diff --git a/advisories/github-reviewed/2023/07/GHSA-353m-jh2m-72v4/GHSA-353m-jh2m-72v4.json b/advisories/github-reviewed/2023/07/GHSA-353m-jh2m-72v4/GHSA-353m-jh2m-72v4.json index 6bff1ee7f70..e7c132fe38f 100644 --- a/advisories/github-reviewed/2023/07/GHSA-353m-jh2m-72v4/GHSA-353m-jh2m-72v4.json +++ b/advisories/github-reviewed/2023/07/GHSA-353m-jh2m-72v4/GHSA-353m-jh2m-72v4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-353m-jh2m-72v4", - "modified": "2023-08-03T19:38:57Z", + "modified": "2024-09-05T16:59:18Z", "published": "2023-07-28T15:30:23Z", "aliases": [ "CVE-2023-39020" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "affected": [ @@ -28,7 +32,7 @@ "introduced": "0" }, { - "last_affected": "3.9.2" + "fixed": "4.5.5" } ] } @@ -40,6 +44,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39020" }, + { + "type": "WEB", + "url": "https://github.com/stanfordnlp/CoreNLP/commit/897231bed0efb24574c80c875c0b5f2225c145bc" + }, { "type": "WEB", "url": "https://github.com/LetianYuan/My-CVE-Public-References/tree/main/edu_stanford_nlp_stanford-parser" diff --git a/advisories/unreviewed/2022/05/GHSA-6mmp-f4p3-97mr/GHSA-6mmp-f4p3-97mr.json b/advisories/unreviewed/2022/05/GHSA-6mmp-f4p3-97mr/GHSA-6mmp-f4p3-97mr.json index da08ae149ac..cad12a7e42f 100644 --- a/advisories/unreviewed/2022/05/GHSA-6mmp-f4p3-97mr/GHSA-6mmp-f4p3-97mr.json +++ b/advisories/unreviewed/2022/05/GHSA-6mmp-f4p3-97mr/GHSA-6mmp-f4p3-97mr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6mmp-f4p3-97mr", - "modified": "2024-09-03T15:30:38Z", + "modified": "2024-09-05T18:30:45Z", "published": "2022-05-17T04:10:14Z", "aliases": [ "CVE-2013-6040" ], "details": "Multiple unspecified vulnerabilities in the MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls allow remote attackers to execute arbitrary code via a crafted HTML document.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/11/GHSA-22g7-wp2f-rmqf/GHSA-22g7-wp2f-rmqf.json b/advisories/unreviewed/2023/11/GHSA-22g7-wp2f-rmqf/GHSA-22g7-wp2f-rmqf.json index ed77881c4e6..62da86294b7 100644 --- a/advisories/unreviewed/2023/11/GHSA-22g7-wp2f-rmqf/GHSA-22g7-wp2f-rmqf.json +++ b/advisories/unreviewed/2023/11/GHSA-22g7-wp2f-rmqf/GHSA-22g7-wp2f-rmqf.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-37hj-qxxx-w7gw/GHSA-37hj-qxxx-w7gw.json b/advisories/unreviewed/2023/11/GHSA-37hj-qxxx-w7gw/GHSA-37hj-qxxx-w7gw.json index e0069dd73c9..9e98dc8b03d 100644 --- a/advisories/unreviewed/2023/11/GHSA-37hj-qxxx-w7gw/GHSA-37hj-qxxx-w7gw.json +++ b/advisories/unreviewed/2023/11/GHSA-37hj-qxxx-w7gw/GHSA-37hj-qxxx-w7gw.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-4mg4-2vjx-5ch2/GHSA-4mg4-2vjx-5ch2.json b/advisories/unreviewed/2023/11/GHSA-4mg4-2vjx-5ch2/GHSA-4mg4-2vjx-5ch2.json index a2a72c0691f..9dbd5c7cd8f 100644 --- a/advisories/unreviewed/2023/11/GHSA-4mg4-2vjx-5ch2/GHSA-4mg4-2vjx-5ch2.json +++ b/advisories/unreviewed/2023/11/GHSA-4mg4-2vjx-5ch2/GHSA-4mg4-2vjx-5ch2.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-59gh-4pp9-3287/GHSA-59gh-4pp9-3287.json b/advisories/unreviewed/2023/11/GHSA-59gh-4pp9-3287/GHSA-59gh-4pp9-3287.json index 47d7252a587..63332149774 100644 --- a/advisories/unreviewed/2023/11/GHSA-59gh-4pp9-3287/GHSA-59gh-4pp9-3287.json +++ b/advisories/unreviewed/2023/11/GHSA-59gh-4pp9-3287/GHSA-59gh-4pp9-3287.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-f28g-35vw-w6r8/GHSA-f28g-35vw-w6r8.json b/advisories/unreviewed/2023/11/GHSA-f28g-35vw-w6r8/GHSA-f28g-35vw-w6r8.json index 418c3fb41f2..13e3503d04e 100644 --- a/advisories/unreviewed/2023/11/GHSA-f28g-35vw-w6r8/GHSA-f28g-35vw-w6r8.json +++ b/advisories/unreviewed/2023/11/GHSA-f28g-35vw-w6r8/GHSA-f28g-35vw-w6r8.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-ffjm-jwpc-gc3f/GHSA-ffjm-jwpc-gc3f.json b/advisories/unreviewed/2023/11/GHSA-ffjm-jwpc-gc3f/GHSA-ffjm-jwpc-gc3f.json index 17d67033d25..abf45ce4cb6 100644 --- a/advisories/unreviewed/2023/11/GHSA-ffjm-jwpc-gc3f/GHSA-ffjm-jwpc-gc3f.json +++ b/advisories/unreviewed/2023/11/GHSA-ffjm-jwpc-gc3f/GHSA-ffjm-jwpc-gc3f.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-jhc6-x647-xmhf/GHSA-jhc6-x647-xmhf.json b/advisories/unreviewed/2023/11/GHSA-jhc6-x647-xmhf/GHSA-jhc6-x647-xmhf.json index 35088781db4..a37e3c7c74e 100644 --- a/advisories/unreviewed/2023/11/GHSA-jhc6-x647-xmhf/GHSA-jhc6-x647-xmhf.json +++ b/advisories/unreviewed/2023/11/GHSA-jhc6-x647-xmhf/GHSA-jhc6-x647-xmhf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jhc6-x647-xmhf", - "modified": "2023-11-14T18:30:20Z", + "modified": "2024-09-05T18:30:47Z", "published": "2023-11-03T06:36:29Z", "aliases": [ "CVE-2023-36620" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-jqrp-vr9m-25fh/GHSA-jqrp-vr9m-25fh.json b/advisories/unreviewed/2023/11/GHSA-jqrp-vr9m-25fh/GHSA-jqrp-vr9m-25fh.json index 3fc8635bb21..7d5c5d95105 100644 --- a/advisories/unreviewed/2023/11/GHSA-jqrp-vr9m-25fh/GHSA-jqrp-vr9m-25fh.json +++ b/advisories/unreviewed/2023/11/GHSA-jqrp-vr9m-25fh/GHSA-jqrp-vr9m-25fh.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-m7v7-jj45-j87q/GHSA-m7v7-jj45-j87q.json b/advisories/unreviewed/2023/11/GHSA-m7v7-jj45-j87q/GHSA-m7v7-jj45-j87q.json index 54b83b0dd50..a33073db3ad 100644 --- a/advisories/unreviewed/2023/11/GHSA-m7v7-jj45-j87q/GHSA-m7v7-jj45-j87q.json +++ b/advisories/unreviewed/2023/11/GHSA-m7v7-jj45-j87q/GHSA-m7v7-jj45-j87q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m7v7-jj45-j87q", - "modified": "2023-11-13T18:30:58Z", + "modified": "2024-09-05T18:30:46Z", "published": "2023-11-03T06:36:29Z", "aliases": [ "CVE-2023-34261" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-mh77-wx4j-rgjj/GHSA-mh77-wx4j-rgjj.json b/advisories/unreviewed/2023/11/GHSA-mh77-wx4j-rgjj/GHSA-mh77-wx4j-rgjj.json index 8e51fca47db..ca54b1ed2b4 100644 --- a/advisories/unreviewed/2023/11/GHSA-mh77-wx4j-rgjj/GHSA-mh77-wx4j-rgjj.json +++ b/advisories/unreviewed/2023/11/GHSA-mh77-wx4j-rgjj/GHSA-mh77-wx4j-rgjj.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-mvvm-c9r9-4wx8/GHSA-mvvm-c9r9-4wx8.json b/advisories/unreviewed/2023/11/GHSA-mvvm-c9r9-4wx8/GHSA-mvvm-c9r9-4wx8.json index 6497dd2903b..a613e3d057f 100644 --- a/advisories/unreviewed/2023/11/GHSA-mvvm-c9r9-4wx8/GHSA-mvvm-c9r9-4wx8.json +++ b/advisories/unreviewed/2023/11/GHSA-mvvm-c9r9-4wx8/GHSA-mvvm-c9r9-4wx8.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-q8x9-r7fc-qfjv/GHSA-q8x9-r7fc-qfjv.json b/advisories/unreviewed/2023/11/GHSA-q8x9-r7fc-qfjv/GHSA-q8x9-r7fc-qfjv.json index faa621de52b..179e8788e44 100644 --- a/advisories/unreviewed/2023/11/GHSA-q8x9-r7fc-qfjv/GHSA-q8x9-r7fc-qfjv.json +++ b/advisories/unreviewed/2023/11/GHSA-q8x9-r7fc-qfjv/GHSA-q8x9-r7fc-qfjv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q8x9-r7fc-qfjv", - "modified": "2023-11-13T21:30:57Z", + "modified": "2024-09-05T18:30:48Z", "published": "2023-11-13T21:30:57Z", "aliases": [ "CVE-2023-47102" diff --git a/advisories/unreviewed/2023/11/GHSA-qv8f-pvcv-2mmv/GHSA-qv8f-pvcv-2mmv.json b/advisories/unreviewed/2023/11/GHSA-qv8f-pvcv-2mmv/GHSA-qv8f-pvcv-2mmv.json index 46e44bcce65..fe7fd2b311b 100644 --- a/advisories/unreviewed/2023/11/GHSA-qv8f-pvcv-2mmv/GHSA-qv8f-pvcv-2mmv.json +++ b/advisories/unreviewed/2023/11/GHSA-qv8f-pvcv-2mmv/GHSA-qv8f-pvcv-2mmv.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-v9wr-p4fq-7wqh/GHSA-v9wr-p4fq-7wqh.json b/advisories/unreviewed/2023/11/GHSA-v9wr-p4fq-7wqh/GHSA-v9wr-p4fq-7wqh.json index 944cb3b5a42..9d570e34da9 100644 --- a/advisories/unreviewed/2023/11/GHSA-v9wr-p4fq-7wqh/GHSA-v9wr-p4fq-7wqh.json +++ b/advisories/unreviewed/2023/11/GHSA-v9wr-p4fq-7wqh/GHSA-v9wr-p4fq-7wqh.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-w2c3-h72m-ch9w/GHSA-w2c3-h72m-ch9w.json b/advisories/unreviewed/2023/11/GHSA-w2c3-h72m-ch9w/GHSA-w2c3-h72m-ch9w.json index 6c4a53baac3..05339b2bf2f 100644 --- a/advisories/unreviewed/2023/11/GHSA-w2c3-h72m-ch9w/GHSA-w2c3-h72m-ch9w.json +++ b/advisories/unreviewed/2023/11/GHSA-w2c3-h72m-ch9w/GHSA-w2c3-h72m-ch9w.