From 9f1a25ac2011ce1b8f4bbf8a44c984dd7e739c12 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 2 Aug 2024 15:32:45 +0000 Subject: [PATCH] Publish Advisories GHSA-mvc8-6ffp-jrx5 GHSA-xfv5-jqgp-vqhj GHSA-m9w6-wp3h-vq8g GHSA-v727-f437-6cxx GHSA-w2rv-8vw7-735j GHSA-57rx-38pp-c45g GHSA-p9g8-3jw8-v3h3 GHSA-pw5j-63j7-2mhr GHSA-v7pg-qx5m-v7x4 GHSA-3q3x-839r-4xrh GHSA-59gf-g6mr-cr4x GHSA-5h59-75vf-973c GHSA-7r4w-v667-c6cr GHSA-jgc6-c9v8-vfqw GHSA-phwx-77rv-743g GHSA-rmpr-6w5x-hf6g GHSA-vqfv-6vgr-3j88 GHSA-4cpx-q734-j233 GHSA-4h6p-wphh-f8rf GHSA-g4w3-q8cv-798h --- .../GHSA-mvc8-6ffp-jrx5.json | 6 ++- .../GHSA-xfv5-jqgp-vqhj.json | 6 ++- .../GHSA-m9w6-wp3h-vq8g.json | 6 ++- .../GHSA-v727-f437-6cxx.json | 6 ++- .../GHSA-w2rv-8vw7-735j.json | 9 ++-- .../GHSA-57rx-38pp-c45g.json | 3 +- .../GHSA-p9g8-3jw8-v3h3.json | 11 +++-- .../GHSA-pw5j-63j7-2mhr.json | 2 +- .../GHSA-v7pg-qx5m-v7x4.json | 2 +- .../GHSA-3q3x-839r-4xrh.json | 11 +++-- .../GHSA-59gf-g6mr-cr4x.json | 11 +++-- .../GHSA-5h59-75vf-973c.json | 11 +++-- .../GHSA-7r4w-v667-c6cr.json | 11 +++-- .../GHSA-jgc6-c9v8-vfqw.json | 1 + .../GHSA-phwx-77rv-743g.json | 9 ++-- .../GHSA-rmpr-6w5x-hf6g.json | 11 +++-- .../GHSA-vqfv-6vgr-3j88.json | 9 ++-- .../GHSA-4cpx-q734-j233.json | 35 ++++++++++++++++ .../GHSA-4h6p-wphh-f8rf.json | 42 +++++++++++++++++++ .../GHSA-g4w3-q8cv-798h.json | 2 +- 20 files changed, 163 insertions(+), 41 deletions(-) create mode 100644 advisories/unreviewed/2024/08/GHSA-4cpx-q734-j233/GHSA-4cpx-q734-j233.json create mode 100644 advisories/unreviewed/2024/08/GHSA-4h6p-wphh-f8rf/GHSA-4h6p-wphh-f8rf.json diff --git a/advisories/github-reviewed/2023/12/GHSA-mvc8-6ffp-jrx5/GHSA-mvc8-6ffp-jrx5.json b/advisories/github-reviewed/2023/12/GHSA-mvc8-6ffp-jrx5/GHSA-mvc8-6ffp-jrx5.json index b080b681f8a..2d0b0dce2e4 100644 --- a/advisories/github-reviewed/2023/12/GHSA-mvc8-6ffp-jrx5/GHSA-mvc8-6ffp-jrx5.json +++ b/advisories/github-reviewed/2023/12/GHSA-mvc8-6ffp-jrx5/GHSA-mvc8-6ffp-jrx5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mvc8-6ffp-jrx5", - "modified": "2023-12-12T00:50:32Z", + "modified": "2024-08-02T15:31:16Z", "published": "2023-12-09T03:30:15Z", "aliases": [ "CVE-2023-6394" @@ -67,6 +67,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2023:7612" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7700" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-6394" diff --git a/advisories/github-reviewed/2023/12/GHSA-xfv5-jqgp-vqhj/GHSA-xfv5-jqgp-vqhj.json b/advisories/github-reviewed/2023/12/GHSA-xfv5-jqgp-vqhj/GHSA-xfv5-jqgp-vqhj.json index 6df9067483d..29daf2001c3 100644 --- a/advisories/github-reviewed/2023/12/GHSA-xfv5-jqgp-vqhj/GHSA-xfv5-jqgp-vqhj.json +++ b/advisories/github-reviewed/2023/12/GHSA-xfv5-jqgp-vqhj/GHSA-xfv5-jqgp-vqhj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xfv5-jqgp-vqhj", - "modified": "2023-12-06T21:43:18Z", + "modified": "2024-08-02T15:31:16Z", "published": "2023-12-06T18:31:05Z", "aliases": [ "CVE-2023-6393" @@ -71,6 +71,10 @@ "type": "WEB", "url": "https://github.com/quarkusio/quarkus/commit/d9ace85caec2d8497b1a2c48b8d52bb163f04adf" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7700" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-6393" diff --git a/advisories/github-reviewed/2024/04/GHSA-m9w6-wp3h-vq8g/GHSA-m9w6-wp3h-vq8g.json b/advisories/github-reviewed/2024/04/GHSA-m9w6-wp3h-vq8g/GHSA-m9w6-wp3h-vq8g.json