Publish Advisories

GHSA-5w3p-jvff-vgwv
GHSA-88xm-xppp-phhf
GHSA-fqvv-mh7w-3jq3
This commit is contained in:
advisory-database[bot]
2024-12-31 09:32:08 +00:00
parent fbce62d41c
commit 9f56232c73
3 changed files with 95 additions and 1 deletions
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5w3p-jvff-vgwv",
"modified": "2024-12-31T09:30:45Z",
"published": "2024-12-31T09:30:45Z",
"aliases": [
"CVE-2024-13067"
],
"details": "A vulnerability was found in CodeAstro Online Food Ordering System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/all_users.php of the component All Users Page. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13067"
},
{
"type": "WEB",
"url": "https://codeastro.com"
},
{
"type": "WEB",
"url": "https://github.com/shaturo1337/POCs/blob/main/Broken%20Access%20Control%20in%20Online%20Food%20Ordering%20System.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.289823"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.289823"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.472081"
}
],
"database_specific": {
"cwe_ids": [
"CWE-266"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-31T09:15:05Z"
}
}
@@ -0,0 +1,34 @@
{
"schema_version": "1.4.0",
"id": "GHSA-88xm-xppp-phhf",
"modified": "2024-12-31T09:30:45Z",
"published": "2024-12-31T09:30:45Z",
"aliases": [
"CVE-2024-49422"
],
"details": "Protection Mechanism Failure in bootloader prior to SMR Oct-2024 Release 1 allows physical attackers to reset lockscreen failure count by hardware fault injection. User interaction is required for triggering this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49422"
},
{
"type": "WEB",
"url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=10"
}
],
"database_specific": {
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-31T09:15:05Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fqvv-mh7w-3jq3",
"modified": "2024-12-21T15:30:32Z",
"modified": "2024-12-31T09:30:45Z",
"published": "2024-12-21T15:30:32Z",
"aliases": [
"CVE-2024-51464"
@@ -22,6 +22,10 @@
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7179509"
},
{
"type": "WEB",
"url": "http://seclists.org/fulldisclosure/2024/Dec/20"
}
],
"database_specific": {