From a10f4ae9b705555b79b1469f6aac86214392f61c Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 17 Sep 2024 21:32:45 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-5j94-f3mf-8685.json | 66 ++++++++++++++++++ .../GHSA-qjxf-mc72-wjr2.json | 69 +++++++++++++++++++ .../GHSA-w2r7-9579-27hf.json | 39 +++++++++-- .../GHSA-9m9m-5xqh-55gx.json | 2 +- .../GHSA-7f54-5cf3-2h2x.json | 6 +- .../GHSA-852f-crfr-xw8c.json | 13 +++- .../GHSA-m325-ccpm-cc67.json | 6 +- .../GHSA-rx9g-4r6p-jpgq.json | 6 +- .../GHSA-xrmw-792x-crvf.json | 6 +- .../GHSA-473p-xqgv-xxw3.json | 39 +++++++++++ .../GHSA-56gf-j26c-43xh.json | 11 +-- .../GHSA-58rw-8pf6-2mgq.json | 42 +++++++++++ .../GHSA-67qp-fprc-rhx4.json | 11 +-- .../GHSA-74qm-4v7r-jw2f.json | 62 +++++++++++++++++ .../GHSA-76f7-g9hr-v32c.json | 39 +++++++++++ .../GHSA-79c6-5cw9-rpwc.json | 11 +-- .../GHSA-86wc-gr98-6p59.json | 39 +++++++++++ .../GHSA-976w-rfcm-5cfg.json | 11 +-- .../GHSA-97x9-7h6v-3jx9.json | 39 +++++++++++ .../GHSA-998c-q8hh-h8gv.json | 42 +++++++++++ .../GHSA-9cx9-7v8g-h36v.json | 42 +++++++++++ .../GHSA-cwj6-8v2q-g52w.json | 11 +-- .../GHSA-cwr3-4fc3-j8h8.json | 39 +++++++++++ .../GHSA-gvcc-mwhq-ccvw.json | 3 +- .../GHSA-h47h-p6xc-8qv6.json | 58 ++++++++++++++++ .../GHSA-hqpj-xx46-mwvh.json | 38 ++++++++++ .../GHSA-jh66-3545-vpm7.json | 35 ++++++++++ .../GHSA-p72w-r6fv-6g5h.json | 35 ++++++++++ .../GHSA-pwwp-3q7j-9mx8.json | 66 ++++++++++++++++++ .../GHSA-r6hg-m6fm-hgwr.json | 38 ++++++++++ .../GHSA-rwxx-p542-9g8c.json | 11 +-- .../GHSA-v6p4-2h6v-crxc.json | 58 ++++++++++++++++ .../GHSA-vh3x-525m-jp4r.json | 58 ++++++++++++++++ .../GHSA-wq22-3j46-hjmw.json | 39 +++++++++++ .../GHSA-xrx8-f378-fwph.json | 39 +++++++++++ 35 files changed, 1092 insertions(+), 37 deletions(-) create mode 100644 advisories/github-reviewed/2024/09/GHSA-5j94-f3mf-8685/GHSA-5j94-f3mf-8685.json create mode 100644 advisories/github-reviewed/2024/09/GHSA-qjxf-mc72-wjr2/GHSA-qjxf-mc72-wjr2.json rename advisories/{unreviewed => github-reviewed}/2024/09/GHSA-w2r7-9579-27hf/GHSA-w2r7-9579-27hf.json (57%) create mode 100644 advisories/unreviewed/2024/09/GHSA-473p-xqgv-xxw3/GHSA-473p-xqgv-xxw3.json create mode 100644 advisories/unreviewed/2024/09/GHSA-58rw-8pf6-2mgq/GHSA-58rw-8pf6-2mgq.json create mode 100644 advisories/unreviewed/2024/09/GHSA-74qm-4v7r-jw2f/GHSA-74qm-4v7r-jw2f.json create mode 100644 advisories/unreviewed/2024/09/GHSA-76f7-g9hr-v32c/GHSA-76f7-g9hr-v32c.json create mode 100644 advisories/unreviewed/2024/09/GHSA-86wc-gr98-6p59/GHSA-86wc-gr98-6p59.json create mode 100644 advisories/unreviewed/2024/09/GHSA-97x9-7h6v-3jx9/GHSA-97x9-7h6v-3jx9.json create mode 100644 advisories/unreviewed/2024/09/GHSA-998c-q8hh-h8gv/GHSA-998c-q8hh-h8gv.json create mode 100644 advisories/unreviewed/2024/09/GHSA-9cx9-7v8g-h36v/GHSA-9cx9-7v8g-h36v.json create mode 100644 advisories/unreviewed/2024/09/GHSA-cwr3-4fc3-j8h8/GHSA-cwr3-4fc3-j8h8.json create mode 100644 advisories/unreviewed/2024/09/GHSA-h47h-p6xc-8qv6/GHSA-h47h-p6xc-8qv6.json create mode 100644 advisories/unreviewed/2024/09/GHSA-hqpj-xx46-mwvh/GHSA-hqpj-xx46-mwvh.json create mode 100644 advisories/unreviewed/2024/09/GHSA-jh66-3545-vpm7/GHSA-jh66-3545-vpm7.json create mode 100644 advisories/unreviewed/2024/09/GHSA-p72w-r6fv-6g5h/GHSA-p72w-r6fv-6g5h.json create mode 100644 advisories/unreviewed/2024/09/GHSA-pwwp-3q7j-9mx8/GHSA-pwwp-3q7j-9mx8.json create mode 100644 advisories/unreviewed/2024/09/GHSA-r6hg-m6fm-hgwr/GHSA-r6hg-m6fm-hgwr.json create mode 100644 advisories/unreviewed/2024/09/GHSA-v6p4-2h6v-crxc/GHSA-v6p4-2h6v-crxc.json create mode 100644 advisories/unreviewed/2024/09/GHSA-vh3x-525m-jp4r/GHSA-vh3x-525m-jp4r.json create mode 100644 advisories/unreviewed/2024/09/GHSA-wq22-3j46-hjmw/GHSA-wq22-3j46-hjmw.json create mode 100644 advisories/unreviewed/2024/09/GHSA-xrx8-f378-fwph/GHSA-xrx8-f378-fwph.json diff --git a/advisories/github-reviewed/2024/09/GHSA-5j94-f3mf-8685/GHSA-5j94-f3mf-8685.json b/advisories/github-reviewed/2024/09/GHSA-5j94-f3mf-8685/GHSA-5j94-f3mf-8685.json new file mode 100644 index 00000000000..7a3845f9473 --- /dev/null +++ b/advisories/github-reviewed/2024/09/GHSA-5j94-f3mf-8685/GHSA-5j94-f3mf-8685.json @@ -0,0 +1,66 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5j94-f3mf-8685", + "modified": "2024-09-17T21:31:28Z", + "published": "2024-09-17T21:31:28Z", + "aliases": [ + "CVE-2024-46976" + ], + "summary": "@backstage/plugin-techdocs-backend vulnerable to circumvention of cross site scripting protection", + "details": "### Impact\n\nAn attacker with control of the contents of the TechDocs storage buckets is able to inject executable scripts in the TechDocs content that will be executed in the victim's browser when browsing documentation or navigating to an attacker provided link.\n\n### Patches\n\nThis has been fixed in the 1.10.13 release of the `@backstage/plugin-techdocs-backend` package.