diff --git a/advisories/github-reviewed/2024/11/GHSA-7p9f-6x8j-gxxp/GHSA-7p9f-6x8j-gxxp.json b/advisories/github-reviewed/2024/11/GHSA-7p9f-6x8j-gxxp/GHSA-7p9f-6x8j-gxxp.json index b5e99ba8f43..91de0f4117a 100644 --- a/advisories/github-reviewed/2024/11/GHSA-7p9f-6x8j-gxxp/GHSA-7p9f-6x8j-gxxp.json +++ b/advisories/github-reviewed/2024/11/GHSA-7p9f-6x8j-gxxp/GHSA-7p9f-6x8j-gxxp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7p9f-6x8j-gxxp", - "modified": "2024-12-04T22:16:58Z", + "modified": "2024-12-17T21:30:34Z", "published": "2024-11-26T21:50:30Z", "aliases": [ "CVE-2024-8676" @@ -90,6 +90,10 @@ "type": "WEB", "url": "https://github.com/cri-o/cri-o/commit/e8e7dcb7838d11b5157976bf3e31a5840bb77de7" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHBA-2024:10826" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-8676" diff --git a/advisories/unreviewed/2023/06/GHSA-944w-cmcw-jwwf/GHSA-944w-cmcw-jwwf.json b/advisories/unreviewed/2023/06/GHSA-944w-cmcw-jwwf/GHSA-944w-cmcw-jwwf.json index 54e9f2888ed..6dcc8c21bb6 100644 --- a/advisories/unreviewed/2023/06/GHSA-944w-cmcw-jwwf/GHSA-944w-cmcw-jwwf.json +++ b/advisories/unreviewed/2023/06/GHSA-944w-cmcw-jwwf/GHSA-944w-cmcw-jwwf.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-276" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-mv2p-xxqx-rg9j/GHSA-mv2p-xxqx-rg9j.json b/advisories/unreviewed/2023/06/GHSA-mv2p-xxqx-rg9j/GHSA-mv2p-xxqx-rg9j.json index ea55f046700..b32c384e765 100644 --- a/advisories/unreviewed/2023/06/GHSA-mv2p-xxqx-rg9j/GHSA-mv2p-xxqx-rg9j.json +++ b/advisories/unreviewed/2023/06/GHSA-mv2p-xxqx-rg9j/GHSA-mv2p-xxqx-rg9j.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-552" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/06/GHSA-v9q4-6qph-xr93/GHSA-v9q4-6qph-xr93.json b/advisories/unreviewed/2023/06/GHSA-v9q4-6qph-xr93/GHSA-v9q4-6qph-xr93.json index 5fc008e8ad9..3262be04cc2 100644 --- a/advisories/unreviewed/2023/06/GHSA-v9q4-6qph-xr93/GHSA-v9q4-6qph-xr93.json +++ b/advisories/unreviewed/2023/06/GHSA-v9q4-6qph-xr93/GHSA-v9q4-6qph-xr93.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-wxp6-wm3h-86w8/GHSA-wxp6-wm3h-86w8.json b/advisories/unreviewed/2023/06/GHSA-wxp6-wm3h-86w8/GHSA-wxp6-wm3h-86w8.json index e8945b83a04..d2de6826ddb 100644 --- a/advisories/unreviewed/2023/06/GHSA-wxp6-wm3h-86w8/GHSA-wxp6-wm3h-86w8.json +++ b/advisories/unreviewed/2023/06/GHSA-wxp6-wm3h-86w8/GHSA-wxp6-wm3h-86w8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-397m-2h32-p5j6/GHSA-397m-2h32-p5j6.json b/advisories/unreviewed/2024/02/GHSA-397m-2h32-p5j6/GHSA-397m-2h32-p5j6.json index e68a9d067c7..7e0364ff509 100644 --- a/advisories/unreviewed/2024/02/GHSA-397m-2h32-p5j6/GHSA-397m-2h32-p5j6.json +++ b/advisories/unreviewed/2024/02/GHSA-397m-2h32-p5j6/GHSA-397m-2h32-p5j6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-f962-cfv2-wvqj/GHSA-f962-cfv2-wvqj.json b/advisories/unreviewed/2024/02/GHSA-f962-cfv2-wvqj/GHSA-f962-cfv2-wvqj.json index 1a1bf143240..2ea74a74544 100644 --- a/advisories/unreviewed/2024/02/GHSA-f962-cfv2-wvqj/GHSA-f962-cfv2-wvqj.json +++ b/advisories/unreviewed/2024/02/GHSA-f962-cfv2-wvqj/GHSA-f962-cfv2-wvqj.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-w953-7xrr-xmmq/GHSA-w953-7xrr-xmmq.json b/advisories/unreviewed/2024/02/GHSA-w953-7xrr-xmmq/GHSA-w953-7xrr-xmmq.json index b5ce73e7c2d..d9be8221712 100644 --- a/advisories/unreviewed/2024/02/GHSA-w953-7xrr-xmmq/GHSA-w953-7xrr-xmmq.json +++ b/advisories/unreviewed/2024/02/GHSA-w953-7xrr-xmmq/GHSA-w953-7xrr-xmmq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-2cm2-8q39-h9qp/GHSA-2cm2-8q39-h9qp.json b/advisories/unreviewed/2024/07/GHSA-2cm2-8q39-h9qp/GHSA-2cm2-8q39-h9qp.json index 97f87be557d..5599fda0016 100644 --- a/advisories/unreviewed/2024/07/GHSA-2cm2-8q39-h9qp/GHSA-2cm2-8q39-h9qp.json +++ b/advisories/unreviewed/2024/07/GHSA-2cm2-8q39-h9qp/GHSA-2cm2-8q39-h9qp.