From a46ab08dabea3aac9681302c66bf24d94277ca74 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 27 Aug 2024 00:32:54 +0000 Subject: [PATCH] Publish Advisories GHSA-2hx4-gpwf-5qv2 GHSA-4ggp-9p27-vq7h GHSA-7m3v-93h9-w27h GHSA-jm5g-jhgq-9vwh GHSA-px7f-qj7m-m4v6 GHSA-q9c4-rq7w-7q8x GHSA-qr26-2mpm-7j4x GHSA-329h-fcrp-rfh4 GHSA-42m4-gw8j-vjvg GHSA-cfq4-896j-74qc --- .../03/GHSA-2hx4-gpwf-5qv2/GHSA-2hx4-gpwf-5qv2.json | 11 +++++++---- .../03/GHSA-4ggp-9p27-vq7h/GHSA-4ggp-9p27-vq7h.json | 9 ++++++--- .../03/GHSA-7m3v-93h9-w27h/GHSA-7m3v-93h9-w27h.json | 11 +++++++---- .../03/GHSA-jm5g-jhgq-9vwh/GHSA-jm5g-jhgq-9vwh.json | 11 +++++++---- .../03/GHSA-px7f-qj7m-m4v6/GHSA-px7f-qj7m-m4v6.json | 11 +++++++---- .../03/GHSA-q9c4-rq7w-7q8x/GHSA-q9c4-rq7w-7q8x.json | 11 +++++++---- .../03/GHSA-qr26-2mpm-7j4x/GHSA-qr26-2mpm-7j4x.json | 11 +++++++---- .../08/GHSA-329h-fcrp-rfh4/GHSA-329h-fcrp-rfh4.json | 11 +++++++---- .../08/GHSA-42m4-gw8j-vjvg/GHSA-42m4-gw8j-vjvg.json | 11 +++++++---- .../08/GHSA-cfq4-896j-74qc/GHSA-cfq4-896j-74qc.json | 11 +++++++---- 10 files changed, 69 insertions(+), 39 deletions(-) diff --git a/advisories/unreviewed/2024/03/GHSA-2hx4-gpwf-5qv2/GHSA-2hx4-gpwf-5qv2.json b/advisories/unreviewed/2024/03/GHSA-2hx4-gpwf-5qv2/GHSA-2hx4-gpwf-5qv2.json index 13057c0beb5..38565212459 100644 --- a/advisories/unreviewed/2024/03/GHSA-2hx4-gpwf-5qv2/GHSA-2hx4-gpwf-5qv2.json +++ b/advisories/unreviewed/2024/03/GHSA-2hx4-gpwf-5qv2/GHSA-2hx4-gpwf-5qv2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2hx4-gpwf-5qv2", - "modified": "2024-03-14T03:31:14Z", + "modified": "2024-08-27T00:31:32Z", "published": "2024-03-14T03:31:14Z", "aliases": [ "CVE-2024-25228" ], "details": "Vinchin Backup and Recovery 7.2 and Earlier is vulnerable to Authenticated Remote Code Execution (RCE) via the getVerifydiyResult function in ManoeuvreHandler.class.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-14T02:15:50Z" diff --git a/advisories/unreviewed/2024/03/GHSA-4ggp-9p27-vq7h/GHSA-4ggp-9p27-vq7h.json b/advisories/unreviewed/2024/03/GHSA-4ggp-9p27-vq7h/GHSA-4ggp-9p27-vq7h.json index 6dd310058f5..2db4bea113f 100644 --- a/advisories/unreviewed/2024/03/GHSA-4ggp-9p27-vq7h/GHSA-4ggp-9p27-vq7h.json +++ b/advisories/unreviewed/2024/03/GHSA-4ggp-9p27-vq7h/GHSA-4ggp-9p27-vq7h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4ggp-9p27-vq7h", - "modified": "2024-03-04T03:30:26Z", + "modified": "2024-08-27T00:31:32Z", "published": "2024-03-04T03:30:26Z", "aliases": [ "CVE-2024-20036" ], "details": "In vdec, there is a possible permission bypass due to a permissions bypass. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08509508; Issue ID: ALPS08509508.