Publish Advisories

GHSA-mvc8-6ffp-jrx5
GHSA-xfv5-jqgp-vqhj
GHSA-m9w6-wp3h-vq8g
GHSA-v727-f437-6cxx
GHSA-w2rv-8vw7-735j
GHSA-57rx-38pp-c45g
GHSA-p9g8-3jw8-v3h3
GHSA-pw5j-63j7-2mhr
GHSA-v7pg-qx5m-v7x4
GHSA-3q3x-839r-4xrh
GHSA-59gf-g6mr-cr4x
GHSA-5h59-75vf-973c
GHSA-7r4w-v667-c6cr
GHSA-jgc6-c9v8-vfqw
GHSA-phwx-77rv-743g
GHSA-rmpr-6w5x-hf6g
GHSA-vqfv-6vgr-3j88
GHSA-4cpx-q734-j233
GHSA-4h6p-wphh-f8rf
GHSA-g4w3-q8cv-798h
This commit is contained in:
advisory-database[bot]
2024-08-02 15:32:45 +00:00
parent b9d09d873c
commit 9f1a25ac20
20 changed files with 163 additions and 41 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mvc8-6ffp-jrx5",
"modified": "2023-12-12T00:50:32Z",
"modified": "2024-08-02T15:31:16Z",
"published": "2023-12-09T03:30:15Z",
"aliases": [
"CVE-2023-6394"
@@ -67,6 +67,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2023:7612"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2023:7700"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-6394"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xfv5-jqgp-vqhj",
"modified": "2023-12-06T21:43:18Z",
"modified": "2024-08-02T15:31:16Z",
"published": "2023-12-06T18:31:05Z",
"aliases": [
"CVE-2023-6393"
@@ -71,6 +71,10 @@
"type": "WEB",
"url": "https://github.com/quarkusio/quarkus/commit/d9ace85caec2d8497b1a2c48b8d52bb163f04adf"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2023:7700"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-6393"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m9w6-wp3h-vq8g",
"modified": "2024-07-08T14:24:58Z",
"modified": "2024-08-02T15:31:16Z",
"published": "2024-04-25T18:30:39Z",
"aliases": [
"CVE-2024-0874"
@@ -63,6 +63,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:0041"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:4850"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-0874"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v727-f437-6cxx",
"modified": "2024-07-24T00:31:18Z",
"modified": "2024-08-02T15:31:16Z",
"published": "2023-12-21T21:30:31Z",
"aliases": [
"CVE-2023-6546"
@@ -37,6 +37,10 @@
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-6546"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:4970"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:4731"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w2rv-8vw7-735j",
"modified": "2024-05-02T06:30:31Z",
"modified": "2024-08-02T15:31:16Z",
"published": "2024-05-02T06:30:31Z",
"aliases": [
"CVE-2024-3476"
],
"details": "The Side Menu Lite WordPress plugin before 4.2.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-02T06:15:50Z"
@@ -32,7 +32,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-276"
"CWE-276",
"CWE-863"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p9g8-3jw8-v3h3",
"modified": "2024-06-26T06:30:29Z",
"modified": "2024-08-02T15:31:16Z",
"published": "2024-06-26T06:30:29Z",
"aliases": [
"CVE-2024-5199"
],
"details": "The Spotify Play Button WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-26T06:15:16Z"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3q3x-839r-4xrh",
"modified": "2024-07-30T09:32:04Z",
"modified": "2024-08-02T15:31:17Z",
"published": "2024-07-30T09:32:04Z",
"aliases": [
"CVE-2024-42224"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: mv88e6xxx: Correct check for empty list\n\nSince commit a3c53be55c95 (\"net: dsa: mv88e6xxx: Support multiple MDIO\nbusses\") mv88e6xxx_default_mdio_bus() has checked that the\nreturn value of list_first_entry() is non-NULL.\n\nThis appears to be intended to guard against the list chip->mdios being\nempty. However, it is not the correct check as the implementation of\nlist_first_entry is not designed to return NULL for empty lists.\n\nInstead, use list_first_entry_or_null() which does return NULL if the\nlist is empty.\n\nFlagged by Smatch.\nCompile tested only.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -53,9 +56,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-754"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-30T08:15:07Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-59gf-g6mr-cr4x",
"modified": "2024-07-30T09:32:04Z",
"modified": "2024-08-02T15:31:17Z",
"published": "2024-07-30T09:32:03Z",
"aliases": [
"CVE-2024-42223"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: dvb-frontends: tda10048: Fix integer overflow\n\nstate->xtal_hz can be up to 16M, so it can overflow a 32 bit integer\nwhen multiplied by pll_mfactor.\n\nCreate a new 64 bit variable to hold the calculations.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -53,9 +56,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-190"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-30T08:15:07Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5h59-75vf-973c",