index 444f6033b9b..f7bc8c8d8c6 100644 --- a/advisories/github-reviewed/2024/04/GHSA-m9w6-wp3h-vq8g/GHSA-m9w6-wp3h-vq8g.json +++ b/advisories/github-reviewed/2024/04/GHSA-m9w6-wp3h-vq8g/GHSA-m9w6-wp3h-vq8g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m9w6-wp3h-vq8g", - "modified": "2024-07-08T14:24:58Z", + "modified": "2024-08-02T15:31:16Z", "published": "2024-04-25T18:30:39Z", "aliases": [ "CVE-2024-0874" @@ -63,6 +63,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:0041" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4850" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-0874" diff --git a/advisories/unreviewed/2023/12/GHSA-v727-f437-6cxx/GHSA-v727-f437-6cxx.json b/advisories/unreviewed/2023/12/GHSA-v727-f437-6cxx/GHSA-v727-f437-6cxx.json index 6c9edecdf79..7d9dcc4d142 100644 --- a/advisories/unreviewed/2023/12/GHSA-v727-f437-6cxx/GHSA-v727-f437-6cxx.json +++ b/advisories/unreviewed/2023/12/GHSA-v727-f437-6cxx/GHSA-v727-f437-6cxx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v727-f437-6cxx", - "modified": "2024-07-24T00:31:18Z", + "modified": "2024-08-02T15:31:16Z", "published": "2023-12-21T21:30:31Z", "aliases": [ "CVE-2023-6546" @@ -37,6 +37,10 @@ "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-6546" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4970" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:4731" diff --git a/advisories/unreviewed/2024/05/GHSA-w2rv-8vw7-735j/GHSA-w2rv-8vw7-735j.json b/advisories/unreviewed/2024/05/GHSA-w2rv-8vw7-735j/GHSA-w2rv-8vw7-735j.json index 899b7d35d28..6020a198bfa 100644 --- a/advisories/unreviewed/2024/05/GHSA-w2rv-8vw7-735j/GHSA-w2rv-8vw7-735j.json +++ b/advisories/unreviewed/2024/05/GHSA-w2rv-8vw7-735j/GHSA-w2rv-8vw7-735j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w2rv-8vw7-735j", - "modified": "2024-05-02T06:30:31Z", + "modified": "2024-08-02T15:31:16Z", "published": "2024-05-02T06:30:31Z", "aliases": [ "CVE-2024-3476" ], "details": "The Side Menu Lite WordPress plugin before 4.2.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-02T06:15:50Z" diff --git a/advisories/unreviewed/2024/06/GHSA-57rx-38pp-c45g/GHSA-57rx-38pp-c45g.json b/advisories/unreviewed/2024/06/GHSA-57rx-38pp-c45g/GHSA-57rx-38pp-c45g.json index 399b59bfbd5..406b1718fe3 100644 --- a/advisories/unreviewed/2024/06/GHSA-57rx-38pp-c45g/GHSA-57rx-38pp-c45g.json +++ b/advisories/unreviewed/2024/06/GHSA-57rx-38pp-c45g/GHSA-57rx-38pp-c45g.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-276" + "CWE-276", + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-p9g8-3jw8-v3h3/GHSA-p9g8-3jw8-v3h3.json b/advisories/unreviewed/2024/06/GHSA-p9g8-3jw8-v3h3/GHSA-p9g8-3jw8-v3h3.json index 86d656bb6e8..59801ec432e 100644 --- a/advisories/unreviewed/2024/06/GHSA-p9g8-3jw8-v3h3/GHSA-p9g8-3jw8-v3h3.json +++ b/advisories/unreviewed/2024/06/GHSA-p9g8-3jw8-v3h3/GHSA-p9g8-3jw8-v3h3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p9g8-3jw8-v3h3", - "modified": "2024-06-26T06:30:29Z", + "modified": "2024-08-02T15:31:16Z", "published": "2024-06-26T06:30:29Z", "aliases": [ "CVE-2024-5199" ], "details": "The Spotify Play Button WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-26T06:15:16Z" diff --git a/advisories/unreviewed/2024/06/GHSA-pw5j-63j7-2mhr/GHSA-pw5j-63j7-2mhr.json b/advisories/unreviewed/2024/06/GHSA-pw5j-63j7-2mhr/GHSA-pw5j-63j7-2mhr.json index 328956fbd78..400d967d98a 100644 --- a/advisories/unreviewed/2024/06/GHSA-pw5j-63j7-2mhr/GHSA-pw5j-63j7-2mhr.json +++ b/advisories/unreviewed/2024/06/GHSA-pw5j-63j7-2mhr/GHSA-pw5j-63j7-2mhr.