Publish Advisories

GHSA-8vvp-2mv7-px5c
GHSA-9954-329g-42vc
GHSA-gh6x-qpj6-x25r
GHSA-2j7g-cpcm-93qx
GHSA-3wxq-76w9-ghcp
GHSA-4w42-hx2p-m2jw
GHSA-5fr5-frrw-m97p
GHSA-73v5-rhgg-73mq
GHSA-9rvg-5948-h2q2
GHSA-h24r-m9qc-pvpg
GHSA-h2rq-qhr7-53gm
GHSA-m4jj-vwgj-qpjf
GHSA-pmvf-52m5-fj89
GHSA-qwqw-5hfm-4vgg
This commit is contained in:
advisory-database[bot]
2024-02-06 12:31:48 +00:00
parent 86d1b46677
commit a78d1eee1e
14 changed files with 432 additions and 2 deletions
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://github.com/redis/redis/commit/0bf90d944313919eb8e63d3588bf63a367f020a3"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.211962"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.211962"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9954-329g-42vc",
"modified": "2024-01-12T18:30:20Z",
"modified": "2024-02-06T12:30:30Z",
"published": "2024-01-08T21:30:34Z",
"aliases": [
"CVE-2023-51408"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gh6x-qpj6-x25r",
"modified": "2024-01-12T18:30:20Z",
"modified": "2024-02-06T12:30:30Z",
"published": "2024-01-08T21:30:34Z",
"aliases": [
"CVE-2023-51490"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2j7g-cpcm-93qx",
"modified": "2024-02-06T12:30:31Z",
"published": "2024-02-06T12:30:31Z",
"aliases": [
"CVE-2024-24942"
],
"details": "In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24942"
},
{
"type": "WEB",
"url": "https://www.jetbrains.com/privacy-security/issues-fixed/"
}
],
"database_specific": {
"cwe_ids": [
"CWE-23"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-06T10:15:11Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3wxq-76w9-ghcp",
"modified": "2024-02-06T12:30:31Z",
"published": "2024-02-06T12:30:31Z",
"aliases": [
"CVE-2024-24940"
],
"details": "In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24940"
},
{
"type": "WEB",
"url": "https://www.jetbrains.com/privacy-security/issues-fixed/"
}
],
"database_specific": {
"cwe_ids": [
"CWE-23"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-06T10:15:10Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4w42-hx2p-m2jw",
"modified": "2024-02-06T12:30:31Z",
"published": "2024-02-06T12:30:31Z",
"aliases": [
"CVE-2024-24938"
],
"details": "In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24938"
},
{
"type": "WEB",
"url": "https://www.jetbrains.com/privacy-security/issues-fixed/"
}
],
"database_specific": {
"cwe_ids": [
"CWE-23"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-06T10:15:10Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5fr5-frrw-m97p",
"modified": "2024-02-06T12:30:31Z",
"published": "2024-02-06T12:30:31Z",
"aliases": [
"CVE-2024-24943"
],
"details": "In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24943"
},
{
"type": "WEB",
"url": "https://www.jetbrains.com/privacy-security/issues-fixed/"
}
],
"database_specific": {
"cwe_ids": [
"CWE-400"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-06T10:15:11Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-73v5-rhgg-73mq",
"modified": "2024-02-06T12:30:30Z",
"published": "2024-02-06T12:30:30Z",
"aliases": [
"CVE-2024-23917"
],
"details": "In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23917"
},
{
"type": "WEB",
"url": "https://www.jetbrains.com/privacy-security/issues-fixed/"
}
],
"database_specific": {
"cwe_ids": [
"CWE-288"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-06T10:15:09Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9rvg-5948-h2q2",
"modified": "2024-02-06T12:30:31Z",
"published": "2024-02-06T12:30:31Z",
"aliases": [
"CVE-2024-24937"
],
"details": "In JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possible",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24937"
},
{
"type": "WEB",
"url": "https://www.jetbrains.com/privacy-security/issues-fixed/"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-06T10:15:09Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h24r-m9qc-pvpg",
"modified": "2024-02-06T12:30:31Z",
"published": "2024-02-06T12:30:31Z",
"aliases": [
"CVE-2024-0690"
],
"details": "An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. It was discovered that information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0690"
},
{
"type": "WEB",
"url": "https://github.com/ansible/ansible/pull/82565"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-0690"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2259013"
}
],
"database_specific": {
"cwe_ids": [
"CWE-117"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-06T12:15:55Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h2rq-qhr7-53gm",
"modified": "2024-02-06T12:30:30Z",
"published": "2024-02-06T12:30:30Z",
"aliases": [
"CVE-2024-23673"
],
"details": "\nMalicious code execution via path traversal in Apache Software Foundation Apache Sling Servlets Resolver.This issue affects all version of Apache Sling Servlets Resolver before 2.11.0. However, whether a system is vulnerable to this attack depends on the exact configuration of the system.\nIf the system is vulnerable, a user with write access to the repository might be able to trick the Sling Servlet Resolver to load a previously uploaded script. \n\nUsers are recommended to upgrade to version 2.11.0, which fixes this issue. It is recommended to upgrade, regardless of whether your system configuration currently allows this attack or not.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23673"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread/5zzx8ztwc6tmbwlw80m2pbrp3913l2kl"
}
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-06T10:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m4jj-vwgj-qpjf",
"modified": "2024-02-06T12:30:30Z",
"published": "2024-02-06T12:30:30Z",
"aliases": [
"CVE-2024-24936"
],
"details": "In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24936"
},
{
"type": "WEB",
"url": "https://www.jetbrains.com/privacy-security/issues-fixed/"
}
],
"database_specific": {
"cwe_ids": [
"CWE-285"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-06T10:15:09Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pmvf-52m5-fj89",
"modified": "2024-02-06T12:30:31Z",
"published": "2024-02-06T12:30:31Z",
"aliases": [
"CVE-2024-24941"
],
"details": "In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24941"
},
{
"type": "WEB",
"url": "https://www.jetbrains.com/privacy-security/issues-fixed/"
}
],
"database_specific": {
"cwe_ids": [
"CWE-20"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-06T10:15:11Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qwqw-5hfm-4vgg",
"modified": "2024-02-06T12:30:31Z",
"published": "2024-02-06T12:30:31Z",
"aliases": [
"CVE-2024-24939"
],
"details": "In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24939"
},
{
"type": "WEB",
"url": "https://www.jetbrains.com/privacy-security/issues-fixed/"
}
],
"database_specific": {
"cwe_ids": [
"CWE-532"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-06T10:15:10Z"
}
}