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-q4rc-j4h5-9m6h/GHSA-q4rc-j4h5-9m6h.json b/advisories/unreviewed/2024/06/GHSA-q4rc-j4h5-9m6h/GHSA-q4rc-j4h5-9m6h.json index 00f59fc26d8..d4ef48f947d 100644 --- a/advisories/unreviewed/2024/06/GHSA-q4rc-j4h5-9m6h/GHSA-q4rc-j4h5-9m6h.json +++ b/advisories/unreviewed/2024/06/GHSA-q4rc-j4h5-9m6h/GHSA-q4rc-j4h5-9m6h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q4rc-j4h5-9m6h", - "modified": "2024-06-13T18:31:58Z", + "modified": "2024-09-05T18:30:49Z", "published": "2024-06-13T18:31:58Z", "aliases": [ "CVE-2024-22441" ], "details": "HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T16:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-rmff-fqq9-pc3q/GHSA-rmff-fqq9-pc3q.json b/advisories/unreviewed/2024/06/GHSA-rmff-fqq9-pc3q/GHSA-rmff-fqq9-pc3q.json index 8f3957b1ebe..869eb9fcfd9 100644 --- a/advisories/unreviewed/2024/06/GHSA-rmff-fqq9-pc3q/GHSA-rmff-fqq9-pc3q.json +++ b/advisories/unreviewed/2024/06/GHSA-rmff-fqq9-pc3q/GHSA-rmff-fqq9-pc3q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rmff-fqq9-pc3q", - "modified": "2024-06-16T15:30:44Z", + "modified": "2024-09-05T18:30:49Z", "published": "2024-06-10T15:31:02Z", "aliases": [ "CVE-2024-36972" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\naf_unix: Update unix_sk(sk)->oob_skb under sk_receive_queue lock.\n\nBilly Jheng Bing-Jhong reported a race between __unix_gc() and\nqueue_oob().\n\n__unix_gc() tries to garbage-collect close()d inflight sockets,\nand then if the socket has MSG_OOB in unix_sk(sk)->oob_skb, GC\nwill drop the reference and set NULL to it locklessly.\n\nHowever, the peer socket still can send MSG_OOB message and\nqueue_oob() can update unix_sk(sk)->oob_skb concurrently, leading\nNULL pointer dereference. [0]\n\nTo fix the issue, let's update unix_sk(sk)->oob_skb under the\nsk_receive_queue's lock and take it everywhere we touch oob_skb.\n\nNote that we defer kfree_skb() in manage_oob() to silence lockdep\nfalse-positive (See [1]).\n\n[0]:\nBUG: kernel NULL pointer dereference, address: 0000000000000008\n PF: supervisor write access in kernel mode\n PF: error_code(0x0002) - not-present page\nPGD 8000000009f5e067 P4D 8000000009f5e067 PUD 9f5d067 PMD 0\nOops: 0002 [#1] PREEMPT SMP PTI\nCPU: 3 PID: 50 Comm: kworker/3:1 Not tainted 6.9.0-rc5-00191-gd091e579b864 #110\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014\nWorkqueue: events delayed_fput\nRIP: 0010:skb_dequeue (./include/linux/skbuff.h:2386 ./include/linux/skbuff.h:2402 net/core/skbuff.c:3847)\nCode: 39 e3 74 3e 8b 43 10 48 89 ef 83 e8 01 89 43 10 49 8b 44 24 08 49 c7 44 24 08 00 00 00 00 49 8b 14 24 49 c7 04 24 00 00 00 00 <48> 89 42 08 48 89 10 e8 e7 c5 42 00 4c 89 e0 5b 5d 41 5c c3 cc cc\nRSP: 0018:ffffc900001bfd48 EFLAGS: 00000002\nRAX: 0000000000000000 RBX: ffff8880088f5ae8 RCX: 00000000361289f9\nRDX: 0000000000000000 RSI: 0000000000000206 RDI: ffff8880088f5b00\nRBP: ffff8880088f5b00 R08: 0000000000080000 R09: 0000000000000001\nR10: 0000000000000003 R11: 0000000000000001 R12: ffff8880056b6a00\nR13: ffff8880088f5280 R14: 0000000000000001 R15: ffff8880088f5a80\nFS: 0000000000000000(0000) GS:ffff88807dd80000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000008 CR3: 0000000006314000 CR4: 00000000007506f0\nPKRU: 55555554\nCall Trace:\n \n unix_release_sock (net/unix/af_unix.c:654)\n unix_release (net/unix/af_unix.c:1050)\n __sock_release (net/socket.c:660)\n sock_close (net/socket.c:1423)\n __fput (fs/file_table.c:423)\n delayed_fput (fs/file_table.c:444 (discriminator 3))\n process_one_work (kernel/workqueue.c:3259)\n worker_thread (kernel/workqueue.c:3329 kernel/workqueue.c:3416)\n kthread (kernel/kthread.c:388)\n ret_from_fork (arch/x86/kernel/process.c:153)\n ret_from_fork_asm (arch/x86/entry/entry_64.S:257)\n \nModules linked in:\nCR2: 0000000000000008", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ "CWE-476" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T15:15:52Z" diff --git a/advisories/unreviewed/2024/07/GHSA-56xm-5973-mjq5/GHSA-56xm-5973-mjq5.json b/advisories/unreviewed/2024/07/GHSA-56xm-5973-mjq5/GHSA-56xm-5973-mjq5.json index 2525369a9c0..e2ea24fcdab 100644 --- a/advisories/unreviewed/2024/07/GHSA-56xm-5973-mjq5/GHSA-56xm-5973-mjq5.json +++ b/advisories/unreviewed/2024/07/GHSA-56xm-5973-mjq5/GHSA-56xm-5973-mjq5.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-56xm-5973-mjq5", - "modified": "2024-07-10T21:30:39Z", + "modified": "2024-09-05T18:30:49Z", "published": "2024-07-10T21:30:39Z", "aliases": [ "CVE-2024-6148" ], "details": "Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/07/GHSA-8ghr-4wgh-3jq8/GHSA-8ghr-4wgh-3jq8.json b/advisories/unreviewed/2024/07/GHSA-8ghr-4wgh-3jq8/GHSA-8ghr-4wgh-3jq8.json index b5347ed37d9..78079816b97 100644 --- a/advisories/unreviewed/2024/07/GHSA-8ghr-4wgh-3jq8/GHSA-8ghr-4wgh-3jq8.json +++ b/advisories/unreviewed/2024/07/GHSA-8ghr-4wgh-3jq8/GHSA-8ghr-4wgh-3jq8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8ghr-4wgh-3jq8", - "modified": "2024-07-29T18:30:39Z", + "modified": "2024-09-05T18:30:50Z", "published": "2024-07-29T18:30:39Z", "aliases": [ "CVE-2024-42063" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Mark bpf prog stack with kmsan_unposion_memory in interpreter mode\n\nsyzbot reported uninit memory usages during map_{lookup,delete}_elem.\n\n==========\nBUG: KMSAN: uninit-value in __dev_map_lookup_elem kernel/bpf/devmap.c:441 [inline]\nBUG: KMSAN: uninit-value in dev_map_lookup_elem+0xf3/0x170 kernel/bpf/devmap.c:796\n__dev_map_lookup_elem kernel/bpf/devmap.c:441 [inline]\ndev_map_lookup_elem+0xf3/0x170 kernel/bpf/devmap.c:796\n____bpf_map_lookup_elem kernel/bpf/helpers.c:42 [inline]\nbpf_map_lookup_elem+0x5c/0x80 kernel/bpf/helpers.c:38\n___bpf_prog_run+0x13fe/0xe0f0 kernel/bpf/core.c:1997\n__bpf_prog_run256+0xb5/0xe0 kernel/bpf/core.c:2237\n==========\n\nThe reproducer should be in the interpreter mode.\n\nThe C reproducer is trying to run the following bpf prog:\n\n 0: (18) r0 = 0x0\n 2: (18) r1 = map[id:49]\n 4: (b7) r8 = 16777216\n 5: (7b) *(u64 *)(r10 -8) = r8\n 6: (bf) r2 = r10\n 7: (07) r2 += -229\n ^^^^^^^^^^\n\n 8: (b7) r3 = 8\n 9: (b7) r4 = 0\n 10: (85) call dev_map_lookup_elem#1543472\n 11: (95) exit\n\nIt is due to the \"void *key\" (r2) passed to the helper. bpf allows uninit\nstack memory access for bpf prog with the right privileges. This patch\nuses kmsan_unpoison_memory() to mark the stack as initialized.\n\nThis should address different syzbot reports on the uninit \"void *key\"\nargument during map_{lookup,delete}_elem.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-908" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:06Z" diff --git a/advisories/unreviewed/2024/07/GHSA-jch8-q42m-ghhr/GHSA-jch8-q42m-ghhr.json b/advisories/unreviewed/2024/07/GHSA-jch8-q42m-ghhr/GHSA-jch8-q42m-ghhr.json index 196890d43d1..bee49652cd2 100644 --- a/advisories/unreviewed/2024/07/GHSA-jch8-q42m-ghhr/GHSA-jch8-q42m-ghhr.json +++ b/advisories/unreviewed/2024/07/GHSA-jch8-q42m-ghhr/GHSA-jch8-q42m-ghhr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jch8-q42m-ghhr", - "modified": "2024-07-23T00:31:46Z", + "modified": "2024-09-05T18:30:49Z", "published": "2024-07-23T00:31:46Z", "aliases": [ "CVE-2024-24507" ], "details": "Cross Site Scripting vulnerability in Act-On 2023 allows a remote attacker to execute arbitrary code via the newUser parameter in the login.jsp component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-22T22:15:02Z" diff --git a/advisories/unreviewed/2024/07/GHSA-m6fq-wgpr-hqx9/GHSA-m6fq-wgpr-hqx9.json b/advisories/unreviewed/2024/07/GHSA-m6fq-wgpr-hqx9/GHSA-m6fq-wgpr-hqx9.json index 469ca5d66c6..899344c2562 100644 --- a/advisories/unreviewed/2024/07/GHSA-m6fq-wgpr-hqx9/GHSA-m6fq-wgpr-hqx9.json +++ b/advisories/unreviewed/2024/07/GHSA-m6fq-wgpr-hqx9/GHSA-m6fq-wgpr-hqx9.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-q54v-7fv8-p57r/GHSA-q54v-7fv8-p57r.json b/advisories/unreviewed/2024/07/GHSA-q54v-7fv8-p57r/GHSA-q54v-7fv8-p57r.json index 946c5d003f2..bf7b42a43aa 100644 --- a/advisories/unreviewed/2024/07/GHSA-q54v-7fv8-p57r/GHSA-q54v-7fv8-p57r.json +++ b/advisories/unreviewed/2024/07/GHSA-q54v-7fv8-p57r/GHSA-q54v-7fv8-p57r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q54v-7fv8-p57r", - "modified": "2024-07-30T09:32:02Z", + "modified": "2024-09-05T18:30:50Z", "published": "2024-07-30T09:32:02Z", "aliases": [ "CVE-2024-42148" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbnx2x: Fix multiple UBSAN array-index-out-of-bounds\n\nFix UBSAN warnings that occur when using a system with 32 physical\ncpu cores or more, or when the user defines a number of Ethernet\nqueues greater than or equal to FP_SB_MAX_E1x using the num_queues\nmodule parameter.\n\nCurrently there is a read/write out of bounds that occurs on the array\n\"struct stats_query_entry query\" present inside the \"bnx2x_fw_stats_req\"\nstruct in \"drivers/net/ethernet/broadcom/bnx2x/bnx2x.h\".