Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-09-30 18:33:03 +00:00
parent ead83a8b15
commit a269c853a9
28 changed files with 499 additions and 24 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4473-7649-rj9x",
"modified": "2024-04-04T08:45:24Z",
"modified": "2024-09-30T18:31:35Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-3042"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4mm4-33wm-56jr",
"modified": "2024-07-26T15:31:48Z",
"modified": "2024-09-30T18:31:35Z",
"published": "2024-04-02T00:30:47Z",
"aliases": [
"CVE-2024-3165"
@@ -44,7 +44,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-522"
"CWE-522",
"CWE-532"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vhhq-fxg5-hvp8",
"modified": "2024-07-26T15:31:48Z",
"modified": "2024-09-30T18:31:35Z",
"published": "2024-04-02T00:30:46Z",
"aliases": [
"CVE-2024-3164"
@@ -44,6 +44,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-284",
"CWE-552"
],
"severity": "MODERATE",
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3vv9-hcm7-cvjm",
"modified": "2024-09-30T18:31:36Z",
"published": "2024-09-30T18:31:36Z",
"aliases": [
"CVE-2024-46475"
],
"details": "A reflected cross-site scripting (XSS) vulnerability on the homepage of Metronic Admin Dashboard Template v2.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46475"
},
{
"type": "WEB",
"url": "https://blog.csdn.net/qq_45744104/article/details/141903463"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-30T16:15:09Z"
}
}
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-125"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-74jr-9xc3-xccr",
"modified": "2024-09-23T09:30:46Z",
"modified": "2024-09-30T18:31:35Z",
"published": "2024-09-23T09:30:46Z",
"aliases": [
"CVE-2024-8606"
],
"details": "Bypass of two factor authentication in RestAPI in Checkmk < 2.3.0p16 and < 2.2.0p34 allows authenticated users to bypass two factor authentication",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8g8m-p65c-g42p",
"modified": "2024-09-25T03:30:36Z",
"modified": "2024-09-30T18:31:36Z",
"published": "2024-09-25T03:30:36Z",
"aliases": [
"CVE-2024-8877"
],
"details": "Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only limited to the SQLite database of measurement data.This issue affects Netman 204: through 4.05.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
@@ -36,7 +36,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-200"
"CWE-200",
"CWE-209"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f93h-pcqv-5rf7",
"modified": "2024-09-25T03:30:36Z",
"modified": "2024-09-30T18:31:36Z",
"published": "2024-09-25T03:30:36Z",
"aliases": [
"CVE-2024-46610"
],
"details": "An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a crafted POST request sent to the endpoint /User/ChangeUser/s in the ChangeUser function in UserController.java",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-25T01:15:44Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g2w3-jpfv-qffv",
"modified": "2024-09-18T21:30:48Z",
"modified": "2024-09-30T18:31:35Z",
"published": "2024-09-18T21:30:48Z",
"aliases": [
"CVE-2024-43025"
],
"details": "An HTML injection vulnerability in RWS MultiTrans v7.0.23324.2 and earlier allows attackers to alter the HTML-layout and possibly execute a phishing attack via a crafted payload injected into a sent e-mail.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-18T20:15:03Z"
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-grj2-m3x4-7f2m",
"modified": "2024-09-30T18:31:36Z",
"published": "2024-09-30T18:31:36Z",
"aliases": [
"CVE-2024-46869"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btintel_pcie: Allocate memory for driver private data\n\nFix driver not allocating memory for struct btintel_data which is used\nto store internal data.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46869"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/2b4545f08cc68d2fc835f5c490b36e0264750030"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/7ffaa200251871980af12e57649ad57c70bf0f43"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/fa9e1c1b1f389a8e6d987ac6cb3e2ba04f8ec875"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-30T16:15:09Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h496-35px-76wp",
"modified": "2024-09-30T18:31:36Z",
"published": "2024-09-30T18:31:36Z",
"aliases": [
"CVE-2024-46549"
],
