From a55ee2a69c756ce553fa88c846fed009013394f6 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 16 Feb 2024 15:31:51 +0000 Subject: [PATCH] Publish Advisories GHSA-53v4-42fg-g287 GHSA-62jr-84gf-wmg4 GHSA-f4qf-m5gf-8jm8 GHSA-c4g9-53v4-f2qg GHSA-f24p-3hqr-7g3q GHSA-chgx-7cw3-hr55 GHSA-jx3x-j983-74m3 GHSA-c4w5-6p37-2vp9 GHSA-h54p-v85c-f69r GHSA-jmh8-4h3g-x5g5 GHSA-4766-3xqh-rp5x GHSA-p6rw-gvvh-q8v4 GHSA-rj8q-prqp-jwfg GHSA-rr4v-xrwq-7rhx GHSA-244g-mc48-hxgx GHSA-95h5-gp28-rjvc GHSA-mqhm-2f26-c69c GHSA-rq54-4p92-2jhj --- .../GHSA-53v4-42fg-g287.json | 6 ++- .../GHSA-62jr-84gf-wmg4.json | 6 ++- .../GHSA-f4qf-m5gf-8jm8.json | 6 ++- .../GHSA-c4g9-53v4-f2qg.json | 9 +++-- .../GHSA-f24p-3hqr-7g3q.json | 10 +++-- .../GHSA-chgx-7cw3-hr55.json | 6 +-- .../GHSA-jx3x-j983-74m3.json | 4 +- .../GHSA-c4w5-6p37-2vp9.json | 3 +- .../GHSA-h54p-v85c-f69r.json | 4 +- .../GHSA-jmh8-4h3g-x5g5.json | 8 ++-- .../GHSA-4766-3xqh-rp5x.json | 6 ++- .../GHSA-p6rw-gvvh-q8v4.json | 6 ++- .../GHSA-rj8q-prqp-jwfg.json | 6 ++- .../GHSA-rr4v-xrwq-7rhx.json | 6 ++- .../GHSA-244g-mc48-hxgx.json | 2 +- .../GHSA-95h5-gp28-rjvc.json | 35 +++++++++++++++++ .../GHSA-mqhm-2f26-c69c.json | 1 + .../GHSA-rq54-4p92-2jhj.json | 38 +++++++++++++++++++ 18 files changed, 136 insertions(+), 26 deletions(-) create mode 100644 advisories/unreviewed/2024/02/GHSA-95h5-gp28-rjvc/GHSA-95h5-gp28-rjvc.json create mode 100644 advisories/unreviewed/2024/02/GHSA-rq54-4p92-2jhj/GHSA-rq54-4p92-2jhj.json diff --git a/advisories/github-reviewed/2023/11/GHSA-53v4-42fg-g287/GHSA-53v4-42fg-g287.json b/advisories/github-reviewed/2023/11/GHSA-53v4-42fg-g287/GHSA-53v4-42fg-g287.json index 588842aac90..85a0c4a1219 100644 --- a/advisories/github-reviewed/2023/11/GHSA-53v4-42fg-g287/GHSA-53v4-42fg-g287.json +++ b/advisories/github-reviewed/2023/11/GHSA-53v4-42fg-g287/GHSA-53v4-42fg-g287.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-53v4-42fg-g287", - "modified": "2023-12-05T21:55:49Z", + "modified": "2024-02-16T15:30:26Z", "published": "2023-11-28T18:30:23Z", "aliases": [ "CVE-2022-41678" @@ -79,6 +79,10 @@ "type": "WEB", "url": "https://lists.apache.org/thread/7g17kwbtjl011mm4tr8bn1vnoq9wh4sl" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240216-0004" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2023/11/28/1" diff --git a/advisories/github-reviewed/2024/01/GHSA-62jr-84gf-wmg4/GHSA-62jr-84gf-wmg4.json b/advisories/github-reviewed/2024/01/GHSA-62jr-84gf-wmg4/GHSA-62jr-84gf-wmg4.json index ef47e748c07..1568e066ba1 100644 --- a/advisories/github-reviewed/2024/01/GHSA-62jr-84gf-wmg4/GHSA-62jr-84gf-wmg4.json +++ b/advisories/github-reviewed/2024/01/GHSA-62jr-84gf-wmg4/GHSA-62jr-84gf-wmg4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-62jr-84gf-wmg4", - "modified": "2024-01-16T15:24:41Z", + "modified": "2024-02-16T15:30:26Z", "published": "2024-01-16T15:24:41Z", "aliases": [ "CVE-2024-22207" @@ -51,6 +51,10 @@ { "type": "PACKAGE", "url": "https://github.com/fastify/fastify-swagger-ui" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240216-0002" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/01/GHSA-f4qf-m5gf-8jm8/GHSA-f4qf-m5gf-8jm8.json