From a3b27a11b5a7289bda6aa2daabae546af2d052e1 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 1 Jul 2024 21:32:00 +0000 Subject: [PATCH] Publish Advisories GHSA-869c-j7wc-8jqv GHSA-gh4x-qv3p-m9pm GHSA-2wcw-rcf9-qm36 GHSA-2wm2-45c2-f92h GHSA-2x8c-95vh-gfv4 GHSA-463r-p989-2f9j GHSA-4fr2-p4v7-6hwq GHSA-9v2f-6vcg-3hgv GHSA-f3w2-7g86-vjj4 GHSA-fjcc-r94c-wxr8 GHSA-fpq9-w5cw-5hf8 GHSA-hqwr-j99j-r27h GHSA-hrh5-4ffc-228q GHSA-pf44-j75v-mhr8 GHSA-phjg-7fch-3c2f GHSA-q935-8vhv-gg93 GHSA-x6g9-g4wf-qrf7 GHSA-x6xm-h7hm-7p9q GHSA-x84h-4cj8-32mv --- .../GHSA-869c-j7wc-8jqv.json | 33 +++++++++++--- .../GHSA-gh4x-qv3p-m9pm.json | 25 ++++++++--- .../GHSA-2wcw-rcf9-qm36.json | 35 +++++++++++++++ .../GHSA-2wm2-45c2-f92h.json | 42 ++++++++++++++++++ .../GHSA-2x8c-95vh-gfv4.json | 10 ++++- .../GHSA-463r-p989-2f9j.json | 35 +++++++++++++++ .../GHSA-4fr2-p4v7-6hwq.json | 35 +++++++++++++++ .../GHSA-9v2f-6vcg-3hgv.json | 35 +++++++++++++++ .../GHSA-f3w2-7g86-vjj4.json | 35 +++++++++++++++ .../GHSA-fjcc-r94c-wxr8.json | 35 +++++++++++++++ .../GHSA-fpq9-w5cw-5hf8.json | 35 +++++++++++++++ .../GHSA-hqwr-j99j-r27h.json | 42 ++++++++++++++++++ .../GHSA-hrh5-4ffc-228q.json | 35 +++++++++++++++ .../GHSA-pf44-j75v-mhr8.json | 35 +++++++++++++++ .../GHSA-phjg-7fch-3c2f.json | 35 +++++++++++++++ .../GHSA-q935-8vhv-gg93.json | 35 +++++++++++++++ .../GHSA-x6g9-g4wf-qrf7.json | 35 +++++++++++++++ .../GHSA-x6xm-h7hm-7p9q.json | 43 +++++++++++++++++++ .../GHSA-x84h-4cj8-32mv.json | 35 +++++++++++++++ 19 files changed, 638 insertions(+), 12 deletions(-) rename advisories/{unreviewed => github-reviewed}/2024/06/GHSA-869c-j7wc-8jqv/GHSA-869c-j7wc-8jqv.json (67%) rename advisories/{unreviewed => github-reviewed}/2024/07/GHSA-gh4x-qv3p-m9pm/GHSA-gh4x-qv3p-m9pm.json (60%) create mode 100644 advisories/unreviewed/2024/07/GHSA-2wcw-rcf9-qm36/GHSA-2wcw-rcf9-qm36.json create mode 100644 advisories/unreviewed/2024/07/GHSA-2wm2-45c2-f92h/GHSA-2wm2-45c2-f92h.json create mode 100644 advisories/unreviewed/2024/07/GHSA-463r-p989-2f9j/GHSA-463r-p989-2f9j.json create mode 100644 advisories/unreviewed/2024/07/GHSA-4fr2-p4v7-6hwq/GHSA-4fr2-p4v7-6hwq.json create mode 100644 advisories/unreviewed/2024/07/GHSA-9v2f-6vcg-3hgv/GHSA-9v2f-6vcg-3hgv.json create mode 100644 advisories/unreviewed/2024/07/GHSA-f3w2-7g86-vjj4/GHSA-f3w2-7g86-vjj4.json create mode 100644 advisories/unreviewed/2024/07/GHSA-fjcc-r94c-wxr8/GHSA-fjcc-r94c-wxr8.json create mode 100644 advisories/unreviewed/2024/07/GHSA-fpq9-w5cw-5hf8/GHSA-fpq9-w5cw-5hf8.json create mode 100644 advisories/unreviewed/2024/07/GHSA-hqwr-j99j-r27h/GHSA-hqwr-j99j-r27h.json create mode 100644 advisories/unreviewed/2024/07/GHSA-hrh5-4ffc-228q/GHSA-hrh5-4ffc-228q.json create mode 100644 advisories/unreviewed/2024/07/GHSA-pf44-j75v-mhr8/GHSA-pf44-j75v-mhr8.json create mode 100644 advisories/unreviewed/2024/07/GHSA-phjg-7fch-3c2f/GHSA-phjg-7fch-3c2f.json create mode 100644 advisories/unreviewed/2024/07/GHSA-q935-8vhv-gg93/GHSA-q935-8vhv-gg93.json create mode 100644 advisories/unreviewed/2024/07/GHSA-x6g9-g4wf-qrf7/GHSA-x6g9-g4wf-qrf7.json create mode 100644 advisories/unreviewed/2024/07/GHSA-x6xm-h7hm-7p9q/GHSA-x6xm-h7hm-7p9q.json create mode 100644 advisories/unreviewed/2024/07/GHSA-x84h-4cj8-32mv/GHSA-x84h-4cj8-32mv.json diff --git a/advisories/unreviewed/2024/06/GHSA-869c-j7wc-8jqv/GHSA-869c-j7wc-8jqv.json b/advisories/github-reviewed/2024/06/GHSA-869c-j7wc-8jqv/GHSA-869c-j7wc-8jqv.json similarity index 67% rename from advisories/unreviewed/2024/06/GHSA-869c-j7wc-8jqv/GHSA-869c-j7wc-8jqv.json rename to advisories/github-reviewed/2024/06/GHSA-869c-j7wc-8jqv/GHSA-869c-j7wc-8jqv.json index 22be640347d..4c380f9c3cf 100644 --- a/advisories/unreviewed/2024/06/GHSA-869c-j7wc-8jqv/GHSA-869c-j7wc-8jqv.json +++ b/advisories/github-reviewed/2024/06/GHSA-869c-j7wc-8jqv/GHSA-869c-j7wc-8jqv.json @@ -1,17 +1,36 @@ { "schema_version": "1.4.0", "id": "GHSA-869c-j7wc-8jqv", - "modified": "2024-06-29T06:31:40Z", + "modified": "2024-07-01T21:30:24Z", "published": "2024-06-29T06:31:40Z", "aliases": [ "CVE-2019-25211" ], + "summary": "Gin mishandles a wildcard at the end of an origin string", "details": "parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g., https://example.community/* is allowed when the intention is that only https://example.com/* should be allowed, and http://localhost.example.com/* is allowed when the intention is that only http://localhost/* should be allowed.", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "Go", + "name": "github.com/gin-gonic/gin" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.6.0" + } + ] + } + ] + } ], "references": [ { @@ -37,15 +56,19 @@ { "type": "WEB", "url": "https://github.com/gin-contrib/cors/releases/tag/v1.6.0" + }, + { + "type": "PACKAGE", + "url": "https://github.com/gin-gonic/gin" } ], "database_specific": { "cwe_ids": [ ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-07-01T21:30:24Z", "nvd_published_at": "2024-06-29T00:15:02Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-gh4x-qv3p-m9pm/GHSA-gh4x-qv3p-m9pm.json b/advisories/github-reviewed/2024/07/GHSA-gh4x-qv3p-m9pm/GHSA-gh4x-qv3p-m9pm.json similarity index 60% rename from advisories/unreviewed/2024/07/GHSA-gh4x-qv3p-m9pm/GHSA-gh4x-qv3p-m9pm.json rename to advisories/github-reviewed/2024/07/GHSA-gh4x-qv3p-m9pm/GHSA-gh4x-qv3p-m9pm.json index 9cddbe89a13..c1015c1712b 100644 --- a/advisories/unreviewed/2024/07/GHSA-gh4x-qv3p-m9pm/GHSA-gh4x-qv3p-m9pm.json +++ b/advisories/github-reviewed/2024/07/GHSA-gh4x-qv3p-m9pm/GHSA-gh4x-qv3p-m9pm.json @@ -1,17 +1,26 @@ { "schema_version": "1.4.0", "id": "GHSA-gh4x-qv3p-m9pm", - "modified": "2024-07-01T15:32:11Z", + "modified": "2024-07-01T21:30:34Z", "published": "2024-07-01T15:32:11Z", "aliases": [ "CVE-2024-38991" ], + "summary": "akbr patch-into was discovered to contain a prototype pollution via the function patchInto", "details": "akbr patch-into v1.0.1 was discovered to contain a prototype pollution via the function patchInto. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "npm", + "name": "@akbr/patch-into" + }, + "versions": [ + "1.0.1" + ] + } ], "references": [ { @@ -21,15 +30,19 @@ { "type": "WEB", "url": "https://gist.github.com/mestrtee/8851413e3b33a96f191f0e9c81706532" + }, + { + "type": "PACKAGE", + "url": "github.com/akbr/patch-into" } ], "database_specific": { "cwe_ids": [ - + "CWE-1321" ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-07-01T21:30:34Z", "nvd_published_at": "2024-07-01T13:15:04Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-2wcw-rcf9-qm36/GHSA-2wcw-rcf9-qm36.json b/advisories/unreviewed/2024/07/GHSA-2wcw-rcf9-qm36/GHSA-2wcw-rcf9-qm36.json new file mode 100644 index 00000000000..4278010f7c4 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-2wcw-rcf9-qm36/GHSA-2wcw-rcf9-qm36.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2wcw-rcf9-qm36", + "modified": "2024-07-01T21:31:15Z", + "published": "2024-07-01T21:31:15Z", + "aliases": [ + "CVE-2024-39573" + ], + "details": "Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy.\nUsers are recommended to upgrade to version 2.4.60, which fixes this issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39573" + }, + { + "type": "WEB", + "url": "https://httpd.apache.org/security/vulnerabilities_24.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-01T19:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-2wm2-45c2-f92h/GHSA-2wm2-45c2-f92h.json b/advisories/unreviewed/2024/07/GHSA-2wm2-45c2-f92h/GHSA-2wm2-45c2-f92h.json new file mode 100644 index 00000000000..409f70486ac --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-2wm2-45c2-f92h/GHSA-2wm2-45c2-f92h.