From 9df142af8206198c64f62244b3ee78eee3e4d7b3 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 30 Mar 2024 03:32:06 +0000 Subject: [PATCH] Publish Advisories GHSA-h8wv-9h96-m4hr GHSA-whh8-fjgc-qp73 GHSA-9w38-p64v-xpmv GHSA-c5q2-7r4c-mv6g GHSA-hhhv-q57g-882q GHSA-xjp4-hw94-mvp5 GHSA-9hpj-m9v9-5wvw GHSA-36c8-x5g7-w9x4 GHSA-3p53-237x-3cww GHSA-4vwm-cmfj-fp9q GHSA-592x-6m4j-68cc GHSA-8rqc-wx6q-m4qc --- .../GHSA-h8wv-9h96-m4hr.json | 6 ++- .../GHSA-whh8-fjgc-qp73.json | 6 ++- .../GHSA-9w38-p64v-xpmv.json | 6 ++- .../GHSA-c5q2-7r4c-mv6g.json | 6 ++- .../GHSA-hhhv-q57g-882q.json | 6 ++- .../GHSA-xjp4-hw94-mvp5.json | 6 ++- .../GHSA-9hpj-m9v9-5wvw.json | 12 +++++- .../GHSA-36c8-x5g7-w9x4.json | 6 ++- .../GHSA-3p53-237x-3cww.json | 6 ++- .../GHSA-4vwm-cmfj-fp9q.json | 39 +++++++++++++++++++ .../GHSA-592x-6m4j-68cc.json | 39 +++++++++++++++++++ .../GHSA-8rqc-wx6q-m4qc.json | 6 ++- 12 files changed, 133 insertions(+), 11 deletions(-) create mode 100644 advisories/unreviewed/2024/03/GHSA-4vwm-cmfj-fp9q/GHSA-4vwm-cmfj-fp9q.json create mode 100644 advisories/unreviewed/2024/03/GHSA-592x-6m4j-68cc/GHSA-592x-6m4j-68cc.json diff --git a/advisories/github-reviewed/2024/02/GHSA-h8wv-9h96-m4hr/GHSA-h8wv-9h96-m4hr.json b/advisories/github-reviewed/2024/02/GHSA-h8wv-9h96-m4hr/GHSA-h8wv-9h96-m4hr.json index ea96100a5b5..1559f5e1feb 100644 --- a/advisories/github-reviewed/2024/02/GHSA-h8wv-9h96-m4hr/GHSA-h8wv-9h96-m4hr.json +++ b/advisories/github-reviewed/2024/02/GHSA-h8wv-9h96-m4hr/GHSA-h8wv-9h96-m4hr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h8wv-9h96-m4hr", - "modified": "2024-03-29T03:30:28Z", + "modified": "2024-03-30T03:30:44Z", "published": "2024-02-23T18:30:59Z", "aliases": [ "CVE-2024-27319" @@ -51,6 +51,10 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FGTBH5ZYL2LGYHIJDHN2MAUURIR5E7PY" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TFJJID2IZDOLFDMWVYTBDI75ZJQC6JOL" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/02/GHSA-whh8-fjgc-qp73/GHSA-whh8-fjgc-qp73.json b/advisories/github-reviewed/2024/02/GHSA-whh8-fjgc-qp73/GHSA-whh8-fjgc-qp73.json index bd1beacb336..9a5060ef085 100644 --- a/advisories/github-reviewed/2024/02/GHSA-whh8-fjgc-qp73/GHSA-whh8-fjgc-qp73.json +++ b/advisories/github-reviewed/2024/02/GHSA-whh8-fjgc-qp73/GHSA-whh8-fjgc-qp73.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-whh8-fjgc-qp73", - "modified": "2024-03-29T03:30:28Z", + "modified": "2024-03-30T03:30:44Z", "published": "2024-02-23T18:30:59Z", "aliases": [ "CVE-2024-27318" @@ -52,6 +52,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FGTBH5ZYL2LGYHIJDHN2MAUURIR5E7PY" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TFJJID2IZDOLFDMWVYTBDI75ZJQC6JOL" + }, { "type": "WEB", "url": "https://security.snyk.io/vuln/SNYK-PYTHON-ONNX-2395479" diff --git a/advisories/github-reviewed/2024/03/GHSA-9w38-p64v-xpmv/GHSA-9w38-p64v-xpmv.json b/advisories/github-reviewed/2024/03/GHSA-9w38-p64v-xpmv/GHSA-9w38-p64v-xpmv.json index 27e36cf1fce..ed6c73beee5 100644 --- a/advisories/github-reviewed/2024/03/GHSA-9w38-p64v-xpmv/GHSA-9w38-p64v-xpmv.json +++ b/advisories/github-reviewed/2024/03/GHSA-9w38-p64v-xpmv/GHSA-9w38-p64v-xpmv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9w38-p64v-xpmv", - "modified": "2024-03-29T06:30:30Z", + "modified": "2024-03-30T03:30:45Z", "published": "2024-03-21T09:31:14Z", "aliases": [ "CVE-2024-29133" @@ -52,6 +52,10 @@ "type": "WEB", "url": "https://lists.apache.org/thread/ccb9w15bscznh6tnp3wsvrrj9crbszh2" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SNKDKEEKZNL5FGCTZKJ6CFXFVWFL5FJ7" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YD4AFTIIQW662LUAQRMWS6BBKYSZG3YS" diff --git a/advisories/github-reviewed/2024/03/GHSA-c5q2-7r4c-mv6g/GHSA-c5q2-7r4c-mv6g.json b/advisories/github-reviewed/2024/03/GHSA-c5q2-7r4c-mv6g/GHSA-c5q2-7r4c-mv6g.json index 21ba90f4633..13bd2ffe824 100644 --- a/advisories/github-reviewed/2024/03/GHSA-c5q2-7r4c-mv6g/GHSA-c5q2-7r4c-mv6g.json +++ b/advisories/github-reviewed/2024/03/GHSA-c5q2-7r4c-mv6g/GHSA-c5q2-7r4c-mv6g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c5q2-7r4c-mv6g", - "modified": "2024-03-29T06:30:30Z", + "modified": "2024-03-30T03:30:44Z", "published": "2024-03-07T22:54:44Z", "aliases": [ "CVE-2024-28180" @@ -106,6 +106,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KXKGNCRU7OTM5AHC7YIYBNOWI742PRMY" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UJO2U5ACZVACNQXJ5EBRFLFW6DP5BROY" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XJDO5VSIAOGT2WP63AXAAWNRSVJCNCRH" diff --git a/advisories/github-reviewed/2024/03/GHSA-hhhv-q57g-882q/GHSA-hhhv-q57g-882q.json b/advisories/github-reviewed/2024/03/GHSA-hhhv-q57g-882q/GHSA-hhhv-q57g-882q.json index 11e7518c1c3..ebb6dba2b6a 100644 --- a/advisories/github-reviewed/2024/03/GHSA-hhhv-q57g-882q/GHSA-hhhv-q57g-882q.json +++ b/advisories/github-reviewed/2024/03/GHSA-hhhv-q57g-882q/GHSA-hhhv-q57g-882q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hhhv-q57g-882q", - "modified": "2024-03-29T06:30:29Z", + "modified": "2024-03-30T03:30:44Z", "published": "2024-03-07T17:40:57Z", "aliases": [ "CVE-2024-28176" @@ -130,6 +130,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KXKGNCRU7OTM5AHC7YIYBNOWI742PRMY" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UJO2U5ACZVACNQXJ5EBRFLFW6DP5BROY" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XJDO5VSIAOGT2WP63AXAAWNRSVJCNCRH" diff --git a/advisories/github-reviewed/2024/03/GHSA-xjp4-hw94-mvp5/GHSA-xjp4-hw94-mvp5.json b/advisories/github-reviewed/2024/03/GHSA-xjp4-hw94-mvp5/GHSA-xjp4-hw94-mvp5.json index 4f9af50bd5f..66636c4777d 100644 --- a/advisories/github-reviewed/2024/03/GHSA-xjp4-hw94-mvp5/GHSA-xjp4-hw94-mvp5.json +++ b/advisories/github-reviewed/2024/03/GHSA-xjp4-hw94-mvp5/GHSA-xjp4-hw94-mvp5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xjp4-hw94-mvp5", - "modified": "2024-03-29T06:30:30Z", + "modified": "2024-03-30T03:30:44Z", "published": "2024-03-21T09:31:14Z", "aliases": [ "CVE-2024-29131" @@ -56,6 +56,10 @@ "type": "WEB", "url": "https://lists.apache.org/thread/03nzzzjn4oknyw5y0871tw7ltj0t3r37" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SNKDKEEKZNL5FGCTZKJ6CFXFVWFL5FJ7" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YD4AFTIIQW662LUAQRMWS6BBKYSZG3YS" diff --git a/advisories/unreviewed/2023/07/GHSA-9hpj-m9v9-5wvw/GHSA-9hpj-m9v9-5wvw.json b/advisories/unreviewed/2023/07/GHSA-9hpj-m9v9-5wvw/GHSA-9hpj-m9v9-5wvw.json index b184cb35cb8..995eef965c9 100644 --- a/advisories/unreviewed/2023/07/GHSA-9hpj-m9v9-5wvw/GHSA-9hpj-m9v9-5wvw.json +++ b/advisories/unreviewed/2023/07/GHSA-9hpj-m9v9-5wvw/GHSA-9hpj-m9v9-5wvw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9hpj-m9v9-5wvw", - "modified": "2023-08-03T15:30:27Z", + "modified": "2024-03-30T03:30:44Z", "published": "2023-07-25T06:30:22Z", "aliases": [ "CVE-2023-38745" @@ -32,13 +32,21 @@ { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/07/msg00029.html" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JGRJHU2FTSGTHHRTNDF7STEKLKKA25JN" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QI6RBP6ZKVC2OOCV6SU2FUHPMAXDDJFU" } ], "database_specific": { "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-07-25T04:15:10Z" diff --git a/advisories/unreviewed/2024/03/GHSA-36c8-x5g7-w9x4/GHSA-36c8-x5g7-w9x4.json b/advisories/unreviewed/2024/03/GHSA-36c8-x5g7-w9x4/GHSA-36c8-x5g7-w9x4.json index d6a3b0165b3..30143ab33f9 100644 --- a/advisories/unreviewed/2024/03/GHSA-36c8-x5g7-w9x4/GHSA-36c8-x5g7-w9x4.json +++ b/advisories/unreviewed/2024/03/GHSA-36c8-x5g7-w9x4/GHSA-36c8-x5g7-w9x4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-36c8-x5g7-w9x4", - "modified": "2024-03-23T03:30:25Z", + "modified": "2024-03-30T03:30:44Z", "published": "2024-03-14T18:30:30Z", "aliases": [ "CVE-2023-28746" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28746" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H63LGAQXPEVJOES73U4XK65I6DASOAAG" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZON4TLXG7TG4A2XZG563JMVTGQW4SF3A" diff --git a/advisories/unreviewed/2024/03/GHSA-3p53-237x-3cww/GHSA-3p53-237x-3cww.json b/advisories/unreviewed/2024/03/GHSA-3p53-237x-3cww/GHSA-3p53-237x-3cww.json index d2a3673cab4..7c9c31e7c24 100644 --- a/advisories/unreviewed/2024/03/GHSA-3p53-237x-3cww/GHSA-3p53-237x-3cww.json +++ b/advisories/unreviewed/2024/03/GHSA-3p53-237x-3cww/GHSA-3p53-237x-3cww.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3p53-237x-3cww", - "modified": "2024-03-23T03:30:25Z", + "modified": "2024-03-30T03:30:44Z", "published": "2024-03-15T18:30:38Z", "aliases": [ "CVE-2024-2193" @@ -34,6 +34,10 @@ "type": "WEB", "url": "https://kb.cert.org/vuls/id/488902" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H63LGAQXPEVJOES73U4XK65I6DASOAAG" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZON4TLXG7TG4A2XZG563JMVTGQW4SF3A" diff --git a/advisories/unreviewed/2024/03/GHSA-4vwm-cmfj-fp9q/GHSA-4vwm-cmfj-fp9q.json b/advisories/unreviewed/2024/03/GHSA-4vwm-cmfj-fp9q/GHSA-4vwm-cmfj-fp9q.json new file mode 100644 index 00000000000..f63865ec5e1 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-4vwm-cmfj-fp9q/GHSA-4vwm-cmfj-fp9q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vwm-cmfj-fp9q", + "modified": "2024-03-30T03:30:44Z", + "published": "2024-03-30T03:30:44Z", + "aliases": [ + "CVE-2024-28288" + ], + "details": "Ruijie RG-NBR700GW 10.3(4b12) router lacks cookie verification when resetting the password, resulting in an administrator password reset vulnerability. An attacker can use this vulnerability to log in to the device and disrupt the business of the enterprise.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28288" + }, + { + "type": "WEB", + "url": "https://github.com/adminquit/CVE-2024-28288/blob/d8223c6d45af877669c27fa0a95adfe51924fa86/CVE-2024-28288/CVE-2024-28288.md" + }, + { + "type": "WEB", + "url": "https://pan.baidu.com/s/1H4J_eA6wSCnDEsUSAWIzsg?pwd=CVE1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-30T01:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-592x-6m4j-68cc/GHSA-592x-6m4j-68cc.json b/advisories/unreviewed/2024/03/GHSA-592x-6m4j-68cc/GHSA-592x-6m4j-68cc.json new file mode 100644 index 00000000000..7d9e0f19daa --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-592x-6m4j-68cc/GHSA-592x-6m4j-68cc.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-592x-6m4j-68cc", + "modified": "2024-03-30T03:30:44Z", + "published": "2024-03-30T03:30:44Z", + "aliases": [ + "CVE-2024-29278" + ], + "details": "funboot v1.1 is vulnerable to Cross Site Scripting (XSS) via the title field in \"create a message .\"", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29278" + }, + { + "type": "WEB", + "url": "https://github.com/funson86/funboot/issues/2" + }, + { + "type": "WEB", + "url": "https://github.com/QDming/cve/blob/main/cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-30T01:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-8rqc-wx6q-m4qc/GHSA-8rqc-wx6q-m4qc.json b/advisories/unreviewed/2024/03/GHSA-8rqc-wx6q-m4qc/GHSA-8rqc-wx6q-m4qc.json index c7c5c767987..8c4bb9002ca 100644 --- a/advisories/unreviewed/2024/03/GHSA-8rqc-wx6q-m4qc/GHSA-8rqc-wx6q-m4qc.json +++ b/advisories/unreviewed/2024/03/GHSA-8rqc-wx6q-m4qc/GHSA-8rqc-wx6q-m4qc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8rqc-wx6q-m4qc", - "modified": "2024-03-28T21:30:31Z", + "modified": "2024-03-30T03:30:44Z", "published": "2024-03-28T21:30:31Z", "aliases": [ "CVE-2024-2947" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2271614" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PIQY2HGDJW2JY27ALTS4GEVZZJJ4XQ36" } ], "database_specific": {