\nLooking at the definition of the \"struct stats_query_entry query\" array:\n\nstruct stats_query_entry query[FP_SB_MAX_E1x+\n BNX2X_FIRST_QUEUE_QUERY_IDX];\n\nFP_SB_MAX_E1x is defined as the maximum number of fast path interrupts and\nhas a value of 16, while BNX2X_FIRST_QUEUE_QUERY_IDX has a value of 3\nmeaning the array has a total size of 19.\nSince accesses to \"struct stats_query_entry query\" are offset-ted by\nBNX2X_FIRST_QUEUE_QUERY_IDX, that means that the total number of Ethernet\nqueues should not exceed FP_SB_MAX_E1x (16). However one of these queues\nis reserved for FCOE and thus the number of Ethernet queues should be set\nto [FP_SB_MAX_E1x -1] (15) if FCOE is enabled or [FP_SB_MAX_E1x] (16) if\nit is not.\n\nThis is also described in a comment in the source code in\ndrivers/net/ethernet/broadcom/bnx2x/bnx2x.h just above the Macro definition\nof FP_SB_MAX_E1x. Below is the part of this explanation that it important\nfor this patch\n\n/*\n * The total number of L2 queues, MSIX vectors and HW contexts (CIDs) is\n * control by the number of fast-path status blocks supported by the\n * device (HW/FW). Each fast-path status block (FP-SB) aka non-default\n * status block represents an independent interrupts context that can\n * serve a regular L2 networking queue. However special L2 queues such\n * as the FCoE queue do not require a FP-SB and other components like\n * the CNIC may consume FP-SB reducing the number of possible L2 queues\n *\n * If the maximum number of FP-SB available is X then:\n * a. If CNIC is supported it consumes 1 FP-SB thus the max number of\n * regular L2 queues is Y=X-1\n * b. In MF mode the actual number of L2 queues is Y= (X-1/MF_factor)\n * c. If the FCoE L2 queue is supported the actual number of L2 queues\n * is Y+1\n * d. The number of irqs (MSIX vectors) is either Y+1 (one extra for\n * slow-path interrupts) or Y+2 if CNIC is supported (one additional\n * FP interrupt context for the CNIC).\n * e. The number of HW context (CID count) is always X or X+1 if FCoE\n * L2 queue is supported. The cid for the FCoE L2 queue is always X.\n */\n\nHowever this driver also supports NICs that use the E2 controller which can\nhandle more queues due to having more FP-SB represented by FP_SB_MAX_E2.\nLooking at the commits when the E2 support was added, it was originally\nusing the E1x parameters: commit f2e0899f0f27 (\"bnx2x: Add 57712 support\").\nBack then FP_SB_MAX_E2 was set to 16 the same as E1x. However the driver\nwas later updated to take full advantage of the E2 instead of having it be\nlimited to the capabilities of the E1x. But as far as we can tell, the\narray \"stats_query_entry query\" was still limited to using the FP-SB\navailable to the E1x cards as part of an oversignt when the driver was\nupdated to take full advantage of the E2, and now with the driver being\naware of the greater queue size supported by E2 NICs, it causes the UBSAN\nwarnings seen in the stack traces below.\n\nThis patch increases the size of the \"stats_query_entry query\" array by\nreplacing FP_SB_MAX_E1x with FP_SB_MAX_E2 to be large enough to handle\nboth types of NICs.\n\nStack traces:\n\nUBSAN: array-index-out-of-bounds in\n drivers/net/ethernet/broadcom/bnx2x/bnx2x_stats.c:1529:11\nindex 20 is out of range for type 'stats_query_entry [19]'\nCPU: 12 PID: 858 Comm: systemd-network Not tainted 6.9.0-060900rc7-generic\n\t #202405052133\nHardware name: HP ProLiant DL360 Gen9/ProLiant DL360 \n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-129" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-3g58-rjqp-pmgh/GHSA-3g58-rjqp-pmgh.json b/advisories/unreviewed/2024/08/GHSA-3g58-rjqp-pmgh/GHSA-3g58-rjqp-pmgh.json index f619d2fa6e8..0702c76d31d 100644 --- a/advisories/unreviewed/2024/08/GHSA-3g58-rjqp-pmgh/GHSA-3g58-rjqp-pmgh.json +++ b/advisories/unreviewed/2024/08/GHSA-3g58-rjqp-pmgh/GHSA-3g58-rjqp-pmgh.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-79" + "CWE-79", + "CWE-89" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-3h49-76hw-pv6f/GHSA-3h49-76hw-pv6f.json b/advisories/unreviewed/2024/08/GHSA-3h49-76hw-pv6f/GHSA-3h49-76hw-pv6f.json index 5850ab2095a..9a1e40289fa 100644 --- a/advisories/unreviewed/2024/08/GHSA-3h49-76hw-pv6f/GHSA-3h49-76hw-pv6f.json +++ b/advisories/unreviewed/2024/08/GHSA-3h49-76hw-pv6f/GHSA-3h49-76hw-pv6f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3h49-76hw-pv6f", - "modified": "2024-08-17T09:30:25Z", + "modified": "2024-09-05T18:30:51Z", "published": "2024-08-17T09:30:25Z", "aliases": [ "CVE-2024-42307" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: fix potential null pointer use in destroy_workqueue in init_cifs error path\n\nDan Carpenter reported a Smack static checker warning:\n fs/smb/client/cifsfs.c:1981 init_cifs()\n error: we previously assumed 'serverclose_wq' could be null (see line 1895)\n\nThe patch which introduced the serverclose workqueue used the wrong\noredering in error paths in init_cifs() for freeing it on errors.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-17T09:15:10Z" diff --git a/advisories/unreviewed/2024/08/GHSA-5469-6p3j-2hpr/GHSA-5469-6p3j-2hpr.json b/advisories/unreviewed/2024/08/GHSA-5469-6p3j-2hpr/GHSA-5469-6p3j-2hpr.json index 71505e03e92..e2521f46d51 100644 --- a/advisories/unreviewed/2024/08/GHSA-5469-6p3j-2hpr/GHSA-5469-6p3j-2hpr.json +++ b/advisories/unreviewed/2024/08/GHSA-5469-6p3j-2hpr/GHSA-5469-6p3j-2hpr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5469-6p3j-2hpr", - "modified": "2024-08-26T12:31:20Z", + "modified": "2024-09-05T18:30:51Z", "published": "2024-08-26T12:31:20Z", "aliases": [ "CVE-2024-43910" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: add missing check_func_arg_reg_off() to prevent out-of-bounds memory accesses\n\nCurrently, it's possible to pass in a modified CONST_PTR_TO_DYNPTR to\na global function as an argument. The adverse effects of this is that\nBPF helpers can continue to make use of this modified\nCONST_PTR_TO_DYNPTR from within the context of the global function,\nwhich can unintentionally result in out-of-bounds memory accesses and\ntherefore compromise overall system stability i.e.\n\n[ 244.157771] BUG: KASAN: slab-out-of-bounds in bpf_dynptr_data+0x137/0x140\n[ 244.161345] Read of size 8 at addr ffff88810914be68 by task test_progs/302\n[ 244.167151] CPU: 0 PID: 302 Comm: test_progs Tainted: G O E 6.10.0-rc3-00131-g66b586715063 #533\n[ 244.174318] Call Trace:\n[ 244.175787] \n[ 244.177356] dump_stack_lvl+0x66/0xa0\n[ 244.179531] print_report+0xce/0x670\n[ 244.182314] ? __virt_addr_valid+0x200/0x3e0\n[ 244.184908] kasan_report+0xd7/0x110\n[ 244.187408] ? bpf_dynptr_data+0x137/0x140\n[ 244.189714] ? bpf_dynptr_data+0x137/0x140\n[ 244.192020] bpf_dynptr_data+0x137/0x140\n[ 244.194264] bpf_prog_b02a02fdd2bdc5fa_global_call_bpf_dynptr_data+0x22/0x26\n[ 244.198044] bpf_prog_b0fe7b9d7dc3abde_callback_adjust_bpf_dynptr_reg_off+0x1f/0x23\n[ 244.202136] bpf_user_ringbuf_drain+0x2c7/0x570\n[ 244.204744] ? 0xffffffffc0009e58\n[ 244.206593] ? __pfx_bpf_user_ringbuf_drain+0x10/0x10\n[ 244.209795] bpf_prog_33ab33f6a804ba2d_user_ringbuf_callback_const_ptr_to_dynptr_reg_off+0x47/0x4b\n[ 244.215922] bpf_trampoline_6442502480+0x43/0xe3\n[ 244.218691] __x64_sys_prlimit64+0x9/0xf0\n[ 244.220912] do_syscall_64+0xc1/0x1d0\n[ 244.223043] entry_SYSCALL_64_after_hwframe+0x77/0x7f\n[ 244.226458] RIP: 0033:0x7ffa3eb8f059\n[ 244.228582] Code: 08 89 e8 5b 5d c3 66 2e 0f 1f 84 00 00 00 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d 8f 1d 0d 00 f7 d8 64 89 01 48\n[ 244.241307] RSP: 002b:00007ffa3e9c6eb8 EFLAGS: 00000206 ORIG_RAX: 000000000000012e\n[ 244.246474] RAX: ffffffffffffffda RBX: 00007ffa3e9c7cdc RCX: 00007ffa3eb8f059\n[ 244.250478] RDX: 00007ffa3eb162b4 RSI: 0000000000000000 RDI: 00007ffa3e9c7fb0\n[ 244.255396] RBP: 00007ffa3e9c6ed0 R08: 00007ffa3e9c76c0 R09: 0000000000000000\n[ 244.260195] R10: 0000000000000000 R11: 0000000000000206 R12: ffffffffffffff80\n[ 244.264201] R13: 000000000000001c R14: 00007ffc5d6b4260 R15: 00007ffa3e1c7000\n[ 244.268303] \n\nAdd a check_func_arg_reg_off() to the path in which the BPF verifier\nverifies the arguments of global function arguments, specifically\nthose which take an argument of type ARG_PTR_TO_DYNPTR |\nMEM_RDONLY. Also, process_dynptr_func() doesn't appear to perform any\nexplicit and strict type matching on the supplied register type, so\nlet's also enforce that a register either type PTR_TO_STACK or\nCONST_PTR_TO_DYNPTR is by the caller.