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-v7pg-qx5m-v7x4/GHSA-v7pg-qx5m-v7x4.json b/advisories/unreviewed/2024/06/GHSA-v7pg-qx5m-v7x4/GHSA-v7pg-qx5m-v7x4.json index 7bd584fa026..880cdb3b35c 100644 --- a/advisories/unreviewed/2024/06/GHSA-v7pg-qx5m-v7x4/GHSA-v7pg-qx5m-v7x4.json +++ b/advisories/unreviewed/2024/06/GHSA-v7pg-qx5m-v7x4/GHSA-v7pg-qx5m-v7x4.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-3q3x-839r-4xrh/GHSA-3q3x-839r-4xrh.json b/advisories/unreviewed/2024/07/GHSA-3q3x-839r-4xrh/GHSA-3q3x-839r-4xrh.json index 0cb5068ab07..e805f6ea877 100644 --- a/advisories/unreviewed/2024/07/GHSA-3q3x-839r-4xrh/GHSA-3q3x-839r-4xrh.json +++ b/advisories/unreviewed/2024/07/GHSA-3q3x-839r-4xrh/GHSA-3q3x-839r-4xrh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3q3x-839r-4xrh", - "modified": "2024-07-30T09:32:04Z", + "modified": "2024-08-02T15:31:17Z", "published": "2024-07-30T09:32:04Z", "aliases": [ "CVE-2024-42224" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: mv88e6xxx: Correct check for empty list\n\nSince commit a3c53be55c95 (\"net: dsa: mv88e6xxx: Support multiple MDIO\nbusses\") mv88e6xxx_default_mdio_bus() has checked that the\nreturn value of list_first_entry() is non-NULL.\n\nThis appears to be intended to guard against the list chip->mdios being\nempty. However, it is not the correct check as the implementation of\nlist_first_entry is not designed to return NULL for empty lists.\n\nInstead, use list_first_entry_or_null() which does return NULL if the\nlist is empty.\n\nFlagged by Smatch.\nCompile tested only.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-754" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:07Z" diff --git a/advisories/unreviewed/2024/07/GHSA-59gf-g6mr-cr4x/GHSA-59gf-g6mr-cr4x.json b/advisories/unreviewed/2024/07/GHSA-59gf-g6mr-cr4x/GHSA-59gf-g6mr-cr4x.json index 9ce9361deb0..4f33ee0cfb3 100644 --- a/advisories/unreviewed/2024/07/GHSA-59gf-g6mr-cr4x/GHSA-59gf-g6mr-cr4x.json +++ b/advisories/unreviewed/2024/07/GHSA-59gf-g6mr-cr4x/GHSA-59gf-g6mr-cr4x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-59gf-g6mr-cr4x", - "modified": "2024-07-30T09:32:04Z", + "modified": "2024-08-02T15:31:17Z", "published": "2024-07-30T09:32:03Z", "aliases": [ "CVE-2024-42223" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: dvb-frontends: tda10048: Fix integer overflow\n\nstate->xtal_hz can be up to 16M, so it can overflow a 32 bit integer\nwhen multiplied by pll_mfactor.\n\nCreate a new 64 bit variable to hold the calculations.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:07Z" diff --git a/advisories/unreviewed/2024/07/GHSA-5h59-75vf-973c/GHSA-5h59-75vf-973c.json b/advisories/unreviewed/2024/07/GHSA-5h59-75vf-973c/GHSA-5h59-75vf-973c.json index 16a7231d292..0b7bdc5b052 100644 --- a/advisories/unreviewed/2024/07/GHSA-5h59-75vf-973c/GHSA-5h59-75vf-973c.json +++ b/advisories/unreviewed/2024/07/GHSA-5h59-75vf-973c/GHSA-5h59-75vf-973c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5h59-75vf-973c", - "modified": "2024-07-30T09:32:03Z", + "modified": "2024-08-02T15:31:17Z", "published": "2024-07-30T09:32:03Z", "aliases": [ "CVE-2024-42159" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: mpi3mr: Sanitise num_phys\n\nInformation is stored in mr_sas_port->phy_mask, values larger then size of\nthis field shouldn't be allowed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-754" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:07Z" diff --git a/advisories/unreviewed/2024/07/GHSA-7r4w-v667-c6cr/GHSA-7r4w-v667-c6cr.json b/advisories/unreviewed/2024/07/GHSA-7r4w-v667-c6cr/GHSA-7r4w-v667-c6cr.json index 51890f61ab4..454b476ba63 100644 --- a/advisories/unreviewed/2024/07/GHSA-7r4w-v667-c6cr/GHSA-7r4w-v667-c6cr.json +++ b/advisories/unreviewed/2024/07/GHSA-7r4w-v667-c6cr/GHSA-7r4w-v667-c6cr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7r4w-v667-c6cr", - "modified": "2024-07-30T09:32:03Z", + "modified": "2024-08-02T15:31:17Z", "published": "2024-07-30T09:32:03Z", "aliases": [ "CVE-2024-42158" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/pkey: Use kfree_sensitive() to fix Coccinelle warnings\n\nReplace memzero_explicit() and kfree() with kfree_sensitive() to fix\nwarnings reported by Coccinelle:\n\nWARNING opportunity for kfree_sensitive/kvfree_sensitive (line 1506)\nWARNING opportunity for kfree_sensitive/kvfree_sensitive (line 1643)\nWARNING opportunity for kfree_sensitive/kvfree_sensitive (line 1770)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-669" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:07Z" diff --git a/advisories/unreviewed/2024/07/GHSA-jgc6-c9v8-vfqw/GHSA-jgc6-c9v8-vfqw.json b/advisories/unreviewed/2024/07/GHSA-jgc6-c9v8-vfqw/GHSA-jgc6-c9v8-vfqw.json index 15f0ed46814..5a5587fa126 100644 --- a/advisories/unreviewed/2024/07/GHSA-jgc6-c9v8-vfqw/GHSA-jgc6-c9v8-vfqw.json +++ b/advisories/unreviewed/2024/07/GHSA-jgc6-c9v8-vfqw/GHSA-jgc6-c9v8-vfqw.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-203", "CWE-204" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/07/GHSA-phwx-77rv-743g/GHSA-phwx-77rv-743g.json b/advisories/unreviewed/2024/07/GHSA-phwx-77rv-743g/GHSA-phwx-77rv-743g.json index ae336635715..6765b0203b5 100644 --- a/advisories/unreviewed/2024/07/GHSA-phwx-77rv-743g/GHSA-phwx-77rv-743g.json +++ b/advisories/unreviewed/2024/07/GHSA-phwx-77rv-743g/GHSA-phwx-77rv-743g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-phwx-77rv-743g", - "modified": "2024-07-30T09:32:03Z", + "modified": "2024-08-02T15:31:17Z", "published": "2024-07-30T09:32:03Z", "aliases": [ "CVE-2024-42157" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/pkey: Wipe sensitive data on failure\n\nWipe sensitive data from stack also if the copy_to_user() fails.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:07Z" diff --git a/advisories/unreviewed/2024/07/GHSA-rmpr-6w5x-hf6g/GHSA-rmpr-6w5x-hf6g.json b/advisories/unreviewed/2024/07/GHSA-rmpr-6w5x-hf6g/GHSA-rmpr-6w5x-hf6g.json index 9ec02b079f0..48a7072d09a 100644 --- a/advisories/unreviewed/2024/07/GHSA-rmpr-6w5x-hf6g/GHSA-rmpr-6w5x-hf6g.json +++ b/advisories/unreviewed/2024/07/GHSA-rmpr-6w5x-hf6g/GHSA-rmpr-6w5x-hf6g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rmpr-6w5x-hf6g", - "modified": "2024-07-30T09:32:03Z", + "modified": "2024-08-02T15:31:17Z", "published": "2024-07-30T09:32:03Z", "aliases": [ "CVE-2024-42160" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: check validation of fault attrs in f2fs_build_fault_attr()\n\n- It missed to check validation of fault attrs in parse_options(),\nlet's fix to add check condition in f2fs_build_fault_attr().