diff --git a/advisories/unreviewed/2022/10/GHSA-8vvp-2mv7-px5c/GHSA-8vvp-2mv7-px5c.json b/advisories/unreviewed/2022/10/GHSA-8vvp-2mv7-px5c/GHSA-8vvp-2mv7-px5c.json index 05d6bbd3bc4..21a98caeda5 100644 --- a/advisories/unreviewed/2022/10/GHSA-8vvp-2mv7-px5c/GHSA-8vvp-2mv7-px5c.json +++ b/advisories/unreviewed/2022/10/GHSA-8vvp-2mv7-px5c/GHSA-8vvp-2mv7-px5c.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://github.com/redis/redis/commit/0bf90d944313919eb8e63d3588bf63a367f020a3" }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.211962" + }, { "type": "WEB", "url": "https://vuldb.com/?id.211962" diff --git a/advisories/unreviewed/2024/01/GHSA-9954-329g-42vc/GHSA-9954-329g-42vc.json b/advisories/unreviewed/2024/01/GHSA-9954-329g-42vc/GHSA-9954-329g-42vc.json index 00c9a8e11e6..4e9a3e4aa9d 100644 --- a/advisories/unreviewed/2024/01/GHSA-9954-329g-42vc/GHSA-9954-329g-42vc.json +++ b/advisories/unreviewed/2024/01/GHSA-9954-329g-42vc/GHSA-9954-329g-42vc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9954-329g-42vc", - "modified": "2024-01-12T18:30:20Z", + "modified": "2024-02-06T12:30:30Z", "published": "2024-01-08T21:30:34Z", "aliases": [ "CVE-2023-51408" diff --git a/advisories/unreviewed/2024/01/GHSA-gh6x-qpj6-x25r/GHSA-gh6x-qpj6-x25r.json b/advisories/unreviewed/2024/01/GHSA-gh6x-qpj6-x25r/GHSA-gh6x-qpj6-x25r.json index 039d8952230..11d6b270460 100644 --- a/advisories/unreviewed/2024/01/GHSA-gh6x-qpj6-x25r/GHSA-gh6x-qpj6-x25r.json +++ b/advisories/unreviewed/2024/01/GHSA-gh6x-qpj6-x25r/GHSA-gh6x-qpj6-x25r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gh6x-qpj6-x25r", - "modified": "2024-01-12T18:30:20Z", + "modified": "2024-02-06T12:30:30Z", "published": "2024-01-08T21:30:34Z", "aliases": [ "CVE-2023-51490" diff --git a/advisories/unreviewed/2024/02/GHSA-2j7g-cpcm-93qx/GHSA-2j7g-cpcm-93qx.json b/advisories/unreviewed/2024/02/GHSA-2j7g-cpcm-93qx/GHSA-2j7g-cpcm-93qx.json new file mode 100644 index 00000000000..60a9d3582ab --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-2j7g-cpcm-93qx/GHSA-2j7g-cpcm-93qx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2j7g-cpcm-93qx", + "modified": "2024-02-06T12:30:31Z", + "published": "2024-02-06T12:30:31Z", + "aliases": [ + "CVE-2024-24942" + ], + "details": "In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24942" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T10:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-3wxq-76w9-ghcp/GHSA-3wxq-76w9-ghcp.json b/advisories/unreviewed/2024/02/GHSA-3wxq-76w9-ghcp/GHSA-3wxq-76w9-ghcp.json new file mode 100644 index 00000000000..f11cb4f0690 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-3wxq-76w9-ghcp/GHSA-3wxq-76w9-ghcp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wxq-76w9-ghcp", + "modified": "2024-02-06T12:30:31Z", + "published": "2024-02-06T12:30:31Z", + "aliases": [ + "CVE-2024-24940" + ], + "details": "In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24940" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T10:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-4w42-hx2p-m2jw/GHSA-4w42-hx2p-m2jw.json b/advisories/unreviewed/2024/02/GHSA-4w42-hx2p-m2jw/GHSA-4w42-hx2p-m2jw.json new file mode 100644 index 00000000000..225ecc07bd1 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-4w42-hx2p-m2jw/GHSA-4w42-hx2p-m2jw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4w42-hx2p-m2jw", + "modified": "2024-02-06T12:30:31Z", + "published": "2024-02-06T12:30:31Z", + "aliases": [ + "CVE-2024-24938" + ], + "details": "In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24938" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T10:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-5fr5-frrw-m97p/GHSA-5fr5-frrw-m97p.json b/advisories/unreviewed/2024/02/GHSA-5fr5-frrw-m97p/GHSA-5fr5-frrw-m97p.json new file mode 100644 index 00000000000..c912c3596bc --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-5fr5-frrw-m97p/GHSA-5fr5-frrw-m97p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fr5-frrw-m97p", + "modified": "2024-02-06T12:30:31Z", + "published": "2024-02-06T12:30:31Z", + "aliases": [ + "CVE-2024-24943" + ], + "details": "In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24943" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T10:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-73v5-rhgg-73mq/GHSA-73v5-rhgg-73mq.json b/advisories/unreviewed/2024/02/GHSA-73v5-rhgg-73mq/GHSA-73v5-rhgg-73mq.json new file mode 100644 index 00000000000..1a9c55d72f4 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-73v5-rhgg-73mq/GHSA-73v5-rhgg-73mq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73v5-rhgg-73mq", + "modified": "2024-02-06T12:30:30Z", + "published": "2024-02-06T12:30:30Z", + "aliases": [ + "CVE-2024-23917" + ], + "details": "In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23917" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-9rvg-5948-h2q2/GHSA-9rvg-5948-h2q2.json b/advisories/unreviewed/2024/02/GHSA-9rvg-5948-h2q2/GHSA-9rvg-5948-h2q2.json new file mode 100644 index 00000000000..5cb756fcc4c --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-9rvg-5948-h2q2/GHSA-9rvg-5948-h2q2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rvg-5948-h2q2", + "modified": "2024-02-06T12:30:31Z", + "published": "2024-02-06T12:30:31Z", + "aliases": [ + "CVE-2024-24937" + ], + "details": "In JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possible", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24937" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-h24r-m9qc-pvpg/GHSA-h24r-m9qc-pvpg.json b/advisories/unreviewed/2024/02/GHSA-h24r-m9qc-pvpg/GHSA-h24r-m9qc-pvpg.json new file mode 100644 index 00000000000..7fb1cb94c81 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-h24r-m9qc-pvpg/GHSA-h24r-m9qc-pvpg.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h24r-m9qc-pvpg", + "modified": "2024-02-06T12:30:31Z", + "published": "2024-02-06T12:30:31Z", + "aliases": [ + "CVE-2024-0690" + ], + "details": "An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. It was discovered that information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0690" + }, + { + "type": "WEB", + "url": "https://github.com/ansible/ansible/pull/82565" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-0690" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2259013" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-117" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T12:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-h2rq-qhr7-53gm/GHSA-h2rq-qhr7-53gm.json b/advisories/unreviewed/2024/02/GHSA-h2rq-qhr7-53gm/GHSA-h2rq-qhr7-53gm.json new file mode 100644 index 00000000000..72374679a01 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-h2rq-qhr7-53gm/GHSA-h2rq-qhr7-53gm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2rq-qhr7-53gm", + "modified": "2024-02-06T12:30:30Z", + "published": "2024-02-06T12:30:30Z", + "aliases": [ + "CVE-2024-23673" + ], + "details": "\nMalicious code execution via path traversal in Apache Software Foundation Apache Sling Servlets Resolver.This issue affects all version of Apache Sling Servlets Resolver before 2.11.0. However, whether a system is vulnerable to this attack depends on the exact configuration of the system.\nIf the system is vulnerable, a user with write access to the repository might be able to trick the Sling Servlet Resolver to load a previously uploaded script. \n\nUsers are recommended to upgrade to version 2.11.0, which fixes this issue. It is recommended to upgrade, regardless of whether your system configuration currently allows this attack or not.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23673" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/5zzx8ztwc6tmbwlw80m2pbrp3913l2kl" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-m4jj-vwgj-qpjf/GHSA-m4jj-vwgj-qpjf.json b/advisories/unreviewed/2024/02/GHSA-m4jj-vwgj-qpjf/GHSA-m4jj-vwgj-qpjf.json new file mode 100644 index 00000000000..efa03054443 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-m4jj-vwgj-qpjf/GHSA-m4jj-vwgj-qpjf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4jj-vwgj-qpjf", + "modified": "2024-02-06T12:30:30Z", + "published": "2024-02-06T12:30:30Z", + "aliases": [ + "CVE-2024-24936" + ], + "details": "In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24936" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-pmvf-52m5-fj89/GHSA-pmvf-52m5-fj89.json b/advisories/unreviewed/2024/02/GHSA-pmvf-52m5-fj89/GHSA-pmvf-52m5-fj89.json new file mode 100644 index 00000000000..eba9968ff41 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-pmvf-52m5-fj89/GHSA-pmvf-52m5-fj89.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmvf-52m5-fj89", + "modified": "2024-02-06T12:30:31Z", + "published": "2024-02-06T12:30:31Z", + "aliases": [ + "CVE-2024-24941" + ], + "details": "In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24941" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T10:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-qwqw-5hfm-4vgg/GHSA-qwqw-5hfm-4vgg.json b/advisories/unreviewed/2024/02/GHSA-qwqw-5hfm-4vgg/GHSA-qwqw-5hfm-4vgg.json new file mode 100644 index 00000000000..84a0f92886b --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-qwqw-5hfm-4vgg/GHSA-qwqw-5hfm-4vgg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qwqw-5hfm-4vgg", + "modified": "2024-02-06T12:30:31Z", + "published": "2024-02-06T12:30:31Z", + "aliases": [ + "CVE-2024-24939" + ], + "details": "In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24939" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T10:15:10Z" + } +} \ No newline at end of file