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T11:15:05Z" diff --git a/advisories/unreviewed/2024/08/GHSA-7846-q6xx-g33p/GHSA-7846-q6xx-g33p.json b/advisories/unreviewed/2024/08/GHSA-7846-q6xx-g33p/GHSA-7846-q6xx-g33p.json index bd1d6c213bc..b25f00b4030 100644 --- a/advisories/unreviewed/2024/08/GHSA-7846-q6xx-g33p/GHSA-7846-q6xx-g33p.json +++ b/advisories/unreviewed/2024/08/GHSA-7846-q6xx-g33p/GHSA-7846-q6xx-g33p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7846-q6xx-g33p", - "modified": "2024-08-26T12:31:20Z", + "modified": "2024-09-05T18:30:51Z", "published": "2024-08-26T12:31:20Z", "aliases": [ "CVE-2024-44936" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: rt5033: Bring back i2c_set_clientdata\n\nCommit 3a93da231c12 (\"power: supply: rt5033: Use devm_power_supply_register() helper\")\nreworked the driver to use devm. While at it, the i2c_set_clientdata\nwas dropped along with the remove callback. Unfortunately other parts\nof the driver also rely on i2c clientdata so this causes kernel oops.\n\nBring the call back to fix the driver.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T11:15:05Z" diff --git a/advisories/unreviewed/2024/08/GHSA-cxw8-j5f9-53mh/GHSA-cxw8-j5f9-53mh.json b/advisories/unreviewed/2024/08/GHSA-cxw8-j5f9-53mh/GHSA-cxw8-j5f9-53mh.json index b21bd61d46e..386a90b89db 100644 --- a/advisories/unreviewed/2024/08/GHSA-cxw8-j5f9-53mh/GHSA-cxw8-j5f9-53mh.json +++ b/advisories/unreviewed/2024/08/GHSA-cxw8-j5f9-53mh/GHSA-cxw8-j5f9-53mh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cxw8-j5f9-53mh", - "modified": "2024-08-26T12:31:20Z", + "modified": "2024-09-05T18:30:51Z", "published": "2024-08-26T12:31:20Z", "aliases": [ "CVE-2024-44931" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: prevent potential speculation leaks in gpio_device_get_desc()\n\nUserspace may trigger a speculative read of an address outside the gpio\ndescriptor array.\nUsers can do that by calling gpio_ioctl() with an offset out of range.\nOffset is copied from user and then used as an array index to get\nthe gpio descriptor without sanitization in gpio_device_get_desc().\n\nThis change ensures that the offset is sanitized by using\narray_index_nospec() to mitigate any possibility of speculative\ninformation leaks.\n\nThis bug was discovered and resolved using Coverity Static Analysis\nSecurity Testing (SAST) by Synopsys, Inc.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T11:15:05Z" diff --git a/advisories/unreviewed/2024/08/GHSA-f2c4-x7qx-mc68/GHSA-f2c4-x7qx-mc68.json b/advisories/unreviewed/2024/08/GHSA-f2c4-x7qx-mc68/GHSA-f2c4-x7qx-mc68.json index 9907953a45b..0528a46fa1e 100644 --- a/advisories/unreviewed/2024/08/GHSA-f2c4-x7qx-mc68/GHSA-f2c4-x7qx-mc68.json +++ b/advisories/unreviewed/2024/08/GHSA-f2c4-x7qx-mc68/GHSA-f2c4-x7qx-mc68.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f2c4-x7qx-mc68", - "modified": "2024-08-21T09:31:31Z", + "modified": "2024-09-05T18:30:51Z", "published": "2024-08-21T09:31:31Z", "aliases": [ "CVE-2022-48877" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: let's avoid panic if extent_tree is not created\n\nThis patch avoids the below panic.\n\npc : __lookup_extent_tree+0xd8/0x760\nlr : f2fs_do_write_data_page+0x104/0x87c\nsp : ffffffc010cbb3c0\nx29: ffffffc010cbb3e0 x28: 0000000000000000\nx27: ffffff8803e7f020 x26: ffffff8803e7ed40\nx25: ffffff8803e7f020 x24: ffffffc010cbb460\nx23: ffffffc010cbb480 x22: 0000000000000000\nx21: 0000000000000000 x20: ffffffff22e90900\nx19: 0000000000000000 x18: ffffffc010c5d080\nx17: 0000000000000000 x16: 0000000000000020\nx15: ffffffdb1acdbb88 x14: ffffff888759e2b0\nx13: 0000000000000000 x12: ffffff802da49000\nx11: 000000000a001200 x10: ffffff8803e7ed40\nx9 : ffffff8023195800 x8 : ffffff802da49078\nx7 : 0000000000000001 x6 : 0000000000000000\nx5 : 0000000000000006 x4 : ffffffc010cbba28\nx3 : 0000000000000000 x2 : ffffffc010cbb480\nx1 : 0000000000000000 x0 : ffffff8803e7ed40\nCall trace:\n __lookup_extent_tree+0xd8/0x760\n f2fs_do_write_data_page+0x104/0x87c\n f2fs_write_single_data_page+0x420/0xb60\n f2fs_write_cache_pages+0x418/0xb1c\n __f2fs_write_data_pages+0x428/0x58c\n f2fs_write_data_pages+0x30/0x40\n do_writepages+0x88/0x190\n __writeback_single_inode+0x48/0x448\n writeback_sb_inodes+0x468/0x9e8\n __writeback_inodes_wb+0xb8/0x2a4\n wb_writeback+0x33c/0x740\n wb_do_writeback+0x2b4/0x400\n wb_workfn+0xe4/0x34c\n process_one_work+0x24c/0x5bc\n worker_thread+0x3e8/0xa50\n kthread+0x150/0x1b4", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-21T07:15:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-h2xr-f73x-x5xm/GHSA-h2xr-f73x-x5xm.json b/advisories/unreviewed/2024/08/GHSA-h2xr-f73x-x5xm/GHSA-h2xr-f73x-x5xm.json index a102adb769f..9fd80ae7d25 100644 --- a/advisories/unreviewed/2024/08/GHSA-h2xr-f73x-x5xm/GHSA-h2xr-f73x-x5xm.json +++ b/advisories/unreviewed/2024/08/GHSA-h2xr-f73x-x5xm/GHSA-h2xr-f73x-x5xm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h2xr-f73x-x5xm", - "modified": "2024-08-26T21:30:33Z", + "modified": "2024-09-05T18:30:51Z", "published": "2024-08-26T21:30:33Z", "aliases": [ "CVE-2024-28077" ], "details": "A denial-of-service issue was discovered on certain GL-iNet devices. Some websites can detect devices exposed to the external network through DDNS, and consequently obtain the IP addresses and ports of devices that are exposed. By using special usernames and special characters (such as half parentheses or square brackets), one can call the login interface and cause the session-management program to crash, resulting in customers being unable to log into their devices. This affects MT6000 4.5.6, XE3000 4.4.5, X3000 4.4.6, MT3000 4.5.0, MT2500 4.5.0, AXT1800 4.5.0, AX1800 4.5.0, A1300 4.5.0, S200 4.1.4-0300, X750 4.3.7, SFT1200 4.3.7, MT1300 4.3.10, AR750 4.3.10, AR750S 4.3.10, AR300M 4.3.10, AR300M16 4.3.10, B1300 4.3.10, MT300N-V2 4.3.10, and XE300 4.3.16.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T20:15:07Z" diff --git a/advisories/unreviewed/2024/08/GHSA-j2jm-9cr2-x48x/GHSA-j2jm-9cr2-x48x.json b/advisories/unreviewed/2024/08/GHSA-j2jm-9cr2-x48x/GHSA-j2jm-9cr2-x48x.json index 89618b62930..43c0b66cf04 100644 --- a/advisories/unreviewed/2024/08/GHSA-j2jm-9cr2-x48x/GHSA-j2jm-9cr2-x48x.json +++ b/advisories/unreviewed/2024/08/GHSA-j2jm-9cr2-x48x/GHSA-j2jm-9cr2-x48x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j2jm-9cr2-x48x", - "modified": "2024-08-26T12:31:20Z", + "modified": "2024-09-05T18:30:51Z", "published": "2024-08-26T12:31:20Z", "aliases": [ "CVE-2024-43914" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid5: avoid BUG_ON() while continue reshape after reassembling\n\nCurrently, mdadm support --revert-reshape to abort the reshape while\nreassembling, as the test 07revert-grow. However, following BUG_ON()\ncan be triggerred by the test:\n\nkernel BUG at drivers/md/raid5.c:6278!\ninvalid opcode: 0000 [#1] PREEMPT SMP PTI\nirq event stamp: 158985\nCPU: 6 PID: 891 Comm: md0_reshape Not tainted 6.9.0-03335-g7592a0b0049a #94\nRIP: 0010:reshape_request+0x3f1/0xe60\nCall Trace:\n \n raid5_sync_request+0x43d/0x550\n md_do_sync+0xb7a/0x2110\n md_thread+0x294/0x2b0\n kthread+0x147/0x1c0\n ret_from_fork+0x59/0x70\n ret_from_fork_asm+0x1a/0x30\n \n\nRoot cause is that --revert-reshape update the raid_disks from 5 to 4,\nwhile reshape position is still set, and after reassembling the array,\nreshape position will be read from super block, then during reshape the\nchecking of 'writepos' that is caculated by old reshape position will\nfail.\n\nFix this panic the easy way first, by converting the BUG_ON() to\nWARN_ON(), and stop the reshape if checkings fail.\n\nNoted that mdadm must fix --revert-shape as well, and probably md/raid\nshould enhance metadata validation as well, however this means\nreassemble will fail and there must be user tools to fix the wrong\nmetadata.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T11:15:05Z" diff --git a/advisories/unreviewed/2024/08/GHSA-j57w-4p34-g57x/GHSA-j57w-4p34-g57x.json b/advisories/unreviewed/2024/08/GHSA-j57w-4p34-g57x/GHSA-j57w-4p34-g57x.json index 3ae8dd0b26a..79c84b6a155 100644 --- a/advisories/unreviewed/2024/08/GHSA-j57w-4p34-g57x/GHSA-j57w-4p34-g57x.json +++ b/advisories/unreviewed/2024/08/GHSA-j57w-4p34-g57x/GHSA-j57w-4p34-g57x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j57w-4p34-g57x", - "modified": "2024-08-26T12:31:20Z", + "modified": "2024-09-05T18:30:51Z", "published": "2024-08-26T12:31:20Z", "aliases": [ "CVE-2024-43912" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: nl80211: disallow setting special AP channel widths\n\nSetting the AP channel width is meant for use with the normal\n20/40/... MHz channel width progression, and switching around\nin S1G or narrow channels isn't supported. Disallow that.