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2wm2-45c2-f92h", + "modified": "2024-07-01T21:31:15Z", + "published": "2024-07-01T21:31:15Z", + "aliases": [ + "CVE-2024-28200" + ], + "details": "The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2.\n\nThis vulnerability was discovered through internal N-central source code review and N-able has not observed any exploitation in the wild.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28200" + }, + { + "type": "WEB", + "url": "https://documentation.n-able.com/N-central/Release_Notes/GA/Content/2024.2%20Release%20Notes.htm" + }, + { + "type": "WEB", + "url": "https://me.n-able.com/s/security-advisory/aArVy0000000673KAA/cve202428200-ncentral-authentication-bypass" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-01T21:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json b/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json index d3da0e1cd6a..709c9534a7e 100644 --- a/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json +++ b/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2x8c-95vh-gfv4", - "modified": "2024-07-01T18:32:40Z", + "modified": "2024-07-01T21:31:14Z", "published": "2024-07-01T15:32:33Z", "aliases": [ "CVE-2024-6387" @@ -53,10 +53,18 @@ "type": "WEB", "url": "https://ubuntu.com/security/CVE-2024-6387" }, + { + "type": "WEB", + "url": "https://stackdiary.com/openssh-race-condition-in-sshd-allows-remote-code-execution" + }, { "type": "WEB", "url": "https://security-tracker.debian.org/tracker/CVE-2024-6387" }, + { + "type": "WEB", + "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0010" + }, { "type": "WEB", "url": "https://news.ycombinator.com/item?id=40843778" diff --git a/advisories/unreviewed/2024/07/GHSA-463r-p989-2f9j/GHSA-463r-p989-2f9j.json b/advisories/unreviewed/2024/07/GHSA-463r-p989-2f9j/GHSA-463r-p989-2f9j.json new file mode 100644 index 00000000000..dad5e136b4b --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-463r-p989-2f9j/GHSA-463r-p989-2f9j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-463r-p989-2f9j", + "modified": "2024-07-01T21:31:13Z", + "published": "2024-07-01T21:31:13Z", + "aliases": [ + "CVE-2024-36387" + ], + "details": "Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36387" + }, + { + "type": "WEB", + "url": "https://httpd.apache.org/security/vulnerabilities_24.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-01T19:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-4fr2-p4v7-6hwq/GHSA-4fr2-p4v7-6hwq.json b/advisories/unreviewed/2024/07/GHSA-4fr2-p4v7-6hwq/GHSA-4fr2-p4v7-6hwq.json new file mode 100644 index 00000000000..8309de5ff94 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-4fr2-p4v7-6hwq/GHSA-4fr2-p4v7-6hwq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fr2-p4v7-6hwq", + "modified": "2024-07-01T21:31:16Z", + "published": "2024-07-01T21:31:16Z", + "aliases": [ + "CVE-2024-32228" + ], + "details": "FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32228" + }, + { + "type": "WEB", + "url": "https://trac.ffmpeg.org/ticket/10951" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-01T21:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-9v2f-6vcg-3hgv/GHSA-9v2f-6vcg-3hgv.json b/advisories/unreviewed/2024/07/GHSA-9v2f-6vcg-3hgv/GHSA-9v2f-6vcg-3hgv.json new file mode 100644 index 00000000000..3485cd388b7 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-9v2f-6vcg-3hgv/GHSA-9v2f-6vcg-3hgv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9v2f-6vcg-3hgv", + "modified": "2024-07-01T21:31:15Z", + "published": "2024-07-01T21:31:15Z", + "aliases": [ + "CVE-2024-39236" + ], + "details": "Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. This vulnerability is triggered via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39236" + }, + { + "type": "WEB", + "url": "https://github.com/Aaron911/PoC/blob/main/Gradio.