Publish Advisories

GHSA-23f9-rm56-9hw4
GHSA-2cvv-v79w-fm34
GHSA-4hvh-m426-wv8w
GHSA-5qxm-qvmj-8v79
GHSA-784x-7qm2-gp97
GHSA-c2jm-97rm-g3c3
GHSA-h3rg-qv35-27xm
GHSA-qpw3-95cg-p883
GHSA-wfxq-5cv4-254v
This commit is contained in:
advisory-database[bot]
2024-08-30 03:32:15 +00:00
parent 7f5ada463d
commit a4b1a33ddb
9 changed files with 366 additions and 0 deletions
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-23f9-rm56-9hw4",
"modified": "2024-08-30T03:30:44Z",
"published": "2024-08-30T03:30:44Z",
"aliases": [
"CVE-2024-8328"
],
"details": "Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular privilege to inject arbitrary JavaScript code and perform Reflected Cross-site scripting attacks.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8328"
},
{
"type": "WEB",
"url": "https://www.twcert.org.tw/en/cp-139-8033-0a98f-2.html"
},
{
"type": "WEB",
"url": "https://www.twcert.org.tw/tw/cp-132-8028-360e1-1.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-30T03:15:04Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2cvv-v79w-fm34",
"modified": "2024-08-30T03:30:44Z",
"published": "2024-08-30T03:30:44Z",
"aliases": [
"CVE-2024-8329"
],
"details": "6SHR system from Gether Technology does not properly validate the specific page parameter, allowing remote attackers with regular privilege to inject SQL command to read, modify, and delete database contents.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8329"
},
{
"type": "WEB",
"url": "https://www.twcert.org.tw/en/cp-139-8034-657b7-2.html"
},
{
"type": "WEB",
"url": "https://www.twcert.org.tw/tw/cp-132-8030-e2eac-1.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-30T03:15:04Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4hvh-m426-wv8w",
"modified": "2024-08-30T03:30:44Z",
"published": "2024-08-30T03:30:44Z",
"aliases": [
"CVE-2024-45490"
],
"details": "An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45490"
},
{
"type": "WEB",
"url": "https://github.com/libexpat/libexpat/issues/887"
},
{
"type": "WEB",
"url": "https://github.com/libexpat/libexpat/pull/890"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-30T03:15:03Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5qxm-qvmj-8v79",
"modified": "2024-08-30T03:30:44Z",
"published": "2024-08-30T03:30:44Z",
"aliases": [
"CVE-2024-45492"
],
"details": "An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45492"
},
{
"type": "WEB",
"url": "https://github.com/libexpat/libexpat/issues/889"
},
{
"type": "WEB",
"url": "https://github.com/libexpat/libexpat/pull/892"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-30T03:15:03Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-784x-7qm2-gp97",
"modified": "2024-08-30T03:30:44Z",
"published": "2024-08-30T03:30:44Z",
"aliases": [
"CVE-2024-45491"
],
"details": "An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45491"
},
{
"type": "WEB",
"url": "https://github.com/libexpat/libexpat/issues/888"
},
{
"type": "WEB",
"url": "https://github.com/libexpat/libexpat/pull/891"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-30T03:15:03Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c2jm-97rm-g3c3",
"modified": "2024-08-30T03:30:44Z",
"published": "2024-08-30T03:30:44Z",
"aliases": [
"CVE-2024-45488"
],
"details": "One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware or HyperV). The fixed versions are 7.0.5.1 LTS, 7.4.2, and 7.5.2.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45488"
},
{
"type": "WEB",
"url": "https://support.oneidentity.com/kb/4376740/safeguard-for-privileged-passwords-security-vulnerability-notification-defect-460620"
},
{
"type": "WEB",
"url": "https://support.oneidentity.com/product-notification/noti-00001628"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-30T02:15:03Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h3rg-qv35-27xm",
"modified": "2024-08-30T03:30:45Z",
"published": "2024-08-30T03:30:44Z",
"aliases": [
"CVE-2024-8330"
],
"details": "6SHR system from Gether Technology does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload web shell scripts and use them to execute arbitrary system commands on the server.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8330"
},
{
"type": "WEB",
"url": "https://www.twcert.org.tw/en/cp-139-8035-53926-2.html"
},
{
"type": "WEB",
"url": "https://www.twcert.org.tw/tw/cp-132-8031-a2f21-1.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-434"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-30T03:15:04Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qpw3-95cg-p883",
"modified": "2024-08-30T03:30:44Z",
"published": "2024-08-30T03:30:44Z",
"aliases": [
"CVE-2024-8327"
],
"details": "Easy test\n\nOnline Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular privilege to inject arbitrary SQL commands to read, modify, and delete database contents.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8327"
},
{
"type": "WEB",
"url": "https://www.twcert.org.tw/en/cp-139-8032-a3d5c-2.html"
},
{
"type": "WEB",
"url": "https://www.twcert.org.tw/tw/cp-132-8028-360e1-1.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-30T03:15:04Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wfxq-5cv4-254v",
"modified": "2024-08-30T03:30:44Z",
"published": "2024-08-30T03:30:44Z",
"aliases": [
"CVE-2024-8234"
],
"details": "** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the functions formSysCmd(), formUpgradeCert(), and formDelcert() in the Zyxel NWA1100-N firmware version 1.00(AACE.1)C0 could allow an unauthenticated attacker to execute some OS commands to access system files on an affected device.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8234"
},
{
"type": "WEB",
"url": "https://github.com/GroundCTL2MajorTom/pocs/blob/main/zyxel_NWAW1100-N_rce.md"
},
{
"type": "WEB",
"url": "https://webservice.zyxel.com/eol/ArchivedEOLModel.pdf"
}
],
"database_specific": {
"cwe_ids": [
"CWE-78"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-30T01:15:03Z"
}
}