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1021", "CWE-269" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/07/GHSA-3wx2-gggp-v6jp/GHSA-3wx2-gggp-v6jp.json b/advisories/unreviewed/2024/07/GHSA-3wx2-gggp-v6jp/GHSA-3wx2-gggp-v6jp.json index 0149fbf143a..2823b1f4991 100644 --- a/advisories/unreviewed/2024/07/GHSA-3wx2-gggp-v6jp/GHSA-3wx2-gggp-v6jp.json +++ b/advisories/unreviewed/2024/07/GHSA-3wx2-gggp-v6jp/GHSA-3wx2-gggp-v6jp.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-362" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-8v98-3h75-pjr6/GHSA-8v98-3h75-pjr6.json b/advisories/unreviewed/2024/07/GHSA-8v98-3h75-pjr6/GHSA-8v98-3h75-pjr6.json index 630935ba298..f54fa035838 100644 --- a/advisories/unreviewed/2024/07/GHSA-8v98-3h75-pjr6/GHSA-8v98-3h75-pjr6.json +++ b/advisories/unreviewed/2024/07/GHSA-8v98-3h75-pjr6/GHSA-8v98-3h75-pjr6.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-1021" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-jhq7-p5mr-3m4w/GHSA-jhq7-p5mr-3m4w.json b/advisories/unreviewed/2024/07/GHSA-jhq7-p5mr-3m4w/GHSA-jhq7-p5mr-3m4w.json index deb44cb452a..71a636c7ab1 100644 --- a/advisories/unreviewed/2024/07/GHSA-jhq7-p5mr-3m4w/GHSA-jhq7-p5mr-3m4w.json +++ b/advisories/unreviewed/2024/07/GHSA-jhq7-p5mr-3m4w/GHSA-jhq7-p5mr-3m4w.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-hh5f-w8h8-vh35/GHSA-hh5f-w8h8-vh35.json b/advisories/unreviewed/2024/09/GHSA-hh5f-w8h8-vh35/GHSA-hh5f-w8h8-vh35.json index ff3454c7483..b5a2630436c 100644 --- a/advisories/unreviewed/2024/09/GHSA-hh5f-w8h8-vh35/GHSA-hh5f-w8h8-vh35.json +++ b/advisories/unreviewed/2024/09/GHSA-hh5f-w8h8-vh35/GHSA-hh5f-w8h8-vh35.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-358" + "CWE-358", + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-xgpg-34fv-3xwr/GHSA-xgpg-34fv-3xwr.json b/advisories/unreviewed/2024/09/GHSA-xgpg-34fv-3xwr/GHSA-xgpg-34fv-3xwr.json index 15f94c071a4..c797260c636 100644 --- a/advisories/unreviewed/2024/09/GHSA-xgpg-34fv-3xwr/GHSA-xgpg-34fv-3xwr.json +++ b/advisories/unreviewed/2024/09/GHSA-xgpg-34fv-3xwr/GHSA-xgpg-34fv-3xwr.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-g7cv-x9wx-38gx/GHSA-g7cv-x9wx-38gx.json b/advisories/unreviewed/2024/10/GHSA-g7cv-x9wx-38gx/GHSA-g7cv-x9wx-38gx.json index 7f5ca65aab6..7417c06dad7 100644 --- a/advisories/unreviewed/2024/10/GHSA-g7cv-x9wx-38gx/GHSA-g7cv-x9wx-38gx.json +++ b/advisories/unreviewed/2024/10/GHSA-g7cv-x9wx-38gx/GHSA-g7cv-x9wx-38gx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g7cv-x9wx-38gx", - "modified": "2024-10-03T18:30:36Z", + "modified": "2024-12-17T21:30:34Z", "published": "2024-10-03T18:30:36Z", "aliases": [ "CVE-2024-8508" @@ -19,13 +19,22 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8508" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/11/msg00009.html" + }, { "type": "WEB", "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2024-8508.txt" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/10/04/5" } ], "database_specific": { "cwe_ids": [ + "CWE-1284", "CWE-606" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/11/GHSA-2p4v-cp2q-5hx3/GHSA-2p4v-cp2q-5hx3.json b/advisories/unreviewed/2024/11/GHSA-2p4v-cp2q-5hx3/GHSA-2p4v-cp2q-5hx3.json index e20317c514a..458432e1ab3 100644 --- a/advisories/unreviewed/2024/11/GHSA-2p4v-cp2q-5hx3/GHSA-2p4v-cp2q-5hx3.json +++ b/advisories/unreviewed/2024/11/GHSA-2p4v-cp2q-5hx3/GHSA-2p4v-cp2q-5hx3.