\n\n### References\n\nIf you have any questions or comments about this advisory:\n\nOpen an issue in the [Backstage repository](https://github.com/backstage/backstage)\nVisit our Discord, linked to in [Backstage README](https://github.com/backstage/backstage)\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "npm", + "name": "@backstage/plugin-techdocs-backend" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.10.13" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/backstage/backstage/security/advisories/GHSA-5j94-f3mf-8685" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46976" + }, + { + "type": "PACKAGE", + "url": "https://github.com/backstage/backstage" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693", + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-09-17T21:31:28Z", + "nvd_published_at": "2024-09-17T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/09/GHSA-qjxf-mc72-wjr2/GHSA-qjxf-mc72-wjr2.json b/advisories/github-reviewed/2024/09/GHSA-qjxf-mc72-wjr2/GHSA-qjxf-mc72-wjr2.json new file mode 100644 index 00000000000..331563229a3 --- /dev/null +++ b/advisories/github-reviewed/2024/09/GHSA-qjxf-mc72-wjr2/GHSA-qjxf-mc72-wjr2.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjxf-mc72-wjr2", + "modified": "2024-09-17T21:31:50Z", + "published": "2024-09-17T21:31:50Z", + "aliases": [ + "CVE-2024-8796" + ], + "summary": "Devise-Two-Factor Authentication Uses Insufficient Default OTP Shared Secret Length", + "details": "### Summary\nUnder the default configuration, Devise-Two-Factor versions >= 2.2.0 & < 6.0.0 generate TOTP shared secrets that are 120 bits instead of the 128-bit minimum defined by [RFC 4226](https://datatracker.ietf.org/doc/html/rfc4226). Using a shared secret shorter than the minimum to generate a multi-factor authentication code could make it easier for an attacker to guess the shared secret and generate valid TOTP codes.\n\n### Remediation\nDevise-Two-Factor should be upgraded to version v6.0.0 as soon as possible. After upgrading, the length of shared secrets and TOTP URLs generated by the library will increase since the new shared secrets will be longer.\n\nIf upgrading is not possible, you can override the default `otp_secret_length` attribute in the model when configuring `two_factor_authenticable` and set it to a value of at least 26 to ensure newly generated shared secrets are at least 128-bits long.\n\nAfter upgrading or implementing the workaround, applications using Devise-Two-Factor may wish to migrate users to the new OTP length to provide increased protection for those accounts. Turning off OTP for users by setting `otp_required_for_login` to false is not recommended since it would leave accounts unprotected. However, you may wish to implement application logic that checks the length of a user's shared secret and prompts users to re-enroll in OTP.\n\n### Background\nDevise-Two-Factor uses [ROTP](https://github.com/mdp/rotp) to generate shared secrets for TOTP. In ROTP < 5.0.0, the first argument to the `ROTP::Base32#random_base32` function represented the number of bytes to read from SecureRandom which were then returned as a base32-encoded string. In ROTP 5.1.0, this function was changed so that the first argument now represents the length of the base32-encoded string returned by the function instead of the number of bytes to read from SecureRandom resulting in a shorter key being generated for the same input value. (https://github.com/mdp/rotp/commit/c6c24ab894e7c2b1579d45ac82c41454d1e98227).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + { + "package": { + "ecosystem": "RubyGems", + "name": "devise-two-factor" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.2.0" + }, + { + "fixed": "6.0.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/devise-two-factor/devise-two-factor/security/advisories/GHSA-qjxf-mc72-wjr2" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8796" + }, + { + "type": "WEB", + "url": "https://github.com/devise-two-factor/devise-two-factor/commit/cc6f34423d9c6af9f3e02be478c3c40dc7462e19" + }, + { + "type": "PACKAGE", + "url": "https://github.com/devise-two-factor/devise-two-factor" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-331" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-09-17T21:31:50Z", + "nvd_published_at": "2024-09-17T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-w2r7-9579-27hf/GHSA-w2r7-9579-27hf.json b/advisories/github-reviewed/2024/09/GHSA-w2r7-9579-27hf/GHSA-w2r7-9579-27hf.json similarity index 57% rename from advisories/unreviewed/2024/09/GHSA-w2r7-9579-27hf/GHSA-w2r7-9579-27hf.json rename to advisories/github-reviewed/2024/09/GHSA-w2r7-9579-27hf/GHSA-w2r7-9579-27hf.json index 27c97b06bb4..9a5ab196f9e 100644 --- a/advisories/unreviewed/2024/09/GHSA-w2r7-9579-27hf/GHSA-w2r7-9579-27hf.json +++ b/advisories/github-reviewed/2024/09/GHSA-w2r7-9579-27hf/GHSA-w2r7-9579-27hf.json @@ -1,20 +1,43 @@ { "schema_version": "1.4.0", "id": "GHSA-w2r7-9579-27hf", - "modified": "2024-09-17T18:33:26Z", + "modified": "2024-09-17T21:32:12Z", "published": "2024-09-17T18:33:26Z", "aliases": [ "CVE-2024-8768" ], + "summary": "vLLM denial of service vulnerability", "details": "A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server, resulting in a denial of service.