From a4b1a33ddbdd8e3ff08496f54dcd81dd43a47309 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 30 Aug 2024 03:32:15 +0000 Subject: [PATCH] Publish Advisories GHSA-23f9-rm56-9hw4 GHSA-2cvv-v79w-fm34 GHSA-4hvh-m426-wv8w GHSA-5qxm-qvmj-8v79 GHSA-784x-7qm2-gp97 GHSA-c2jm-97rm-g3c3 GHSA-h3rg-qv35-27xm GHSA-qpw3-95cg-p883 GHSA-wfxq-5cv4-254v --- .../GHSA-23f9-rm56-9hw4.json | 42 +++++++++++++++++++ .../GHSA-2cvv-v79w-fm34.json | 42 +++++++++++++++++++ .../GHSA-4hvh-m426-wv8w.json | 39 +++++++++++++++++ .../GHSA-5qxm-qvmj-8v79.json | 39 +++++++++++++++++ .../GHSA-784x-7qm2-gp97.json | 39 +++++++++++++++++ .../GHSA-c2jm-97rm-g3c3.json | 39 +++++++++++++++++ .../GHSA-h3rg-qv35-27xm.json | 42 +++++++++++++++++++ .../GHSA-qpw3-95cg-p883.json | 42 +++++++++++++++++++ .../GHSA-wfxq-5cv4-254v.json | 42 +++++++++++++++++++ 9 files changed, 366 insertions(+) create mode 100644 advisories/unreviewed/2024/08/GHSA-23f9-rm56-9hw4/GHSA-23f9-rm56-9hw4.json create mode 100644 advisories/unreviewed/2024/08/GHSA-2cvv-v79w-fm34/GHSA-2cvv-v79w-fm34.json create mode 100644 advisories/unreviewed/2024/08/GHSA-4hvh-m426-wv8w/GHSA-4hvh-m426-wv8w.json create mode 100644 advisories/unreviewed/2024/08/GHSA-5qxm-qvmj-8v79/GHSA-5qxm-qvmj-8v79.json create mode 100644 advisories/unreviewed/2024/08/GHSA-784x-7qm2-gp97/GHSA-784x-7qm2-gp97.json create mode 100644 advisories/unreviewed/2024/08/GHSA-c2jm-97rm-g3c3/GHSA-c2jm-97rm-g3c3.json create mode 100644 advisories/unreviewed/2024/08/GHSA-h3rg-qv35-27xm/GHSA-h3rg-qv35-27xm.json create mode 100644 advisories/unreviewed/2024/08/GHSA-qpw3-95cg-p883/GHSA-qpw3-95cg-p883.json create mode 100644 advisories/unreviewed/2024/08/GHSA-wfxq-5cv4-254v/GHSA-wfxq-5cv4-254v.json diff --git a/advisories/unreviewed/2024/08/GHSA-23f9-rm56-9hw4/GHSA-23f9-rm56-9hw4.json b/advisories/unreviewed/2024/08/GHSA-23f9-rm56-9hw4/GHSA-23f9-rm56-9hw4.json new file mode 100644 index 00000000000..38ca0045e12 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-23f9-rm56-9hw4/GHSA-23f9-rm56-9hw4.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23f9-rm56-9hw4", + "modified": "2024-08-30T03:30:44Z", + "published": "2024-08-30T03:30:44Z", + "aliases": [ + "CVE-2024-8328" + ], + "details": "Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular privilege to inject arbitrary JavaScript code and perform Reflected Cross-site scripting attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8328" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-8033-0a98f-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-8028-360e1-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T03:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-2cvv-v79w-fm34/GHSA-2cvv-v79w-fm34.json b/advisories/unreviewed/2024/08/GHSA-2cvv-v79w-fm34/GHSA-2cvv-v79w-fm34.json new file mode 100644 index 00000000000..9e7190ed239 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2cvv-v79w-fm34/GHSA-2cvv-v79w-fm34.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cvv-v79w-fm34", + "modified": "2024-08-30T03:30:44Z", + "published": "2024-08-30T03:30:44Z", + "aliases": [ + "CVE-2024-8329" + ], + "details": "6SHR system from Gether Technology does not properly validate the specific page parameter, allowing remote attackers with regular privilege to inject SQL command to read, modify, and delete database contents.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8329" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-8034-657b7-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-8030-e2eac-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T03:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4hvh-m426-wv8w/GHSA-4hvh-m426-wv8w.json b/advisories/unreviewed/2024/08/GHSA-4hvh-m426-wv8w/GHSA-4hvh-m426-wv8w.json new file mode 100644 index 00000000000..060705b8e3c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4hvh-m426-wv8w/GHSA-4hvh-m426-wv8w.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hvh-m426-wv8w", + "modified": "2024-08-30T03:30:44Z", + "published": "2024-08-30T03:30:44Z", + "aliases": [ + "CVE-2024-45490" + ], + "details": "An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45490" + }, + { + "type": "WEB", + "url": "https://github.com/libexpat/libexpat/issues/887" + }, + { + "type": "WEB", + "url": "https://github.com/libexpat/libexpat/pull/890" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T03:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5qxm-qvmj-8v79/GHSA-5qxm-qvmj-8v79.json b/advisories/unreviewed/2024/08/GHSA-5qxm-qvmj-8v79/GHSA-5qxm-qvmj-8v79.json new file mode 100644 index 00000000000..2f8eaeb3ff0 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5qxm-qvmj-8v79/GHSA-5qxm-qvmj-8v79.