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-276" + "CWE-276", + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-3qg5-qhw5-vc9x/GHSA-3qg5-qhw5-vc9x.json b/advisories/unreviewed/2024/11/GHSA-3qg5-qhw5-vc9x/GHSA-3qg5-qhw5-vc9x.json index 92bbe527cab..2edcfe25eaa 100644 --- a/advisories/unreviewed/2024/11/GHSA-3qg5-qhw5-vc9x/GHSA-3qg5-qhw5-vc9x.json +++ b/advisories/unreviewed/2024/11/GHSA-3qg5-qhw5-vc9x/GHSA-3qg5-qhw5-vc9x.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-276" + "CWE-276", + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-4m65-6q77-h9mp/GHSA-4m65-6q77-h9mp.json b/advisories/unreviewed/2024/11/GHSA-4m65-6q77-h9mp/GHSA-4m65-6q77-h9mp.json index d82ff861cdc..3d23d4bb911 100644 --- a/advisories/unreviewed/2024/11/GHSA-4m65-6q77-h9mp/GHSA-4m65-6q77-h9mp.json +++ b/advisories/unreviewed/2024/11/GHSA-4m65-6q77-h9mp/GHSA-4m65-6q77-h9mp.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-862", "CWE-94" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/11/GHSA-7xp3-xc7q-7r4h/GHSA-7xp3-xc7q-7r4h.json b/advisories/unreviewed/2024/11/GHSA-7xp3-xc7q-7r4h/GHSA-7xp3-xc7q-7r4h.json index 5bab0bef81b..7484738b7d4 100644 --- a/advisories/unreviewed/2024/11/GHSA-7xp3-xc7q-7r4h/GHSA-7xp3-xc7q-7r4h.json +++ b/advisories/unreviewed/2024/11/GHSA-7xp3-xc7q-7r4h/GHSA-7xp3-xc7q-7r4h.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-476", "CWE-862" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/12/GHSA-3fm6-6429-pc94/GHSA-3fm6-6429-pc94.json b/advisories/unreviewed/2024/12/GHSA-3fm6-6429-pc94/GHSA-3fm6-6429-pc94.json index 209c06c2751..a6c15c6c388 100644 --- a/advisories/unreviewed/2024/12/GHSA-3fm6-6429-pc94/GHSA-3fm6-6429-pc94.json +++ b/advisories/unreviewed/2024/12/GHSA-3fm6-6429-pc94/GHSA-3fm6-6429-pc94.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3fm6-6429-pc94", - "modified": "2024-12-16T06:30:44Z", + "modified": "2024-12-17T21:30:34Z", "published": "2024-12-16T06:30:43Z", "aliases": [ "CVE-2024-53376" ], "details": "CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the phpSelection field to the websites/submitWebsiteCreation URI.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-16T04:15:05Z" diff --git a/advisories/unreviewed/2024/12/GHSA-4hxr-28mv-q729/GHSA-4hxr-28mv-q729.json b/advisories/unreviewed/2024/12/GHSA-4hxr-28mv-q729/GHSA-4hxr-28mv-q729.json new file mode 100644 index 00000000000..3fcadd85c74 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4hxr-28mv-q729/GHSA-4hxr-28mv-q729.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hxr-28mv-q729", + "modified": "2024-12-17T21:30:34Z", + "published": "2024-12-17T21:30:34Z", + "aliases": [ + "CVE-2024-11993" + ], + "details": "Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.1.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38, 7.3 GA through update 36, 7.2 GA through fix pack 20 and 7.1 GA through fix pack 28 allows remote attackers to execute arbitrary web script or HTML via Dispatch name field", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11993" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2024-11993" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-527r-mrh4-wx97/GHSA-527r-mrh4-wx97.json b/advisories/unreviewed/2024/12/GHSA-527r-mrh4-wx97/GHSA-527r-mrh4-wx97.json new file mode 100644 index 00000000000..e08f29a32d3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-527r-mrh4-wx97/GHSA-527r-mrh4-wx97.