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "vllm" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.5.5" + } + ] + } + ] + } ], "references": [ { @@ -29,6 +52,10 @@ "type": "WEB", "url": "https://github.com/vllm-project/vllm/pull/7746" }, + { + "type": "WEB", + "url": "https://github.com/vllm-project/vllm/commit/e25fee57c2e69161bd261f5986dc5aeb198bbd42" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-8768" @@ -36,6 +63,10 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2311895" + }, + { + "type": "PACKAGE", + "url": "https://github.com/vllm-project/vllm" } ], "database_specific": { @@ -43,8 +74,8 @@ "CWE-617" ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-09-17T21:32:12Z", "nvd_published_at": "2024-09-17T17:15:11Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-9m9m-5xqh-55gx/GHSA-9m9m-5xqh-55gx.json b/advisories/unreviewed/2024/01/GHSA-9m9m-5xqh-55gx/GHSA-9m9m-5xqh-55gx.json index fb25adb4a60..86367c9a358 100644 --- a/advisories/unreviewed/2024/01/GHSA-9m9m-5xqh-55gx/GHSA-9m9m-5xqh-55gx.json +++ b/advisories/unreviewed/2024/01/GHSA-9m9m-5xqh-55gx/GHSA-9m9m-5xqh-55gx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9m9m-5xqh-55gx", - "modified": "2024-01-24T15:30:30Z", + "modified": "2024-09-17T21:30:30Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2023-0094" diff --git a/advisories/unreviewed/2024/06/GHSA-7f54-5cf3-2h2x/GHSA-7f54-5cf3-2h2x.json b/advisories/unreviewed/2024/06/GHSA-7f54-5cf3-2h2x/GHSA-7f54-5cf3-2h2x.json index 5cd37d4ef03..fcb303f8e4b 100644 --- a/advisories/unreviewed/2024/06/GHSA-7f54-5cf3-2h2x/GHSA-7f54-5cf3-2h2x.json +++ b/advisories/unreviewed/2024/06/GHSA-7f54-5cf3-2h2x/GHSA-7f54-5cf3-2h2x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7f54-5cf3-2h2x", - "modified": "2024-06-27T12:30:48Z", + "modified": "2024-09-17T21:30:30Z", "published": "2024-06-27T12:30:48Z", "aliases": [ "CVE-2024-6368" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-852f-crfr-xw8c/GHSA-852f-crfr-xw8c.json b/advisories/unreviewed/2024/06/GHSA-852f-crfr-xw8c/GHSA-852f-crfr-xw8c.json index a4aceabd4c5..4ff2a3f9bcb 100644 --- a/advisories/unreviewed/2024/06/GHSA-852f-crfr-xw8c/GHSA-852f-crfr-xw8c.json +++ b/advisories/unreviewed/2024/06/GHSA-852f-crfr-xw8c/GHSA-852f-crfr-xw8c.json @@ -1,14 +1,21 @@ { "schema_version": "1.4.0", "id": "GHSA-852f-crfr-xw8c", - "modified": "2024-06-27T18:31:32Z", + "modified": "2024-09-17T21:30:30Z", "published": "2024-06-27T18:31:31Z", "aliases": [ "CVE-2024-39374" ], "details": "TELSAT marKoni FM Transmitters are vulnerable to an attacker exploiting a hidden admin account that can be accessed through the use of hard-coded credentials.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } ], "affected": [ @@ -27,7 +34,7 @@ "cwe_ids": [ "CWE-798" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-27T16:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-m325-ccpm-cc67/GHSA-m325-ccpm-cc67.json b/advisories/unreviewed/2024/06/GHSA-m325-ccpm-cc67/GHSA-m325-ccpm-cc67.json index ce23ce051c7..e3850232536 100644 --- a/advisories/unreviewed/2024/06/GHSA-m325-ccpm-cc67/GHSA-m325-ccpm-cc67.json +++ b/advisories/unreviewed/2024/06/GHSA-m325-ccpm-cc67/GHSA-m325-ccpm-cc67.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m325-ccpm-cc67", - "modified": "2024-06-27T12:30:48Z", + "modified": "2024-09-17T21:30:30Z", "published": "2024-06-27T12:30:48Z", "aliases": [ "CVE-2024-6367" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-rx9g-4r6p-jpgq/GHSA-rx9g-4r6p-jpgq.json b/advisories/unreviewed/2024/06/GHSA-rx9g-4r6p-jpgq/GHSA-rx9g-4r6p-jpgq.json index e8534cb31e2..3a23c118807 100644 --- a/advisories/unreviewed/2024/06/GHSA-rx9g-4r6p-jpgq/GHSA-rx9g-4r6p-jpgq.json +++ b/advisories/unreviewed/2024/06/GHSA-rx9g-4r6p-jpgq/GHSA-rx9g-4r6p-jpgq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rx9g-4r6p-jpgq", - "modified": "2024-06-27T12:30:49Z", + "modified": "2024-09-17T21:30:30Z", "published": "2024-06-27T12:30:49Z", "aliases": [ "CVE-2024-6370" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-xrmw-792x-crvf/GHSA-xrmw-792x-crvf.json b/advisories/unreviewed/2024/06/GHSA-xrmw-792x-crvf/GHSA-xrmw-792x-crvf.json index d123988a33f..22dfae9c49e 100644 --- a/advisories/unreviewed/2024/06/GHSA-xrmw-792x-crvf/GHSA-xrmw-792x-crvf.json +++ b/advisories/unreviewed/2024/06/GHSA-xrmw-792x-crvf/GHSA-xrmw-792x-crvf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xrmw-792x-crvf", - "modified": "2024-06-27T12:30:49Z", + "modified": "2024-09-17T21:30:30Z", "published": "2024-06-27T12:30:49Z", "aliases": [ "CVE-2024-6369" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/09/GHSA-473p-xqgv-xxw3/GHSA-473p-xqgv-xxw3.json b/advisories/unreviewed/2024/09/GHSA-473p-xqgv-xxw3/GHSA-473p-xqgv-xxw3.json new file mode 100644 index 00000000000..6896ae1f7f3 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-473p-xqgv-xxw3/GHSA-473p-xqgv-xxw3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-473p-xqgv-xxw3", + "modified": "2024-09-17T21:30:33Z", + "published": "2024-09-17T21:30:33Z", + "aliases": [ + "CVE-2024-8909" + ], + "details": "Inappropriate implementation in UI in Google Chrome on iOS prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8909" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_17.