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T11:15:05Z" diff --git a/advisories/unreviewed/2024/08/GHSA-qw8c-gxp5-84j6/GHSA-qw8c-gxp5-84j6.json b/advisories/unreviewed/2024/08/GHSA-qw8c-gxp5-84j6/GHSA-qw8c-gxp5-84j6.json index 04f5e4045c0..6fbb751dca2 100644 --- a/advisories/unreviewed/2024/08/GHSA-qw8c-gxp5-84j6/GHSA-qw8c-gxp5-84j6.json +++ b/advisories/unreviewed/2024/08/GHSA-qw8c-gxp5-84j6/GHSA-qw8c-gxp5-84j6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qw8c-gxp5-84j6", - "modified": "2024-08-19T06:30:53Z", + "modified": "2024-09-05T18:30:50Z", "published": "2024-08-17T09:30:24Z", "aliases": [ "CVE-2024-42288" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Fix for possible memory corruption\n\nInit Control Block is dereferenced incorrectly. Correctly dereference ICB", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-17T09:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-w46w-6cr6-6pvh/GHSA-w46w-6cr6-6pvh.json b/advisories/unreviewed/2024/08/GHSA-w46w-6cr6-6pvh/GHSA-w46w-6cr6-6pvh.json index 2f85bcf38ae..1c7c6cdd147 100644 --- a/advisories/unreviewed/2024/08/GHSA-w46w-6cr6-6pvh/GHSA-w46w-6cr6-6pvh.json +++ b/advisories/unreviewed/2024/08/GHSA-w46w-6cr6-6pvh/GHSA-w46w-6cr6-6pvh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w46w-6cr6-6pvh", - "modified": "2024-08-26T12:31:20Z", + "modified": "2024-09-05T18:30:51Z", "published": "2024-08-26T12:31:20Z", "aliases": [ "CVE-2024-43913" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvme: apple: fix device reference counting\n\nDrivers must call nvme_uninit_ctrl after a successful nvme_init_ctrl.\nSplit the allocation side out to make the error handling boundary easier\nto navigate. The apple driver had been doing this wrong, leaking the\ncontroller device memory on a tagset failure.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T11:15:05Z" diff --git a/advisories/unreviewed/2024/08/GHSA-xv7c-g3v3-rjqw/GHSA-xv7c-g3v3-rjqw.json b/advisories/unreviewed/2024/08/GHSA-xv7c-g3v3-rjqw/GHSA-xv7c-g3v3-rjqw.json index 264f38eba85..89c8c726add 100644 --- a/advisories/unreviewed/2024/08/GHSA-xv7c-g3v3-rjqw/GHSA-xv7c-g3v3-rjqw.json +++ b/advisories/unreviewed/2024/08/GHSA-xv7c-g3v3-rjqw/GHSA-xv7c-g3v3-rjqw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xv7c-g3v3-rjqw", - "modified": "2024-08-19T06:30:53Z", + "modified": "2024-09-05T18:30:50Z", "published": "2024-08-17T09:30:24Z", "aliases": [ "CVE-2024-42289" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: During vport delete send async logout explicitly\n\nDuring vport delete, it is observed that during unload we hit a crash\nbecause of stale entries in outstanding command array. For all these stale\nI/O entries, eh_abort was issued and aborted (fast_fail_io = 2009h) but\nI/Os could not complete while vport delete is in process of deleting.\n\n BUG: kernel NULL pointer dereference, address: 000000000000001c\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 [#1] PREEMPT SMP NOPTI\n Workqueue: qla2xxx_wq qla_do_work [qla2xxx]\n RIP: 0010:dma_direct_unmap_sg+0x51/0x1e0\n RSP: 0018:ffffa1e1e150fc68 EFLAGS: 00010046\n RAX: 0000000000000000 RBX: 0000000000000021 RCX: 0000000000000001\n RDX: 0000000000000021 RSI: 0000000000000000 RDI: ffff8ce208a7a0d0\n RBP: ffff8ce208a7a0d0 R08: 0000000000000000 R09: ffff8ce378aac9c8\n R10: ffff8ce378aac8a0 R11: ffffa1e1e150f9d8 R12: 0000000000000000\n R13: 0000000000000000 R14: ffff8ce378aac9c8 R15: 0000000000000000\n FS: 0000000000000000(0000) GS:ffff8d217f000000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 000000000000001c CR3: 0000002089acc000 CR4: 0000000000350ee0\n Call Trace:\n \n qla2xxx_qpair_sp_free_dma+0x417/0x4e0\n ? qla2xxx_qpair_sp_compl+0x10d/0x1a0\n ? qla2x00_status_entry+0x768/0x2830\n ? newidle_balance+0x2f0/0x430\n ? dequeue_entity+0x100/0x3c0\n ? qla24xx_process_response_queue+0x6a1/0x19e0\n ? __schedule+0x2d5/0x1140\n ? qla_do_work+0x47/0x60\n ? process_one_work+0x267/0x440\n ? process_one_work+0x440/0x440\n ? worker_thread+0x2d/0x3d0\n ? process_one_work+0x440/0x440\n ? kthread+0x156/0x180\n ? set_kthread_struct+0x50/0x50\n ? ret_from_fork+0x22/0x30\n \n\nSend out async logout explicitly for all the ports during vport delete.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-17T09:15:09Z" diff --git a/advisories/unreviewed/2024/09/GHSA-2fh4-99wm-m59g/GHSA-2fh4-99wm-m59g.json b/advisories/unreviewed/2024/09/GHSA-2fh4-99wm-m59g/GHSA-2fh4-99wm-m59g.json index c2d86537426..4b92bec0331 100644 --- a/advisories/unreviewed/2024/09/GHSA-2fh4-99wm-m59g/GHSA-2fh4-99wm-m59g.json +++ b/advisories/unreviewed/2024/09/GHSA-2fh4-99wm-m59g/GHSA-2fh4-99wm-m59g.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-3pj2-86g9-6mf7/GHSA-3pj2-86g9-6mf7.json b/advisories/unreviewed/2024/09/GHSA-3pj2-86g9-6mf7/GHSA-3pj2-86g9-6mf7.json new file mode 100644 index 00000000000..0de59cab435 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3pj2-86g9-6mf7/GHSA-3pj2-86g9-6mf7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3pj2-86g9-6mf7", + "modified": "2024-09-05T18:30:56Z", + "published": "2024-09-05T18:30:56Z", + "aliases": [ + "CVE-2024-45096" + ], + "details": "IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user with access to the package to obtain sensitive information through a directory listing.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45096" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7167255" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-548" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-58p8-2q88-9m3p/GHSA-58p8-2q88-9m3p.json b/advisories/unreviewed/2024/09/GHSA-58p8-2q88-9m3p/GHSA-58p8-2q88-9m3p.json index 8cb7f9ae51a..58f9243fd11 100644 --- a/advisories/unreviewed/2024/09/GHSA-58p8-2q88-9m3p/GHSA-58p8-2q88-9m3p.json +++ b/advisories/unreviewed/2024/09/GHSA-58p8-2q88-9m3p/GHSA-58p8-2q88-9m3p.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-755" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-5fw5-93q4-68pf/GHSA-5fw5-93q4-68pf.json b/advisories/unreviewed/2024/09/GHSA-5fw5-93q4-68pf/GHSA-5fw5-93q4-68pf.json index c1daa34a61e..aa24ce91e1f 100644 --- a/advisories/unreviewed/2024/09/GHSA-5fw5-93q4-68pf/GHSA-5fw5-93q4-68pf.json +++ b/advisories/unreviewed/2024/09/GHSA-5fw5-93q4-68pf/GHSA-5fw5-93q4-68pf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5fw5-93q4-68pf", - "modified": "2024-09-04T21:30:32Z", + "modified": "2024-09-05T18:30:56Z", "published": "2024-09-04T21:30:32Z", "aliases": [ "CVE-2024-44981" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nworkqueue: Fix UBSAN 'subtraction overflow' error in shift_and_mask()\n\nUBSAN reports the following 'subtraction overflow' error when booting\nin a virtual machine on Android:\n\n | Internal error: UBSAN: integer subtraction overflow: 00000000f2005515 [#1] PREEMPT SMP\n | Modules linked in:\n | CPU: 0 PID: 1 Comm: swapper/0 Not tainted 6.10.0-00006-g3cbe9e5abd46-dirty #4\n | Hardware name: linux,dummy-virt (DT)\n | pstate: 600000c5 (nZCv daIF -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n | pc : cancel_delayed_work+0x34/0x44\n | lr : cancel_delayed_work+0x2c/0x44\n | sp : ffff80008002ba60\n | x29: ffff80008002ba60 x28: 0000000000000000 x27: 0000000000000000\n | x26: 0000000000000000 x25: 0000000000000000 x24: 0000000000000000\n | x23: 0000000000000000 x22: 0000000000000000 x21: ffff1f65014cd3c0\n | x20: ffffc0e84c9d0da0 x19: ffffc0e84cab3558 x18: ffff800080009058\n | x17: 00000000247ee1f8 x16: 00000000247ee1f8 x15: 00000000bdcb279d\n | x14: 0000000000000001 x13: 0000000000000075 x12: 00000a0000000000\n | x11: ffff1f6501499018 x10: 00984901651fffff x9 : ffff5e7cc35af000\n | x8 : 0000000000000001 x7 : 3d4d455453595342 x6 : 000000004e514553\n | x5 : ffff1f6501499265 x4 : ffff1f650ff60b10 x3 : 0000000000000620\n | x2 : ffff80008002ba78 x1 : 0000000000000000 x0 : 0000000000000000\n | Call trace:\n | cancel_delayed_work+0x34/0x44\n | deferred_probe_extend_timeout+0x20/0x70\n | driver_register+0xa8/0x110\n | __platform_driver_register+0x28/0x3c\n | syscon_init+0x24/0x38\n | do_one_initcall+0xe4/0x338\n | do_initcall_level+0xac/0x178\n | do_initcalls+0x5c/0xa0\n | do_basic_setup+0x20/0x30\n | kernel_init_freeable+0x8c/0xf8\n | kernel_init+0x28/0x1b4\n | ret_from_fork+0x10/0x20\n | Code: f9000fbf 97fffa2f 39400268 37100048 (d42aa2a0)\n | ---[ end trace 0000000000000000 ]---\n | Kernel panic - not syncing: UBSAN: integer subtraction overflow: Fatal exception\n\nThis is due to shift_and_mask() using a signed immediate to construct\nthe mask and being called with a shift of 31 (WORK_OFFQ_POOL_SHIFT) so\nthat it ends up decrementing from INT_MIN.