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-527r-mrh4-wx97", + "modified": "2024-12-17T21:30:34Z", + "published": "2024-12-17T21:30:34Z", + "aliases": [ + "CVE-2024-55058" + ], + "details": "An insecure direct object reference (IDOR) vulnerability was discovered in PHPGurukul Online Birth Certificate System v1.0. This vulnerability resides in the viewid parameter of /user/view-application-detail.php. Authenticated users can exploit this flaw by manipulating the viewid parameter in the URL to access sensitive birth certificate details of other users without proper authorization checks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55058" + }, + { + "type": "WEB", + "url": "https://github.com/SCR-athif/CVE/tree/main/CVE-2024-55058" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5mpw-4546-2wcr/GHSA-5mpw-4546-2wcr.json b/advisories/unreviewed/2024/12/GHSA-5mpw-4546-2wcr/GHSA-5mpw-4546-2wcr.json new file mode 100644 index 00000000000..5f28497a891 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5mpw-4546-2wcr/GHSA-5mpw-4546-2wcr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mpw-4546-2wcr", + "modified": "2024-12-17T21:30:34Z", + "published": "2024-12-17T21:30:34Z", + "aliases": [ + "CVE-2024-12539" + ], + "details": "An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12539" + }, + { + "type": "WEB", + "url": "https://discuss.elastic.co/t/elasticsearch-8-16-2-8-17-0-security-update/372091" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6pwv-ppw3-h39w/GHSA-6pwv-ppw3-h39w.json b/advisories/unreviewed/2024/12/GHSA-6pwv-ppw3-h39w/GHSA-6pwv-ppw3-h39w.json new file mode 100644 index 00000000000..a8f6f25a2be --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6pwv-ppw3-h39w/GHSA-6pwv-ppw3-h39w.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pwv-ppw3-h39w", + "modified": "2024-12-17T21:30:34Z", + "published": "2024-12-17T21:30:34Z", + "aliases": [ + "CVE-2024-55514" + ], + "details": "A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_sfmig.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded, potentially leading to unauthorized access to server permissions.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55514" + }, + { + "type": "WEB", + "url": "https://gist.github.com/wscg928/cbe88078751abad2ada2334eb12a5060" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T20:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9r59-cc3r-2gm6/GHSA-9r59-cc3r-2gm6.json b/advisories/unreviewed/2024/12/GHSA-9r59-cc3r-2gm6/GHSA-9r59-cc3r-2gm6.json new file mode 100644 index 00000000000..2a2604859ce --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9r59-cc3r-2gm6/GHSA-9r59-cc3r-2gm6.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9r59-cc3r-2gm6", + "modified": "2024-12-17T21:30:34Z", + "published": "2024-12-17T21:30:34Z", + "aliases": [ + "CVE-2024-55056" + ], + "details": "A stored cross-site scripting (XSS) vulnerability was identified in Phpgurukul Online Birth Certificate System 1.0 in /user/certificate-form.php via the full name field.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55056" + }, + { + "type": "WEB", + "url": "https://github.com/SCR-athif/CVE/tree/main/CVE-2024-55056" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hw97-cgm7-v26g/GHSA-hw97-cgm7-v26g.json b/advisories/unreviewed/2024/12/GHSA-hw97-cgm7-v26g/GHSA-hw97-cgm7-v26g.json new file mode 100644 index 00000000000..19daa93ac1b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hw97-cgm7-v26g/GHSA-hw97-cgm7-v26g.