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-01T19:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-f3w2-7g86-vjj4/GHSA-f3w2-7g86-vjj4.json b/advisories/unreviewed/2024/07/GHSA-f3w2-7g86-vjj4/GHSA-f3w2-7g86-vjj4.json new file mode 100644 index 00000000000..74b587a32d9 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-f3w2-7g86-vjj4/GHSA-f3w2-7g86-vjj4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3w2-7g86-vjj4", + "modified": "2024-07-01T21:31:15Z", + "published": "2024-07-01T21:31:15Z", + "aliases": [ + "CVE-2024-39251" + ], + "details": "An issue in the component ControlCenter.sys/ControlCenter64.sys of ThundeRobot Control Center v2.0.0.10 allows attackers to access sensitive information, execute arbitrary code, or escalate privileges via sending crafted IOCTL requests.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39251" + }, + { + "type": "WEB", + "url": "https://github.com/Souhardya/Exploit-PoCs/tree/main/ThundeRobot_Control_center" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-01T19:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-fjcc-r94c-wxr8/GHSA-fjcc-r94c-wxr8.json b/advisories/unreviewed/2024/07/GHSA-fjcc-r94c-wxr8/GHSA-fjcc-r94c-wxr8.json new file mode 100644 index 00000000000..54e77832145 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-fjcc-r94c-wxr8/GHSA-fjcc-r94c-wxr8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjcc-r94c-wxr8", + "modified": "2024-07-01T21:31:14Z", + "published": "2024-07-01T21:31:14Z", + "aliases": [ + "CVE-2024-38472" + ], + "details": "SSRF in Apache HTTP Server on Windows allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests or content \nUsers are recommended to upgrade to version 2.4.60 which fixes this issue.  Note: Existing configurations that access UNC paths will have to configure new directive \"UNCList\" to allow access during request processing.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38472" + }, + { + "type": "WEB", + "url": "https://httpd.apache.org/security/vulnerabilities_24.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-01T19:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-fpq9-w5cw-5hf8/GHSA-fpq9-w5cw-5hf8.json b/advisories/unreviewed/2024/07/GHSA-fpq9-w5cw-5hf8/GHSA-fpq9-w5cw-5hf8.json new file mode 100644 index 00000000000..8b9bea1907c --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-fpq9-w5cw-5hf8/GHSA-fpq9-w5cw-5hf8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpq9-w5cw-5hf8", + "modified": "2024-07-01T21:31:14Z", + "published": "2024-07-01T21:31:14Z", + "aliases": [ + "CVE-2024-38476" + ], + "details": "Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable.\n\nUsers are recommended to upgrade to version 2.4.60, which fixes this issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38476" + }, + { + "type": "WEB", + "url": "https://httpd.apache.org/security/vulnerabilities_24.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-829" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-01T19:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-hqwr-j99j-r27h/GHSA-hqwr-j99j-r27h.json b/advisories/unreviewed/2024/07/GHSA-hqwr-j99j-r27h/GHSA-hqwr-j99j-r27h.json new file mode 100644 index 00000000000..14186b9b0cd --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-hqwr-j99j-r27h/GHSA-hqwr-j99j-r27h.