"modified": "2024-07-30T09:32:03Z",
"modified": "2024-08-02T15:31:17Z",
"published": "2024-07-30T09:32:03Z",
"aliases": [
"CVE-2024-42159"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: mpi3mr: Sanitise num_phys\n\nInformation is stored in mr_sas_port->phy_mask, values larger then size of\nthis field shouldn't be allowed.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-754"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-30T08:15:07Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7r4w-v667-c6cr",
"modified": "2024-07-30T09:32:03Z",
"modified": "2024-08-02T15:31:17Z",
"published": "2024-07-30T09:32:03Z",
"aliases": [
"CVE-2024-42158"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/pkey: Use kfree_sensitive() to fix Coccinelle warnings\n\nReplace memzero_explicit() and kfree() with kfree_sensitive() to fix\nwarnings reported by Coccinelle:\n\nWARNING opportunity for kfree_sensitive/kvfree_sensitive (line 1506)\nWARNING opportunity for kfree_sensitive/kvfree_sensitive (line 1643)\nWARNING opportunity for kfree_sensitive/kvfree_sensitive (line 1770)",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-669"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-30T08:15:07Z"
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-203",
"CWE-204"
],
"severity": "MODERATE",
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-phwx-77rv-743g",
"modified": "2024-07-30T09:32:03Z",
"modified": "2024-08-02T15:31:17Z",
"published": "2024-07-30T09:32:03Z",
"aliases": [
"CVE-2024-42157"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/pkey: Wipe sensitive data on failure\n\nWipe sensitive data from stack also if the copy_to_user() fails.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -55,7 +58,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-30T08:15:07Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rmpr-6w5x-hf6g",
"modified": "2024-07-30T09:32:03Z",
"modified": "2024-08-02T15:31:17Z",
"published": "2024-07-30T09:32:03Z",
"aliases": [
"CVE-2024-42160"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: check validation of fault attrs in f2fs_build_fault_attr()\n\n- It missed to check validation of fault attrs in parse_options(),\nlet's fix to add check condition in f2fs_build_fault_attr().\n- Use f2fs_build_fault_attr() in __sbi_store() to clean up code.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-754"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-30T08:15:07Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vqfv-6vgr-3j88",
"modified": "2024-07-30T09:32:03Z",
"modified": "2024-08-02T15:31:17Z",
"published": "2024-07-30T09:32:03Z",
"aliases": [
"CVE-2024-42156"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/pkey: Wipe copies of clear-key structures on failure\n\nWipe all sensitive data from stack for all IOCTLs, which convert a\nclear-key into a protected- or secure-key.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-30T08:15:07Z"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4cpx-q734-j233",
"modified": "2024-08-02T15:31:19Z",
"published": "2024-08-02T15:31:19Z",
"aliases": [
"CVE-2024-38890"
],
"details": "An issue in Horizon Business Services Inc. Caterease Software 16.0.1.1663 through 24.0.1.2405 and possibly later versions allows a local attacker to perform an Authentication Bypass by Capture-replay attack due to insufficient protection against capture-replay attacks.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38890"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.273374"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-02T15:16:35Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4h6p-wphh-f8rf",
"modified": "2024-08-02T15:31:19Z",
"published": "2024-08-02T15:31:19Z",
"aliases": [
"CVE-2024-7029"
],
"details": "Commands can be injected over the network and executed without authentication.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7029"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-214-07"
}
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-02T15:16:37Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g4w3-q8cv-798h",
"modified": "2024-08-01T06:30:34Z",
"modified": "2024-08-02T15:31:17Z",
"published": "2024-08-01T06:30:34Z",
"aliases": [
"CVE-2024-1715"