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hw97-cgm7-v26g", + "modified": "2024-12-17T21:30:34Z", + "published": "2024-12-17T21:30:34Z", + "aliases": [ + "CVE-2024-55059" + ], + "details": "A stored HTML Injection vulnerability was identified in PHPGurukul Online Birth Certificate System v1.0 in /user/certificate-form.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55059" + }, + { + "type": "WEB", + "url": "https://github.com/SCR-athif/CVE/tree/main/CVE-2024-55059" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jxw2-jvxf-5vrp/GHSA-jxw2-jvxf-5vrp.json b/advisories/unreviewed/2024/12/GHSA-jxw2-jvxf-5vrp/GHSA-jxw2-jvxf-5vrp.json new file mode 100644 index 00000000000..c38022ea330 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jxw2-jvxf-5vrp/GHSA-jxw2-jvxf-5vrp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxw2-jvxf-5vrp", + "modified": "2024-12-17T21:30:34Z", + "published": "2024-12-17T21:30:34Z", + "aliases": [ + "CVE-2024-49194" + ], + "details": "Databricks JDBC Driver before 2.6.40 could potentially allow remote code execution (RCE) by triggering a JNDI injection via a JDBC URL parameter. The vulnerability is rooted in the improper handling of the krbJAASFile parameter. An attacker could potentially exploit this vulnerability to achieve Remote Code Execution in the context of the driver by tricking a victim into using a crafted connection URL that uses the property krbJAASFile.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49194" + }, + { + "type": "WEB", + "url": "https://kb.databricks.com/en_US/data-sources/security-bulletin-databricks-jdbc-driver-vulnerability-advisory-cve-2024-49194" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T20:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p299-jc9j-rfc4/GHSA-p299-jc9j-rfc4.json b/advisories/unreviewed/2024/12/GHSA-p299-jc9j-rfc4/GHSA-p299-jc9j-rfc4.json index 4299cb31c5b..fbd5873882d 100644 --- a/advisories/unreviewed/2024/12/GHSA-p299-jc9j-rfc4/GHSA-p299-jc9j-rfc4.json +++ b/advisories/unreviewed/2024/12/GHSA-p299-jc9j-rfc4/GHSA-p299-jc9j-rfc4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p299-jc9j-rfc4", - "modified": "2024-12-13T09:31:13Z", + "modified": "2024-12-17T21:30:34Z", "published": "2024-12-13T09:31:13Z", "aliases": [ "CVE-2024-55918" ], "details": "An issue was discovered in the Graphics::ColorNames package before 3.2.0 for Perl. There is an ambiguity between modules and filenames that can lead to HTML injection by an attacker who can create a file in the current working directory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-13T07:15:04Z" diff --git a/advisories/unreviewed/2024/12/GHSA-p4gh-942g-mc76/GHSA-p4gh-942g-mc76.json b/advisories/unreviewed/2024/12/GHSA-p4gh-942g-mc76/GHSA-p4gh-942g-mc76.json index d93bf0bbde8..897958db738 100644 --- a/advisories/unreviewed/2024/12/GHSA-p4gh-942g-mc76/GHSA-p4gh-942g-mc76.json +++ b/advisories/unreviewed/2024/12/GHSA-p4gh-942g-mc76/GHSA-p4gh-942g-mc76.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-335" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-p586-gwq2-42qx/GHSA-p586-gwq2-42qx.json b/advisories/unreviewed/2024/12/GHSA-p586-gwq2-42qx/GHSA-p586-gwq2-42qx.json new file mode 100644 index 00000000000..5bbb6c21d60 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p586-gwq2-42qx/GHSA-p586-gwq2-42qx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p586-gwq2-42qx", + "modified": "2024-12-17T21:30:34Z", + "published": "2024-12-17T21:30:34Z", + "aliases": [ + "CVE-2024-55515" + ], + "details": "A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_ipslib.