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-04T03:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-7m3v-93h9-w27h/GHSA-7m3v-93h9-w27h.json b/advisories/unreviewed/2024/03/GHSA-7m3v-93h9-w27h/GHSA-7m3v-93h9-w27h.json index 91cdd03e723..ad30c4df59a 100644 --- a/advisories/unreviewed/2024/03/GHSA-7m3v-93h9-w27h/GHSA-7m3v-93h9-w27h.json +++ b/advisories/unreviewed/2024/03/GHSA-7m3v-93h9-w27h/GHSA-7m3v-93h9-w27h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7m3v-93h9-w27h", - "modified": "2024-03-09T06:30:41Z", + "modified": "2024-08-27T00:31:32Z", "published": "2024-03-09T06:30:41Z", "aliases": [ "CVE-2023-49341" ], "details": "An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to obtain sensitive information via cleartext credential storage in backup.htm component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-312" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-09T05:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-jm5g-jhgq-9vwh/GHSA-jm5g-jhgq-9vwh.json b/advisories/unreviewed/2024/03/GHSA-jm5g-jhgq-9vwh/GHSA-jm5g-jhgq-9vwh.json index 1ebf6261bb6..b0a4778dd23 100644 --- a/advisories/unreviewed/2024/03/GHSA-jm5g-jhgq-9vwh/GHSA-jm5g-jhgq-9vwh.json +++ b/advisories/unreviewed/2024/03/GHSA-jm5g-jhgq-9vwh/GHSA-jm5g-jhgq-9vwh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jm5g-jhgq-9vwh", - "modified": "2024-03-07T18:30:28Z", + "modified": "2024-08-27T00:31:32Z", "published": "2024-03-07T18:30:28Z", "aliases": [ "CVE-2024-27733" ], "details": "File Upload vulnerability in Byzro Network Smart s42 Management Platform v.S42 allows a local attacker to execute arbitrary code via the useratte/userattestation.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-07T17:15:13Z" diff --git a/advisories/unreviewed/2024/03/GHSA-px7f-qj7m-m4v6/GHSA-px7f-qj7m-m4v6.json b/advisories/unreviewed/2024/03/GHSA-px7f-qj7m-m4v6/GHSA-px7f-qj7m-m4v6.json index 6ae110161d8..2a9f378e2c5 100644 --- a/advisories/unreviewed/2024/03/GHSA-px7f-qj7m-m4v6/GHSA-px7f-qj7m-m4v6.json +++ b/advisories/unreviewed/2024/03/GHSA-px7f-qj7m-m4v6/GHSA-px7f-qj7m-m4v6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-px7f-qj7m-m4v6", - "modified": "2024-06-10T18:30:53Z", + "modified": "2024-08-27T00:31:32Z", "published": "2024-03-27T21:30:47Z", "aliases": [ "CVE-2024-28085" ], "details": "wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -81,9 +84,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-150" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-27T19:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-q9c4-rq7w-7q8x/GHSA-q9c4-rq7w-7q8x.json b/advisories/unreviewed/2024/03/GHSA-q9c4-rq7w-7q8x/GHSA-q9c4-rq7w-7q8x.json index dd4902b05d2..e70752606c8 100644 --- a/advisories/unreviewed/2024/03/GHSA-q9c4-rq7w-7q8x/GHSA-q9c4-rq7w-7q8x.json +++ b/advisories/unreviewed/2024/03/GHSA-q9c4-rq7w-7q8x/GHSA-q9c4-rq7w-7q8x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q9c4-rq7w-7q8x", - "modified": "2024-03-04T03:30:26Z", + "modified": "2024-08-27T00:31:32Z", "published": "2024-03-04T03:30:26Z", "aliases": [ "CVE-2024-20025" ], "details": "In da, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541686; Issue ID: ALPS08541686.