b/advisories/github-reviewed/2024/01/GHSA-f4qf-m5gf-8jm8/GHSA-f4qf-m5gf-8jm8.json index 9ee5c736553..59857757a21 100644 --- a/advisories/github-reviewed/2024/01/GHSA-f4qf-m5gf-8jm8/GHSA-f4qf-m5gf-8jm8.json +++ b/advisories/github-reviewed/2024/01/GHSA-f4qf-m5gf-8jm8/GHSA-f4qf-m5gf-8jm8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f4qf-m5gf-8jm8", - "modified": "2024-02-01T21:03:23Z", + "modified": "2024-02-16T15:30:26Z", "published": "2024-01-19T12:30:18Z", "aliases": [ "CVE-2024-21733" @@ -67,6 +67,10 @@ "type": "WEB", "url": "https://lists.apache.org/thread/h9bjqdd0odj6lhs2o96qgowcc6hb0cfz" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240216-0005" + }, { "type": "WEB", "url": "http://packetstormsecurity.com/files/176951/Apache-Tomcat-8.5.63-9.0.43-HTTP-Response-Smuggling.html" diff --git a/advisories/unreviewed/2022/04/GHSA-c4g9-53v4-f2qg/GHSA-c4g9-53v4-f2qg.json b/advisories/unreviewed/2022/04/GHSA-c4g9-53v4-f2qg/GHSA-c4g9-53v4-f2qg.json index 56592780677..8128dc2a235 100644 --- a/advisories/unreviewed/2022/04/GHSA-c4g9-53v4-f2qg/GHSA-c4g9-53v4-f2qg.json +++ b/advisories/unreviewed/2022/04/GHSA-c4g9-53v4-f2qg/GHSA-c4g9-53v4-f2qg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c4g9-53v4-f2qg", - "modified": "2022-04-30T18:18:16Z", + "modified": "2024-02-16T15:30:25Z", "published": "2022-04-30T18:18:16Z", "aliases": [ "CVE-2001-1559" ], "details": "The uipc system calls (uipc_syscalls.c) in OpenBSD 2.9 and 3.0 provide user mode return instead of versus rval kernel mode values to the fdrelease function, which allows local users to cause a denial of service and trigger a null dereference.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-f24p-3hqr-7g3q/GHSA-f24p-3hqr-7g3q.json b/advisories/unreviewed/2022/05/GHSA-f24p-3hqr-7g3q/GHSA-f24p-3hqr-7g3q.json index 3dbce0c7c00..199af98f5d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-f24p-3hqr-7g3q/GHSA-f24p-3hqr-7g3q.json +++ b/advisories/unreviewed/2022/05/GHSA-f24p-3hqr-7g3q/GHSA-f24p-3hqr-7g3q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f24p-3hqr-7g3q", - "modified": "2022-05-01T02:31:32Z", + "modified": "2024-02-16T15:30:25Z", "published": "2022-05-01T02:31:32Z", "aliases": [ "CVE-2005-4868" ], "details": "Shared memory sections and events in IBM DB2 8.1 have default permissions of read and write for the Everyone group, which allows local users to gain unauthorized access, gain sensitive information, such as cleartext passwords, and cause a denial of service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -45,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-732" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-chgx-7cw3-hr55/GHSA-chgx-7cw3-hr55.json b/advisories/unreviewed/2023/08/GHSA-chgx-7cw3-hr55/GHSA-chgx-7cw3-hr55.json index e0b68f041e1..cb35f1ec4f3 100644 --- a/advisories/unreviewed/2023/08/GHSA-chgx-7cw3-hr55/GHSA-chgx-7cw3-hr55.json +++ b/advisories/unreviewed/2023/08/GHSA-chgx-7cw3-hr55/GHSA-chgx-7cw3-hr55.