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55515" + }, + { + "type": "WEB", + "url": "https://gist.github.com/wscg928/cbe88078751abad2ada2334eb12a5060" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T20:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p6j5-54wr-g5qj/GHSA-p6j5-54wr-g5qj.json b/advisories/unreviewed/2024/12/GHSA-p6j5-54wr-g5qj/GHSA-p6j5-54wr-g5qj.json new file mode 100644 index 00000000000..0fe2d8171be --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p6j5-54wr-g5qj/GHSA-p6j5-54wr-g5qj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6j5-54wr-g5qj", + "modified": "2024-12-17T21:30:34Z", + "published": "2024-12-17T21:30:34Z", + "aliases": [ + "CVE-2024-55516" + ], + "details": "A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 v3.90. The component affected by this issue is /upload_sysconfig.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded, potentially leading to unauthorized access to server permissions.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55516" + }, + { + "type": "WEB", + "url": "https://gist.github.com/wscg928/cbe88078751abad2ada2334eb12a5060" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T20:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-px56-8cj3-6h4p/GHSA-px56-8cj3-6h4p.json b/advisories/unreviewed/2024/12/GHSA-px56-8cj3-6h4p/GHSA-px56-8cj3-6h4p.json index ae271f17701..052cb6d5405 100644 --- a/advisories/unreviewed/2024/12/GHSA-px56-8cj3-6h4p/GHSA-px56-8cj3-6h4p.json +++ b/advisories/unreviewed/2024/12/GHSA-px56-8cj3-6h4p/GHSA-px56-8cj3-6h4p.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-w5m9-xcgh-j73w/GHSA-w5m9-xcgh-j73w.json b/advisories/unreviewed/2024/12/GHSA-w5m9-xcgh-j73w/GHSA-w5m9-xcgh-j73w.json new file mode 100644 index 00000000000..9640f5b1900 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w5m9-xcgh-j73w/GHSA-w5m9-xcgh-j73w.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w5m9-xcgh-j73w", + "modified": "2024-12-17T21:30:34Z", + "published": "2024-12-17T21:30:34Z", + "aliases": [ + "CVE-2024-55513" + ], + "details": "A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_netaction.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded, potentially leading to unauthorized access to server permissions.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55513" + }, + { + "type": "WEB", + "url": "https://gist.github.com/wscg928/cbe88078751abad2ada2334eb12a5060" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T20:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wv62-mc54-722c/GHSA-wv62-mc54-722c.json b/advisories/unreviewed/2024/12/GHSA-wv62-mc54-722c/GHSA-wv62-mc54-722c.json new file mode 100644 index 00000000000..618ba26b6b6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wv62-mc54-722c/GHSA-wv62-mc54-722c.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wv62-mc54-722c", + "modified": "2024-12-17T21:30:34Z", + "published": "2024-12-17T21:30:34Z", + "aliases": [ + "CVE-2024-55057" + ], + "details": "Phpgurukul Online Birth Certificate System 1.0 suffers from insufficient password requirements which can lead to unauthorized access to user accounts.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55057" + }, + { + "type": "WEB", + "url": "https://github.com/SCR-athif/CVE/tree/main/CVE-2024-55057" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T21:15:08Z" + } +} \ No newline at end of file