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qxm-qvmj-8v79", + "modified": "2024-08-30T03:30:44Z", + "published": "2024-08-30T03:30:44Z", + "aliases": [ + "CVE-2024-45492" + ], + "details": "An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45492" + }, + { + "type": "WEB", + "url": "https://github.com/libexpat/libexpat/issues/889" + }, + { + "type": "WEB", + "url": "https://github.com/libexpat/libexpat/pull/892" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T03:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-784x-7qm2-gp97/GHSA-784x-7qm2-gp97.json b/advisories/unreviewed/2024/08/GHSA-784x-7qm2-gp97/GHSA-784x-7qm2-gp97.json new file mode 100644 index 00000000000..e09c795df25 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-784x-7qm2-gp97/GHSA-784x-7qm2-gp97.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-784x-7qm2-gp97", + "modified": "2024-08-30T03:30:44Z", + "published": "2024-08-30T03:30:44Z", + "aliases": [ + "CVE-2024-45491" + ], + "details": "An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45491" + }, + { + "type": "WEB", + "url": "https://github.com/libexpat/libexpat/issues/888" + }, + { + "type": "WEB", + "url": "https://github.com/libexpat/libexpat/pull/891" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T03:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c2jm-97rm-g3c3/GHSA-c2jm-97rm-g3c3.json b/advisories/unreviewed/2024/08/GHSA-c2jm-97rm-g3c3/GHSA-c2jm-97rm-g3c3.json new file mode 100644 index 00000000000..3a0441bc002 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c2jm-97rm-g3c3/GHSA-c2jm-97rm-g3c3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2jm-97rm-g3c3", + "modified": "2024-08-30T03:30:44Z", + "published": "2024-08-30T03:30:44Z", + "aliases": [ + "CVE-2024-45488" + ], + "details": "One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware or HyperV). The fixed versions are 7.0.5.1 LTS, 7.4.2, and 7.5.2.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45488" + }, + { + "type": "WEB", + "url": "https://support.oneidentity.com/kb/4376740/safeguard-for-privileged-passwords-security-vulnerability-notification-defect-460620" + }, + { + "type": "WEB", + "url": "https://support.oneidentity.com/product-notification/noti-00001628" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T02:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-h3rg-qv35-27xm/GHSA-h3rg-qv35-27xm.json b/advisories/unreviewed/2024/08/GHSA-h3rg-qv35-27xm/GHSA-h3rg-qv35-27xm.json new file mode 100644 index 00000000000..6bb9395769c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-h3rg-qv35-27xm/GHSA-h3rg-qv35-27xm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h3rg-qv35-27xm", + "modified": "2024-08-30T03:30:45Z", + "published": "2024-08-30T03:30:44Z", + "aliases": [ + "CVE-2024-8330" + ], + "details": "6SHR system from Gether Technology does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload web shell scripts and use them to execute arbitrary system commands on the server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8330" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-8035-53926-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-8031-a2f21-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T03:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qpw3-95cg-p883/GHSA-qpw3-95cg-p883.json b/advisories/unreviewed/2024/08/GHSA-qpw3-95cg-p883/GHSA-qpw3-95cg-p883.json new file mode 100644 index 00000000000..62c739c2519 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qpw3-95cg-p883/GHSA-qpw3-95cg-p883.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpw3-95cg-p883", + "modified": "2024-08-30T03:30:44Z", + "published": "2024-08-30T03:30:44Z", + "aliases": [ + "CVE-2024-8327" + ], + "details": "Easy test\n\nOnline Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular privilege to inject arbitrary SQL commands to read, modify, and delete database contents.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8327" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-8032-a3d5c-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-8028-360e1-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T03:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wfxq-5cv4-254v/GHSA-wfxq-5cv4-254v.json b/advisories/unreviewed/2024/08/GHSA-wfxq-5cv4-254v/GHSA-wfxq-5cv4-254v.json new file mode 100644 index 00000000000..21ac0db8012 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-wfxq-5cv4-254v/GHSA-wfxq-5cv4-254v.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfxq-5cv4-254v", + "modified": "2024-08-30T03:30:44Z", + "published": "2024-08-30T03:30:44Z", + "aliases": [ + "CVE-2024-8234" + ], + "details": "** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the functions formSysCmd(), formUpgradeCert(), and formDelcert() in the Zyxel NWA1100-N firmware version 1.00(AACE.1)C0 could allow an unauthenticated attacker to execute some OS commands to access system files on an affected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8234" + }, + { + "type": "WEB", + "url": "https://github.com/GroundCTL2MajorTom/pocs/blob/main/zyxel_NWAW1100-N_rce.md" + }, + { + "type": "WEB", + "url": "https://webservice.zyxel.com/eol/ArchivedEOLModel.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T01:15:03Z" + } +} \ No newline at end of file