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqwr-j99j-r27h", + "modified": "2024-07-01T21:31:16Z", + "published": "2024-07-01T21:31:16Z", + "aliases": [ + "CVE-2024-5322" + ], + "details": "The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO, which can lead to authentication bypass.\n \nThis vulnerability is present in all Entra-supported deployments of N-central prior to 2024.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5322" + }, + { + "type": "WEB", + "url": "https://documentation.n-able.com/N-central/Release_Notes/GA/Content/2024.3%20Release%20Notes.htm" + }, + { + "type": "WEB", + "url": "https://me.n-able.com/s/security-advisory/aArVy0000000BgDKAU/cve20245322-ncentral-authentication-bypass-via-session-rebinding" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-01T21:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-hrh5-4ffc-228q/GHSA-hrh5-4ffc-228q.json b/advisories/unreviewed/2024/07/GHSA-hrh5-4ffc-228q/GHSA-hrh5-4ffc-228q.json new file mode 100644 index 00000000000..84df97e93b2 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-hrh5-4ffc-228q/GHSA-hrh5-4ffc-228q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrh5-4ffc-228q", + "modified": "2024-07-01T21:31:14Z", + "published": "2024-07-01T21:31:14Z", + "aliases": [ + "CVE-2024-38473" + ], + "details": "Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests.\nUsers are recommended to upgrade to version 2.4.60, which fixes this issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38473" + }, + { + "type": "WEB", + "url": "https://httpd.apache.org/security/vulnerabilities_24.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-116" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-01T19:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-pf44-j75v-mhr8/GHSA-pf44-j75v-mhr8.json b/advisories/unreviewed/2024/07/GHSA-pf44-j75v-mhr8/GHSA-pf44-j75v-mhr8.json new file mode 100644 index 00000000000..d2321671041 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-pf44-j75v-mhr8/GHSA-pf44-j75v-mhr8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf44-j75v-mhr8", + "modified": "2024-07-01T21:31:14Z", + "published": "2024-07-01T21:31:14Z", + "aliases": [ + "CVE-2024-38475" + ], + "details": "Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. \n\nSubstitutions in server context that use a backreferences or variables as the first segment of the substitution are affected.  Some unsafe RewiteRules will be broken by this change and the rewrite flag \"UnsafePrefixStat\" can be used to opt back in once ensuring the substitution is appropriately constrained.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38475" + }, + { + "type": "WEB", + "url": "https://httpd.apache.org/security/vulnerabilities_24.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-116" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-01T19:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-phjg-7fch-3c2f/GHSA-phjg-7fch-3c2f.json b/advisories/unreviewed/2024/07/GHSA-phjg-7fch-3c2f/GHSA-phjg-7fch-3c2f.json new file mode 100644 index 00000000000..39571fb4fc3 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-phjg-7fch-3c2f/GHSA-phjg-7fch-3c2f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phjg-7fch-3c2f", + "modified": "2024-07-01T21:31:14Z", + "published": "2024-07-01T21:31:14Z", + "aliases": [ + "CVE-2024-38477" + ], + "details": "null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request.\nUsers are recommended to upgrade to version 2.4.60, which fixes this issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38477" + }, + { + "type": "WEB", + "url": "https://httpd.apache.org/security/vulnerabilities_24.