7m-86hq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rxq5-6v7m-86hq", + "modified": "2024-07-10T15:30:29Z", + "published": "2024-07-10T15:30:29Z", + "aliases": [ + "CVE-2024-40336" + ], + "details": "idccms v1.35 is vulnerable to Cross Site Scripting (XSS) within the 'Image Advertising Management.'", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40336" + }, + { + "type": "WEB", + "url": "https://github.com/Tank992/cms/blob/main/73/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-v458-23rq-7r33/GHSA-v458-23rq-7r33.json b/advisories/unreviewed/2024/07/GHSA-v458-23rq-7r33/GHSA-v458-23rq-7r33.json new file mode 100644 index 00000000000..dc4e3a1b9cd --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-v458-23rq-7r33/GHSA-v458-23rq-7r33.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v458-23rq-7r33", + "modified": "2024-07-10T15:30:28Z", + "published": "2024-07-10T15:30:28Z", + "aliases": [ + "CVE-2024-40332" + ], + "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/moneyRecord_deal.php?mudi=delRecord", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40332" + }, + { + "type": "WEB", + "url": "https://github.com/Tank992/cms/blob/main/65/csrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-vjcf-4947-pvqf/GHSA-vjcf-4947-pvqf.json b/advisories/unreviewed/2024/07/GHSA-vjcf-4947-pvqf/GHSA-vjcf-4947-pvqf.json new file mode 100644 index 00000000000..d9563cd19a6 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-vjcf-4947-pvqf/GHSA-vjcf-4947-pvqf.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjcf-4947-pvqf", + "modified": "2024-07-10T15:30:28Z", + "published": "2024-07-10T15:30:28Z", + "aliases": [ + "CVE-2024-6642" + ], + "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6642" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-x6fc-g9vq-7q2g/GHSA-x6fc-g9vq-7q2g.json b/advisories/unreviewed/2024/07/GHSA-x6fc-g9vq-7q2g/GHSA-x6fc-g9vq-7q2g.json new file mode 100644 index 00000000000..18687672ae1 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-x6fc-g9vq-7q2g/GHSA-x6fc-g9vq-7q2g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6fc-g9vq-7q2g", + "modified": "2024-07-10T15:30:27Z", + "published": "2024-07-10T15:30:27Z", + "aliases": [ + "CVE-2024-40328" + ], + "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/memberOnline_deal.php?mudi=del&dataType=&dataID=6", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40328" + }, + { + "type": "WEB", + "url": "https://github.com/Tank992/cms/blob/main/70/csrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T13:15:10Z" + } +} \ No newline at end of file