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/341353783" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-56gf-j26c-43xh/GHSA-56gf-j26c-43xh.json b/advisories/unreviewed/2024/09/GHSA-56gf-j26c-43xh/GHSA-56gf-j26c-43xh.json index 337e6eed380..8237928a518 100644 --- a/advisories/unreviewed/2024/09/GHSA-56gf-j26c-43xh/GHSA-56gf-j26c-43xh.json +++ b/advisories/unreviewed/2024/09/GHSA-56gf-j26c-43xh/GHSA-56gf-j26c-43xh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-56gf-j26c-43xh", - "modified": "2024-09-17T00:31:05Z", + "modified": "2024-09-17T21:30:31Z", "published": "2024-09-17T00:31:05Z", "aliases": [ "CVE-2024-44132" ], "details": "This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15. An app may be able to break out of its sandbox.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-61" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:50Z" diff --git a/advisories/unreviewed/2024/09/GHSA-58rw-8pf6-2mgq/GHSA-58rw-8pf6-2mgq.json b/advisories/unreviewed/2024/09/GHSA-58rw-8pf6-2mgq/GHSA-58rw-8pf6-2mgq.json new file mode 100644 index 00000000000..8df3ad2bf29 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-58rw-8pf6-2mgq/GHSA-58rw-8pf6-2mgq.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58rw-8pf6-2mgq", + "modified": "2024-09-17T21:30:33Z", + "published": "2024-09-17T21:30:33Z", + "aliases": [ + "CVE-2024-8956" + ], + "details": "PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Authorization header. The result is a remote and unauthenticated attacker can leak sensitive data such as usernames, password hashes, and configurations details. Additionally, the attacker can update individual configuration values or overwrite the whole file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8956" + }, + { + "type": "WEB", + "url": "https://ptzoptics.com/firmware-changelog" + }, + { + "type": "WEB", + "url": "https://vulncheck.com/advisories/ptzoptics-insufficient-auth" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T20:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-67qp-fprc-rhx4/GHSA-67qp-fprc-rhx4.json b/advisories/unreviewed/2024/09/GHSA-67qp-fprc-rhx4/GHSA-67qp-fprc-rhx4.json index f59b516a938..5b063ec56fb 100644 --- a/advisories/unreviewed/2024/09/GHSA-67qp-fprc-rhx4/GHSA-67qp-fprc-rhx4.json +++ b/advisories/unreviewed/2024/09/GHSA-67qp-fprc-rhx4/GHSA-67qp-fprc-rhx4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-67qp-fprc-rhx4", - "modified": "2024-09-17T15:31:23Z", + "modified": "2024-09-17T21:30:32Z", "published": "2024-09-17T15:31:23Z", "aliases": [ "CVE-2024-46362" ], "details": "FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_directory", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T13:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-74qm-4v7r-jw2f/GHSA-74qm-4v7r-jw2f.json b/advisories/unreviewed/2024/09/GHSA-74qm-4v7r-jw2f/GHSA-74qm-4v7r-jw2f.json new file mode 100644 index 00000000000..1146f594802 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-74qm-4v7r-jw2f/GHSA-74qm-4v7r-jw2f.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-74qm-4v7r-jw2f", + "modified": "2024-09-17T21:30:33Z", + "published": "2024-09-17T21:30:33Z", + "aliases": [ + "CVE-2024-8946" + ], + "details": "A vulnerability was found in MicroPython 1.23.0. It has been classified as critical. Affected is the function mp_vfs_umount of the file extmod/vfs.c of the component VFS Unmount Handler. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 29943546343c92334e8518695a11fc0e2ceea68b. It is recommended to apply a patch to fix this issue. In the VFS unmount process, the comparison between the mounted path string and the unmount requested string is based solely on the length of the unmount string, which can lead to a heap buffer overflow read.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8946" + }, + { + "type": "WEB", + "url": "https://github.com/micropython/micropython/issues/13006" + }, + { + "type": "WEB", + "url": "https://github.com/micropython/micropython/issues/13006#issuecomment-1820309455" + }, + { + "type": "WEB", + "url": "https://github.com/micropython/micropython/commit/29943546343c92334e8518695a11fc0e2ceea68b" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.277764" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.277764" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.409312" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T19:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-76f7-g9hr-v32c/GHSA-76f7-g9hr-v32c.json b/advisories/unreviewed/2024/09/GHSA-76f7-g9hr-v32c/GHSA-76f7-g9hr-v32c.json new file mode 100644 index 00000000000..82ca3c8d5af --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-76f7-g9hr-v32c/GHSA-76f7-g9hr-v32c.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76f7-g9hr-v32c", + "modified": "2024-09-17T21:30:33Z", + "published": "2024-09-17T21:30:33Z", + "aliases": [ + "CVE-2024-8907" + ], + "details": "Insufficient data validation in Omnibox in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (XSS) via a crafted set of UI gestures. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8907" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_17.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/360642942" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-79c6-5cw9-rpwc/GHSA-79c6-5cw9-rpwc.json b/advisories/unreviewed/2024/09/GHSA-79c6-5cw9-rpwc/GHSA-79c6-5cw9-rpwc.json index aa7e68463d9..e2d42634bb5 100644 --- a/advisories/unreviewed/2024/09/GHSA-79c6-5cw9-rpwc/GHSA-79c6-5cw9-rpwc.json +++ b/advisories/unreviewed/2024/09/GHSA-79c6-5cw9-rpwc/GHSA-79c6-5cw9-rpwc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-79c6-5cw9-rpwc", - "modified": "2024-09-17T00:31:04Z", + "modified": "2024-09-17T21:30:31Z", "published": "2024-09-17T00:31:04Z", "aliases": [ "CVE-2024-40825" ], "details": "The issue was addressed with improved checks. This issue is fixed in visionOS 2, macOS Sequoia 15. A malicious app with root privileges may be able to modify the contents of system files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:48Z" diff --git a/advisories/unreviewed/2024/09/GHSA-86wc-gr98-6p59/GHSA-86wc-gr98-6p59.json b/advisories/unreviewed/2024/09/GHSA-86wc-gr98-6p59/GHSA-86wc-gr98-6p59.json new file mode 100644 index 00000000000..ab3f5360d29 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-86wc-gr98-6p59/GHSA-86wc-gr98-6p59.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86wc-gr98-6p59", + "modified": "2024-09-17T21:30:33Z", + "published": "2024-09-17T21:30:33Z", + "aliases": [ + "CVE-2024-8908" + ], + "details": "Inappropriate implementation in Autofill in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8908" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_17.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/337222641" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-976w-rfcm-5cfg/GHSA-976w-rfcm-5cfg.json b/advisories/unreviewed/2024/09/GHSA-976w-rfcm-5cfg/GHSA-976w-rfcm-5cfg.json index 9f8fd8c6db3..0bc6b749823 100644 --- a/advisories/unreviewed/2024/09/GHSA-976w-rfcm-5cfg/GHSA-976w-rfcm-5cfg.json +++ b/advisories/unreviewed/2024/09/GHSA-976w-rfcm-5cfg/GHSA-976w-rfcm-5cfg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-976w-rfcm-5cfg", - "modified": "2024-09-17T00:31:03Z", + "modified": "2024-09-17T21:30:31Z", "published": "2024-09-17T00:31:03Z", "aliases": [ "CVE-2024-27876" ], "details": "A race condition was addressed with improved locking. This issue is fixed in macOS Ventura 13.7, iOS 17.7 and iPadOS 17.7, visionOS 2, iOS 18 and iPadOS 18, macOS Sonoma 14.7, macOS Sequoia 15. Unpacking a maliciously crafted archive may allow an attacker to write arbitrary files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:48Z" diff --git a/advisories/unreviewed/2024/09/GHSA-97x9-7h6v-3jx9/GHSA-97x9-7h6v-3jx9.json b/advisories/unreviewed/2024/09/GHSA-97x9-7h6v-3jx9/GHSA-97x9-7h6v-3jx9.json new file mode 100644 index 00000000000..61749068bc2 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-97x9-7h6v-3jx9/GHSA-97x9-7h6v-3jx9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97x9-7h6v-3jx9", + "modified": "2024-09-17T21:30:32Z", + "published": "2024-09-17T21:30:32Z", + "aliases": [ + "CVE-2024-8900" + ], + "details": "An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects Firefox < 129.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8900" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1872841" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-33" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T19:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-998c-q8hh-h8gv/GHSA-998c-q8hh-h8gv.json b/advisories/unreviewed/2024/09/GHSA-998c-q8hh-h8gv/GHSA-998c-q8hh-h8gv.json new file mode 100644 index 00000000000..b85db8911a0 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-998c-q8hh-h8gv/GHSA-998c-q8hh-h8gv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-998c-q8hh-h8gv", + "modified": "2024-09-17T21:30:32Z", + "published": "2024-09-17T21:30:32Z", + "aliases": [ + "CVE-2024-8660" + ], + "details": "Concrete CMS versions 9.0.0 through 9.3.3 are affected by a\nstored XSS vulnerability in the \"Top Navigator Bar\" block.\nSince the \"Top Navigator Bar\" output was not sufficiently sanitized, a rogue administrator could add a malicious payload that could be executed when targeted users visited the home page.The Concrete CMS Security Team gave this vulnerability a CVSS v4 score of 4.6\nwith vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N . This\ndoes not affect versions below 9.0.0 since they do not have the Top\nNavigator Bar Block. Thanks, Chu Quoc Khanh for reporting.