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-chgx-7cw3-hr55", - "modified": "2023-11-14T15:30:23Z", + "modified": "2024-02-16T15:30:25Z", "published": "2023-08-11T15:30:45Z", "aliases": [ "CVE-2023-39418" @@ -51,7 +51,7 @@ }, { "type": "WEB", - "url": "https://security.netapp.com/advisory/ntap-20230915-0002/" + "url": "https://security.netapp.com/advisory/ntap-20230915-0002" }, { "type": "WEB", @@ -59,7 +59,7 @@ }, { "type": "WEB", - "url": "https://www.postgresql.org/support/security/CVE-2023-39418/" + "url": "https://www.postgresql.org/support/security/CVE-2023-39418" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/08/GHSA-jx3x-j983-74m3/GHSA-jx3x-j983-74m3.json b/advisories/unreviewed/2023/08/GHSA-jx3x-j983-74m3/GHSA-jx3x-j983-74m3.json index eaeb00ec9fc..a5579129116 100644 --- a/advisories/unreviewed/2023/08/GHSA-jx3x-j983-74m3/GHSA-jx3x-j983-74m3.json +++ b/advisories/unreviewed/2023/08/GHSA-jx3x-j983-74m3/GHSA-jx3x-j983-74m3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jx3x-j983-74m3", - "modified": "2023-11-14T15:30:23Z", + "modified": "2024-02-16T15:30:25Z", "published": "2023-08-11T15:30:45Z", "aliases": [ "CVE-2023-39417" @@ -119,7 +119,7 @@ }, { "type": "WEB", - "url": "https://security.netapp.com/advisory/ntap-20230915-0002/" + "url": "https://security.netapp.com/advisory/ntap-20230915-0002" }, { "type": "WEB", diff --git a/advisories/unreviewed/2023/09/GHSA-c4w5-6p37-2vp9/GHSA-c4w5-6p37-2vp9.json b/advisories/unreviewed/2023/09/GHSA-c4w5-6p37-2vp9/GHSA-c4w5-6p37-2vp9.json index 9bebe1ac396..f4f01735337 100644 --- a/advisories/unreviewed/2023/09/GHSA-c4w5-6p37-2vp9/GHSA-c4w5-6p37-2vp9.json +++ b/advisories/unreviewed/2023/09/GHSA-c4w5-6p37-2vp9/GHSA-c4w5-6p37-2vp9.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-h54p-v85c-f69r/GHSA-h54p-v85c-f69r.json b/advisories/unreviewed/2023/09/GHSA-h54p-v85c-f69r/GHSA-h54p-v85c-f69r.json index acd63c02837..2d5ec3c731a 100644 --- a/advisories/unreviewed/2023/09/GHSA-h54p-v85c-f69r/GHSA-h54p-v85c-f69r.json +++ b/advisories/unreviewed/2023/09/GHSA-h54p-v85c-f69r/GHSA-h54p-v85c-f69r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h54p-v85c-f69r", - "modified": "2023-11-14T12:30:26Z", + "modified": "2024-02-16T15:30:25Z", "published": "2023-09-14T18:32:40Z", "aliases": [ "CVE-2023-41032" @@ -31,7 +31,7 @@ }, { "type": "WEB", - "url": "https://www.bentley.com/advisories/be-2023-0004/" + "url": "https://www.bentley.com/advisories/be-2023-0004" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-jmh8-4h3g-x5g5/GHSA-jmh8-4h3g-x5g5.json b/advisories/unreviewed/2023/10/GHSA-jmh8-4h3g-x5g5/GHSA-jmh8-4h3g-x5g5.json index 286762e6a52..35de5432f01 100644 --- a/advisories/unreviewed/2023/10/GHSA-jmh8-4h3g-x5g5/GHSA-jmh8-4h3g-x5g5.json +++ b/advisories/unreviewed/2023/10/GHSA-jmh8-4h3g-x5g5/GHSA-jmh8-4h3g-x5g5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jmh8-4h3g-x5g5", - "modified": "2023-11-02T18:30:24Z", + "modified": "2024-02-16T15:30:26Z", "published": "2023-10-25T21:30:32Z", "aliases": [ "CVE-2023-42852" @@ -23,15 +23,15 @@ }, { "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RPPMOWFYZODONTA3RLZOKSGNR4DELGG2/" + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RPPMOWFYZODONTA3RLZOKSGNR4DELGG2" }, { "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S3O7ITSBZDHLBM5OG22K6RZAHRRTGECM/" + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S3O7ITSBZDHLBM5OG22K6RZAHRRTGECM" }, { "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZTCZGQPRDAOPP6NK4CIDJKIPMBWD5J7K/" + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZTCZGQPRDAOPP6NK4CIDJKIPMBWD5J7K" }, { "type": "WEB", diff --git a/advisories/unreviewed/2024/01/GHSA-4766-3xqh-rp5x/GHSA-4766-3xqh-rp5x.json b/advisories/unreviewed/2024/01/GHSA-4766-3xqh-rp5x/GHSA-4766-3xqh-rp5x.json index ad5f766947c..515c2b7a139 100644 --- a/advisories/unreviewed/2024/01/GHSA-4766-3xqh-rp5x/GHSA-4766-3xqh-rp5x.json +++ b/advisories/unreviewed/2024/01/GHSA-4766-3xqh-rp5x/GHSA-4766-3xqh-rp5x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4766-3xqh-rp5x", - "modified": "2024-01-16T15:30:27Z", + "modified": "2024-02-16T15:30:26Z", "published": "2024-01-09T03:30:22Z", "aliases": [ "CVE-2023-49238" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://security.gradle.com/advisory/2023-01" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240216-0003" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-p6rw-gvvh-q8v4/GHSA-p6rw-gvvh-q8v4.json b/advisories/unreviewed/2024/01/GHSA-p6rw-gvvh-q8v4/GHSA-p6rw-gvvh-q8v4.json index 8b37b52d5d9..49a55b699b8 100644 --- a/advisories/unreviewed/2024/01/GHSA-p6rw-gvvh-q8v4/GHSA-p6rw-gvvh-q8v4.json +++ b/advisories/unreviewed/2024/01/GHSA-p6rw-gvvh-q8v4/GHSA-p6rw-gvvh-q8v4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p6rw-gvvh-q8v4", - "modified": "2024-02-15T09:30:35Z", + "modified": "2024-02-16T15:30:26Z", "published": "2024-01-31T15:30:20Z", "aliases": [ "CVE-2023-6246" @@ -41,6 +41,10 @@ "type": "WEB", "url": "https://security.gentoo.org/glsa/202402-01" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240216-0007" + }, { "type": "WEB", "url": "https://www.openwall.com/lists/oss-security/2024/01/30/6" diff --git a/advisories/unreviewed/2024/01/GHSA-rj8q-prqp-jwfg/GHSA-rj8q-prqp-jwfg.json b/advisories/unreviewed/2024/01/GHSA-rj8q-prqp-jwfg/GHSA-rj8q-prqp-jwfg.json index 4384da62ed6..5e2852a2761 100644 --- a/advisories/unreviewed/2024/01/GHSA-rj8q-prqp-jwfg/GHSA-rj8q-prqp-jwfg.json +++ b/advisories/unreviewed/2024/01/GHSA-rj8q-prqp-jwfg/GHSA-rj8q-prqp-jwfg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rj8q-prqp-jwfg", - "modified": "2024-01-24T00:30:31Z", + "modified": "2024-02-16T15:30:26Z", "published": "2024-01-09T18:30:27Z", "aliases": [ "CVE-2023-6129" @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://github.com/openssl/openssl/commit/f3fc5808fe9ff74042d639839610d03b8fdcc015" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240216-0009" + }, { "type": "WEB", "url": "https://www.openssl.org/news/secadv/20240109.txt" diff --git a/advisories/unreviewed/2024/01/GHSA-rr4v-xrwq-7rhx/GHSA-rr4v-xrwq-7rhx.json b/advisories/unreviewed/2024/01/GHSA-rr4v-xrwq-7rhx/GHSA-rr4v-xrwq-7rhx.json index 93e4153e68f..4f7d0d016bf 100644 --- a/advisories/unreviewed/2024/01/GHSA-rr4v-xrwq-7rhx/GHSA-rr4v-xrwq-7rhx.json +++ b/advisories/unreviewed/2024/01/GHSA-rr4v-xrwq-7rhx/GHSA-rr4v-xrwq-7rhx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rr4v-xrwq-7rhx", - "modified": "2024-01-15T12:30:20Z", + "modified": "2024-02-16T15:30:26Z", "published": "2024-01-15T12:30:20Z", "aliases": [ "CVE-2023-4001" @@ -53,6 +53,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CHLZQ47HM64NDOHMHYO7VIJFYD5ZPPYN" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240216-0006" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/01/15/3" diff --git a/advisories/unreviewed/2024/02/GHSA-244g-mc48-hxgx/GHSA-244g-mc48-hxgx.json b/advisories/unreviewed/2024/02/GHSA-244g-mc48-hxgx/GHSA-244g-mc48-hxgx.json index 356a3dc9d91..1ae64d0a6f6 100644 --- a/advisories/unreviewed/2024/02/GHSA-244g-mc48-hxgx/GHSA-244g-mc48-hxgx.json +++ b/advisories/unreviewed/2024/02/GHSA-244g-mc48-hxgx/GHSA-244g-mc48-hxgx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-244g-mc48-hxgx", - "modified": "2024-02-10T09:30:21Z", + "modified": "2024-02-16T15:30:26Z", "published": "2024-02-10T09:30:21Z", "aliases": [ "CVE-2024-23517" diff --git a/advisories/unreviewed/2024/02/GHSA-95h5-gp28-rjvc/GHSA-95h5-gp28-rjvc.json b/advisories/unreviewed/2024/02/GHSA-95h5-gp28-rjvc/GHSA-95h5-gp28-rjvc.json new file mode 100644 index 00000000000..b61d155a6be --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-95h5-gp28-rjvc/GHSA-95h5-gp28-rjvc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95h5-gp28-rjvc", + "modified": "2024-02-16T15:30:27Z", + "published": "2024-02-16T15:30:27Z", + "aliases": [ + "CVE-2024-25320" + ], + "details": "Tongda OA v2017 and up to v11.9 was discovered to contain a SQL injection vulnerability via the $AFF_ID parameter at /affair/delete.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25320" + }, + { + "type": "WEB", + "url": "https://github.com/cqliuke/cve/blob/main/sql.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-16T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-mqhm-2f26-c69c/GHSA-mqhm-2f26-c69c.json b/advisories/unreviewed/2024/02/GHSA-mqhm-2f26-c69c/GHSA-mqhm-2f26-c69c.json index 3cb1f3ee6c3..0a446d65afa 100644 --- a/advisories/unreviewed/2024/02/GHSA-mqhm-2f26-c69c/GHSA-mqhm-2f26-c69c.json +++ b/advisories/unreviewed/2024/02/GHSA-mqhm-2f26-c69c/GHSA-mqhm-2f26-c69c.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-23" ], "severity": "LOW", diff --git a/advisories/unreviewed/2024/02/GHSA-rq54-4p92-2jhj/GHSA-rq54-4p92-2jhj.json b/advisories/unreviewed/2024/02/GHSA-rq54-4p92-2jhj/GHSA-rq54-4p92-2jhj.json new file mode 100644 index 00000000000..ee82bc8eb45 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-rq54-4p92-2jhj/GHSA-rq54-4p92-2jhj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rq54-4p92-2jhj", + "modified": "2024-02-16T15:30:27Z", + "published": "2024-02-16T15:30:27Z", + "aliases": [ + "CVE-2024-21775" + ], + "details": "Zoho ManageEngine Exchange Reporter Plus versions 5714 and below are vulnerable to the Authenticated SQL injection in report exporting feature.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21775" + }, + { + "type": "WEB", + "url": "https://www.manageengine.com/products/exchange-reports/advisory/CVE-2024-21775.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-16T15:15:08Z" + } +} \ No newline at end of file