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-01T19:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-q935-8vhv-gg93/GHSA-q935-8vhv-gg93.json b/advisories/unreviewed/2024/07/GHSA-q935-8vhv-gg93/GHSA-q935-8vhv-gg93.json new file mode 100644 index 00000000000..7826773ece2 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-q935-8vhv-gg93/GHSA-q935-8vhv-gg93.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q935-8vhv-gg93", + "modified": "2024-07-01T21:31:16Z", + "published": "2024-07-01T21:31:16Z", + "aliases": [ + "CVE-2024-32230" + ], + "details": "FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a negative-size-param bug at libavcodec/mpegvideo_enc.c:1216:21 in load_input_picture in FFmpeg7.0", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32230" + }, + { + "type": "WEB", + "url": "https://trac.ffmpeg.org/ticket/10952" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-01T21:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-x6g9-g4wf-qrf7/GHSA-x6g9-g4wf-qrf7.json b/advisories/unreviewed/2024/07/GHSA-x6g9-g4wf-qrf7/GHSA-x6g9-g4wf-qrf7.json new file mode 100644 index 00000000000..50b2a433fa5 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-x6g9-g4wf-qrf7/GHSA-x6g9-g4wf-qrf7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6g9-g4wf-qrf7", + "modified": "2024-07-01T21:31:14Z", + "published": "2024-07-01T21:31:14Z", + "aliases": [ + "CVE-2024-38474" + ], + "details": "Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in\ndirectories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI.\n\nUsers are recommended to upgrade to version 2.4.60, which fixes this issue.\n\nSome RewriteRules that capture and substitute unsafely will now fail unless rewrite flag \"UnsafeAllow3F\" is specified.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38474" + }, + { + "type": "WEB", + "url": "https://httpd.apache.org/security/vulnerabilities_24.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-116" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-01T19:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-x6xm-h7hm-7p9q/GHSA-x6xm-h7hm-7p9q.json b/advisories/unreviewed/2024/07/GHSA-x6xm-h7hm-7p9q/GHSA-x6xm-h7hm-7p9q.json new file mode 100644 index 00000000000..aac37c9be3a --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-x6xm-h7hm-7p9q/GHSA-x6xm-h7hm-7p9q.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6xm-h7hm-7p9q", + "modified": "2024-07-01T21:31:15Z", + "published": "2024-07-01T21:31:15Z", + "aliases": [ + "CVE-2024-39249" + ], + "details": "Async <= 2.6.4 and <= 3.2.5 are vulnerable to ReDoS (Regular Expression Denial of Service) while parsing function in autoinject function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39249" + }, + { + "type": "WEB", + "url": "https://github.com/caolan/async/blob/v3.2.5/lib/autoInject.js#L41" + }, + { + "type": "WEB", + "url": "https://github.com/caolan/async/blob/v3.2.5/lib/autoInject.js#L6" + }, + { + "type": "WEB", + "url": "https://github.com/zunak/CVE-2024-39249" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-01T20:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-x84h-4cj8-32mv/GHSA-x84h-4cj8-32mv.json b/advisories/unreviewed/2024/07/GHSA-x84h-4cj8-32mv/GHSA-x84h-4cj8-32mv.json new file mode 100644 index 00000000000..fe4a2d8d2a8 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-x84h-4cj8-32mv/GHSA-x84h-4cj8-32mv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x84h-4cj8-32mv", + "modified": "2024-07-01T21:31:16Z", + "published": "2024-07-01T21:31:16Z", + "aliases": [ + "CVE-2024-32229" + ], + "details": "FFmpeg 7.0 contains a heap-buffer-overflow at libavfilter/vf_tiltandshift.c:189:5 in copy_column.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32229" + }, + { + "type": "WEB", + "url": "https://trac.ffmpeg.org/ticket/10950" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-01T21:15:03Z" + } +} \ No newline at end of file