"details": "An issue in the TP-Link MQTT Broker and API gateway of TP-Link Kasa KP125M v1.0.3 allows attackers to establish connections by impersonating devices owned by other users.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46549"
},
{
"type": "WEB",
"url": "https://github.com/Chapoly1305/tp-link-cve/blob/main/CVE-2024-46549.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-30T17:15:04Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hg56-xvvv-cj4c",
"modified": "2024-09-30T18:31:36Z",
"published": "2024-09-30T18:31:36Z",
"aliases": [
"CVE-2024-46548"
],
"details": "TP-Link Tapo P125M and Kasa KP125M v1.0.3 was discovered to improperly validate certificates, allowing attackers to eavesdrop on communications and access sensitive information via a man-in-the-middle attack.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46548"
},
{
"type": "WEB",
"url": "https://github.com/Chapoly1305/tp-link-cve/blob/main/CVE-2024-46548.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-30T17:15:04Z"
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hgwc-f2wf-xrf8",
"modified": "2024-09-30T18:31:36Z",
"published": "2024-09-30T18:31:36Z",
"aliases": [
"CVE-2024-46540"
],
"details": "A remote code execution (RCE) vulnerability in the component /admin/store.php of Emlog Pro before v2.3.15 allows attackers to use remote file downloads and self-extract fucntions to upload webshells to the target server, thereby obtaining system privileges.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46540"
},
{
"type": "WEB",
"url": "https://gist.github.com/microvorld/1c1ef9c3390a5d88a5ede9f9424a8bd2"
},
{
"type": "WEB",
"url": "https://github.com/emlog/emlog"
},
{
"type": "WEB",
"url": "https://github.com/microvorld/CVE-2024/blob/main/emlog.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-30T17:15:04Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hjpg-cfqw-g6jv",
"modified": "2024-09-30T18:31:36Z",
"published": "2024-09-30T18:31:36Z",
"aliases": [
"CVE-2024-42017"
],
"details": "An issue was discovered in Atos Eviden iCare 2.7.1 through 2.7.11. The application exposes a web interface locally. In the worst-case scenario, if the application is remotely accessible, it allows an attacker to execute arbitrary commands with system privilege on the endpoint hosting the application, without any authentication.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42017"
},
{
"type": "WEB",
"url": "https://eviden.com"
},
{
"type": "WEB",
"url": "https://support.bull.com/ols/product/security/psirt/security-bulletins/multiple-critical-vulnerabilities-in-icare-psirt-625-tlp-clear-version-0-7-cve-2024-42017/view"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-30T18:15:05Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hrqj-68hr-6cvc",
"modified": "2024-09-30T18:31:36Z",
"published": "2024-09-30T18:31:36Z",
"aliases": [
"CVE-2024-35495"
],
"details": "An Information Disclosure vulnerability in the Telemetry component in TP-Link Kasa KP125M V1.0.0 and Tapo P125M 1.0.0 Build 220930 Rel.143947 allows attackers to observe device state via observing network traffic.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35495"
},
{
"type": "WEB",
"url": "https://github.com/Chapoly1305/tp-link-cve/blob/main/CVE-2024-35495.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-30T18:15:05Z"
}
}
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pp67-vh85-488h",
"modified": "2024-09-30T18:31:36Z",
"published": "2024-09-30T18:31:36Z",
"aliases": [
"CVE-2024-45993"
],
"details": "Giflib Project v5.2.2 is vulnerable to a heap buffer overflow via gif2rgb.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45993"
},
{
"type": "WEB",
"url": "https://gitlab.com/mthandazo/project-pov"
},
{
"type": "WEB",
"url": "http://giflib.com"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-30T17:15:04Z"
}
}
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q586-q77x-838f",
"modified": "2024-09-23T21:30:48Z",
"modified": "2024-09-30T18:31:36Z",
"published": "2024-09-23T21:30:47Z",
"aliases": [
"CVE-2024-8263"
],
"details": "An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15, 3.12.9, 3.13.4, and 3.14.1. This vulnerability was reported via the GitHub Bug Bounty program.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"

Some files were not shown because too many files have changed in this diff Show More