\n- Use f2fs_build_fault_attr() in __sbi_store() to clean up code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-754" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:07Z" diff --git a/advisories/unreviewed/2024/07/GHSA-vqfv-6vgr-3j88/GHSA-vqfv-6vgr-3j88.json b/advisories/unreviewed/2024/07/GHSA-vqfv-6vgr-3j88/GHSA-vqfv-6vgr-3j88.json index 33f22b5bef9..6cc82a56fdd 100644 --- a/advisories/unreviewed/2024/07/GHSA-vqfv-6vgr-3j88/GHSA-vqfv-6vgr-3j88.json +++ b/advisories/unreviewed/2024/07/GHSA-vqfv-6vgr-3j88/GHSA-vqfv-6vgr-3j88.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vqfv-6vgr-3j88", - "modified": "2024-07-30T09:32:03Z", + "modified": "2024-08-02T15:31:17Z", "published": "2024-07-30T09:32:03Z", "aliases": [ "CVE-2024-42156" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/pkey: Wipe copies of clear-key structures on failure\n\nWipe all sensitive data from stack for all IOCTLs, which convert a\nclear-key into a protected- or secure-key.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:07Z" diff --git a/advisories/unreviewed/2024/08/GHSA-4cpx-q734-j233/GHSA-4cpx-q734-j233.json b/advisories/unreviewed/2024/08/GHSA-4cpx-q734-j233/GHSA-4cpx-q734-j233.json new file mode 100644 index 00000000000..4bda3795bea --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4cpx-q734-j233/GHSA-4cpx-q734-j233.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cpx-q734-j233", + "modified": "2024-08-02T15:31:19Z", + "published": "2024-08-02T15:31:19Z", + "aliases": [ + "CVE-2024-38890" + ], + "details": "An issue in Horizon Business Services Inc. Caterease Software 16.0.1.1663 through 24.0.1.2405 and possibly later versions allows a local attacker to perform an Authentication Bypass by Capture-replay attack due to insufficient protection against capture-replay attacks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38890" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273374" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-02T15:16:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4h6p-wphh-f8rf/GHSA-4h6p-wphh-f8rf.json b/advisories/unreviewed/2024/08/GHSA-4h6p-wphh-f8rf/GHSA-4h6p-wphh-f8rf.json new file mode 100644 index 00000000000..4743da15075 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4h6p-wphh-f8rf/GHSA-4h6p-wphh-f8rf.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4h6p-wphh-f8rf", + "modified": "2024-08-02T15:31:19Z", + "published": "2024-08-02T15:31:19Z", + "aliases": [ + "CVE-2024-7029" + ], + "details": "Commands can be injected over the network and executed without authentication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7029" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-214-07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-02T15:16:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g4w3-q8cv-798h/GHSA-g4w3-q8cv-798h.json b/advisories/unreviewed/2024/08/GHSA-g4w3-q8cv-798h/GHSA-g4w3-q8cv-798h.json index c70ae4ceb74..bf852c713cd 100644 --- a/advisories/unreviewed/2024/08/GHSA-g4w3-q8cv-798h/GHSA-g4w3-q8cv-798h.json +++ b/advisories/unreviewed/2024/08/GHSA-g4w3-q8cv-798h/GHSA-g4w3-q8cv-798h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g4w3-q8cv-798h", - "modified": "2024-08-01T06:30:34Z", + "modified": "2024-08-02T15:31:17Z", "published": "2024-08-01T06:30:34Z", "aliases": [ "CVE-2024-1715"