From 9f56232c730e9972596ea73acfe62c83a7f61d49 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 31 Dec 2024 09:32:08 +0000 Subject: [PATCH] Publish Advisories GHSA-5w3p-jvff-vgwv GHSA-88xm-xppp-phhf GHSA-fqvv-mh7w-3jq3 --- .../GHSA-5w3p-jvff-vgwv.json | 56 +++++++++++++++++++ .../GHSA-88xm-xppp-phhf.json | 34 +++++++++++ .../GHSA-fqvv-mh7w-3jq3.json | 6 +- 3 files changed, 95 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2024/12/GHSA-5w3p-jvff-vgwv/GHSA-5w3p-jvff-vgwv.json create mode 100644 advisories/unreviewed/2024/12/GHSA-88xm-xppp-phhf/GHSA-88xm-xppp-phhf.json diff --git a/advisories/unreviewed/2024/12/GHSA-5w3p-jvff-vgwv/GHSA-5w3p-jvff-vgwv.json b/advisories/unreviewed/2024/12/GHSA-5w3p-jvff-vgwv/GHSA-5w3p-jvff-vgwv.json new file mode 100644 index 00000000000..3e0a10e0737 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5w3p-jvff-vgwv/GHSA-5w3p-jvff-vgwv.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5w3p-jvff-vgwv", + "modified": "2024-12-31T09:30:45Z", + "published": "2024-12-31T09:30:45Z", + "aliases": [ + "CVE-2024-13067" + ], + "details": "A vulnerability was found in CodeAstro Online Food Ordering System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/all_users.php of the component All Users Page. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13067" + }, + { + "type": "WEB", + "url": "https://codeastro.com" + }, + { + "type": "WEB", + "url": "https://github.com/shaturo1337/POCs/blob/main/Broken%20Access%20Control%20in%20Online%20Food%20Ordering%20System.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289823" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289823" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.472081" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T09:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-88xm-xppp-phhf/GHSA-88xm-xppp-phhf.json b/advisories/unreviewed/2024/12/GHSA-88xm-xppp-phhf/GHSA-88xm-xppp-phhf.json new file mode 100644 index 00000000000..706ca1c3fb5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-88xm-xppp-phhf/GHSA-88xm-xppp-phhf.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88xm-xppp-phhf", + "modified": "2024-12-31T09:30:45Z", + "published": "2024-12-31T09:30:45Z", + "aliases": [ + "CVE-2024-49422" + ], + "details": "Protection Mechanism Failure in bootloader prior to SMR Oct-2024 Release 1 allows physical attackers to reset lockscreen failure count by hardware fault injection. User interaction is required for triggering this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49422" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=10" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T09:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fqvv-mh7w-3jq3/GHSA-fqvv-mh7w-3jq3.json b/advisories/unreviewed/2024/12/GHSA-fqvv-mh7w-3jq3/GHSA-fqvv-mh7w-3jq3.json index 8f8b6fd3bbe..eda67c1ae5a 100644 --- a/advisories/unreviewed/2024/12/GHSA-fqvv-mh7w-3jq3/GHSA-fqvv-mh7w-3jq3.json +++ b/advisories/unreviewed/2024/12/GHSA-fqvv-mh7w-3jq3/GHSA-fqvv-mh7w-3jq3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fqvv-mh7w-3jq3", - "modified": "2024-12-21T15:30:32Z", + "modified": "2024-12-31T09:30:45Z", "published": "2024-12-21T15:30:32Z", "aliases": [ "CVE-2024-51464" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://www.ibm.com/support/pages/node/7179509" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Dec/20" } ], "database_specific": {