Publish Advisories

GHSA-44wm-f244-xhp3
GHSA-3g9f-gfm4-qv9g
GHSA-4vg5-5hxg-j62g
GHSA-4wh3-3wf2-39m9
GHSA-5x5r-9wg7-qvxf
GHSA-7772-pg67-3gwx
GHSA-8mxv-xwmq-cj65
GHSA-gh6h-7xpj-3cm5
GHSA-gmmq-m222-3g72
GHSA-p8qj-j5r9-6rcf
GHSA-xhgv-wv66-p2v9
This commit is contained in:
advisory-database[bot]
2024-04-11 00:32:25 +00:00
parent a9d5ee9e65
commit a5cdd28b9b
11 changed files with 393 additions and 1 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-44wm-f244-xhp3",
"modified": "2024-04-03T14:53:39Z",
"modified": "2024-04-11T00:30:34Z",
"published": "2024-04-03T03:30:30Z",
"aliases": [
"CVE-2024-28219"
@@ -48,6 +48,14 @@
"type": "PACKAGE",
"url": "https://github.com/python-pillow/Pillow"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00008.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4XLPUT3VK4GQ6EVY525TT2QNUIXNRU5M"
},
{
"type": "WEB",
"url": "https://pillow.readthedocs.io/en/stable/releasenotes/10.3.0.html#security"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3g9f-gfm4-qv9g",
"modified": "2024-04-11T00:30:36Z",
"published": "2024-04-11T00:30:36Z",
"aliases": [
"CVE-2024-29447"
],
"details": "An issue was discovered in the default configurations of ROS2 Humble Hawksbill in ROS2 Humble Hawksbill in ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows unauthenticated attackers to gain access using default credentials.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29447"
},
{
"type": "WEB",
"url": "https://github.com/yashpatelphd/CVE-2024-29447"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T00:15:07Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4vg5-5hxg-j62g",
"modified": "2024-04-11T00:30:35Z",
"published": "2024-04-11T00:30:35Z",
"aliases": [
"CVE-2024-29439"
],
"details": "An unauthorized node injection vulnerability has been identified in ROS2 Humble Hawksbill in ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows remote attackers to escalate privileges and inject malicious ROS2 nodes into the system.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29439"
},
{
"type": "WEB",
"url": "https://github.com/yashpatelphd/CVE-2024-29439"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-10T23:15:06Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4wh3-3wf2-39m9",
"modified": "2024-04-11T00:30:35Z",
"published": "2024-04-11T00:30:35Z",
"aliases": [
"CVE-2024-29504"
],
"details": "Cross Site Scripting vulnerability in Summernote v.0.8.18 and before allows a remote attacker to execute arbtirary code via a crafted payload to the codeview parameter.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29504"
},
{
"type": "WEB",
"url": "https://github.com/summernote/summernote/pull/3782"
},
{
"type": "WEB",
"url": "https://gist.github.com/phoenix118go/a9192281efcfa518daa709ab7638712b"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-10T22:15:07Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5x5r-9wg7-qvxf",
"modified": "2024-04-11T00:30:36Z",
"published": "2024-04-11T00:30:36Z",
"aliases": [
"CVE-2024-3613"
],
"details": "A vulnerability was found in SourceCodester Warehouse Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file supplier.php. The manipulation of the argument nama_supplier/alamat_supplier/notelp_supplier leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-260270 is the identifier assigned to this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3613"
},
{
"type": "WEB",
"url": "https://github.com/fubxx/CVE/blob/main/WarehouseManagementSystemXSS2.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.260270"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.260270"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.312701"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T00:15:07Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7772-pg67-3gwx",
"modified": "2024-04-11T00:30:36Z",
"published": "2024-04-11T00:30:36Z",
"aliases": [
"CVE-2024-29441"
],
"details": "An issue was discovered in ROS2 (Robot Operating System 2) Humble Hawksbill in ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows remote attackers to cause a denial of service (DoS) via the ROS2 nodes.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29441"
},
{
"type": "WEB",
"url": "https://github.com/yashpatelphd/CVE-2024-29441"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T00:15:07Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8mxv-xwmq-cj65",
"modified": "2024-04-11T00:30:36Z",
"published": "2024-04-11T00:30:36Z",
"aliases": [
"CVE-2024-29444"
],
"details": "An OS command injection vulnerability has been discovered in ROS2 (Robot Operating System 2) Humble Hawksbill in ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via External Command Execution Modules, System Call Handlers, and Interface Scripts.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29444"
},
{
"type": "WEB",
"url": "https://github.com/yashpatelphd/CVE-2024-29444"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T00:15:07Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gh6h-7xpj-3cm5",
"modified": "2024-04-11T00:30:36Z",
"published": "2024-04-11T00:30:36Z",
"aliases": [
"CVE-2024-29445"
],
"details": "An issue was discovered in ROS2 (Robot Operating System 2) Humble Hawksbill in ROS_VERSION 2 and ROS_PYTHON_VERSION 3 where the system transmits messages in plaintext, allowing attackers to access sensitive information via a man-in-the-middle attack.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29445"
},
{
"type": "WEB",
"url": "https://github.com/yashpatelphd/CVE-2024-29445"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-10T23:15:06Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gmmq-m222-3g72",
"modified": "2024-04-11T00:30:36Z",
"published": "2024-04-11T00:30:36Z",
"aliases": [
"CVE-2024-30728"
],
"details": "An issue was discovered in the default configurations of ROS (Robot Operating System) Kinetic Kame ROS_VERSION 1 and ROS_ PYTHON_VERSION 3, allows unauthenticated attackers to gain access using default credentials.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30728"
},
{
"type": "WEB",
"url": "https://github.com/yashpatelphd/CVE-2024-30728"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-10T23:15:07Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p8qj-j5r9-6rcf",
"modified": "2024-04-11T00:30:36Z",
"published": "2024-04-11T00:30:36Z",
"aliases": [
"CVE-2024-3612"
],
"details": "A vulnerability was found in SourceCodester Warehouse Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file barang.php. The manipulation of the argument nama_barang/merek leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260269 was assigned to this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3612"
},
{
"type": "WEB",
"url": "https://github.com/fubxx/CVE/blob/main/WarehouseManagementSystemXSS.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.260269"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.260269"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.312700"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T00:15:07Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xhgv-wv66-p2v9",
"modified": "2024-04-11T00:30:36Z",
"published": "2024-04-11T00:30:36Z",
"aliases": [
"CVE-2024-29443"
],
"details": "A shell injection vulnerability was discovered in ROS2 (Robot Operating System 2) Humble Hawksbill in ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information due to the way ROS2 handles shell command execution in components like command interpreters or interfaces that process external inputs.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29443"
},
{
"type": "WEB",
"url": "https://github.com/yashpatelphd/CVE-2024-29443"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-10T23:15:06Z"
}
}