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8660" + }, + { + "type": "WEB", + "url": "https://github.com/concretecms/concretecms/pull/12128" + }, + { + "type": "WEB", + "url": "https://documentation.concretecms.org/9-x/developers/introduction/version-history/934-release-notes" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T19:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-9cx9-7v8g-h36v/GHSA-9cx9-7v8g-h36v.json b/advisories/unreviewed/2024/09/GHSA-9cx9-7v8g-h36v/GHSA-9cx9-7v8g-h36v.json new file mode 100644 index 00000000000..7eefa05dbdb --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-9cx9-7v8g-h36v/GHSA-9cx9-7v8g-h36v.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9cx9-7v8g-h36v", + "modified": "2024-09-17T21:30:33Z", + "published": "2024-09-17T21:30:33Z", + "aliases": [ + "CVE-2024-8957" + ], + "details": "PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not sufficiently validate the ntp_addr configuration value which may lead to arbitrary command execution when ntp_client is started. When chained with CVE-2024-8956, a remote and unauthenticated attacker can execute arbitrary OS commands on affected devices.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8957" + }, + { + "type": "WEB", + "url": "https://ptzoptics.com/firmware-changelog" + }, + { + "type": "WEB", + "url": "https://vulncheck.com/advisories/ptzoptics-command-injection" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-cwj6-8v2q-g52w/GHSA-cwj6-8v2q-g52w.json b/advisories/unreviewed/2024/09/GHSA-cwj6-8v2q-g52w/GHSA-cwj6-8v2q-g52w.json index 5fd25289602..493b3d4ce8c 100644 --- a/advisories/unreviewed/2024/09/GHSA-cwj6-8v2q-g52w/GHSA-cwj6-8v2q-g52w.json +++ b/advisories/unreviewed/2024/09/GHSA-cwj6-8v2q-g52w/GHSA-cwj6-8v2q-g52w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cwj6-8v2q-g52w", - "modified": "2024-09-17T15:31:23Z", + "modified": "2024-09-17T21:30:32Z", "published": "2024-09-17T15:31:23Z", "aliases": [ "CVE-2024-46085" ], "details": "FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/rename", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T13:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-cwr3-4fc3-j8h8/GHSA-cwr3-4fc3-j8h8.json b/advisories/unreviewed/2024/09/GHSA-cwr3-4fc3-j8h8/GHSA-cwr3-4fc3-j8h8.json new file mode 100644 index 00000000000..db1ae43960f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-cwr3-4fc3-j8h8/GHSA-cwr3-4fc3-j8h8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwr3-4fc3-j8h8", + "modified": "2024-09-17T21:30:33Z", + "published": "2024-09-17T21:30:33Z", + "aliases": [ + "CVE-2024-8904" + ], + "details": "Type Confusion in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8904" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_17.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/365376497" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gvcc-mwhq-ccvw/GHSA-gvcc-mwhq-ccvw.json b/advisories/unreviewed/2024/09/GHSA-gvcc-mwhq-ccvw/GHSA-gvcc-mwhq-ccvw.json index 244aaf244bb..7c240393ae4 100644 --- a/advisories/unreviewed/2024/09/GHSA-gvcc-mwhq-ccvw/GHSA-gvcc-mwhq-ccvw.json +++ b/advisories/unreviewed/2024/09/GHSA-gvcc-mwhq-ccvw/GHSA-gvcc-mwhq-ccvw.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-h47h-p6xc-8qv6/GHSA-h47h-p6xc-8qv6.json b/advisories/unreviewed/2024/09/GHSA-h47h-p6xc-8qv6/GHSA-h47h-p6xc-8qv6.json new file mode 100644 index 00000000000..eaa17f0d124 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-h47h-p6xc-8qv6/GHSA-h47h-p6xc-8qv6.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h47h-p6xc-8qv6", + "modified": "2024-09-17T21:30:32Z", + "published": "2024-09-17T21:30:32Z", + "aliases": [ + "CVE-2024-8949" + ], + "details": "A vulnerability classified as critical has been found in SourceCodester Online Eyewear Shop 1.0. This affects an unknown part of the file /classes/Master.php of the component Cart Content Handler. The manipulation of the argument cart_id/id leads to improper ownership management. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8949" + }, + { + "type": "WEB", + "url": "https://github.com/gurudattch/CVEs/edit/main/Sourcecodester-Online-Eyewear-shop-webiste-Broken-access-control.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.277767" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.277767" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.409459" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-282" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T19:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-hqpj-xx46-mwvh/GHSA-hqpj-xx46-mwvh.json b/advisories/unreviewed/2024/09/GHSA-hqpj-xx46-mwvh/GHSA-hqpj-xx46-mwvh.json new file mode 100644 index 00000000000..034d328442e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-hqpj-xx46-mwvh/GHSA-hqpj-xx46-mwvh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqpj-xx46-mwvh", + "modified": "2024-09-17T21:30:32Z", + "published": "2024-09-17T21:30:32Z", + "aliases": [ + "CVE-2024-38183" + ], + "details": "An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to click on a malicious link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38183" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38183" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T19:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-jh66-3545-vpm7/GHSA-jh66-3545-vpm7.json b/advisories/unreviewed/2024/09/GHSA-jh66-3545-vpm7/GHSA-jh66-3545-vpm7.json