Publish Advisories

GHSA-v64w-96p6-fx7w
GHSA-8x43-mjg3-6x36
GHSA-mx4m-rmpq-fcw6
GHSA-pqfp-6wmf-23ch
GHSA-3hfr-246f-6fxv
GHSA-4xp8-3mc6-r83c
GHSA-57rg-p28x-x2f6
GHSA-6vc2-fw8r-6xjf
GHSA-f3f2-9wgq-fw79
GHSA-mw76-72hw-4357
GHSA-p53h-fpw3-ffwh
GHSA-v3mg-77fv-q6qh
GHSA-vqjx-886g-c3rv
GHSA-xm2p-hxq8-xj3q
This commit is contained in:
advisory-database[bot]
2024-03-05 18:32:51 +00:00
parent 99c652a4fd
commit a1128bcc5f
14 changed files with 389 additions and 5 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v64w-96p6-fx7w",
"modified": "2022-07-27T21:38:21Z",
"modified": "2024-03-05T18:31:42Z",
"published": "2022-05-17T04:48:11Z",
"aliases": [
"CVE-2013-1777"
@@ -37,6 +37,14 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2013-1777"
},
{
"type": "WEB",
"url": "https://github.com/apache/geronimo/commit/ee031c5e62b0d358250d06c2aa6722518579a6c5"
},
{
"type": "PACKAGE",
"url": "https://github.com/apache/geronimo"
},
{
"type": "WEB",
"url": "https://issues.apache.org/jira/browse/GERONIMO-6477"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8x43-mjg3-6x36",
"modified": "2023-11-04T06:34:05Z",
"modified": "2024-03-05T18:31:11Z",
"published": "2023-10-10T15:30:50Z",
"aliases": [
"CVE-2023-43787"
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2242254"
},
{
"type": "WEB",
"url": "https://jfrog.com/blog/xorg-libx11-vulns-cve-2023-43786-cve-2023-43787-part-two"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231103-0006"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mx4m-rmpq-fcw6",
"modified": "2024-02-13T21:30:29Z",
"modified": "2024-03-05T18:31:13Z",
"published": "2024-02-13T21:30:29Z",
"aliases": [
"CVE-2024-1369"
@@ -40,7 +40,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-20"
"CWE-20",
"CWE-77"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -40,7 +40,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-20"
"CWE-20",
"CWE-77"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3hfr-246f-6fxv",
"modified": "2024-03-05T18:31:14Z",
"published": "2024-03-05T18:31:14Z",
"aliases": [
"CVE-2024-22255"
],
"details": "VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process.  \n\n\n\n\n\n\n\n\n\n\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22255"
},
{
"type": "WEB",
"url": "https://www.vmware.com/security/advisories/VMSA-2024-0006.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-05T18:15:48Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4xp8-3mc6-r83c",
"modified": "2024-03-05T18:31:14Z",
"published": "2024-03-05T18:31:13Z",
"aliases": [
"CVE-2024-22252"
],
"details": "VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22252"
},
{
"type": "WEB",
"url": "https://www.vmware.com/security/advisories/VMSA-2024-0006.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-05T18:15:47Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-57rg-p28x-x2f6",
"modified": "2024-03-05T18:31:14Z",
"published": "2024-03-05T18:31:14Z",
"aliases": [
"CVE-2024-22253"
],
"details": "VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22253"
},
{
"type": "WEB",
"url": "https://www.vmware.com/security/advisories/VMSA-2024-0006.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-05T18:15:47Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6vc2-fw8r-6xjf",
"modified": "2024-03-05T18:31:13Z",
"published": "2024-03-05T18:31:13Z",
"aliases": [
"CVE-2024-27565"
],
"details": "A Server-Side Request Forgery (SSRF) in weixin.php of ChatGPT-wechat-personal commit a0857f6 allows attackers to force the application to make arbitrary requests.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27565"
},
{
"type": "WEB",
"url": "https://github.com/dirk1983/chatgpt-wechat-personal/issues/4"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-05T17:15:07Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f3f2-9wgq-fw79",
"modified": "2024-03-05T18:31:13Z",
"published": "2024-03-05T18:31:13Z",
"aliases": [
"CVE-2022-46088"
],
"details": "Online Flight Booking Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the feedback form.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46088"
},
{
"type": "WEB",
"url": "https://github.com/ASR511-OO7/CVE-2022-46088/blob/main/CVE-36"
},
{
"type": "WEB",
"url": "https://packetstormsecurity.com"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-05T16:15:49Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mw76-72hw-4357",
"modified": "2024-03-05T18:31:14Z",
"published": "2024-03-05T18:31:14Z",
"aliases": [
"CVE-2024-22254"
],
"details": "VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds write leading to an escape of the sandbox.\n\n\n\n\n\n\n\n\n\n\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22254"
},
{
"type": "WEB",
"url": "https://www.vmware.com/security/advisories/VMSA-2024-0006.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-05T18:15:48Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p53h-fpw3-ffwh",
"modified": "2024-03-05T18:31:13Z",
"published": "2024-03-05T18:31:13Z",
"aliases": [
"CVE-2024-27561"
],
"details": "A Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the installThemePlugin parameter.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27561"
},
{
"type": "WEB",
"url": "https://github.com/zer0yu/CVE_Request/blob/master/WonderCMS/wondercms_installUpdateThemePluginAction_plugins.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-05T17:15:06Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v3mg-77fv-q6qh",
"modified": "2024-03-05T18:31:13Z",
"published": "2024-03-05T18:31:13Z",
"aliases": [
"CVE-2024-24098"
],
"details": "Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection via the News Feed.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24098"
},
{
"type": "WEB",
"url": "https://code-projects.org/scholars-tracking-system-in-php-with-source-code"
},
{
"type": "WEB",
"url": "https://github.com/ASR511-OO7/CVE-2024-24098/blob/main/CVE-13"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-05T16:15:49Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vqjx-886g-c3rv",
"modified": "2024-03-05T18:31:13Z",
"published": "2024-03-05T18:31:13Z",
"aliases": [
"CVE-2024-27563"
],
"details": "A Server-Side Request Forgery (SSRF) in the getFileFromRepo function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the pluginThemeUrl parameter.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27563"
},
{
"type": "WEB",
"url": "https://github.com/zer0yu/CVE_Request/blob/master/WonderCMS/wondercms_pluginThemeUrl.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-05T17:15:06Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xm2p-hxq8-xj3q",
"modified": "2024-03-05T18:31:13Z",
"published": "2024-03-05T18:31:13Z",
"aliases": [
"CVE-2024-27564"
],
"details": "A Server-Side Request Forgery (SSRF) in pictureproxy.php of ChatGPT commit f9f4bbc allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the urlparameter.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27564"
},
{
"type": "WEB",
"url": "https://github.com/dirk1983/chatgpt/issues/114"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-05T17:15:06Z"
}
}