\n\nUse an unsigned constant '1U' to generate the mask in shift_and_mask().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-04T20:15:07Z" diff --git a/advisories/unreviewed/2024/09/GHSA-5q69-34vj-qhx4/GHSA-5q69-34vj-qhx4.json b/advisories/unreviewed/2024/09/GHSA-5q69-34vj-qhx4/GHSA-5q69-34vj-qhx4.json new file mode 100644 index 00000000000..4a52eb88fde --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5q69-34vj-qhx4/GHSA-5q69-34vj-qhx4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5q69-34vj-qhx4", + "modified": "2024-09-05T18:30:56Z", + "published": "2024-09-05T18:30:56Z", + "aliases": [ + "CVE-2024-45097" + ], + "details": "IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource modification.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45097" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7167255" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-650" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-5qmx-gqwp-wvwm/GHSA-5qmx-gqwp-wvwm.json b/advisories/unreviewed/2024/09/GHSA-5qmx-gqwp-wvwm/GHSA-5qmx-gqwp-wvwm.json new file mode 100644 index 00000000000..fe73bcba690 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5qmx-gqwp-wvwm/GHSA-5qmx-gqwp-wvwm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qmx-gqwp-wvwm", + "modified": "2024-09-05T18:30:56Z", + "published": "2024-09-05T18:30:56Z", + "aliases": [ + "CVE-2024-45171" + ], + "details": "An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to upload dangerous files, for instance PHP code, to the C-MOR system. By analyzing the C-MOR web interface, it was found out that the upload functionality for backup files allows an authenticated user to upload arbitrary files. The only condition is that the filename contains a .cbkf string. Therefore, webshell.cbkf.php is considered a valid file name for the C-MOR web application. Uploaded files are stored within the directory \"/srv/www/backups\" on the C-MOR system, and can thus be accessed via the URL https:///backup/upload_. Due to broken access control, low-privileged authenticated users can also use this file upload functionality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45171" + }, + { + "type": "WEB", + "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-026.txt" + }, + { + "type": "WEB", + "url": "https://www.syss.de/pentest-blog/mehrere-sicherheitsschwachstellen-in-videoueberwachungssoftware-c-mor-syss-2024-020-bis-030" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-82fj-4p4v-8rc2/GHSA-82fj-4p4v-8rc2.json b/advisories/unreviewed/2024/09/GHSA-82fj-4p4v-8rc2/GHSA-82fj-4p4v-8rc2.json new file mode 100644 index 00000000000..dae24193b26 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-82fj-4p4v-8rc2/GHSA-82fj-4p4v-8rc2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82fj-4p4v-8rc2", + "modified": "2024-09-05T18:30:57Z", + "published": "2024-09-05T18:30:57Z", + "aliases": [ + "CVE-2024-45589" + ], + "details": "RapidIdentity LTS through 2023.0.2 and Cloud through 2024.08.0 improperly restricts excessive authentication attempts and allows a remote attacker to cause a denial of service via the username parameters.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45589" + }, + { + "type": "WEB", + "url": "https://benrogozinski.github.io/CVE-2024-45589" + }, + { + "type": "WEB", + "url": "https://help.rapididentity.com/docs/rapididentity-lts-release-notes" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8mjg-c853-xc3w/GHSA-8mjg-c853-xc3w.json b/advisories/unreviewed/2024/09/GHSA-8mjg-c853-xc3w/GHSA-8mjg-c853-xc3w.json new file mode 100644 index 00000000000..595e83657e3 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8mjg-c853-xc3w/GHSA-8mjg-c853-xc3w.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8mjg-c853-xc3w", + "modified": "2024-09-05T18:30:56Z", + "published": "2024-09-05T18:30:56Z", + "aliases": [ + "CVE-2023-51712" + ], + "details": "An issue was discovered in Trusted Firmware-M through 2.0.0. The lack of argument verification in the logging subsystem allows attackers to read sensitive data via the login function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51712" + }, + { + "type": "WEB", + "url": "https://git.trustedfirmware.org/TF-M/trusted-firmware-m.git" + }, + { + "type": "WEB", + "url": "https://trustedfirmware-m.readthedocs.io/en/latest/security/security_advisories/debug_log_vulnerability.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8vqw-9f68-8m8p/GHSA-8vqw-9f68-8m8p.json b/advisories/unreviewed/2024/09/GHSA-8vqw-9f68-8m8p/GHSA-8vqw-9f68-8m8p.json index 3eae7aaa93f..f9c427bac75 100644 --- a/advisories/unreviewed/2024/09/GHSA-8vqw-9f68-8m8p/GHSA-8vqw-9f68-8m8p.json +++ b/advisories/unreviewed/2024/09/GHSA-8vqw-9f68-8m8p/GHSA-8vqw-9f68-8m8p.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-cx8j-vf9x-758j/GHSA-cx8j-vf9x-758j.json b/advisories/unreviewed/2024/09/GHSA-cx8j-vf9x-758j/GHSA-cx8j-vf9x-758j.json new file mode 100644 index 00000000000..56b855019e9 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-cx8j-vf9x-758j/GHSA-cx8j-vf9x-758j.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cx8j-vf9x-758j", + "modified": "2024-09-05T18:30:56Z", + "published": "2024-09-05T18:30:56Z", + "aliases": [ + "CVE-2024-45175" + ], + "details": "An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Sensitive information is stored in cleartext. It was found out that sensitive information, for example login credentials of cameras, is stored in cleartext. Thus, an attacker with filesystem access, for example exploiting a path traversal attack, has access to the login data of all configured cameras, or the configured FTP server.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45175" + }, + { + "type": "WEB", + "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-028.txt" + }, + { + "type": "WEB", + "url": "https://www.syss.de/pentest-blog/mehrere-sicherheitsschwachstellen-in-videoueberwachungssoftware-c-mor-syss-2024-020-bis-030" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-f5qr-p3r9-wjr7/GHSA-f5qr-p3r9-wjr7.json b/advisories/unreviewed/2024/09/GHSA-f5qr-p3r9-wjr7/GHSA-f5qr-p3r9-wjr7.json new file mode 100644 index 00000000000..6b4e1d72873 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-f5qr-p3r9-wjr7/GHSA-f5qr-p3r9-wjr7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5qr-p3r9-wjr7", + "modified": "2024-09-05T18:30:56Z", + "published": "2024-09-05T18:30:56Z", + "aliases": [ + "CVE-2024-42885" + ], + "details": "SQL Injection vulnerability in ESAFENET CDG 5.6 and before allows an attacker to execute arbitrary code via the id parameter of the data.jsp page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42885" + }, + { + "type": "WEB", + "url": "https://supervisor0.notion.site/ESAFENET-CDG-SQL-Injection-17d7e244810147f697c3c42a884f932b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-fv74-m98x-m3w2/GHSA-fv74-m98x-m3w2.json b/advisories/unreviewed/2024/09/GHSA-fv74-m98x-m3w2/GHSA-fv74-m98x-m3w2.json index 060a36c470b..e2a502b3ea5 100644 --- a/advisories/unreviewed/2024/09/GHSA-fv74-m98x-m3w2/GHSA-fv74-m98x-m3w2.json +++ b/advisories/unreviewed/2024/09/GHSA-fv74-m98x-m3w2/GHSA-fv74-m98x-m3w2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fv74-m98x-m3w2", - "modified": "2024-09-04T21:30:32Z", + "modified": "2024-09-05T18:30:56Z", "published": "2024-09-04T21:30:32Z", "aliases": [ "CVE-2024-44985" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: prevent possible UAF in ip6_xmit()\n\nIf skb_expand_head() returns NULL, skb has been freed\nand the associated dst/idev could also have been freed.\n\nWe must use rcu_read_lock() to prevent a possible UAF.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-04T20:15:07Z" diff --git a/advisories/unreviewed/2024/09/GHSA-fxwr-6hqv-m4wv/GHSA-fxwr-6hqv-m4wv.json b/advisories/unreviewed/2024/09/GHSA-fxwr-6hqv-m4wv/GHSA-fxwr-6hqv-m4wv.json index 768a65b9a22..e99d5f6f7fa 100644 --- a/advisories/unreviewed/2024/09/GHSA-fxwr-6hqv-m4wv/GHSA-fxwr-6hqv-m4wv.json +++ b/advisories/unreviewed/2024/09/GHSA-fxwr-6hqv-m4wv/GHSA-fxwr-6hqv-m4wv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fxwr-6hqv-m4wv", - "modified": "2024-09-04T21:30:32Z", + "modified": "2024-09-05T18:30:56Z", "published": "2024-09-04T21:30:32Z", "aliases": [ "CVE-2024-42642" ], "details": "Micron Crucial MX500 Series Solid State Drives M3CR046 is vulnerable to Buffer Overflow, which can be triggered by sending specially crafted ATA packets from the host to the drive controller.