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-04T03:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-qr26-2mpm-7j4x/GHSA-qr26-2mpm-7j4x.json b/advisories/unreviewed/2024/03/GHSA-qr26-2mpm-7j4x/GHSA-qr26-2mpm-7j4x.json index 46bd0959667..8d5cf26f3d9 100644 --- a/advisories/unreviewed/2024/03/GHSA-qr26-2mpm-7j4x/GHSA-qr26-2mpm-7j4x.json +++ b/advisories/unreviewed/2024/03/GHSA-qr26-2mpm-7j4x/GHSA-qr26-2mpm-7j4x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qr26-2mpm-7j4x", - "modified": "2024-03-04T03:30:25Z", + "modified": "2024-08-27T00:31:32Z", "published": "2024-03-04T03:30:25Z", "aliases": [ "CVE-2024-20017" ], "details": "In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation Patch ID: WCNCR00350938; Issue ID: MSV-1132.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-04T03:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-329h-fcrp-rfh4/GHSA-329h-fcrp-rfh4.json b/advisories/unreviewed/2024/08/GHSA-329h-fcrp-rfh4/GHSA-329h-fcrp-rfh4.json index 4976cfbdc48..855ec2b9e5c 100644 --- a/advisories/unreviewed/2024/08/GHSA-329h-fcrp-rfh4/GHSA-329h-fcrp-rfh4.json +++ b/advisories/unreviewed/2024/08/GHSA-329h-fcrp-rfh4/GHSA-329h-fcrp-rfh4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-329h-fcrp-rfh4", - "modified": "2024-08-26T21:30:33Z", + "modified": "2024-08-27T00:31:33Z", "published": "2024-08-26T21:30:33Z", "aliases": [ "CVE-2024-42906" ], "details": "TestLink before v.1.9.20 is vulnerable to Cross Site Scripting (XSS) via the pop-up on upload file. When uploading a file, the XSS payload can be entered into the file name.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T20:15:07Z" diff --git a/advisories/unreviewed/2024/08/GHSA-42m4-gw8j-vjvg/GHSA-42m4-gw8j-vjvg.json b/advisories/unreviewed/2024/08/GHSA-42m4-gw8j-vjvg/GHSA-42m4-gw8j-vjvg.json index d7c3b4db827..5e1aa304c84 100644 --- a/advisories/unreviewed/2024/08/GHSA-42m4-gw8j-vjvg/GHSA-42m4-gw8j-vjvg.json +++ b/advisories/unreviewed/2024/08/GHSA-42m4-gw8j-vjvg/GHSA-42m4-gw8j-vjvg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-42m4-gw8j-vjvg", - "modified": "2024-08-26T21:30:34Z", + "modified": "2024-08-27T00:31:33Z", "published": "2024-08-26T21:30:34Z", "aliases": [ "CVE-2024-44793" ], "details": "A cross-site scripting (XSS) vulnerability in the component /managers/multiple_freeleech.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the torrents parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T20:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-cfq4-896j-74qc/GHSA-cfq4-896j-74qc.json b/advisories/unreviewed/2024/08/GHSA-cfq4-896j-74qc/GHSA-cfq4-896j-74qc.json index 6ad63acf605..123012f24c6 100644 --- a/advisories/unreviewed/2024/08/GHSA-cfq4-896j-74qc/GHSA-cfq4-896j-74qc.json +++ b/advisories/unreviewed/2024/08/GHSA-cfq4-896j-74qc/GHSA-cfq4-896j-74qc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cfq4-896j-74qc", - "modified": "2024-08-26T21:30:34Z", + "modified": "2024-08-27T00:31:33Z", "published": "2024-08-26T21:30:34Z", "aliases": [ "CVE-2024-44795" ], "details": "A cross-site scripting (XSS) vulnerability in the component /login/disabled.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T20:15:08Z"