new file mode 100644 index 00000000000..0a17d2359a7 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-jh66-3545-vpm7/GHSA-jh66-3545-vpm7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jh66-3545-vpm7", + "modified": "2024-09-17T21:30:32Z", + "published": "2024-09-17T21:30:32Z", + "aliases": [ + "CVE-2024-45537" + ], + "details": "Apache Druid allows users with certain permissions to read data from other database systems using JDBC. This functionality allows trusted users to set up Druid lookups or run ingestion tasks. Druid also allows administrators to configure a list of allowed properties that users are able to provide for their JDBC connections. By default, this allowed properties list restricts users to TLS-related properties only. However, when configuration a MySQL JDBC connection, users can use a particularly-crafted JDBC connection string to provide properties that are not on this allow list.\n\nUsers without the permission to configure JDBC connections are not able to exploit this vulnerability.\nCVE-2021-26919 describes a similar vulnerability which was partially addressed in Apache Druid 0.20.2.\n\nThis issue is fixed in Apache Druid 30.0.1.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45537" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/2ovx1t77y6tlkhk5b42clp4vwo4c8cjv" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T19:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-p72w-r6fv-6g5h/GHSA-p72w-r6fv-6g5h.json b/advisories/unreviewed/2024/09/GHSA-p72w-r6fv-6g5h/GHSA-p72w-r6fv-6g5h.json new file mode 100644 index 00000000000..9cca758b59d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-p72w-r6fv-6g5h/GHSA-p72w-r6fv-6g5h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p72w-r6fv-6g5h", + "modified": "2024-09-17T21:30:32Z", + "published": "2024-09-17T21:30:32Z", + "aliases": [ + "CVE-2024-45384" + ], + "details": "Padding Oracle vulnerability in Apache Druid extension, druid-pac4j.\nThis could allow an attacker to manipulate a pac4j session cookie.\n\nThis issue affects Apache Druid versions 0.18.0 through 30.0.0.\nSince the druid-pac4j extension is optional and disabled by default, Druid installations not using the druid-pac4j extension are not affected by this vulnerability.\n\nWhile we are not aware of a way to meaningfully exploit this flaw, we \nnevertheless recommend upgrading to version 30.0.1 or higher which fixes the issue\nand ensuring you have a strong \ndruid.auth.pac4j.cookiePassphrase as a precaution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45384" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/gr94fnp574plb50lsp8jw4smvgv1lbz1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T19:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-pwwp-3q7j-9mx8/GHSA-pwwp-3q7j-9mx8.json b/advisories/unreviewed/2024/09/GHSA-pwwp-3q7j-9mx8/GHSA-pwwp-3q7j-9mx8.json new file mode 100644 index 00000000000..80120adbb62 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pwwp-3q7j-9mx8/GHSA-pwwp-3q7j-9mx8.json @@ -0,0 +1,66 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwwp-3q7j-9mx8", + "modified": "2024-09-17T21:30:32Z", + "published": "2024-09-17T21:30:32Z", + "aliases": [ + "CVE-2024-8947" + ], + "details": "A vulnerability was found in MicroPython 1.22.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file py/objarray.c. The manipulation leads to use after free. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 1.23.0 is able to address this issue. The identifier of the patch is 4bed614e707c0644c06e117f848fa12605c711cd. It is recommended to upgrade the affected component. In micropython objarray component, when a bytes object is resized and copied into itself, it may reference memory that has already been freed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8947" + }, + { + "type": "WEB", + "url": "https://github.com/micropython/micropython/issues/13283" + }, + { + "type": "WEB", + "url": "https://github.com/micropython/micropython/issues/13283#issuecomment-1918479709" + }, + { + "type": "WEB", + "url": "https://github.com/micropython/micropython/commit/4bed614e707c0644c06e117f848fa12605c711cd" + }, + { + "type": "WEB", + "url": "https://github.com/micropython/micropython/releases/tag/v1.23.0" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.277765" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.277765" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.409316" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T19:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-r6hg-m6fm-hgwr/GHSA-r6hg-m6fm-hgwr.json b/advisories/unreviewed/2024/09/GHSA-r6hg-m6fm-hgwr/GHSA-r6hg-m6fm-hgwr.json new file mode 100644 index 00000000000..1853365c7bc --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-r6hg-m6fm-hgwr/GHSA-r6hg-m6fm-hgwr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6hg-m6fm-hgwr", + "modified": "2024-09-17T21:30:32Z", + "published": "2024-09-17T21:30:32Z", + "aliases": [ + "CVE-2024-43460" + ], + "details": "Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43460" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43460" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T19:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-rwxx-p542-9g8c/GHSA-rwxx-p542-9g8c.json b/advisories/unreviewed/2024/09/GHSA-rwxx-p542-9g8c/GHSA-rwxx-p542-9g8c.json index eb4fc5fffa4..c52c5c973c9 100644 --- a/advisories/unreviewed/2024/09/GHSA-rwxx-p542-9g8c/GHSA-rwxx-p542-9g8c.json +++ b/advisories/unreviewed/2024/09/GHSA-rwxx-p542-9g8c/GHSA-rwxx-p542-9g8c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rwxx-p542-9g8c", - "modified": "2024-09-17T00:31:03Z", + "modified": "2024-09-17T21:30:31Z", "published": "2024-09-17T00:31:03Z", "aliases": [ "CVE-2024-27879" ], "details": "The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18. An attacker may be able to cause unexpected app termination.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-119" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:48Z" diff --git a/advisories/unreviewed/2024/09/GHSA-v6p4-2h6v-crxc/GHSA-v6p4-2h6v-crxc.json b/advisories/unreviewed/2024/09/GHSA-v6p4-2h6v-crxc/GHSA-v6p4-2h6v-crxc.json new file mode 100644 index 00000000000..7ddeaba8394 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-v6p4-2h6v-crxc/GHSA-v6p4-2h6v-crxc.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6p4-2h6v-crxc", + "modified": "2024-09-17T21:30:33Z", + "published": "2024-09-17T21:30:33Z", + "aliases": [ + "CVE-2024-8951" + ], + "details": "A vulnerability classified as problematic was found in SourceCodester Resort Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file manage_fee.php. The manipulation of the argument toview leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8951" + }, + { + "type": "WEB", + "url": "https://github.com/gurudattch/CVEs/blob/main/Sourcecodester-Resort-Reservation-system-XSS.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.277777" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.277777" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.409586" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T20:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vh3x-525m-jp4r/GHSA-vh3x-525m-jp4r.json b/advisories/unreviewed/2024/09/GHSA-vh3x-525m-jp4r/GHSA-vh3x-525m-jp4r.json new file mode 100644 index 00000000000..92426ddcd07 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vh3x-525m-jp4r/GHSA-vh3x-525m-jp4r.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vh3x-525m-jp4r", + "modified": "2024-09-17T21:30:32Z", + "published": "2024-09-17T21:30:32Z", + "aliases": [ + "CVE-2024-8948" + ], + "details": "A vulnerability was found in MicroPython 1.23.0. It has been rated as critical. Affected by this issue is the function mpz_as_bytes of the file py/objint.c. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The patch is identified as 908ab1ceca15ee6fd0ef82ca4cba770a3ec41894. It is recommended to apply a patch to fix this issue. In micropython objint component, converting zero from int to bytes leads to heap buffer-overflow-write at mpz_as_bytes.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8948" + }, + { + "type": "WEB", + "url": "https://github.com/micropython/micropython/issues/13041" + }, + { + "type": "WEB", + "url": "https://github.com/micropython/micropython/commit/908ab1ceca15ee6fd0ef82ca4cba770a3ec41894" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.277766" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.277766" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.409317" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T19:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-wq22-3j46-hjmw/GHSA-wq22-3j46-hjmw.json b/advisories/unreviewed/2024/09/GHSA-wq22-3j46-hjmw/GHSA-wq22-3j46-hjmw.json new file mode 100644 index 00000000000..0d7c85f9b17 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-wq22-3j46-hjmw/GHSA-wq22-3j46-hjmw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wq22-3j46-hjmw", + "modified": "2024-09-17T21:30:33Z", + "published": "2024-09-17T21:30:33Z", + "aliases": [ + "CVE-2024-8906" + ], + "details": "Incorrect security UI in Downloads in Google Chrome prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8906" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_17.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/352681108" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xrx8-f378-fwph/GHSA-xrx8-f378-fwph.json b/advisories/unreviewed/2024/09/GHSA-xrx8-f378-fwph/GHSA-xrx8-f378-fwph.json new file mode 100644 index 00000000000..88fcfb610c3 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xrx8-f378-fwph/GHSA-xrx8-f378-fwph.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrx8-f378-fwph", + "modified": "2024-09-17T21:30:33Z", + "published": "2024-09-17T21:30:33Z", + "aliases": [ + "CVE-2024-8905" + ], + "details": "Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8905" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_17.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/359949835" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T21:15:13Z" + } +} \ No newline at end of file