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-04T20:15:07Z" diff --git a/advisories/unreviewed/2024/09/GHSA-grr4-6qxm-23qc/GHSA-grr4-6qxm-23qc.json b/advisories/unreviewed/2024/09/GHSA-grr4-6qxm-23qc/GHSA-grr4-6qxm-23qc.json index 1989514aa27..ce1ac82710f 100644 --- a/advisories/unreviewed/2024/09/GHSA-grr4-6qxm-23qc/GHSA-grr4-6qxm-23qc.json +++ b/advisories/unreviewed/2024/09/GHSA-grr4-6qxm-23qc/GHSA-grr4-6qxm-23qc.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-h7mq-2245-9qxr/GHSA-h7mq-2245-9qxr.json b/advisories/unreviewed/2024/09/GHSA-h7mq-2245-9qxr/GHSA-h7mq-2245-9qxr.json new file mode 100644 index 00000000000..96c2e62f77e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-h7mq-2245-9qxr/GHSA-h7mq-2245-9qxr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h7mq-2245-9qxr", + "modified": "2024-09-05T18:30:57Z", + "published": "2024-09-05T18:30:57Z", + "aliases": [ + "CVE-2024-44727" + ], + "details": "Sourcecodehero Event Management System1.0 is vulnerable to SQL Injection via the parameter 'username' in /event/admin/login.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44727" + }, + { + "type": "WEB", + "url": "https://github.com/AslamMahi/CVE-Aslam-Mahi/blob/main/Sourcecodehero%20Event%20Management%20System/CVE-2024-44727.MD" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-hmgr-rm4x-vvjh/GHSA-hmgr-rm4x-vvjh.json b/advisories/unreviewed/2024/09/GHSA-hmgr-rm4x-vvjh/GHSA-hmgr-rm4x-vvjh.json index 4019a0ff44b..2e22837bb66 100644 --- a/advisories/unreviewed/2024/09/GHSA-hmgr-rm4x-vvjh/GHSA-hmgr-rm4x-vvjh.json +++ b/advisories/unreviewed/2024/09/GHSA-hmgr-rm4x-vvjh/GHSA-hmgr-rm4x-vvjh.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-hrmf-4pvg-rf3x/GHSA-hrmf-4pvg-rf3x.json b/advisories/unreviewed/2024/09/GHSA-hrmf-4pvg-rf3x/GHSA-hrmf-4pvg-rf3x.json index 0cf30ded4eb..fe5d9076895 100644 --- a/advisories/unreviewed/2024/09/GHSA-hrmf-4pvg-rf3x/GHSA-hrmf-4pvg-rf3x.json +++ b/advisories/unreviewed/2024/09/GHSA-hrmf-4pvg-rf3x/GHSA-hrmf-4pvg-rf3x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hrmf-4pvg-rf3x", - "modified": "2024-09-04T09:30:45Z", + "modified": "2024-09-05T18:30:55Z", "published": "2024-09-04T09:30:45Z", "aliases": [ "CVE-2024-45195" ], "details": "Direct Request ('Forced Browsing') vulnerability in Apache OFBiz.\n\nThis issue affects Apache OFBiz: before 18.12.16.\n\nUsers are recommended to upgrade to version 18.12.16, which fixes the issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ "CWE-425" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-04T09:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-j44j-crfp-mcpr/GHSA-j44j-crfp-mcpr.json b/advisories/unreviewed/2024/09/GHSA-j44j-crfp-mcpr/GHSA-j44j-crfp-mcpr.json index 222e65ba59a..841cb54c8d1 100644 --- a/advisories/unreviewed/2024/09/GHSA-j44j-crfp-mcpr/GHSA-j44j-crfp-mcpr.json +++ b/advisories/unreviewed/2024/09/GHSA-j44j-crfp-mcpr/GHSA-j44j-crfp-mcpr.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-mgf7-9fq3-64j5/GHSA-mgf7-9fq3-64j5.json b/advisories/unreviewed/2024/09/GHSA-mgf7-9fq3-64j5/GHSA-mgf7-9fq3-64j5.json index fcc7b44af66..291a8863539 100644 --- a/advisories/unreviewed/2024/09/GHSA-mgf7-9fq3-64j5/GHSA-mgf7-9fq3-64j5.json +++ b/advisories/unreviewed/2024/09/GHSA-mgf7-9fq3-64j5/GHSA-mgf7-9fq3-64j5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mgf7-9fq3-64j5", - "modified": "2024-09-04T21:30:32Z", + "modified": "2024-09-05T18:30:56Z", "published": "2024-09-04T21:30:32Z", "aliases": [ "CVE-2024-44974" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: avoid possible UaF when selecting endp\n\nselect_local_address() and select_signal_address() both select an\nendpoint entry from the list inside an RCU protected section, but return\na reference to it, to be read later on. If the entry is dereferenced\nafter the RCU unlock, reading info could cause a Use-after-Free.\n\nA simple solution is to copy the required info while inside the RCU\nprotected section to avoid any risk of UaF later. The address ID might\nneed to be modified later to handle the ID0 case later, so a copy seems\nOK to deal with.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-04T20:15:07Z" diff --git a/advisories/unreviewed/2024/09/GHSA-mhpj-hp73-2h88/GHSA-mhpj-hp73-2h88.json b/advisories/unreviewed/2024/09/GHSA-mhpj-hp73-2h88/GHSA-mhpj-hp73-2h88.json new file mode 100644 index 00000000000..5c850a2b395 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mhpj-hp73-2h88/GHSA-mhpj-hp73-2h88.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhpj-hp73-2h88", + "modified": "2024-09-05T18:30:56Z", + "published": "2024-09-05T18:30:56Z", + "aliases": [ + "CVE-2024-45176" + ], + "details": "An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper input validation, the C-MOR web interface is vulnerable to reflected cross-site scripting (XSS) attacks. It was found out that different functions are prone to reflected cross-site scripting attacks due to insufficient user input validation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45176" + }, + { + "type": "WEB", + "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-020.txt" + }, + { + "type": "WEB", + "url": "https://www.syss.de/pentest-blog/mehrere-sicherheitsschwachstellen-in-videoueberwachungssoftware-c-mor-syss-2024-020-bis-030" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-p6rh-3qqf-r3cq/GHSA-p6rh-3qqf-r3cq.json b/advisories/unreviewed/2024/09/GHSA-p6rh-3qqf-r3cq/GHSA-p6rh-3qqf-r3cq.json index 7dc2f80a162..038e6ec4b9e 100644 --- a/advisories/unreviewed/2024/09/GHSA-p6rh-3qqf-r3cq/GHSA-p6rh-3qqf-r3cq.json +++ b/advisories/unreviewed/2024/09/GHSA-p6rh-3qqf-r3cq/GHSA-p6rh-3qqf-r3cq.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-q683-6jpm-44v4/GHSA-q683-6jpm-44v4.json b/advisories/unreviewed/2024/09/GHSA-q683-6jpm-44v4/GHSA-q683-6jpm-44v4.json new file mode 100644 index 00000000000..739aaf3b213 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-q683-6jpm-44v4/GHSA-q683-6jpm-44v4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q683-6jpm-44v4", + "modified": "2024-09-05T18:30:56Z", + "published": "2024-09-05T18:30:56Z", + "aliases": [ + "CVE-2024-45098" + ], + "details": "IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource modification.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45098" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7167255" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-650" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-r7pq-7pwm-wmf5/GHSA-r7pq-7pwm-wmf5.json b/advisories/unreviewed/2024/09/GHSA-r7pq-7pwm-wmf5/GHSA-r7pq-7pwm-wmf5.json index e918a80542c..1061e033608 100644 --- a/advisories/unreviewed/2024/09/GHSA-r7pq-7pwm-wmf5/GHSA-r7pq-7pwm-wmf5.json +++ b/advisories/unreviewed/2024/09/GHSA-r7pq-7pwm-wmf5/GHSA-r7pq-7pwm-wmf5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r7pq-7pwm-wmf5", - "modified": "2024-09-05T15:33:37Z", + "modified": "2024-09-05T18:30:56Z", "published": "2024-09-05T15:33:37Z", "aliases": [ "CVE-2024-45178" ], "details": "An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to download arbitrary files from the C-MOR system via a path traversal attack. It was found out that different functionalities are vulnerable to path traversal attacks, due to insufficient user input validation. For instance, the download functionality for backups provided by the script download-bkf.pml is vulnerable to a path traversal attack via the parameter bkf. This enables an authenticated user to download arbitrary files as Linux user www-data from the C-MOR system. Another path traversal attack is in the script show-movies.pml, which can be exploited via the parameter cam.