mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-8vvp-2mv7-px5c GHSA-9954-329g-42vc GHSA-gh6x-qpj6-x25r GHSA-2j7g-cpcm-93qx GHSA-3wxq-76w9-ghcp GHSA-4w42-hx2p-m2jw GHSA-5fr5-frrw-m97p GHSA-73v5-rhgg-73mq GHSA-9rvg-5948-h2q2 GHSA-h24r-m9qc-pvpg GHSA-h2rq-qhr7-53gm GHSA-m4jj-vwgj-qpjf GHSA-pmvf-52m5-fj89 GHSA-qwqw-5hfm-4vgg
This commit is contained in:
@@ -25,6 +25,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/redis/redis/commit/0bf90d944313919eb8e63d3588bf63a367f020a3"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://vuldb.com/?ctiid.211962"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://vuldb.com/?id.211962"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-9954-329g-42vc",
|
||||
"modified": "2024-01-12T18:30:20Z",
|
||||
"modified": "2024-02-06T12:30:30Z",
|
||||
"published": "2024-01-08T21:30:34Z",
|
||||
"aliases": [
|
||||
"CVE-2023-51408"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-gh6x-qpj6-x25r",
|
||||
"modified": "2024-01-12T18:30:20Z",
|
||||
"modified": "2024-02-06T12:30:30Z",
|
||||
"published": "2024-01-08T21:30:34Z",
|
||||
"aliases": [
|
||||
"CVE-2023-51490"
|
||||
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-2j7g-cpcm-93qx",
|
||||
"modified": "2024-02-06T12:30:31Z",
|
||||
"published": "2024-02-06T12:30:31Z",
|
||||
"aliases": [
|
||||
"CVE-2024-24942"
|
||||
],
|
||||
"details": "In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24942"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.jetbrains.com/privacy-security/issues-fixed/"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-23"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-02-06T10:15:11Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-3wxq-76w9-ghcp",
|
||||
"modified": "2024-02-06T12:30:31Z",
|
||||
"published": "2024-02-06T12:30:31Z",
|
||||
"aliases": [
|
||||
"CVE-2024-24940"
|
||||
],
|
||||
"details": "In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24940"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.jetbrains.com/privacy-security/issues-fixed/"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-23"
|
||||
],
|
||||
"severity": "LOW",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-02-06T10:15:10Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4w42-hx2p-m2jw",
|
||||
"modified": "2024-02-06T12:30:31Z",
|
||||
"published": "2024-02-06T12:30:31Z",
|
||||
"aliases": [
|
||||
"CVE-2024-24938"
|
||||
],
|
||||
"details": "In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24938"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.jetbrains.com/privacy-security/issues-fixed/"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-23"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-02-06T10:15:10Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-5fr5-frrw-m97p",
|
||||
"modified": "2024-02-06T12:30:31Z",
|
||||
"published": "2024-02-06T12:30:31Z",
|
||||
"aliases": [
|
||||
"CVE-2024-24943"
|
||||
],
|
||||
"details": "In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24943"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.jetbrains.com/privacy-security/issues-fixed/"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-400"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-02-06T10:15:11Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-73v5-rhgg-73mq",
|
||||
"modified": "2024-02-06T12:30:30Z",
|
||||
"published": "2024-02-06T12:30:30Z",
|
||||
"aliases": [
|
||||
"CVE-2024-23917"
|
||||
],
|
||||
"details": "In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23917"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.jetbrains.com/privacy-security/issues-fixed/"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-288"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-02-06T10:15:09Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-9rvg-5948-h2q2",
|
||||
"modified": "2024-02-06T12:30:31Z",
|
||||
"published": "2024-02-06T12:30:31Z",
|
||||
"aliases": [
|
||||
"CVE-2024-24937"
|
||||
],
|
||||
"details": "In JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possible",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24937"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.jetbrains.com/privacy-security/issues-fixed/"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-79"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-02-06T10:15:09Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,46 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-h24r-m9qc-pvpg",
|
||||
"modified": "2024-02-06T12:30:31Z",
|
||||
"published": "2024-02-06T12:30:31Z",
|
||||
"aliases": [
|
||||
"CVE-2024-0690"
|
||||
],
|
||||
"details": "An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. It was discovered that information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0690"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/ansible/ansible/pull/82565"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/security/cve/CVE-2024-0690"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2259013"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-117"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-02-06T12:15:55Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-h2rq-qhr7-53gm",
|
||||
"modified": "2024-02-06T12:30:30Z",
|
||||
"published": "2024-02-06T12:30:30Z",
|
||||
"aliases": [
|
||||
"CVE-2024-23673"
|
||||
],
|
||||
"details": "\nMalicious code execution via path traversal in Apache Software Foundation Apache Sling Servlets Resolver.This issue affects all version of Apache Sling Servlets Resolver before 2.11.0. However, whether a system is vulnerable to this attack depends on the exact configuration of the system.\nIf the system is vulnerable, a user with write access to the repository might be able to trick the Sling Servlet Resolver to load a previously uploaded script. \n\nUsers are recommended to upgrade to version 2.11.0, which fixes this issue. It is recommended to upgrade, regardless of whether your system configuration currently allows this attack or not.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23673"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.apache.org/thread/5zzx8ztwc6tmbwlw80m2pbrp3913l2kl"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-22"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-02-06T10:15:08Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-m4jj-vwgj-qpjf",
|
||||
"modified": "2024-02-06T12:30:30Z",
|
||||
"published": "2024-02-06T12:30:30Z",
|
||||
"aliases": [
|
||||
"CVE-2024-24936"
|
||||
],
|
||||
"details": "In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24936"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.jetbrains.com/privacy-security/issues-fixed/"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-285"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-02-06T10:15:09Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-pmvf-52m5-fj89",
|
||||
"modified": "2024-02-06T12:30:31Z",
|
||||
"published": "2024-02-06T12:30:31Z",
|
||||
"aliases": [
|
||||
"CVE-2024-24941"
|
||||
],
|
||||
"details": "In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24941"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.jetbrains.com/privacy-security/issues-fixed/"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-20"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-02-06T10:15:11Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-qwqw-5hfm-4vgg",
|
||||
"modified": "2024-02-06T12:30:31Z",
|
||||
"published": "2024-02-06T12:30:31Z",
|
||||
"aliases": [
|
||||
"CVE-2024-24939"
|
||||
],
|
||||
"details": "In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24939"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.jetbrains.com/privacy-security/issues-fixed/"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-532"
|
||||
],
|
||||
"severity": "LOW",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-02-06T10:15:10Z"
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user