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-05T15:15:16Z" diff --git a/advisories/unreviewed/2024/09/GHSA-rq26-5593-xpg9/GHSA-rq26-5593-xpg9.json b/advisories/unreviewed/2024/09/GHSA-rq26-5593-xpg9/GHSA-rq26-5593-xpg9.json new file mode 100644 index 00000000000..523cae8967d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-rq26-5593-xpg9/GHSA-rq26-5593-xpg9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rq26-5593-xpg9", + "modified": "2024-09-05T18:30:57Z", + "published": "2024-09-05T18:30:57Z", + "aliases": [ + "CVE-2024-7591" + ], + "details": "Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects:\n\n* LoadMaster: 7.2.40.0 and above\n\n* ECS: All versions\n\n* Multi-Tenancy: 7.1.35.4 and above", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7591" + }, + { + "type": "WEB", + "url": "https://support.kemptechnologies.com/hc/en-us/articles/29196371689613-LoadMaster-Security-Vulnerability-CVE-2024-7591" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T18:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-w8f6-p9wh-2f93/GHSA-w8f6-p9wh-2f93.json b/advisories/unreviewed/2024/09/GHSA-w8f6-p9wh-2f93/GHSA-w8f6-p9wh-2f93.json new file mode 100644 index 00000000000..624c1387693 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-w8f6-p9wh-2f93/GHSA-w8f6-p9wh-2f93.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8f6-p9wh-2f93", + "modified": "2024-09-05T18:30:57Z", + "published": "2024-09-05T18:30:57Z", + "aliases": [ + "CVE-2024-44728" + ], + "details": "Sourcecodehero Event Management System 1.0 allows Stored Cross-Site Scripting via parameters Full Name, Address, Email, and contact# in /clientdetails/admin/regester.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44728" + }, + { + "type": "WEB", + "url": "https://github.com/AslamMahi/CVE-Aslam-Mahi/blob/main/Sourcecodehero%20Event%20Management%20System/CVE-2024-44728.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-wj9f-3j22-wx34/GHSA-wj9f-3j22-wx34.json b/advisories/unreviewed/2024/09/GHSA-wj9f-3j22-wx34/GHSA-wj9f-3j22-wx34.json index 4bc0c1dfce5..4ab00579241 100644 --- a/advisories/unreviewed/2024/09/GHSA-wj9f-3j22-wx34/GHSA-wj9f-3j22-wx34.json +++ b/advisories/unreviewed/2024/09/GHSA-wj9f-3j22-wx34/GHSA-wj9f-3j22-wx34.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-wp45-jw6q-jm9q/GHSA-wp45-jw6q-jm9q.json b/advisories/unreviewed/2024/09/GHSA-wp45-jw6q-jm9q/GHSA-wp45-jw6q-jm9q.json index a0ac4b5ea37..bf26b73efa0 100644 --- a/advisories/unreviewed/2024/09/GHSA-wp45-jw6q-jm9q/GHSA-wp45-jw6q-jm9q.json +++ b/advisories/unreviewed/2024/09/GHSA-wp45-jw6q-jm9q/GHSA-wp45-jw6q-jm9q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wp45-jw6q-jm9q", - "modified": "2024-09-04T21:30:32Z", + "modified": "2024-09-05T18:30:56Z", "published": "2024-09-04T21:30:32Z", "aliases": [ "CVE-2024-44987" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: prevent UAF in ip6_send_skb()\n\nsyzbot reported an UAF in ip6_send_skb() [1]\n\nAfter ip6_local_out() has returned, we no longer can safely\ndereference rt, unless we hold rcu_read_lock().\n\nA similar issue has been fixed in commit\na688caa34beb (\"ipv6: take rcu lock in rawv6_send_hdrinc()\")\n\nAnother potential issue in ip6_finish_output2() is handled in a\nseparate patch.\n\n[1]\n BUG: KASAN: slab-use-after-free in ip6_send_skb+0x18d/0x230 net/ipv6/ip6_output.c:1964\nRead of size 8 at addr ffff88806dde4858 by task syz.1.380/6530\n\nCPU: 1 UID: 0 PID: 6530 Comm: syz.1.380 Not tainted 6.11.0-rc3-syzkaller-00306-gdf6cbc62cc9b #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/06/2024\nCall Trace:\n \n __dump_stack lib/dump_stack.c:93 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:119\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0x169/0x550 mm/kasan/report.c:488\n kasan_report+0x143/0x180 mm/kasan/report.c:601\n ip6_send_skb+0x18d/0x230 net/ipv6/ip6_output.c:1964\n rawv6_push_pending_frames+0x75c/0x9e0 net/ipv6/raw.c:588\n rawv6_sendmsg+0x19c7/0x23c0 net/ipv6/raw.c:926\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0x1a6/0x270 net/socket.c:745\n sock_write_iter+0x2dd/0x400 net/socket.c:1160\n do_iter_readv_writev+0x60a/0x890\n vfs_writev+0x37c/0xbb0 fs/read_write.c:971\n do_writev+0x1b1/0x350 fs/read_write.c:1018\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7f936bf79e79\nCode: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007f936cd7f038 EFLAGS: 00000246 ORIG_RAX: 0000000000000014\nRAX: ffffffffffffffda RBX: 00007f936c115f80 RCX: 00007f936bf79e79\nRDX: 0000000000000001 RSI: 0000000020000040 RDI: 0000000000000004\nRBP: 00007f936bfe7916 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\nR13: 0000000000000000 R14: 00007f936c115f80 R15: 00007fff2860a7a8\n \n\nAllocated by task 6530:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3f/0x80 mm/kasan/common.c:68\n unpoison_slab_object mm/kasan/common.c:312 [inline]\n __kasan_slab_alloc+0x66/0x80 mm/kasan/common.c:338\n kasan_slab_alloc include/linux/kasan.h:201 [inline]\n slab_post_alloc_hook mm/slub.c:3988 [inline]\n slab_alloc_node mm/slub.c:4037 [inline]\n kmem_cache_alloc_noprof+0x135/0x2a0 mm/slub.c:4044\n dst_alloc+0x12b/0x190 net/core/dst.c:89\n ip6_blackhole_route+0x59/0x340 net/ipv6/route.c:2670\n make_blackhole net/xfrm/xfrm_policy.c:3120 [inline]\n xfrm_lookup_route+0xd1/0x1c0 net/xfrm/xfrm_policy.c:3313\n ip6_dst_lookup_flow+0x13e/0x180 net/ipv6/ip6_output.c:1257\n rawv6_sendmsg+0x1283/0x23c0 net/ipv6/raw.c:898\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0x1a6/0x270 net/socket.c:745\n ____sys_sendmsg+0x525/0x7d0 net/socket.c:2597\n ___sys_sendmsg net/socket.c:2651 [inline]\n __sys_sendmsg+0x2b0/0x3a0 net/socket.c:2680\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nFreed by task 45:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3f/0x80 mm/kasan/common.c:68\n kasan_save_free_info+0x40/0x50 mm/kasan/generic.c:579\n poison_slab_object+0xe0/0x150 mm/kasan/common.c:240\n __kasan_slab_free+0x37/0x60 mm/kasan/common.c:256\n kasan_slab_free include/linux/kasan.h:184 [inline]\n slab_free_hook mm/slub.c:2252 [inline]\n slab_free mm/slub.c:4473 [inline]\n kmem_cache_free+0x145/0x350 mm/slub.c:4548\n dst_destroy+0x2ac/0x460 net/core/dst.c:124\n rcu_do_batch kernel/rcu/tree.c:2569 [inline]\n rcu_core+0xafd/0x1830 kernel/rcu/tree.\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-04T20:15:07Z" diff --git a/advisories/unreviewed/2024/09/GHSA-ww4q-5m6p-gm46/GHSA-ww4q-5m6p-gm46.json b/advisories/unreviewed/2024/09/GHSA-ww4q-5m6p-gm46/GHSA-ww4q-5m6p-gm46.json index 6cbb4a48999..bb616a2f436 100644 --- a/advisories/unreviewed/2024/09/GHSA-ww4q-5m6p-gm46/GHSA-ww4q-5m6p-gm46.json +++ b/advisories/unreviewed/2024/09/GHSA-ww4q-5m6p-gm46/GHSA-ww4q-5m6p-gm46.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-755" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-x53w-73fx-jmfj/GHSA-x53w-73fx-jmfj.json b/advisories/unreviewed/2024/09/GHSA-x53w-73fx-jmfj/GHSA-x53w-73fx-jmfj.json index 6ce2429942c..a7e7def31af 100644 --- a/advisories/unreviewed/2024/09/GHSA-x53w-73fx-jmfj/GHSA-x53w-73fx-jmfj.json +++ b/advisories/unreviewed/2024/09/GHSA-x53w-73fx-jmfj/GHSA-x53w-73fx-jmfj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x53w-73fx-jmfj", - "modified": "2024-09-04T21:30:32Z", + "modified": "2024-09-05T18:30:56Z", "published": "2024-09-04T21:30:32Z", "aliases": [ "CVE-2024-44986" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: fix possible UAF in ip6_finish_output2()\n\nIf skb_expand_head() returns NULL, skb has been freed\nand associated dst/idev could also have been freed.\n\nWe need to hold rcu_read_lock() to make sure the dst and\nassociated idev are alive.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-04T20:15:07Z" diff --git a/advisories/unreviewed/2024/09/GHSA-xqr4-wc4c-36xj/GHSA-xqr4-wc4c-36xj.json b/advisories/unreviewed/2024/09/GHSA-xqr4-wc4c-36xj/GHSA-xqr4-wc4c-36xj.json index 274a159694c..a270061c841 100644 --- a/advisories/unreviewed/2024/09/GHSA-xqr4-wc4c-36xj/GHSA-xqr4-wc4c-36xj.json +++ b/advisories/unreviewed/2024/09/GHSA-xqr4-wc4c-36xj/GHSA-xqr4-wc4c-36xj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xqr4-wc4c-36xj", - "modified": "2024-09-04T21:30:32Z", + "modified": "2024-09-05T18:30:56Z", "published": "2024-09-04T21:30:32Z", "aliases": [ "CVE-2024-44971" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: bcm_sf2: Fix a possible memory leak in bcm_sf2_mdio_register()\n\nbcm_sf2_mdio_register() calls of_phy_find_device() and then\nphy_device_remove() in a loop to remove existing PHY devices.\nof_phy_find_device() eventually calls bus_find_device(), which calls\nget_device() on the returned struct device * to increment the refcount.\nThe current implementation does not decrement the refcount, which causes\nmemory leak.\n\nThis commit adds the missing phy_device_free() call to decrement the\nrefcount via put_device() to balance the refcount.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-04T19:15:31Z"